Privacy Policy for Europa Vistula
Last updated: 06 September 2026
Website address: https://vistulaeuropa.com
Europa Vistula (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).
1. Data Controller
Europa Vistula is the Data Controller responsible for your personal data processed through this website. For any privacy-related enquiries, please contact us at: privacy@vistulaeuropa.com.
2. Personal Data We Collect
We collect and process the following categories of personal data:
Communication data: If you contact us via email or through our contact forms, we retain the information you provide, including your email address and message content.
Comment data: Your name, email address, website (if provided), and the content of your comment, along with your IP address and browser user agent string for spam detection purposes.
Account data: For registered users, the personal information you provide when creating or editing your user profile (e.g., name, email address, display name).
Usage data: Information collected automatically through cookies, including your login session data, screen display preferences, and interaction with embedded content.
3. Legal Basis for Processing
We rely on the following lawful bases under Article 6 of the GDPR:
| Purpose of Processing | Legal Basis | GDPR Article |
|---|---|---|
| Processing comments and associated metadata (IP, user agent) | Legitimate interests — protecting our website from spam and abuse | Art. 6(1)(f) |
| Providing Gravatar profile pictures via hashed email | Legitimate interests — enhancing user experience on comments | Art. 6(1)(f) |
| Managing user accounts and profiles | Performance of a contract — providing the service you registered for | Art. 6(1)(b) |
| Setting functional cookies (login, screen preferences) | Consent or legitimate interests — enabling core website functionality | Art. 6(1)(a) / Art. 6(1)(f) |
| Password reset emails (including IP address) | Legitimate interests — securing user accounts against unauthorised access | Art. 6(1)(f) |
| Automated spam detection on comments | Legitimate interests — protecting our platform and users | Art. 6(1)(f) |
| Processing contact form submissions | Legitimate interests — responding to your enquiry | Art. 6(1)(f) |
You have the right to object to processing based on legitimate interests at any time (see Section 8 below).
4. Comments
When visitors leave comments on our site, we collect the data shown in the comments form, along with the visitor’s IP address and browser user agent string to help with spam detection.
An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
5. Media
If you upload images to our website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
6. Cookies
If you leave a comment on our site, you may opt-in to saving your name, email address, and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for one year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies are removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
| Cookie Category | Purpose | Duration | Consent Required? |
|---|---|---|---|
| Comment preference cookies | Remember commenter name/email/site | 1 year | Yes (opt-in) |
| Session cookies (login) | Authenticate logged-in users | 2 days (14 days with “Remember Me”) | No (strictly necessary) |
| Screen options cookies | Save display preferences | 1 year | No (strictly necessary) |
| Post editor cookie | Indicate post ID being edited | 1 day | No (strictly necessary) |
| Temporary cookie (login page) | Check browser cookie support | Session | No (strictly necessary) |
7. Embedded Content from Other Websites
Articles on our site may include embedded content (e.g., videos, images, articles). Embedded content from other websites behaves in the exact same way as if the visitor had visited the other website directly.
These third-party websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content — including tracking your interaction if you have an account and are logged in to that website. We do not control the data collection practices of these third parties. We recommend reviewing the privacy policies of any embedded content providers.
8. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You can request correction of inaccurate or incomplete personal data.
- Right to erasure / “right to be forgotten” (Art. 17): You can request deletion of your personal data, subject to exceptions where we are legally obliged to retain it.
- Right to restrict processing (Art. 18): You can request that we limit the processing of your data in certain circumstances.
- Right to data portability (Art. 20): You can request an export of your personal data in a structured, machine-readable format and have it transmitted to another controller.
- Right to object (Art. 21): You can object to processing based on legitimate interests or performed for direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): Where processing is based on your consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint with a supervisory authority (Art. 77): If you believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the relevant data protection supervisory authority — typically in your place of habitual residence, place of alleged infringement, or with the authority of the EU Member State where Europa Vistula operates.
To exercise any of these rights, please contact us at privacy@vistulaeuropa.com. We will respond to your request within one month of receipt, as required by Article 12 of the GDPR. This period may be extended by two further months where necessary, taking into account the complexity and number of requests; we will inform you of any extension within that initial month.
9. Who We Share Your Data With
We do not sell your personal data. We may share your data with the following recipients:
- Automated spam detection service: Visitor comments may be checked through an automated spam detection service, which processes comment content, IP address, and related metadata.
- Gravatar (Automattic Inc.): For retrieving profile pictures associated with commenters’ email addresses.
- Hosting provider: Our website is hosted by a third-party hosting provider that processes data on our behalf as a data processor under a written agreement (Art. 28 GDPR).
- Email service provider: For sending password reset emails and other transactional communications.
Where we engage third-party processors, we ensure that appropriate data processing agreements are in place in accordance with Article 28 of the GDPR.
10. International Data Transfers
Some of the third parties mentioned above may process your data outside the European Economic Area (EEA). Where this occurs, we ensure that appropriate safeguards are in place, such as:
- The European Commission’s adequacy decision for the recipient country, or
- Standard Contractual Clauses (SCCs) adopted by the European Commission, or
- Other transfer mechanisms recognised under Chapter V of the GDPR.
You may request a copy of the relevant safeguards by contacting us at privacy@vistulaeuropa.com.
11. How Long We Retain Your Data
| Data Type | Retention Period | Reason |
|---|---|---|
| Comments and metadata | Indefinitely | To recognise and auto-approve follow-up comments without moderation delays |
| Registered user profile data | Until account deletion by the user or administrator | Account management and service provision |
| Password reset requests (incl. IP) | Up to 30 days after the reset is completed | Security audit trail |
| Contact form submissions | Up to 12 months after resolution | Record of correspondence |
| Comment preference cookies | 1 year | User convenience |
| Login/session cookies | 2 days (14 days with “Remember Me”) | Session management |
| Post editor cookie | 1 day | Editorial workflow |
Users can request to have their data erased at any time, subject to legal or administrative retention obligations (see Section 8, Right to erasure).
12. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- HTTPS/TLS encryption for data transmission
- Access controls limiting data access to authorised personnel only
- Regular security updates and monitoring of our website infrastructure
- Secure password hashing for user accounts
13. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected data subjects without undue delay, in accordance with Article 34 of the GDPR.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be available on this page with an updated “Last updated” date. We recommend reviewing this page periodically. Where significant changes are made, we will provide a prominent notice on our website.
15. Contact Us
If you have any questions about this Privacy Policy or wish to exercise any of your data subject rights, please contact us at:
Europa Vistula
Email: privacy@vistulaeuropa.com
Website: https://vistulaeuropa.com
