I like Chopin

Privacy Policy

Version 1.1 · in force from 27.08.2026

This policy explains what data we collect about you, why, and what you can do about it. We wrote it so that it can be read without a lawyer — references to legislation appear where they genuinely add something.


1. Who processes your data

The controller of your personal data is:

Lobos Maciej Łobos, Rajska 4C, 80-850 Gdańsk, Poland, VAT ID (NIP): 5833569755

For any matter concerning personal data, write to info@ilikechopingdansk.com or call +48 883 107 854. A real person answers here, not a form.

We run intimate candlelit piano concerts in the hall at ul. Rajska 4C in Gdańsk and sell tickets for them through this website.

We have not appointed a data protection officer — the law does not require us to.


2. Where we get your data from

From two sources. You give it to us yourself — when buying a ticket or a voucher, or when writing to us. It is collected automatically — when you visit the website (IP address, browser information, cookies) and when you enter the hall, which is covered by video surveillance.

We sell tickets exclusively through this website. We do not buy databases and we do not obtain data from intermediaries.


3. We do not create accounts and we have no passwords

On this website there is no registration, no account and no password. You buy a ticket as you would at a box office: you give only what is needed to issue the ticket and take the payment.

We send the ticket by e-mail as an individual link secured with a cryptographic signature. The link works until the day of the concert and expires afterwards. If you need access to the order details later — for example in the case of a complaint — write to us and we will find them.

Because there are no accounts, we store no passwords. That is a deliberate decision: passwords that do not exist cannot leak.


4. What we collect, why, and on what legal basis

4.1 Ticket purchase

What we collect: the first and last name of the buyer, e-mail address, phone number (optional field), the chosen concert and date, the number and type of tickets, the amount and the payment identifier.

Why: to sell you the ticket, send it to you, admit you to the concert, contact you about your order and notify you if the date changes or the concert is cancelled.

The phone number is voluntary. Give it to us if you want us to be able to call you in case of a sudden change of date — without it we will only send an e-mail.

Legal basis: Art. 6(1)(b) GDPR — processing is necessary for the performance of a contract to which you are a party. As regards the phone number: Art. 6(1)(a) GDPR, that is your consent expressed by providing it.

How long: for the time needed to perform the order, and then for the period during which claims under the contract may be pursued — 6 years, counted to the end of the calendar year.

Is it required: providing the data is voluntary, but without a first name, last name and e-mail address we cannot sell you a ticket.

4.2 Concert attendees' data

Our tickets are personalised — at purchase we ask for the first and last name of every person who is to enter the concert.

Why: to check at the entrance that the ticket belongs to the person presenting it, and to verify eligibility for a reduced-price ticket.

Legal basis: Art. 6(1)(b) GDPR — a personalised ticket is part of the contract you conclude with us; as regards the check at the entrance, also Art. 6(1)(f) GDPR, that is our legitimate interest in making sure that only eligible people enter the concert.

How long: the same as the order data (§4.1).

If you buy tickets for other people, you give us their data — please inform them that you have done so and where we got their name from. This policy is available to them at the same address.

4.3 Payment

What we collect: the amount, the transaction identifier, the payment status and the method chosen.

We do not see and do not store your card number or your bank login details. The payment is handled by the operator indicated in §7 — you give the card details or the login details directly to them, on their site.

Legal basis: Art. 6(1)(b) GDPR.

4.4 Invoicing and accounting

What we collect: invoicing details — first and last name or company name, address, VAT ID (NIP) if you provide it.

Legal basis: Art. 6(1)(c) GDPR — we have such an obligation under the Accounting Act and tax legislation.

How long: 5 years, counted from the end of the calendar year in which the tax payment deadline fell.

We transmit invoices to the National e-Invoicing System (KSeF) operated by the Minister of Finance — this is a statutory requirement, not our decision, and you cannot object to it.

4.5 Vouchers and discount codes

What we collect: the e-mail address of the person receiving the gift, if you provide it, the voucher code, its balance and its usage history.

Why: to issue the voucher, deliver it, and keep track of the usage limits of a discount code.

Legal basis: Art. 6(1)(b) GDPR towards the buyer; towards the person receiving the gift — Art. 6(1)(f) GDPR, that is our legitimate interest in delivering the gift to them.

How long: until the voucher is used or expires, and then for the limitation period for claims.

4.6 Contacting us

What we collect: your name, e-mail address, phone number if you provide it, and the content of the message.

Why: to answer your question or to quote a private or group concert.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in corresponding with people who write to us. If the question concerns concluding a contract — Art. 6(1)(b) GDPR.

How long: 12 months from the end of the correspondence. Longer only where the matter may lead to a contract or a claim.

4.7 Visit statistics

What we collect: which page you opened and when, which concert or post it concerned, in which language, whether you clicked "buy ticket", the address of the page you came to us from — only its domain, never the full address or the phrase you typed — and whether you read us on a phone, a tablet or a computer.

What we do not collect: we do not save a cookie and we do not read anything from your device. We do not store your IP address. It takes part in computing a one-off key that lets us count how many readers there were, not just how many page views — but the address itself is never stored anywhere, and the key changes every day at midnight, with the previous one deleted. From that moment on, not even we are able to tell that yesterday's and today's reader are the same person.

Why: to know which concerts and which language versions interest our visitors, and to improve the website on that basis. We are interested in patterns, not individual people — and that is how this measurement is built, not merely how it is declared.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in knowing how our website is used.

How long: 400 days. The key that allows a reader to be recognised within a single day dies the same day at midnight.

4.8 Website security and technical logs

What we collect: IP address, the date and time of the request, the address of the page opened, browser information. Separately we record events relating to orders: ticket check-in at the entrance, refunds and changes to attendee details.

Why: so that the website works, so that we can detect abuse and errors, and so that we can reconstruct the course of an order should a dispute arise.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the security and proper functioning of the website and in defending against claims.

How long: server logs 90 days. Order records — as long as the order itself.

4.9 Video surveillance in the hall

The hall at ul. Rajska 4C and its entrance are covered by video surveillance. The cameras cover the entrance to the hall and its interior.

Why: to protect the people present in the hall and our property — above all the piano and the sound equipment — and to be able to clarify any incidents, for example theft, damage to property or an accident.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in protecting people and property.

What we record: image only. We do not record sound.

How long: recordings are automatically overwritten after 30 days. We keep longer only a specific recording secured as evidence in a case — until that case is finally concluded.

Who has access: only company staff and persons authorised by us. We disclose recordings externally only to authorities entitled to them under the law.

The area covered by surveillance is marked with information signs at the entrance.

You have the right to object to being recorded (§9). We will consider the objection individually — we may not uphold it if the protection of people and property turns out to be more important, but we will always explain why.

4.10 What we do not do

For clarity, because people often ask:

  • We do not run a newsletter. There is no mailing-list sign-up and we do not send marketing mailings. If that changes, we will update this policy, and signing up will require your explicit consent.

  • We do not photograph or film the audience during concerts for promotional purposes. The surveillance described in §4.9 serves security only and does not end up on social media or on the website.

  • We do not embed content from other services on the website — there are no Google Maps, no YouTube videos, no Facebook plugins and no review widgets. Because of this, opening our page does not pass your IP address to third-party companies.

  • We do not run tracking advertising. There is no Meta pixel and no Google Ads remarketing lists.

  • We do not sell or rent out your data. Never, to anyone.


5. Cookies

Cookies are small files that the website saves in your browser. We use two categories — and only two.

Essential

Without them the website does not work. They maintain the basket and the purchase session, protect forms against abuse, and remember the language version you chose and your decision from the cookie banner.

We store them on the basis of Art. 398(3) of the Electronic Communications Law — they are necessary to provide the service you request, so we do not ask for consent. They are not used to track you.

Analytics — only with your consent

They show us how visitors move around the website.

Until consent is given, the analytics script does not load at all. You give consent in the banner on your first visit and you can change or withdraw it at any time by clicking "Cookie settings" in the website footer. Withdrawal of consent takes effect for the future — it does not invalidate what we collected earlier.

You can also delete and block cookies in your browser settings. Blocking essential cookies will, however, make buying a ticket impossible.

We have no marketing category, because we do not run tracking advertising. The banner therefore contains no such question.


6. Does data go outside Europe

Yes, partly — two of our technical providers process data in the United States: the e-mail provider that sends you the ticket, and the provider of the server administration tool. Google statistics are collected in Ireland with transfer to the USA.

We transfer data there on the basis of the European Commission's decision on the EU‑U.S. Data Privacy Framework — for providers holding a current certification — or on the basis of standard contractual clauses approved by the Commission. You can ask us for a copy of these safeguards by writing to the address in §1.

The website itself and the database containing your order run on servers in Germany, that is within the European Union.


7. Who we pass data to

Only to entities that help us run sales and the website — and only to the extent they need for that. Each of them is bound to us by a data processing agreement.

Who

Why

Where

Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114

sending e-mails with tickets and notifications

USA

Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen

servers on which the website and the database run

Germany

Puls Online Krzysztof Kalkowski, ul. Mariana Kołodzieja 53B/7, 80-180 Gdańsk

building, maintaining and administering the website

Poland

Laravel Holdings, Inc. (Laravel Forge), 60 Broad Street, 24th Floor, #1559, New York, NY 10004

server administration tool

USA

Minister of Finance — National e-Invoicing System

statutory circulation of invoices

Poland

Regiondo GmbH, Karlsplatz 3, 80335 Munich

ticket sales within the website

Germany

We also disclose data to state authorities — the police, the courts, the tax office — but only where we have a legal obligation to do so and only to the extent covered by the request.


8. How long we keep data

We gave the periods next to each purpose in §4. In short:

What

How long

Orders and attendees' data

6 years, to the end of the calendar year

Invoices and accounting documents

5 years from the end of the year in which the tax payment deadline fell

Correspondence

12 months from the end of the matter

Surveillance recordings

30 days

Server logs

90 days

Statistical data in GA4

14 months

Statistical data (our own)

400 days

Vouchers

until used or expired, then the limitation period

After these periods we delete the data or strip it of the features that allow you to be identified. We keep sales statistics longer, but in a form from which it is impossible to read who bought a ticket.


9. Your rights

In relation to your data you have the right of:

Access — you can ask what data we hold about you and request a copy of it.

Rectification — if it is incorrect or incomplete, we will correct it.

Erasure — if we no longer have a basis to keep it. We will not delete data from invoices already issued for as long as tax law requires it — we will then tell you plainly what stays and why.

Restriction of processing — you can demand that we only store the data and do nothing else with it.

Portability — data you provided on the basis of a contract or consent will be given to you in a machine-readable format or sent to an entity you indicate.

Objection — to processing based on our legitimate interest, that is to correspondence (§4.6), logs (§4.8) and surveillance (§4.9). We will consider it individually and give reasons for our decision.

Withdrawal of consent — at any time, without giving a reason. This concerns analytics cookies and a phone number provided voluntarily. Withdrawal takes effect for the future and does not invalidate what we did earlier in accordance with the law.

Send your request to info@ilikechopingdansk.com. We reply within one month. Should the matter prove complex, we may extend this deadline by two months — we will then let you know in advance and explain why. Exercising your rights is free of charge.

If you consider that we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00‑193 Warsaw, Poland. We would be sorry, however, if we failed to clear the matter up directly first — write to us before that.


10. Automated decisions and profiling

We do not take decisions about you based solely on automated processing and we do not profile you. Nobody and nothing on our website assesses you algorithmically or differentiates the ticket price on that basis.


11. Security

The website works exclusively over an encrypted connection (HTTPS). We do not store payment card data at all. There are no accounts and no passwords, so there is nothing to take over. Ticket links are cryptographically signed and expire on the day of the concert. Only authorised persons have access to the sales panel, and operations on orders are logged. We back up the database, and access to the server is restricted and logged.

No safeguard is perfect. Should a breach occur that could result in a high risk to your rights, we will notify you without undue delay — as required by Art. 34 GDPR.


12. Children

The website is not directed at children and we do not knowingly collect data of people under 16 directly from them. A ticket for a child is bought by an adult, and it is the adult who provides the child's first and last name for the personalised ticket.


13. Language versions

The policy is available in Polish and that version is binding, regardless of the country in which the ticket was bought or the website visited.


14. Changes to the policy

We may change the policy when the law or the way the website works changes. We publish the new version at the same address, with the effective date at the top. Previous versions are available on request.