GDPR - your rights
GDPR rights at New European Strategies: what you have, how to exercise them, how fast we respond and where to lodge a complaint.
Last updated: 2026-09-14
What the GDPR is and when it protects you
The GDPR is Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data. In Poland it is supplemented by the Personal Data Protection Act of 10 May 2018.
It protects you whenever New European Strategies processes information that can identify you - including indirectly, for example through an account identifier, an IP address or a device identifier. Having an account is irrelevant: GDPR rights also apply to people who only subscribed to the newsletter, sent a contact form or attended an event.
The data controller is New European Strategies. For all data protection matters: office@neweuropeanstrategies.com.
Your rights - the full list
- Access and a copy of your data (Article 15) - confirmation of whether we process your data, which data, for what purpose, who receives it and how long we keep it, together with a copy.
- Rectification (Article 16) - correction of inaccurate data and completion of incomplete data. Most profile data you can correct yourself.
- Erasure, the right to be forgotten (Article 17) - deletion when the data is no longer needed, when you withdraw consent or when you successfully object.
- Restriction of processing (Article 18) - freezing the data while we resolve a dispute over its accuracy or over our legitimate interest.
- Data portability (Article 20) - receiving data processed on the basis of consent or a contract in a structured, commonly used, machine-readable format.
- Objection (Article 21) - against processing based on legitimate interest. An objection to direct marketing is UNCONDITIONAL: we always honour it and never ask why.
- Withdrawal of consent (Article 7(3)) - at any time and as easily as it was given. Withdrawal takes effect for the future and does not affect the lawfulness of what we did before.
- Not being subject to an automated decision (Article 22) - the right to human intervention where a decision produces legal or similarly significant effects.
- Complaint to a supervisory authority (Article 77) - independently of contacting us and without having to exhaust our internal route first.
How to submit a request
The fastest channel is the app: the Privacy page in your profile (/profile/privacy) lets you download a full copy of your data, change consents, set your visibility in the people directory and start account deletion yourself. These are exactly the operations we would perform on request - without the wait.
The written channel: office@neweuropeanstrategies.com. Just tell us what the request is about - no form and no justification required (except for an objection to processing other than marketing, where the GDPR requires you to point to your particular situation).
- You do not need to cite a specific GDPR article - describing what you want is enough.
- Requests are free of charge. Article 12(5) allows a fee or a refusal only for manifestly unfounded or excessive requests, for example serially repeated ones; if we ever rely on that, we will justify it in writing.
- If we cannot identify you, we will ask for additional information (Article 12(6)). We ask for the minimum needed to confirm identity - never for a scan of an ID document just in case.
- A request on behalf of someone else requires a power of attorney. Without it we will not release another person's data, not even to a family member.
How quickly we respond
- Without undue delay and within one month of receiving the request at the latest (Article 12(3)).
- That period may be extended by a further two months where the request is complex or where several requests coincide. We inform you of the extension and its reason within the first month.
- If we take no action, within one month we explain why and inform you about the complaint to a supervisory authority and about judicial remedies.
- Objections to direct marketing and withdrawals of marketing consent are actioned immediately - we do not wait out the month.
Data export - exactly what you get
The export you start from the panel returns a JSON file with a manifest: section by section it lists what the file contains and also WHAT IT DELIBERATELY OMITS and why. The manifest travels inside the package, so a missing category is visible to you, not only to us.
High-volume sections (messages, reading history, comments) have a declared row limit. When a package is truncated, the manifest marks that section as truncated - so the file never pretends to be complete. If you need history beyond the limit, write to us and we will prepare it manually.
- Included: account and profile, subscriptions and orders, consents with their decision history, content (comments, threads, replies), messages and contacts, event registrations, reports and complaints.
- Excluded: other people's data (for example the content of their messages), trade secrets, and security logs whose release would weaken the protection of your own account. Every exclusion is named in the manifest.
Account deletion and the limits of erasure
You can start account deletion yourself in the panel. The operation is irreversible: we will not restore the profile, the history or access to paid content.
The right to erasure is not absolute. Article 17(3) allows us to keep data where processing is necessary to comply with a legal obligation or for the establishment, exercise or defence of legal claims.
- We keep accounting and settlement documents for the period required by tax law - invoices do not disappear with the account.
- We keep the minimum trace needed to handle a dispute while that dispute is ongoing.
- An email address covered by a marketing opt-out stays on a suppression list - that is the only way an unsubscribe is remembered reliably and you do not receive another message after a list is re-imported.
- Your public contributions (comments, threads) may be kept in anonymised form so that other people's discussions do not fall apart. The link to you is removed.
Profiling and automated decisions
We do not take decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you within the meaning of Article 22(1).
We do use low-risk profiling: we select content recommendations, ordering and newsletter segmentation based on what you read and which topics you follow. You can switch this off by withdrawing the personalisation consent.
Automated anti-spam filters may hold a comment for review. That is not a final decision: every such item is assessed by a human, and the appeal route is described in the moderation document (/moderacja-komentarzy).
Personal data breaches
- We notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach (Article 33).
- Where a breach is likely to result in a high risk to your rights and freedoms, we also notify you, without undue delay and in plain language (Article 34).
- The notification describes the nature of the breach, its likely consequences, the measures taken and what you can do yourself.
- You can report a suspected breach to us at office@neweuropeanstrategies.com - we treat such reports as a priority.
Complaint to a supervisory authority
If you believe we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. The authority competent for us is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
You may also complain in the EU Member State of your habitual residence or place of work, if that is a different country. Independently of a complaint you have the right to an effective judicial remedy (Article 79) and to compensation (Article 82).
You do not have to contact us first - but if you do, we will usually resolve the matter faster than administrative proceedings would.
Contact
All data protection matters: office@neweuropeanstrategies.com. Putting "GDPR" in the subject line is enough - we then route the message straight to the person responsible for data protection.
We have not appointed a data protection officer because none of the conditions in Article 37(1) applies. This changes nothing about your rights or our response times - it only means there is no separate DPO address.
This document covers how to exercise your GDPR rights. The full description of purposes, legal bases and recipients is in the privacy notice (/polityka-prywatnosci); the operational layer is in the data processing policy (/polityka-przetwarzania-danych).