Privacy policy governance
How New European Strategies versions its privacy policies: who owns them, how we announce changes and where you manage your settings.
Last updated: 2026-09-14
Why govern policies in a separate document
Article 5(2) GDPR requires a controller not only to comply but to be able to DEMONSTRATE compliance. A privacy notice that nobody versions and whose changes are never announced fails that test: a year later there is no way to tell which text a person consented to yesterday and which text another person consented to last season.
So this document describes the process: who owns the content, how a new version is produced, when a change requires fresh consent and how we notify you.
Map of the documents and their scope
Where documents differ, the one more specific to the surface prevails; in data protection matters the privacy notice prevails.
- Privacy notice (/polityka-prywatnosci) - what we process, why, on what basis and who receives it. The primary document under Articles 13-14 GDPR.
- GDPR - your rights (/rodo) - how to exercise your rights: channels, deadlines, export scope, limits of erasure, complaints to the authority.
- Data processing policy (/polityka-przetwarzania-danych) - the operational layer: records of processing, processors, retention, transfers, security.
- Cookie policy (/cookies) - categories of cookies and similar technologies together with the preference centre.
- Communications and marketing (/komunikacja-i-marketing) - newsletter, notifications, marketing consents and opting out.
- Terms and conditions (/regulamin), refunds and complaints (/zwroty-i-reklamacje) - the contractual and consumer layer.
- Content moderation (/moderacja-komentarzy), discussion clubs (/regulamin-klubow-dyskusyjnych), events and tickets (/regulamin-wydarzen-i-biletow) - rules for surfaces where we process data in a specific context.
Who owns the content
- New European Strategies owns all policies; decisions about changes are taken at the publisher's management level.
- A change may be initiated by the editorial team, the product team or the person responsible for data protection - usually because a real process changed, not because the wording did.
- Changes affecting legal bases, data scope, recipients or retention periods go through legal review before publication.
- We have not appointed a data protection officer - none of the conditions in Article 37(1) GDPR applies. Coordination duties sit with a designated person on the publisher's team.
Versioning and accountability
Every legal document has its own version history in the system: draft, published version and archived versions. Exactly one version of a document is published at any moment, and publishing is atomic - there is no state in which an address carries no binding text.
A version carries a label, a note on the scope of the change and an effective date. If no published version exists in the database, the page renders the baseline text built into the application code - so a legal document remains available even if the data layer fails.
- Document addresses are permanent. Changing the content does not change the address, so a link you shared a year ago still leads to the version in force.
- The Last updated date on a page refers to THAT document. We do not roll it forward on documents where nothing changed - that would destroy its only informational value.
- Consents collected in the service are stored together with the version of the text they were given for, a timestamp and the source of the decision. That makes it possible to reconstruct exactly what a person agreed to.
How we announce changes
- Editorial changes (wording, clarifications, new examples) are published immediately with an updated date on the document page.
- Material changes - a new purpose, a new category of recipients, a new legal basis, longer retention, changed moderation rules - are announced at least 14 days before they take effect.
- We notify registered users of material changes by a message to the address on the account and by an in-service notice. That is a service message: you receive it regardless of marketing consents.
- A change to the TEXT OF A CONSENT requires a fresh decision. We bump the consent version and the previous one stops being a basis for processing - we never inherit an old consent onto a new scope.
- If you do not accept a change to the terms, you may terminate the service before it takes effect, on the conditions set out in the terms and conditions.
Where you manage privacy yourself
The settings hub is the Privacy page in your profile (/profile/privacy). Its layout follows increasing irreversibility: what you change daily first, what cannot be undone last.
- Visibility and contact - presence in the people directory, accepting enquiries, who may start a conversation or invite you to their network, read receipts, typing indicator.
- Consents - the catalogue of communication, product and analytics consents with their decision history, linked to the cookie preference centre.
- Your data - export of a full copy (Articles 15 and 20 GDPR) and account deletion (Article 17 GDPR).
- Cookie preferences can also be changed without signing in, from the cookie policy (/cookies) - the consent banner opens directly from that page.
- We honour the Global Privacy Control (GPC) signal sent by your browser and treat it as an objection to processing for marketing purposes.
Review cycle
- We perform a full review of all policies at least once every 12 months.
- An out-of-cycle review is triggered by any of: onboarding a new processor, launching a surface that collects new categories of data, a change in law or regulatory guidance, a security incident.
- The review also covers whether our statements match the code: the export scope, the consent catalogue and the processor list are tested automatically, so a drift between document and system blocks the release.
Questions and feedback on the policies
If any passage is unclear or looks inconsistent with what the service actually does, write to office@neweuropeanstrategies.com. We treat reports of inconsistency like bug reports: we check the process, not just the wording.
This document describes the process, not the content of the policies themselves. Current versions live at their permanent addresses - those addresses do not change, only the content behind them does.