This is a courtesy translation. In case of discrepancies, the Polish version prevails.
In brief
This website does not build profiles and does not display advertising. It counts visits with Cloudflare statistics, which save nothing in your browser and read nothing from it. It does, however, save four technical pieces of information in the browser — the chosen theme, a marker that the intro has been shown, your choice from the consent bar and, after logging in with a Member’s code, a session cookie — and, in the preview version before publication, also an access cookie. We list them right next to this. External materials work separately: a YouTube video and an Instagram post connect you to Google or Meta only when you yourself click.
What exactly we save
The complete list of what we save deliberately — four items in the public version and one additional, only in the preview before publication; no others. The three entries in browser storage stay on your device and go nowhere; the browser attaches both cookies to every request to our server — and sends them only there, to no one else. You delete them by clearing the site data in your browser.
| Name | Where | What for and when it is created | How long |
|---|---|---|---|
| bni-theme | local storage (localStorage) | Remembers the chosen theme: light or dark. It is created when you switch the theme — we do not set it ourselves. | until site data is cleared |
| bni-intro | session storage (sessionStorage) | A marker that the home page intro has already been shown, so that it does not replay on every return. It is created on the first opening of the home page, without your clicking. | until the tab is closed |
| bni-zgody | local storage (localStorage) | Remembers your choice from the consent bar: whether external materials — YouTube recordings and Instagram posts — may start immediately after clicking. It is created only when you click one of the buttons — closing the bar without choosing saves nothing. | until site data is cleared |
| bni-czlonek | cookie (HttpOnly) | Maintains a Member’s session after logging in with an access code — before the people search tool and the materials form. It is created after a correct code is entered; it is a signed token with an expiry date and a random session number — without a first name, surname or e-mail address. The session number serves only to count queries in the people search tool (at most 60 per 10 minutes), so that no one downloads the directory in bulk; the counter is not stored permanently anywhere. Logging out deletes the cookie immediately. | 24 hours |
| bni-preview | cookie (HttpOnly) | Maintains access to the PIN-protected preview version. It is created after the PIN is entered; the public version does not use it. | 30 days |
None of this information says who you are. The theme, the intro marker and the consent record are technical and are not used to measure traffic or for advertising — we reach for them only so that the page behaves as it did last time. Each time the page is opened we check the saved theme so as not to flash a light screen in dark mode. The consent record is three things: one value — yes or no — the date of the choice and the version number of the record. The version number is there so that we can ask you again should the consent bar change.
A separate matter is the ordinary browser cache — it is not in the table, because it is not a marker, but since we promise a complete list, we mention it too. We send the Member search tool’s response with a header that forbids saving it (`no-store`) — the browser keeps nothing of it, and the same phrase goes to the server every time. The company look-up by NIP number in the forms works differently: the browser may keep the response with the name and address from the register in its cache for up to an hour, so that it does not ask the register a second time when the same number is entered again. This is a transport record on your device — we do not read it and do not send it anywhere; it disappears together with the browser cache. The server-side buffer is described in the Privacy Policy.
What cookies are
Cookies are small text files that a website saves in the visitor’s browser. They usually serve to remember settings, maintain a session after logging in, or to measure traffic and target advertising.
What this website does not do
The website is an information site — it has no basket or user account. The only login is the access code for Members before the people search tool and the materials form; it is maintained by the session cookie from the table above and nothing else. We do not use advertising tools or analytics that track individual people: Google Analytics, Meta Pixel, Hotjar and any other tool building a visitor profile do not operate here. We only count visits, without cookies — described in the section below.
The typefaces the website uses are uploaded to our server and loaded from there. Your browser does not connect to Google’s servers when fetching them.
Visit statistics without cookies
We measure the number of visits and which pages are read with Cloudflare Web Analytics (Cloudflare, Inc.). When a page loads, the browser fetches a small script from Cloudflare’s servers, which sends them information about the visit: the page address, the page you came from, the browser and device type, the country and the page load time.
The script saves nothing on your device and reads nothing from it — it uses no cookies or browser storage, assigns you no identifier and does not recognise you on your next visit. Cloudflare does not store your IP address for the statistics. We see only aggregate data — how many visits a page had, from which countries and devices — with no way of identifying a specific person.
Because nothing is saved on your device or read from it, the statistics do not require consent and have no entry in the consent bar. Popular ad-blocking extensions block the script — the website then works unchanged. The legal basis and the recipient of the data are described in the Privacy Policy.
Browser storage beyond cookies
Cookies are not the only way a website can save something on your device. Browsers also have local and session storage and a built-in database — websites use them to remember settings, the language version or the fact that a banner has already been closed. The law does not speak only of cookies: the obligation to ask for consent applies to every storing of information on the device and every access to information already stored there.
That is why we count it more broadly — and why we also listed above what is not a cookie. The website uses local and session storage in exactly the three places described in the table. It does not set up a database in the browser, does not install any software and has no mechanism that would operate after the tab is closed.
The exception: YouTube videos and Instagram posts
On a dozen or so sub-pages we embed recordings from YouTube. The player does not load on its own — until you click, you see a still frame and a button, and the browser does not connect to YouTube.
Clicking the play button starts the player in privacy-enhanced mode (youtube-nocookie.com). In this mode YouTube does not save cookies used to personalise advertising, but it may save the technical information needed to play the recording — also in the browser storage we describe above. Your IP address then also goes to Google. From that moment Google’s rules apply, not ours — they are described in the Google Privacy Policy.
Instagram posts on the Events page work the same way: a post opens in a large window only after you click the button. The browser then connects to Instagram’s servers, passes your IP address there, and Instagram may save its own cookies and information in the browser storage. From that moment Meta’s rules apply — they are described in the Meta Privacy Policy.
If you do not want this to happen — simply do not click play or the preview. All of the website’s content is available without starting the videos and posts.
If in the consent bar you chose “Essential only”, the video frame — and the window with the Instagram post — asks once more: before connecting it shows what will happen and waits for confirmation. With the choice “Accept” the video starts, and the post opens, immediately after clicking.
The consent bar and your choice
On your first visit to the website a consent bar appears. It has two buttons of equal weight — “Accept” and “Essential only” — because refusal must cost exactly the same as consent: one click. A third, smaller button — “Settings” — expands both categories: the essential one, which cannot be switched off, and external materials with a checkbox. “Save choice” saves the state of that box: ticked works like “Accept”, unticked like “Essential only”. The bar does not cover the content and does not block the page; you can close it with the Esc key, in which case we save nothing and the no-consent state applies.
Consent is not required for what is necessary to display the page you yourself request — as the electronic communications regulations provide. That is the case with the theme, the intro marker and the logged-in Member’s session cookie. The bar shows the theme and the marker as a fixed item, without a switch. The session cookie is created only after logging in with a Member’s code, outside the bar — the table above describes it. Visit statistics save nothing on the device and read nothing from it, and we show no advertising, so there is nothing to ask about there. What remains are the external materials that really go beyond this website: recordings from YouTube and Instagram posts.
- Accept — the recording starts immediately after you click the frame, and the Instagram post opens immediately in the window.
- Essential only — before starting the player or opening the post, the frame asks for confirmation and says plainly that it connects you to Google or Meta.
In both cases, until you click, the browser connects neither to YouTube nor to Instagram — you see a still frame or a button loaded from our server. The consent bar neither unlocks nor blocks anything in advance; it only settles whether we ask once more before connecting.
You can change your choice at any time: the “Cookie settings” link is in the footer, at the bottom of every page, next to the other documents. It opens the same bar, with the state that applies marked. The record of the choice itself is described in the table above — one value, a date and the version number of the record, nothing about you.
If in the future we launch tools that save something in the browser or build a visitor profile (for example Google Analytics), a separate category will be added to the bar, and we will update this document before they are switched on.
How to manage cookies in your browser
Regardless of what a particular website does, every browser can be set to block cookies or to ask for consent at every attempt to save one. You will find the settings in your browser’s privacy section — the instructions are provided by the vendors:
Blocking cookies and browser storage will not shut you out of the content — the page will simply forget the chosen theme, show the home page intro afresh on every visit, ask for consents every time, and the Member login will not persist between sub-pages. It may, however, make it impossible to play the embedded videos and open the posts.
Changes and contact
This document describes the state as at the date of publication. We will change it if the way the website works changes — and we will describe the change openly, not quietly.
The bnipolska.pl website is run by BNI Poland Sp. z o.o. with its registered office in Warsaw, ul. Chłodna 51, 00-867 Warszawa, KRS 0000475787, NIP 1132868575, REGON 146851390. It is the company that saves in your browser the cookies and entries described above and is the controller of your personal data — you will find its full details and the processing rules in the Privacy Policy.
Questions about cookies and personal data: rodo@bnipolska.pl or a letter to the registered office address.
The rules on data processing are described in the Privacy PolicyContact
