How do we process your personal data? – GDPR Information Clause
The administrator of your personal data - "ADMINISTRATOR" - is Hotel Cesarski SPA Sp. z o.o. ul. Stanisława Wyspiańskiego 34A 72-600 Świnoujście NIP 8551570571
Contact with the Administrator is possible via email: rodo@cesarskieogrody.pl, phone +48 / 91 - 88 88 500 ext. 556 or in writing at the company headquarters address. The Administrator uses personal data for the following purposes:
Filling in the form involves providing certain personal data by the User. Providing personal data is voluntary; however, failure to provide data marked as necessary will make it impossible to handle the matter sent via the contact form. If data processing is necessary for the execution of a contract to which the data subject is a party, or to take actions at the request of the data subject before concluding a contract, providing the necessary and specific scope of data is required. Consent to receive commercial information via electronic means of communication is voluntary.
Period of processing and storage of personal data:
To conclude a contract and prepare an offer, the Administrator requires providing data necessary to conclude the contract (if you do not provide them, the contract will not be concluded, and no offer will be presented). Additionally, the Administrator may request optional data that do not affect contract conclusion (if not received, the Administrator may not be able, e.g., to call the contact number, supervise contract performance, or respond to an offer inquiry). Providing data at contract conclusion is not a statutory requirement.
To whom does the Administrator transfer your data?
Your personal data is transferred to:
Your personal data may be obtained directly from you (during a visit to the branch, via forms on the website, by phone or in writing). They may also be obtained from other entities if you have consented to this.
Will your data be transferred outside the European Economic Area (EEA)?Currently, the Administrator does not plan to transfer data outside the EEA (covering the European Union, Norway, Liechtenstein, and Iceland).
Automated decision-makingThe Administrator does not make automated decisions having significant effects on you.
Your rightsYou may submit a request to the Administrator (regarding personal data) to:
You can exercise these rights by sending a request by mail or electronically to the Administrator’s address. To ensure you are entitled to submit the request, the Administrator may ask for additional information allowing the authentication of the requester. The scope of each right and the situations in which they may be exercised result from the law. Which right you may use depends, e.g., on the legal basis of data processing by the Administrator and the purpose of processing.
Right to objectRegardless of the rights mentioned above, you may object at any time to the processing of your data (including profiling) for the purpose of direct marketing. After receiving the objection, the Administrator is obliged to stop processing data for this purpose. In special cases, you may object at any time to the processing of your personal data by the Administrator (including profiling), if the legal basis for data use is the legitimate interest of the Administrator or public interest. In such a case, after considering your objection, the Administrator cannot process the personal data covered by the objection on that basis, unless the Administrator demonstrates that there are:
Consent
If the use of your personal data by the Administrator is not necessary to perform a contract, fulfill a legal obligation, or does not constitute the legitimate interest of the Administrator, the Administrator may ask for your consent to specific uses of your data. You can withdraw your consent at any time (this will not affect the lawfulness of processing before consent withdrawal).
Complaint
You have the right to file a complaint to the President of the Personal Data Protection Office if you believe that the processing of your personal data violates the law.
CookiesCookies are small text files placed on your computer’s hard drive to identify your computer on our servers. If your browser is set to accept cookies, we will use cookies to recognize your computer during visits to the website to provide a more personalized and improved service experience and enhance the quality of the site. You can configure your browser to block cookies.
Google AnalyticsMonitoring your activity on the website – your personal data will be processed in an automated manner (including profiling), but this will not have any legal effects on you. Profiling refers to processing data (also automated) to predict personal preferences and interests.
The entity uses Google Analytics service offered by Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA) to analyze user behavior on our website. Google Analytics uses cookies stored on the user’s computer to analyze their use of the service. Information obtained by the cookie about the user’s way of using the service is usually transmitted to Google servers and stored there.Users can disable all cookies or delete some of them by appropriate browser software settings. Please note that in this case, the user may not fully benefit from all service features. Additionally, the user can prevent Google from collecting data obtained by the cookie and related to their use of the service (including IP address) and from processing such data by Google by downloading and installing a browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=pl.
Google Analytics also collects IP addresses to ensure secure use of the service and to recognize which countries, regions, and cities users come from (geolocation based on IP).
Data are stored in an encoded format optimized for performance, not in traditional file systems or databases. They are distributed across many physical and logical volumes, ensuring redundancy and convenient access, thereby protecting against external interference.Data of all Google users (consumers, businesses, and even Google’s own data) are distributed in a shared infrastructure consisting of many homogeneous computers located in Google data centers.
Google Analytics additionally ensures secure transmission of its JavaScript libraries and measurement data. Google Analytics uses by default the HTTP Strict Transport Security (HSTS) mechanism, which instructs browsers supporting HTTP over SSL (HTTPS) to use this encrypted protocol for all communication between users, services, and Google Analytics servers.
Our site uses the anonymizeIP function in Google Analytics. This means IP addresses are further processed after shortening to exclude the possibility of linking them to specific individuals. If, for collected personal data about a user, it is possible to link them to a specific person, such linking is immediately excluded, and the personal data is promptly deleted.
We use Google Analytics to analyze website usage and improve it regularly. Thanks to the obtained statistics, we can improve our offer and make it more interesting for users. The legal basis for using Google Analytics is Art. 6(1)(f) GDPR.
You can find Google's privacy policy at this link: https://policies.google.com/privacy?hl=pl. Remember that Google changes this policy from time to time, so always make sure it's the current version.
How we protect dataThe Administrator applies appropriate technical and organizational measures ensuring the security of the processed personal data proportional to threats and categories of data protected.
The service is secured with security measures aimed at protecting personal data we process from modification, destruction, unauthorized access and disclosure or acquisition, as well as loss, and processing in violation of regulations specifying principles of personal data processing.
Access to personal data processing is granted only to a limited number of company employees authorized by the data administrator.
Contact Any questions related to processing and protection of personal data of System Users and use of cookies, including concerning this "Privacy Policy" should be addressed to the data Administrator.
Users can also contact us to obtain information on if and to what extent the Administrator processes User data, the purposes and methods of personal data processing of the Service User, as well as due to exercising their rights according to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Changes in policyThis Policy is effective from the above-specified date. From time to time we may change this Policy, and if we do, we will post all changes on this page. If you continue using our website after changes are made, you agree to the changed Policy.
List of data processing entities