Home   Privacy Policy

Privacy Policy

PRIVACY POLICY

This Privacy Policy

Adrian Wilgosz, conducting business under the name Adrian Wilgosz NADWIL, with its registered address at ul. Artura Grottgera 15, 76-200 Słupsk, entered in the Central Registration and Information on Economic Activity with NIP: 9111703689 and in the Central Register of Tourism Organisers and Entrepreneurs Facilitating the Acquisition of Related Travel Services (hereinafter: “CEOTiPUNPUT”) under registration number: 42161 (hereinafter: “NADWIL Wilgosz Adrian”)

concerns matters related to the protection of personal data and other information and materials (hereinafter: “Data”) made available by you to NADWIL Wilgosz Adrian via the website available at www.ondatravel.pl and via the online shop operated within that website, for which NADWIL Wilgosz Adrian is the controller (hereinafter: the “Service”), as well as the method of collecting information contained in cookies in order to gather data related to your use of the Service (hereinafter: “Cookies”).

We would like to assure you that we process your Data with due care and taking into account the obligations arising from the applicable personal data protection laws. At the same time, NADWIL Wilgosz Adrian attaches great importance to protecting your privacy. Moreover, NADWIL Wilgosz Adrian makes every effort, legally, technically and organisationally, to protect the Data received to the greatest possible extent. We apply appropriate organisational, technical and administrative measures to maintain the accuracy and up-to-dateness of the personal data under our control and to protect such personal data against unauthorised or unlawful processing, as well as accidental loss, destruction or damage.

In this Privacy Policy you will find information on how we use information about you that constitutes Data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”). You will also find information about the rights you are entitled to in connection with the processing of your personal data by NADWIL Wilgosz Adrian.

The purpose of this Policy is to inform you about:

  • the manner of collecting and processing the Data obtained through your access to and use of the Service,
  • the purposes for which the Data is processed,
  • your rights, the ways of exercising them and the assistance provided by NADWIL Wilgosz Adrian in exercising them.
  1. Data Controller

The controller of your Data made available by you through the Service is Adrian Wilgosz, conducting business under the name Adrian Wilgosz NADWIL, with its registered address at ul. Artura Grottgera 15, 76-200 Słupsk, entered in CEiDG with NIP: 9111703689 and in CEOTiPUNPUT under registration number: 42161.

e-mail: [email protected], telephone number: 531 919 819

  1. Definitions

All words capitalised in this Policy shall have the meaning assigned to them in the definitions below:

Controllera natural person or legal entity, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data, in accordance with Article 4(7) GDPR
Datadata made available to the Controller, including through the Service by the User, such as first and last name, e-mail address, IP number, telephone number, billing address, shipping address, city, NIP number
Children’s Datapersonal data of persons under 16 years of age
Criminal Datadata referred to in Article 10 GDPR, i.e. data relating to criminal convictions and offences
Special Datadata referred to in Article 9(1) GDPR, i.e. Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, or data concerning health, sex life or sexual orientation
Sensitive DataSpecial Data and Criminal Data
Data Exportthe transfer of Data to a third country or an international organisation
Person

Cookies
a natural person to whom the Data relates, unless otherwise clearly follows from the context
IT data, in particular text files, stored on the user’s end device and intended for use of the Service. They are mainly used to maintain a session. They usually contain the name of the website from which they originate, the storage time on the end device and a unique number
Processoran organisation or person entrusted by the Controller with the processing of Data (including businesses cooperating with the Controller, as well as an IT service provider and outsourced accounting)
Profilingthe use of your Data to evaluate certain of your characteristics, in particular to analyse or predict aspects concerning your personal preferences, including travel preferences and preferences regarding trips/tours available in the Service
Servicethe website available at www.ondatravel.pl and the online shop operated within that website, for which NADWIL Wilgosz Adrian is the controller
Usera natural person who browses the contents of the Service, uses its functionalities, for example by sending messages via the Contact section of the Service, and also makes purchases in the online shop within travel/tour packages available in the Service, thereby making their Data available in the Service
  1. Purposes, legal basis and manner of Data processing
  1. The Controller processes your Data if you have given your consent, pursuant to Article 6(1)(a) GDPR:
  1. to analyse the way you use the Service,
  2. to provide you with tailored information, in particular concerning your travel preferences, the organisation of trips/tours and educational content in the “Travel Blog” section available in the Service,
  3. to assess the effectiveness of the Service,
  4. to create your personality profile (Profiling),
  5. to allow you to receive commercial information,
  6. to save data in Cookies and collect data from websites and mobile applications,
  7. to organise competitions or promotional campaigns in which you may participate.

3.2 The Controller processes your Data necessary for the performance of a contract, pursuant to Article 6(1)(b) GDPR:

  1. to enable you to use the functionalities of the Service necessary for the proper performance by the Controller of the service agreement and to provide you with information about the services offered by the Controller in the Service;
  2. to ensure the technical operation of the Service and to protect your Data against theft, loss or unauthorised access,
  3. to prepare and respond to enquiries or other submissions directed to the Controller, in particular those related to obtaining information about trips/tours and available places on such trips/tours.

3.3 The Controller processes your Data when necessary to comply with a legal obligation incumbent on the Controller, pursuant to Article 6(1)(c) GDPR:

  1. to carry out accounting settlements related to orders for services placed by you within the services available in the Service,
  2. to handle requests and proceedings conducted by authorised bodies, e.g. courts, prosecutors’ offices, law enforcement bodies, offices, which may concern User data.
  3. The Controller processes your Data on the basis of a legitimate interest, pursuant to Article 6(1)(f) GDPR:
  1. for analytical purposes (better matching of services to your needs, general optimisation of the Controller’s services, optimisation of service processes, building knowledge about Service Users),
  2. for archival (evidential) purposes in order to secure information in the event of a legal need to demonstrate facts,
  3. for the possible establishment, pursuit or defence of claims,
  4. to examine your satisfaction and level of satisfaction with the Service and to determine the quality of the Service,
  5. to offer you services directly (direct marketing) in the field of organising trips/tours, including matching them to your needs, i.e. Profiling;
  6. to prepare and respond to enquiries or other submissions directed to the Controller.
  1. In the cases specified above, you have the right at any time to withdraw your consent to the processing of your Data, but withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
  2. Providing the Data specified above is voluntary.
  3. Your Data, due to the need to ensure proper organisation, e.g. in terms of IT infrastructure or ongoing matters concerning our business, as well as the exercise of your rights, may be transferred to the following categories of recipients:
  1. entities cooperating with the Controller in the performance of services available in the Service,
  2. sanitary authorities, fire services, police and other services authorised to supervise the Controller’s activity and to control our activities;
  3. providers supplying the Controller with technical and organisational solutions enabling the provision of our services and the management of our organisation, in particular ICT service providers,
  4. providers supporting the Controller in the marketing area, in particular entities carrying out SMS and e-mail communications,
  5. providers of legal and advisory services, in particular law firms and accounting offices.
  1. Personal data processed by the Controller, including within the Service
  1. If you decide to use the Service, you determine the scope of the Data processed.
  2. During your use of the Service, the following Data will be processed by the Controller:
  • Data in the form of your IP number and, if you decide to contact the Controller by sending a message via the Contact section available in the Service, the Controller may also process the Data provided by you in that message, such as your first and last name, e-mail address and information contained by you in the message to the Controller,
  • Data in the form of your IP number, first and last name, city, e-mail address and telephone number if you decide to purchase the Controller’s service online,
  • Data in the form of your IP number, first name and e-mail address if you wish to use our promotions available in the Service.
  1. As a rule, we do not aim to collect Sensitive Data and Special Data or Children’s Data; however, in certain situations obtaining such Data may prove necessary. We will make every effort to obtain explicit consent for the processing of such Data and will treat it in a manner that ensures its security.
  2. If a person is under 16 years of age, they should read this Privacy Policy together with their parent or guardian so that both persons understand it. If we learn that a person is under 16 years of age and that we have collected information about that person without the consent of their parent or guardian, we will delete such information as soon as possible.
  3. While you are using our website, we make decisions in an automated manner, including Profiling, based on the Data provided. These decisions are made entirely automatically based, for example, on scoring models/statistical analyses.
  4. Automated decision-making for the purposes based on Article 6(1)(a) GDPR, i.e. point 3.1 of this Policy, takes place solely on the basis of the consent granted by you.
  1. Use of the Service
  1. In order to use the Service, you must visit the website: https://ondatravel.pl
  2. If you stop using the Service, your Data will not be stored by the Controller, except that the Controller reserves the right to retain a minimum amount of Data in case it becomes necessary for the Controller to demonstrate that your Data has been deleted (together with the date of deletion), as well as for archival (evidential) purposes in the event of a legal need to demonstrate facts and for the possible establishment, pursuit or defence of claims.
  3. Please note that such changes may not be introduced immediately. We will make every effort to comply with your request as soon as possible.
  1. Data retention period

6.1 The retention period of personal data depends on the specific nature and circumstances (and in particular the purpose) for which the Data was collected. Data will be processed until:

  1. the legitimate interests pursued by the Controller in connection with the processing of specific Data have been fulfilled;
  2. the expiry of limitation periods whose basis is a contract, including in connection with your use of services related to the processing of Data or related to the limitation of the Controller’s legal obligations.
  1. Cookies
  1. The Controller is the entity placing Cookies on your device as a user of the Service and obtaining access to them.
  2. Cookies are used for the purpose of:
  1. adapting the content of the Service to the user’s preferences and optimising the use of websites; in particular, these files make it possible to recognise the Service user’s device and appropriately display the website, tailored to their individual needs;
  2. creating statistics that help understand how Service users use websites, which makes it possible to improve their structure and content.
  1. In many cases, software used for browsing websites (web browser) allows Cookies to be stored on the user’s end device by default. Service users may change Cookie settings at any time. These settings may in particular be changed so as to block the automatic handling of Cookies in the browser settings or to inform about their placement on the user’s device each time. Detailed information about the possibilities and methods of handling Cookies is available in the browser software settings.
  2. The Controller informs you that restricting the use of Cookies may affect some functionalities available on the Service’s websites.
  3. The Controller uses “session” Cookies stored on the user’s device until the website or web browser is turned off, and “persistent” Cookies stored on the user’s device for the time specified in Cookie parameters or until you delete them, as well as Cookies of external entities, i.e. coming for example from the servers of service providers cooperating with the Controller of the Service. These files allow, for example, advertisements and promotions to be adapted to users’ preferences and habits. Information collected on the basis of Cookies may only be read by the Controller and — for technical reasons — Trusted Partners. A list of Trusted Partners is available below.
  4. Within the Service, the following types of Cookies are used, distinguished according to the purpose for which the Controller uses them:

a. necessary — Cookies enabling the use of services available within the Service, e.g. authentication Cookies and Cookies used to ensure security, e.g. used to detect abuse in authentication within the Service;

b. other:

  1. “personalisation” Cookies, enabling the user’s settings to be “remembered” and their interface personalised;
  2. “analytical” Cookies, collecting data and creating statistics that enable the effectiveness of marketing activities to be measured without identifying personal data and improve the functioning of the website, in particular Cookies used to distinguish users and collect information about the number of visits and the date of the user’s last and first visit;
  3. “marketing” Cookies, enabling users to receive advertising content tailored to their interests, without identifying personal data, including in particular Cookies used to re-engage visitors who may become customers based on their behaviour on the website and to advertise products from external advertisers.
  1. Cookies adapt and optimise the Service and its services to users’ needs through such activities as creating Service visit statistics and ensuring the security of the Service. We apply appropriate organisational, technical and administrative measures to maintain the accuracy and timeliness of personal data under our control and to protect such personal data against unauthorised or unlawful processing, as well as accidental loss, destruction or damage.
  2. Cookies are also necessary to maintain the user’s session after leaving the website; they enable the user to return to a form without losing its parameters, which would otherwise require filling it in again.
  1. Your rights
  1. You have the right to contact the Controller in order to obtain comprehensive information about the way your Data is used. The Controller clearly informs you about the Data collected, how it is used, the purposes it serves and to whom it is transferred, what protection is ensured when transferring it to other entities, and also provides information about the institutions to contact in case of doubts, questions and remarks.
  2. Under the GDPR, you are entitled to:
  • the right of access to your Data and to receive a copy thereof;
  • the right to withdraw your consent to the processing of Data at any time;
  • the right to request rectification (correction) of your Data;
  • the right to erase Data or restrict the processing of Data, although restricting or deleting Data may mean that we are unable to provide services to you;
  • the right to object to the processing of Data;
  • the right to Data portability;
  • the right to transmit your data to another controller;
  • the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office.
  1. In accordance with the Cookie policy, you may at any time completely block or delete the collection of Cookies using your web browser.
  2. Blocking the collection of Cookies on your device may hinder or prevent the use of some functionalities of the Service; you are fully entitled to do so, but you should be aware of the resulting limitations of the functionalities available in the Service.
  3. If you do not want to use Cookies for the purpose described in point 7 of this Policy, you may delete them manually at any time. For detailed instructions, visit the website of the manufacturer of your web browser.
  1. Withdrawal of consent to Data processing (objection)
  1. You may at any time withdraw your previously given consent to the processing of your Data without stating a reason. To do so, contact the Controller by e-mail at [email protected]. Your Data will be blocked from further use in the Service. Please note that withdrawal of consent does not affect the lawfulness of any processing carried out by the Controller on the basis of the consent you had previously given.
  2. The Controller will stop processing your Data immediately, including Data for the purposes to which you previously consented, unless the Controller is able to demonstrate that there are compelling legitimate grounds for the Controller in relation to your Data which override your interests, rights and freedoms, or your Data is necessary for the possible establishment, pursuit or defence of claims.
  3. Your use of all or part of the Service may be restricted or impossible after you withdraw your consent to the processing of Data.
  1. Complaint regarding Data processing

10.1 You have the right to lodge a complaint against the Controller’s actions regarding the processing of your Data with the supervisory authority, i.e. the President of the Personal Data Protection Office.

  1. Data recipients
  1. Your Data may be disclosed to Processors being the Controller’s business partners or collaborators.
  2. Our subcontractors (as Processors), accounting firms, law firms and IT companies may also have access to your Data.
  3. Your Data may be transferred by the Controller to a third country after prior notification to you and after meeting the conditions set out in Article 44 GDPR.
  4. The Controller also uses tools offered by Google Ireland Ltd., as well as Meta Platforms Ireland Limited (formerly Facebook Ireland Ltd.) such as Facebook, Instagram, Messenger, Facebook and Instagram social plugins, and TikTok. As these are international entities, they may transfer your Data to a third country on the basis of standard contractual clauses adopted by the European Commission and in accordance with the data processing rules applicable to those entities.

for Facebook https://www.facebook.com/privacy/explanation,

for Google https://policies.google.com/privacy?hl=pl,

for Instagram https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect

for TikTok https://www.tiktok.com/legal/page/eea/privacy-policy/pl

  1. Questions and contact
  1. In order to exercise your rights and/or obtain any relevant information, you should contact the Controller using the form available in the Service in the “Contact” section. The User will be asked to provide identification information such as first and last name, phone number and e-mail address; this is required in order to verify whether the request was sent by you. The Controller will respond to the User’s request within one month of receiving it.
  2. If you request that your Data be updated or deleted from the database, or if you have any questions about this Privacy Policy, you may contact the Controller via e-mail at [email protected].
  3. If you have a complaint regarding the way we handle your personal data, you have the right to contact the supervisory authority in your country of residence.
  4. More information about Cookies is available in the help menu of each web browser and at www.wszystkoociasteczkach.pl. Example web browsers supporting the aforementioned Cookies include Microsoft Edge, Mozilla Firefox, Google Chrome and Opera. More about Cookies can be found at www.wszystkoociasteczkach.pl or in the “Help” section of your browser menu.
  1. Changes to the Privacy Policy
  1. The development of internet technology, legislative changes in the field of Data protection and Cookies, as well as the development of the Service, may result in changes to the Policy. The Controller will promptly inform Users of any changes to the Privacy Policy via the Service and by e-mail.
  2. The Privacy Policy is effective as of 20.10.2024.