POLITYKA PRYWATNOŚCI, PLIKÓW COOKIES ORAZ INFORMACJA PRAWNA SERWISU
Square Apartments Gdynia / www.SquareApartmentsGdynia.pl
Niniejsza Polityka prywatności i wykorzystywania plików cookies, dalej: „Polityka”, określa zasady przetwarzania danych osobowych oraz wykorzystywania plików cookies w związku z korzystaniem z serwisu internetowego www.SquareApartmentsGdynia.pl , dalej: „Serwis”.
Polityka została przygotowana z uwzględnieniem obowiązujących przepisów krajowych i unijnych dotyczących ochrony danych osobowych, w szczególności Rozporządzenia Parlamentu Europejskiego i Rady UE 2016/679 z dnia 27 kwietnia 2016 r., dalej: „RODO”.
Właścicielem Serwisu oraz Administratorem danych osobowych jest Stefczyk Finanse S.A. z siedzibą w Gdyni (81-472), przy ul. Legionów 126-128, wpisana do Krajowego Rejestru Sądowego przez Sąd Rejonowy Gdańsk-Północ w Gdańsku, VIII Wydział Gospodarczy Krajowego Rejestru Sądowego, pod numerem KRS 0000677966, NIP 586-227-30-23, REGON 221516706, prowadząca obiekt pod nazwą Square Apartments Gdynia, dalej: „Obiekt”.
Dokument został podzielony na trzy odrębne części, aby użytkownik mógł szybko odnaleźć informacje dotyczące ochrony danych osobowych, plików cookies oraz informacji prawnych związanych z korzystaniem z Serwisu.
Część
Zakres
Część I – RODO
Informacje o administratorze, celach i podstawach przetwarzania danych osobowych, źródłach danych, odbiorcach, transferach, okresach przechowywania, prawach osób oraz dobrowolności podania danych.
Część II – Cookies i podobne technologie
Informacje o plikach cookies, podobnych technologiach, logach technicznych, narzędziach zewnętrznych, mediach społecznościowych oraz zasadach zarządzania zgodami.
Część III – Informacja prawna Serwisu
Informacje o prawach autorskich, korzystaniu z treści Serwisu, linkach do stron trzecich oraz zmianach dokumentu.
Ta część zawiera informacje wymagane przepisami RODO, w szczególności informacje o administratorze, celach i podstawach przetwarzania, kategoriach danych, odbiorcach, transferach poza EOG, okresach przechowywania oraz prawach osób, których dane dotyczą.
Ta część zawiera najważniejsze informacje o przetwarzaniu danych osobowych. Szczegółowe zasady znajdują się w dalszych punktach Polityki.
Obszar
Informacja
Administrator
Administratorem danych osobowych jest Stefczyk Finanse S.A. z siedzibą w Gdyni, ul. Legionów 126-128, 81-472 Gdynia.
Kontakt z IOD
W sprawach dotyczących danych osobowych można skontaktować się z Inspektorem Ochrony Danych: iod@squareapartmentsgdynia.pl albo listownie na adres Administratora.
Główne cele
Obsługa zapytań, rezerwacji i pobytu, sprzedaż voucherów, płatności i rozliczenia, obsługa reklamacji, bezpieczeństwo osób i mienia, nagrywanie rozmów, prowadzenie korespondencji, marketing za zgodą oraz prawidłowe działanie Serwisu.
Podstawy prawne
W zależności od celu: wykonanie umowy, obowiązek prawny, prawnie uzasadniony interes Administratora albo dobrowolna zgoda.
Cookies
Niezbędne cookies służą działaniu Serwisu. Cookies analityczne, marketingowe, remarketingowe, konwersyjne i podobne technologie są stosowane po uzyskaniu zgody, o ile zgoda jest wymagana.
Prawa użytkownika
Przysługuje prawo dostępu do danych, sprostowania, usunięcia, ograniczenia, przenoszenia, sprzeciwu, wycofania zgody oraz skargi do Prezesa UODO.
Część dotycząca RODO opisuje zasady przetwarzania danych osobowych osób korzystających z serwisu internetowego www.SquareApartmentsGdynia.pl, osób kontaktujących się z Obiektem, osób dokonujących rezerwacji lub zakupu vouchera, gości Obiektu, osób objętych monitoringiem wizyjnym, osób kontaktujących się telefonicznie oraz osób korzystających z profili lub funkcji społecznościowych związanych z Obiektem.
Zasady dotyczące plików cookies i podobnych technologii zostały wyodrębnione w Części II dokumentu.
Administratorem Pani/Pana danych osobowych jest Stefczyk Finanse S.A. z siedzibą w Gdyni (81-472), przy ul. Legionów 126-128, wpisana do Krajowego Rejestru Sądowego przez Sąd Rejonowy Gdańsk-Północ w Gdańsku, VIII Wydział Gospodarczy Krajowego Rejestru Sądowego, KRS 0000677966, NIP 586-227-30-23, REGON 221516706, prowadząca obiekt pod nazwą Square Apartments Gdynia.
W sprawach dotyczących ochrony danych osobowych można kontaktować się z Inspektorem Ochrony Danych:
· e-mail: iod@squareapartmentsgdynia.pl;
· adres korespondencyjny: Stefczyk Finanse S.A., ul. Legionów 126-128, 81-472 Gdynia, z dopiskiem „Inspektor Ochrony Danych”.
Dane osobowe pozyskujemy bezpośrednio od Pani/Pana, w szczególności gdy korzysta Pani/Pan z formularza kontaktowego, kontaktuje się telefonicznie, mailowo, listownie lub osobiście, dokonuje rezerwacji, korzysta z usług Obiektu, składa reklamację albo udziela zgody marketingowej.
Dane mogą pochodzić także od innych podmiotów, w szczególności od zewnętrznych portali rezerwacyjnych, operatorów płatności, biur podróży, organizatorów pobytu, kontrahentów, pracodawców lub innych podmiotów dokonujących rezerwacji w Pani/Pana imieniu. W takiej sytuacji źródłem danych jest podmiot, który przekazał dane Administratorowi w związku z rezerwacją, organizacją lub rozliczeniem pobytu.
Jeżeli dane nie zostały pozyskane bezpośrednio od Pani/Pana, informacje wymagane przepisami RODO są przekazywane najpóźniej przy pierwszej komunikacji z Panią/Panem albo w inny sposób zgodny z przepisami, w szczególności poprzez udostępnienie niniejszej Polityki.
Przykładowe dane
Kontakt i zapytania
imię i nazwisko, adres e-mail, numer telefonu, treść wiadomości, dane identyfikujące sprawę, dane techniczne komunikacji.
Rezerwacja i pobyt
imię i nazwisko, dane kontaktowe, numer dokumentu tożsamości, dane rezerwacji, termin pobytu, liczba osób, preferencje pobytu, informacje konieczne do wykonania usługi, dane przekazane w ramach rezerwacji.
Płatności i rozliczenia
dane do faktury, dane transakcyjne, status płatności, identyfikator transakcji, ewentualnie zamaskowane dane karty płatniczej udostępnione przez operatora płatności lub portal rezerwacyjny.
Reklamacje i roszczenia
dane identyfikacyjne, kontaktowe, dane rezerwacji lub pobytu, treść reklamacji lub zgłoszenia, dokumentacja sprawy, historia korespondencji.
Rozmowy telefoniczne
głos, treść rozmowy, numer telefonu, data i godzina połączenia, dane przekazane podczas rozmowy.
Monitoring wizyjny
wizerunek, data, godzina i miejsce utrwalenia obrazu w obszarze objętym monitoringiem.
Serwis i cookies
adres IP, identyfikatory cookies, dane o urządzeniu, przeglądarce, systemie operacyjnym, aktywności w Serwisie, źródle wejścia na stronę i zdarzeniach konwersji.
Marketing
imię i nazwisko, adres e-mail, numer telefonu, informacja o zgodzie, historia zgód i sprzeciwów, dane dotyczące preferencji, jeżeli wynikają z udzielonej zgody lub ustawień cookies.
Administrator nie wymaga przekazywania danych szczególnych kategorii, np. danych o zdrowiu, chyba że jest to niezbędne w konkretnej sytuacji, np. do obsługi szczególnego zgłoszenia gościa. Jeżeli takie dane zostaną przekazane z własnej inicjatywy, będą przetwarzane wyłącznie w zakresie niezbędnym do obsługi sprawy albo dochodzenia lub obrony roszczeń, zgodnie z właściwą podstawą prawną.
Poniższa tabela przedstawia główne cele przetwarzania danych, podstawy prawne oraz podstawowe okresy przechowywania danych. Okresy mogą zostać wydłużone, jeżeli wymagają tego przepisy prawa, toczy się postępowanie albo dane są potrzebne do ustalenia, dochodzenia lub obrony roszczeń.
Cel przetwarzania
Kategorie danych
Podstawa prawna
Okres przechowywania
Obsługa zapytań przed rezerwacją lub bez związku z rezerwacją.
Dane kontaktowe, treść zapytania, historia korespondencji.
art. 6 ust. 1 lit. f RODO – prawnie uzasadniony interes polegający na prowadzeniu komunikacji i udzielaniu odpowiedzi.
Przez czas niezbędny do udzielenia odpowiedzi i zakończenia sprawy, a następnie przez okres potrzebny do obrony przed roszczeniami.
Podjęcie działań przed zawarciem umowy, dokonanie rezerwacji, zawarcie i wykonanie umowy zakwaterowania oraz sprzedaż vouchera.
Dane identyfikacyjne, kontaktowe, dane rezerwacji, pobytu, płatności i preferencji usługi.
art. 6 ust. 1 lit. b RODO – wykonanie umowy albo działania przed zawarciem umowy.
Przez czas realizacji rezerwacji, pobytu lub vouchera, a po zakończeniu przez okres przedawnienia roszczeń.
Obsługa rezerwacji dokonanej przez zewnętrzny portal rezerwacyjny, biuro podróży, organizatora pobytu lub inny podmiot.
Dane przekazane przez portal lub organizatora, w szczególności dane kontaktowe, dane rezerwacji, pobytu, płatności i rozliczeń.
art. 6 ust. 1 lit. b RODO – wykonanie usługi wobec gościa; art. 6 ust. 1 lit. f RODO – rozliczenia, wymiana informacji z portalem, obsługa zgłoszeń i roszczeń.
Przez czas obsługi rezerwacji i pobytu, rozliczeń z operatorem lub organizatorem, a następnie przez okres przedawnienia roszczeń.
Wystawianie faktur, prowadzenie rozliczeń oraz realizacja obowiązków podatkowych i rachunkowych.
Dane identyfikacyjne, dane do faktury, dane transakcyjne, dokumentacja księgowa.
art. 6 ust. 1 lit. c RODO – obowiązek prawny Administratora.
Przez okres wymagany przepisami podatkowymi i rachunkowymi, co do zasady 5 lat licząc od końca roku, w którym upłynął termin płatności podatku, chyba że przepisy wymagają dłuższego okresu.
Obsługa płatności, zwrotów i potwierdzeń transakcji.
Dane transakcyjne, status płatności, identyfikator transakcji, ewentualnie zamaskowane dane karty.
art. 6 ust. 1 lit. b RODO – wykonanie umowy; art. 6 ust. 1 lit. f RODO – prawidłowe rozliczenie i bezpieczeństwo transakcji.
Przez czas obsługi płatności, rozliczeń i ewentualnych zwrotów, a następnie przez okres przedawnienia roszczeń lub wymagany przepisami prawa.
Obsługa reklamacji, skarg, wniosków i zgłoszeń związanych z rezerwacją, pobytem lub usługą.
Dane identyfikacyjne, kontaktowe, dane rezerwacji, treść zgłoszenia, dokumentacja sprawy.
art. 6 ust. 1 lit. b RODO – obsługa sprawy związanej z umową; art. 6 ust. 1 lit. f RODO – dokumentowanie sprawy i obrona przed roszczeniami.
Przez czas obsługi sprawy, a następnie przez okres przedawnienia roszczeń albo do zakończenia postępowania.
Ustalenie, dochodzenie lub obrona przed roszczeniami oraz działania windykacyjne.
Dane potrzebne do wykazania przebiegu sprawy, rezerwacji, pobytu, płatności, korespondencji lub szkody.
art. 6 ust. 1 lit. f RODO – prawnie uzasadniony interes Administratora.
Przez okres przedawnienia roszczeń wynikający z przepisów prawa albo do prawomocnego zakończenia postępowania.
Nagrywanie rozmów telefonicznych w celu obsługi zgłoszeń, rezerwacji, reklamacji, kontroli jakości i dokumentowania ustaleń.
Głos, treść rozmowy, numer telefonu, data i godzina połączenia.
art. 6 ust. 1 lit. f RODO – prawnie uzasadniony interes w zapewnieniu jakości obsługi i zabezpieczeniu dowodów; w zakresie ustaleń umownych także art. 6 ust. 1 lit. b RODO.
Dane są przechowywane przez czas trwania umowy oraz rok po jej zakończeniu, chyba że nagranie stanowi lub może stanowić dowód w sprawie; wtedy do czasu zakończenia postępowania albo ustania potrzeby zabezpieczenia.
Monitoring wizyjny służący bezpieczeństwu osób, ochronie mienia, zapobieganiu naruszeniom porządku i niszczeniu mienia.
Wizerunek, miejsce, data i godzina utrwalenia obrazu.
art. 6 ust. 1 lit. f RODO – prawnie uzasadniony interes w zapewnieniu bezpieczeństwa i ochrony mienia.
Nie dłużej niż 3 miesiące od dnia nagrania, chyba że nagranie stanowi lub może stanowić dowód; wtedy do zakończenia postępowania albo ustania potrzeby zabezpieczenia.
Prowadzenie marketingu bezpośredniego i przesyłanie informacji handlowych drogą elektroniczną.
Dane kontaktowe, informacja o zgodzie, historia zgód, historia sprzeciwów.
art. 6 ust. 1 lit. a RODO – zgoda; wymagana jest również zgoda komunikacyjna, jeżeli wymaga jej Prawo komunikacji elektronicznej.
Do czasu wycofania zgody, wniesienia sprzeciwu, zakończenia celu marketingowego albo ustalenia, że dane nie są już przydatne.
Stosowanie cookies analitycznych, marketingowych, remarketingowych, konwersyjnych i podobnych technologii.
Identyfikatory cookies, adres IP, dane urządzenia, dane o aktywności w Serwisie, źródła wejścia i zdarzenia konwersji.
art. 6 ust. 1 lit. a RODO – zgoda; dodatkowo zgoda na przechowywanie lub dostęp do informacji w urządzeniu końcowym, o ile jest wymagana przez Prawo komunikacji elektronicznej.
Przez okres wynikający z ustawień danego narzędzia albo do czasu wycofania zgody.
Zapewnienie działania, bezpieczeństwa i administracji Serwisu, w tym logi techniczne.
Adres IP, data i godzina, nazwa strony, URL referencyjny, port źródłowy, ilość danych, przeglądarka, system operacyjny.
art. 6 ust. 1 lit. f RODO – prawnie uzasadniony interes w zapewnieniu bezpieczeństwa, stabilności i rozliczalności działania Serwisu.
Do 12 miesięcy, chyba że logi są potrzebne do wyjaśnienia incydentu, zabezpieczenia dowodu lub dochodzenia roszczeń.
Obsługa profili w mediach społecznościowych oraz interakcji z użytkownikami.
Identyfikator profilu, imię i nazwisko lub nazwa użytkownika, treść komentarzy i wiadomości, reakcje, dane statystyczne udostępnione przez platformę.
art. 6 ust. 1 lit. f RODO – komunikacja, promocja Obiektu i ochrona praw; w zakresie dobrowolnych zgód – art. 6 ust. 1 lit. a RODO.
Przez czas dostępności danych na platformie albo do czasu usunięcia interakcji, wniesienia skutecznego sprzeciwu lub zakończenia sprawy.
W zakresie, w jakim podstawą przetwarzania Pani/Pana danych osobowych jest zgoda, w tym zgoda na otrzymywanie informacji handlowych i marketingowych drogą elektroniczną, ma Pani/Pan prawo wycofać zgodę w dowolnym momencie. Wycofanie zgody oznacza zaprzestanie przesyłania takich informacji na przyszłość i nie ma wpływu na zgodność z prawem przetwarzania, którego dokonano na podstawie zgody przed jej wycofaniem.
Jeżeli rezerwacja została dokonana za pośrednictwem zewnętrznego portalu rezerwacyjnego, biura podróży, organizatora pobytu, pracodawcy lub innego podmiotu, dane osobowe są przetwarzane w celu obsługi rezerwacji, realizacji pobytu, kontaktu z gościem, dokonania rozliczeń, obsługi reklamacji oraz dochodzenia lub obrony roszczeń.
Zakres danych zależy od sposobu dokonania rezerwacji i od danych przekazanych Administratorowi. Administrator nie wymaga danych nadmiarowych. Jeżeli portal lub operator płatności przetwarza dane jako odrębny administrator, zasady tego przetwarzania określa także polityka prywatności tego podmiotu.
Płatności mogą być obsługiwane przez zewnętrznych operatorów płatności, banki lub portale rezerwacyjne. Co do zasady Administrator otrzymuje dane potrzebne do potwierdzenia i rozliczenia płatności, takie jak status płatności, identyfikator transakcji, kwota, data płatności oraz ewentualnie zamaskowane dane karty płatniczej, jeżeli są udostępniane przez operatora lub portal.
Pełne dane karty płatniczej powinny być przetwarzane wyłącznie przez uprawnionego operatora płatności lub portal rezerwacyjny, jeżeli taki model obsługi płatności jest stosowany. Administrator nie powinien samodzielnie utrwalać pełnych danych karty płatniczej poza bezpiecznymi rozwiązaniami dostawców płatności.
Rozmowy telefoniczne mogą być nagrywane w celu zapewnienia prawidłowej obsługi zgłoszeń, rezerwacji, reklamacji i ustaleń związanych z pobytem, podnoszenia jakości obsługi, dokumentowania przebiegu rozmowy oraz ustalenia, dochodzenia lub obrony przed roszczeniami.
Przed rozpoczęciem rozmowy albo na jej początku osoba dzwoniąca otrzymuje informację o nagrywaniu. Kontynuowanie rozmowy po uzyskaniu informacji oznacza przyjęcie do wiadomości, że rozmowa jest rejestrowana. Jeżeli nie chce Pani/Pan, aby rozmowa była nagrywana, można przerwać połączenie i skorzystać z innego kanału kontaktu, np. e-mail, formularz kontaktowy, kontakt listowny albo osobisty.
Na terenie Obiektu lub w jego obrębie może być stosowany monitoring wizyjny. Monitoring służy bezpieczeństwu gości i innych osób, ochronie mienia, zapobieganiu oszustwom, naruszeniom porządku i niszczeniu mienia oraz dochodzeniu lub obronie roszczeń.
Monitoring obejmuje obraz. W Obiekcie funkcjonuje monitoring, przy wejściach do obszarów objętych monitoringiem znajdują się widoczne oznaczenia oraz skrócona informacja o monitoringu. Pełne informacje o monitoringu są udostępnione w odrębnej klauzuli informacyjnej dotyczącej monitoringu wizyjnego Klauzuli informacyjnej - monitoring wizyjny.
Dane osobowe mogą być przetwarzane w celu marketingu bezpośredniego oraz przesyłania informacji handlowych i marketingowych dotyczących Square Apartments Gdynia, w szczególności informacji o ofercie, usługach, promocjach, pakietach pobytowych i aktualnościach.
Przesyłanie informacji handlowych i marketingowych drogą elektroniczną, telefonicznie, SMS, komunikatorem lub przy użyciu innych środków komunikacji elektronicznej odbywa się wyłącznie w zakresie udzielonej zgody oraz zgodnie z właściwymi przepisami dotyczącymi komunikacji elektronicznej. Zgodę można wycofać w każdym czasie.
W przypadku marketingu bezpośredniego przysługuje prawo wniesienia sprzeciwu. Po wniesieniu sprzeciwu dane nie będą dalej przetwarzane w tym celu.
Dane osobowe mogą być przetwarzane przez Administratora oraz osoby działające z jego upoważnienia. Dane mogą być także udostępniane lub powierzane podmiotom wspierającym Administratora w prowadzeniu działalności.
Kategoria odbiorcy
Przykłady
Podmioty przetwarzające dane na zlecenie Administratora
dostawcy IT, hosting, obsługa techniczna Serwisu, dostawcy systemów rezerwacyjnych, dostawcy systemów korespondencji, podmioty świadczące usługi marketingowe, analityczne, archiwizacyjne, techniczne lub ochrony.
Odrębni administratorzy
banki, operatorzy płatności, operatorzy zewnętrznych portali rezerwacyjnych, operatorzy pocztowi i kurierscy, ubezpieczyciele, doradcy prawni lub podatkowi, organy publiczne działające na podstawie przepisów prawa.
Podmioty organizujące pobyt
biura podróży, organizatorzy pobytów grupowych, pracodawcy, kontrahenci lub inne podmioty dokonujące rezerwacji w imieniu gościa.
Podmioty przetwarzające dane na zlecenie Administratora przetwarzają dane na podstawie umów powierzenia przetwarzania danych osobowych i wyłącznie zgodnie z poleceniami Administratora, chyba że przepisy prawa stanowią inaczej.
W związku z korzystaniem z niektórych narzędzi technologicznych, w szczególności dostawców takich jak Meta, Google lub Microsoft, dane osobowe mogą być przekazywane poza Europejski Obszar Gospodarczy albo mogą być dostępne z państw trzecich.
Jeżeli dochodzi do takiego przekazania, Administrator stosuje mechanizmy przewidziane w RODO, w szczególności decyzję Komisji Europejskiej stwierdzającą odpowiedni stopień ochrony, uczestnictwo odbiorcy w odpowiednim programie zapewniającym podstawę transferu, standardowe klauzule umowne zatwierdzone przez Komisję Europejską albo inne zabezpieczenia przewidziane przepisami. Informację o stosowanych zabezpieczeniach można uzyskać kontaktując się z Administratorem lub Inspektorem Ochrony Danych.
Na zasadach określonych w RODO przysługują Pani/Panu następujące prawa:
Prawo
Opis
Dostęp do danych
prawo uzyskania informacji, czy Administrator przetwarza dane, oraz otrzymania kopii danych.
Sprostowanie danych
prawo żądania poprawienia danych nieprawidłowych lub uzupełnienia danych niekompletnych.
Usunięcie danych
prawo żądania usunięcia danych w przypadkach przewidzianych przepisami.
Ograniczenie przetwarzania
prawo żądania ograniczenia przetwarzania danych w określonych sytuacjach.
Przenoszenie danych
prawo otrzymania danych w ustrukturyzowanym formacie i przesłania ich innemu administratorowi, jeżeli przetwarzanie odbywa się na podstawie zgody lub umowy i w sposób zautomatyzowany.
Sprzeciw
prawo sprzeciwu wobec przetwarzania danych na podstawie prawnie uzasadnionego interesu, w tym wobec marketingu bezpośredniego.
Wycofanie zgody
prawo wycofania zgody w każdym czasie, bez wpływu na zgodność z prawem przetwarzania dokonanego przed wycofaniem zgody.
Skarga do organu nadzorczego
prawo wniesienia skargi do Prezesa Urzędu Ochrony Danych Osobowych.
W celu realizacji praw można skontaktować się z Administratorem lub Inspektorem Ochrony Danych. Niektóre prawa nie mają charakteru bezwzględnego i mogą podlegać ograniczeniom wynikającym z RODO lub innych przepisów prawa.
Sytuacja
Znaczenie podania danych
Rezerwacja, pobyt, voucher
Podanie danych jest dobrowolne, ale niezbędne do zawarcia lub wykonania umowy. Brak danych może uniemożliwić rezerwację albo skorzystanie z usługi.
Faktura i rozliczenia
Podanie danych wymaganych do wystawienia faktury lub rozliczeń może wynikać z przepisów prawa. Brak danych może uniemożliwić wystawienie faktury albo prawidłowe rozliczenie.
Kontakt, zapytania, reklamacje
Podanie danych jest dobrowolne, ale niezbędne do udzielenia odpowiedzi lub rozpatrzenia sprawy.
Podanie danych i udzielenie zgody jest dobrowolne. Brak zgody oznacza, że nie będą przesyłane informacje handlowe i marketingowe objęte zgodą.
Cookies wymagające zgody
Udzielenie zgody jest dobrowolne. Brak zgody nie powinien ograniczać dostępu do podstawowych funkcji Serwisu, z wyjątkiem funkcji zależnych od danej technologii.
Wejście do obszaru objętego monitoringiem wiąże się z przetwarzaniem wizerunku w zakresie niezbędnym do wskazanych celów.
Nagrywanie rozmów
Osoba, która nie chce, aby rozmowa była nagrywana, może zakończyć połączenie i skorzystać z innego kanału kontaktu.
Administrator nie podejmuje wobec Pani/Pana decyzji w sposób wyłącznie zautomatyzowany, w tym w oparciu o profilowanie, które wywoływałyby wobec Pani/Pana skutki prawne lub w podobny sposób istotnie na Panią/Pana wpływały.
Narzędzia analityczne, marketingowe lub remarketingowe mogą służyć do tworzenia statystyk, grup odbiorców albo dostosowania reklam, jeżeli użytkownik wyraził zgodę na odpowiednie cookies lub podobne technologie. Nie oznacza to podejmowania wobec użytkownika decyzji w rozumieniu art. 22 RODO.
Administrator stosuje środki organizacyjne i techniczne odpowiednie do charakteru, zakresu, kontekstu i celów przetwarzania danych oraz ryzyka naruszenia praw lub wolności osób, których dane dotyczą. Obejmują one w szczególności kontrolę dostępu, upoważnienia, zabezpieczenia systemów IT, umowy powierzenia z dostawcami oraz procedury reagowania na incydenty.
Ta część opisuje zasady wykorzystywania plików cookies i podobnych technologii w Serwisie. Cookies niezbędne są stosowane w celu dostarczenia usługi żądanej przez użytkownika lub zapewnienia transmisji komunikatu, a pozostałe kategorie cookies i podobnych technologii są stosowane po uzyskaniu zgody, jeżeli zgoda jest wymagana przez Prawo komunikacji elektronicznej i RODO.
Cookies to niewielkie pliki lub informacje zapisywane w urządzeniu użytkownika albo odczytywane z tego urządzenia podczas korzystania z Serwisu. Serwis może wykorzystywać także podobne technologie, takie jak piksele, tagi, identyfikatory internetowe, lokalna pamięć przeglądarki lub narzędzia pomiarowe.
Cookies niezbędne są stosowane w celu zapewnienia działania Serwisu, bezpieczeństwa, utrzymania sesji, obsługi formularzy lub procesu rezerwacji. Pozostałe kategorie cookies, w szczególności analityczne, marketingowe, remarketingowe, konwersyjne i społecznościowe, są stosowane po uzyskaniu zgody, jeżeli zgoda jest wymagana.
Kategoria
Cel
Podstawa / warunek stosowania
Niezbędne
Działanie Serwisu, bezpieczeństwo, utrzymanie sesji, obsługa formularzy i rezerwacji.
Co do zasady nie wymagają zgody na podstawie przepisów o cookies, jeżeli są niezbędne do świadczenia usługi żądanej przez użytkownika. W zakresie danych osobowych: art. 6 ust. 1 lit. f RODO.
Analityczne
Pomiar ruchu, statystyki, analiza sposobu korzystania z Serwisu, poprawa jakości strony.
Zgoda użytkownika, jeżeli narzędzie nie mieści się w kategorii niezbędnej. W zakresie danych osobowych: art. 6 ust. 1 lit. a RODO.
Marketingowe i remarketingowe
Personalizacja reklam, kierowanie reklam, tworzenie grup odbiorców, ponowne docieranie do osób, które odwiedziły Serwis.
Zgoda użytkownika. W zakresie danych osobowych: art. 6 ust. 1 lit. a RODO.
Konwersyjne i śledzące
Pomiar skuteczności kampanii, ustalanie źródła rezerwacji lub zapytania, analiza wydajności kanałów sprzedaży.
Społecznościowe
Obsługa funkcji społecznościowych, integracja z profilami Obiektu, pomiar skuteczności działań w mediach społecznościowych.
Zgoda użytkownika, jeżeli technologia nie jest niezbędna. W zakresie danych osobowych: art. 6 ust. 1 lit. a RODO lub art. 6 ust. 1 lit. f RODO – zależnie od funkcji.
Użytkownik może wyrazić zgodę na wszystkie cookies wymagające zgody, odmówić zgody albo dostosować ustawienia. Zgody można zmienić lub wycofać w każdym czasie w panelu zarządzania zgodami dostępnym w Serwisie. Wycofanie zgody nie wpływa na zgodność z prawem przetwarzania dokonanego przed jej wycofaniem.
Użytkownik może także zarządzać cookies w ustawieniach przeglądarki:
· Edge
· Chrome
· Safari
· Firefox
· Opera
· Android
· Safari (iOS)
· Windows Phone
Ograniczenie lub zablokowanie cookies niezbędnych może spowodować nieprawidłowe działanie Serwisu, w szczególności formularzy, funkcji bezpieczeństwa albo procesu rezerwacji.
Podczas korzystania z Serwisu automatycznie przetwarzane są dane techniczne zapisywane w logach serwera. Mogą one obejmować: datę i godzinę połączenia, nazwę otwieranej strony, adres IP, port źródłowy, adres URL strony odsyłającej, ilość przesłanych danych, informacje o przeglądarce, systemie operacyjnym i urządzeniu.
Logi służą zapewnieniu prawidłowego działania Serwisu, bezpieczeństwa, wykrywaniu błędów, ochronie przed atakami, analizie incydentów oraz dochodzeniu lub obronie roszczeń. Logi mogą zostać udostępnione uprawnionym organom publicznym, jeżeli wynika to z przepisów prawa.
Serwis może korzystać z narzędzi zewnętrznych, w szczególności narzędzi Meta, takich jak Facebook lub Instagram, oraz narzędzi Google lub Microsoft. Narzędzia te mogą służyć prowadzeniu profili społecznościowych, przekierowaniu do profili Obiektu, pomiarowi skuteczności reklam, analizie ruchu w Serwisie, remarketingowi, zabezpieczeniu formularzy, obsłudze korespondencji lub usług IT.
Jeżeli w Serwisie stosowany jest Meta Pixel, Google Analytics, Google Ads, Google Tag Manager, Google Maps, reCAPTCHA, Microsoft Clarity albo inne podobne narzędzie, może dochodzić do przetwarzania takich danych jak adres IP, identyfikatory cookies, informacje o urządzeniu, przeglądarce, źródle wejścia, aktywności w Serwisie oraz zdarzeniach konwersji. Narzędzia niewymagane do działania Serwisu powinny być uruchamiane dopiero po uzyskaniu odpowiedniej zgody użytkownika.
Dostawcy narzędzi zewnętrznych mogą działać jako odrębni administratorzy, podmioty przetwarzające albo – w określonych zakresach – współadministratorzy danych. Szczegółowe zasady przetwarzania przez tych dostawców wynikają z ich własnych zasad prywatności i warunków usług.
Informacje dot. przetwarzania danych osobowych przez Administratora znajdują się w Polityce prywatności użytkowników fanpage w serwisie Facebook oraz profilu Instagram Square Apartments Gdynia.
Ta część zawiera informacje prawne niezwiązane bezpośrednio z obowiązkiem informacyjnym RODO, ale istotne dla korzystania z treści, materiałów i odesłań dostępnych w Serwisie.
Wszelkie treści, informacje i materiały udostępnione w Serwisie, w szczególności teksty, oznaczenia, nazwy, znaki graficzne, zdjęcia, grafiki, filmy, układ strony, elementy identyfikacji wizualnej oraz inne materiały, stanowią własność Administratora albo są wykorzystywane przez Administratora na podstawie właściwych uprawnień, licencji lub przepisów prawa.
Treści i materiały dostępne w Serwisie podlegają ochronie na podstawie przepisów prawa, w szczególności ustawy z dnia 4 lutego 1994 r. o prawie autorskim i prawach pokrewnych, przepisów dotyczących ochrony znaków towarowych, zwalczania nieuczciwej konkurencji oraz innych właściwych przepisów.
Korzystanie z Serwisu nie oznacza nabycia przez użytkownika jakichkolwiek praw własności intelektualnej do treści lub materiałów w nim udostępnionych. Zabronione jest kopiowanie, utrwalanie, rozpowszechnianie, publikowanie, modyfikowanie, przesyłanie, wykorzystywanie komercyjne albo usuwanie oznaczeń praw autorskich lub innych oznaczeń prawnych bez uprzedniej zgody uprawnionego, chyba że takie działanie jest dozwolone na podstawie bezwzględnie obowiązujących przepisów prawa.
Użytkownik może korzystać z treści Serwisu wyłącznie w zakresie własnego użytku osobistego, zwykłego korzystania z Serwisu, zapoznania się z ofertą Obiektu, dokonania rezerwacji lub kontaktu z Administratorem. Wszelkie inne wykorzystanie wymaga uprzedniej zgody Administratora albo innego właściwego uprawnionego.
Serwis może zawierać linki do stron internetowych lub usług innych podmiotów. Strony te działają niezależnie od Administratora i mogą stosować własne zasady prywatności, cookies oraz bezpieczeństwa. Przed skorzystaniem z takich stron zalecamy zapoznanie się z ich dokumentami prywatności.
Polityka może być aktualizowana, w szczególności w razie zmiany przepisów prawa, zmian w Serwisie, zmian narzędzi cookies, zmian dostawców lub sposobów przetwarzania danych. Aktualna wersja Polityki jest publikowana w Serwisie.
Jeżeli zmiana Polityki istotnie wpływa na sposób przetwarzania danych osób, których dane dotyczą, Administrator powinien poinformować o zmianie w odpowiedni sposób, z uwzględnieniem charakteru relacji z daną osobą i kanału komunikacji.
Polityka obowiązuje od dnia jej publikacji w Serwisie. Data ostatniej aktualizacji: 26 maja 2026 r.
PRIVACY POLICY, COOKIE POLICY, AND LEGAL NOTICE FOR THE WEBSITE
This Privacy and Cookie Policy, hereinafter referred to as the “Policy,” sets forth the rules for the processing of personal data and the use of cookies in connection with the use of the website www.SquareApartmentsGdynia.pl, hereinafter referred to as the “Website.”
This policy was prepared in accordance with applicable national and EU regulations on the protection of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, hereinafter referred to as “GDPR.”
The owner of the Website and the controller of personal data is Stefczyk Finanse S.A., with its registered office in Gdynia (81-472), at ul. Legionów 126-128, entered in the National Court Register by the Gdańsk-Północ District Court in Gdańsk, 8th Commercial Division of the National Court Register, under KRS number 0000677966, Tax ID (NIP) 586-227-30-23, REGON 221516706, operating the facility under the name Square Apartments Gdynia, hereinafter referred to as the “Facility.”
Document Structure
The document has been divided into three separate sections so that users can quickly find information regarding the protection
of personal data, cookies, and legal information related to the use of the Website.
Part
Scope
Part ! – GDPR
Information about the controller, the purposes and legal bases for processing personal data, data sources, recipients, transfers, retention periods, data subjects’ rights, and the voluntary nature of providing data.
Part II - Cookies and Similar Technologies
Information about cookies, similar technologies, technical logs, third-party tools, social media, and consent management policies.
Part III – Legal Information About the Website
Information about copyright, use of the Website’s content, links to third-party websites, and changes to this document.
PART I. INFORMATION ON THE PROCESSING OF PERSONAL DATA (GDPR)
This section contains the information required by the GDPR, specifically information about the controller, the purposes and legal bases for processing, categories of data, recipients, transfers outside the EEA, retention periods, and the rights of data subjects.
1. Key Information at a Glance
This section contains the most important information about the processing of personal data. Detailed rules are provided in the following sections of the Policy.
Section
Information
Data Controller
The data controller is Stefczyk Finanse S.A., with its registered office in Gdynia, at ul. Legionów 126-128, 81-472 Gdynia.
Contacting the Data Protection Officer
For matters regarding personal data, please contact the Data Protection Officer at iod@squareapartmentsgdynia.pl or by mail at the Administrator’s address.
Main Purposes
Handling inquiries, reservations, and stays; selling vouchers; processing payments and settlements; handling complaints; ensuring the safety of persons and property; recording conversations; conducting correspondence; marketing with consent; and ensuring the proper functioning of the Website.
Legal Basis
Depending on the purpose: performance of a contract, legal obligation, the Controller’s legitimate interest, or voluntary consent.
Essential cookies are necessary for the Website to function. Analytical, marketing, remarketing, and conversion cookies, as well as similar technologies, are used after obtaining consent, if consent is required.
User Rights
You have the right to access your data, to have it corrected, deleted, or restricted, to data portability, to object, to withdraw your consent, and to file a complaint with the President of the Personal Data Protection Office (UODO).
2. Scope of the GDPR Section
The GDPR section describes the rules governing the processing of personal data of individuals who use the website www. SquareApartmentsGdynia.pl, individuals who contact the Facility, individuals making reservations or purchasing vouchers, guests of the Facility, individuals subject to video surveillance, individuals contacting the Facility by phone, and individuals using social media profiles or features related to the Facility.
The rules regarding cookies and similar technologies are set forth in Part II of this document.
3. Data Controller and Contact Information for the Data Protection Officer
The controller of your personal data is Stefczyk Finanse S.A., with its registered office in Gdynia (81-472), at ul. Legionów 126-128, entered in the National Court Register by the Gdańsk-Północ District Court in Gdańsk, 8th Commercial Division of the National Court Register, KRS 0000677966, NIP 586-227-30-23, REGON 221516706, operating the facility under the name Square Apartments Gdynia
For matters related to the protection of personal data, please contact the Data Protection Officer:
• email: iod@squareapartmentsgdynia.pl;
• mailing address: Stefczyk Finanse S.A., ul. Legionów 126-128, 81-472 Gdynia, marked “Data Protection Officer.”
4. Sources of Data Collection
We collect personal data directly from you, particularly when you use the contact form, contact us by phone, email, mail, or in person, make a reservation, use the Facility’s services, file a complaint, or provide marketing consent.
Data may also come from other entities, in particular from third-party booking portals, payment processors, travel agencies, trip organizers, business partners, employers, or other entities making reservations on your behalf. In such cases, the source of the data is the entity that provided the data to the Controller in connection with the reservation, organization, or settlement of your stay.
If the data was not collected directly from you, the information required by the GDPR will be provided no later than at the time of our first communication with you or by other means in accordance with the regulations, in particular by making this Policy available to you.
5. Categories of Personal Data
Category
Sample Data
Contact and Inquiries
First and last name, email address, phone number, message content, information identifying the matter, technical communication data.
Reservation and Stay
first and last name, contact information, ID number, reservation details, dates of stay, number of guests, stay preferences, information necessary to provide the service, data provided as part of the reservation.
Payments and Billing
invoicing information, transaction details, payment status, transaction ID, and, where applicable, masked payment card information provided by the payment processor or booking platform.
Complaints and Claims
identification and contact information, reservation or stay details, the content of the complaint or report, case documentation, and correspondence history.
Phone Calls
voice, content of the call, phone number, date and time of the call, and information provided during the call.
Video surveillance
image, date, time, and location of the recording within the monitored area.
Website and Cookies
IP address, cookie identifiers, data about the device, browser, operating system, activity on the Website, referral source, and conversion events.
first and last name, email address, phone number, consent information, history of consents and objections, and preference data, if derived from consent or cookie settings.
The administrator does not require the provision of special categories of data, such as health data, unless it is necessary in a specific situation, such as to handle a specific guest request. If such data is provided voluntarily, it will be processed only to the extent necessary to handle the matter or to assert or defend claims, in accordance with the applicable legal basis.
6. Purposes, Legal Bases, and Data Retention Periods
The table below outlines the main purposes of data processing, the legal bases, and the standard data retention periods. These periods may be extended if required by law, if legal proceedings are pending, or if the data is needed to establish, assert, or defend legal claims.
Purpose of Processing
Data Categories
Retention period
Handling inquiries prior to a reservation or unrelated to a reservation.
Contact information, inquiry content, correspondence history.
Article 6(1)(f) of the GDPR – legitimate interest in communicating and responding
For the time necessary to respond and resolve the matter, and thereafter for the period required to defend against claims.
Taking actions prior to entering into a contract, making a reservation, entering into and performing an accommodation contract, and selling a voucher.
Identification information, contact information, reservation details, stay details, payment information, and service preferences.
Article 6(1)(b) of the GDPR – performance of a contract or taking steps prior to entering into a contract.
For the duration of the reservation, stay, or voucher, and thereafter for the statute of limitations period for claims.
Processing reservations made through an external booking portal, travel agency, tour operator, or other entity.
Data provided by the portal or the organizer, in particular contact information, reservation details, stay details, payment details, and billing information.
Article 6(1)(b) of the GDPR – providing services to guests; Article 6(1)(f) of the GDPR – billing, exchanging information with the portal, and handling inquiries and claims.
For the duration of handling the reservation and stay, and settling accounts with the operator or organizer, and thereafter for the statute of limitations period for claims.
Issuing invoices, managing settlements, and fulfilling tax and accounting obligations.
Identification data, billing information, transaction data, and accounting records.
Article 6(1)(c) of the GDPR – the Controller’s legal obligation.
For the period required by tax and accounting regulations, generally 5 years from the end of the year in which the tax payment deadline expired, unless the regulations require a longer period.
Processing payments, refunds, and transaction confirmations.
Transaction data, payment status, transaction ID, and, where applicable, masked card details.
Article 6(1)(b) of the GDPR – performance of a contract; Article 6(1)(f) of the GDPR – proper settlement and security of transactions.
For the duration of processing payments, settlements, and any refunds, and thereafter for the statute of limitations period for claims or as required by law.
Handling complaints, grievances, requests, and inquiries related to reservations, stays, or services.
Identification and contact information, reservation details, the content of the report, and case documentation.
Article 6(1)(b) of the GDPR – processing related to a contract; Article 6(1)(f) of the GDPR – documenting the matter and defending against claims.
For the duration of handling the matter, and thereafter for the statute of limitations period for claims or until the conclusion of the proceedings.
Establishing, pursuing, or defending against claims, as well as debt collection activities.
Data needed to document the course of the case, reservations, stay, payments, correspondence, or damage.
Article 6(1)(f) of the GDPR – the Controller’s legitimate interest.
For the duration of the statute of limitations on claims under applicable law or until the proceedings are finally concluded.
Recording telephone conversations for the purpose of handling inquiries, reservations, complaints, quality control, and documenting agreements.
Voice recording, conversation content, phone number, and date and time of the call.
Article 6(1)(f) of the GDPR – legitimate interest in ensuring the quality of service and securing evidence; with regard to contractual arrangements, also Article 6(1)(b) of the GDPR.
Data is retained for the duration of the contract and for one year after its termination, unless the recording constitutes or may constitute evidence in a case; in that case, until the proceedings are concluded or the need for preservation ceases.
Video surveillance for the purpose of ensuring personal safety, protecting property, and preventing disturbances of public order and damage to property.
Image, location, date, and time the image was captured.
Article 6(1)(f) of the GDPR – legitimate interest in ensuring safety and protecting property.
No longer than 3 months from the date of the recording, unless the recording constitutes or may constitute evidence; in that case, until the conclusion of the proceedings or until the need for preservation ceases.
Conducting direct marketing and sending commercial information electronically.
Contact information, consent information, consent history, and objection history.
Article 6(1)(a) of the GDPR – consent; communication consent is also required if required by the Electronic Communications Act.
Until consent is withdrawn, an objection is filed, the marketing purpose is fulfilled, or it is determined that the data is no longer useful.
The use of analytical, marketing, remarketing, and conversion cookies, as well as similar technologies.
Cookie identifiers, IP address, device data, data on activity on the Website, referral sources, and conversion events.
Article 6(1)(a) of the GDPR – consent; additionally, consent to the storage of or access to information on an end device, to the extent required by the Electronic Communications Act.
For the period specified by the settings of the relevant tool, or until consent is withdrawn.
Ensuring the operation, security, and administration of the Website, including technical logs.
IP address, date and time, page name, referrer URL, source port, data volume, browser, operating system.
Article 6(1)(f) of the GDPR – legitimate interest in ensuring the security, stability, and accountability of the Website’s operation.
Up to 12 months, unless the logs are needed to clarify an incident, preserve evidence, or pursue claims.
Managing social media profiles and interacting with users.
Profile ID, first and last name or username, content of comments and messages, reactions, statistics provided by the platform.
Article 6(1)(f) of the GDPR – communication, promotion of the Facility, and protection of rights; with regard to voluntary consents – Article 6(1)(a) of the GDPR.
For as long as the data is available on the platform, or until the interaction is deleted, a valid objection is filed, or the matter is resolved.
To the extent that the basis for the processing of your personal data is consent—including consent to receive commercial and marketing information electronically—you have the right to withdraw your consent at any time. Withdrawal of consent means that such information will no longer be sent to you in the future and does not affect the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.
7. Reservations Made Through Third-Party Portals and Travel Organizers
If a reservation was made through a third-party booking portal, a travel agency, a travel organizer, an employer, or another entity, personal data is processed for the purposes of managing the reservation, facilitating the stay, contacting the guest, processing payments, handling complaints, and asserting or defending claims.
The scope of data depends on the method of booking and the information provided to the Controller. The Controller does not require any excess data. If the portal or payment processor processes data as a separate controller, the rules governing such processing are also set forth in that entity’s privacy policy.
8. Payments and Payment Card Data
Payments may be processed by third-party payment providers, banks, or booking platforms. As a general rule, the Controller receives the data necessary to confirm and settle payments, such as payment status, transaction ID, amount, payment date, and, where applicable, masked payment card data, if provided by the payment provider or platform.
Full payment card details should be processed exclusively by an authorized payment processor or booking portal, if such a payment processing model is used. The administrator should not store full payment card details on their own outside of the secure solutions provided by payment providers.
9. Recording of Phone Calls
Phone calls may be recorded to ensure the proper handling of inquiries, reservations, complaints, and arrangements related to your stay; to improve the quality of service; to document the course of the conversation; and to establish, investigate, or defend against claims.
Before the call begins or at the start of the call, the caller is informed that the call is being recorded. By continuing the call after receiving this information, you acknowledge that the call is being recorded. If you do not wish for the call to be recorded, you may end the call and use another method of contact, such as email, the contact form, mail, or in person.
10. Video Surveillance
Video surveillance may be used on the premises of the Facility or within its boundaries. Surveillance is used to ensure the safety of guests and other individuals, to protect property, to prevent fraud, disturbances, and property damage, and to investigate or defend against claims.
The surveillance system captures video footage. The Facility is equipped with a surveillance system; visible signs and a brief notice regarding the surveillance are posted at the entrances to the monitored areas. Full information about the surveillance system is available in a separate privacy notice regarding video surveillance: Privacy Notice – Video Surveillance .
11. Marketing and Communication Consents
Personal data may be processed for the purposes of direct marketing and sending commercial and marketing information regarding Square Apartments Gdynia, in particular information about offers, services, promotions, stay packages, and news.
The transmission of commercial and marketing information via email, telephone, text message, instant messaging, or other means of electronic communication takes place solely within the scope of the consent provided and in accordance with the applicable regulations governing electronic communications. Consent may be withdrawn at any time.
In the case of direct marketing, you have the right to object. Once you have objected, your data will no longer be processed for this purpose.
12. Recipients of the Data
Personal data may be processed by the Controller and by persons acting on the Controller’s behalf. The data may also be disclosed to or entrusted to entities that assist the Controller in conducting its business.
Recipient Category
Examples
Entities processing data on behalf of the Controller
IT providers, hosting providers, technical support providers for the Website, reservation system providers, correspondence system providers, and entities providing marketing, analytics, archiving, technical, or security services.
Separate data controllers
banks, payment processors, operators of third-party booking portals, postal and courier service providers, insurers, legal or tax advisors, and public authorities acting in accordance with the law.
Entities organizing the stay
travel agencies, group tour operators, employers, business partners, or other entities making reservations on behalf of the guest.
Data processors acting on behalf of the Controller process data pursuant to personal data processing agreements and solely in accordance with the Controller’s instructions, unless otherwise provided by law.
13. Transfer of Data Outside the European Economic Area
Due to the use of certain technological tools, in particular those provided by companies such as Meta, Google, or Microsoft, personal data may be transferred outside the European Economic Area or may be accessible from third countries.
If such a transfer takes place, the Controller applies the mechanisms provided for in the GDPR, in particular a European Commission decision confirming an adequate level of protection, the recipient’s participation in a relevant program providing a basis for the transfer, standard contractual clauses approved by the European Commission, or other safeguards provided for by law. Information about the safeguards in place can be obtained by contacting the Controller or the Data Protection Officer.
14. Rights of Data Subjects
Under the terms of the GDPR, you have the following rights:
Rights
Description
Access to data
the right to obtain information on whether the Controller is processing data and to receive a copy of the data.
Rectification of data
the right to request the correction of inaccurate data or the completion of incomplete data.
Erasure of data
the right to request the erasure of data in cases provided for by law.
Restriction of processing
the right to request that data processing be restricted in certain situations.
Data Portability
the right to receive data in a structured format and to transmit it to another controller, provided that the processing is based on consent or a contract and is carried out by automated means.
Objection
the right to object to the processing of data based on a legitimate interest, including direct marketing.
Withdrawal of Consent
the right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to the withdrawal of consent.
Complaint to the supervisory authority
the right to file a complaint with the President of the Personal Data Protection Office.
To exercise your rights, you may contact the Data Controller or the Data Protection Officer. Some rights are not absolute and may be subject to restrictions under the GDPR or other laws.
15. Voluntary or Mandatory Provision of Data
Situation
Importance of Providing Data
Reservation, Stay, Voucher
Providing data is voluntary but necessary to enter into or perform a contract. Failure to provide data may prevent you from making a reservation or using the service.
Invoices and Billing
Providing the data required to issue an invoice or process billing may be required by law. Failure to provide this data may prevent us from issuing an invoice or processing billing correctly.
Contact, Inquiries, Complaints
Providing your information is voluntary but necessary for us to respond to your inquiry or address your issue.
Providing your data and giving your consent is voluntary. Failure to give consent means that commercial and marketing information covered by the consent will not be sent to you.
Cookies Requiring Consent
Giving consent is voluntary. Failure to give consent should not restrict access to the basic functions of the Website, with the exception of functions that depend on the specific technology.
Video Surveillance
Entering the monitored area involves the processing of your image to the extent necessary for the specified purposes.
Call Recording
If you do not wish to have your call recorded, you may end the call and use another contact method.
16. Automated Decision-Making and Profiling
The controller does not make decisions regarding you in a fully automated manner, including based on profiling, that would produce legal effects on you or similarly significantly affect you.
Analytics, marketing, or remarketing tools may be used to generate statistics, create audience segments, or tailor advertisements, provided the user has consented to the use of the relevant cookies or similar technologies. This does not constitute decision-making regarding the user within the meaning of Article 22 of the GDPR.
17. Data Security
The controller implements organizational and technical measures appropriate to the nature, scope, context, and purposes of the data processing, as well as the risk of infringement of the rights or freedoms of data subjects. These include, in particular, access controls, authorizations, IT system security measures, data processing agreements with vendors, and incident response procedures.
PART II. INFORMATION ABOUT COOKIES AND SIMILAR TECHNOLOGIES
This section describes the rules governing the use of cookies and similar technologies on the Website. Essential cookies are used
to provide the service requested by the user or to ensure the transmission of a message, while other categories of cookies
and similar technologies are used after obtaining consent, if such consent is required by the Electronic Communications Act
and the GDPR.
1. Cookies and Similar Technologies
Cookies are small files or pieces of information stored on the user’s device or read from that device while using the Website. The Website may also use similar technologies, such as pixels, tags, web identifiers, local browser storage, or measurement tools.
Essential cookies are used to ensure the Website functions properly, to maintain security, to maintain sessions, and to support forms or the booking process. Other categories of cookies—in particular, analytics, marketing, remarketing, conversion,
and social media cookies—are used after obtaining consent, if consent is required.
Purpose
Basis / Condition for Use
Essential
Website operation, security, session maintenance, form and reservation processing.
As a general rule, they do not require consent under cookie regulations if they are necessary to provide the service requested by the user. With regard to personal data: Article 6(1)(f) of the GDPR.
Analytics
Traffic measurement, statistics, analysis of website usage, and improvement of website quality.
User consent, if the tool does not fall under the “necessary” category. With regard to personal data: Article 6(1)(a) of the GDPR.
Marketing and Remarketing
Ad personalization, ad targeting, creating audience groups, retargeting visitors to the Website.
User consent. With regard to personal data: Article 6(1)(a) of the GDPR.
Conversion and Tracking
Measuring campaign effectiveness, determining the source of a reservation or inquiry, analyzing the performance of sales channels.
Social Media
Support for social media features, integration with the property’s profiles, and measuring the effectiveness of social media activities.
User consent, if the technology is not essential. With regard to personal data: Article 6(1)(a) of the GDPR or Article 6(1)(f) of the GDPR—depending on the function.
Users may consent to all cookies that require consent, refuse consent, or adjust their settings. Consent may be changed or withdrawn at any time in the consent management panel available on the Website. Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.
Users can also manage cookies in their browser settings:
Restricting or blocking essential cookies may cause the Website to malfunction, particularly with regard to forms, security features, or the booking process.
2. Technical Logs of the Website
When you use the Website, technical data is automatically processed and stored in server logs. This data may include: the date and time of the connection, the name of the page accessed, the IP address, the source port, the URL of the referring page, the amount of data transferred, and information about the browser, operating system, and device.
Logs are used to ensure the proper functioning of the Website, to maintain security, to detect errors, to protect against attacks, to analyze incidents, and to investigate or defend against claims. Logs may be disclosed to authorized public authorities if required by law.
3. Social Media, Meta Pixel, Google, and Other Third-Party Tools
The Website may use third-party tools, in particular Meta tools such as Facebook or Instagram, as well as Google or Microsoft tools. These tools may be used to manage social media profiles, redirect users to the Facility’s profiles, measure ad effectiveness, analyze Website traffic, conduct remarketing, secure forms, handle correspondence, or provide IT services.
If the Website uses Meta Pixel, Google Analytics, Google Ads, Google Tag Manager, Google Maps, reCAPTCHA, Microsoft Clarity, or other similar tools, data such as IP addresses, cookie identifiers, information about the device, browser, referral source, activity on the Website, and conversion events may be processed. Tools that are not required for the Website to function should only be activated after obtaining the user’s appropriate consent.
Third-party tool providers may act as separate data controllers, data processors, or—in certain areas—joint data controllers. The specific rules governing processing by these providers are set forth in their own privacy policies and terms of service.
Information regarding the processing of personal data by the Data Controller can be found in the Privacy Policy for users of the Facebook fan page and the Square Apartments Gdynia Instagram profile.
PART III. LEGAL INFORMATION ABOUT THE WEBSITE
This section contains legal information not directly related to the GDPR’s disclosure requirements, but which is relevant to the use of the content, materials, and links available on the Website.
1. Copyright and Use of the Website’s Content
All content, information, and materials made available on the Website—including, but not limited to, texts, designations, names, logos, photographs, graphics, videos, page layout, visual identity elements, and other materials—are the property of the Administrator or are used by the Administrator pursuant to applicable rights, licenses, or legal provisions.
The content and materials available on the Website are protected under applicable law, in particular the Act of February 4, 1994, on Copyright and Related Rights, regulations concerning trademark protection, the prevention of unfair competition, and other relevant provisions.
Use of the Website does not imply that the user acquires any intellectual property rights to the content or materials made available on it. It is prohibited to copy, record, distribute, publish, modify, transmit, use for commercial purposes, or remove copyright notices or other legal notices without the prior consent of the rights holder, unless such action is permitted under mandatory provisions of law.
Users may use the content of the Website solely for their own personal use, for the ordinary use of the Website, to review the Facility’s offerings, to make a reservation, or to contact the Administrator. Any other use requires the prior consent of the Administrator or another authorized party.
2. Links to Third-Party Sites
The Website may contain links to websites or services provided by other entities. These sites operate independently of the Administrator and may have their own privacy, cookie, and security policies. We recommend that you review their privacy policies before using such sites.
3. Changes to the Policy
This Policy may be updated, in particular in the event of changes to applicable laws, changes to the Website, changes to cookie tools, changes to providers, or changes to data processing methods. The current version of the Policy is published on the Website.
If a change to the Policy significantly affects how the data of data subjects is processed, the Controller should notify the data subjects of the change in an appropriate manner, taking into account the nature of the relationship with the data subject and the communication channel.
4. Effective Date
This Policy is effective as of the date of its publication on the Website. Last updated: May 26, 2026.