Privacy Policy
The Privacy Policy describes the rules for processing information about you, including personal data and cookies.
1. General Information
This policy applies to the website operating at the URL: grandtatry.pl
The website operator and Data Controller is: MONIKA MADEJA, Środkowa 195a, 34-500 Białka Tatrzańska
Contact e-mail address of the operator: recepcja@grandhotel.pl
The Operator is the Controller of your personal data with regard to data voluntarily provided on the website.
The website processes personal data for the following purposes:
- Managing the newsletter
- Conducting online chat conversations
- Handling inquiries via the contact form
- Presenting offers or information
The website collects information about users and their behavior in the following ways:
- Through data voluntarily entered in forms, which are then stored in the Operator’s systems
- Through storing cookies on end-user devices
2. Selected Data Protection Methods Used by the Operator
- Login areas and places where personal data are entered are protected at the transmission layer (SSL certificate). Thanks to this, personal and login data entered on the site are encrypted on the user’s computer and can only be read on the target server.
- Personal data stored in the database are encrypted in such a way that only the Operator holding the key can read them. This protects the data in the event of the database being stolen from the server.
- User passwords are stored in hashed form. The hashing function is one-way – it cannot be reversed, which is the modern standard for storing user passwords.
- The website uses two-factor authentication, providing an additional form of login protection.
- The Operator periodically changes administrative passwords.
- To protect data, the Operator regularly creates backup copies.
- An essential element of data protection is the regular updating of all software used by the Operator to process personal data, including system and programming components.
3. Hosting
The Service is hosted (technically maintained) on the servers of: cyberFolks.pl
In order to ensure technical reliability, the hosting company maintains server-level logs. These logs may include:
- resources identified by URL (addresses of requested resources – pages, files),
- the time the request arrived,
- the time the response was sent,
- the client station name – identified through the HTTP protocol,
- information about errors that occurred during the execution of HTTP transactions,
- the URL of the page previously visited by the user (referer link) – in cases where the transition to the Service occurred via a link,
- information about the user’s browser,
- information about the IP address,
- diagnostic information related to the process of ordering services through forms on the website,
- information related to handling email addressed to the Operator and sent by the Operator.
4. Your Rights and Additional Information on Data Usage
In certain situations, the Administrator has the right to transfer your personal data to other recipients, if it is necessary to perform the contract concluded with you or to fulfill the legal obligations of the Administrator. This applies to the following groups of recipients:
- the hosting company (under a data processing agreement),
- postal operators,
- payment operators,
- online chat solution providers,
- authorized employees and collaborators who use the data to achieve the purposes of the website,
- companies providing marketing services to the Administrator.
Your personal data are processed by the Administrator no longer than necessary to perform activities related to them as defined by specific regulations (e.g., accounting). With regard to marketing data, the data will not be processed for longer than 3 years.
You have the right to request from the Administrator:
- access to your personal data,
- rectification,
- erasure,
- restriction of processing,
- and data portability.
You also have the right to object, as described in point 3.2, to the processing of your personal data for the purposes of legitimate interests pursued by the Administrator, including profiling. However, the right to object cannot be exercised where there are valid, legally justified grounds for processing that override your interests, rights, and freedoms, in particular for the establishment, exercise, or defense of legal claims.
You have the right to lodge a complaint against the Administrator’s actions with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.
Providing personal data is voluntary, but necessary for the operation of the Service.
You may be subject to automated decision-making, including profiling, for the purpose of providing services under the agreement and for the Administrator’s direct marketing purposes.
Personal data are not transferred to third countries within the meaning of data protection regulations. This means we do not transfer them outside the European Union.
5. Information in Forms
The Service collects information provided voluntarily by the user, including personal data, if such are provided.
The Service may store information about connection parameters (time, IP address).
In some cases, the Service may store information that makes it easier to link data in a form to the email address of the user filling out the form. In such cases, the user’s email address appears within the URL of the page containing the form.
Data provided in the form are processed for the purpose arising from the function of the specific form, e.g., handling a service request, commercial contact, service registration, etc. Each time, the context and description of the form clearly inform the user what it is used for.
6. Administrator’s Logs
Information about users’ behavior on the website may be subject to logging. These data are used for administering the Service.
7. Important Marketing Techniques
The Operator uses statistical traffic analysis on the site through Google Analytics (Google Inc., based in the USA). The Operator does not provide personal data to the operator of this service, only anonymized information. The service is based on the use of cookies stored on the user’s device.
With regard to information about user preferences collected by the Google advertising network, the user can view and edit information derived from cookies using this tool:
👉 https://www.google.com/ads/preferences/
The Operator also uses the Facebook Pixel. This technology informs Facebook (Facebook Inc., based in the USA) that a registered user is using the Service. In this case, the service relies on data for which Facebook itself is the controller. The Operator does not provide any additional personal data to Facebook. The service is based on the use of cookies stored on the user’s device.
8. Information on Cookies
The Service uses cookies.
Cookies are IT data, in particular text files, which are stored on the end device of the Service User and are intended for use with the Service’s web pages. Cookies usually contain the name of the website from which they originate, their storage time on the end device, and a unique number.
The entity placing cookies on the Service User’s end device and gaining access to them is the Service Operator.
Cookies are used for the following purposes:
- maintaining the Service User’s session (after logging in), so the user does not have to re-enter login and password on every subpage,
- implementing the purposes described above in the section “Important Marketing Techniques”.
The Service uses two main types of cookies: “session” cookies and “persistent” cookies.
- Session cookies are temporary files stored on the User’s end device until logout, leaving the website, or closing the browser.
- Persistent cookies remain stored on the User’s end device for the time specified in the cookie parameters or until deleted by the User.
Web browsers usually allow cookies to be stored on the User’s end device by default. Service Users may change these settings. The web browser enables deletion of cookies and may also allow automatic blocking of cookies. Detailed information on this is provided in the browser’s help section or documentation.
Restrictions on the use of cookies may affect some functionalities available on the Service’s websites.
Cookies placed on the User’s device may also be used by entities cooperating with the Service Operator, in particular:
- Google (Google Inc., USA),
- Facebook (Facebook Inc., USA),
- Twitter (Twitter Inc., USA).
9. Managing Cookies – How to Give and Withdraw Consent in Practice
If the user does not wish to receive cookies, they may change their browser settings. Please note that disabling cookies necessary for authentication, security, or maintaining user preferences may hinder, and in extreme cases may prevent, the use of the website.
To manage cookie settings, select your web browser from the list below and follow the instructions:
- Edge
- Internet Explorer
- Chrome
- Safari
- Firefox
- Opera
Mobile devices:
- Android
- Safari (iOS)
- Windows Phone