Ptivacy policy

§1 General Provisions

  1. The administrator of your data is the Foundation for Education, Health, and Development, based in Sucha Beskidzka at Spółdzielców Street 1, 34-200 Sucha Beskidzka, NIP 552-171-86-13.
  2. You can contact the Administrator via email at hotel@monttis.com.pl, by phone at (33) 87 42 584, or by post at the Administrator’s registered office address.
  3. You can contact the Data Protection Officer designated by the Administrator via email at hotel@monttis.com.pl.
  4. This Privacy Policy defines the rules for the processing and protection of personal data provided:
    1. by users in connection with using the services offered by the website http://monttis.com.pl;
    2. by individuals contacting the Administrator directly via email.
  5. Personal data is processed in accordance with applicable law, including particularly the Regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as “GDPR”, and the Personal Data Protection Act of 10 May 2018 – hereinafter referred to as “the Act”.
  6. The Administrator takes particular care to protect the rights of the individuals whose data is processed, and in particular ensures that the data collected is processed in accordance with the principles of legality, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.
  7. The Administrator guarantees the confidentiality of all personal data provided and ensures that all security and protection measures required by applicable regulations are taken. Personal data is collected with due diligence and appropriately protected from unauthorized access. Personal data is processed exclusively within the territory of the European Union.

§2 Purpose and Legal Basis for Processing Personal Data

  1. Your personal data will be processed:
    1. based on Article 6(1)(a) – your voluntary consent to process personal data;
    2. based on Article 6(1)(b) – for the purposes of providing hotel services, renting a conference room, providing catering services, organizing special events, including confirming reservations, processing payments, issuing invoices, refunding payments, handling complaints, withdrawing from contracts, and contacting you for purposes related to the execution of the contract;
    3. based on Article 6(1)(c) – to fulfill a legal obligation incumbent upon the Administrator, i.e., for tax and accounting purposes and for submitting reports to the Central Statistical Office (GUS) on the use of tourist accommodation facilities;
    4. based on Article 6(1)(f) – for the legitimate interests of the Administrator, to carry out marketing activities, including direct marketing of own services, handling inquiries from you sent via email when they are not directly related to the execution of the contract.
    5. Data will also be processed for the Administrator to assert potential claims, pursue debt recovery, conduct statistical analyses, store data for archival purposes, and ensure accountability, i.e., to demonstrate compliance with regulations regarding the processing of personal data. The data will be stored for the period during which the Administrator is required to keep data or documents containing them to document compliance with legal requirements and to enable public authorities to verify that the requirements are met.
    6. The Administrator also obtains personal data from partners of booking platforms where you have made a reservation: Booking.com, HRS, E-travel, E-holiday, Nocleg.pl, Biznesindex.pl.
    7. The Administrator may share your personal data with service providers responsible for managing IT systems, banks, payment operators, accounting, legal, and audit services, as well as entities or authorities authorized under the law.
    8. The Administrator reserves the right to disclose your personal data to appropriate authorities or third parties if required by applicable laws.
    9. The Administrator does not intend to transfer your data to third countries, i.e., outside the European Economic Area (EEA), or to other international organizations.
  2. Period of Processing Personal Data:
    1. Your personal data processed for handling inquiries made through the contact form or directly to the Administrator’s email address will be processed for the duration of the correspondence, justified by the nature of the inquiry, but no longer than one year from its completion.
    2. Your personal data provided for the purpose of hotel services, conference room rental, catering services, or organizing special events will be processed by the Administrator for the duration of the contract, and also after its completion for the period specified by applicable laws, for the purpose of asserting potential claims.
    3. In the case that the contract is not concluded before payment, the personal data you provided will be immediately deleted by the Administrator. If you make a payment, your personal data will be processed for the period defined by tax and accounting laws. Your personal data provided for issuing an invoice for the services rendered will be processed for the period specified by applicable tax and accounting laws.
    4. Personal data provided by you as part of the expressed consent will be processed until the consent is withdrawn.

§3 Rights of Data Subjects

  1. The rights available to you under the applicable regulations:
    1. the right to access your data,
    2. the right to rectify your data if it is inaccurate or incomplete,
    3. the right to erase your data (“right to be forgotten”) when the data is no longer necessary for the purposes for which it was collected by the Administrator,
    4. the right to restrict the processing of your data if it is inaccurate – you can request the restriction of processing of this data for a period that allows the Administrator to verify its accuracy, or if you object to the processing of the data – until it is determined whether the Administrator’s legally justified grounds take precedence over your objection,
    5. the right to data portability when your data is processed based on your consent or a contract, and the processing is done automatically,
    6. the right to object if your personal data is processed based on a legitimate interest or for statistical purposes, and your objection is justified by a particular situation, or if your data is being processed for direct marketing purposes, including profiling for such purposes,
    7. the right to withdraw consent to the processing of personal data – you can withdraw consent at any time without affecting the lawfulness of the processing carried out based on the consent before its withdrawal.
  2. The above rights can be exercised according to the principles described in the GDPR by contacting the Administrator at: Fundacja Edukacja Zdrowie Rozwój, ul. Spółdzielców 1, 34-200 Sucha Beskidzka, or by email at: hotel@monttis.com.pl.
  3. You also have the right to file a complaint with the Data Protection Office if you believe that the processing of your personal data violates the provisions of the GDPR.
  4. Providing your personal data is:
    1. voluntary in the scope of the consent granted,
    2. voluntary, but necessary for the Administrator to provide the offered services.

§4 Cookies

  1. The service automatically collects only information contained in cookies.
  2. Cookies are text files stored on the user’s end device. They are intended for use with the service’s pages. They mainly contain the name of the website from which they originate, a unique number, and the time they are stored on the end device.
  3. The service operator uses cookies for the following purposes:
    1. to adjust the website content to the individual preferences of the user, primarily these files recognize the user’s device to display the page according to their preferences;
    2. to prepare statistics that help understand users’ preferences and behaviors, the analysis of these statistics is anonymous and allows for adjusting the content and appearance of the service to current trends, and the statistics are also used to assess the popularity of the page;
    3. The service uses two main types of cookies – session and persistent cookies. Session cookies are temporary and are stored until the user leaves the service page (by visiting another page, logging out, or closing the browser). Persistent cookies are stored on the user’s end device until they are deleted by the user or for the time specified by their settings.
  4. The user can change the settings of their browser at any time to block cookies or to receive information every time cookies are placed on their device. Other available options can be checked in the settings of the user’s web browser. It should be noted that most browsers are set by default to accept the saving of cookies on the end device.
  5. The service operator informs that changing the settings in the user’s web browser may limit access to certain features of the service’s website.
  6. The cookies used by the service (placed on the user’s end device) may be made available to its partners and cooperating advertisers.
  7. Information regarding web browser settings can be found in the browser’s menu (help) or on the browser manufacturer’s website.
  8. The Administrator reserves the right to change the privacy policy, which may be caused by the development of internet technologies, changes in data protection laws, and the development of the Service.
  9. The Administrator reserves the right to introduce changes to the Privacy Policy.
Sucha Beskidzka, 25.05.2018.