Privacy Policy
1. General Information
- This policy applies to the website operating at the URL: www.nordic-sauna.szczecin.pl
- The operator of the website and the Administrator of personal data is: Holiday.szczecin.pl & WebWork Media ANNA SZAŁKIEWICZ, ul. Kazimierska 2e lok. 19, 71-043 Szczecin, 8522639834
- Operator’s contact e-mail address: rezerwacje@holiday.szczecin.pl
- The Operator is the Administrator of your personal data with respect to data provided voluntarily on the Website.
- The Website uses personal data for the following purposes:
- Operating a classified ads system
- Preparing, packing, and shipping goods
- Debt collection
- Handling inquiries submitted through the form
- Providing ordered services
- Presenting offers or information
- The Website obtains information about users and their behavior in the following ways:
- Through data voluntarily entered in forms, which is then entered into the Operator’s systems.
- Through storing cookie files on end-user devices.
2. Selected Data Protection Methods Used by the Operator
- Login areas and places where personal data is entered are protected at the transmission layer using an SSL certificate. As a result, personal data and login details entered on the website are encrypted on the user’s computer and can only be read on the target server.
- Personal data stored in the database is encrypted in such a way that only the Operator holding the key can read it. This protects the data in the event that the database is stolen from the server.
- User passwords are stored in hashed form. The hashing function is one-way, meaning it cannot be reversed, which is currently the modern standard for storing user passwords.
- The Operator periodically changes administrative passwords.
- To minimize the risk of unauthorized access to data, the Operator uses complex passwords containing lowercase and uppercase letters, numbers, and special characters, with a minimum length of 8 characters.
- Two-factor authentication is used on the Website, providing an additional form of login protection.
- An important element of data protection is the regular updating of all software used by the Operator to process personal data, which in particular means regular updates of software components.
3. Hosting
- The Website is hosted and technically maintained on the server of the operator: cyberFolks.pl
- To ensure technical reliability, the hosting company keeps server-level logs. The following may be recorded:
- resources identified by URL identifiers, such as addresses of requested resources — pages and files,
- time of the request,
- time of sending the response,
- client station name — identification performed via the HTTP protocol,
- information about errors that occurred during the HTTP transaction,
- URL address of the page previously visited by the user, if the user accessed the Website via a link,
- information about the user’s browser,
- information about the IP address,
- diagnostic information related to the self-service ordering process via website registrars,
- information related to the handling of e-mail correspondence addressed to and sent by the Operator.
4. Your Rights and Additional Information on Data Use
- In certain situations, the Administrator has the right to transfer your personal data to other recipients if this is necessary to perform an agreement concluded with you or to fulfill obligations imposed on the Administrator. This applies to the following groups of recipients:
- postal operators
- law firms and debt collectors
- payment operators
- authorized employees and associates who use the data to fulfill the purpose of the website’s operation
- couriers
- banks
- Your personal data is processed by the Administrator no longer than necessary to perform the related activities specified in separate regulations, such as accounting regulations. With regard to marketing data, the data will not be processed for longer than 3 years.
- You have the right to request from the Administrator:
- access to your personal data,
- rectification of your data,
- deletion of your data,
- restriction of processing,
- and data portability.
- You have the right to object to the processing referred to in point 3.3 c) with regard to the processing of personal data for the purposes of legitimate interests pursued by the Administrator, including profiling. However, the right to object may not be exercised if there are valid legitimate grounds for processing that override your interests, rights, and freedoms, in particular the establishment, pursuit, or defense of claims.
- You have the right to lodge a complaint against the Administrator’s actions with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
- Providing personal data is voluntary but necessary for using the Website.
- Automated decision-making activities, including profiling, may be undertaken in relation to you for the purpose of providing services under the concluded agreement and for the Administrator’s direct marketing purposes.
- Personal data is transferred to third countries within the meaning of personal data protection regulations. This means that we transfer it outside the European Union.
5. Information in Forms
- The Website collects information voluntarily provided by the user, including personal data, if provided.
- The Website may record information about connection parameters, such as timestamp and IP address.
- In some cases, the Website may save information that facilitates linking the data in the form with the e-mail address of the user completing the form. In such cases, the user’s e-mail address appears inside the URL of the page containing the form.
- Data provided in the form is processed for the purpose resulting from the function of the specific form, for example to handle a service request, commercial contact, service registration, etc. Each time, the context and description of the form clearly indicate what it is used for.
6. Administrator Logs
- Information about user behavior on the Website may be logged. This data is used to administer the Website.
7. Important Marketing Techniques
- The Operator uses statistical analysis of website traffic through Google Analytics (Google Inc., based in the USA). The Operator does not transfer personal data to the provider of this service, but only anonymized information. The service is based on the use of cookies on the user’s end device. With regard to user preference information collected by the Google advertising network, the user may view and edit information derived from cookies using the tool: https://www.google.com/ads/preferences/
- The Operator uses the Facebook pixel. This technology causes Facebook (Facebook Inc., based in the USA) to know that a person registered with Facebook is using the Website. In this case, Facebook relies on data for which it is itself the administrator. The Operator does not transfer any additional personal data to Facebook. The service is based on the use of cookies on the user’s end device.
- The Operator uses remarketing techniques that allow advertising messages to be tailored to the user’s behavior on the Website. This may create the impression that the user’s personal data is being used to track them, but in practice no personal data is transferred from the Operator to advertising operators. The technological condition for such activities is enabled cookie support.
- The Operator uses a solution that analyzes user behavior by creating heat maps and recording behavior on the Website. This information is anonymized before being sent to the service provider, so the provider does not know which natural person it concerns. In particular, entered passwords and other personal data are not recorded.
- The Operator uses a solution that automates the Website’s operation in relation to users, for example by sending an e-mail to the user after visiting a specific subpage, provided that the user has consented to receiving commercial correspondence from the Operator.
- The Operator may use profiling within the meaning of personal data protection regulations.
8. Information About Cookies
- The Website uses cookies.
- Cookies are IT data, in particular text files, stored on the end device of the Website User and intended for use with the Website’s web pages. Cookies usually contain the name of the website they come from, the time they are stored on the end device, and a unique number.
- The entity placing cookies on the Website User’s end device and accessing them is the Website operator.
- Cookies are used for the following purposes:
- maintaining the Website User’s session after logging in, so that the user does not have to re-enter their login and password on every subpage of the Website;
- fulfilling the purposes specified above in the “Important Marketing Techniques” section;
- The Website uses two basic types of cookies: session cookies and persistent cookies. Session cookies are temporary files stored on the User’s end device until logging out, leaving the website, or closing the software/browser. Persistent cookies are stored on the User’s end device for the time specified in the cookie parameters or until deleted by the User.
- Web browsing software usually allows cookies to be stored on the User’s end device by default. Website Users may change these settings. The web browser allows cookies to be deleted. It is also possible to automatically block cookies. Detailed information on this subject is available in the help section or documentation of the web browser.
- Restrictions on the use of cookies may affect some functionalities available on the Website.
- Cookies placed on the Website User’s end device may also be used by entities cooperating with the Website operator, in particular: Google (Google Inc., based in the USA), Facebook (Facebook Inc., based in the USA), and Twitter (Twitter Inc., based in the USA).
9. Managing Cookies — How to Give and Withdraw Consent in Practice
- If the user does not want to receive cookies, they may change their browser settings. Please note that disabling cookies necessary for authentication, security, and maintaining user preferences may make it difficult, and in extreme cases impossible, to use websites.
- To manage cookie settings, select the web browser you use from the list below and follow the instructions:
- Mobile devices: