Terms and Privacy Policy
PRIVACY POLICY
www.archemielno.plTable of contentsPREAMBLE2§1 Definitions2§2 Data Controller and Data Protection Officer3§3 Data Protection Officer3§4 Purposes of processing your personal data3§4A Processing of personal data for the purpose of responding to your requests/inquiries submitted to us through the contact sources available on the Website, including through our fan pages on social media websites3§4B Processing of data for the purpose of concluding and properly performing an agreement for the provision of hotel services or taking action at your request prior to its conclusion4§5 Joint controllership of personal data in connection with sending commercial information about promotions, offers and events organised by the Joint Controllers, including sending newsletters (direct marketing).6§6 Your rights7§7 Automated decision-making8§8 Security of personal data8§9 Cookie Files8
PREAMBLE The privacy policy of www.archemielno.pl sets out the principles according to which your data will be processed and identifies the entity responsible for its processing – in accordance with generally applicable laws. The privacy policy also specifies the purposes for which your personal data will be processed, the scope of such processing and the rights you have in connection with our processing of your personal data. §1 Definitions The terms used in this document mean:
§2 Data Controller and Data Protection Officer
§4B Processing of data for the purpose of concluding and properly performing an agreement for the provision of hotel services or taking action at your request prior to its conclusion
www.archemielno.plTable of contentsPREAMBLE2§1 Definitions2§2 Data Controller and Data Protection Officer3§3 Data Protection Officer3§4 Purposes of processing your personal data3§4A Processing of personal data for the purpose of responding to your requests/inquiries submitted to us through the contact sources available on the Website, including through our fan pages on social media websites3§4B Processing of data for the purpose of concluding and properly performing an agreement for the provision of hotel services or taking action at your request prior to its conclusion4§5 Joint controllership of personal data in connection with sending commercial information about promotions, offers and events organised by the Joint Controllers, including sending newsletters (direct marketing).6§6 Your rights7§7 Automated decision-making8§8 Security of personal data8§9 Cookie Files8
PREAMBLE The privacy policy of www.archemielno.pl sets out the principles according to which your data will be processed and identifies the entity responsible for its processing – in accordance with generally applicable laws. The privacy policy also specifies the purposes for which your personal data will be processed, the scope of such processing and the rights you have in connection with our processing of your personal data. §1 Definitions The terms used in this document mean:
- Policy – the privacy policy of the website www.archemielno.pl.
- Website – www.archemielno.pl.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 2016 No. 119, p. 1, as amended).
- Personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific factors relating to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; indirectly identified, in particular on the basis of an identifier such as a first and last name, identification number, location data, online identifier or one or more specific factors determining the physical, physiological, genetic, mental, economic, cultural or social identity of a natural person;
- Processing – an operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- Controller – a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
- Joint Controller – at least two controllers jointly determining the purposes and means of processing your personal data.
- Processor – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
- Recipient – a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
§2 Data Controller and Data Protection Officer
- The Controller of your personal data is Arche S.A., with its registered office at 05-520 Konstancin - Jeziorna, ul. Mirkowska 45A, entered in the register of entrepreneurs of the National Court Register by the District Court for the Capital City of Warsaw in Warsaw, XIII Commercial Division of the National Court Register under number: 0000831001, NIP: 8211639335, REGON: 71002127700000, with share capital of PLN 2,982,300.00 – paid in full.
- You may contact the Controller by traditional mail at the Controller’s registered office address indicated above or by e-mail at: rodo@arche.pl.
- The Controller has appointed a Data Protection Officer, whom you may contact in all matters related to the processing of your personal data by us via:
- traditional mail at the Controller’s registered office address indicated in §2(1) of this policy, marked “Data Protection Officer”.
- by e-mail at: rodo@arche.pl.
- Your personal data will be processed by us for the following purposes:
- Responding to your requests/inquiries submitted to us through the contact sources available on the Website, including through our fan pages on social media websites.
- Concluding and properly performing an agreement for the provision of hotel services or taking action at your request prior to its conclusion.
- Sending you commercial information about promotions, offers and events organised by the Joint Controllers, including sending to your email address for the newsletter (direct marketing) – if you consent to such action. This action will be carried out במסגרת joint controllership of personal data – as referred to in §5 of the Policy.
- We will process your personal data in order to respond to your message/inquiry if you decide to contact us through our communication channels available on the Website (including, among others, via the contact form, by email or through our fan pages on social media portals such as Facebook and Instagram).
- The legal basis for our processing of your personal data will be Article 6(1)(f) of the GDPR, i.e. the legitimate interest of the Controller consisting in handling your requests or inquiries submitted to us and responding to them.
- If you submit an inquiry or request to us through our profile on a social media portal:
- Facebook and Instagram – the recipient of your personal data will be Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter: Meta Facebook Platforms).
- https://www.facebook.com/privacy/center/.
- https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect.
- If your data is transferred through fan pages on the above-mentioned social media portals to a location in a third country (outside the European Economic Area), this will take place only with appropriate data security measures in place (standard contractual clauses).
- In addition, the recipients of your personal data may include entities providing the Controller with IT and legal services.
- We will store your personal data for the period necessary to conduct correspondence with you, in particular for the period necessary to respond to your messages/inquiries.
- Providing your personal data is mandatory if you wish to contact us and receive a response to your inquiry or request.
§4B Processing of data for the purpose of concluding and properly performing an agreement for the provision of hotel services or taking action at your request prior to its conclusion
- Your personal data will be processed for the following purposes:
- concluding and properly performing an agreement for the provision of services (hereinafter: the Agreement) or taking action at your request prior to concluding the Agreement.
- fulfilling the legal obligations imposed on the Controller by generally applicable laws.
- pursuing or defending against any claims that may arise during the performance of the Agreement or after its termination.
- ensuring the safety of hotel guests and other persons staying on the premises of Arche Fabryka Samolotów Mielno by means of video surveillance.
- The legal basis for our processing of your personal data will be:
- for the purpose of concluding and properly performing the Agreement or taking action at your request prior to its conclusion – Article 6(1)(b) of the GDPR.
- for the purpose of fulfilling the legal obligations imposed on the Controller by generally applicable laws – Article 6(1)(c) of the GDPR in conjunction with Article 70 of the Act of 29 August 1997 – Tax Ordinance and Article 74 of the Act of 29 September 1994 on Accounting.
- for the purpose of pursuing or defending against any claims that may arise during the performance of the Agreement or after its termination, as well as ensuring the safety of hotel guests and other persons staying on the premises of Arche Fabryka Samolotów Mielno by means of video surveillance – our legitimate interest consisting in pursuing the above-mentioned purposes (i.e. Article 6(1)(f) of the GDPR).
- The recipients of your personal data will be entities providing the Controller with legal, financial and IT services.
- Your personal data will be stored:
- for the purpose of concluding and properly performing the Agreement or taking action at your request prior to its conclusion – for the period necessary to conclude or properly perform it.
- for the purpose of fulfilling the legal obligations imposed on the Controller by generally applicable laws – for no longer than 5 years, calculated from the end of the calendar year in which the basis for calculating the public-law receivable arose.
- for the purpose of pursuing or defending against any claims that may arise during the performance of the Agreement or after its termination – for the period provided for in generally applicable laws, depending on the legal relationship from which the claim will arise.
- for the purpose of ensuring the safety of hotel guests and other persons staying on the premises of Arche Fabryka Samolotów Mielno by means of video surveillance – for a period not exceeding 90 days. However, if the surveillance recording serves as evidence in civil, criminal or misdemeanor proceedings, the video surveillance recordings will be stored until the proceedings in question have been finally concluded.
- Providing the personal data referred to in §4B(1)(a) of the Policy is a condition for concluding the agreement, as without providing it we will not be able to conclude the agreement with you. Providing your remaining personal data is mandatory, as without it we will be unable to fulfill the legal obligations imposed on us and will also be unable to pursue our legitimate interests.
- The Joint Controllers of your personal data will be the following entities, which will process your personal data on the basis of the Joint Controllership Agreement (hereinafter: the Joint Controllers):
- Arche S.A. with its registered office at 05-520 Konstancin - Jeziorna, ul. Mirkowska 45A.
- Lena Grochowska Foundation, with its registered office in Siedlce (postal code: 08 – 110), at ul. Brzeska 134.
- The Joint Controllers are jointly responsible for the protection of your personal data.
- Your point of contact in matters concerning the protection of your personal data is Auraco Sp. z o.o., with its registered office in Warsaw (postal code: 00 – 382), at ul. Solec 81B/73A, which you may contact at the registered office address indicated above or via e-mail at: arche.marketing@auraco.pl.
- The Joint Controllers will process your personal data for the purpose of undertaking marketing activities directed at you by sending personalised commercial information about promotions and current offers of the Joint Controllers’ products and services, as well as information about events concerning the Joint Controllers and activities undertaken by them, to your e-mail address and/or telephone number.
- The legal basis for processing your personal data will be your consent to its processing for the above-mentioned purposes (i.e. Article 6(1)(a) of the GDPR), which you may withdraw at any time – however, withdrawing your consent will not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
- Recipients of your personal data may include intermediaries offering our services or products or supporting our ventures, as well as entities supporting our marketing activities, i.e. providers of systems used to manage marketing databases and entities providing IT and telecommunications services to us. Under no circumstances, however, will your personal data be transferred by the Joint Controllers outside the European Economic Area.
- We will store your personal data until you withdraw your consent to its processing or the purposes of the Joint Controllers for which it was collected cease to apply (e.g. if marketing campaigns are discontinued).
- Providing your personal data is entirely voluntary; however, without it, the Joint Controllers will not be able to send commercial information about promotions and current offers of their products and services to your e-mail address and/or telephone number.
- We will analyse your history of relations with us (e.g. the services you have used) and information obtained through analysis of your interactions with our websites in order to determine your preferences and interests, which will enable us to send personalised commercial information about products, offers and events organised by the Joint Controllers.
- We will not process your personal data for the purpose of automated decision-making.
- In connection with our processing of your personal data, you have the right to:
- Withdraw your consent to the processing of your personal data at any time (where we process your personal data on the basis of your consent.
- Object to the processing of personal data (in the cases specified in Articles 21 and 22 of the GDPR).
- Transfer your personal data – where the legal basis for our processing of your personal data is your consent to its processing, as well as the conclusion and proper performance of the Agreement.
- Access your personal data and receive a copy thereof (Article 15 of the GDPR).
- Rectify inaccurate personal data and complete incomplete data (Article 16 of the GDPR).
- Erase your personal data (the so-called right to be forgotten, in the cases specified in Article 17 of the GDPR).
- Restrict the processing of your personal data (in the cases specified in Article 18 of the GDPR).
- If you determine that we process your personal data in a manner inconsistent with generally applicable laws, you have the right to lodge a complaint with the supervisory authority, which in the territory of the Republic of Poland is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
- The website has a valid certificate issued by a trusted certification authority. This means that information, e.g. passwords or credit card details, is sent securely to this website and cannot be intercepted.
- The IT employee grants users of IT systems authorisation to process personal data in the Administrator’s IT systems immediately after receiving from the user a declaration of maintaining the confidentiality of personal data and the methods of securing it.
- Access to the Administrator’s IT systems used for processing personal data is possible only after entering a unique identifier and password.
- Data encryption is used, in particular for data transmitted via a public network.
- Each person employed or cooperating in the processing of personal data has been authorised to process the data.
- Data processing agreements within the meaning of Article 28 of the GDPR have been concluded with third parties processing data on behalf of the data controller.
- Authorised persons have been trained in the principles of secure personal data processing.
- Responsibility for activities related to personal data security has been defined.
- Persons processing personal data have submitted declarations confirming the confidentiality of personal data and methods of securing personal data.
- The integrity of databases is periodically verified by restoring data contained in backup copies.
- Emergency power backup for servers and workstations has been implemented using UPS systems or a separate power supply network.
- A cookie is a small text file that a website uses to save information on a user’s computer or mobile device when the user visits it.
- Cookies may be installed by the Website and may only be read by it (administrator files). The Website may also use files from external services. In such a case, the data may be read by the cookie owner (e.g. Google).
- Cookies can be divided into persistent cookies (which are stored on the user's computer and are not automatically deleted when the browser is closed; they are stored for a specified period) and session cookies (which are deleted when the browser is closed).
- Cookies store individual information about the configuration of the user's device and the user's preferences (e.g. username, language, etc.). Cookies may also be used to compile anonymous statistics on the use of websites. Thanks to them, it is not necessary to enter the same data again during subsequent visits to the Website or read the cookie notice each time.
- The Website uses the Administrator's cookies and cookies from external services. The number, type and function of cookies used by external services may vary between individual users due to their individual characteristics, e.g. whether they have an account on a social networking service, etc.
- The Website uses four types of cookies:
- necessary;
- statistical/analytical;
- marketing
- other (Unclassified cookies are cookies that we are in the process of classifying together with the providers of individual services; these include, for example, ubtru, ubtrs and ProfitroomToken- www.archemielno.pl).
- The Website uses the following necessary cookies:
- PHPSESSID – this is a cookie used to maintain the user's session state. It is a session cookie.
- test_cookie - Used to check whether the user's browser supports cookies. It is stored for a period of one day.
- The Website uses the following analytical cookies:
- _ga – Registers a unique identifier used to generate statistical data on how the visitor uses the Website. It is stored for a period of two years.
- _ga_# - Used by Google Analytics to collect data on how many times a user has visited the Website, as well as the date of the first and last visit. It is stored for a period of two years.
- _gat - Used by Google Analytics to limit the request rate. It is stored for a period of one day.
- _gid - Registers a unique identifier used to generate statistical data on how the visitor uses the Website. It is stored for a period of one day.
- The Website uses the following marketing cookies:
- _gcl_au - Used by Google AdSense to test the effectiveness of advertisements on websites using its services. It is stored for a period of three months.
- ads/ga-audiences - Used to detect whether a user tends to leave the Website based on cursor movements. The file is stored for the duration of the session on the Website.
- Cookies can be freely managed and deleted. More information can be found in the browser instructions (links displayed below):
- All cookies on the device can be deleted completely or selectively by selecting a specific file. However, please note that this may result in the loss of saved information (e.g. saved login details or website preferences).
- Browser settings can be used to block, completely or selectively, cookies originating from a specific Website. More information on managing cookies from specific websites can be found in the privacy and cookie settings of the selected browser.
- Most modern browsers allow you to prevent cookies from being placed on your device, but in that case it may be necessary to set your preferences again each time you visit the Website. Some services and features may not function properly (e.g. logging in to a profile).
- The processing of data by functional/necessary files (essential for the proper functioning of the Website) is carried out for the purpose of pursuing the legitimate interest of the Administrator, which is to provide the highest-quality content on the Website.
- The processing of data by the remaining files is based on the consent of the Website user.
- The Administrator will transfer personal data to other recipients entrusted with processing personal data on behalf of and for the benefit of the Administrator, e.g. entities responsible for the technical aspects of the Website's operation. In addition, the Administrator will disclose personal data to other recipients where such an obligation arises from legal provisions.
- Data within individual cookies will be stored for a period corresponding to their validity cycle, which has been saved on the user's device. Cookies on the device can be deleted completely or selectively by selecting a specific file.PRIVACY POLICY
www.archemielno.plTable of contentsPREAMBLE2§1 Definitions2§2 Data Administrator and Data Protection Officer3§3 Data Protection Officer3§4 Purposes of processing your personal data3§4A Processing of personal data for the purpose of responding to your requests/inquiries submitted to us through the contact channels available on the Website, including through our fan pages on social media portals3§4B Processing of data for the purpose of concluding and properly performing an agreement for the provision of hotel services or taking steps at your request prior to entering into such agreement4§5 Joint controllership of personal data in connection with sending commercial information about promotions, offers and events organized by the Joint Controllers, including sending newsletters (direct marketing).6§6 Your rights7§7 Automated decision-making8§8 Security of personal data8§9 Cookie files8
PREAMBLEThe privacy policy of www.archemielno.pl sets out the principles according to which your data will be processed and the entity responsible for its processing – in accordance with generally applicable legal provisions. The privacy policy also specifies the purposes for which your personal data will be processed, the scope of processing and the rights to which you are entitled in connection with our processing of your personal data.§1 DefinitionsThe terms used in this document mean: - Policy – the privacy policy of the website www.archemielno.pl.
- Website – www.archemielno.pl.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L of 2016 No. 119, p. 1, as amended).
- Personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or one or more specific factors characteristic of that natural person’s physical, physiological, genetic, mental, economic, cultural or social identity;
- Processing – any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; or combination, restriction, erasure or destruction;
- Controller – a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
- Joint Controller – at least two controllers jointly determining the purposes and means of processing your personal data.
- Processor – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
- Recipient – a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether or not it is a third party. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
§2 Data Controller and Data Protection Officer- The Controller of your personal data is Arche S.A., with its registered office at Arche S.A. with its registered office at 05-520 Konstancin - Jeziorna, ul. Mirkowska 45A entered in the register of entrepreneurs of the National Court Register by the District Court for the capital city of Warsaw in Warsaw, XIII Commercial Division of the National Court Register under number: 0000831001, NIP: 8211639335, REGON: 71002127700000, with a share capital of PLN 2,982,300.00 – paid in full.
- You may contact the Controller by traditional mail at the Controller’s registered office address indicated above or by e-mail at: rodo@arche.pl.
- §3 Data Protection Officer
- The Controller has appointed a Data Protection Officer, whom you may contact in all matters related to our processing of your personal data via:
- traditional mail at the Controller’s registered office address indicated in §2 section 1 of this policy, marked – Data Protection Officer.
- by e-mail at: rodo@arche.pl.
- §4 Purposes of processing your personal data
- We will process your personal data for the following purposes:
- Responding to your requests/inquiries submitted to us through the contact channels available on the Website, including through our fan pages on social media portals.
- Concluding and properly performing an agreement for the provision of hotel services or taking steps at your request prior to entering into such agreement.
- Sending you commercial information about promotions, offers and events organized by the Joint Controllers, including sending a newsletter to your e-mail address (direct marketing) – if you consent to such activity. This activity will be carried out as part of the joint controllership of personal data – as referred to in §5 of the Policy.
- §4A Processing of personal data for the purpose of responding to your requests/inquiries submitted to us through the contact channels available on the Website, including through our fan pages on social media portals
- Your personal data will be processed by us in order to respond appropriately to your message/inquiry if you decide to contact us through our communication channels available on the Website (including, among others, via the contact form, by e-mail or through our fan pages on social media portals such as Facebook and Instagram).
- The legal basis for processing your personal data by us will be Article 6(1)(f) of the GDPR, i.e. the legitimate interest of the Controller consisting in handling your requests or inquiries addressed to us and responding to them.
- If you submit an inquiry or request to us via our profile on a social media portal:
- Facebook and Instagram – the recipient of your personal data will be Meta Platforms Ireland Ltd. 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter: Meta Facebook Platforms).
- More information on the processing of your personal data by the Facebook and Instagram social media portals can be found at the following links:
- https://www.facebook.com/privacy/center/.
- https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect.
- If your data are transferred within the fan pages on the aforementioned social media portals to a location in a third country (outside the European Economic Area), this will take place only with the provision of appropriate data security measures (standard contractual clauses).
- In addition, the recipients of your personal data may include entities providing the Controller with IT and legal services.
- We will store your personal data for the period necessary to conduct correspondence with you, in particular for the period necessary to respond to your messages/inquiries.
- Providing your personal data is mandatory if you wish to contact us and receive a response to your inquiry or request.
§4B Processing of data for the purpose of concluding and properly performing an agreement for the provision of hotel services or taking action at your request prior to its conclusion- Your personal data will be processed for the following purposes:
- concluding and properly performing an agreement for the provision of services (hereinafter: the Agreement) or taking action at your request prior to the conclusion of the Agreement.
- fulfilling the legal obligations imposed on the Controller by generally applicable legal provisions.
- pursuing or defending against possible claims arising in the course of performing the Agreement or after its termination.
- ensuring the safety of hotel guests and other persons present on the premises of Arche Fabryka Samolotów Mielno by means of video surveillance.
- The legal basis for processing your personal data by us will be:
- for the purpose of concluding and properly performing the Agreement or taking action at your request prior to its conclusion – Article 6(1)(b) of the GDPR.
- for the purpose of fulfilling the legal obligations imposed on the Controller by generally applicable legal provisions – Article 6(1)(c) of the GDPR in conjunction with Article 70 of the Act of 29 August 1997 – the Tax Ordinance and Article 74 of the Act of 29 September 1994 on accounting.
- for the purpose of pursuing or defending against possible claims arising in the course of performing the Agreement or after its termination, as well as ensuring the safety of hotel guests and other persons present on the premises of Arche Fabryka Samolotów Mielno by means of video surveillance – our legitimate interest consisting in pursuing the aforementioned purposes (i.e. Article 6(1)(f) of the GDPR).
- The recipients of your personal data will be entities providing the Controller with legal, financial and IT services.
- Your personal data will be stored:
- for the purpose of concluding and properly performing the Agreement or taking action at your request prior to its conclusion – for the period necessary for its conclusion or proper performance.
- for the purpose of fulfilling the legal obligations imposed on the Controller by generally applicable legal provisions – no longer than 5 years, counted from the end of the calendar year in which the basis for calculating the public-law liability arose.
- for the purpose of pursuing or defending against possible claims arising in the course of performing the Agreement or after its termination – for the period stipulated in generally applicable legal provisions, depending on the legal relationship from which the claim will arise.
- for the purpose of ensuring the safety of hotel guests and other persons present on the premises of Arche Fabryka Samolotów Mielno by means of video surveillance – for a period not exceeding 90 days. However, if the surveillance recording serves as evidence in civil, criminal or misdemeanor proceedings, the video surveillance recordings will be stored until the final conclusion of the relevant proceedings.
- Providing the personal data referred to in §4B section 1 point a) of the Policy is a condition for concluding the agreement, since without providing it we will not be able to conclude it with you. Providing your remaining personal data is mandatory, since without it we will be unable to fulfill the legal obligations imposed on us and will also be unable to pursue our legitimate interests.
- §5 Joint controllership of personal data in connection with sending commercial information about promotions, offers and events organized by the Joint Controllers, including sending newsletters (direct marketing).
- The Joint Controllers of your personal data will be the following entities, which will process your personal data on the basis of the Joint Controllership Agreement (hereinafter: the Joint Controllers):
- Arche S.A. with its registered office at 05-520 Konstancin - Jeziorna, ul. Mirkowska 45A
- Lena Grochowska Foundation with its registered office in Siedlce (postal code: 08 – 110), at ul. Brzeska 134.
- We note that the current list of Joint Controllers may change in the future – the current list of Joint Controllers can always be found on the website www.arche.pl.
- The Joint Controllers are jointly responsible for protecting your personal data.
- Your point of contact for matters concerning the protection of your personal data is Auraco Sp. z o.o., with its registered office in Warsaw (postal code: 00 – 382) at ul. Solec 81B/73A, which you may contact at the registered office address indicated above or via email: arche.marketing@auraco.pl.
- The Joint Controllers will process your personal data for the purpose of undertaking marketing activities directed at you by sending to your email address and/or telephone number personalised commercial information about promotions and current offers for the products and services of the Joint Controllers, as well as about events concerning the Joint Controllers and activities undertaken by them.
- The legal basis for processing your personal data will be your consent to its processing for the above-mentioned purposes (i.e. Article 6(1)(a) of the GDPR), which you may withdraw at any time; however, its withdrawal will not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
- The recipients of your personal data may include intermediaries offering our services or products or supporting our ventures, as well as entities supporting our marketing activities, i.e. providers of systems used to manage marketing databases and entities providing IT and telecommunications services to us. Under no circumstances, however, will your personal data be transferred by the Joint Controllers outside the European Economic Area.
- We will store your personal data until you withdraw your consent to its processing or the purposes of the Joint Controllers for which it was collected cease to apply (e.g. if marketing campaigns are discontinued).
- Providing your personal data is entirely voluntary; however, without it, the Joint Controllers will not be able to send commercial information about promotions and current offers for their products and services to your email address and/or telephone number.
- We will analyse your history of relations with us (e.g. the services you have used) and information obtained through analysing your interactions with our websites in order to determine your preferences and interests, which will enable us to send you personalised commercial information about products, offers and events organised by the Joint Controllers.
- We will not process your personal data for the purpose of automated decision-making.
- §6 Your rights
- In connection with our processing of your personal data, you have the right to:
- Withdraw your consent to the processing of your personal data at any time (where we process your personal data on the basis of your consent).
- Object to the processing of personal data (in the cases specified in Articles 21 and 22 of the GDPR).
- Data portability – where the legal basis for our processing of your personal data is your consent to its processing or the conclusion and proper performance of the Agreement.
- Access your personal data and receive a copy thereof (Article 15 of the GDPR).
- Rectify inaccurate personal data and complete incomplete data (Article 16 of the GDPR).
- Erase your personal data (the so-called right to be forgotten, in the cases specified in Article 17 of the GDPR).
- Restrict the processing of your personal data (in the cases specified in Article 18 of the GDPR).
- If you find that we process your personal data in a manner inconsistent with generally applicable laws, you have the right to lodge a complaint with the supervisory authority, which in the territory of the Republic of Poland is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
- §7 Automated decision-makingWe will not process your personal data for the purpose of automated decision-making.§8 Personal data security
- The website has a valid certificate issued by a trusted certification authority. This means that information, passwords or credit card details are sent securely to this website and cannot be intercepted.
- The IT employee grants users of IT systems authorisation to process personal data in the Administrator's IT systems immediately after receiving from the user a declaration concerning the confidentiality of personal data and the methods of securing it.
- Access to the Administrator's IT systems used to process personal data is possible only after entering a unique identifier and password.
- Data encryption is used, in particular for data transmitted via a public network.
- Each person employed or cooperating in the processing of personal data has been authorised to process data.
- Data processing agreements within the meaning of Article 28 of the GDPR have been concluded with third parties processing data on behalf of the data administrator.
- Authorised persons have been trained in the principles of secure personal data processing.
- Responsibility for activities related to personal data security has been defined.
- Persons processing personal data have submitted a declaration concerning the confidentiality of personal data and methods of securing personal data.
- The integrity of databases is verified periodically by restoring data contained in backup copies.
- Emergency power backup for servers and workstations has been introduced using UPS systems or a dedicated power supply network.
- §9 Cookie files
- A cookie is a small text file that a website uses to save information on the user's computer or mobile device when the user accesses it.
- Cookies may be installed by the Website and may be read exclusively by it (administrator cookies). The Website may also use cookies from external services. In that case, the data may be read by the owner of the cookie (e.g. Google).
- Cookies can be divided into persistent cookies (which are saved on the user's computer and are not automatically deleted when the browser is closed, but are stored for a specified period) and session cookies (which are deleted when the browser is closed).
- Cookies store individual information about the configuration of the user’s device and the user’s preferences (e.g. username, language, etc.). Cookies may also be used to compile anonymous statistics on the use of websites. Thanks to them, it is not necessary to re-enter the same data during subsequent visits to the website or read the cookie notice each time.
- The website uses the Administrator’s cookies and cookies of external services. The number, type and function of cookies used by external services may vary between individual users due to their individual characteristics, e.g. whether they have an account on a social networking service, etc.
- The website uses four types of cookies:
- necessary;
- statistical/analytical;
- marketing
- other (Unclassified cookies are cookies that we are in the process of classifying together with the providers of individual services; these include, for example, ubtru, ubtrs and ProfitroomToken- www.archemielno.pl).
- The website uses the following necessary cookies:
- PHPSESSID – this is a cookie used to preserve the user’s session state. It is a session cookie.
- test_cookie - Used to check whether the user’s browser supports cookies. It is stored for one day.
- The website uses the following analytical cookies:
- _ga – Records a unique identifier used to generate statistical data about how the visitor uses the website. It is stored for two years.
- _ga_# - Used by Google Analytics to collect data on how many times the user has visited the website, as well as the dates of the first and last visit. It is stored for two years.
- _gat - Used by Google Analytics to limit the request rate. It is stored for one day.
- _gid - Records a unique identifier used to generate statistical data about how the visitor uses the website. It is stored for one day.
- The website uses the following marketing cookies:
- _gcl_au - Used by Google AdSense to test the effectiveness of advertisements on websites using their services. It is stored for three months.
- ads/ga-audiences - Used to detect whether the user tends to leave the website through cursor movements. The file is stored for the duration of the session on the website.
- Cookies can be freely managed and deleted. More information can be found in the browser instructions (links shown below):
- Google Chrome;
- Mozilla Firefox;
- Microsoft Edge;
- Opera;
- Safari.
- All cookies on the device can be deleted in full or selectively by choosing a specific cookie. However, please note that this may result in the loss of stored information (e.g. saved login details and website preferences).
- Browser settings can be used to block, in full or selectively, cookies originating from a specific website. More information about managing cookies originating from specific websites can be found in the privacy and cookie settings of the selected browser.
- Most modern browsers allow you to prevent cookies from being placed on your device, but in that case you may need to reset your preferences each time you visit the website. Some services and functions may not work properly (e.g. logging in to your profile).
- The processing of data through functional/necessary cookies (essential for the proper functioning of the website) is carried out for the purpose of pursuing the legitimate interest of the Administrator, namely providing the highest quality content on the Website.
- The processing of data through the remaining cookies is based on the consent of the website user.
- The Administrator will transfer personal data to other recipients entrusted with processing personal data on behalf and for the benefit of the Administrator, e.g. entities responsible for the technical functioning of the website. In addition, the Administrator will disclose personal data to other recipients where such obligation arises from legal provisions.
- Data within individual cookies will be stored for a period corresponding to their validity period, which was stored on the user’s device. Cookies on the device can be deleted in full or selectively by choosing a specific cookie.PRIVACY POLICY
www.archemielno.plTable of contentsPREAMBLE2§1 Definitions2§2 Data Controller and Data Protection Officer3§3 Data Protection Officer3§4 Purposes of processing your personal data3§4A Processing personal data in order to respond to your requests/inquiries submitted to us via the contact channels available on the Website, including through our fan pages on social networking sites3§4B Processing data for the purpose of concluding and properly performing a contract for the provision of hotel services or taking action at your request prior to its conclusion4§5 Joint controllership of personal data in connection with sending commercial information about promotions, offers and events organised by the Joint Controllers, including sending newsletters (direct marketing).6§6 Your rights7§7 Automated decision-making8§8 Security of personal data8§9 Cookie Files8
PREAMBLEThe privacy policy of www.archemielno.pl sets out the principles according to which your data will be processed and identifies the entity responsible for its processing – in accordance with generally applicable laws. The privacy policy also specifies the purposes for which your personal data will be processed, the scope of such processing and the rights to which you are entitled in connection with our processing of your personal data.§1 DefinitionsThe terms used in this document mean: - Policy – the privacy policy of the website www.archemielno.pl.
- Website – www.archemielno.pl.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L of 2016, No. 119, p. 1, as amended).
- Personal data – any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific factors relating to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- Processing – any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- Controller – a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data;
- Joint Controller – at least two controllers jointly determining the purposes and means of processing your personal data.
- Processor – a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
- Recipient – a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the context of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
§2 Data Controller and Data Protection Officer- The controller of your personal data is Arche S.A., with its registered office at 05-520 Konstancin - Jeziorna, ul. Mirkowska 45A entered in the register of entrepreneurs of the National Court Register by the District Court for the Capital City of Warsaw in Warsaw, XIII Commercial Division of the National Court Register under number: 0000831001, NIP: 8211639335, REGON: 71002127700000, with share capital of PLN 2,982,300.00 – paid in full.
- You may contact the Controller by traditional mail at the Controller’s registered office address indicated above or by e-mail at: rodo@arche.pl.
- §3 Data Protection Officer
- The Controller has appointed a Data Protection Officer, whom you may contact in all matters related to our processing of your personal data via:
- traditional mail at the Controller’s registered office address indicated in §2 section 1 of this policy, marked – Data Protection Officer.
- by e-mail at: rodo@arche.pl.
- §4 Purposes of processing your personal data
- We will process your personal data for the following purposes:
- Responding to your requests/inquiries submitted to us via the contact channels available on the Website, including via our fan pages on social media platforms.
- Concluding and properly performing a contract for the provision of hotel services or taking action at your request prior to its conclusion.
- Sending you commercial information about promotions, offers and events organised by the Joint Controllers, including sending a newsletter to your e-mail address (direct marketing) – if you consent to such action. This activity will take place under joint controllership of personal data – as referred to in §5 of the Policy.
- §4A Processing personal data for the purpose of responding to your requests/inquiries submitted to us via the contact channels available on the Website, including via our fan pages on social media platforms
- We will process your personal data in order to respond to your message/inquiry if you decide to contact us via our communication channels available on the Website (including, among others, via the contact form, by e-mail or via our fan pages on social media platforms such as Facebook and Instagram).
- The legal basis for our processing of your personal data will be Article 6(1)(f) of the GDPR, i.e. the legitimate interest of the Controller consisting in handling your requests or inquiries submitted to us and responding to them.
- If you submit an inquiry or request to us via our profile on a social media platform:
- Facebook and Instagram – the recipient of your personal data will be Meta Platforms Ireland Ltd. 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (hereinafter: Meta Facebook Platforms).
- More information on the processing of your personal data by the Facebook and Instagram social media platforms can be found at the following links:
- https://www.facebook.com/privacy/center/.
- https://privacycenter.instagram.com/policy/?entry_point=ig_help_center_data_policy_redirect.
- If your data is transferred within the fan pages on the aforementioned social media platforms to a location in a third country (outside the European Economic Area), this will take place only with appropriate data security measures in place (standard contractual clauses).
- In addition, recipients of your personal data may include entities providing the Controller with IT and legal services.
- We will store your personal data for the period necessary to conduct correspondence with you, in particular for the period necessary to respond to your messages/inquiries.
- Providing your personal data is mandatory if you wish to contact us and receive a response to your inquiry or request.
§4B Processing data for the purpose of concluding and properly performing an agreement for the provision of hotel services or taking action at your request before its conclusion- Your personal data will be processed for the following purposes:
- concluding and properly performing an agreement for the provision of services (hereinafter: the Agreement) or taking action at your request before concluding the Agreement.
- fulfilling the legal obligations imposed on the Controller by generally applicable laws.
- pursuing or defending against potential claims arising during or after the performance of the Agreement.
- ensuring the safety of hotel guests and other persons present on the premises of Arche Fabryka Samolotów Mielno through video surveillance.
- The legal basis for our processing of your personal data will be:
- for the purpose of concluding and properly performing the Agreement or taking action at your request before its conclusion – Article 6(1)(b) of the GDPR.
- for the purpose of fulfilling the legal obligations imposed on the Controller by generally applicable laws – Article 6(1)(c) of the GDPR in conjunction with Article 70 of the Act of 29 August 1997 – Tax Ordinance and Article 74 of the Act of 29 September 1994 on Accounting.
- for the purpose of pursuing or defending against potential claims arising during or after the performance of the Agreement, as well as ensuring the safety of hotel guests and other persons present on the premises of Arche Fabryka Samolotów Mielno through video surveillance – our legitimate interest consisting in pursuing the aforementioned purposes (i.e. Article 6(1)(f) of the GDPR). staying on the premises of Arche Fabryka Samolotów Mielno through video surveillance – our legitimate interest consisting in pursuing the aforementioned purposes (i.e. Article 6(1)(f) of the GDPR).
- The recipients of your personal data will be entities providing the Controller with legal, financial and IT services.
- Your personal data will be stored:
- for the purpose of concluding and properly performing the Agreement or taking action at your request before its conclusion – for the period necessary to conclude or properly perform it.
- for the purpose of fulfilling the legal obligations imposed on the Controller by generally applicable laws – for no longer than 5 years, calculated from the end of the calendar year in which the basis for calculating the public-law receivable arose.
- for the purpose of pursuing or defending against potential claims arising during or after the performance of the Agreement – for the period provided for in generally applicable laws, depending on the legal relationship from which the claim arises.
- for the purpose of ensuring the safety of hotel guests and other persons present on the premises of Arche Fabryka Samolotów Mielno through video surveillance – for a period not exceeding 90 days. However, if the surveillance recording serves as evidence in civil, criminal or misdemeanor proceedings, the video surveillance recordings will be stored until the final conclusion of the relevant proceedings.
- Providing your personal data (referred to in §4B section 1 point a) of the Policy is a condition for concluding the agreement, since without providing it we will not be able to conclude the agreement with you. Providing your remaining personal data is mandatory, since without it we will be unable to fulfil the legal obligations imposed on us, nor will we be able to pursue our legitimate interests.
- §5 Joint controllership of personal data in connection with sending commercial information about promotions, offers and events organized by the Joint Controllers, including sending newsletters (direct marketing).
- The Joint Controllers of your personal data will be the following entities, which will process your personal data on the basis of the Joint Controllership Agreement (hereinafter: the Joint Controllers):
- Arche S.A. with its registered office at 05-520 Konstancin - Jeziorna, ul. Mirkowska 45A
- Lena Grochowska Foundation with its registered office in Siedlce (postal code: 08 – 110), at ul. Brzeska 134.
- We note that the current list of Joint Controllers may change in the future – the current list of Joint Controllers can always be found on the website www.arche.pl.
- The Joint Controllers are jointly responsible for protecting your personal data.
- Your point of contact for matters concerning the protection of your personal data is Auraco Sp. z o.o. with its registered office in Warsaw (postal code: 00 – 382), at ul. Solec 81B/73A, which you may contact at the registered office address indicated above or via the following e-mail address: arche.marketing@auraco.pl.
- The Joint Controllers will process your personal data for the purpose of undertaking marketing activities directed at you by sending personalized commercial information about promotions and current offers of the Joint Controllers’ products and services, as well as about events concerning the Joint Controllers and activities undertaken by them, to your e-mail address and/or telephone number activities.
- The legal basis for processing your personal data will be your consent to its processing for the aforementioned purposes (i.e. Article 6(1)(a) of the GDPR), which you may withdraw at any time; however, its withdrawal will not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
- The recipients of your personal data may include intermediaries offering our services or products or supporting our ventures, as well as entities supporting our marketing activities, i.e. providers of systems used to manage marketing databases and entities providing IT and telecommunications services to us. Under no circumstances, however, will your personal data be transferred by the Joint Controllers outside the European Economic Area.
- We will store your personal data until you withdraw your consent to its processing or until the purposes of the Joint Controllers for which it was collected cease to apply (e.g. if marketing campaigns are discontinued).
- Providing your personal data is entirely voluntary; however, without providing it, the Joint Controllers will not be able to send commercial information about promotions and current offers of their products and services to your email address and/or telephone number.
- We will analyse your history of interactions with us (e.g. the services you have used) and the information obtained through analysing your interactions with our websites in order to determine your preferences and interests, which will enable us to send you personalised commercial information about products, offers and events organised by the Joint Controllers.
- We will not process your personal data for the purpose of automated decision-making.
- §6 Your rights
- In connection with our processing of your personal data, you have the right to:
- Withdraw your consent to the processing of your personal data at any time (where we process your personal data on the basis of your consent.
- Object to the processing of personal data (in the cases specified in Articles 21 and 22 of the GDPR).
- Data portability – where the legal basis for our processing of your personal data is your consent to its processing, as well as the conclusion and proper performance of the Agreement.
- Access your personal data and receive a copy thereof (Article 15 of the GDPR).
- Rectify inaccurate personal data and complete incomplete data (Article 16 of the GDPR).
- Erase your personal data (the so-called right to be forgotten, in the cases specified in Article 17 of the GDPR).
- Restrict the processing of your personal data (in the cases specified in Article 18 of the GDPR).
- If you determine that we process your personal data in a manner inconsistent with generally applicable legal provisions, you have the right to lodge a complaint with the supervisory authority, which in the territory of the Republic of Poland is the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
- §7 Automated decision-makingWe will not process your data personal data for the purpose of automated decision-making.§8 Security of personal data
- The website has a valid certificate issued by a trusted certification authority. This means that information, e.g. passwords or credit card details, is sent securely to this website and cannot be intercepted.
- The IT employee grants users of IT systems authorisation to process personal data in the Administrator's IT systems immediately after receiving from the user a declaration concerning the confidentiality of personal data and the methods of securing it.
- Access to the Administrator's IT systems used to process personal data is possible only after entering a unique identifier and password.
- Data encryption is used, in particular for data transmitted via a public network.
- Each person employed or cooperating in the processing of personal data has been authorised to process the data.
- Data processing agreements within the meaning of Article 28 of the GDPR have been concluded with third parties processing data on behalf of the data controller.
- Authorised persons have been trained in the principles of secure personal data processing.
- Responsibility for activities related to personal data security has been defined.
- Persons processing personal data have submitted a declaration concerning the confidentiality of personal data and the methods of securing personal data.
- The integrity of databases is periodically verified by restoring data contained in backup copies.
- Emergency power supply for servers and workstations has been introduced using UPS units or a separate power supply network.
- §9 Cookie files
- A cookie is a small text file that a website uses to record information on the user's computer or mobile device when the user accesses it.
- Cookies may be installed by the Website and may be read exclusively by it (administrator cookies). The Website may also use cookies from external services. In that case, the data may be read by the owner of the cookie (e.g. Google).
- Cookies can be divided into persistent cookies (which are stored on the user's computer and are not automatically deleted when the browser is closed, but are stored for a specified period) and session cookies (which are deleted when the browser is closed).
- Cookies store individual information about the configuration of the user's device and the user's preferences (e.g. username, language, etc.). Cookies may also be used to compile anonymous statistics on the use of websites. Thanks to them, it is not necessary to re-enter the same data during subsequent visits to the website or read the cookie notice each time.
- The website uses Administrator cookies and cookies from external services. The number, type and function of cookies used by external services may vary between individual users due to their individual characteristics, e.g. whether they have an account on a social networking service, etc.
- The website uses four types of cookies:
- necessary;
- statistical/analytical;
- marketing
- other (Unclassified cookies are cookies that we are currently classifying together with the providers of individual services; these include, for example, ubtru, ubtrs and ProfitroomToken- www.archemielno.pl).
- The website uses the following necessary cookies:
- PHPSESSID – this is a cookie used to maintain the user's session state. It is a session cookie.
- test_cookie - Used to check whether the user's browser supports cookies. It is stored for one day.
- The website uses the following analytical cookies:
- _ga – Records a unique identifier used to generate statistical data about how the visitor uses the website. It is stored for two years.
- _ga_# - Used by Google Analytics to collect data on how many times a user has visited the website, as well as the date of the first and most recent visit. It is stored for two years.
- _gat - Used by Google Analytics to limit the request rate. It is stored for one day.
- _gid - Records a unique identifier used to generate statistical data about how the visitor uses the website. It is stored for one day.
- The website uses the following marketing cookies:
- _gcl_au - Used by Google AdSense to test the effectiveness of advertisements on websites using its services. It is stored for three months.
- ads/ga-audiences - Used to detect whether a user tends to leave the website based on cursor movements. The cookie is stored for the duration of the website session.
- Cookies can be freely managed and deleted. More information can be found in the browser instructions (links displayed below):
- Google Chrome;
- Mozilla Firefox;
- Microsoft Edge;
- Opera;
- Safari.
- All cookies on the device can be deleted completely or selectively by choosing a specific cookie. However, please note that this may result in the loss of saved information (e.g. saved login details and site preferences).
- Browser settings can be used to block, completely or selectively, cookies originating from a specific website. More information about managing cookies from specific websites can be found in the privacy and cookie settings of the selected browser.
- Most modern browsers allow you to prevent cookies from being placed on your device, but in that case you may need to reset your preferences each time you visit the website. Some services and features may not function properly (e.g. logging in to your profile).
- The processing of data by functional/necessary cookies (essential for the proper functioning of the website) is carried out for the purposes of pursuing the legally legitimate interest of the controller, namely providing the highest-quality content on the Website.
- The processing of data by the remaining cookies is based on the consent of the website user.
- The Controller will transfer personal data to other recipients entrusted with processing personal data on behalf and for the benefit of the Controller, e.g. entities responsible for the technical operation of the website. In addition, the Controller will disclose personal data to other recipients where such an obligation arises from applicable law.
- Data within individual cookies will be stored for a period corresponding to their validity cycle, which is stored on the user's device. Cookies on the device can be deleted completely or selectively by choosing a specific cookie.