I. General information
- This policy applies to the Website operating under the address url: hostel-helvetia.pl
- The website operator and personal data administrator is: Smart Solutions Izabela Szwedzicka ul. Jeziorowa 28B, 03-991, Warsaw
- The operator’s e-mail contact address is firstname.lastname@example.org
- The Operator is the Administrator of your personal data in relation to the data provided voluntarily on the Website.
- The website uses personal data for the following purposes:
- Query handling by the form
- Presentation of the offer or information
- The website gathers information about users and their behavior in the following ways:
Through data voluntarily entered in forms that are entered into the Operator’s systems.
By saving cookie files in end devices (so-called “cookies”).
II. Selected methods of data protection used by the Operator
- User passwords are stored in a hash form. The hash function works in one direction – it is not possible to reverse its operation, which is now a modern standard in the field of storing user passwords.
- The operator periodically changes its administrative passwords.
- To protect data, the Operator regularly makes backup copies.
- An important element of data protection is the regular update of all software used by the Operator to process personal data, which in particular means regular updates of programming components.
- The website is hosted (technically maintained) on the operator’s server: ogicom.pl
- Registration details of the hosting company: H88 S.A. with its registered office in Poznań, Franklin Roosevelt 22, 60-829 Poznań, entered into the National Court Register by the Poznań District Court – Nowe Miasto and Wilda in Poznań, VIII Commercial Department of the National Court Register under the number KRS 0000612359, REGON 364261632, NIP 7822622168, share capital PLN 210,000.00 fully paid up.
- Hosting company:
- uses measures to protect against data loss (e.g. disk arrays, regular backups),
- applies adequate measures to protect processing locations in the event of a fire (e.g. special fire extinguishing systems),
- applies adequate measures to protect processing systems in the event of a sudden power failure (e.g. dual power lines, aggregates, UPS voltage support systems),
- applies physical security measures to access to data processing sites (e.g. access control, monitoring),
- applies measures to ensure appropriate environmental conditions for servers as elements of the data processing system (e.g. control of environmental conditions, specialized air-conditioning systems),
- applies organizational solutions to ensure the highest possible level of protection and confidentiality (training, internal regulations, password policies, etc.),
- appointed a Data Protection Officer.
- The hosting company maintains server-level logs to ensure technical reliability. Registration may be subject to:
- resources specified by URL identifier (addresses of requested resources – pages, files),
- time of receipt of the inquiry,
- response time,
- name of the client station – identification carried out by the HTTP protocol,
- information about errors that occurred during the implementation of the HTTP transaction,
- URL address of the page previously visited by the user (referrer link) – if the Website was accessed via a link,
- information about the user’s browser,
- information about the IP address,
- diagnostic information related to the process of self-ordering services via recorders on the website,
- information related to the handling of electronic mail addressed to the Operator and sent by the Operator.
IV. Your rights and additional information on how to use the data
- In some situations, the Administrator has the right to transfer your personal data to other recipients, if it is necessary to perform the contract concluded with you or to fulfill the obligations incumbent on the Administrator. This applies to such groups of recipients:
- payment operators
- authorized employees and associates who use data to achieve the purpose of the site
- Your personal data processed by the Administrator for no longer than is necessary to perform the related activities specified in separate regulations (e.g. on accounting). With regard to marketing data, the data will not be processed for more than 3 years.
- You have the right to request from the Administrator:
- access to personal data concerning you,
- correcting them,
- processing restrictions,
- and data transfer.
- You have the right to object to the processing indicated in point 3.3 c) to the processing of personal data for the purpose of exercising legitimate interests pursued by the Administrator, including profiling, however, the right to object cannot be exercised if there are valid legitimate grounds for the processing of interests, rights and freedoms overriding you, in particular the determination, exercise or defense of claims.
- The Administrator’s actions may be appealed to the President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw.
- Providing personal data is voluntary, but necessary to operate the Website.
- In relation to you, actions may be taken that involve automated decision making, including profiling to provide services under the concluded contract and for direct marketing by the Administrator.
- Personal data is not transferred from third countries within the meaning of the provisions on the protection of personal data. This means that we do not send them outside the European Union.
V. Information on forms
- The website collects information provided voluntarily by the user, including personal data, if they are provided.
- The website may save information about connection parameters (time, IP address).
- In some cases, the website may save information that makes it easier to link data in the form to the email address of the user completing the form. In this case, the user’s email address appears inside the url of the page containing the form.
- The data provided in the form are processed for the purpose resulting from the function of a specific form, e.g. to process the service request or business contact, service registration, etc. Each time the context and description of the form clearly indicates what it is used for.
VI. Administrator logs
- Information on user behavior on the website may be subject to login. These data are used to administer the site.
VII. Important marketing techniques
VIII. Information about cookies
- Cookie files (so-called “cookies”) are IT data, in particular text files, which are stored on the Website User’s end device and are intended for using the Website’s pages. Cookies usually contain the name of the website from which they originate, their storage time on the end device and a unique number.
- The entity placing cookies on the Website User’s end device and accessing them is the Website operator.
- Cookies are used for the following purposes:
- maintaining the Website user’s session (after logging in), thanks to which the user does not have to re-enter the login and password on each subpage of the Website;
- achieving the goals set out above in the “Important marketing techniques” section;
- The Website uses two basic types of cookies: session cookies and persistent cookies. Session cookies are temporary files that are stored on the User’s end device until logging out, leaving the website or turning off the software (web browser). Persistent cookies are stored on the User’s end device for the time specified in the cookie parameters or until they are deleted by the User.
- Software for browsing websites (web browser) usually by default allows storing cookies on the User’s end device. Website Users can change the settings in this area. The web browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this subject is provided in the help or documentation of the web browser.
- Cookies placed on the Website User’s end device may also be used by entities cooperating with the Website operator, in particular, the companies: Google (Google Inc. with its registered office in the USA), Facebook (Facebook Inc. with its registered office in the USA), Twitter (Twitter Inc. with headquarters in the USA).
IX. Managing cookie files – how to give and withdraw consent in practice?
- If the user does not want to receive cookies, he can change the browser settings. We reserve that disabling cookies necessary for authentication processes, security, maintaining user preferences may make it difficult, and in extreme cases may prevent the use of websites
- To manage cookie settings, select the web browser you use from the list below and follow the instructions:
- Internet Explorer
- Mobile devices:
- Safari (iOS)
- Windows Phone