PRIVACY AND COOKIES POLICY OF THE SERVICE
I. Data Controller and Definitions
The personal data controller of the Guests/Users of the Service is: EPOL HOLDING SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, +48 669 902 180, 7282749467.
The Data Controller can be contacted:
By correspondence at: ul. Targowa 9A, 90-042, Łódź, Poland
By email at: office@riversideaparthotel.com
Service User – a natural person visiting the page/pages presenting the Offer and enabling the conclusion of a lodging rental agreement or using the services or functionalities described in this Privacy and Cookies Policy.
Service Provider – EPOL HOLDING SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, 7282749467, ul. Targowa 9A, 90-042, Łódź, Poland.
Offer – accommodation offered by the Service Provider for the purpose of concluding a lodging rental agreement through the Service.
Guest – a natural person with full legal capacity, a legal entity, or an organizational unit referred to in Article 331 of the Civil Code, entering into a lodging rental agreement with the Service Provider.
Service – presentation of the Service Provider’s Offer online, enabling the conclusion of an online lodging rental agreement.
Newsletter – information, including commercial information within the meaning of the Act of 18 July 2002 on the provision of electronic services (Journal of Laws of 2020, item 344), sent by the Service Provider to the Guest/User electronically; receiving it is voluntary and requires the Guest/User’s consent.
Account – a collection of data stored in the Service and in the Service Provider’s IT system regarding a specific Guest/User and their bookings and concluded agreements, through which the Guest/User can place orders and enter agreements.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation).
II. Purposes, Legal Basis, and Data Retention Period
To fulfill a remote lodging rental agreement, the Service Provider processes:
Information about the User’s device to ensure proper functioning of services: computer IP address, information contained in cookies or other similar technologies, session data, browser data, device data, activity on the Site, including specific subpages.
Geolocation information, if the Guest/User has given consent for the Service Provider to access geolocation. Geolocation information is used to provide more tailored product and service offers.
Personal data of Users: first and last name, registered office address, correspondence address, email address, phone number, tax ID (NIP), bank account number, or other personal data required to complete the purchase, as requested during the booking process by the Controller.
This information does not include data directly identifying Guests/Users but may constitute personal data when combined with other information; therefore, the Controller provides full protection under the GDPR.
The data is processed under Article 6(1)(b) GDPR for service execution, i.e., a contract for electronic services according to the Terms and Conditions, and under Article 6(1)(a) GDPR based on consent for certain cookies or similar technologies, given through browser settings or for geolocation purposes. Data is processed until the Guest/User stops using the Service.
The Controller undertakes all measures required under Article 32 GDPR, considering technical knowledge, implementation costs, nature, scope, purposes of processing, and risk, to implement appropriate technical and organizational measures ensuring security proportional to the risk.
III. Marketing Activities of the Controller
The Controller may display marketing information about its products or services on the Service pages. This is based on Article 6(1)(f) GDPR, i.e., the Controller’s legitimate interest in publishing content related to its services and promotional activities. This does not violate Guests’/Users’ rights or freedoms; they expect and may even seek such content when visiting the Service.
IV. Recipients of User Data
The Controller discloses personal data only to entities processing data under contracts to provide services for the Controller, e.g., hosting, IT services, marketing, and PR.
V. Transfer of Personal Data to Third Countries
Personal data will not be processed in third countries.
VI. Rights of Data Subjects
Every data subject has the right to:
Access (Art. 15 GDPR) – confirmation whether their personal data is processed and, if so, access to it and information about processing purposes, data categories, recipients, storage period, right to rectification, deletion, restriction, and objection.
Receive a copy of data (Art. 15(3) GDPR) – the first copy free, additional copies may incur a reasonable administrative fee.
Rectification (Art. 16 GDPR) – request correction of inaccurate or incomplete personal data.
Erasure (Art. 17 GDPR) – request deletion if there is no legal basis for processing or data is no longer needed.
Restriction of processing (Art. 18 GDPR) – request restriction if accuracy is contested, processing is unlawful, data is no longer needed by the Controller, or objection to processing is pending.
Data portability (Art. 20 GDPR) – receive structured, machine-readable data and request transfer to another controller.
Objection (Art. 21 GDPR) – object to processing for legitimate interests, including profiling. The Controller will assess if their legitimate interests override the data subject’s interests.
Withdraw consent at any time without affecting lawfulness of prior processing.
To exercise these rights, contact the Data Controller using the details in Section I, point 2.
VII. President of the Personal Data Protection Office
Data subjects may file a complaint with the supervisory authority in Poland: President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, via:
Mail: ul. Stawki 2, 00-193 Warsaw
Electronic contact form: https://www.uodo.gov.pl/pl/p/kontakt
Hotline: 606-950-0000
VIII. Data Protection Officer
Data subjects may contact the Controller’s DPO via email or in writing at the address in Section I, point 2.
IX. Changes to the Privacy Policy
The Privacy and Cookies Policy may be updated to reflect current needs and ensure accurate information for Guests/Users.
X. Cookies
The Service collects information about Guests/Users as follows:
Voluntarily provided in forms;
Via cookies stored on devices;
Through web server logs collected by the hosting operator.
Cookies are text files stored on the User’s device containing site name, storage time, and a unique number.
Cookies are used only with the Guest/User’s prior consent. Consent is given by clicking “I agree, go to site” or closing the cookie notice.
Consent may cover selected cookies using the “Cookie Settings” option. Disabling essential cookies may impair Service functionality.
Without consent, Users may select “I do not agree” or change browser settings, which may affect functionality.
Instructions for managing cookies depend on browser/device: Internet Explorer, Chrome, Safari, Firefox, Opera, Android, iOS Safari, Windows Phone.
Legal basis: legitimate interests of the Controller in providing high-quality, secure services.
Cookies include session and persistent types.
Purposes: statistics, session maintenance, user profiling for recommendations and advertising networks (especially Google).
Browsers allow cookie management and deletion; blocking cookies may affect some functionality.
Cookies may be used by advertising partners and networks for targeted ads. Users can review preferences at https://www.google.com/ads/preferences/.
Plugins may share data with providers like Facebook or Google.
Online payment systems may process data to execute bookings.
XI. Newsletter
Users may consent to receive commercial information via email during registration or later.
Users can unsubscribe anytime via account settings, newsletter links, or Customer Service.
XII. Account
Users cannot provide unlawful content.
Access to the Account requires registration.
Registration requires providing account type/gender, name, company name, NIP, billing info, email, and password. Users confirm accuracy and acceptance of Terms and Conditions.
Access creates a perpetual electronic services agreement for the Account.
Registration on one Service page allows access to all Service pages.
Users can terminate the agreement at any time by email or written notice.
The Service Provider may terminate the agreement for inactivity (6 months), violations, or transfer of service, with seven days’ notice. Re-registration may require permission.