Privacy

I. GENERAL PROVISIONS

1. This Privacy Policy concerns the processing and protection of personal data provided by users who are natural persons using products and services offered by Dune Beach Resort Sp. z.o.o.

2. The website www.dunebeachresort.com is operated by Dune Beach Resort Sp. z o.o., with its registered office in Koszalin at ul. Wojska-Polskiego 24-26, 75-712 Koszalin, entered in the entrepreneurs’ register of the National Court Register by the District Court in Koszalin, 9th Commercial Division of the National Court Register, under KRS number 0000680475, NIP 6692536463, REGON 367401312, with share capital of PLN 325,000.

3. The controller of users’ personal data is Dune Beach Resort Sp. z o.o., with its registered office in Koszalin at ul. Wojska-Polskiego 24-26, 75-712 Koszalin, entered in the entrepreneurs’ register of the National Court Register by the District Court in Koszalin, 9th Commercial Division of the National Court Register, under KRS number 0000680475, NIP 6692536463, REGON 367401312, with share capital of PLN 325,000 (the “Controller”).

4. The Controller has appointed a Data Protection Officer. The Data Protection Officer may be contacted on all matters concerning personal-data processing in writing at ul. Wojska-Polskiego 24-26, 75-712 Koszalin, or by email: rodo@dunebeachresort.pl

5. The Controller processes users’ personal data in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on protecting natural persons regarding the processing of personal data and the free movement of such data, repealing Directive 95/46/EC (the “GDPR”), and the Personal Data Protection Act of 10 May 2018.

6. Processing users’ personal data by the Controller means any operation or set of operations performed on personal data or sets of personal data, whether automated or not, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or other provision, alignment or combination, restriction, erasure or destruction.

7. When processing users’ personal data, the Controller applies appropriate technical and organisational measures ensuring adequate protection against unauthorised or unlawful processing and accidental loss, destruction or damage.

II. PURPOSES OF PERSONAL-DATA PROCESSING

1. The Controller processes users’ personal data for various purposes; such processing always complies with applicable law.

2. The Controller processes users’ personal data as necessary to:

a. respond to user enquiries submitted via the contact form,

b. take steps before entering into a contract at the data subject’s request, or perform a contract for services provided by the Controller to which the data subject is a party, under Art. 6(1)(b) GDPR,

c. accept reservations through the online booking system,

d. take steps before entering into a contract at the data subject’s request under Art. 6(1)(b) GDPR,

e. provide products or services offered by the Controller under Art. 6(1)(b) GDPR,

f. comply with the Controller’s legal obligations (including tax, archiving and complaint-handling obligations) under Art. 6(1)(c) GDPR,

g. market the Controller’s products and services and those of entities belonging to Dune Beach Resort Sp. z o.o., including sending commercial information by email where the Customer has consented by selecting the relevant box during booking or when submitting an enquiry via the contact form,

h. pursue the Controller’s legitimate interest in specific cases under Art. 6(1)(f) GDPR, e.g. debt collection or video monitoring of activity on the premises.

III. TYPES OF PERSONAL DATA PROCESSED

1. In accordance with the data-minimisation principle, the Controller processes only the categories of personal data necessary to achieve the purposes referred to in section II(2) of this Privacy Policy.

2. For steps before entering into a contract, entering into and performing a contract concerning use of the Controller’s products and services, the Controller processes the user’s: a. first and last name, b. address details (street and building/apartment number, town/city with postcode, province, country), c. date of birth, d. email address, e. telephone number, f. NIP number where the user conducts business activity, g. IP address.

3. When responding to enquiries submitted via the contact form, the Controller processes the user’s: a. first and last name, b. email address, c. telephone number, d. IP address.

4. For marketing the Controller’s products and services and those of entities belonging to Dune Beach Resort SP. z o.o., including sending commercial information, the Controller processes the user’s: a. first and last name, b. email address, c. IP address.

5. Providing personal data is voluntary. However, where the user enters into a contract concerning use of the Controller’s products and services, failure to provide specified data will make it impossible to perform the contract or provide certain services.

IV. LEGAL BASIS FOR PERSONAL-DATA PROCESSING

Users’ personal data are processed on the basis of:

1. Art. 6(1)(a) GDPR – where users consent to processing their personal data for a specified purpose or purposes,

2. Art. 6(1)(b) GDPR – where processing is necessary to perform a contract between the Controller and the user or to take steps at the user’s request before entering into a contract,

3. Art. 6(1)(c) GDPR – where processing is necessary to comply with a legal obligation incumbent on the Controller,

4. Art. 6(1)(f) GDPR – where processing is necessary for purposes arising from the legitimate interests pursued by the Controller or a third party, in particular pursuing or defending claims and ensuring the security of the Controller’s property and resources (including by video monitoring activity on the premises).

V. RETENTION PERIOD FOR PERSONAL DATA

1. The Controller processes users’ personal data for the period necessary to fulfil the purposes for which it is processed or until processing is required by applicable law.

2. Where processing is based on users’ consent, the Controller processes their personal data until consent is withdrawn and, after withdrawal, for the limitation period applicable to any claims available to users or the Controller.

3. Where processing is based on performance of a contract, the Controller processes users’ personal data for the period necessary to perform the contract and thereafter for the limitation period applicable to any claims available to users or the Controller.

4. Where processing is based on the Controller’s legitimate interest, the Controller processes users’ personal data until an effective objection to processing for that purpose is made.

VI. INFORMATION ON PERSONAL-DATA RECIPIENTS OR CATEGORIES OF RECIPIENTS

Users’ personal data may be transferred to the Controller’s subcontractors, i.e. entities used by the Controller in conducting its business, performing contracts and providing services. In particular, data may be transferred to IT service providers, postal and courier service providers, booking-system providers, payment-service providers, accounting firms and marketing agencies. These entities process users’ personal data under agreements with the Controller and in accordance with applicable data-protection laws. Users’ personal data may also be transferred to entities authorised to obtain it under applicable law, in particular judicial authorities.

VII. INFORMATION ON AUTOMATED DECISION-MAKING, INCLUDING PROFILING

The Controller may use automated decision-making, including profiling, for marketing purposes and to tailor the offer.

VIII. INFORMATION ON THE INTENTION TO TRANSFER PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS

The Controller does not intend to transfer users’ personal data to Third Countries or international organisations.

IX. INFORMATION ON USERS’ RIGHTS IN CONNECTION WITH THE PROCESSING OF THEIR PERSONAL DATA

In connection with the processing of their personal data by the Controller, users have the following rights:

1. the right to request access from the Controller to personal data concerning them – by providing their data to the Controller, users have the right to view and access them; users also have the right to obtain information from the Controller about their personal data, in particular the purposes and legal bases of processing, the scope of data held, the entities to which personal data are disclosed and the planned date of their deletion,

2. the right to rectification of personal data – users have the right to immediate rectification of inaccurate personal data processed by the Controller,

3. the right to complete personal data – users have the right to request completion of incomplete personal data processed by the Controller,

4. the right to erasure of personal data – users have the right to request that the Controller immediately erase their personal data where one of the following circumstances applies:

a. personal data are no longer necessary for the purposes for which they were collected or otherwise processed; b. the data subject has withdrawn consent; c. the data subject objects under Article 21(1) or (2) of the GDPR; d. personal data were processed unlawfully; e. personal data must be erased to comply with a legal obligation; f. personal data were collected in connection with the provision of information society services.

5. the right to restriction of processing of personal data – users have the right to request that the Controller restrict processing of their personal data in the situations specified in Article 18 of the GDPR.

6. the right to object to processing of personal data – users have the right to object to processing based on the Controller’s legitimate interest or carried out for direct marketing purposes.

7. the right to data portability – users have the right to receive personal data in a structured, machine-readable format and to transmit such data to another controller.

X. INFORMATION ON THE USER’S RIGHT TO WITHDRAW CONSENT TO THE PROCESSING OF PERSONAL DATA

1. Where the user’s personal data are processed on the basis of consent, the User has the right to withdraw it at any time.

2. The User may withdraw consent by: a. sending an e-mail to: rodo@dunebeachresort.pl b. sending a letter to: ul. Wojska-Polskiego 24-26, 75-712 Koszalin.

4. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

XI. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY

The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, Warsaw).

XII. COOKIES

1. The website www.dunebeachresort.com uses Cookies and other similar technologies to adapt its operation to users’ needs.

2. Installing Cookies is necessary for the website to function properly. The User may change browser settings at any time.

3. The following files are used: a. session (temporary), b. persistent (stored until deletion or expiry).

4. Cookie functionalities: conversion, tracking, marketing, analytics tools, necessary files.

5. Cookies may be placed to support the booking process and analyse statistical data.

XIII. FINAL PROVISIONS

1. Matters not covered by this Privacy Policy are governed by applicable law.

2. In the event of any changes to this Privacy Policy the user will be notified at the e-mail address provided.