GGniazdo OrlikaReturn to the apartment

Gniazdo Orlika · Orlik Residence

Privacy policy

Source version: 2026-09-25-v4Effective from: 2026-09-25Polish source ID: 887f10c0ca87…

English translation of the currently published Polish source. You can also open the Polish original.

Privacy policy — translation of version 2026-09-25-v4

This is a faithful English translation of the published Polish document. It is provided so that an English-speaking Guest can understand how personal data is processed.

1. Controller and contact

  1. The personal-data controller is “Polimet” Krzysztof Policht, Przedwojów 90, 58-400 Przedwojów, Polish tax ID 6141446675, REGON 231078865, hereinafter the “Controller”. Gniazdo Orlika is the property brand and does not replace the Controller’s legal identity.
  2. Data enquiries: rezerwacje@gniazdoorlika.pl, +48 661 110 895, or by post to the address above.
  3. The Controller has not appointed a data protection officer.

2. Data categories and sources

  1. For an enquiry or booking the Controller may process name, telephone number, email, country, stay dates, number of Guests, message, quotation, special arrangements, accepted document versions, IP address and technical records of the time and course of operations.
  2. After confirmation, the Controller processes the booking identifier and source, payment status and amount, receipt date and transaction identifier, correspondence and data needed for the stay, complaints, refunds and damage reports, and, where the Guest requests an invoice or books as a business, the buyer details required to issue it. For a consumer this includes at least name and address; for a business, company name and tax ID as well.
  3. During pre-check-in, the Controller processes the data needed to operate the stay and settle local tourist tax for each person, in particular name, home address, country, number of stay days and, where applicable, the statutory exemption basis. Do not upload an identity-document scan or data not requested by the form.
  4. Where one person books for other Guests, their data may come from the person booking, who should give them this Policy. A parent or guardian supplies a minor’s data only as needed for the stay and mandatory accounting.
  5. Data may also come from a payment provider, channel manager or booking platform where that channel is used.

3. Purposes and legal bases

  1. Answering enquiries, checking availability, preparing a quotation, entering into and performing the contract and operational contact — Article 6(1)(b) GDPR.
  2. Tax and accounting, required records, local tourist tax and other legal obligations — Article 6(1)(c) GDPR.
  3. Establishing, pursuing and defending claims, complaints, fraud prevention, website security, event audit and business continuity — the Controller’s legitimate interests under Article 6(1)(f) GDPR.
  4. Marketing messages — only with voluntary consent under Article 6(1)(a) GDPR and electronic-communications law. Consent may be withdrawn at any time without affecting prior lawful processing or the booking.

4. Is providing data mandatory?

  1. Providing fields marked as required is voluntary but necessary to conclude and perform an online booking, send confirmation and, on request, an invoice, and make stay-related contact. Without them an online booking is not possible.
  2. Data about people staying is needed for the required register, local tourist tax and temporary access. Exemption information is needed only if the person wishes to claim it.
  3. Marketing consent is entirely voluntary and is not a booking condition.

5. Recipients

  1. To the necessary extent, recipients may include:
  • server, email, IT and technical-support providers;
  • accountants, banks and the payment provider for the transaction;
  • the Head of the Polish National Revenue Administration and Ministry of Finance systems for issuing, submitting and storing invoices in KSeF;
  • an SMS provider once SMS notifications are enabled;
  • a channel manager and Booking.com, Airbnb or another platform where the booking originates there or synchronisation is needed;
  • an electronic-lock provider once temporary codes are enabled;
  • Karpacz Municipality and other public authorities authorised by law;
  • legal advisers, insurer or services where needed to protect people or property or pursue claims.
  1. Processors acting for the Controller may process data only under contract and documented instructions. Independent controllers, especially banks, payment providers and booking platforms, provide their own privacy information.
  2. Stripe, Beds24, Booking.com, Airbnb, SMS and electronic-lock integrations are currently off or in test mode. Before activation the Controller will verify contracts, roles, scope and update this Policy if necessary. Data is not sold.

6. Transfers outside the EEA

  1. Core website and email operation does not intentionally transfer data outside the European Economic Area.
  2. Future payment, booking, messaging or lock providers may use infrastructure or subcontractors outside the EEA. A transfer will occur only in accordance with the GDPR, in particular an adequacy decision or Standard Contractual Clauses. Information about the provider and safeguards actually selected will be made available before transfers begin.

7. Retention

  1. An enquiry not leading to a booking is kept until contact ends and generally no longer than 12 months afterwards unless needed longer to defend a claim.
  2. Confirmed-booking data is kept while the contract is performed and until claim limitation periods expire. Data needed for a specific claim may be kept until the case is finally concluded.
  3. Tax and accounting documents and local tourist-tax records are kept for periods required by law and municipal settlement rules.
  4. Access-code data is deleted or anonymised when no longer needed and after the necessary security period. Access is revoked after departure or cancellation.
  5. Marketing data is kept until consent is withdrawn or the purpose ends, while the consent and withdrawal record is kept as long as needed to demonstrate compliance.
  6. Security and audit logs are kept for a period proportionate to risk and accountability obligations, then deleted or anonymised unless connected with an open incident or claim.

8. Individual rights

  1. Within GDPR limits, individuals have rights of access and copy, rectification, erasure, restriction, portability, objection to legitimate-interest processing and withdrawal of consent.
  2. Requests may be sent to rezerwacje@gniazdoorlika.pl. To protect data, the Controller may request information necessary to verify identity but will not request excessive data.
  3. A complaint may be lodged with the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl.

9. Automation

  1. The system automatically calculates price from dates and number of people, checks availability, confirms after full payment, calculates the Host’s internal tourist-tax settlement and may trigger messages and an access code. These rules fulfil the Guest’s request and do not evaluate the Guest as a person.
  2. The Controller does not profile Guests or make decisions producing legal effects within Article 22 GDPR. Late payment, calendar discrepancies and lock errors go to manual review.

10. Cookies and technical logs

  1. The public website currently uses no analytics or marketing cookies.
  2. The private admin panel uses an essential protected cookie to maintain the signed-in session. Login cannot work without it.
  3. The server records necessary technical data, including IP, request time and error details, to protect the website, prevent abuse and diagnose failures.

11. Security and Policy changes

  1. The Controller applies risk-appropriate measures, including HTTPS, access control, panel authentication, backups, operation logs and limited data access.
  2. A change receives a new designation and effective date. The version accepted with a booking is recorded. A change does not affect the lawfulness of prior processing or the terms of an earlier contract.