Privacy
1. This Privacy Policy sets out the rules for processing and protecting personal data provided by users in connection with their use of services offered by the GREEN MOUNTAIN HOTEL***** website - www.green-mountain.pl (hereinafter: the Website), and describes the rules for processing personal data by Osada Śnieżka Operator spółka z ograniczoną odpowiedzialnością, based in Warsaw. The Policy applies to personal data of Website users, particularly those making online reservations, using the contact form or other Website features.
2. The controller of personal data processed through the Website is Osada Śnieżka Operator spółka z ograniczoną odpowiedzialnością, Warsaw 00-023, ul. Widok 8, entered in the register of entrepreneurs under KRS: 0000502497, NIP: 7010415841 (hereinafter: Controller).
3. To protect entrusted personal data, the Controller follows internal procedures and guidelines compliant with applicable data-protection laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on protecting individuals regarding the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.
4. The Controller takes particular care to protect the interests of data subjects and ensures that personal data are:
a. processed lawfully,
b. collected for specified, lawful purposes and not further processed incompatibly with those purposes,
c. substantively accurate and adequate for the purposes of processing,
d. kept in a form permitting identification of data subjects for no longer than necessary to achieve the processing purpose.
5. The Controller obtains information about users and their behaviour through information voluntarily entered in forms, for the purpose of:
a. responding to enquiries sent via the contact form (the processing basis is the Controller’s legitimate interest in handling correspondence and responding – Article 6(1)(f) GDPR),
b. accepting reservations through the online booking system (the processing is necessary to conclude and perform a contract – Article 6(1)(b) GDPR),
c. providing services offered by the Controller (the processing is necessary to conclude and perform a contract – Article 6(1)(b) GDPR),
d. direct marketing of GREEN MOUNTAIN HOTEL***** products and services, including sending commercial information and marketing offers by e-mail and SMS to the provided phone number, whereby:
1) the processing basis for direct marketing, particularly of the e-mail address and phone number, is the Controller’s legitimate interest in promoting its own services (Article 6(1)(f) GDPR), with the right to object at any time to processing for direct-marketing purposes;
2) using the user’s e-mail address or phone number to send commercial information and marketing offers by electronic means, including SMS, requires the user’s prior separate consent to use that communication channel, given under Article 398 of the Act of 12 July 2024 – Electronic Communications Law. Consent is voluntary. Refusing consent to a channel (e-mail, SMS) does not affect the ability to use the Controller’s services, but may prevent receipt of commercial information and marketing offers through that channel. Consent may be withdrawn at any time; this will stop such messages through that channel and will not affect the lawfulness of processing before withdrawal.
e. pursuing the Controller’s legitimate interests, e.g. debt recovery and defence against claims (the processing basis is the Controller’s legitimate interest – Article 6(1)(f) GDPR).
6. To send marketing offers and commercial information by SMS, the Controller processes, in particular, the user’s mobile phone number and identification data needed to address the offer correctly (e.g. first and last name). Providing a phone number for SMS marketing is voluntary but necessary to receive marketing content by SMS.
7. On the first visit to the Website, users are informed about cookies and may choose which categories to accept. Users may accept all cookies, reject them or make a detailed choice, except for cookies necessary for the Website to function properly.
8. Cookie settings change after restarting or refreshing the session on the Controller’s website.
9. Installing “cookies necessary for the Website’s basic functionality” is required for proper operation, in particular for authorisation.
10. Necessary website cookies can be changed by changing browser settings; however, this may cause the website to malfunction.
11. More information about cookies is available in the “Help” section of the user’s internet browser
menu.12. Users who, after reading the information available on the Website, do not want cookies stored in their device’s browser should delete them after leaving the Website. The Website uses the following types of cookies:
a. session cookies - remain in the browser until it is closed or the user logs out of the Website,
b. persistent cookies - remain in the device’s browser until deleted by the user or until the period specified in the cookie parameters expires.
13. By functionality, cookies can be divided into:
a. analytical cookies, which help improve website usability by showing how users use and convert on it,
b. marketing cookies, used to personalise advertising content, target it appropriately and analyse marketing and sales-channel performance,
c. necessary cookies, fundamental to the Website’s basic functionality.
14. Necessary cookies are installed on the basis of the Controller’s legitimate interest in ensuring proper Website operation (Article 6(1)(f) GDPR). Analytical and marketing cookies are used only with the user’s consent (Article 6(1)(a) GDPR and relevant provisions of the Electronic Communications Law).
15. The cookies used by the Controller help develop the Website.
16. Some cookies may be placed by the Online Booking System provider solely to:
a. improve and support the booking process,
b. analyse and collect statistics on use of the website and online booking system to improve them,
c. the Online Booking System provider informs users about installed cookies in the system interface.
17. The Controller may use automated decision-making, including profiling, for marketing purposes (including automatically matching advertisements to your interests and measuring their effectiveness) and to tailor offers under Article 6(1)(a) GDPR, based on user consent. Profiling may include analysing booking history, visited Website pages and clicked offers to match marketing content to user interests and measure marketing effectiveness. The Controller does not make, based on profiling, decisions producing legal effects or similarly significantly affecting the user.
18. Personal data may be received by authorities, institutions and entities authorised by law, as well as entities providing services to the Controller (e.g. legal, IT, marketing and accounting services, entities carrying out mass e-mail and SMS mailings for the Controller or providing tools for such mailings, and other entities involved in delivering the ordered service).
19. The Controller uses Google Analytics to compile Website-use statistics and optimise the Website. In certain cases, user data may be transferred to third countries. In such cases, the Controller applies safeguards required by the GDPR, particularly an adequacy decision of the European Commission or standard contractual clauses. Detailed information may be obtained by contacting the Controller.
20. Personal data processed to send commercial information and marketing offers, particularly by SMS, will be processed until the user withdraws consent or objects to processing for marketing purposes. It may then be retained to demonstrate compliance or defend against claims, but no longer than the limitation period for potential claims related to the Controller’s marketing activities.
21. Personal data processed in connection with concluding and performing contracts for services provided by the Controller, including hotel-service reservations, will be stored for the contract term, then for the limitation period of claims under that contract and for the period required by law, particularly tax and accounting laws.
22. Personal data processed to handle correspondence sent via the contact form or other communication channels will be stored as long as necessary to respond and conduct correspondence, then for no longer than 24 months from the date correspondence ends, to defend against potential claims.
23. Website users have the right to request access to their data, rectification, erasure, restriction of processing and data portability; to object to processing, including processing for direct marketing; and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
24. To exercise the above rights, Website users may contact the Controller directly using the details provided in the Policy or the Data Protection Officer appointed by the Controller at: rodo@osada-sniezka.pl.
25. The Service User may withdraw any consent given (including consent to use their email address and phone number to send commercial information and marketing offers by SMS) at any time, without affecting the lawfulness of processing carried out before withdrawal. Consent may be withdrawn in particular by:
a. clicking the relevant unsubscribe link in the received email,
b. contacting the ADO or its Data Protection Officer at the correspondence address or email: rodo@osada-sniezka.pl.
26. For technologies using cookies, users may withdraw consent by changing their browser settings. Users may also change their cookie choices at any time via the consent management panel available on the Service, without changing browser settings.
27. Any Service user may lodge a complaint with the supervisory authority, the President of the Personal Data Protection Office, if their personal data is processed unlawfully.
28. The Service may contain links to other websites that operate independently and are not supervised by the Service in any way. These sites may have their own privacy policies and terms, which the ADO recommends reading carefully.
29. The ADO reserves the right to amend the Service's privacy policy due to developments in internet technology, possible changes in personal data protection law, and the Service's development. The ADO will inform users of all changes in a clear and visible manner.