Privacy policy

The personal data controller is CRH Patio Spółka z ograniczoną odpowiedzialnością.

Users may contact the Controller, including for the purpose of exercising their rights, through the following communication channels: e-mail: odo@zagiel.pl; postal address: ul. Roztocze 4a, 20-722 Lublin.

Definitions

User – means an entity for whom, in accordance with applicable law, services may be provided electronically or with whom an Agreement for the provision of electronic services may be concluded.

Device – means an electronic device through which the User accesses the Website.

Controller – CRH Patio Sp. z o.o., ul. Kiełbaśnicza 25, 50-110 Wrocław, KRS: 0000231186, NIP: 8971702720, REGON: 020045790, District Court for Wrocław-Fabryczna in Wrocław, 6th Commercial Division of the National Court Register, which provides services and stores and accesses information on the User’s Devices.

Website – means the website or application operated by the Controller at: hotepatio.pl.

Cookies – means IT data in the form of small text files saved and stored on the Devices through which the User accesses the Website.

Controller Cookies – means Cookies placed by the Controller in connection with the provision of electronic services by the Controller through the Website.

Third-party Cookies – means Cookies placed by the Controller’s partners through the Website.

Types of Cookies Used

The Cookies used by the Controller are safe for the User’s Device. In particular, they cannot be used to transmit viruses, other unwanted software or malicious software to Users’ Devices. These files make it possible to identify the software used by the User and to adapt the Website individually to each User. Cookies usually contain the name of the domain from which they originate, the period for which they are stored on the Device and an assigned value.

The Controller uses the following Cookies:

Session Cookies: these are stored on the User’s Device and remain there until the end of the relevant browser session. The stored information is then permanently deleted from the Device’s memory. The session-cookie mechanism does not allow any personal data or confidential information to be retrieved from the User’s Device.

Persistent Cookies: these are stored on the User’s Device and remain there until they are deleted. Ending a browser session or switching off the Device does not remove them from the User’s Device. The persistent-cookie mechanism does not allow any personal data or confidential information to be retrieved from the User’s Device.

Purposes for Which the Controller May Use Cookies

The Controller may use its own Cookies for the following purposes:

• analysis, research and audience measurement audits;

• creating anonymous statistics that help explain how Users of the Website use the service, enabling its structure and content to be improved;

• ensuring the security and reliability of the Website.

The Controller uses Third-party Cookies for the following purposes:

• collecting general and anonymous statistical data through analytical tools – Google Analytics [cookie controller: Google Inc., based in the USA];

• displaying advertisements tailored to the User’s preferences through the Google AdWords and Facebook Ads online advertising systems;

• using interactive features to promote the Website through social media.

The entities placing Cookies on the end device of a User of the Website are the Controller and:

• Google Inc., based in Mountain View, California, United States. To learn more about this controller’s privacy policy, click here: https://policies.google.com/privacy;

• Facebook Inc., based in Menlo Park, California, United States. To learn more about this controller’s privacy policy, click here: https://www.facebook.com/policy.php;

Where Cookies contain personal data, the entities listed in point 3.3 are the controllers of the personal data contained in the Cookies within the meaning of the GDPR.

Cookies usually contain the name of the website from which they originate, the period for which they are stored on the end device and a unique number.

Options for Defining the Conditions for Storing or Accessing Cookies

The User may restrict or disable Cookies’ access to their Device. Where this option is used, the Website will remain available except for functions that, by their nature, require Cookies.

By default, most web browsers available on the market accept the storage of Cookies. Every User may define the conditions for using Cookies through their web-browser settings. This means that it is possible, for example, to partially restrict the storage of Cookies, including temporarily, or to disable it completely.

Web-browser settings relating to Cookies are relevant to consent to the Website’s use of Cookies. In accordance with applicable law, such consent may also be expressed through the web-browser settings. Where such consent is not given, the web-browser settings relating to Cookies should be changed accordingly.

Detailed information on changing Cookie settings and deleting Cookies independently in the most popular web browsers is available in the browser’s help section and on the following pages:

• for the Chrome browser;

• for the Firefox browser;

• for the Internet Explorer browser;

• for the Opera browser;

• for the Safari browser;

• for the Microsoft Edge browser.

The Controller also processes anonymised usage data connected with the use of the Website in order to generate statistics that assist in administering the Website. These data are aggregated and anonymous, meaning that they do not contain characteristics identifying persons who visit the Website.

Information Provided in Forms

The Controller collects information provided voluntarily by the User.

Data entered in a form are not made available to third parties other than with the User’s consent.

Data entered in a form are processed for the purpose arising from the function of the specific form, for example to process a service request or a business enquiry.

Server Logs

Information about certain User activities is logged at the server level.

These data are used solely to administer the service and to ensure the most efficient possible operation of the hosting services provided.

Resources viewed by Users are identified by their URLs.

The following information may also be recorded:

• the time at which a request is received;

• the time at which a response is sent;

• the name of the client station, identified through the HTTP protocol;

• information about errors occurring during HTTP transactions;

• the URL of the page previously visited by the User (referrer link), where the Website was accessed through a link;

• information about the User’s browser;

• information about the IP address.

The above data are not associated with specific persons browsing the Website.

The above data are used solely for server-administration purposes.

Disclosure of Data

Data are disclosed to external entities only within the limits permitted by law.

Data enabling the identification of a natural person are disclosed only with that person’s consent.

The Controller may be required to provide information collected through the Website to authorised authorities on the basis of lawful requests and to the extent covered by such requests.

DATA CONTROLLER INFORMATION CLAUSE

Pursuant to Article 13 of the General Data Protection Regulation (GDPR) of 27 April 2016 (Official Journal of the European Union L 119 of 4 May 2016), we hereby inform you that:

The joint controllers of your personal data are CRH Patio Sp. z o.o., ul. Kiełbaśnicza 25, Wrocław, and CRH Żagiel Sp. z o.o., ul. Roztocze 4, Lublin. As part of the Żagiel Group, they jointly determine the purposes and means of data processing and carry out joint marketing activities pursuant to Article 26(1) of the General Data Protection Regulation of 27 April 2016 (hereinafter: the GDPR).

The essential content of the arrangements between the Joint Controllers is made available by the Data Protection Officer.

The Data Protection Officer, Ewelina Jemielniak, may be contacted at iod@hotelpatio.pl. The Deputy Data Protection Officer is Daniel Stelmaskiewicz.

The personal data provided by you will be processed for the following purposes:

• the performance of services provided by Hotel Patio, pursuant to Article 6(1)(b) of the GDPR;

• administering the database and customer consent clauses, as well as marketing the services and products of the Żagiel Group, within the framework of the legitimate interests pursued by the Joint Controllers, pursuant to Article 6(1)(f) of the GDPR, and on the basis of your consent, pursuant to Article 6(1)(a) of the GDPR.

Your personal data will be stored for the period resulting from the provisions of the Polish Tax Ordinance and the Accounting Act.

Recipients of your personal data may include authorities, institutions and entities authorised under applicable law, as well as entities providing services to the data controllers, including legal, IT, marketing, accounting and human-resources services, and entities participating in the performance of the agreement or service.

You have the right to request access to your personal data from the controllers, as well as rectification, erasure or restriction of processing, the right to object to processing, the right to withdraw your consent at any time and the right to data portability.

You have the right to lodge a complaint with the President of the Personal Data Protection Office.

Providing personal data is voluntary.