Privacy Policy

Privacy Policy

I. Data Controller and definitions

  1. The controller of the personal data of Guests/Users of the Website is: UNIQUE HOME DAWID BULASIŃSKI, +48 690690910, 5213381773.
  2. The Data Controller may be contacted:
    • at the correspondence address: ul. Podchorążych 41/20, 00-722 Warsaw;
    • by e-mail at: rezerwacja@seaview.pl.
  3. Website User – a natural person visiting the website/websites presenting the Offer and enabling the conclusion of an accommodation rental agreement, or using the services or functionalities described in this Privacy and Cookies Policy;
  4. Service Provider – Dawid Bulasiński, UNIQUE HOME DAWID BULASIŃSKI, 5213381773, ul. Podchorążych 41/20, 00-722 Warsaw;
  5. Offer – accommodation offered by the Service Provider for the purpose of concluding an accommodation rental agreement through the Website;
  6. Guest – a natural person with full legal capacity, a legal person or an organisational unit referred to in Article 331 of the Civil Code, concluding an accommodation rental agreement with the Service Provider;
  7. Website – the presentation of the Service Provider’s Offer on the Internet, enabling an Accommodation Rental Agreement to be concluded online;
  8. Newsletter – information, including commercial information within the meaning of the Act of 18 July 2002 on the Provision of Electronic Services (Journal of Laws of 2020, item 344), originating from the Service Provider and sent electronically to the Guest/User; receiving it is voluntary and requires the Guest’s/User’s consent;
  9. Account – a collection of data stored on the Website and in the Service Provider’s IT system concerning a particular Guest/User, as well as reservations made and agreements concluded by that person, through which the Guest/Website User may place orders and conclude agreements;
  10. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC – General Data Protection Regulation.
  1. For the purpose of performing a distance Accommodation Rental Agreement, the Service Provider processes:
    • information concerning the User’s device in order to ensure the proper operation of the services: the computer’s IP address, information contained in cookies or other similar technologies, session data, web browser data, device data and information concerning activity on the Website, including activity on individual subpages;
    • geolocation information, where the Guest/User has consented to the Service Provider accessing their geolocation. Geolocation information is used to provide more personalised offers of products and services;
    • Users’ personal data: first name, surname, registered office address, correspondence address, e-mail address, telephone number, tax identification number, bank account number or other personal data that must be provided in order to complete the purchase and that the Controller requires during the reservation process.
  2. This information does not contain data concerning the identity of Guests/Users; however, when combined with other information, it may constitute personal data. The Controller therefore provides it with the full protection available under the GDPR.
  3. These data are processed pursuant to Article 6(1)(b) of the GDPR for the purpose of providing the service, namely performing an agreement for the provision of electronic services in accordance with the Terms and Conditions, and pursuant to Article 6(1)(a) of the GDPR in connection with consent to the use of specific cookies or other similar technologies, expressed through the appropriate web browser settings in accordance with Telecommunications Law, or in connection with consent to geolocation. The data are processed until the Guest/User finishes using the Website.
  4. The Controller undertakes to implement all measures required under Article 32 of the GDPR. Taking into account the state of technical knowledge, implementation costs and the nature, scope and purposes of processing, as well as the risk of infringement of the rights or freedoms of natural persons of varying likelihood and severity, the Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

III. Marketing activities of the Data Controller

The Data Controller may publish marketing information about its products or services on the Website. Such content is displayed by the Data Controller pursuant to Article 6(1)(f) of the GDPR, meaning in accordance with the Data Controller’s legitimate interest in publishing content relating to the services provided and promotional campaigns in which the Data Controller is involved. At the same time, this activity does not infringe the rights and freedoms of Guests/Users. Guests/Users expect to receive content of a similar nature, may even actively expect it, or it may be the direct purpose of their visit to the Website or its individual pages.

IV. Recipients of Users’ data

The Data Controller discloses Users’ personal data solely to processors acting under concluded data processing agreements for the purpose of providing services to the Data Controller, such as Website hosting and maintenance, IT services, marketing services and public relations services.

V. Transfer of personal data to third countries

  1. The Controller uses tools and services provided by entities belonging to the Google and Meta groups, particularly for analytics, advertising, measuring advertising effectiveness and supporting the functionalities of the Website. As a result of using these services, Users’ personal data may be transferred or made available to recipients located outside the European Economic Area, including in the United States of America.
  2. The transferred data may include, in particular, the IP address, online identifiers, identifiers stored in cookies or similar technologies, device and browser information, data concerning the User’s activity on the Website, visited subpages, interactions with content and advertisements, and information about specific actions performed on the Website, such as submitting a form or making a reservation.
  3. The transfer of data to a third country may take place on the basis of a European Commission adequacy decision pursuant to Article 45 of the GDPR.
  4. Where data are transferred to a recipient in the United States participating in the EU–US Data Privacy Framework, the transfer takes place on the basis of a European Commission adequacy decision. The Controller verifies whether the specific recipient holds a valid and appropriate certification under this programme.
  5. Where an adequacy decision cannot be applied to a particular recipient, the transfer takes place on the basis of appropriate safeguards specified in Article 46 of the GDPR, in particular the standard contractual clauses adopted by the European Commission and, where necessary, additional technical and organisational measures.
  6. In each case, the Controller verifies the scope of the transferred data, the recipient of the data and the legal basis for the transfer.
  7. Information concerning the safeguards applied and the method of obtaining a copy of them may be obtained by contacting the Controller at: rezerwacja@seaview.pl. The copy provided may be appropriately anonymised or limited in order to protect trade secrets and other legally protected information.

VI. Rights of data subjects

  1. Every data subject has the right:
    • to access data pursuant to Article 15 of the GDPR – to obtain confirmation from the Data Controller as to whether their personal data are being processed. Where personal data concerning that person are being processed, the person is entitled to access those data and obtain information concerning the purposes of processing, the categories of personal data, the recipients or categories of recipients to whom the data have been or will be disclosed, the period for which the data will be stored or the criteria used to determine that period, the right to request the rectification or erasure of personal data or restriction of processing, and the right to object to such processing;
    • to receive a copy of the data pursuant to Article 15(3) of the GDPR – to obtain a copy of the data undergoing processing. The first copy is provided free of charge, while the Data Controller may charge a reasonable fee based on administrative costs for any additional copies;
    • to rectification pursuant to Article 16 of the GDPR – to request the rectification of inaccurate personal data concerning the person or the completion of incomplete data;
    • to erasure pursuant to Article 17 of the GDPR – to request the erasure of personal data where the Data Controller no longer has a legal basis for processing them or the data are no longer necessary for the purposes of processing;
    • to restriction of processing pursuant to Article 18 of the GDPR – to request the restriction of the processing of personal data where:
      • the data subject disputes the accuracy of the personal data – for a period allowing the Data Controller to verify the accuracy of the data;
      • the processing is unlawful and the data subject objects to the erasure of the personal data, requesting instead the restriction of their use;
      • the Data Controller no longer requires the data, but they are required by the data subject for the establishment, exercise or defence of legal claims;
      • the data subject has objected to processing – until it has been established whether the legitimate grounds of the Controller override the grounds for the data subject’s objection;
    • to data portability pursuant to Article 20 of the GDPR – to receive personal data concerning the person that they have provided to the Data Controller in a structured, commonly used and machine-readable format, and to request that those data be transmitted to another controller, where the data are processed on the basis of the data subject’s consent or an agreement concluded with that person and the processing is carried out by automated means;
    • to object pursuant to Article 21 of the GDPR – to object, on grounds relating to the person’s particular situation, to the processing of their personal data for the Controller’s legitimate purposes, including profiling. The Data Controller will then assess whether compelling legitimate grounds for the processing exist that override the interests, rights and freedoms of the data subject, or whether grounds exist for the establishment, exercise or defence of legal claims. If the assessment determines that the interests of the data subject override the interests of the Controller, the Data Controller will be required to stop processing the data for those purposes;
    • to withdraw consent at any time without giving a reason. However, personal data processing carried out before the withdrawal of consent will remain lawful. Withdrawal of consent will result in the Data Controller ceasing to process personal data for the purpose for which the consent was given.
  2. To exercise the rights listed above, the data subject should contact the Data Controller using the provided contact details and inform the Controller which right they wish to exercise and to what extent.

VII. President of the Personal Data Protection Office

The data subject has the right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office, with its registered office at ul. Stawki 2 in Warsaw. The authority may be contacted in the following ways:

  1. by post: ul. Stawki 2, 00-193 Warsaw;
  2. through the electronic submission box available at: https://www.uodo.gov.pl/pl/p/kontakt;
  3. helpline: 606-950-0000.

VIII. Data Protection Officer

In every case, the data subject may also contact the Controller’s Data Protection Officer directly by e-mail or in writing at the Data Controller’s address specified in Section I, point 2 of this Privacy and Cookies Policy.

IX. Amendments to the Privacy Policy

The Privacy and Cookies Policy may be supplemented or updated according to the Controller’s current needs in order to provide Guests/Users with up-to-date and reliable information.

X. Cookies

  1. The Website obtains information about Guests, Website Users and their behaviour in the following ways:
    • through information voluntarily entered into forms for purposes resulting from the function of the particular form;
    • through cookies stored on terminal devices;
    • through the collection of web server logs by the hosting operator of the Online Store, which is necessary for the proper functioning of the Website.
  2. Cookies are IT data, particularly text files, that are stored on the terminal device of the Guest/Website User and are intended for using the Website. Cookies usually contain the name of the website from which they originate, the period for which they are stored on the terminal device and a unique number.
  3. The Website uses cookies necessary for the proper functioning of the website without obtaining the User’s consent, to the extent permitted by applicable law. Other cookies, particularly analytical, functional and marketing cookies, are stored or accessed only after the User has given prior consent through the cookie management panel. The User may accept all optional cookies, reject all of them or select individual categories in the settings. Failure to make a selection, closing the notice, scrolling through the website or continuing to use the Website is not considered consent to optional cookies. The User may change or withdraw consent at any time using the permanently available “Cookie settings” link. Withdrawal of consent does not affect the lawfulness of activities carried out before its withdrawal.
  4. To manage cookie settings, select the web browser or operating system from the list below and follow the relevant instructions:
    • Internet Explorer
    • Chrome
    • Safari
    • Firefox
    • Opera
    • Android
    • Safari (iOS)
    • Windows Phone
  5. The legal basis for processing personal data in connection with the use of cookies necessary for the proper and secure operation of the Website is the Controller’s legitimate interest pursuant to Article 6(1)(f) of the GDPR. For optional cookies, particularly analytical, functional and marketing cookies, the legal basis for processing personal data is the User’s consent pursuant to Article 6(1)(a) of the GDPR. Consent may be withdrawn or changed at any time through the cookie management panel.
  6. The Website uses two principal types of cookies: session cookies and persistent cookies. Session cookies are temporary files stored on the Website User’s terminal device until the User logs out, leaves the Website or closes the software, meaning the web browser. Persistent cookies are stored on the Guest’s/Website User’s terminal device for the period specified in the cookie parameters or until they are deleted by the Guest/User.
  7. Cookies are used for the following purposes:
    • creating statistics that help to understand how Guests/Website Users use websites, which makes it possible to improve their structure and content;
    • maintaining the Guest’s/Website User’s session after logging in, so that the Guest/Website User does not have to re-enter their login and password on every subpage of the Website;
    • determining the profile of the Guest/Website User in order to display product recommendations and personalised materials in advertising networks, particularly the Google advertising network.
  8. Web browsing software, meaning the web browser, usually allows cookies to be stored on the Guest’s/User’s terminal device by default. Guests/Users may change their settings in this respect. The web browser makes it possible to delete cookies. It is also possible to block cookies automatically.
  9. Restrictions on the use of cookies may affect some of the functionalities available on the Online Store’s websites.
  10. Cookies placed on the terminal device of the Guest/Website User may also be used by advertisers and partners cooperating with the Website.
  11. Cookies may be used by advertising networks, particularly the Google advertising network, to display advertisements tailored to the way in which the Guest/User uses the Website. For this purpose, they may retain information concerning the Guest’s/User’s browsing path or the amount of time spent on a particular page.
  12. We recommend that the Guest/User read the privacy policies of these companies in order to learn the rules governing the use of cookies used for statistical purposes: Google Analytics Privacy Policy.
  13. Cookies may be used by advertising networks, particularly the Google advertising network, to display advertisements tailored to the way in which the Guest/User uses the Website. For this purpose, they may retain information concerning the User’s browsing path or the amount of time spent on a particular page.
  14. Regarding information about the Guest’s/User’s preferences collected by the Google advertising network, the Guest/User may view and edit information resulting from cookies using the following tool: https://www.google.com/ads/preferences/.
  15. The Website contains plug-ins that may transfer Guests’/Users’ data to controllers such as, for example:
    • Facebook
    • Google
  16. For the proper performance of the distance Accommodation Rental Agreement, the Controller may disclose Guests’/Users’ data to online payment systems. The prepayment methods currently available on the Website are listed at: https://www.idobooking.com/pl/integracja-z-innymi-systemami/systemy-platnosci-zintegrowane-z-idobooking/.

XI. Newsletter

  1. The Guest/User may consent to receiving commercial information electronically by selecting the appropriate option in the registration form or, at a later date, in the appropriate tab. Where such consent has been given, the Guest/User will receive the Website’s information in the form of a Newsletter, as well as other commercial information sent by the Seller, at the e-mail address provided by the Guest/User.
  2. The Guest/User may unsubscribe from the Newsletter at any time by deselecting the appropriate box on their Account page, accessing the relevant form, clicking the appropriate link included in each Newsletter or contacting the Customer Service Office.

XII. Account

  1. The Guest/User may not publish on the Website or provide to the Service Provider any unlawful content, including reviews and other unlawful data.
  2. The Guest/User gains access to the Account after completing the registration process.
  3. During registration, the Guest/User provides the account type or gender, first name, surname, company name, tax identification number, information required to issue a sales document and an e-mail address, and selects a password. The Guest/User confirms that the data provided in the registration form are accurate. Registration requires the Guest/User to carefully read the Terms and Conditions and select a box on the registration form confirming that the Guest/User has read the Terms and Conditions and fully accepts all of their provisions.
  4. When access to the Account is granted, an agreement for the provision of electronic services concerning the Account is concluded between the Service Provider and the Guest/User for an indefinite period.
  5. Registration of an Account on one of the Website’s pages also constitutes registration enabling access to the other pages through which the Website is available.
  6. The Guest/User may terminate the agreement for the provision of electronic services at any time with immediate effect by informing the Service Provider by e-mail or in writing at the Data Controller’s address specified in Section I, point 2 of this Privacy and Cookies Policy.
  7. The Service Provider has the right to terminate the agreement for the provision of services concerning the Account where the Service Provider ceases providing the Website service or transfers it to a third party, where the Guest/User infringes the law or the provisions of the Terms and Conditions, or where the Guest/User has been inactive for a period of six months. The agreement will be terminated subject to a seven-day notice period. The Service Provider may stipulate that the re-registration of an Account will require the Service Provider’s authorisation.
Call