Privacy Policy

1. OUR GOAL:

1.1. As of May 25, 2018, the applicable regulations regarding the protection of personal data have changed; the current regulations on the protection of personal data are set forth in the General Data Protection Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: the General Data Protection Regulation, “GDPR”).

1.2. This Privacy Policy is a set of rules intended to inform you about aspects of the process related to the collection, processing, and security of your personal data.

2. SCOPE OF THE PRIVACY POLICY:

2.1. This Privacy Policy sets forth the rules for processing data collected via the website www.warsawquest.pl, which belongs to our Travel Portal operating at the domain www.warsawtour.pl, when individuals perform activities such as: browsing the website’s content, taking a quiz.

2.2. All actions taken by the Controller are subject to the laws generally applicable in Poland, including those relating to the protection of personal data, in particular the General Data Protection Regulation (GDPR).

2.3. The Administrator ensures the transparency of data processing and places particular emphasis on ensuring that data is collected only to the extent necessary for the specified purpose and processed only for as long as necessary.

3. SECURITY MANAGEMENT:

3.1. The controller—taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing, as well as the risk of varying likelihood and severity of harm to the rights and freedoms of natural persons – shall implement appropriate technical and organizational measures to ensure the protection of the personal data being processed, appropriate to the risks and the category of data being protected, and in particular shall protect the data against unauthorized access, unauthorized removal, processing in violation of applicable laws, and alteration, loss, damage, or destruction.

4. PERSONAL DATA CONTROLLER:

4.1. The personal data controller, i.e., the entity that independently determines the purposes and means of processing personal data, is the Director of the Warsaw Tourist Office, with its registered office in Warsaw.

4.2. You can contact the Controller:

a) by mail to the following address: Pl. Defilad 1 (10th floor), 00-901 Warsaw;
b) by email: sekretariat@warsawtour.pl

5. DATA PROTECTION OFFICER:

5.1. The Controller has appointed a Data Protection Officer; you can contact them:

a) by email: iod@warsawtour.pl;
b) by phone: 22 656 64 86.

6. RULES FOR PROCESSING PERSONAL DATA COLLECTED DURING THE USER’S ACTIVITY ON THE TOURISM PORTAL:

6.1 What data we process:

a) Your device’s IP address, request URL, domain name, device ID, browser type, browser language, number of clicks, time spent on the website, date and time of use of the Tourism Portal, operating system type and version, screen resolution, data collected in server logs, and other similar information.

b) The information collected may constitute personal data and be stored in cookies or similar technologies that you use while visiting our Portal. As a general rule, the cookies we use, or the data stored in access logs, are not used to intentionally identify the user.

6.2 Data sources and the purpose of their processing:

a) cookies:

• Cookies are small text files stored on a user’s computer or other mobile device while the user is active on the Internet;
• These files are used for technical and security purposes and allow for customization, such as remembering visits to the website and the user’s preferences regarding that website (including the website’s language, color, font size, layout, content placement, and other similar features that facilitate interaction with the website). Cookies provide us with, among other things, statistical information about user traffic, their activity, and how the Portal is used.
• We do not use cookies to remember user preferences or to personalize our Portal in terms of content display or ad targeting;
• Cookies allow us to collect data such as IP address, operating system type, and browser type;
• Cookies are not harmful to your computers or smartphones—they do not affect how they operate, nor do they cause configuration changes in end devices or in the software installed on those devices;

b) access logs:

• The Administrator collects information regarding the use of the Portal by its users based on the analysis of access logs. This information is collected for purposes related to the administration of the Tourism Portal; in particular, it is used to identify server-related issues, analyze potential security breaches, and manage the Portal. The following data is obtained from the above-mentioned source:
• the IP address of the computer from which the request originated;
• the time the request was received;
• the first line of the HTTP request;
• the HTTP response code;
• the number of bytes sent by the server;
• the URL of the page previously visited by the user (referrer link) – in the event that the user accessed the Portal via a link;
• information about the user’s browser;
• information about errors that occurred during the execution of the HTTP transaction;
• for statistical purposes, i.e., to collect and analyze demographic data of visitors to the Tourism Portal (e.g., information about the region from which the connection was made), IP addresses are collected.  Based on the information obtained in the manner described above, in specific cases, aggregate, general statistical reports are compiled, including information about the traffic on our Portal. These reports do not contain data that allows for identification (determining your identity).

6.3 Tools used:

a) Cookies also allow us to generate anonymous statistics on visitors to our Portal. For this purpose, the Administrator uses the services of third parties. On our Portal, we use the Google Analytics tool provided by Google Inc. (“Google”), headquartered in the USA. Information generated by cookies regarding your use of the Portal, which is described here: https://policies.google.com/privacy?hl=pl, is transmitted to and stored on a Google server in the United States. The data collected for the aforementioned purpose allows, among other things, for:

• monitor traffic on our tourism Portal;
• collect anonymous, aggregate statistics that help us understand how users interact with our Portal, enabling us to improve its structure and content.

6.4 Social media plugins:

a) Our Portal uses so-called social media plugins, specifically those that redirect to platforms such as Facebook, Twitter, Instagram, and YouTube. By using these features, you can share or recommend content posted on our Portal. However, using the above-mentioned features may result in social media platforms collecting your data; specifically, the service obtains information that a user is visiting our travel Portal from a specific IP address or device ID. This may occur regardless of whether the user is a subscriber to the service or not, and whether they are currently logged into the social media platform.

6.5 Legal basis for the processing of personal data:

a) The legal basis authorizing us to process your personal data is:
• our legitimate interest (Article 6(1)(f) of the GDPR) – consisting in facilitating the use of services provided electronically and improving functionality, as well as establishing, pursuing, and enforcing claims and defending against claims in proceedings before courts and other state authorities.

6.6 Retention period for personal data:

a) Your personal data will be stored for the period necessary to achieve the purposes specified in sections 6.2–6.3, and thereafter for the period and to the extent required by generally applicable law.

6.7 Voluntary provision of data:

a) Please note that you have the option to manage the “cookies” used by us or by third-party providers yourself by changing your web browser settings. Restricting the use of cookies on a given device prevents or significantly hinders the proper use of our Portal. Detailed information on settings and disabling cookies in individual browsers is provided by the browser developers on their websites;

b) Please note that you can prevent the collection of data obtained through cookies and data (including your IP address) related to your use of the website by Google, as well as prevent the processing of such data by Google, by downloading and installing the browser plugin available at the following link: https:// tools.google.com/dlpage/gaoptout?hl=pl;

c) please note that if you are logged into a given social media platform, that platform may automatically associate your visit to the Portal with your user profile. The same applies when you share (“like” , “recommend,” etc.) specific content from our site. Logging out of a given service while visiting the Portal will prevent that social media service from associating your visit with a specific account.

7. LINKS TO OTHER ENTITIES’ WEBSITES:

7.1. The websites of entities cooperating with the Administrator, in particular those operating under the domains: www.warsawconvention.pl, http://wot.waw.pl/, as well as other websites linked to on the tourism portal www.warsawtour.pl, are subject to their own privacy policies (including regarding the use of cookies). We encourage you to review the privacy provisions posted on the websites to which the links lead.

8. PROCESSING OF PERSONAL DATA OF INDIVIDUALS CONTACTING THE CAPITAL CITY TOURISM OFFICE VIA E-MAIL OR BY PHONE:

8.1 Purpose of personal data processing:

a) We process the personal data you provide when contacting us in order to respond to your inquiries, as well as, if necessary, to pursue claims and defend against claims;

8.2 What data we process:

a) When you contact us, we process the following personal data: email address, first and last name, possibly phone number, and job title;

8.3 Legal basis for data processing:

a) The legal basis authorizing us to process your personal data is our legitimate interest (Article 6(1)(f) of the GDPR)—consisting of communicating with users of the Travel Portal and defending against potential claims;

8.4 Data retention period:

a) Your data will be processed for no longer than is necessary to respond to you; after that time, it may be processed for the duration of the statute of limitations for any potential claims;

8.5 Voluntary provision of personal data:

a) When contacting us, the provision of your data is voluntary but necessary to answer your question.

9. ENTITIES TO WHICH PERSONAL DATA IS DISCLOSED:

9.1 In each case, the list of recipients of your personal data processed by the Controller is primarily determined by the scope of services you use. The list of data recipients is also based on your consent or legal provisions and is further specified as a result of actions you take while using our Travel Portal.

a) Your data is processed on behalf of the Controller by entities providing the Controller with advisory, consulting, auditing, legal, marketing, hosting, or ICT services, as well as software or hardware maintenance services used by the Controller, and entities supplying software, including systems for analyzing traffic on the Portal;

b) in connection with the use of so-called social media plugins, the result of your use of these links is that the aforementioned social media platforms are able to collect data, e.g., stored in cookies;

c) in connection with the Administrator’s use of the Google Analytics tool, your data may be transferred to Google Inc. (“Google”), headquartered in the U.S.;

d) to the extent necessary and in situations where required by mandatory legal provisions, and in a manner consistent with such provisions, your data, in particular your IP address, is made available to law enforcement agencies, regulatory authorities, and other public administration bodies (e.g., the Public Prosecutor’s Office, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection).

10. TRANSFER OF DATA OUTSIDE THE EEA:

10.1 Your personal data will be transferred outside the European Economic Area to Google Inc., based in the USA. The transfer will be based on data protection safeguards approved by the European Commission.

11. AUTOMATED DECISION-MAKING

11.1 The information collected by the Controller in connection with your activity on our Portal may be processed in an automated manner (including through profiling); however, this will not have any legal consequences for you as a natural person or otherwise significantly affect your situation.

11.2 The Administrator does not subject your data to automated decision-making.

12. RIGHTS OF DATA SUBJECTS:

To exercise the rights listed below, as well as for any questions regarding the scope and exercise of these rights, please contact us (contact details for the Controller and the Data Protection Officer are provided in sections 4 and 5 of the Privacy Policy). We reserve the right to exercise the following rights only after positively verifying the identity of the person requesting the action. The Controller will provide information regarding actions taken in accordance with the data subject’s request within one month of receiving it. If it is necessary to extend this deadline, the Controller will inform the aforementioned person of the reasons for the delay.

12.1 Right of access to your personal data (Article 15 of the GDPR):

a) You have the right to obtain from the Controller confirmation as to whether personal data concerning you are being processed, and if so, you have the right to obtain:

• access to your personal data;
• information regarding the purposes of processing, the categories of personal data being processed, the recipients or categories of recipients of such data, the planned retention period, and, if this is not possible, the criteria for determining that period, your rights under the GDPR, and your right to lodge a complaint with a supervisory authority, the source of such data, automated decision-making, including profiling, and the safeguards applied in connection with the transfer of such data outside the European Union;
• a copy of the personal data being processed.

12.2 the right to request the rectification of your personal data (Article 16 of the GDPR):

a) this right includes your right to:

• request that the Controller immediately rectify personal data that is inaccurate;
• request that incomplete personal data be completed, including by providing an additional statement (the request must take into account the purposes of processing).

12.3 Right to request the erasure of your personal data (Article 17 of the GDPR):

a) You have the right to request that the Controller erase your personal data, and the Controller is obligated to erase the personal data without undue delay if one of the following circumstances applies:

• the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
• the consent on which the processing is based has been withdrawn, in accordance with Article 6(1)(a) or Article 9(2)(a) of the GDPR, and there is no other legal basis for the processing;
• the personal data has been processed unlawfully;
• the personal data must be erased to comply with a legal obligation under Union law or the law of the Member State to which the controller is subject;
• the personal data has been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR (services offered directly to a child).

b) the right to be forgotten is not absolute—it is limited to the extent specified in Article 17(3) of the GDPR.

12.4 The right to request restriction of the processing of your personal data (Article 18 of the GDPR):

a) Restriction of the processing of personal data consists in limiting the processing of data solely to its storage. Processing of data beyond its storage is possible only if one of the following conditions applies:

• you have given your consent;
• for the establishment, exercise, or defense of legal claims;
• for the protection of the rights of another natural or legal person;
• for reasons of substantial public interest of the Union or of a Member State;

b) The controller is required to restrict the processing of personal data if one of the following conditions applies:

• the data subject challenges the accuracy of the personal data, in accordance with Article 16 of the GDPR; in such a case, the restriction of processing takes effect automatically, for a period allowing the controller to verify the accuracy of such data;
• the data subject objects to the erasure of personal data processed unlawfully (there is no legal basis for processing under Article 6 or Article 9 of the GDPR), requesting instead that its use be restricted;
• the data subject requests that the data controller restrict the processing of data which, in accordance with the principle of data retention limitation, should be erased but which the data subject needs to establish, assert, exercise, or defend legal claims to which that person is entitled or against whom such claims are made;
• an objection has been raised against the processing of personal data in accordance with Article 21(1) of the GDPR; in such a case, the restriction of processing takes effect automatically, for a period allowing the controller to determine whether the controller’s legitimate grounds override the grounds for the objection of the to whom the data relates, i.e., for the time needed to determine whether the objection is justified.

12.5 Right to data portability (Article 20 of the GDPR):

a) You may exercise your right to data portability if both of the following conditions are met:

• the data processing is based on consent (Article 6(1)(a) or Article 9(2)(a) of the GDPR) or for the performance of a contract (Article 6(1)(b) of the GDPR);
• the data processing is carried out by automated means;

b) The Controller provides the data you have supplied in a machine-readable format;

c) it is also possible to request that this data be transferred to another entity, provided that the technical capabilities exist for this purpose on the part of both the Controller and that other entity. Direct transmission of data from one controller to another may take place when communication between the two systems is possible in a secure manner and when the receiving system has the technical capability to receive the incoming data.

12.6 Right to object to the processing of your personal data (Article 21 of the GDPR):

a) You have the right to object at any time to the processing of your personal data:

• which is based on a legitimate interest pursued by the Controller (Article 6(1)(f) of the GDPR), including standard profiling, for reasons related to your particular situation;
• for direct marketing purposes, at any time, to the extent that the processing is related to such direct marketing;

b) the consequence of objecting to the processing of personal data, which is carried out on the basis of the Controller’s legitimate interest, is a prohibition on further processing of the data. However, the Controller is entitled to assess whether there are valid legal grounds for processing that override the interests, rights, and freedoms of the data subject, or grounds for establishing, pursuing, or defending claims. If the above situations apply, the Controller may continue to process the data subject to the objection. If you disagree with the Controller’s assessment, you may exercise your right to lodge a complaint with a supervisory authority;

c) The consequence of objecting to the processing of personal data for direct marketing purposes is a prohibition on further processing of the data for that purpose. Therefore, despite the objection, further processing of the data for other purposes is permitted, such as, in particular, the pursuit of claims against the data subject.

12.7 Right to withdraw consent (Article 7(3) of the GDPR):

a) you have the right to withdraw your consent at any time;

b) the effect of withdrawing consent is that personal data may no longer be processed in the future on that basis. However, the withdrawal of consent does not affect the lawfulness of the processing of personal data carried out on the basis of consent prior to its withdrawal.

12.8 Right to lodge a complaint with the supervisory authority, i.e., the President of the Personal Data Protection Office:

a) You have the right to lodge a complaint with the supervisory authority responsible for personal data protection.

13. CHANGES TO THE PRIVACY POLICY:

13.1 Due to continuous technological development and progress, this privacy policy is reviewed on an ongoing basis and updated as necessary.

13.2 You will be notified of any changes to the privacy policy 7 days in advance by the publication of the new version of the document on our Travel Portal.

13.3 The current version of the privacy policy is effective as of July 20, 2018