zdjęcie przedtawiające Villa la Roca
Villa La Roca Garden & Spa

Privacy Policy

 1. General Information

  1. This policy applies to the website functioning under the URL address: villalaroca.pl
  2. The website operator and data administrator is Apart-Center Agnieszka Bourgeois, based in Zakopane, ul. Pardałówka 32/6, 34-500 Zakopane, registered under the business number NIP 7361469874, REGON 120773226.
  3. Contact email address of the operator: kontakt@villalaroca.pl
  4. The operator is the Administrator of your personal data provided voluntarily on the website.
  5. The website uses personal data for the following purposes:
    • Conducting online chat conversations
    • Handling inquiries via forms
    • Presentation of offers or information
  6. The website collects information about users and their behavior in the following ways:
    1. Through voluntarily provided data entered into forms, which are added to the operator's systems.
    2. Through cookies stored on the user's devices.

2. Selected Data Protection Methods Used by the Operator

  1. Login areas and personal data entry points are protected by transmission encryption (SSL certificate). This ensures that personal data and login details entered on the website are encrypted on the user’s device and can only be read on the target server.
  2. Personal data stored in the database is encrypted so that only the operator with the decryption key can access it, protecting the data in case of database theft.
  3. User passwords are stored in a hashed form. The hashing function is one-way, ensuring passwords cannot be reversed, which is a modern standard for storing user passwords.
  4. The operator periodically changes administrative passwords.
  5. To ensure data protection, the operator regularly performs backups.
  6. An essential element of data protection is the regular update of all software used by the operator for processing personal data, particularly updating software components.

3. Hosting

  1. The website is hosted (technically maintained) on servers provided by Hostido.pl
  2. The hosting provider ensures technical reliability and keeps server logs, which may include:
    • Resources identified by URL (addresses of requested resources – pages, files)
    • Time of request
    • Time of response
    • Name of the client's station – identified through the HTTP protocol
    • Information about errors that occurred during HTTP transactions
    • The URL of the page previously visited by the user (referrer link) if the transition to the website was via a link
    • Information about the user's browser
    • IP address information
    • Diagnostic information related to the process of independently ordering services through recorders on the website
    • Information related to email communication directed to and sent by the operator

4. Your Rights and Additional Information on Data Usage

  1. In some cases, the Administrator has the right to transfer your personal data to other recipients if it is necessary to execute a contract with you or to fulfill obligations imposed on the Administrator. This includes the following groups of recipients:
    • Hosting providers (based on delegation agreements)
    • Operators of online chat solutions
    • Authorized employees and collaborators who use the data to fulfill the website's purpose
    • Companies providing marketing services for the Administrator
  2. Your personal data is processed by the Administrator no longer than necessary to perform actions related to it, as specified by separate regulations (e.g., for accounting purposes). For marketing-related data, it will not be processed for longer than three years.
  3. You have the right to request from the Administrator:
    • Access to your personal data
    • Correction of your data
    • Deletion of your data
    • Restriction of data processing
    • Data portability
  4. You have the right to object to data processing under point 3.2 related to the processing of your personal data for the legitimate interests pursued by the Administrator, including profiling, unless there are valid, legally justified grounds for processing overriding your interests, rights, and freedoms, particularly for establishing, pursuing, or defending claims.
  5. You have the right to file a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.
  6. Providing personal data is voluntary but necessary for the operation of the website.
  7. Automated decision-making, including profiling, may be applied to you to deliver services under the contract and for direct marketing by the Administrator.
  8. Personal data is not transferred to third countries as defined by personal data protection regulations. This means we do not transfer it outside the European Union.

5. Information in Forms

  1. The website collects information provided voluntarily by users, including personal data if supplied.
  2. The website may store information about connection parameters (timestamp, IP address).
  3. In some cases, the website may store information linking data in forms with the email address of the user filling out the form. In such cases, the user's email address appears within the URL of the page containing the form.
  4. Data entered into the form is processed for purposes resulting from the function of the specific form, such as handling service requests, business inquiries, or registering services. The context and description of each form clearly state its purpose.

6. Administrator Logs

  1. Information on user behavior on the website may be logged. This data is used for website administration.

7. Essential Marketing Techniques

  1. The operator uses Google Analytics (Google Inc., USA) for statistical traffic analysis. No personal data is transferred to this service, only anonymized information. The service uses cookies stored on the user's device. Users can view and edit their preferences for information gathered by Google's advertising network via: https://www.google.com/ads/preferences/
  2. The operator uses Facebook Pixel technology. This allows Facebook (Facebook Inc., USA) to identify a registered user using the website. This service is based on cookies, and no additional personal data is shared with Facebook.

8. Cookie Information

  1. The website uses cookies.
  2. Cookies are small text files stored on the user's device designed to help use the website. They typically include the website's name, storage duration, and a unique identifier.
  3. The website operator is responsible for placing cookies and accessing them.
  4. Cookies are used for:
    1. Maintaining user sessions (after logging in) to avoid re-entering login and password details on each subpage.
    2. Achieving objectives specified in "Essential Marketing Techniques."
  5. There are two main types of cookies used on the website: "session" cookies (temporary files stored on the user's device until they log out, leave the website, or close the browser) and "persistent" cookies (stored on the user's device for the time specified in the cookie parameters or until manually deleted).
  6. Web browsers usually allow cookie storage by default. Users can change settings to block cookies or remove them. Detailed information can be found in the browser's help documentation.
  7. Limiting the use of cookies may affect certain functionalities of the website.
  8. Cookies may also be used by third-party services such as Google, Facebook, or Twitter.

9. Managing Cookies – How to Express and Withdraw Consent?

  1. If the user does not want to receive cookies, they can change their browser settings. Blocking cookies necessary for authentication, security, or user preferences may hinder website functionality.
  2. To manage cookie settings, select your browser from the list below and follow the instructions:
  3. Mobile devices:

 

Przewodnik po okolicy