About us
Just Sp. z o.o., with its registered office in Kraków, ul. Bonerowska 7, owner of Willa Carlton (hereinafter referred to as the “Hotel”, “we”, “us” or “our”), is the entity responsible for processing personal data obtained from you or concerning you (“you”, “your”, “Guest”). As our registered office is located within the European Union, we process personal data in accordance with European data protection regulations and other applicable legal provisions. We attach great importance to the privacy of our Guests and other individuals whose personal data is processed by the Hotel.
What is personal data?
Personal data means information that enables your direct or indirect identification as a natural person (“indirectly” meaning in combination with other information), based on elements such as your name and surname, postal address, e-mail address, telephone number, or unique device identifier.
Use of personal data
- The Hotel complies with privacy protection regulations in its operations, including in particular Regulation (EU) 2016/679, commonly referred to as the GDPR. The Hotel strives to ensure that every individual whose personal data is processed receives complete information regarding the scope, purpose, and method of processing, as well as information about their rights. The Controller uses only the data necessary to fulfil each purpose for which personal data is processed. We do not collect or process more personal data, or different categories of personal data, than is necessary to achieve the purposes specified below. We use personal data solely in accordance with this Privacy Policy unless you have provided separate consent for another use of your personal data. If we intend to use your personal data processed on the basis of your consent for purposes other than those specified in that consent, we will inform you in advance and, if you provide the appropriate consent, we will proceed with such processing.
- The Guest’s personal data is processed on the basis of a contract for hotel services concluded between the Guest and the Hotel, or a reservation made by the Guest. The purpose of processing personal data is the provision of hotel services or other similar services requested by the Guest. In addition, the Guest’s personal data may be processed through video surveillance used at the Hotel. The purpose of video surveillance is to ensure the safety and security of Guests and other persons staying at or near the Hotel.
- The Hotel informs you that providing personal data is both a contractual and statutory requirement (for example, when issuing a VAT invoice for services provided). Failure to provide personal data makes it impossible to conclude a contract with the Hotel and may also prevent the issuance of a VAT invoice.
- The Guest’s personal data may also be processed for the purpose of conducting guest satisfaction surveys relating to services provided by the Hotel. The legal basis for processing personal data for this purpose is the Hotel’s legitimate interest (Article 6(1)(f) GDPR). The Hotel has assessed the impact of such activities on privacy and concluded that this processing does not excessively interfere with the Guest’s privacy. Furthermore, this processing aims to improve the quality of services provided by the Hotel, which benefits Guests through a better understanding of their needs. Therefore, the Guest’s interests are not adversely affected.
- The Hotel informs you that personal data will be stored throughout the period during which hotel services are provided, as well as for the duration of limitation periods applicable to potential claims, including tax and civil law claims. Personal data processed through video surveillance will be retained for a period of 30 days unless special circumstances (e.g., an accident) require longer retention.
- If accommodation is booked through an online booking platform, the categories of personal data transferred to the Hotel by such entities may include, in particular, the Guest’s name and surname, stay dates, e-mail address, and telephone number. Information regarding the precise source from which the Hotel obtained the Guest’s personal data may be obtained at Reception.
- We may be required to use and archive personal data for legal and compliance purposes, such as preventing, detecting, and investigating criminal offences, preventing data loss and fraud, and combating other forms of misuse of our services and IT systems. We are also entitled to use your personal data to comply with internal and external audit requirements, ensure information security, protect and enforce our rights, safeguard privacy, ensure the safety of persons and property, and protect the property of others.
Disclosure of personal data
We disclose personal data only to the entities specified below and solely for the purposes described herein, unless you have expressly consented to the transfer of your personal data to other categories of third parties mentioned elsewhere. We take all reasonable steps to ensure that your personal data is processed, protected, and transferred in accordance with applicable law.
External service providers
Where necessary, we engage other companies and individuals to perform specific tasks on our behalf under data processing agreements. We also cooperate with external entities to facilitate the provision of hotel services. These include, in particular:
- Accounting firms – for accounting services and financial settlements;
- Law firms – for pursuing claims arising from hotel service agreements or for legal defence purposes;
- Insurance companies – for concluding insurance agreements and pursuing insurance-related claims;
- IT companies and providers of IT infrastructure support and management services – for hosting our databases and applications and providing technical support services;
- Courier and postal service providers – for the delivery of correspondence.
Personal data disclosed to external service providers is transferred only to the extent necessary to achieve a specific purpose. External service providers may not use the personal data received from us for any other purpose, particularly for their own benefit or the benefit of third parties. They are contractually obliged to maintain the confidentiality of your personal data.
Transfer of assets
In the event of a reorganisation, restructuring, merger, sale, or other transfer of assets (collectively referred to as a “Transfer of Assets”), we may transfer information, including personal data, to the extent permitted and necessary, provided that the receiving party agrees to process your personal data in accordance with applicable data protection laws. We will continue to protect the confidentiality of personal data and will notify affected users if their personal data becomes subject to a different privacy policy.
Public authorities
We disclose your personal data to public authorities where required by applicable law. For example, we respond to requests from courts, law enforcement agencies, regulatory authorities, and other public institutions, including those located outside your country of residence.
Transfer of personal data abroad
In certain circumstances, it may be necessary to transfer your personal data to countries outside the European Union (EU) and the European Economic Area (EEA), referred to as “third countries”. This Privacy Policy also applies where personal data is transferred to third countries, where a different level of data protection may apply than in your country of residence.
Cookie Policy
Cookies are small text files automatically created by a web browser when visiting websites. Cookies typically contain the name of the website from which they originate, the duration of their storage on the user’s device, and a unique identifier.
The Hotel is the entity that places cookies on the user’s device and has access to them.
We use cookies for the following purposes:
- To tailor the content of our website to the individual preferences of users. In particular, these files recognise the user’s device and display the website according to their preferences;
- To compile statistics that help us understand users’ preferences and behaviour. Analysis of these statistics is anonymous and enables us to adapt the content and appearance of the website to prevailing trends. Statistics are also used to assess the popularity of the website;
- To carry out marketing activities.
Our website uses two basic types of cookies: session cookies and persistent cookies. Session cookies are temporary files stored until the user leaves the Hotel website (by visiting another website or closing the browser). Persistent cookies remain stored on the user’s device until they are deleted by the user or until the expiry date specified in their settings.
Users may change their browser settings at any time to block cookies or to receive information each time cookies are placed on their device. Other available options can be found in the settings of the web browser being used. Please note that most web browsers are configured by default to accept cookies.
The Hotel informs users that changes to browser settings may limit access to certain functions of the website. Cookies used by our website and stored on the user’s device may be shared with our partners and cooperating advertisers.
Security
We take data security very seriously. We apply appropriate security measures and implement suitable physical, electronic, and administrative procedures designed to protect the information we collect against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access, or other forms of unlawful processing. Our information security policies and procedures are aligned with widely recognised international standards and are regularly reviewed and updated to reflect business needs, technological developments, and regulatory requirements.
Access to your personal data is granted only to employees, service providers, and entities that have a legitimate business need to access such information or require it in connection with the performance of their duties.
In the event of a personal data breach, we will comply with all applicable legal requirements concerning breach notification.
Your rights
Every data subject has specific rights relating to their personal data. These rights apply throughout the entire data processing lifecycle described in this Privacy Policy. We respect individual rights and address all concerns appropriately.
The following list outlines your rights under applicable data protection legislation:
Right to withdraw consent
Where the processing of personal data is based on your consent, you may withdraw that consent at any time by following the procedure described in the relevant consent form. We ensure that consent can be withdrawn in the same manner in which it was given, for example electronically.
Right to rectification
You may request that we correct personal data concerning you. We make every reasonable effort to ensure that personal data held by us and used on an ongoing basis is accurate, complete, up to date, relevant, and based on the latest available information. Where appropriate, we provide access to self-service portals that enable users to review and correct their personal data.
Right to restriction of processing
You may request restriction of the processing of your personal data where:
- you contest the accuracy of the personal data, for a period enabling us to verify its accuracy;
- the processing is unlawful and you oppose the erasure of the personal data and request the restriction of its use instead;
- we no longer need the personal data for processing purposes, but you require it for the establishment, exercise, or defence of legal claims; or
- you have objected to processing pending verification of whether our legitimate grounds override your rights and interests.
Right of access to personal data
You may request information about your personal data that we hold, including details regarding the categories of personal data processed, the purposes for which it is used, the source from which it was obtained (where not collected directly from you), and the recipients to whom it has been disclosed, where applicable.
You are entitled to receive one copy of your personal data free of charge. We reserve the right to charge a reasonable fee for any additional copies requested.
Right to data portability
Upon your request, we will transfer your personal data to another controller, where technically feasible, provided that the processing is based on your consent or is necessary for the performance of a contract. Instead of receiving a copy of your personal data, you may request that we transmit such data directly to another controller designated by you.
Right to erasure
You may request the deletion of your personal data where:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- you exercise your right to object to further processing and there are no overriding legitimate grounds for processing;
- the processing is based on your consent, you withdraw that consent, and there is no other legal basis for processing;
- the personal data has been processed unlawfully;
- erasure is required to comply with a legal obligation to which we are subject.
The above right does not apply where processing is necessary for compliance with legal obligations, statutory retention requirements, or for the establishment, exercise, or defence of legal claims.
Right to object
You have the right to object, at any time and on grounds relating to your particular situation, to the processing of your personal data where such processing is based on our legitimate interests or the legitimate interests of a third party rather than your consent.
In such circumstances, we will cease processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.
If you object to processing, please specify whether you request the erasure of your data or the restriction of its processing.
Right to lodge a complaint
If you believe that applicable data protection laws have been violated, you have the right to lodge a complaint with the competent supervisory authority in your country of residence or in the country where the alleged infringement occurred.
Time period
We will endeavour to respond to your request within 30 days. However, this period may be extended due to reasons related to the specific right being exercised or the complexity of the request.
Access restrictions
In certain circumstances, we may not be able to provide access to all or part of your personal data due to statutory restrictions. Where access is denied, we will explain the reasons for such refusal.
Inability to identify the data subject
In some cases, we may be unable to identify your personal data based on the identifiers provided in your request. Examples of personal data that we may be unable to locate solely on the basis of your name and e-mail address include data collected through cookies stored in your browser.
Where we are unable to identify you as the data subject, we may be unable to fulfil your request to exercise the rights described in this section unless you provide additional information enabling us to verify your identity.
Exercising your rights
To exercise your rights, please contact us in writing, either by e-mail or by traditional mail. Contact details can be found at the end of this Privacy Policy.
Retention of your personal data
As a general rule, we delete personal data when it is no longer required for the purposes for which it was collected. However, legal obligations may require us to retain certain personal data for a longer period.
We may also retain limited information where you have requested that we no longer contact you in the future. In such cases, we maintain suppression records containing information about individuals who do not wish to receive communications from us (for example newsletters or marketing e-mails). We consider such requests as consent to retain the necessary information for this purpose unless instructed otherwise by you.
Changes to this Privacy Policy
We reserve the right, at our sole discretion, to modify our privacy practices and to amend this Privacy Policy at any time. For this reason, we encourage you to review this Privacy Policy regularly.
This Privacy Policy is effective as of the date indicated as the “last updated” date. If you do not have an account on our website, we will notify you of any material changes by e-mail or traditional mail and provide you with the updated version of the Privacy Policy.
We undertake to process your personal data in accordance with the Privacy Policy under which the data was originally collected unless we obtain your consent to process it differently.
Contact information
For any questions relating to data protection or requests concerning the exercise of your rights, please contact:
Adrian Gubała
E-mail: ag@carlton.pl