WEBSITE PRIVACY POLICY
IMBACHHORN.EU
§ 1
GENERAL PROVISIONS
- The administrator of the personal data collected via the imbachhorn.eu online shop is Pension Imbachhorn ESKO Kotowski KG, Zeller Fusch 79, A-5672 Fusch a.d. Großglocknerstraße, NIP/UID: ATU61614658, electronic mail address (e-mail): info@imbachhorn.eu, hereinafter referred to as "Administrator".
- The personal data collected by the Administrator through the website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the RODO.
§ 2
THE TYPE OF PERSONAL DATA PROCESSED, THE PURPOSE AND SCOPE OF DATA COLLECTION
- PURPOSE OF PROCESSING AND LEGAL BASIS. The controller processes the personal data of imbachhorn.eu users in case:
- registration of an account on the website, in order to create and manage an individual account, on the basis of Article 6(1)(b) of the RODO (performance of a contract for the provision of electronic services in accordance with the Shop Regulations),
- making a booking on the website, for the purpose of performing the contract for the provision of travel services, on the basis of Article 6(1)(b) of the DPA (performance of the contract),
- THE TYPE OF PERSONAL DATA BEING PROCESSED. In the case of:
- account the user states:
- Name,
- Login,
- Address,
- Email address.
- booking user states:
- Name,
- Address,
- Email address,
- Phone number.
- account the user states:
- ARCHIVING PERIOD FOR PERSONAL DATA. Your personal data is stored by the Administrator:
- where the processing is based on the performance of a contract, for as long as is necessary for the performance of the contract and thereafter for a period corresponding to the period of limitation of claims. Unless specifically provided otherwise, the period of limitation shall be ten years, and for periodic performance claims and claims related to the conduct of business, three years.
- where the basis for data processing is consent, for as long as the consent is not revoked, and after revoking the consent for a period of time corresponding to the period of limitation of claims which the Administrator may raise and which may be raised against him. Unless a specific provision provides otherwise, the period of limitation shall be ten years, and for claims for periodic performance and claims related to the conduct of business activity - three years.
- When using the website, additional information may be collected, in particular: the IP address assigned to the user's computer or the external IP address of the internet provider, domain name, browser type, access time, operating system type.
- Navigation data may also be collected from users, including information about the links and references they choose to click on or other actions they take on the website. The legal basis for such activities is the Administrator's legitimate interest (Article 6(1)(f) RODO) in facilitating the use of services provided electronically and in improving the functionality of these services.
- The provision of personal data by the user is voluntary.
- Personal data will also be processed in an automated manner in the form of profiling, provided that the user consents to this on the basis of Article 6(1)(a) RODO. The consequence of profiling will be the assignment of a profile to a person in order to make decisions concerning him or her or to analyse or predict his or her preferences, behaviour and attitudes.
- The controller shall take special care to protect the interests of the data subjects and, in particular, shall ensure that the data it collects are:
- processed in accordance with the law,
- collected for specified, legitimate purposes and not subjected to further processing incompatible with those purposes,
- Substantially correct and adequate in relation to the purposes for which they are processed and kept in a form which permits identification of data subjects for no longer than is necessary to achieve the purpose of the processing.
§ 3
SHARING OF PERSONAL DATA
- Users' personal data are transferred to the service providers used by the Administrator in the operation of the website. The service providers to whom personal data is transferred, depending on the contractual arrangements and circumstances, are either subject to the Administrator's instructions as to the purposes and means of processing such data (processors) or determine the purposes and means of processing themselves (controllers).
- Your personal data is stored exclusively in the European Economic Area (EEA).
§ 4
THE RIGHT TO CONTROL, ACCESS AND RECTIFY THEIR OWN DATA
- The data subject has the right of access to the content of their personal data and the right to rectification, erasure, restriction of processing, the right to data portability, the right to object, the right to withdraw consent at any time without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal.
- Legal basis of the user's request:
- Access to data - Article 15 RODO
- Rectification of data - Article 16 RODO.
- Deletion of data (so-called right to be forgotten) - Article 17 RODO.
- Restriction of processing - Article 18 RODO.
- Data portability - Article 20 RODO.
- Objection - Article 21 RODO
- Withdrawal of consent - Article 7(3) RODO.
- In order to exercise the rights referred to in point 2, you may send an e-mail to the following address: info@imbachhron.eu.
- If the user makes a request for fulfilment of his/her rights under the above mentioned rights, the Administrator shall either comply with the request or refuse to comply with it immediately, but no later than within one month after receiving the request. However, if - due to the complexity of the request or the number of requests - the Administrator is not able to comply with the request within one month, it shall comply with the request within the following two months, informing the user in advance, within one month of receiving the request, of the intended extension of the deadline and the reasons for it.
- If it is established that the processing of personal data violates the provisions of the RODO, the data subject has the right to lodge a complaint with the President of the Data Protection Authority.
§ 5
COOKIES
- The Administrator's website uses "cookies".
- The installation of cookies is necessary for the proper provision of services on the Administrator's website. Cookies contain information necessary for the proper functioning of the website, and they also provide the possibility of compiling general statistics on website visits.
- The website uses two types of "cookies": "session" and "permanent".
- "Session" cookies are temporary files that are stored on the user's terminal equipment until the user logs out (leaves the website).
- "Permanent" cookies are stored on the user's terminal equipment for the duration specified in the parameters of the cookies or until they are deleted by the user.
- The administrator uses its own cookies to better understand how users interact with the content of the website. The cookies collect information about the user's use of the website, the type of website from which the user was redirected, and the number of visits and the length of the user's visit to the website. This information does not record specific personal data about the user, but is used to compile statistics on the use of the website.
- The administrator uses external cookies to collect general and anonymous statistical data via the analytical tool Google Analytics (external cookie administrator: Google Inc., based in the USA).
- The user has the right to decide on the access of "cookies" to his/her computer by selecting them in advance in his/her browser window. Detailed information on the possibility and handling of cookies is available in the settings of your software (browser).
§ 6
FINAL PROVISIONS
- The controller shall apply technical and organisational measures to ensure the protection of the processed personal data appropriate to the risks and categories of data protected, and in particular to protect the data against their access to unauthorised persons, against their being taken by an unauthorised person, against their being processed in violation of the applicable regulations, and against their alteration, loss, damage or destruction.
- The administrator shall make available appropriate technical measures to prevent the acquisition and modification by unauthorised persons, of personal data sent electronically.
- In matters not covered by this Privacy Policy, the provisions of the RODO and other relevant provisions of Polish law shall apply accordingly.