Principles of Data Processing
Przedsiębiorstwo Turystyczne Mazowsze Sp. z o.o., operating under the brand Zdrowotel Łeba (hereinafter “Zdrowotel Łeba”), attaches great importance to respecting the rights of internet users, with particular regard to the right to privacy. The privacy policy presented below explains the principles we apply when collecting and processing personal data.
When collecting and processing personal data, Zdrowotel Łeba adheres to all of the data processing principles set out below and satisfies at least one of the conditions for the lawful processing of personal data for every person whose data is processed by Zdrowotel Łeba.
1.1. Principles relating to the processing of personal data:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
1.2. Conditions for the lawful processing of personal data:
- The data subject has given consent to the processing of their personal data for one or more specific purposes
- Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract
- Processing is necessary for compliance with a legal obligation to which the controller is subject
- Processing is necessary in order to protect the vital interests of the data subject or of another natural person
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
- Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child
1.3. Consent mechanism for data processing
Out of respect for the users of our website and to maintain transparency in processing, as well as to meet GDPR requirements, we have implemented a clear consent mechanism. During your first visit to our website, you will see a banner asking for your consent to:
- The processing of personal data for marketing and analytical purposes
- The use of cookies
- The use of tracking pixels and analytics tags (including Google Analytics)
- Ad personalisation
Consent is voluntary, but withholding it may limit access to certain features of the website.
What data do we collect about you?
Data collected during registration
In order to use certain features offered by the website, you will need to register. During registration, we will ask you for:
- Login and password
- First and last name
- Email address
- Phone number
- Stay details (dates, number of people, preferred services)
You will also be asked to consent to the processing of your personal data by Zdrowotel Łeba. We record every consent given, including the date, time and the text of the notice displayed to you.
Data collected automatically
During your visit to our website, data relating to your visit is collected automatically, in particular:
- Your IP address
- Domain name
- Browser type
- Operating system type
- Information about clicks and on-site behaviour
- Time spent on the website
- The pages that referred you to our website
More information can be found in the section devoted to cookies.
Google Enhanced Conversions
We use Google's Enhanced Conversions feature, which sends Google hashed data (e.g. your email address) submitted in a form. Hashing means the data is encoded in such a way that Google cannot identify you directly. This feature allows conversions to be accurately attributed to advertising campaigns without revealing your identity. Consent to Enhanced Conversions is optional and can be withdrawn at any time.
Ad personalisation and performance measurement
Our website uses Google advertising technologies (Google Ads, Google Analytics, Google Tag Manager), which may collect data for the following purposes:
- Ad personalisation – tailoring ads to your interests based on your previous activity
- Ad performance measurement – tracking whether you clicked on our ad and which actions you took on our website
- Remarketing – displaying our ads to you on other websites you have previously visited
Ad personalisation and performance measurement require consent to data processing and to the use of cookies.
Who is the controller and how to contact the Data Protection Officer
Personal data controller:
Zdrowotel Łeba
ul. Nadmorska 15/17
84-360 Łeba, Poland
The Data Protection Officer is Mr Marek Pióro, CISA, CISM, CGEIT, CRISC, CDPSE.
You can contact the DPO via:
- Email: iod@zdrowotel.pl
- Regular mail: Data Protection Officer, Przedsiębiorstwo Turystyczne Mazowsze Sp. z o.o., ul. Nadmorska 15/17, 84-360 Łeba, Poland
For what purpose and on what basis will data be processed
Your personal data obtained in connection with your use of Zdrowotel Łeba's services will be processed for the following purposes:
- Handling reservations – legal basis: contract
- Conducting marketing activities, including customer acquisition and retention – legal basis: consent
- Selling services – legal basis: contract
- Analyses and statistics related to our business activity – legal basis: the controller's legitimate interest
- Ensuring the security of the website and services – legal basis: the controller's legitimate interest
- Archiving – legal basis: legal obligation or legitimate interest
- Fulfilling legal obligations incumbent on Zdrowotel Łeba – legal basis: legal obligation
- Measuring the effectiveness of advertising campaigns – legal basis: consent (for users from the EEA)
Legal bases for processing
The processing of your data will be carried out on the following legal bases:
- Consent given – for marketing purposes, ad personalisation, campaign performance measurement, and processing of Enhanced Conversions data
- Necessity for the performance of a contract or to take steps at your request prior to entering into a contract
- Necessity for compliance with a legal obligation to which the controller is subject
- The controller's legitimate interest – e.g. responding to your letters and requests, system security
Important: due to GDPR requirements, we must obtain your explicit consent before loading any Google tags or tracking pixels. If you do not give consent, these technologies will not run in your browser.
Who will receive your data and where it will be transferred
Your personal data will not be transferred to third countries or international organisations, unless this results from agreements concluded with us.
Your data may be disclosed to the following entities:
- Data processors in connection with activities commissioned by Zdrowotel Łeba and carried out on its behalf (e.g. IT service providers, vendors)
Google LLC – for the processing of data for the purposes of:
- Website analytics (Google Analytics)
- Ad personalisation and remarketing
- Measuring the effectiveness of advertising campaigns
- Processing Enhanced Conversions
More information on how Google processes data can be found in Google's Privacy Policy: https://business.safety.google/privacy/
- Courier companies – which will deliver shipments
- Law firms – commissioned by Zdrowotel Łeba to conduct proceedings
- Entities or authorities authorised under applicable law
Details regarding Google and transparency:
In accordance with GDPR requirements and Google's EU User Consent Policy guidelines, we hereby confirm that:
- Data may be processed by Google in the United States
- Google processes data under a data processing agreement
- A link to Google's Privacy Policy is available above and in our consent banner
For how long will data be processed
The period for which your personal data is processed depends on the purpose for which it is processed:
- User account management — Duration of the account + 3 years from the last activity
- Archiving of reservations and invoices — 5 years (required by income tax law)
- Debt collection — Claims period + limitation period (6 years)
- Data for marketing purposes — 3 years from the granting of consent or until it is withdrawn
- Cookie data (session identifiers) — Duration of the session or a maximum of 12 months
- Consent logs — 3 years (in accordance with Google's guidelines)
- Enhanced Conversions (hashed data) — 90 days
Additional information: in order to protect Zdrowotel Łeba's legal interests, data may be stored for the period necessary to defend against claims. The retention period is calculated on the basis of: applicable law, account management, the controller's legitimate interest, and the period for which consent was given.
What rights do you have?
You have the following rights regarding your personal data:
1. Right of access
You have the right to request access to your personal data, including information about the purposes of processing, the recipients of the data, and the retention period.
2. Right to rectification
You have the right to request the rectification of inaccurate data and the completion of incomplete data.
3. Right to erasure (“right to be forgotten”)
In certain situations, you may request the erasure of your data, e.g. when:
- The data is no longer needed for the purposes for which it was collected
- You have withdrawn your consent and there is no other legal basis for processing
- You object to the processing
However, this right does not apply if processing is necessary for compliance with a legal obligation.
4. Right to restriction of processing
You may request the restriction of the processing of your data, e.g. while its accuracy is being verified.
5. Right to data portability
You have the right to receive your data in a structured, commonly used format and to transmit that data to another controller.
6. Right to object
You may object to the processing of your data for marketing purposes or for purposes arising from the controller's legitimate interests.
7. Right to withdraw consent
You have the right to withdraw your consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal.
How to exercise your rights
To exercise the rights listed above, please contact us:
- Email: iod@zdrowotel.pl
- Regular mail to: Przedsiębiorstwo Turystyczne Mazowsze Sp. z o.o., ul. Nadmorska 15/17, 84-360 Łeba, Poland, marked “Personal data”
If your data was collected via cookies, we may ask you for additional information to confirm your identity.
Right to lodge a complaint
If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with:
The President of the Personal Data Protection Office (UODO)
ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland
Email: kancelaria@uodo.gov.pl
UODO electronic delivery address: AE:PL-67085-31860-RWFHC-35
Website: https://uodo.gov.pl
What are the consequences of not providing your data?
- Reservation form data – providing this data is a prerequisite for concluding a contract. Without it, the reservation cannot be processed.
- Marketing data – providing this data is voluntary. Not consenting to marketing will not affect your ability to use our core services.
- Cookie and personalisation data – without consent to cookies, the website will still function, but some features may be limited.
How do we profile you?
Zdrowotel Łeba does not use automated decision-making systems that could independently determine your rights or obligations. All decisions concerning your data are made by natural persons.
How can you obtain information about the processing of your data?
Please direct all correspondence regarding the processing of your personal data to:
- Email: iod@zdrowotel.pl
- Regular mail to: Przedsiębiorstwo Turystyczne Mazowsze Sp. z o.o., ul. Nadmorska 15/17, 84-360 Łeba, Poland, marked “Personal data”
Use of cookies
Our website uses cookies, which are used to identify your browser while you use our website. Cookies are small pieces of text that can only be read by the website that sent them. The information collected allows us to learn how often you visit our website, which of its elements interest you the most, and to monitor the security of the website.
We use the data obtained for:
- Better tailoring the website to your needs
- Making the website easier to use and navigate
- Statistical and analytical purposes
- Ad personalisation (with your consent)
- Protection against fraud and abuse
Important: cookies cannot be used to infect your device with viruses or other malicious software (malware).
Each individual cookie consists of four basic parts:
- Website name – the name of the domain or subdomain that set the cookie
- Cookie name – each cookie has a unique name for each website
- Expiry date – session cookies expire when the browser is closed, while persistent cookies expire once a set date is reached
- Value – information the website uses to remember your previous visit
What do we store in cookies?
In cookies, we store:
- User session identifiers
- Preference settings (e.g. language choice)
- Information about the pages viewed and display format
- Identifiers for ad personalisation
- Security tokens
Use of cookies for the purposes of:
- Recognising users logging into protected web pages
- Recording user preferences – browsing content and format
- Recording pages visited – helps us improve content and navigation
- Ad personalisation – displaying ads tailored to your interests
- Measuring campaign effectiveness – tracking conversions and interactions
Types of cookies:
- Necessary cookies — Required for the website to function, for security and preferences. Consent required: No (required by law)
- Analytics cookies — Google Analytics – collecting anonymised data about users. Consent required: Yes
- Marketing cookies — Ad personalisation, remarketing. Consent required: Yes
- Third-party cookies — Meta, LinkedIn, Bing – for marketing purposes. Consent required: Yes
Right to refuse cookies:
You have the right to:
- Refuse to have cookies saved – you can change your browser settings or decline consent in our banner
- Delete cookies – they can be removed via your browser settings
- Block cookies – for specific websites you choose, or for all websites
Note: blocking cookies may result in the loss of certain features that require cookies to be installed, including personalised ads.
Information on managing cookies can be found at: https://www.allaboutcookies.org/manage-cookies/ and https://wszystkoociasteczkach.pl/
We use the following cookies on our website:
- PHPSESSID — expires after: End of session — Session identification and correct display of information
- _ga — expires after: 2 years — Google Analytics – user identifier
- _gid — expires after: 24 hours — Google Analytics – session identifier
- _gat — expires after: 1 minute — Google Analytics – request rate limiting
- GTM-* — expires after: Variable — Google Tag Manager – tag management
- fbp — expires after: 3 months — Facebook Pixel – conversion tracking
- bscookie — expires after: 2 years — LinkedIn – tracking professional users
Additional information: cookies may also be set by our advertising partners. Detailed information about their cookies can be found in their respective privacy policies.
Consent to cookies and personalisation – important information
Consent banner
When you visit our website for the first time (or after clearing your cookies), you will see a banner asking you to consent to:
- Necessary cookies (e.g. for security) – set automatically
- Analytics cookies (Google Analytics) – requires your consent
- Marketing cookies (ad personalisation) – requires your consent
- Third-party cookies – requires your consent
How to give consent
- Click “Accept all” – all cookies will be applied
- Click “Customise” – to choose which cookies to accept
- Click “Reject” – only necessary cookies will be applied
How to withdraw consent
Withdrawing consent is just as easy as giving it:
- Find the “Manage cookies” / “Change settings” link (usually at the bottom of the page or in the settings)
- Change your cookie preferences
- Save your changes
You can also change your consents in your browser settings.
How do we protect your personal data?
Data transmission security
- Communication between your browser and our server is encrypted using the SSL/TLS protocol (Secure Socket Layer / Transport Layer Security)
- The connection is identified by a padlock icon in the URL address bar
- We implement the PCI DSS standard for the protection of credit card data (where applicable)
Database security
- Our databases are protected against access by third parties
- We implement multiple layers of security, including firewalls and monitoring systems
- Only authorised personnel have access to personal data
- We perform regular data backups
Staff security
- Employees undergo training on the protection of personal data
- They are bound by a duty of confidentiality
- Access to data is restricted on the basis of the “least privilege” principle
Security of Google Analytics and other tools
- We apply IP anonymisation when sending data to Google
- Data in Enhanced Conversions is hashed (encrypted)
- We use Google Tag Manager for secure tag management
Changes to our privacy policy
We reserve the right to amend the above privacy policy by publishing a new version on our website. After a change is made, the Privacy Policy will appear on the website with a new date.
Change history:
- 25.05.2018 (version 1.0) — Initial version (GDPR 2018)
- 13.08.2026 (version 2.0) — Updated in line with Google's EU User Consent Policy and changes to the guidelines on ad personalisation, Enhanced Conversions, performance measurement, and consent log retention requirements
Contact
Registered office of the controller:
Przedsiębiorstwo Turystyczne Mazowsze Sp. z o.o.
ul. Nadmorska 15/17
84-360 Łeba, Poland
Phone: +48 59 866 18 70, +48 509 667 369
- Reservations and general enquiries: info@zdrowotel.pl
- Privacy / GDPR: iod@zdrowotel.pl
Social media:
- Facebook: http://facebook.com/ZdrowotelLeba
- Instagram: https://www.instagram.com/zdrowotel.leba/
- YouTube: https://www.youtube.com/@zdrowotel_leba
Appendices
Appendix A – Link to Google's Privacy Policy
In accordance with Google's EU User Consent Policy guidelines, we provide access to information on how Google processes personal data: https://business.safety.google/privacy/
Appendix B – Information on analytics and marketing service providers
- Google LLC — Analytics, Ads, Tag Manager — https://policies.google.com/privacy
- Meta Platforms — Facebook Pixel — https://www.facebook.com/privacy/explanation
- LinkedIn — Insight Tag — https://www.linkedin.com/legal/privacy-policy
- Microsoft — Bing Ads — https://privacy.microsoft.com/en-us/privacystatement
Łeba, 13 August 2026
This Privacy and Cookie Policy has been approved by the Data Protection Officer, Marek Pióro, CISA, CISM, CGEIT, CRISC, CDPSE.
This privacy policy applies to all language versions of the Zdrowotel Łeba website (PL, EN, DE, CS) and is binding on all users of the website.