Privacy Policy

This Privacy Policy sets out the rules for storing and accessing data on User Devices using the Service for electronic service provision by the Administrator and the rules for collecting and processing personal data provided by Users voluntarily through the tools available in the Service.

This Privacy Policy is an integral part of the Terms of Service, which defines the rules, rights, and obligations of Users using the Service.

§1 Definitions

  • Service - the "GuideTravio.com" website operating at https://GuideTravio.com

  • External Service - websites of partners, service providers, or service recipients cooperating with the Administrator

  • Service/Data Administrator - the Administrator of the Service and Data (hereinafter Administrator) is "SoftEnd Kamil Rodak", located at: Bożnów 107, 68-100 Żagań, with a tax identification number (NIP): 9241889830, providing electronic services through the Service

  • User - a natural person for whom the Administrator provides services electronically via the Service.

  • Device - an electronic device with software through which the User gains access to the Service

  • Cookies - text data collected in the form of files placed on the User's Device

  • GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

  • Personal Data - means information about an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person

  • Processing - means an operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction

  • Restriction of Processing - means the marking of stored personal data with the aim of limiting their processing in the future

  • Profiling - means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements

  • Consent - the data subject's consent means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her

  • Data Breach - means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed

  • Pseudonymization - means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person

  • Anonymization - Data anonymization is an irreversible process of data operations that destroys or alters "personal data" to prevent identification or association of a particular record with a specific user or individual.

§2 Data Protection Officer

Pursuant to Art. 37 GDPR, the Administrator has not appointed a Data Protection Officer.

For matters concerning data processing, including personal data, please contact the Administrator directly.

§3 Types of Cookies

  • Internal Cookies - files placed and read from the User's Device by the Service's telecommunication system

  • External Cookies - files placed and read from the User's Device by telecommunication systems of External Services. Scripts of External Services that can place cookies on the User's Device have been consciously placed in the Service through scripts and services made available and installed in the Service

  • Session Cookies - files placed and read from the User's Device by the Service during one session of that Device. After the session ends, the files are deleted from the User's Device.

  • Persistent Cookies - files placed and read from the User's Device by the Service until they are manually deleted. The files are not deleted automatically after the Device session ends unless the User's Device configuration is set to delete cookies after the Device session ends.

§4 Data Storage Security

  • Storage and Reading Mechanisms of Cookies - Storage, reading, and data exchange mechanisms between Cookies saved on the User's Device and the Service are implemented through built-in web browser mechanisms and do not allow other data to be downloaded from the User's Device or other websites visited by the User, including personal data or confidential information. It is also practically impossible to transfer viruses, trojans, and other worms to the User's Device.

  • Internal Cookies - Cookies used by the Administrator are safe for Users' Devices and do not contain scripts, content, or information that could threaten the security of personal data or the security of the Device used by the User.

  • External Cookies - The Administrator takes all possible actions to verify and select Service partners in the context of User security. The Administrator selects known, large partners with global social trust. However, he does not have full control over the content of cookies from external partners. The Administrator is not responsible for the security of cookies, their content, and their legitimate use by scripts installed in the Service from External Services, to the extent permitted by law. The list of partners is included in the further part of the Privacy Policy.

  • Cookie Control

  • User Risks - The Administrator uses all possible technical measures to ensure the security of data placed in cookies. However, the security of these data depends on both parties, including the User's activities. The Administrator is not responsible for data interception, impersonation of the User's session, or their deletion as a result of the User's conscious or unconscious activity, viruses, trojans, and other spyware that may or may have been infected the User's Device. Users should follow the recommendations for safe internet use to protect against these threats.

  • Storage of Personal Data - The Administrator ensures that all efforts are made to ensure the security of personal data voluntarily entered by Users, access to them is limited and carried out in accordance with their purpose and processing goals. The Administrator also ensures that all efforts are made to secure the data from loss through appropriate physical and organizational safeguards.

  • Password Storage - The Administrator states that passwords are stored in an encrypted form using the latest standards and guidelines in this regard. Decryption of passwords provided in the Service is practically impossible.

§5 Purposes of Using Cookies

  • Improving and facilitating access to the Service
  • Personalizing the Service for Users
  • Enabling login to the Service
  • Marketing, Remarketing in external services
  • Ad serving services
  • Affiliate services
  • Statistics (users, visits, device types, connection, etc.)
  • Serving multimedia services
  • Providing social networking services

§6 Purposes of Processing Personal Data

Personal data voluntarily provided by Users is processed for one of the following purposes:

  • Providing electronic services:
    • Registration and maintenance of the User's account in the Service and related functionalities
    • Newsletter services (including sending advertising content with consent)
    • Sharing information about content posted on the Service in social networks or other websites.
  • Communication of the Administrator with Users regarding the Service and data protection
  • Ensuring the legitimate interest of the Administrator

Data about Users collected anonymously and automatically are processed for one of the following purposes:

  • Statistics
  • Remarketing
  • Serving ads tailored to User preferences
  • Handling affiliate programs
  • Ensuring the legitimate interest of the Administrator

§7 Cookies of External Services

The Administrator in the Service uses JavaScript scripts and web components of partners who may place their cookies on the User's Device. Remember that in your browser settings you can decide which cookies are allowed to be used by individual websites. Below is a list of partners or their services implemented in the Service that may place cookies:

Services provided by third parties are beyond the control of the Administrator. These entities may change their terms of service, privacy policies, data processing purposes, and cookie usage methods at any time.

§8 Types of Collected Data

The Service collects data about Users. Some data is collected automatically and anonymously, while some data is personal data provided voluntarily by Users when signing up for various services offered by the Service.

Anonymous data collected automatically:

  • IP address
  • Browser type
  • Screen resolution
  • Location
  • Pages viewed within the Service
  • Time spent on a specific page of the Service
  • Operating system type
  • Previous page address
  • Referring page address
  • Browser language
  • Internet connection speed
  • Internet service provider
  • Demographic data (age, gender)

Data collected during registration:

  • First name / last name / nickname
  • Login
  • Email address
  • IP address (collected automatically)

Data collected during newsletter signup:

  • First name / last name / nickname
  • Email address
  • IP address (collected automatically)

Data collected when adding a comment:

  • First name and last name / nickname
  • Email address
  • Website address
  • IP address (collected automatically)

Some data (without identifying data) may be stored in cookies. Some data (without identifying data) may be transferred to statistical service providers.

§9 Access to Personal Data by Third Parties

As a rule, the only recipient of personal data provided by Users is the Administrator. Data collected as part of the services provided are not transferred or resold to third parties.

Access to data (usually based on a data processing agreement) may be granted to entities responsible for maintaining the infrastructure and services necessary for the operation of the Service, such as:

  • Hosting companies providing hosting services or related services to the Administrator
  • Companies through which the Newsletter service is provided
  • Companies intermediating in online payments for goods or services offered within the Service (in the case of purchase transactions in the Service)
  • Companies responsible for the Administrator's accounting (in the case of purchase transactions in the Service)

Entrusting the processing of personal data - Newsletter

The Administrator, in order to provide the Newsletter service, uses a third-party service - Mailerlite. Data entered in the newsletter signup form is transferred, stored, and processed in the external service of this provider.

We inform you that the indicated partner may modify the indicated privacy policy without the Administrator's consent.


Entrusting the processing of personal data - Hosting, VPS, or Dedicated Servers

The Administrator, in order to operate the Service, uses the services of an external provider of hosting, VPS, or Dedicated Servers - OVH sp. z o.o.. All data collected and processed in the Service are stored and processed in the service provider's infrastructure located outside the European Union. Access to data may occur as a result of service work performed by the service provider's personnel. Access to this data is regulated by an agreement between the Administrator and the Service Provider.


Processing data for online payments

In the case of online payments, all payment data is transferred directly by the User to the entity processing the payment - EasyCart.com. Selected data necessary for transaction execution is then transferred by this entity to the Administrator. Data transfer is regulated by an agreement between the Administrator and the Service Provider.


Transferring personal data - Accounting Services

In the case of transactions, some personal data of individuals or data of individuals conducting business activities are transferred to the entity providing accounting services to the Administrator - InFakt. The transfer of this data is regulated by the relevant laws and an agreement between the Administrator and the Service Provider.


§10 How Personal Data is Processed

Personal data voluntarily provided by Users:

  • Personal data is transferred outside the European Union.
    Data transfer outside the EU is due to the use of services of entities located outside the EU or as a result of publication as a result of individual User actions (e.g., entering a comment or entry), making the data available to anyone visiting the service.
    In the case of transfer or entrusting the processing of personal data outside the EU, this data is processed based on an agreement between the Administrator and the Service Provider.
  • Personal data is used for automated decision-making (profiling).
    Profiling personal data does not have legal effects or similarly significantly affect the person to whom the data subject to automated decision-making applies.
  • Personal data will not be resold to third parties.

Anonymous data (without personal data) collected automatically:

  • Anonymous data (without personal data) will be transferred outside the European Union.
  • Anonymous data (without personal data) may be used for automated decision-making (profiling).
    Profiling anonymous data (without personal data) does not have legal effects or similarly significantly affect the person to whom the data subject to automated decision-making applies.
  • Anonymous data (without personal data) will not be resold to third parties.

§11 Legal Bases for Processing Personal Data

The Service collects and processes Users' data based on:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
    • Art. 6 sec. 1 lit. a
      the data subject has given consent to the processing of his or her personal data for one or more specific purposes
    • Art. 6 sec. 1 lit. b
      processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract
    • Art. 6 sec. 1 lit. f
      processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
  • Act of 10 May 2018 on the protection of personal data (Journal of Laws 2018 item 1000)
  • Act of 16 July 2004 Telecommunications Law (Journal of Laws 2004 No. 171 item 1800)
  • Act of 4 February 1994 on copyright and related rights (Journal of Laws 1994 No. 24 item 83)

§12 Personal Data Processing Period

Personal data voluntarily provided by Users:

As a rule, the indicated personal data is stored only for the period of providing the Service by the Administrator. They are deleted or anonymized within 30 days from the end of providing services (e.g., deletion of a registered user account, unsubscribe from the Newsletter, etc.)

An exception is a situation that requires securing the legally justified purposes of further processing of these data by the Administrator. In such a case, the Administrator will store the indicated data, from the time of the request for their deletion by the User, for no longer than 3 years in the event of a violation or suspicion of violation of the service regulations by the User.

Anonymous data (without personal data) collected automatically:

Anonymous statistical data, not constituting personal data, are stored by the Administrator for an indefinite period to conduct service statistics.

§13 User Rights Related to the Processing of Personal Data

Users have the following rights regarding the processing of their personal data:

  • Right to access personal data
    Users have the right to access their personal data, realized through the user panel available after logging in and tools enabling access to the account in case of forgotten password.

  • Right to rectify personal data
    Users have the right to request the Administrator to promptly correct personal data that is inaccurate or to complete incomplete personal data, realized upon request submitted to the Administrator

  • Right to delete personal data
    Users have the right to request the Administrator to promptly delete personal data, realized through the user panel available after logging in and tools enabling access to the account in case of forgotten password. In the case of user accounts, deleting data means anonymizing data that allows identifying the User. The Administrator reserves the right to withhold the request for data deletion to protect the legitimate interest of the Administrator (e.g., when the User has violated the Regulations or the data was obtained as a result of correspondence).
    In the case of the Newsletter service, the User can delete their personal data independently using the link provided in each email message.

  • Right to restrict the processing of personal data
    Users have the right to restrict the processing of personal data in cases specified in Art. 18 GDPR, including questioning the accuracy of personal data, realized upon request submitted to the Administrator

  • Right to data portability
    Users have the right to obtain from the Administrator the personal data concerning the User in a structured, commonly used, machine-readable format, realized upon request submitted to the Administrator

  • Right to object to the processing of personal data
    Users have the right to object to the processing of their personal data in cases specified in Art. 21 GDPR, realized upon request submitted to the Administrator

  • Right to lodge a complaint
    Users have the right to lodge a complaint with the supervisory authority responsible for data protection.

§14 Contact with the Administrator

You can contact the Administrator in one of the following ways:

  • Postal address - SoftEnd Kamil Rodak, Bożnów 107, 68-100 Żagań

  • Email address - admin@GuideTravio.com

  • Contact form - available at: /contact

§15 Service Requirements

  • Limiting the saving and access to cookies on the User's Device may cause some Service functions to malfunction.

  • The Administrator is not responsible for malfunctioning Service functions if the User restricts the ability to save and read cookies in any way.

§16 External Links

In the Service - articles, posts, entries, or User comments may contain links to external sites that the Service Owner does not cooperate with. These links and the pages or files they point to may be dangerous for your Device or pose a threat to your data security. The Administrator is not responsible for the content outside the Service.

§17 Changes to the Privacy Policy

  • The Administrator reserves the right to change this Privacy Policy at any time without notifying Users regarding the use and application of anonymous data or the use of cookies.

  • The Administrator reserves the right to change this Privacy Policy at any time regarding the processing of Personal Data, of which Users with user accounts or subscribed to the newsletter will be informed via email within 7 days of the change. Continued use of the services means reading and accepting the changes to the Privacy Policy. If the User does not agree with the introduced changes, they must delete their account from the Service or unsubscribe from the Newsletter.

  • Introduced changes to the Privacy Policy will be published on this subpage of the Service.

  • Introduced changes take effect upon their publication.