This policy is intended for information purposes and to fulfil the information obligations imposed on the data controller under GDPR, Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
The Controller of your personal data is Vision Warsaw sp. z o.o. with its registered office at
Al. Jerozolimskie 81/22, 02-001 Warsaw, Poland, entered in the commercial register of the National Court Register kept by the District Court for the capital city of Warsaw, 12th Commercial Division of the National Court Register (KRS), under number KRS: 0000252344, Tax Identification Number (NIP): 1070004446, National Business Registry Number (REGON): 140260072, share capital amounting to: PLN 50,000 (hereinafter referred to as “VISIONAPARTMENTS”).
You may contact the Personal Data Controller in particular via e-mail at: firstname.lastname@example.org
What information do we collect?
We collect a variety of personal data from and about you through the services, including:
- Information that you provide to us directly;
- Information provided automatically through logging and analytics tools, cookies, pixel tags, and as a result of your use of and access to the services; and
- Information from third-party sources, including properties where you book stays; service providers; individuals or entities who book stays or order services on your behalf, including but not limited to online travel agencies, corporate travel managers, and travel agents; ad networks that provide online behavioural advertising services, service providers such as Google Analytics, and from your interactions with us on social media websites.
You have choices about whether we collect certain information. When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide any aspect of our services, it may not be possible for you to use those services. As noted below in the section entitled “Your choices” it is possible to change your browser settings to block the automatic collection of certain information.
Finally, we may collect data that is not identifiable to you or otherwise associated with you, such as aggregated data, which is therefore not personal data. To the extent that this data is stored or associated with personal data, it will be treated as personal data; otherwise, the data is not subject to this notice.
We collect personal data from you when you provide it to us, including through website forms, online chat, when booking stays, placing orders, or contacting us with questions or comments.
If you book stays or order products or services through the services, you must provide us with information to process that request and/or enter into or execute a contract with you (including but not limited to your email address, first and last name, mailing address, billing address, payment information, telephone number, and any other information you may optionally provide.
In addition, you can choose to sign up for email notifications about VISIONAPARTMENTS through the services, by providing us with your email address.
If you contact us with questions, requests, or complaints, or to exercise your legal rights, including through our online chat function, we collect personal data that is necessary to answer your questions, address your requests, and/or handle your complaints, as applicable. In certain situations, we may also require you to provide personal data to authenticate your identity in order to carry out your requests.
We also collect information from you that, depending on applicable law, may not constitute personal data.
When you browse or use the services, we utilize commonly-used logging and analytics tools, including Google Analytics, to collect information about your device, the network used to access the services, and information about your use of the services (such as how you navigate and move around the services).
We also use certain technology on the services, including cookies and pixel tags, that allows us, our service providers, and other third parties, to store information locally on your device, identify your device, track your interactions with other sites or with our email campaigns, and track activity over time and across websites.
Information collected automatically includes the software and hardware attributes of the device you use to access the services, unique device ID information, regional and language settings, performance data about the services, the network provider, and the IP address (a number assigned to your device when you use the internet). In addition, information is collected passively in the form of log files and third-party analytics (including Google Analytics) that record website activity. For example, log file entries and analytics data are generated every time you visit a particular page on our website, which track the dates and times that you use the services, the pages you visit, the amount of time spent on specific pages, and other similar usage information, as well as general data (including the name of the web page from which you entered our website).
We receive personal data from online travel agencies, corporate travel managers, and travel agents, properties where you book stays, other accommodation providers, as well as third parties that we have commissioned to provide services to us, including our suppliers and vendors, as well as from third parties that provide web analytics and usage information to us such as Google Analytics.
In addition, if you choose to interact with us or our partners on social media by posting to our pages, tagging us (or using certain hashtags or other identifiers) in posts, or participating in activities, we may collect certain information from the social media account you use to interact with us, including the name associated with the account, the account handle, recent activity, the content of any posts in which we are tagged, and other information that may be contained on your social media profile to allow us to respond to the posts and understand and engage with our audience.
How do we process personal data?
We process personal data for three general purposes:
- For our business operations (including communicating with you, fulfilling orders, providing information about our products and services, improving the services, and complying with applicable legal requirements);
- To market and promote our products and offerings, if you give your consent for it,
- To market and promote our partners’ products and offerings, if you give your consent for it.
We disclose personal data to our service providers to allow them to provide services to us and assist us in carrying out your requests, and to our partners in aggregate, demographic form in connection with our marketing and business development efforts.
In addition, we may disclose information we hold, including personal data: when permitted or required to do so by law; in response to a request from a law enforcement agency or authority, or any regulatory authority; and/or to protect the integrity of the services or our interests, rights, property, or safety, and/or that of our users and others.
See the “Your choices” section below for information about how you can make decisions about how we process personal data, including how to opt out of certain marketing communications.
Legal basis for processing
We process personal data for, or based on, one or more of the following legal bases:
- Execution of a contract. We may use personal data to enter into, or execute, the agreement between us, such as when you book stays or purchase products or services.
- Legitimate interests. We may use personal data for our legitimate interests and those of certain third parties, including to improve our service; provide appropriate reports to corporate travel managers and relocation and accommodation providers; provide information about our products and/or services; to the extent that is necessary and proportionate, for the purpose of ensuring network and information security; and for administrative, fraud detection, and legal compliance purposes.
- Compliance with legal obligations and the protection of individuals. We may use personal data to comply with the law and our legal obligations, as well as to protect you and other individuals from certain harms.
- Your consent. We may process certain personal data based on your consent to process it in that manner.
Operational uses. We process your personal data as part of our operations, which include:
- Providing you with information tailored to your requests, responding to inquiries, and delivering services and products;
- Operating, maintaining, and improving the quality of the services and such content, products and/or services that we may make available through the services;
- Communicating with you by email, mail, text message (SMS, MMS), telephone, social media messaging, online chat, and other methods of communication, in each case with your consent, if such consent is required in accordance with applicable laws, about products, services, order status, and other topics;
- Compliance with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies;
- Endeavouring to protect our rights and our partners’ rights, property, or safety, and the rights, property, and safety of our users and other third parties; and
- For other purposes, as permitted or required by law.
We also process your personal data to send messages to you about us, our partners, and the content, products and services we and our partners offer, which may include, from time to time, contests, rewards, events, and special offers for products and services. These communications are tailor-made for you, based on the communications preferences you select when providing us with your information, and will only occur with your prior consent, if such consent is required in accordance with applicable laws. For example, we will not call you or send you text messages unless you both consent to receive such communication and provide us with your telephone number. We process personal data collected through social media platforms and web tracking technologies to market to, and understand, our audience.
Disclosure of personal data
Some of the afore-mentioned processing involves disclosing collected personal data to third parties, including service providers, affiliates, and other partners.
We disclose personal data to third parties when you ask us to do so;
We disclose personal data among our affiliated entities;
We disclose contact information with the supply partner (e.g., the property, managing company) responsible for providing accommodation that you have booked;
We disclose personal data with our service providers, including payment processing companies, software and web developers, service providers for order processing and execution, commercial email providers, security consultants, properties where you book stays, and other vendors we commission so that they may provide services to us or on our behalf;
We disclose the personal data we collect, in aggregated, demographic form, with certain customers, partners, prospective partners, and service providers in order to provide us and/or our affiliates and partners with information about the use of the services and levels of engagement with the services, to allow us to enter into new business relationships, and to allow us to market products or services on their behalf. For example, stay data for guests staying with the same company or client may be aggregated and provided to that party based on our contractual obligations or to address informational request or requirements of that party; and
We disclose personal data with third parties when we believe it is required by, or is necessary to comply with, the applicable law.
Protecting personal data
We employ reasonable and appropriate physical, technical, and organizational safeguards designed to promote the security of our systems and protect the confidentiality, integrity, availability, and resilience of personal data. These safeguards include: (i) the pseudonymization and encryption of personal data where we deem appropriate; (ii) taking steps to ensure personal data is backed up and remains available in the event of a security incident; and (iii) the periodic testing, assessment, and evaluation of the effectiveness of our safeguards.
However, no method of safeguarding information is completely secure. While we use measures designed to protect personal data, we cannot guarantee that our safeguards will be effective or sufficient. In addition, you should be aware that the transfer of data on the internet is not always secure, and we cannot guarantee that information you transmit by using the services is or will be secure.
Retention of personal data
We retain your personal data for as long as is necessary or appropriate to fulfil the purpose for which it was collected, and to the extent necessary or appropriate to carry out the processing described above, including but not limited to compliance with applicable laws, regulations, rules and requests of relevant law enforcement and/or other governmental agencies, and to the extent we deem reasonably necessary to protect our rights and our partners’ rights, property, or safety, and the rights, property, and safety of our users and other third parties.
We take into account and consider multiple factors, including the scope and nature of the personal data, the potential risk of harm to data subjects from a data breach, and legal requirements, in determining the appropriate retention period. If you have a specific question regarding the retention of your personal data, you may contact us as described in the section “Additional information and assistance”.
Specifically, billing information is retained for 5 years for accounting and tax law purposes, and information about legal transactions is retained for 10 years to enable us to review any ongoing legal obligations, to resolve disputes, and to enforce agreements. We will also retain your information for marketing communication purposes until you “opt-out” of such communication, or request that we delete all the information that we have collected about you.
The data we collect in connection with the operation of the services may be processed in an automated manner (in this case, in the form of profiling), but this will not lead to legal effects concerning you or similarly significantly effects for you.
The data we use for profiling is not sensitive.
As a result of profiling marketing, actions will be generated, and sales analyses and forecasts will be created.
You may object to profiling relating to you by contacting us on this e-mail address email@example.com
Your rights regarding personal data
Please note, however, that we may request certain reasonable additional information (that may include personal data) to help us authenticate the request and/or to clarify or understand the scope of such requests.
These rights vary depending on the particular laws in the jurisdiction applicable to you, but may include:
- The right to know whether, and for what purposes, we process personal data about you;
- The right to be informed about the personal data we collect and/or process about you;
- The right to learn the source of personal data about you that we process, if we obtain the personal data from a source other than you.
- The right to access, modify, and correct personal data about you (as set out in more detail below under “Accessing, modifying, rectifying, and correcting collected personal data”)
- The right to know with whom we have shared personal data about you, for what purposes, and what personal data has been shared (including whether personal data was disclosed to third parties for their own direct marketing purposes);
- If the processing of personal data about you is based on your consent, the right to withdraw your consent to this processing; and
- The right to lodge a complaint with a supervisory authority located in the jurisdiction of your place of residence, place of work, or where an alleged violation of law occurred.
Accessing, modifying, rectifying, and correcting collected personal data.
We strive to maintain the accuracy of any personal data collected from you, and will undertake commercially reasonable efforts to respond promptly to update our database, when you tell us the information in our database is not accurate. However, we must rely upon you to ensure that the information you provide to us is complete, accurate, and up-to-date, and that you inform us of any changes. Please review all of your information carefully before submitting it to us, and notify us as soon as possible of any updates or corrections.
In accordance with the applicable law, you may obtain from us certain personal data, about your person, that is held in our records. If you wish to access, review, or make any changes to the personal data you have provided to us through the services, you may do so at any time by contacting us as provided below. Please note, however, that we reserve the right to deny access as permitted or required by applicable law.
Your privacy rights. In addition to the rights listed above, certain privacy laws provide individuals with enhanced rights in respect of their personal data. These rights may include, depending on the circumstances surrounding the processing of personal data:
- The right to object to decisions based on profiling or automated decision-making that cause legal or similarly significant effects on you;
- The right to request the restriction of processing of your personal data or object to the processing of your personal data carried out pursuant to (i) a legitimate interest or (ii) the performance of a task in the public interest (including, but not limited to, processing for direct marketing purposes);
- In certain circumstances, the right to data portability, which means that you can request that we provide certain personal data we hold about you in a machine-readable format; and
- In certain circumstances, the right to erasure and/or the right to be forgotten, which means that you can request the deletion or removal of certain personal data we process about you.
Please note that we may need to request additional information from you to validate your request. To exercise any of the rights above, you may contact us as described in the section “Additional information and assistance”.
In addition to your choices with respect to the collection of personal data (see the section “What information do we collect?” above), you have the ability to make certain choices about how we communicate with you, and how we process certain personal data.
Please note that if you do business with us in the future, you may not, subject to the applicable law, opt out of certain automated notifications, such as order or subscription confirmations, based on business transactions (e.g., e-commerce).
For the purposes of the correct performance of the Services, VISIONAPARTMENTS uses cookie support technology. Cookies are information files stored on your device by the services, usually containing information corresponding to the intended use of a particular file, by means of which you use the services. Usually, cookies contain the address of the service, the date of publishing, the cookie’s lifespan, a unique number and additional information corresponding to the intended use of a particular file.
VISIONAPARTMENTS uses two types of cookies: session cookies, which are permanently deleted upon the closing of your browser’s session, and permanent cookies, which remain on your device after closing the session, until they are deleted.
It is not possible to identify you on the basis of cookie files, whether session or permanent cookies. The cookie mechanism prevents the collection of any personal data.
The cookies used by the VISIONAPARTMENTS are safe for your device, in particular they prevent viruses or other software from hacking into the device. In turn, third-party cookies (i.e. cookies provided by associated partners of VISIONAPARTMENTS) may be read by an external server.
You may disable the storage of cookies on your device in accordance with the instructions of the browser software provider, but this may disable certain parts, or the entire operation, of the services.
The following types of cookies are used in the services:
- Strictly necessary cookies: These files are necessary to enable you to browse our website and use its functions, such as access to our website areas. Without those cookies, the services you select, such as the shopping cart, may not be able to be provided.
- Performance cookies: These cookies collect information about the manner in which you use our website, for example which sites are visited by you most often and if you receive error messages from websites. These cookies do not collect information which could identify you. Any information collected by these cookies is of a collective, and therefore anonymous, character. They are solely used for the purpose of improving the functioning of our website operation.
- Functionality cookies: These cookies enable our website to remember the choices you make (such as user name, language or the region you are located in) and ensure improved, more personalised use. These files may also be used to remember any changes made with regard to text size, fonts and other website elements which you may adjust. They may also be used to provide the services you have selected, for example watching videos or commenting on a blog.
- Advertising cookies: These cookies collect information about your browsing habits in order to provide you with advertisements adjusted to you and your interests, insofar as you consent to this by selecting the relevant settings in your browser. They are also used to reduce the number of advertisement impressions, and they also help to check the effectiveness of advertising campaigns. Usually they are placed by advertising networks with our consent. They remember that you have visited the website and this information (in a collective and anonymous form) is shared with other entities, such as advertisers. Quite often, advertising cookies will be connected with the functions of another entity’s website. If you disable these cookies, you may still use our website.
- Third-party cookies: When you use our website, your device or browser may receive cookies from third parties, for example when you use posted content and links to social networks, insofar as you consent to this by selecting the relevant settings in your browser. You need to be aware that we have no access to or control over cookies used by those third-party companies or websites. We advise you to visit third-party websites to read more information on the cookies they use and how to manage them. If you disable these cookies, you may still use our website.
In many cases, software designed to browse sites (a browser) by default allows cookies to be stored on your device. You may change the settings relating to cookies at any time. These settings may be changed in particular to block the automatic cookie support in the browser settings or to notify each case of them being stored on your device. Detailed information on the options and methods of cookie support is available in the software (browser) settings.
Cookies placed on your device may also be used by advertisers and partners co-operating with the services operator. You may individually change the cookies settings at any time, stating the conditions of their storage, through the browser settings or configuration of the service. You may also individually delete cookies stored on your device at any time in accordance with the instructions of the browser provider.
Detailed information concerning the support for cookies is available in the browser settings.
Other important information about personal data and the services.
Collection of personal data from minors. Children under 16 years of age are not permitted to use the services, and we do not knowingly collect information from children under the age of 16. By using the services, you declare that you are 18 years of age or older, or are 16 years of age or older and have valid parental consent to do so. With respect to minors, when information is collected, it is generally only the age of the child, and in certain cases the child’s name, gender, and/or school district, as is appropriate to provide specific elements of our services.
Transfer of business. We may, in the future, sell or otherwise transfer some or all of our business, operations or assets to a third party, whether by merger, acquisition or otherwise. Personal data we obtain from or about you via the services may be disclosed to any potential or actual third-party acquirers and may be among those assets transferred.
Do not track.
We use analytics systems and providers and participate in ad networks that process personal data about your online activities over time and across third-party websites or online services, and these systems and providers may provide some of this information to us. We do not currently process or comply with any web browser’s “do not track” signal or similar mechanisms.
Please note, however, that you may find information about how to opt out of Google Analytics, online behavioural advertising, and/or block or reject certain tracking technologies in our Cookie Notice.
We transfer your data to third countries, i.e. countries not in the European Economic Area, the United States, on the basis of the Commission Implementing Decision of 12 July 2016 introducing the so-called Privacy Shield (under this decision, data is only transferred to certified entities, as a result of which those entities are obliged to appropriately secure personal data), as well as to other countries, only on the basis of standard contractual clauses under which relevant entities will be obliged to appropriately secure personal data.
You may obtain copies of the personal data transmitted to third countries at any time.
Additional information and assistance
Privacy Office of VISIONAPARTMENTS
Data Protection Officer of VISIONAPARTMENTS
If you live in the European Economic Area, and wish to raise a concern regarding our use of your personal data, you have the right to do so with our lead supervisory authority, the U.K. Information Commissioner’s Office (the “ICO”) at www.ico.org.uk, or your local supervisory authority. We would, however, appreciate the opportunity to deal with your concerns before you approach the ICO, so please contact us first.
This policy comes into effect as per 25.05.2018