Privacy Policy (GDPR)

Information on the processing of personal data

1. Data Controller

We hereby inform you that the controller of your personal data is MWR Szarotka S.C. Ryszard Sobiesiak, Magdalena Sobiesiak-Michalska, ul. Zieleniec 72, 57-340 Duszniki-Zdrój, NIP 883 177 03 25.

Contact with the Facility regarding personal data protection is possible at the following e-mail address: recepcja@szarotka.eu.


2. Purposes and Legal Bases for the Processing of Personal Data

In order to provide services in accordance with the scope of its business activities, the Facility processes your personal data for various purposes, but always in accordance with applicable law. The personal data provided will be processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR.

We obtain personal data from you in the course of activities aimed at concluding a contract (making a reservation for a stay and providing services related to your stay at the Facility), or from our partners operating reservation portals, if you have given your consent to this. Below you will find a list of the purposes for processing personal data together with the relevant legal bases.

A. For the purpose of preparing a quotation for a service, making a service reservation and providing the service, as well as in the case of concluding other contracts related to the scope of our business activities, we may process the following personal data:

  • First and last name;
  • Address (street, house/apartment number, postal code and city);
  • Telephone number;
  • E-mail address;
  • Company details, including the NIP tax identification number (in the case of issuing a VAT invoice to a company);
  • Registration number of the vehicle belonging to the Client (if the hotel car park is used);
  • Basic bank account details for confirming a bank transfer;
  • Identity document number/PESEL number;
  • Nationality information;
  • Your payment card number and other card details, as well as authentication data and other billing and account information associated with mobile payments;
  • Reservation number.


The legal basis for such processing is Article 6(1)(b) of the GDPR, which permits the processing of personal data where it is necessary for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract.

Children's data, such as their first and last name, nationality and date of birth, are collected exclusively from their parents or legal guardians for the purpose of determining their age and applicable discounts, as well as for statistical purposes (Central Statistical Office [GUS] reporting obligations and local tourist tax).

B. For the purpose of handling complaints, we process the following personal data:

  • First and last name;
  • Address (street, house/apartment number, postal code and city);
  • Telephone number;
  • E-mail address;
  • Reservation number;
  • Bank account number, if a refund is made.

The legal basis for such processing is Article 6(1)(b) of the GDPR, which permits the processing of personal data where it is necessary for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract.

For the purpose of personalizing services in accordance with the user's personal preferences and managing customer relationships before, during and after the stay, we process the following personal data:

  • Monitoring the use of services (telephone, bar, pay TV, etc.);
  • Managing access to rooms;
  • E-mail address;
  • First and last name;
  • Reservation number.

The legal basis for such processing is Article 6(1)(b) of the GDPR, which permits the processing of personal data where it is necessary for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract, as well as Article 6(1)(a) of the GDPR, which permits the processing of personal data on the basis of freely given consent.

C. For the purpose of issuing invoices and fulfilling other obligations arising from tax regulations, such as the obligation to retain accounting records for 5 years, we process the following personal data:

  • First and last name;
  • Company name;
  • Residential address or registered office address;
  • NIP tax identification number;
  • Reservation number.

The legal basis for such processing is Article 6(1)(c) of the GDPR, which permits the processing of personal data where such processing is necessary for the Data Controller to comply with legal obligations.

D. For the purpose of examining satisfaction with the services offered, conducting audits, and improving and modifying our services, we process the following personal data:

  • E-mail address;
  • Reservation number;
  • First and last name;
  • Guest's; comments or suggestions.

The legal basis for such processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interest (in this case, the Facility's interest is to obtain customers' opinions about the services provided in order to adapt them to the needs and expectations of interested parties).

E. For the purpose of ensuring the safety of employees and guests of the Facility and preventing fraud, we process the following personal data:

  • Data from the key card system;
  • Images of individuals obtained through video surveillance;
  • First and last name;
  • E-mail address;
  • IP address.

The legal basis for such processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interest (in this case, the Facility's interest is to ensure the safety of all persons staying on the Facility's premises). CCTV data are deleted no later than 30 days after the date on which they were recorded.

F. For the purpose of creating registers and records related to the GDPR, including, for example, a register of customers who have objected in accordance with the GDPR, we process the following personal data:

  • First and last name;
  • E-mail address.

The GDPR imposes certain documentation obligations on us in order to demonstrate compliance and accountability. If, for example, you object to the processing of your personal data for marketing purposes, we must know whose data should be excluded from direct marketing.

The legal basis for such processing is Article 6(1)(c) of the GDPR, which permits the processing of personal data where such processing is necessary for the Data Controller to comply with legal obligations arising from the law (the provisions of the GDPR), as well as Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interest (in this case, the Facility's interest is to have information about individuals exercising their rights under the GDPR).

G. For the purpose of establishing, pursuing or defending against claims, we process the following personal data:

  • First and last name (if provided) or, where applicable, company name;
  • Residential address (if provided);
  • PESEL number or NIP tax identification number (if provided);
  • E-mail address;
  • IP address;
  • Reservation number.

The legal basis for such processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interest (in this case, the Facility's interest is to have personal data enabling it to establish, pursue or defend against claims, including those made by customers and third parties).

H. For analytical purposes, i.e. examining and analyzing activity on the website belonging to the Facility, we process the following personal data:

  • Date and time of the website visit;
  • Type of operating system;
  • Approximate location;
  • Type of web browser used to browse the website;
  • Time spent on the website;
  • Pages visited;
  • The page on which the contact form was completed.

The legal basis for such processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interest (in this case, the Facility's interest is to understand customers' activity on the website).

I. For the purpose of using cookies on the website, we process textual information of this type (cookies are described in a separate section). The legal basis for such processing is Article 6(1)(a) of the GDPR, which permits the processing of personal data on the basis of freely given consent (when visiting the website for the first time, you will be asked to consent to the use of cookies).

J. For the purpose of administering the website, we process the following personal data:

  • IP address;
  • Server date and time;
  • Web browser information;
  • Operating system information.

This data is automatically recorded in so-called server logs whenever the website belonging to the Facility is used. Administering the website without the use of a server and without this automatic recording would not be possible. The legal basis for such processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interest (in this case, the Facility's interest is to administer the website).


3. Cookies

A. The Facility, like other entities, uses so-called cookies on its website, i.e. short text files stored on the user's computer, telephone, tablet or other device. They may be read by our system as well as by systems belonging to other entities whose services we use (e.g. Facebook and Google).

B. Cookies perform many functions on a website, most of which are useful. We will try to describe them below (if the information provided is insufficient, please contact us):

  • ensuring security — cookies are used to authenticate users and prevent unauthorized use of the customer panel. They therefore serve to protect the user's personal data from access by unauthorized persons;
  • affecting website processes and performance — cookies are used to ensure that the website operates smoothly and that its available functions can be used, including by remembering settings between successive visits. They therefore enable efficient navigation of the website and its individual pages;
  • session status — cookies often store information about how visitors use the website, e.g. which pages they view most frequently. They also make it possible to identify errors displayed on certain pages. Cookies used to store the so-called “session state” therefore help improve services and increase browsing comfort;
  • maintaining session status — when a customer logs in to their panel, cookies make it possible to maintain the session. This means that after moving to another page, it is not necessary to enter the login and password again each time, which makes using the website more convenient;
  • creating statistics — cookies are used to analyze how users use the website (how many people open the website, how long they stay on it, which content attracts the greatest interest, etc.). This enables us to continuously improve the website and adapt its operation to users; preferences. To track activity and create statistics, we use Google's tools, such as Google Analytics; in addition to reporting website usage statistics, the Google Analytics pixel may also, together with some of the cookies described above, help display more relevant content to the user in Google services (e.g. Google Search) and across the network;
  • using social features — the website contains a so-called Facebook pixel, which enables users to like our fan page while using the website. However, in order for this to be possible, we must use cookies provided by Facebook.

C. Your web browser allows the use of cookies on your device by default, which is why, during your first visit, we ask you to consent to the use of cookies. However, if you do not wish to use cookies while browsing the website, you can change the settings in your web browser — you can completely block the automatic handling of cookies or request a notification each time cookies are placed on your device. The settings can be changed at any time.

D. While respecting the autonomy of all persons using the website, we are nevertheless obliged to warn you that disabling or restricting the use of cookies may cause significant difficulties in using the website, such as the need to log in on every page, longer loading times, limitations in the use of certain functionalities, limitations in liking the Facebook page, etc.


4. Right to Withdraw Consent

A. If the processing of personal data is based on consent, you may withdraw your consent at any time.

B. If you wish to withdraw your consent to the processing of personal data, you should follow the procedure described in section 10, subsection F. If the processing of your personal data was based on consent, withdrawing that consent does not mean that the processing carried out up to that point was unlawful. In other words, until consent is withdrawn, we are entitled to process your personal data, and withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

5. Requirement to Provide Personal Data

A. Providing any personal data is voluntary and depends on your decision. However, in certain cases, providing specific personal data is necessary in order to meet your expectations regarding the use of our services.

B. In order to order a service at the Facility, it is necessary to provide the data indicated in section 2 A of this Privacy Policy.

C. In order to receive an invoice for services, it is necessary to provide all data required under tax law — without this information, we are unable to issue a proper invoice.

D. In order for us to contact you by telephone regarding the provision of a service, it is necessary to provide a telephone number and e-mail address — without this information, we are unable to establish telephone contact or send a reservation confirmation.

6. Automated Decision-Making and Profiling

We hereby inform you that we do not carry out automated decision-making, including decision-making based on profiling. The content of an inquiry submitted via the form is not evaluated by an IT system. The proposed price of the service is provided on the basis of the Facility's price list.

7. Recipients of Personal Data

A. Like most businesses, we use the assistance of other entities in our operations, which may sometimes involve the transfer of personal data. Therefore, where necessary, we may provide your personal data to lawyers cooperating with us who provide legal services, companies handling fast payments, an accounting firm, a hosting company, companies providing IT services, a company responsible for sending SMS communications, as well as an insurance company (if it becomes necessary to compensate for damage).

B. In addition, it may happen that, for example, pursuant to an applicable legal provision or a decision of a competent authority, we will also be required to provide your personal data to other authorities or entities.


8. Transfer of Personal Data to Third Countries

A. Like most businesses, we use various popular services and technologies offered by entities such as Facebook, Microsoft and Google. These companies are headquartered outside the European Union and are therefore considered third countries within the meaning of the GDPR.

B. The GDPR introduces certain restrictions on the transfer of personal data to third countries because, as European regulations generally do not apply there, the protection of the personal data of European Union citizens may unfortunately be insufficient. Therefore, every data controller is required to establish a legal basis for such transfers.

C. For our part, we ensure that when using services and technologies, we transfer personal data exclusively to entities in the United States and only to entities that have joined the Privacy Shield program, pursuant to the European Commissions implementing decision of 12 July 2016 — more information on this subject can be found on the European Commission's website at the address provided in the original document.

Entities participating in the Privacy Shield program guarantee that they will comply with the high standards of personal data protection applicable in the European Union; therefore, using their services and technologies in the process of processing personal data is lawful.

D. We will provide you with additional explanations regarding the transfer of personal data at any time, particularly if this issue causes you concern.

9. Period of Personal Data Processing

A. In accordance with applicable law, we do not process your personal data “indefinitely”, but only for the period necessary to achieve the specified purpose. After this period, your personal data will be irreversibly deleted or destroyed.

B. Where we do not need to perform any other operations on your personal data apart from storing them (e.g. where we retain the content of an order for the purpose of defending against claims), until they are permanently deleted or destroyed, we additionally secure them through pseudonymization. Pseudonymization consists of encrypting personal data or a set of personal data in such a way that they cannot be read without an additional key, making such information completely useless to an unauthorized person.

C. With regard to the individual periods for processing personal data, we inform you that personal data are processed for the following periods:

  • for the duration of the contract — with regard to personal data processed for the purpose of concluding and performing the contract;
  • 3 years or 6 years + 1 year — with regard to personal data processed for the purpose of establishing, pursuing or defending against claims (the length of the period depends on whether both parties are businesses or not);
  • 6 months — with regard to personal data collected when preparing a quotation for a service where no contract was immediately concluded;
  • 5 years + 1 year — with regard to personal data associated with compliance with tax obligations;
  • until consent is withdrawn or the purpose of processing is achieved, but no longer than 5 years — with regard to personal data processed on the basis of consent;
  • until an effective objection is made or the purpose of processing is achieved, but no longer than 5 years — with regard to personal data processed on the basis of the Data Controllers legitimate interest or for marketing purposes;
  • until the data become outdated or lose their usefulness, but no longer than 3 years — with regard to personal data processed mainly for analytical purposes, the use of cookies and website administration.

D. Periods expressed in years are calculated from the end of the year in which we began processing personal data, in order to streamline the process of deleting or destroying data. Calculating the period separately for each contract concluded would involve significant organizational and technical difficulties, as well as considerable financial expenditure; therefore, establishing a single date for deleting or destroying personal data allows us to manage this process more efficiently. Naturally, if you exercise your right to be forgotten, such situations are considered individually.


E. The additional year relating to the processing of personal data collected for the performance of a contract is justified by the fact that, hypothetically, you may submit a claim shortly before the limitation period expires, the claim may be delivered with a significant delay, or you may incorrectly determine the limitation period applicable to your claim.

10. Rights of Data Subjects

A. We hereby inform you that you have the right to:

  • access your personal data;
  • rectify your personal data;
  • erase your personal data;
  • restrict the processing of your personal data;
  • object to the processing of your personal data;
  • have your data erased (“the right to be forgotten”) where permitted by other applicable laws;
  • receive a copy of your data;
  • data portability.

B. We respect your rights under personal data protection legislation and strive to facilitate their exercise to the greatest extent possible.

C. We point out that the rights listed above are not absolute. Therefore, in certain circumstances, we may lawfully refuse to comply with your request. However, if we refuse to comply with a request, this will only be done following a thorough analysis and only where such refusal is necessary.

D. With regard to the right to object, we explain that you have the right at any time to object to the processing of your personal data based on the Data Controllers legitimate interest (as listed in section III) on grounds relating to your particular situation. However, you must bear in mind that, in accordance with applicable law, we may refuse to uphold the objection if we demonstrate that:

  • there are compelling legitimate grounds for the processing which override your interests, rights and freedoms; or
  • there are grounds for establishing, pursuing or defending against claims.

E. In addition, you may object at any time to the processing of your personal data for direct marketing purposes. In such a situation, upon receiving your objection, we will cease processing your data for this purpose.

F. You may exercise your rights in the following ways:

  • by sending an e-mail to the Data Controller at: recepcja@szarotka.eu;
  • or by informing the receptionist during your visit to our Facility.


11. Right to Lodge a Complaint

If you believe that your personal data are being processed in violation of applicable law, you may lodge a complaint with the President of the Personal Data Protection Office (UODO).

12. Final Provisions

A. Matters not regulated by this Privacy Policy shall be governed by the applicable personal data protection legislation.

B. The Facility reserves the right to amend this Privacy Policy, provided that services performed before the amendment shall be governed by the version of the Privacy Policy in force at the time the service was booked.

C. Amendments to the Privacy Policy may not infringe the rights acquired by Guests.

D. Information about an amendment to the Privacy Policy will be published on the Facility's website, www.szarotka.eu, 14 calendar days before the amendment enters into force.

E. This Privacy Policy has been in force since 16 July 2021.

Book your stay in Zieleniec

in the very center, directly on the slope
up to 25% discount on ski passes
the best price directly in the property
the best rooms within accessibility
Duszniki-Zdrój
Warsaw
473 km/4.5h
Berlin
407 km/4.4h
Karpacz
101 km/2h
Krakow
321 km/3.4h
Wroclaw
121 km/2h
Poznan
300 km/3.3h
Szczecin
453 km/4.4h
© 2026
Szarotka
A mountain hotel with a pool and saunas, designed for families with children and business travelers