Back

Privacy Policy

Effective from: 1 June 2026 · Version 1.0
English version — provided for your convenience. The legally binding text of this document is the Polish-language version. In the event of any discrepancy between the language versions, the Polish version shall prevail. You can switch to Polish using the language selector above.

Table of contents

  1. Controller of personal data
  2. Purposes and legal bases of processing
  3. Scope of processed data
  4. Data recipients
  5. Retention period
  6. Rights of the data subject
  7. Cookies and similar technologies
  8. Transfers of data outside the EEA
  9. Automated decision-making and profiling
  10. Data security
  11. Changes to the privacy policy
  12. Contact

§1. Controller of personal data

  1. The Controller of your personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”) is:
    • registered address: Al. Jerozolimskie 125/127, 02-017 Warszawa
    • NIP (Tax ID): 1230850240, REGON: 015874032
    • entered in the Central Register and Information on Economic Activity (CEIDG)
    • hereinafter referred to as the “Controller” or “WLR Apartments”.
  2. The Controller may be contacted:
  3. The Controller has not appointed a Data Protection Officer. For all matters relating to the processing of personal data, please contact us at the e-mail address indicated above.

§2. Purposes and legal bases of processing

  1. Your personal data is processed for the following purposes:
    1. Conclusion and performance of the short-term rental agreement (apartment booking, stay handling, contact in matters related to the booking) — legal basis: Art. 6(1)(b) GDPR (necessity for the performance of a contract);
    2. Fulfilment of tax and accounting obligations, including issuing VAT invoices, named receipts and submitting invoices to the National e-Invoicing System (KSeF) — legal basis: Art. 6(1)(c) GDPR in conjunction with the Act on the Tax on Goods and Services and the Accounting Act;
    3. Handling online payments (Przelewy24: card, BLIK, instant transfer) and Bitcoin payments — legal basis: Art. 6(1)(b) GDPR;
    4. Handling complaints and pursuing potential claims related to the contract — legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller);
    5. Marketing of our own services (newsletter, special offers, loyalty programmes) — legal basis: Art. 6(1)(a) GDPR (consent); consent may be withdrawn at any time;
    6. Statistics, analytics, proper operation of the website and cookie handling — legal basis: Art. 6(1)(f) GDPR (legitimate interest) or Art. 6(1)(a) GDPR (consent — for cookies other than strictly necessary ones);
    7. Ensuring the safety of the stay and property (e.g. verification of an identity document at check-in) — legal basis: Art. 6(1)(f) GDPR.
  2. Providing data in the booking form is voluntary but necessary to conclude and perform the rental agreement. Without providing contact data, it is not possible to confirm the booking or to communicate in relation to it.

Summary — purpose, legal basis and retention period:

Purpose of processing Legal basis (GDPR) Retention period
Conclusion and performance of the rental agreement (booking, stay)Art. 6(1)(b)for the duration of the contract and the limitation period for claims
Tax and accounting obligations (invoices, receipts, KSeF)Art. 6(1)(c)5 years from the end of the tax year in which the obligation arose
Payment handling (Przelewy24, Bitcoin)Art. 6(1)(b)until the payment is settled and the limitation period for claims expires
Complaints and pursuit of claimsArt. 6(1)(f)until the limitation period for claims expires
Own marketing (newsletter, offers)Art. 6(1)(a) (consent)until consent is withdrawn
Statistics, analytics and cookiesArt. 6(1)(f) or (a)until consent is withdrawn / in accordance with the Cookies Policy
Safety of the stay and property (identity verification)Art. 6(1)(f)until the end of the stay and expiry of the limitation period for claims

§3. Scope of processed data

  1. During the booking process we collect the following data:
    • first name and surname;
    • e-mail address;
    • phone number together with the country dialling code;
    • country of residence;
    • number of guests, expected time of arrival and departure;
    • optionally — comments on the booking.
  2. If the VAT invoice option is selected, we additionally collect:
    • NIP (Tax ID), company name, registered address (street, postal code, town);
    • e-mail address for sending the invoice;
    • optionally — recipient details for KSeF (name, address, NIP/internal ID).
  3. If a named receipt is selected, we collect:
    • first name and surname;
    • address (street, postal code, town);
    • e-mail address for sending the receipt.
  4. At check-in we verify that the data matches the identity document (ID card, passport). We do not make copies or scans of documents — we only record that the data matches the details provided at booking.
  5. Payment data (card number, bank account details) is not stored by the Controller — it is processed solely by the payment operator Przelewy24 (PayPro S.A.) in accordance with its privacy policy.
  6. In the case of Bitcoin payments, we store only the public transaction identifier (TXID) and the receiving wallet address, for accounting purposes and payment confirmation.

§4. Data recipients

  1. We may transfer your personal data to the following categories of recipients:
    • Payment operator: Przelewy24 — PayPro S.A. with its registered office in Poznań (handling card, BLIK and instant transfer payments);
    • Accounting office servicing the Controller — to the extent necessary to keep accounting books and issue accounting documents;
    • National e-Invoicing System (KSeF) of the Ministry of Finance — in the case of issuing a VAT invoice;
    • IT service providers: hosting, e-mail, booking system, analytics, communication tools (under data processing agreements — Art. 28 GDPR);
    • Courier and postal companies — where it is necessary to send documents or items left in the apartment;
    • Law firm and debt-collection agency — in the case of pursuing claims;
    • Public authorities (tax office, courts, police, prosecutor's office) — solely to the extent and on the grounds required by law.
  2. We do not sell your personal data to third parties for marketing purposes.

§5. Retention period

  1. We will process your data for the periods indicated below:
    • Booking data and guest data — for the duration of the contract and for the limitation period of claims arising from the contract (generally up to 6 years — Art. 118 of the Civil Code);
    • Data on invoices and receipts — for a period of 5 years counting from the end of the financial year in which the document was issued (Art. 86 § 1 of the Tax Ordinance);
    • Data processed for marketing purposes — until consent is withdrawn or an objection is raised;
    • Data in cookies — in accordance with the lifetime of the given file (from a single session to 24 months, depending on the type);
    • E-mail correspondence, contact forms — up to 3 years from the last interaction.
  2. After the indicated periods have elapsed, the data will be deleted or anonymised.

§6. Rights of the data subject

  1. In connection with the processing of personal data, you have the following rights:
    • Right of access — you may obtain information on whether we process your data and receive a copy of it (Art. 15 GDPR);
    • Right to rectification — you may request the correction of inaccurate data or the completion of incomplete data (Art. 16 GDPR);
    • Right to erasure (“right to be forgotten”) — subject to data whose processing results from a legal obligation (e.g. data on VAT invoices) (Art. 17 GDPR);
    • Right to restriction of processing (Art. 18 GDPR);
    • Right to data portability — in respect of data processed on the basis of consent or a contract, by automated means (Art. 20 GDPR);
    • Right to object — to processing based on the legitimate interest of the Controller (Art. 21 GDPR); in the case of marketing, the objection is unconditional;
    • Right to withdraw consent at any time — without affecting the lawfulness of processing carried out before its withdrawal (Art. 7(3) GDPR);
    • Right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
  2. To exercise any of the above rights, please contact us at the Controller's e-mail address indicated in §1. We respond without undue delay, and no later than within one month of receiving the request.

§7. Cookies and similar technologies

  1. The website uses cookies — small text files saved on the user's device. We divide them into:
    • Necessary — required for the proper operation of the website (maintaining the session, the booking basket, security). They do not require consent;
    • Functional — they remember user preferences (currency, language, form settings);
    • Analytical — anonymous traffic statistics (e.g. Google Analytics);
    • Marketing — used to personalise advertising and measure its effectiveness (e.g. Facebook Pixel, Google Ads).
  2. Consent to cookies other than necessary ones is obtained via the cookie banner displayed on the first visit. You may at any time:
    • modify your consent through the cookie settings panel on the website;
    • withdraw it through your browser settings (instructions for the most popular browsers are available on their help pages);
    • clear it — by deleting cookies from within your browser.
  3. Disabling necessary cookies may cause the website to malfunction, in particular making it impossible to make a booking.

§8. Transfers of data outside the European Economic Area (EEA)

  1. As a rule, your data is processed within the European Economic Area.
  2. Some of the tools we use (e.g. analytics or marketing services provided by entities from the USA) may result in the transfer of data outside the EEA. In such a case, the transfer takes place:
    • on the basis of a European Commission decision confirming an adequate level of protection (e.g. the EU-US Data Privacy Framework);
    • or on the basis of Standard Contractual Clauses (SCC) approved by the European Commission;
    • or on the basis of other safeguards provided for in Art. 46 GDPR.

§9. Automated decision-making and profiling

  1. We do not make decisions about you in a solely automated manner that would produce legal effects or similarly significantly affect you (Art. 22 GDPR).
  2. For marketing purposes, we may use messages tailored to your preferences (e.g. seasonal promotions). Each such communication contains information on the possibility of unsubscribing.

§10. Data security

  1. The Controller applies appropriate technical and organisational measures ensuring the protection of the personal data processed, in particular:
    • HTTPS (TLS) connection encryption on the website;
    • access control to processing systems;
    • regular backups;
    • software updates and incident monitoring;
    • data processing agreements (Art. 28 GDPR) with IT service providers.
  2. In the event of a personal data breach that may result in a high risk to the rights or freedoms of natural persons, we will promptly notify the data subjects and the President of UODO — in accordance with Art. 33–34 GDPR.

§11. Changes to the privacy policy

  1. The current version of the Privacy Policy is available on the website.
  2. We will inform you of significant changes 14 days in advance in a manner visible on the website or by e-mail (if we have your address).
  3. The Policy in its new wording enters into force on the date indicated in its content. Continued use of the website after that date constitutes acceptance of the changes.

§12. Contact

  1. For all matters relating to the processing of personal data, please contact us:
© 2026 WLR Training Group Wojciech Jędrzejczyk · Privacy Policy version 1.0