Privacy
§1. GENERAL PROVISIONS
- This Privacy Policy applies to persons using the Website located at: https://lakehillmazury.pl
and has been in effect since 18.08.2026. - The controller of personal data is: MASURIA RESORT INVESTMENTS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Warsaw (00-014), ul. Stanisława Moniuszki 1A, Poland, entered in the register of entrepreneurs of the National Court Register (KRS) under number 0000659993, NIP (tax ID) 5252695748, REGON (statistical ID) 366415542 (hereinafter referred to as "We" or the "Controller").
- For matters related to the protection of personal data, please contact us at: dariusz.karpinski@audythotel.pl.
§2. PERSONAL DATA
In connection with the implementation of the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter "GDPR"), we inform you that:
- We process data for the following purposes:
- conclusion and performance of the hotel services agreement (booking, stay), including via the Profitroom system, or taking steps at the request of the data subject prior to entering into an agreement (legal basis: Art. 6(1)(b) GDPR) — we store this data for the duration of the service, and thereafter until any potential claims become time-barred (up to 6 years),
- guest registration (registration card) under the provisions on hotel services and, in the case of foreign guests, the provisions on the registration of foreigners' stay (legal basis: Art. 6(1)(c) GDPR) — includes data such as first and last name, ID/passport series and number, national ID number (if applicable), date of birth, nationality, and address of residence - up to 5 years
- handling inquiries and correspondence (Art. 6(1)(f) GDPR) — for up to 2 years from the end of the correspondence,
- handling complaints (Art. 6(1)(b) GDPR),
- keeping records and fulfilling the Controller's legal obligations, including tax and accounting obligations (Art. 6(1)(c) GDPR) — for 5 years counted from the end of the calendar year in which the tax became due,
- sending our newsletter via the Profitroom system (Art. 6(1)(a) GDPR) — until consent is withdrawn,
- monitoring and improving the quality of our services — requesting completion of a survey or answers to a few questions about the quality of the services provided (Art. 6(1)(f) GDPR) — for up to 1 year from the date the response was provided,
- displaying personalised commercial information on social media and running advertising campaigns on Google Ads and Meta Ads, including remarketing targeted on the basis of an email address (Art. 6(1)(a) GDPR) — until consent is withdrawn,
- ensuring the safety of individuals and property on the Hotel premises through video monitoring (CCTV) covering common areas, the reception and the car park (Art. 6(1)(f) GDPR) — recordings are stored for up to 30 days from the date of recording, unless a recording constitutes evidence in proceedings,
- establishing, pursuing or defending against legal claims (Art. 6(1)(f) GDPR) — until such claims become time-barred.
- Providing your data is voluntary, although necessary to use our services. Where processing is based on consent, that consent is entirely voluntary and is given by ticking a checkbox containing the terms of the consent granted.
- Where a person has given consent to data processing (legal basis: Art. 6(1)(a) GDPR), the data is processed until that consent is withdrawn, although after that point we may retain a record of who gave consent, when, and for what, for the purposes of establishing, pursuing or defending against legal claims. In other cases, data is processed for a period justified by the purpose of processing (e.g. performance of a contract, responding to enquiries, tax regulations, etc.). The retention period depends on the ability to establish, pursue or defend against claims, or on retention requirements arising from tax regulations.
- Consent may be withdrawn at any time. Please click the unsubscribe link, or send an email to the address indicated in §1(3).
- Every data subject has the right to access their personal data, to have it corrected, erased or its processing restricted, the right to object, the right to data portability, and the right to lodge a complaint with the supervisory authority. Details can be found in §8 below.
- Transaction data, including personal data, is transferred directly by the user to the payment service provider.
- Visitors to the Website may complete a form to subscribe to our newsletter and may provide an email address and/or phone number as a basis for automated contact.
- Visitors to the Website may consent to our running social media advertising campaigns targeted on the basis of an email address.
§3. RECIPIENTS OF DATA
We use the services of software companies and providers that maintain IT systems, with whom we have entered into appropriate agreements. These agreements cover data processing rules and confidentiality. This data is not disclosed further, and none of these companies is entitled to process the data in any way other than as set out in the agreement. Your data, to the extent a given company has access to it, may only be processed for the purpose of properly providing the service in question. Recipients of data include in particular:
- Profitroom — provider of the booking system, CRM and newsletter tool.
- Hosting and IT service providers supporting the operation of the Website and our systems.
- Accounting and legal service providers, and the entity supporting us in the area of personal data protection.
- Google LLC — in connection with our use of Google Ads and Google Analytics.
- Meta Platforms Ireland Ltd. — in connection with our use of Meta Ads (Meta Pixel) on Facebook and Instagram. In this respect, the Hotel and Meta may act as joint controllers of data within the meaning of Art. 26 GDPR, on the terms set out by Meta in its "Controller Addendum".
- Radisson Hotel Group — in respect of the Radisson Rewards loyalty programme, which Hotel guests may join. The rules for processing personal data under this programme are set out in Radisson Hotel Group's own, separate privacy notice, available at radissonhotels.com/en-us/privacy, while the rules of the loyalty programme itself are set out in the terms and conditions available at radissonhotels.com/en-us/terms-and-conditions.
Personal data may also be disclosed to public authorities entitled to obtain it under applicable law.
§4. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
In connection with our use of Google's and Meta's tools, personal data may be transferred to third countries, including the United States. Such transfers are based on the participation of these providers in the EU-U.S. Data Privacy Framework, following the European Commission's adequacy decision (July 2023), supplemented by standard contractual clauses (SCCs) as an additional safeguard.
§5. COOKIES
- Cookies are sent to web browsers and are then stored in device memory and read by the server each time a connection is made to the Website.
- Please note that storing cookies does not give Us access to your private device, nor does it allow Us to read any data other than that stored in the cookies themselves.
- We use so-called technical cookies, which enable the correct transmission of content, allow Us to remember your settings, and are used to create simple statistics about the Service.
- We use cookies and similar technologies to collect data that helps us analyse traffic on the Website. This allows us to optimise how it works, improve the features that are of most interest to visitors, and display tailored messages and offers. You can give consent, refuse it, withdraw it, or manage your settings by clicking here.
- We use the following cookies:
- Google Advertising Products (Google LLC) - Category: marketing. Purpose: displaying personalised ads, remarketing, tracking conversions from Google Ads campaigns, and measuring ad effectiveness. Privacy policy: policies.google.com/privacy
- Meta Ads (Meta Platforms Ireland Ltd.) - Category: marketing. Purpose: displaying ads on Facebook and Instagram, remarketing, and measuring conversions using the Meta Pixel. Privacy policy: facebook.com/privacy/policy
- Profitroom - Category: analytics / functional. Purpose: operating the booking system, analysing user behaviour during the booking process, and remembering search preferences. Privacy policy: profitroom.com/privacy-policy
- stape.io - Category: marketing. Purpose: server-side tagging — transmitting data on on-site events to external advertising and analytics platforms server-side, in order to improve measurement accuracy while maintaining GDPR compliance. Privacy policy: stape.io/privacy-policy
§6. PROFILING
As part of our marketing activities (including Google Ads and Meta Ads campaigns and personalised content on social media), personal data may be processed in an automated way in order to tailor the advertising content displayed to a user's preferences (profiling). This profiling does not produce legal effects concerning the user, nor does it similarly significantly affect them, and decisions in this regard are not made in a fully automated manner within the meaning of Art. 22 GDPR. Users have the right to object to such processing.
§7. VIDEO MONITORING
The Hotel premises (common areas, reception and car park) are covered by video monitoring (CCTV) in order to ensure the safety of guests and staff and to protect property. The legal basis for this processing is the Controller's legitimate interest (Art. 6(1)(f) GDPR). Recordings are stored for up to 30 days from the date of recording, unless a recording constitutes evidence in proceedings. Information about the areas covered by video monitoring is available in a visible location on the Hotel premises.
§8. RIGHTS OF DATA SUBJECTS
Every data subject has the right to:
- access their personal data and obtain a copy of it,
- rectify (correct) their data,
- erasure of their data ("the right to be forgotten"), to the extent provided for by law,
- restrict the processing of their data,
- data portability,
- object to processing based on the Controller's legitimate interest, including profiling,
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal,
- lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
To exercise the rights above, please contact us at the email address indicated in §1(3). You may unsubscribe from our newsletter at any time using the unsubscribe link included in every message.
§9. DATA SECURITY
The Controller applies technical and organisational measures to protect the personal data processed, appropriate to the risks involved and the categories of data being protected, in accordance with the requirements of Art. 32 GDPR, including safeguarding the data against unauthorised access, loss, destruction or unauthorised modification.
§10. CHANGES TO THIS PRIVACY POLICY
This Privacy Policy may be updated from time to time, in particular in connection with changes in the law or in the scope of the services we provide and the tools we use. The current version of this Policy is always available on this page. Last updated: 18.08.2026.
§11. INFORMATION CLAUSE
Pursuant to Article 13 of the General Data Protection Regulation of 27 April 2016 (EU Official Journal L 119 of 4 May 2016), we inform you that:
- the controller of your personal data is Europlan Zakopane sp. z o.o. with its registered office in Warsaw (00-033) at ul. Moniuszki 1a.
- your personal data will be processed for the purpose of subscribing to the newsletter, on the basis of Article 6(1)(a) of the General Data Protection Regulation of 27 April 2016.
- your personal data will be stored until you request removal from the subscription.
- you have the right to request from the controller access to your personal data and to receive a copy thereof, the right to rectify (correct) it, to erase it or restrict its processing in the cases specified in Articles 17 and 18 of the GDPR, the right to data portability, the right to withdraw your consent, and the right to data portability without affecting the lawfulness of processing carried out before its withdrawal.
- you have the right to lodge a complaint with the President of the Personal Data Protection Office if you consider that the processing of your personal data infringes the provisions of the GDPR.
- providing your personal data is voluntary, however failure to provide it will result in the inability to subscribe to the newsletter.
- your personal data will be shared with entities authorized under legal provisions, as well as with entities acting on behalf of the controller and obliged to maintain confidentiality, i.e. GiP sp. z o.o., DK Computers Usługi Informatyczne Dariusz Karpiński, Profitroom S.A.
- you may contact the Data Protection Officer at the following e-mail address: dariusz.karpinski@audythotel.pl and phone number: 515 268 610.
Information Clause for Hotel Guests
Pursuant to Article 13 of the General Data Protection Regulation of 27 April 2016 (EU Official Journal L 119 of 4 May 2016), we inform you that:
- the controller of your personal data is Europlan Zakopane sp. z o.o. with its registered office in Warsaw (00-033) at ul. Moniuszki 1a.
- your personal data will be processed for the purpose of concluding a hotel services agreement and providing hotel services to you, i.e. on the basis of Article 6(1)(b) and (f) of the General Data Protection Regulation of 27 April 2016, as well as for the purpose of fulfilling obligations arising from tax and accounting regulations, i.e. on the basis of Article 6(1)(c) of the General Data Protection Regulation of 27 April 2016.
- your personal data will be shared with entities authorized under legal provisions, as well as with entities acting on behalf of the controller and obliged to maintain confidentiality, i.e. GiP Sp. z o.o., DK Computers Usługi Informatyczne Dariusz Karpiński, Profitroom S.A.
- your personal data will be stored for a period of 3 years from the performance of the agreement, and for the period resulting from tax and accounting regulations;
- you have the right to request from the controller access to your personal data and to receive a copy thereof, the right to rectify (correct) it, the right to object to processing carried out for a legitimate purpose, the right to erasure or restriction of processing in the cases specified in Articles 17 and 18 of the GDPR, and the right to data portability.
- you have the right to lodge a complaint with the President of the Personal Data Protection Office if you consider that the processing of your personal data infringes the provisions of the GDPR.
- providing your personal data is not obligatory, however failure to provide it will make it impossible to conclude and perform the agreement;
- you may contact the Data Protection Officer at the following e-mail address: dariusz.karpinski@audythotel.pl and phone number: 515 268 610.
Information Clause for an Accompanying Person
Pursuant to Article 13 of the General Data Protection Regulation of 27 April 2016 (EU Official Journal L 119 of 4 May 2016), we inform you that:
- the controller of your personal data is Europlan Zakopane sp. z o.o. with its registered office in Warsaw (00-033) at ul. Moniuszki 1a.
- the controller processes the following data belonging to you: first name and surname.
- the controller obtained your data directly from you or from the controller's customer.
- your personal data will be processed on the basis of the controller's legitimate interest relating to ensuring fire safety on the hotel premises, as well as for the purpose of serving you meals, if this falls within the scope of the agreement with the customer.
- your personal data will be shared with entities authorized under legal provisions, as well as with entities acting on behalf of the controller and obliged to maintain confidentiality, i.e. the company responsible for maintaining the monitoring system and the company responsible for the IT system;
- your personal data will be stored for the duration of your stay at the hotel;
- you have the right to request from the controller access to your personal data and to receive a copy thereof, the right to rectify (correct) it, the right to object to the processing of your data, the right to erasure or restriction of processing in the cases specified in Articles 17 and 18 of the GDPR.
- you have the right to lodge a complaint with the President of the Personal Data Protection Office if you consider that the processing of your personal data infringes the provisions of the GDPR.
- failure to provide personal data will make it impossible to book accommodation for accompanying persons at the hotel.
- in the case of registration by phone, your voice will be processed on the basis of your consent (Article 6(1)(a) GDPR). Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
- you may contact the Data Protection Officer at the following e-mail address: dariusz.karpinski@audythotel.pl and phone number: 515 268 610.