Draft - Operator details must be completed
Privacy Policy of the Siedliska11.pl website
Version: 1.0 Effective from: 01.08.2026
Contents
- § 1. General information
- § 2. Personal data controller
- § 3. Scope of data processed
- § 4. Purposes, legal bases and retention periods
- § 5. CCTV monitoring
- § 6. Cookies and similar technologies
- § 7. Maps, links and external services
- § 8. Recipients of data
- § 9. Transfers of data outside the European Economic Area
- § 10. Automated decision-making
- § 11. Rights of data subjects
- § 12. Data security
- § 13. Changes to the Privacy Policy
§ 1. General information
1. This Privacy Policy sets out the rules for processing personal data of persons using:
a) the siedliska11.pl website,
b) the Siedliska11 booking system,
c) the Siedliska11 fishery and fishing stands,
d) contact, complaint and notification forms,
e) additional services offered by the Operator.
2. This Privacy Policy fulfils the information obligation arising in particular from Articles 12 and 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter referred to as the "GDPR".
3. This Privacy Policy supplements:
a) the Rules for Use of the Siedliska11 Fishery and Fishing Stands,
b) the booking terms and conditions,
c) the price list,
d) the fishing rules,
e) safety notices published by the Operator.
4. The term "User" used in this Policy means a person visiting the website, making a booking, contacting the Operator or staying on the fishery premises.
§ 2. Personal data controller
1. The controller of personal data is Siedliska11 Sp. z o.o., address: Siedliska 91, Tax Identification Number (NIP): 88123456789, e-mail: info@siedliska11.pl, telephone: +48 888 999 111, hereinafter referred to as the "Controller" or the "Operator".
2. For matters concerning personal data, the Controller may be contacted:
a) electronically at info@siedliska11.pl,
b) in writing at the address indicated above,
c) by telephone at the number indicated above.
3. The Controller has not appointed a Data Protection Officer, unless a separate notice published on the website states otherwise.
§ 3. Scope of data processed
1. Depending on how the services are used, the Controller may process:
a) identification data, in particular first name and surname,
b) contact data, in particular email address, telephone number, town/city and postal code,
c) booking data, in particular the booking number, selected fishing stand, date and hours of stay, number of anglers, accompanying persons and children, selected extras, and information concerning a camper van, caravan, vehicles or an electricity connection,
d) payment data, in particular the amount, payment method, payment status, transaction identifier, and information concerning a refund or settlement of a deposit,
e) the content of messages, comments, complaints and notifications submitted to the Controller,
f) data included in the acknowledgement of having read the Rules, in particular first name and surname, telephone number, booking or fishing stand number, date, time and signature,
g) data concerning the guardian of a minor, if their provision is required in connection with use of the fishery,
h) data concerning accidents and safety-related incidents, including data of participants, injured persons and witnesses, a description of the incident, photographs of the incident location and information provided to emergency services,
i) an image recorded by CCTV, if monitoring has been activated and properly signposted,
j) technical data connected with use of the website, such as IP address, date and time of connection, device type, operating system, browser type, referring address, session identifier, and information stored in cookies or similar technologies.
2. As a rule, the Controller does not require the first names and surnames of children included in a booking. The system may collect only information about the number of children, unless identification of a child is necessary for safety reasons, in connection with an accident, the provision of assistance or a legal obligation.
3. The User should not enter information about health, disability or other special-category data in the "Comments" field unless this is necessary for the safe performance of the booking.
§ 4. Purposes, legal bases and retention periods
1. Handling enquiries before a booking is made Data are processed for the purpose of:
a) responding to an enquiry,
b) presenting the availability of fishing stands and the conditions of use,
c) taking steps at the User's request before entering into a contract. The legal basis for processing is Article 6(1)(b) GDPR and, in the case of general enquiries, also the Controller's legitimate interest in handling correspondence - Article 6(1)(f) GDPR. As a rule, correspondence is retained for 12 months after the matter has been closed, and for longer if it is connected with a contract, complaint or the establishment, exercise or defence of claims.
2. Booking a fishing stand and performance of the contract Data are processed for the purpose of:
a) checking the availability of a fishing stand,
b) creating and confirming a booking,
c) calculating the price and advance payment,
d) handling payments, amendments and cancellations,
e) identifying the User on the fishery premises,
f) providing access to the selected fishing stand and additional services,
g) providing organisational and safety information,
h) settling a deposit and any damage. The legal basis for processing is that the data are necessary to enter into and perform a contract - Article 6(1)(b) GDPR. Providing data marked as mandatory is necessary to make a booking. Failure to provide such data may make it impossible to enter into or perform the contract. Booking data are retained for the duration of the contract and subsequently for the period required under tax and accounting regulations and until the relevant limitation period for claims has expired.
3. Online payments. Payment may be processed through PayU, Przelewy24 or BLIK, depending on the method made available in the booking form. Data are transferred to the selected payment service provider to the extent necessary to:
a) initiate and authorise a transaction,
b) confirm payment,
c) handle refunds, complaints and settlements,
d) prevent payment fraud. The legal basis for processing is the performance of the contract - Article 6(1)(b) GDPR - and compliance with the Controller's legal obligations - Article 6(1)(c) GDPR. As a rule, the Controller does not receive the full payment card number, security code or online banking credentials. Such data are processed directly by the bank or payment service provider.
4. Accounting and tax documentation Data included in invoices, payment confirmations and other accounting documents are processed in order to comply with obligations arising from tax and accounting regulations. The legal basis for processing is Article 6(1)(c) GDPR. Documents are retained for the period required by applicable law, as a rule for 5 years calculated from the end of the relevant tax year, taking into account cases in which the running of a time limit is suspended or interrupted.
5. Complaints, refunds and claims Data are processed for the purpose of:
a) receiving and examining complaints,
b) refunding payments or settling an unused service,
c) determining liability for damage,
d) establishing, exercising or defending claims. The legal basis for processing is the performance of the contract or compliance with legal obligations - Article 6(1)(b) and (c) GDPR - and the Controller's legitimate interest in protecting its rights - Article 6(1)(f) GDPR. Data are retained until the proceedings have been concluded and the applicable limitation period for the relevant claims has expired.
6. Safety on the fishery premises and documenting incidents Data may be processed for the purpose of:
a) protecting the life and health of Users,
b) calling and cooperating with emergency services,
c) documenting accidents, injuries, falls into the water, fainting and other incidents,
d) establishing the course and causes of an incident,
e) securing evidence,
f) notifying the insurer of a loss,
g) establishing, exercising or defending claims. The legal basis for processing is the legitimate interest of the Controller and Users in ensuring safety and documenting incidents - Article 6(1)(f) GDPR - and the protection of the vital interests of a natural person - Article 6(1)(d) GDPR - where applicable. The Controller does not routinely collect health data. If health information arises in connection with an accident or the provision of assistance, it may be processed only to the extent necessary, in particular to protect the vital interests of a person who is physically or legally incapable of giving consent, or for the establishment, exercise or defence of legal claims. Incident documentation is retained until the matter has been concluded and subsequently until the relevant limitation period for claims has expired or proceedings conducted by emergency services, a court, an insurer or another competent authority have been concluded.
7. Acknowledgement of having read the Rules Data contained in a paper or electronic acknowledgement of having read the Rules are processed for the purpose of:
a) demonstrating that the rules of use and safety rules were made available,
b) identifying the person using a fishing stand,
c) documenting the performance of the Operator's obligations,
d) establishing the course of any incident or dispute. The legal basis is the performance of the contract - Article 6(1)(b) GDPR - and the Controller's legitimate interest in demonstrating the proper organisation and safety of the services - Article 6(1)(f) GDPR.
8. Electronic marketing Data may be used to send information about available dates, offers, new services, events and promotions only after separate and voluntary consent has been given. The legal basis for the processing of personal data is Article 6(1)(a) GDPR, while the basis for using email, telephone or other terminal equipment is the consent required by the Polish Electronic Communications Law. Marketing consent:
a) is not a condition for making a booking,
b) may be withdrawn at any time,
c) may be withdrawn without affecting the lawfulness of processing carried out before its withdrawal,
d) should be given separately for email messages and for telephone contact or SMS messages. Marketing data are processed until consent is withdrawn, marketing activities are discontinued or the recipient is found to be permanently inactive. Information concerning the giving and withdrawal of consent may be retained for longer in order to demonstrate the Controller's compliance with the law.
9. Ensuring the operation and security of the website Technical data and server logs may be processed for the purpose of:
a) displaying the website correctly,
b) maintaining the booking session,
c) temporarily blocking a selected date while a booking is being submitted,
d) detecting errors and failures,
e) preventing unauthorised access, attacks, automated spam and abuse,
f) creating backups,
g) determining the causes of technical incidents. The legal basis for processing is the Controller's legitimate interest in operating the website and booking system securely and reliably - Article 6(1)(f) GDPR. Standard technical logs are, as a rule, retained for no longer than 90 days, unless longer retention is necessary to investigate an incident, secure evidence or comply with a legal obligation.
§ 5. CCTV monitoring
1. The fishery premises may be covered by CCTV monitoring only after the monitored area has been properly signposted.
2. CCTV monitoring may cover in particular:
a) the vehicle entrance and pedestrian entrance to the premises,
b) car parks and access roads,
c) publicly accessible routes,
d) selected elements of infrastructure,
e) the vicinity of fishing stands or rescue equipment, where this is necessary for safety.
3. CCTV monitoring does not cover toilets, changing rooms or other places where a person may reasonably expect a high degree of privacy.
4. The purposes of CCTV monitoring are:
a) the protection of life and health,
b) the protection of property,
c) the prevention of theft, vandalism and safety breaches,
d) the documentation of accidents and other incidents.
5. The legal basis for processing images is the Controller's legitimate interest - Article 6(1)(f) GDPR.
6. Recordings are retained for no longer than 30 days from the date on which they were made, unless:
a) a recording documents an accident, loss, criminal offence or another incident,
b) it has been secured at the request of an authorised authority,
c) it is required for the establishment, exercise or defence of claims.
7. Recordings may be accessed only by authorised persons. They may be disclosed to the Police, public prosecutor's office, courts, emergency services, an insurer or other authorised entities.
8. Recordings are not used for facial recognition or the automated identification of persons.
9. If CCTV monitoring has not actually been activated, this section is for information only and does not mean that the premises are currently monitored.
§ 6. Cookies and similar technologies
1. The website may use cookies, browser local storage and other similar technologies.
2. Essential cookies may be used without separate consent if they are necessary to:
a) ensure the correct operation of the website,
b) ensure security,
c) remember privacy settings,
d) maintain the User's session,
e) operate a form and the booking system,
f) temporarily block a selected date,
g) handle a payment requested by the User.
3. Functional cookies may be used, among other things, to remember the website language version or selected settings.
4. Analytics cookies may be used only after the User has given consent. They may be used to create aggregate visitor statistics and improve the website.
5. Marketing cookies and technologies enabling the tracking of User behaviour may be used only after separate consent has been obtained.
6. During the first visit, the User should be given the option to:
a) accept all optional cookies,
b) reject all optional cookies,
c) select individual categories,
d) subsequently change or withdraw consent.
7. Refusal to consent to optional cookies must not prevent the use of the website's basic functions or the making of a booking.
8. A detailed list of cookies, including their name, provider, purpose and duration, should be available in the consent management panel.
9. The User may also delete or block cookies in their browser settings. However, blocking essential cookies may cause a form or the booking system to operate incorrectly.
§ 7. Maps, links and external services
1. The website may contain links to external map services, in particular OpenStreetMap or Google Maps.
2. After clicking a link, the User is redirected to an external service that processes data in accordance with its own rules and may act as a separate data controller.
3. If an interactive map that downloads data directly from an external provider is embedded on the website, it should be activated only after the appropriate consent has been obtained where the provider uses optional cookies or tracking technologies.
4. The Controller is not responsible for the privacy practices of external websites to which links lead.
§ 8. Recipients of data
1. Data may be transferred to entities providing the Controller with services necessary for conducting its business, in particular:
a) a hosting and server infrastructure provider,
b) the technical administrator of the website and booking system,
c) an email service provider,
d) a payment service provider and banks,
e) an accounting system provider and accounting office,
f) providers of archiving, backup and cybersecurity services,
g) insurance companies,
h) law firms and advisers,
i) entities providing maintenance and property protection services.
2. Entities processing data on the Controller's behalf may use them only in accordance with the concluded agreement and the Controller's instructions.
3. Data may be transferred to public authorities, emergency services, the Police, public prosecutor's office, courts, tax authorities or other entities if disclosure is required by law or is necessary to protect life or health.
4. The Controller does not sell personal data or disclose them to other entities for those entities' own marketing purposes.
§ 9. Transfers of data outside the European Economic Area
1. The Controller should in the first instance use providers that process data within the European Economic Area.
2. If a provider of IT, analytics, email or other services processes data outside the European Economic Area, data are transferred only on the basis of an appropriate legal mechanism, in particular:
a) a European Commission adequacy decision,
b) standard contractual clauses,
c) another mechanism permitted under the GDPR.
3. Information about the safeguard applied may be obtained by contacting the Controller.
§ 10. Automated decision-making
1. The booking system automatically:
a) checks the availability of fishing stands,
b) calculates the price of the booking and extras,
c) temporarily blocks the selected date,
d) provides information concerning payment status.
2. These activities are technical in nature and do not constitute decisions concerning the User that produce legal effects solely by automated means within the meaning of Article 22 GDPR.
3. The Controller does not carry out profiling that produces legal effects concerning the User or similarly significantly affects the User.
§ 11. Rights of data subjects
1. A data subject may have:
a) the right of access to data and to receive a copy thereof,
b) the right to rectify inaccurate data or complete incomplete data,
c) the right to erasure where the conditions specified in the GDPR are met,
d) the right to restriction of processing,
e) the right to data portability in relation to data processed by automated means on the basis of consent or a contract,
f) the right to object to processing based on a legitimate interest,
g) the right to withdraw consent at any time,
h) the right to lodge a complaint with a supervisory authority.
2. An objection to direct marketing is unconditional. Upon receiving such an objection, the Controller will cease using the data for that purpose.
3. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
4. To exercise these rights, the data subject should contact the Controller at info@siedliska11.pl.
5. The Controller may request additional information necessary to confirm the identity of the person submitting the request.
6. A person who considers that their data are processed unlawfully may lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
§ 12. Data security
1. The Controller applies technical and organisational measures appropriate to the nature of the data processed and the level of risk.
2. Such measures may include in particular:
a) an encrypted connection to the website,
b) access controls for the booking system,
c) individual accounts and passwords for authorised persons,
d) software updates,
e) backups,
f) the logging of technical events,
g) restricted access to paper documentation and recordings,
h) data processing agreements,
i) incident response procedures.
3. The User should protect their own device, email account and booking number against access by unauthorised persons.
§ 13. Changes to the Privacy Policy
1. This Policy may be amended in the event of:
a) a change in applicable law,
b) a change in the scope of services,
c) the launch of new website functions,
d) a change of technical or payment service providers,
e) the launch of CCTV monitoring, analytics or marketing tools.
2. The current version of the Policy is published on siedliska11.pl together with its effective date.
3. An amendment to the Policy does not prejudice the rights of persons whose data were collected before the amendment entered into force.
4. Privacy Policy version 1.0 is effective from 01.08.2026.
Technical inventory of cookies and browser storage
| Name | Purpose | Duration |
|---|---|---|
| s11_lang | Remembering the selected language | 1 year |
| s11r_step, s11r_station, s11r_hold | Handling the current booking | Until the tab is closed |
| s11r_last_booking | Displaying the last booking number | 30 days - removed on the next visit |
| s11_privacy_preferences | Remembering privacy preferences | 180 days |
Optional analytics and marketing tools remain disabled until voluntary consent is given.

