Privacy & Cookies Policy — Orli Domek
Privacy & Cookies Policy — Orli Domek
Version 1.1, effective 01.06.2025.
1. Data controller
The controller is FHU Kamil Orlicki, NIP 9860170083, REGON 321429588, Zwycięstwa 17a, 72-514 Kołczewo, Poland, e-mail: rezerwacje@orlidomek.pl. Orli Domek is located at Wolności 5e, 72-514 Kołczewo.
2. Data and purposes
For bookings we may process your name, contact and address details, stay and guest information, invoice details, payment information, selected extras and correspondence. We use the data to take steps before entering into and to perform the accommodation contract, handle payments and the stay, comply with legal obligations, and establish, exercise or defend legal claims. Marketing is carried out only on the basis of voluntary consent where consent is required.
If you booked through a booking platform (e.g. Booking.com, Airbnb), we receive from the platform the data needed to handle the stay, in particular your name, dates, number of guests and — if the platform provides them — contact details.
3. Online check-in and registration card
Before arrival we ask you to complete the online check-in via a personal link valid until 3 days after departure. The online check-in covers: first and last name, date of birth, citizenship, address, country, e-mail address, phone number, type and number of identity document, number of adults and children (with children’s ages), pets, planned arrival time, car registration number (optional), notes and a handwritten signature.
The purpose is to confirm the identity of the Lead Guest, prepare and hand over the property, keep the stay safe and establish, exercise or defend legal claims. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and our legitimate interests (Art. 6(1)(f) GDPR), and — to the extent required by law — a legal obligation (Art. 6(1)(c) GDPR). We do not copy identity documents.
The document number, check-in data and signature are stored encrypted in the booking system. From them we create a registration card as a PDF, sent only to the hosts at the property’s e-mail address; the file is not kept on the website server. The e-mail address given in the check-in is used for further correspondence about the stay (section 4).
4. Messages about your stay
In connection with your booking we send the messages needed to handle it: the booking confirmation together with the booking terms, an invitation and a reminder for the online check-in, and information before arrival, on the arrival day and before departure. We send them by e-mail or — if the booking comes from a platform and we do not know your e-mail address — through the platform’s messaging system. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
After the stay we send one message thanking you and asking for a Google review. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR); you can object by replying to the message. Clicking the link does not pass any booking data to us or to Google; reviews are published under Google’s terms.
5. Offers
We send offers and invitations for another stay by e-mail only to people who have consented to this (Art. 6(1)(a) GDPR) — by ticking the box in the booking form or online check-in, or orally during their stay. Oral consent is recorded in the booking system with its date and source so that it can be demonstrated. Every such message contains an unsubscribe link; after unsubscribing, the address is placed on a suppression list and receives no further offers. Consent can be withdrawn at any time, also by writing to rezerwacje@orlidomek.pl.
6. Legal bases
The legal bases include performance of a contract or pre-contract steps (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR), the controller’s legitimate interests — such as security, handling complaints and claims, and review requests (Art. 6(1)(f) GDPR) — and consent where voluntarily given (Art. 6(1)(a) GDPR).
7. Recipients
Data may be shared with providers of: hosting and IT (website server), e-mail, the Smoobu booking and channel-management system, booking platforms — for bookings made through them, form abuse protection (Cloudflare Turnstile), online payment services (Stripe, PayPal) — if you choose to pay that way, banks — for bank transfers, accounting and legal services, and with public authorities where required by law. Providers receive only the data necessary for their tasks. The website hosting and e-mail provider is SEOHOST (seohost.pl).
8. Transfers outside the EEA
If a service provider processes data outside the European Economic Area, transfers are made only using safeguards required by the GDPR, as applicable to the provider and destination (e.g. standard contractual clauses or a European Commission adequacy decision). This may apply in particular to payment operators (Stripe, PayPal) and form protection (Cloudflare).
9. Retention
Booking data, including online check-in data, are kept for as long as necessary to perform the stay, settle accounts and handle claims. The adopted retention period is 60 months after the end of the stay, after which data are deleted or anonymised automatically by the booking system; accounting and tax records and data needed to defend claims may be kept longer where required by law or limitation periods. The registration card PDF is kept by the hosts in the property’s mailbox for the same period. Marketing data are processed until consent is withdrawn or the marketing purpose ends; unsubscribed addresses are kept on a suppression list so that no further messages are sent.
10. CCTV
External areas of the Property are monitored, including the gate, parking area, entrance and part of the yard. CCTV does not cover the interior or places where privacy may reasonably be expected and does not record sound. Its purposes are safety, protection of persons and property, and the establishment, exercise or defence of claims (Art. 6(1)(f) GDPR). Recordings are normally retained for 60 days unless a specific recording is needed as evidence or for claims. Access is limited to the controller and persons authorised by the controller.
11. Your rights
Where provided by the GDPR, you have rights of access and copy, rectification, erasure, restriction, data portability and objection — in particular to processing based on legitimate interests. If processing is based on consent, you may withdraw it at any time without affecting prior lawful processing. You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO).
12. Cookies and device storage
The website uses cookies and similar storage necessary for the booking form, security, session handling and essential settings. Non-essential mechanisms, such as analytics (Google) or marketing, are activated only after consent is given in the cookie banner; you can change your choice at any time in the banner settings. Details are in the Cookie Policy. You may also manage cookies in your browser settings.
13. Booking form and security
The booking form uses anti-abuse protections and short-lived quote tokens. Online check-in links are digitally signed and expire; sensitive data (document number, signature) are encrypted. Data are shared only to the extent necessary to process a particular stay.
14. Voluntary provision of data
Providing the data required to enter into and perform the contract and for the online check-in is voluntary, but without it a booking or the handover of the property may not be possible. Marketing consent is entirely optional and does not affect the ability to book.
15. Contact
For privacy matters contact rezerwacje@orlidomek.pl.
