Skip to content Skip to footer

Privacy Policy describes the rules for processing information about you, including personal data and cookies.

1. General information
  1. This policy applies to the website www.mazurskieflow.pl
  2. The service operator and data controller is: SUN AND FUN Jacek Masiak, Skorupki 146, 11-520 Ryn, NIP: 5221004826, REGON: 010751483.
  3. The operator’s email contact: mazurskieflow@gmail.com
  4. The operator is the administrator of your personal data concerning data voluntarily provided on the website.
  5. The service uses personal data for the following purposes:
    • Handling inquiries via forms
  6. The service collects information about users and their behavior in the following ways:
    1. By voluntarily entering data in forms, which are then entered into the Operator’s systems.
    2. By storing cookie files (“cookies”) on end devices.
2. Selected data protection methods used by the Operator
  1. Places for logging in and entering personal data are protected in the transmission layer (SSL certificate). This encrypts personal data and login data entered on the website into the user’s computer and can only be read on the target server.
  2. Personal data stored in the database is encrypted in such a way that only the Operator possessing the key can read it. This protects data in case of theft of the database from the server.
  3. User passwords are stored in hashed form. The hashing function works one-way – it is not possible to reverse its operation, which is the current standard for storing user passwords.
  4. The service uses two-factor authentication, providing additional login protection.
  5. The Operator periodically changes its administrative passwords.
  6. The Operator regularly backs up data to protect it.
  7. Regularly updating all software used by the Operator to process personal data is an essential part of data protection, particularly regular updates of software components.
3. Hosting
  1. The service is hosted (technically maintained) on the operator’s servers: hostinghouse.pl
4. Your rights and additional information about data usage
  1. In some situations, the Administrator has the right to transfer your personal data to other recipients if necessary to fulfill the contract concluded with you or to fulfill obligations incumbent on the Administrator. This applies to such groups of recipients:
    • persons authorized by us, employees, and associates who need access to personal data to perform their duties,
    • hosting company,
    • companies handling mailings,
    • companies handling SMS messages,
    • companies with which the Administrator cooperates in the field of its own marketing,
    • couriers,
    • insurers,
    • law firms and debt collectors,
    • banks,
    • payment operators,
    • public authorities.
  2. Your personal data processed by the Administrator will not be retained longer than necessary for the purposes for which they were collected, as specified by separate regulations (e.g., accounting regulations). Regarding marketing data, the data will not be processed for more than 3 years.
  3. You have the right to request from the Administrator:
    • access to your personal data,
    • their rectification,
    • erasure,
    • restriction of processing,
    • and data portability.
  4. You have the right to object to the processing referred to in point 3.3 c) regarding the processing of personal data for the purpose of the legitimate interests pursued by the Administrator, including profiling, provided that the right to object cannot be exercised in the case of the existence of compelling legitimate grounds for processing, overriding your interests, rights, and freedoms, in particular the establishment, investigation, or defense of legal claims.
  5. You have the right to lodge a complaint with the President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw, regarding the actions of the Administrator.
  6. Providing personal data is voluntary but necessary for the operation of the Service.
  7. Actions may be taken against you involving automated decision-making, including profiling, for the purpose of providing services under the concluded contract and for direct marketing conducted by the Administrator.
  8. Personal data is not transferred to third countries within the meaning of personal data protection regulations. This means that they are not transferred outside the European Union territory.
5. Information in forms
  1. The service collects information voluntarily provided by the user, including personal data if provided.
  2. In some cases, the service may save information facilitating the connection of data in the form with the user’s email address filling out the form. In such a case, the user’s email address appears within the URL of the page containing the form.
  3. Data provided in the form is processed for the purpose resulting from the function of a specific form, e.g., to carry out the service request process or commercial contact, service registration, etc. Each time, the context and description of the form clearly indicate its purpose.
6. Administrator logs
  1. Information about user behavior on the website may be subject to logging. This data is used to administer the service.
7. Important marketing techniques
  1. The Operator uses statistical analysis of website traffic through Google Analytics (Google Inc. based in the USA). The Operator does not provide personal data to the service provider, only anonymized information. The service is based on the use of cookies on the user’s end device. Regarding information about user preferences collected by the Google advertising network, the user can view and edit the information resulting from cookies using the following tool: https://www.google.com/ads/preferences/
8. Information about cookies
  1. The service uses cookies.
  2. Cookies are computer data, especially text files, which are stored in the user’s end device and are intended for using the Service’s websites. Cookies usually contain the name of the website they come from, the time of storing them on the end device, and a unique number.
  3. The entity placing cookies on the user’s end device and accessing them is the operator of the Service.
  4. Cookies are used for the following purposes:
    1. maintaining the user’s session on the Service (after logging in), thanks to which the user does not have to re-enter their login and password on each page of the Service;
    2. achieving the goals specified above in the “Important marketing techniques” section;
  5. Two basic types of cookies are used within the Service: “session” cookies and “persistent” cookies. “Session” cookies are temporary files that are stored on the user’s end device until logging out, leaving the website, or turning off the software (web browser). “Persistent” cookies are stored on the user’s end device for the time specified in the cookie parameters or until they are deleted by the user.
  6. The software for browsing websites (web browser) usually allows storing cookies on the user’s end device by default. Service users can change their cookie settings. The web browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this subject is provided in the help or documentation of the web browser.
  7. Limiting the use of cookies may affect some of the functionalities available on the Service’s websites.
  8. Cookies placed on the user’s end device may also be used by entities cooperating with the Service operator, in particular, this applies to companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA), Twitter (Twitter Inc. based in the USA).
9. Managing cookies – how to express and withdraw consent in practice?
  1. If the user does not want to receive cookies, they can change their browser settings. Please note that disabling cookies necessary for authentication processes, security, maintaining user preferences may hinder, and in extreme cases may prevent the use of websites.
  2. To manage cookie settings, select from the list below the web browser you use and follow the instructions: Mobile devices: