PRIVACY POLICY

Article 1 Details of the Personal Data Controller

Please be advised that the controller of your personal data is Gołębiewski Holding sp. z o.o., with its registered office in Ciemne; 05-250 Ciemne, Radzymin; ul. Wołomińska 125, Tax Identification No. (NIP): 125-173.93-35, National Business Registry No. (REGON): 523380176, entered into the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register (KRS), under KRS Number: 00009996308, hereinafter referred to as ‘TAGO’

Article 2 Data Protection Officer

TAGO has appointed a Data Protection Officer who will be happy to assist you with any matters relating to the protection of personal data, and in particular will answer any questions you may have regarding the processing of your personal data. You can contact the Data Protection Officer at the following email address: iod@golebiewski.pl;

Article 3 Purposes and legal basis for the processing of personal data

In order to provide services in line with its business profile, TAGO processes your personal data for various purposes, but always in accordance with the law. Provided personal data will be processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR). We collect your personal data either from you as part of the process leading up to the conclusion of a contract, or from our partners on booking platforms, provided you have given your consent. Below you will find a detailed list of the purposes for which we process personal data, together with the legal bases.

a. In order to conclude and perform a contract for the purchase, sale, supply or any other contract falling within the scope of our business activities, we may process personal data such as:
∙ First and last name;
∙ Address (street, street number, postcode and town/city);
∙ Telephone number;
∙ E-mail address;
∙ Company details, including the company’s tax identification number (if a VAT invoice is to be issued to the company);
∙ The registration number of the Customer’s vehicle;
∙ Basic bank account details for confirming the wire transfer;
∙ ID number/PESEL identification No.;
∙ Order number;
∙ Your payment card number and other card details, as well as authentication details and other billing and account information relating to mobile payments;
The legal basis for such data processing is Article 6(1)(b) of the GDPR, which permits the processing of personal data where it is necessary for the performance of a contract or for taking steps to enter into a contract.

b. In order to handle your complaint, we process personal data such as:
∙ First and last name;
∙ Address (street, street number, postcode and town/city);
∙ Telephone number;
∙ E-mail address;
∙ Order number;
∙ Alternatively, your bank account number – if a refund is to be made.
The legal basis for such data processing is Article 6(1)(b) of the GDPR, which permits the processing of personal data where it is necessary for the performance of a contract or for taking steps to enter into a contract;

c. In order to issue invoices and fulfil other legal obligations, such as retaining accounting records for five years, complying with the Central Statistical Office’s statistical requirements, or paying local taxes, we process the following personal data:
∙ First and last name;
∙ Company name;
∙ Home address or registered office address;
∙ Tax identification number (NIP);
∙ Order number.
The legal basis for such data processing is Article 6(1)(c) of the GDPR, which permits the processing of personal data where such processing is necessary for the Data Controller to comply with a legal obligation;

d. In order to ensure the safety of employees and visitors on the TAGO premises and to prevent fraud, we process personal data such as:
∙ Image from the CCTV system;
∙ First and last name;
∙ E-mail address;
∙ Telephone number;
∙ IP address;
∙ ID number.
The legal basis for such data processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing a legitimate interest (in this case, the Hotel’s interest is to ensure the safety of all persons on the Hotel’s premises). CCTV footage is deleted no later than 30 days after it is recorded.

e. In order to maintain records and registers relating to the GDPR, including, for example, a register of customers who have objected in accordance with the GDPR, we process personal data such as:
∙ First and last name;
∙ E-mail address.
The provisions of the GDPR impose certain documentation obligations on us to demonstrate compliance and accountability. If, for example, you object to the processing of your personal data for marketing purposes, we need to know who not to target with direct marketing.
The legal basis for such data processing is Article 6(1)(c) of the GDPR, which permits the processing of personal data where such processing is necessary for the Data Controller to fulfil its legal obligations (the provisions of the GDPR); and Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing a legitimate interest (in this case, TAGO’s interest is to have knowledge of the persons exercising their rights under the GDPR);

f. In order to establish, investigate or defend against claims, we process personal data such as:
∙ First and last name (if a surname has been provided) or, alternatively, company name;
∙ Home address (if provided);
∙ PESEL No. or NIP No. (if provided);
∙ E-mail address;
∙ IP address;
∙ Order number.
The legal basis for such data processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing a legitimate interest (in this case, TAGO’s interest is to hold personal data that will enable it to establish, assert or defend against claims, including those from customers and third parties);

g. For analytical purposes, i.e. to monitor and analyse your activity on TAGO’s website, we process personal data such as:
∙ Date and time of your visit to the website;
∙ Operating system type;
∙ Approximate location;
∙ Type of web browser used to view the website;
∙ Time spent on the website;
∙ Pages visited;
∙ Page where the contact form has been completed.
The legal basis for such data processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interests (in this case, TAGO’s interest is to understand customer activity on the website).

h. In order to use cookies on the website, we process such text-based information (cookies will be described in a separate section). The legal basis for such processing is Article 6(1)(a) of the GDPR, which permits the processing of personal data on the basis of freely given consent (a request for consent to the use of cookies appears when you first visit the website);

i. In order to manage the website, we process personal data such as:
∙ IP address;
∙ Server date and time;
∙ Information about your web browser;
∙ Information about your operating system
This data is automatically recorded in server logs every time you visit a TAGO website. It would not be possible to manage a website without a server and without this automatic logging. The legal basis for such data processing is Article 6(1)(f) of the GDPR, which permits the processing of personal data where the Data Controller is pursuing its legitimate interests (in this case, TAGO’s interest is the website management);

j. In order to market our own products and services, send marketing communications (newsletters) electronically , as well as via other communication channels to which you have given your consent, and to analyse statistical data – i.e. to assess and analyse the effectiveness of marketing campaigns – we process the following personal data:
∙ First and last name;
∙ E-mail address;
∙ Address of residence;
∙ Information regarding previous purchases;
∙ Telephone number.
The legal basis for processing such data is Article 6(1)(a) of the GDPR, which permits the processing of personal data on the basis of consent freely given. This personal data will be stored until your consent is withdrawn.

k. In order to manage competitions, we process personal data such as:
∙ First and last name;
∙ Address (street, street number, postcode and town/city);
∙ Telephone number;
∙ E-mail address;
∙ Date of birth
The legal basis for processing such data is Article 6(1)(a) of the GDPR, which permits the processing of personal data on the basis of consent freely given.

Article 4 Cookies

  1. Similar to other companies, TAGO uses so-called cookies on its website, which are small text files stored on the user's computer, phone, tablet or other device. They can be read by our system and by systems of other entities whose services we use (e.g. Meta Platforms, Google’a, PayPal).
  2. Cookies perform many functions on the website, usually useful functionalities, which we attempted to describe below (if the information is insufficient, please contact us):
    ∙ providing security – cookies are used to authenticate users and prevent unauthorised use of the customer panel. Thus, they protect your personal data from unauthorised access;
    ∙ impact on the processes and the efficiency of website use – cookies are used to ensure that the website runs smoothly and that the available functions available can be used, which is possible i.e. thanks to remembering your settings between individual website visits. Thus, they enable smooth navigation of the website and its individual pages;
    ∙ session status – cookies often store information about how visitors use the website, e.g. which pages they view most often. They also enable the identification of errors displayed on certain subpages. Cookies used to store the so-called “session status” therefore help us improve services and enhance the browsing experience;
    ∙ maintaining session status – if the customer logs in to their panel, cookies enable the session to be continued. This means that the user does not have to enter the login and the password again after visiting a different subpage. This enhances the comfort of using the website;
    ∙ statistics generation – cookies are used to analyse how users use the website (how many visit the website, how long they stay, which content is the most interesting, etc.). This allows the website to be continuously improved and adapted to user preferences. We use tools provided by Google, such as Google Analytics, to track the activity and generate statistics; in addition to statistic reporting for the use of the website, the pixel Google Analytics may also be used in combination with some of the cookie files described above to help displaying the user more accurate content in Google services (e.g. in the Google search engine) and throughout the network;
    ∙ marketing techniques and ad personalisation – these allow advertising messages to be tailored to users’ behaviour on the website. Cookies are used to track users on the Controller’s websites and in the mobile app provided by the Controller. The aim is to display ads that are relevant and of interest to individual users. In order to perform these functions, the Controller uses tracking technologies, including Web Push, as referred to in paragraph 5.
    ∙ use of social functionalities – we have a so-called Facebook pixel on the website, which allows the user to like our Facebook fanpage when using the website. We must use the cookies provided eg. by Meta to enable this, however.
  3. Your browser enables the use of cookies on your device by default; this is why we ask for the consent to use the cookies during the first website visit. However, if you do not wish to use cookies while browsing the website, you can change the settings of your browser – by completely blocking automatic handling of cookies or to request a notification each time cookies are saved on your devices. These settings can be changed at any time.
  4. We respect the autonomy of all visitors to the website, however, we feel obliged to forewarn that disabling or limiting the cookies may result in significant difficulties in using the website, e.g. in the need to log on every subpage, longer page loading times, limited functionalities, etc.
  5. We use Web Push technology to send you regular brief notifications, in particular the latest news, information and offers regarding our services.

    Article 5 Right of consent withdrawal

  6. If the processing of your personal data is based on your consent, you may withdraw this consent at any time.
  7. You may withdraw your consent to the processing of your personal data for the purpose described in § 3(l) at any time via the user panel on the website or in the mobile app provided by the Controller, by clicking the link in the email entitled ‘unsubscribe’ or by sending a statement to the email address: zgody@golebiewski.pl. This personal data will be stored until your consent is withdrawn.
  8. If the processing of your personal data was carried out on the basis of your consent, the withdrawal of this consent does not render the processing of your personal data until that point unlawful. In other words, we have the right to process your personal data until the consent is withdrawn, and the withdrawal does not impact the legality of processing until this point.


    Article 6 Requirement to provide personal data

  9. Providing any personal data is entirely voluntary and is at your discretion. However, in some cases, the provision of certain personal data is necessary in order to meet your expectations regarding the use of the services.
  10. To enter into a contract with TAGO, you must provide the data specified in Article 3(a) of this privacy policy.
  11. To receive an invoice, you are required to provide all data required by the tax laws, without which we are unable to issue a correct invoice.
  12. In order to be able to contact you by phone regarding the provision of services, we require you to provide your telephone number and e-mail address, without which we cannot contact you by phone or send a booking confirmation.

    Article 7 Automated decision-making and profiling

    The Controller may use profiling (i.e. automated data processing) to create user profiles, analyse preferences, behaviour and interests, and send personalised marketing communications, promotions and commercial offers. The Controller shall not make a decision based solely on automated processing, including profiling, which produces significant effects on the data subject.

    Article 8 Recipients of personal data

  13. Like most businesses, we rely on the assistance of third parties in our operations, which sometimes involves the need to transfer personal data. Accordingly, where necessary, we may share your personal data with lawyers working with us who provide services, companies handling instant payments, an accountancy firm, a web hosting provider, a company responsible for sending text messages, providers of system solutions such as a booking system or a customer satisfaction survey system, service providers handling newsletter distribution and direct marketing, as well as an insurance company (should it become necessary to compensate for any damage).
  14. It may also be the case that we are obliged to provide your personal data to other entities and authorities, e.g. on the basis of the relevant legal regulation or a decision of a competent authority.

    Article 9 Transfer of personal data to third countries

  15. Like most businesses, we use a range of popular services and technologies provided by companies such as Meta, Microsoft, Google and Zendesk. These companies are based outside the European Union and are therefore treated as third countries under the provisions of the GDPR.
  16. The GDPR introduces certain restrictions on the transfer of personal data to third countries, since European regulations generally do not apply there, and the protection of personal data of EU citizens may unfortunately be insufficient. Therefore, every personal data controller is required to establish the legal basis for such data transfers.
  17. For our part, we assure you that when using our services and technologies, we transfer personal data only to entities in the United States, and only to those that have joined the Privacy Shield programme, pursuant to the European Commission’s Implementing Decision of 12 July 2016 – you can read more about this on the European Commission’s website at https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/eu-us-privacy-shield_pl. Companies which acceded to the Privacy Shield programme represent that they observe high standards applicable to personal data protection effective in the European Union, thus the use of their services and offered technology used with personal data processing is legal.
  18. We can provide you with further clarification on the transfer of personal data at any time, particularly if the issue concerns you.

    Article 10 Personal data processing period

  19. In accordance with the applicable legislation, we do not process your personal data indefinitely, but for a period of time necessary to achieve the stated purpose. After this period, your personal data will be permanently deleted or destroyed.
  20. Where we do not need to process your personal data other than storing it (e.g. when we store the contents of an order for the purpose of defence against claims), we additionally secure it by pseudonymisation – until it is permanently deleted or destroyed. Pseudonymisation involves the encryption of personal data, or a set of personal data, in such a way that it cannot be read without an additional key, and therefore such information becomes completely useless to an unauthorised person.
  21. Regarding the specific periods of time for personal data processing, we would like to advise that we process the personal data for the following periods of time:
    ∙ the duration of the contract – in relation to personal data processed for the purpose of concluding and performing the contract;
    ∙ 3 years or 10 years + 1 year – in relation to personal data processed for the purpose of establishing, pursuing or defending legal claims (the length of the period depends on whether both parties are businesses or not);
    ∙ 6 months – in respect of personal data collected during the quotation process, where no contract was concluded immediately;
    ∙ 5 years – in respect of personal data relating to the fulfilment of obligations under tax law;
    ∙ until your consent is withdrawn or the purpose of processing is achieved, in respect of personal data processed on the basis of the consent;
    ∙ until an objection is successfully lodged or the purpose of the processing is achieved, but for no longer than 5 years – in respect of personal data processed on the basis of the Data Controller’s legitimate interest;
    ∙ until such time as the data becomes out of date or no longer relevant—in relation to personal data processed primarily for analytical purposes, the use of cookies and the management of the website.
  22. We count the periods in years starting at the end of the year, during which we started the processing of personal data, to facilitate the process of destroying or deleting personal data. The separate counting of the deadline for each concluded contract would entail significant organisational and technical difficulties and significant expenses, thus setting a single date of deletion or destruction of personal data helps us facilitate the management of these processes. If you exercise your right to be forgotten, such situations are handled on a case-by-case basis, of course.
  23. The additional year related to the processing of personal data collected for the purpose of contract execution results from the fact that you can hypothetically raise a claim immediately before the expiry period ends, and the claim may be delivered with a significant delay or you may incorrectly set the expiry deadline for your claim.

    Article 11 Rights of data subjects
  24. We would like to inform you that you have the right to:
    ∙ access your personal data;
    ∙ rectify your personal data;
    ∙ request that your personal data be erased;
    ∙ restrict the processing of your personal data;
    ∙ object to the processing of your personal data;
    ∙ be forgotten where other legal provisions so permit;
    ∙ receive a copy of your data
    ∙ transfer your personal data.
  25. We respect your rights under data protection legislation and strive to facilitate the exercise of these rights to the greatest extent possible.
  26. We would like to point out that the listed rights are not absolute and that we may therefore legitimately refuse the related requests in certain situations. However, if we refuse to grant a request, such a decision is made only after careful consideration and only if the refusal to grant the request is necessary.
  27. In regards to the right to object, we would like to explain that you can object to the processing of personal data on the basis of legally justified interest of the Personal Data Controller (which is listed in paragraph III) at any time, in relation to your special situation. You must remember, however, that we may refuse to acknowledge the objection legally, if we can prove that:
    ∙ there are legitimate grounds for processing which override your interests, rights and freedoms, or
    ∙ there are grounds for the establishment, assertion or defence of claims.
  28. Furthermore, you may withdraw your consent to the processing of your personal data at any time in accordance with Article 5. In this situation, we shall cease the processing for this purpose upon the receipt of consent withdrawal.
  29. You can exercise your right to object in the following way:
    ∙ send an email to the Data Protection Officer at iod@golebiewski.pl or
    ∙ send such a request to the Data Protection Officer at – ul. Wołomińska 125, Ciemne, 05-250 Radzymin.

Article 12 Right to lodge a complaint

If you believe that your personal data is being processed contrary to the applicable law, you may lodge a complaint with the President of the Data Protection Authority.

Article 13 Final provisions

  1. The data protection regulations shall apply to any matters not covered by this Privacy Policy.
  2. TAGO reserves the right to make changes to this Privacy Policy.
  3. Changes to the Privacy Policy must not infringe upon the rights acquired by our Guests.
  4. Information about changes to the Privacy Policy will be published on TAGO's website: www.tago.com.pl 14 calendar days before the changes take effect.
  5. This Privacy Policy is effective as of 12 February 2026.