Privacy

I. GENERAL PROVISIONS

1. This Privacy Policy concerns the processing and protection of personal data provided by users who are natural persons and use the products and services offered by Molo Park Mielno Sp. z o.o.

2. The website at www.molopark.pl is operated by Molo Park Mielno Sp. z o.o., with its registered office in Mścice at ul. Dworcowa 29, 76-031 Mścice, entered in the register of entrepreneurs of the National Court Register by the District Court in Koszalin, 9th Commercial Division of the National Court Register, under KRS number 0000768189, NIP number 4990676594, REGON number 382383427, with share capital of PLN 250,000.

3. The controller of users' personal data is Molo Park Mielno Sp. z o.o., with its registered office in Mścice at ul. Dworcowa 29, 76-031 Mścice, entered in the register of entrepreneurs of the National Court Register by the District Court in Koszalin, 9th Commercial Division of the National Court Register, under KRS number 0000768189, NIP number 4990676594, REGON number 382383427, with share capital of PLN 250,000 (hereinafter the “Controller”).

4. The Controller has appointed a Data Protection Officer. The Data Protection Officer may be contacted on all matters related to the processing of personal data in writing at: ul. Dworcowa 29, 76-031 Mścice, or by email: rodo@molopark.pl

5. The Controller processes users' personal data in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and the free movement of such data, repealing Directive 95/46/EC (hereinafter the “GDPR”), and the Personal Data Protection Act of 10 May 2018.

6. The processing of users' personal data by the Controller means an operation or set of operations performed on personal data or sets of personal data, whether by automated or non-automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or other provision, alignment or combination, restriction, erasure or destruction.

7. When processing users' personal data, the Controller uses appropriate technical and organisational measures to ensure adequate security against unauthorised or unlawful processing and accidental loss, destruction or damage.

II. PURPOSES OF PERSONAL DATA PROCESSING

1. The Controller processes users' personal data for various purposes, and such processing always complies with applicable law.

2. The Controller processes users' personal data to the extent necessary for:

a. responding to users' enquiries submitted via the contact form,

b. taking steps before entering into a contract at the data subject's request or performing a contract for services provided by the Controller to which the data subject is a party, under Article 6(1)(b) GDPR,

c. accepting bookings via the online booking system,

d. taking steps before entering into a contract at the data subject's request under Article 6(1)(b) GDPR

e. providing products or services supplied by the Controller under Article 6(1)(b) GDPR,

f. complying with the Controller's legal obligations (including tax, archiving and complaint handling obligations) under Article 6(1)(c) GDPR,

g. marketing the Controller's products and services and those of entities belonging to Molo Park Mielno Sp. z o.o., including sending commercial information by email where the Client has consented by selecting the relevant box during the booking process or when submitting an enquiry via the contact form,

h. pursuing the legitimate interests of the data Controller in specific cases under Article 6(1)(f) GDPR, e.g. debt collection or video monitoring of movement on the premises.

III. TYPES OF PERSONAL DATA PROCESSED

1. In accordance with the data minimisation principle, the Controller processes only those categories of personal data that are necessary to achieve the purposes referred to in Section II(2) of this Privacy Policy.

2. In connection with steps before entering into a contract, entering into and performing a contract for the use of products and services offered by the Controller, the Controller processes the user's personal data:

a. first and last name,

b. address details (street and building or apartment number, town/city and postcode, voivodeship, country),

c. date of birth,

d. email address,

e. telephone number,

f. NIP number where the user conducts business activity, g. IP address.

3. When responding to users' enquiries submitted via the contact form, the Controller processes the user's personal data:

a. first and last name,

b. email address,

c. telephone number,

d. IP address.

4. In connection with marketing the Controller's products and services and those of entities belonging to Molo Park Mielno Sp. z o.o., including sending commercial information, the Controller processes the user's personal data:

a. first and last name,

b. email address,

c. IP address.

5. Providing personal data by the user is voluntary; however, where the user enters into a contract for the use of products and services offered by the Controller, failure to provide certain data will make it impossible to perform the contract or provide specific services by the Controller.

IV. LEGAL BASIS FOR PROCESSING PERSONAL DATA

Users' personal data are processed on the basis of:

1. Article 6(1)(a) GDPR – where users have consented to the processing of their personal data for a specific purpose or purposes,

2. Article 6(1)(b) GDPR – where processing is necessary to perform a contract between the Controller and the user or to take steps at the user's request before entering into a contract, 3. Article 6(1)(c) GDPR – where processing users' personal data is necessary to comply with a legal obligation imposed on the Controller, 4. Article 6(1)(f) GDPR – where processing users' personal data is necessary for purposes arising from the legitimate interests pursued by the Controller or a third party, in particular for pursuing or defending claims and ensuring the security of the data Controller's property and resources (including through video monitoring of movement on the premises).

V. RETENTION PERIOD FOR PERSONAL DATA

1. Users' personal data are processed by the Controller for the period necessary to fulfil the purposes for which the data are processed or until processing is required by applicable law.

2. Where the basis for processing users' personal data is their consent, the Controller processes Users' personal data until consent is withdrawn and, after withdrawal, for a period corresponding to the limitation period for any claims available to users or the Controller.

3. Where the basis for processing users' personal data is performance of a contract, the Controller processes users' personal data for the time necessary to perform the contract and thereafter for a period corresponding to the limitation period for any claims available to users or the Controller.

4. Where the basis for processing users' personal data is the Controller's legitimate interest, the Controller processes Users' personal data until an effective objection to processing for that purpose is made.

VI. INFORMATION ON PERSONAL DATA RECIPIENTS OR CATEGORIES OF RECIPIENTS

Users' personal data may be transferred to the Controller's subcontractors, i.e. entities used by the Controller in conducting its business and performing concluded agreements and service provision; in particular, users’ personal data may be transferred to entities such as IT service providers, postal and courier service providers, reservation system service providers, payment service providers, accounting firms and marketing agencies. These entities process Users’ personal data under an agreement with the Controller and in accordance with applicable personal data protection regulations. Additional users’ personal data may be transferred to entities entitled to obtain it under applicable law, in particular judicial authorities.

VII. INFORMATION ON AUTOMATED DECISION-MAKING, INCLUDING PROFILING

The Controller may use automated decision-making, including profiling, for marketing purposes and to tailor the offer.

VIII. INFORMATION ON THE INTENTION TO TRANSFER PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS

The Controller does not intend to transfer users’ personal data to Third Countries or international organisations.

IX. INFORMATION ON USERS’ RIGHTS IN CONNECTION WITH THE PROCESSING OF THEIR PERSONAL DATA

In connection with the processing of their personal data by the Controller, Users have the following rights:

1. the right to request access from the Controller to personal data concerning them – by providing their data to the Controller, users have the right to inspect and access it; users also have the right to obtain from the Controller information concerning their personal data, including in particular the purposes and legal bases of processing, the scope of data held, the entities to which personal data is disclosed and the planned deletion date,

2. the right to rectification of personal data – users have the right to the prompt rectification of inaccurate personal data processed by the Controller,

3. the right to complete personal data – users have the right to request completion of incomplete personal data processed by the Controller,

4. the right to erasure of personal data – users have the right to request the Controller to promptly erase their personal data if one of the following circumstances applies:

a. the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;

b. the data subject has withdrawn consent on which processing is based under Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, and there is no other legal basis for processing;

c. the data subject objects under Article 21(1) GDPR to processing and there are no overriding legitimate grounds for processing, or the data subject objects under Article 21(2) GDPR to processing;

d. the personal data has been unlawfully processed;

e. the personal data must be erased to comply with a legal obligation under Union or Member State law to which the Controller is subject;

f. the personal data was collected in connection with the offering of information society services referred to in Article 8(1) GDPR.

5. the right to restriction of processing of personal data – users have the right to request that the Controller restrict processing of their personal data where:

a. the data subject contests the accuracy of the personal data – for a period enabling the controller to verify its accuracy;

b. processing is unlawful and the data subject opposes erasure of the personal data, requesting restriction of its use instead;

c. the Controller no longer needs the personal data for processing purposes, but it is required by the data subject to establish, pursue or defend claims;

d. the data subject has objected under Article 21(1) GDPR to processing – until it is determined whether the controller’s legitimate grounds override the grounds of the data subject’s objection.

6. the right to object to processing of personal data – users have the right to object:

a. to processing of their personal data based on Article 6(1)(e) or (f) GDPR, including profiling based on those provisions, for reasons related to their particular situation,

b. to processing of users’ personal data for direct marketing purposes, including profiling, insofar as it relates to such direct marketing.

7. the right to data portability – users have the right to receive, in a structured, commonly used and machine-readable format, personal data concerning them that they have provided to the Controller, and the right to transmit that data to another controller without hindrance from the Controller to whom it was provided, where processing is based on consent under Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, or on a contract under Article 6(1)(b) GDPR, and processing is carried out by automated means.

X. INFORMATION ON THE USER’S RIGHT TO WITHDRAW CONSENT TO THE PROCESSING OF PERSONAL DATA

1. If the Controller processes a user’s personal data based on consent given for one or more specified purposes, the User has the right to withdraw consent to processing their personal data for one or more of the purposes for which consent was given.

2. The User may withdraw consent to processing their personal data by:

a. sending an email to: rodo@molopark.pl

b. sending information by letter to ul. Dworcowa 29, 76-031 Mścice. If the user’s withdrawal of consent to the processing of their personal data is to concern only a specific purpose, the user should specify the scope to which the withdrawal of consent to processing applies.

4. Withdrawal of consent by the user does not affect the lawfulness of processing the user’s personal data carried out on the basis of consent before its withdrawal.

XI. RIGHT TO LODGE A COMPLAINT WITH A SUPERVISORY AUTHORITY

The data subject has the right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office, based in Warsaw at ul. Stawki 2. XII. COOKIES

1. The website www.dunebeachresort.com. uses Cookies technology and other similar technologies, including tracking pixels, to tailor its operation to users’ individual needs. Accordingly, users may consent to remembering the data and information they enter, enabling this information to be used during subsequent visits to the website without entering it again.

If users do not consent to personalising the website www.molopark.pl the Controller recommends disabling Cookies in the web browser settings.

2. Installing Cookies is necessary for the website www.molopark.pl to function properly, in particular where authorisation is required. The User may change their browser settings concerning the handling and storage of Cookies at any time.

3. The following Cookies are used as part of the website www.molopark.pl:

a. session Cookies – remain in the browser until it is closed or the user logs out of the website on which they were placed,

b. persistent Cookies – remain in the device’s web browser until deleted by the user or until the predetermined period specified in the Cookie parameters expires.

4. In terms of functionality, Cookies can be divided into:

a. conversion Cookies, which enable analysis of the performance of various sales channels,

b. tracking Cookies, which, together with conversions, help analyse the performance of various sales channels,

c. marketing Cookies, used to personalise advertising content and target it appropriately,

d. marketing Cookies, used to personalise advertising content and target it appropriately,

e. analytics tools, which help improve the user experience by understanding how users use the website,

f. essential Cookies, fundamental to the website’s basic functionality. The Cookies we use enable us to develop our website.

5. Some Cookies may be placed by the website and online reservation system provider solely for the purpose of: a. improving and supporting the reservation process, b. analysing and collecting statistical data on the use of the website and online reservation system in order to improve them.

XIII. FINAL PROVISIONS

1. Matters not covered by this Privacy Policy are governed by applicable law.

2. If this Privacy Policy changes, the user will be notified at the email address provided.