PRIVACY POLICY DESERT-STORIES.COM

§ 1 General Provisions

 

  1. The Administrator of the personal data of users of the online service available under the domain www.desert.pl is Agata Orowiecka-Khidouma, conducting business activity under the name DESERT STORIES AGATA OROWIECKA-KHIDOUMA, entered in the Central Register and Information on Economic Activity of the Republic of Poland maintained by the minister competent for economic affairs, with its registered office at: ul. Brzozowa 12, 07-202 Kamieńczyk, NIP: 5222608213, REGON: 542272078 (hereinafter: the “Administrator”).
  2. The Administrator has designated an electronic contact point intended for direct communication with the authorities of the Member States, the Commission, and the Digital Services Board: [email protected]. The same contact point may also be used by any user for direct and prompt communication with the Administrator. The Administrator can also be contacted in writing at: ul. Brzozowa 12, 07-202 Kamieńczyk, via its social media channels (Facebook, Instagram), through the contact form provided on its website, and at the following telephone numbers: +48 789086459 or +212 645020842 (costs as for a standard telephone call, according to the tariff package of the service provider used by the Participant). Communication may be conducted in Polish or English.
  3. The purpose of this Policy is to define the actions taken with regard to personal data collected via the Administrator’s website and the related services and tools used by its users, as well as in the context of activities related to concluding and performing contracts outside of the website.
  4. Where necessary, the provisions of this Policy may be amended. Any change shall be communicated to users by publication of the new version of the Policy, and in the case of a database of persons who have consented to the processing of their data by e-mail or who provided e-mail data when performing contracts, they shall also be notified of the change by e-mail.

 

§ 2 Legal Bases, Purposes and Storage of Personal Data

 

  1. Users’ personal data are processed in accordance with the General Data Protection Regulation, the Personal Data Protection Act of 10 May 2018, and the Act on the Provision of Electronic Services of 18 July 2002, together with their subsequent amendments, and — for the purpose of making a notification under Article 16(1) of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services and amending Directive 2000/31/EC (Digital Services Act) (OJ L 277, 2022, p. 1, as amended; “DSA”) — also pursuant to Article 3(h) DSA.
  2. The Administrator may collect the following data for the following purposes:

PURPOSE OF DATA PROCESSING

LEGAL BASIS FOR PROCESSING AND DATA RETENTION PERIOD

DATA RETENTION PERIOD

SCOPE OF DATA PROCESSED

Performance of a contract with the Customer or taking action at the request of the data subject prior to entering into the above-mentioned contracts

Article 6(1)(b) of the GDPR (performance of a contract).

•    for the duration of the above-mentioned agreement    until the expiry of  the legal obligation related to accounting

•    the data will be processed until the end of the period during which it is possible to pursue claims

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    company name,

•    tax identification number

Marketing

Article 6(1)(a) of the GDPR (consent)

• Until consent is withdrawn – remember, you can withdraw your consent at any time. Data processing remains lawful until you withdraw your consent.

• Data will be processed until the end of the period during which claims can be pursued.

• Until you unsubscribe from the newsletter.

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

Customer feedback

Article 6(1)(a) of the GDPR

•    if no opinion is expressed within 30 days of your purchase or until the objection to processing is accepted;

•    if an opinion is expressed – until it is removed or until the objection to processing is accepted

•    the data will be processed until the end of the period during which claims can be pursued

•    first and last name;

•    email address;

•    phone number;

Bookkeeping

Article 6(1)(c) of the GDPR in conjunction with Article 86 § 1 of the Tax Ordinance, i.e. of January 17, 2017 (Journal of Laws of 2017, item 201) or Article 74(2) of the Accounting Act, i.e. of January 30, 2018 (Journal of Laws of 2018, item 395).

•    the data will be processed until the end of the period during which claims may be pursued

•    the data is stored for the period required by law for the storage of tax records (until the expiry of the limitation period for tax liabilities, unless tax laws provide otherwise) or accounting records (5 years from the beginning of the year following the financial year to which the data relates).

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    tax identification number;

•    company name;

Making refunds

Performance of a contract or taking steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) of the GDPR).

5 years after the end of business relations with the Customer

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    business entity details.

Determining, investigating, or defending claims that may be raised by the Administrator or that may be raised against the Administrator

Article 6(1)(f) of the GDPR

• Data is stored for the duration of our legitimate interest, but no longer than the limitation period for claims against the data subject in relation to our business activities.

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    tax identification number;

•    company name;

Customer service provision

Performance of a contract or taking steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) of the GDPR)

•    5 years after the end of business relations with the Customer

•    2 years after the last update of the Customer’s inquiry

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    business entity details,

Correct functioning of the website

Maintaining the performance of the Website and improving it (Article 6(1)(f) of the GDPR)

•    5 years after the end of business relations with the Customer

• As in the cell above,

• Information about activities performed on the website (button clicks, visit duration, notifications read, other information depending on the specific business case).

Overseeing compliance with regulations, agreements, and privacy policies

Protection and security of the website, interests of Customers, ensuring Customer security (Article 6(1)(f) of the GDPR)

•    5 years after the end of business relations with the Customer

• transaction data,

• business entity data.

Processing requests concerning personal data,

Article 6(1)(c) of the GDPR

• The period of existence of the Administrator’s legitimate interest, but no longer than the limitation period for claims against the data subject in relation to the business activity conducted.

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    tax identification number;

•    company name.

Providing information to law enforcement agencies and other state institutions,

Article 6(1)(c) of the GDPR

• The period of existence of the Administrator’s legitimate interest, but no longer than the limitation period for claims against the data subject in relation to the business activity conducted.

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    tax identification number;

•    company name.

Compliance with the legal obligation specified in Article 16(1), (4), (5), and (6) of the DSA, consisting of:

1. accepting information from a notification of presence on a hosting service which, in the opinion of the notifier, constitutes illegal content within the meaning of Article 3(h) of the DSA;

2. examining the notification;

3. informing the notifying party of the decision taken on the notification;

4. informing the notifying party of the possibility of appealing against the decision referred to in point 3).

Article 6(1)(c) of the GDPR

Until notification of:

1) the decision made by the Administrator regarding the notification;

2) the possibility of appealing against the decision referred to in point 2).

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    tax identification number;

•    company name.

Processing of personal data to the extent that, on the basis of proceedings conducted before authorized

public administration bodies, including law enforcement authorities, in matters concerning the purposes or grounds for processing personal data, the Controller is obliged to process them.

Article 6(1)(c) of the GDPR

For the duration of such obligation

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    tax identification number;

•    company name.

Taking action to identify and report potential product hazards, ensure product compliance with safety requirements, and inform the relevant authorities or users of the need to take safety measures, to the extent required by the GPSR Regulation.

Article 6(1)(c) of the GDPR

For the duration of such obligation

•    first and last name;

•    email address;

•    phone number;

•    address (street, house number, apartment number, postal code, city, country),

•    tax identification number;

•    company name.

 

  1. The Administrator may use profiling for the purposes of direct marketing, but decisions made by the Administrator on this basis do not concern the conclusion or refusal to conclude a contract, nor the possibility of using electronic services.
  2. To the extent necessary for the proper functioning of the website and its functionalities, the site may, during the User’s use thereof, collect other information, including but not limited to:
  1. a) IP address;
  2. b) information about the device, hardware and software, such as hardware identifiers, mobile device identifiers (e.g. Apple Identifier for Advertising \[“IDFA”] or the advertising identifier on an Android device \[“AAID”]);
  3. c) type of platform;
  4. d) data concerning the internet browser, including the type of browser and preferred language.
  1. Taking into account the nature, scope, context and purposes of the processing, as well as the risk of violation of the rights or freedoms of natural persons of varying likelihood and severity, the Administrator implements appropriate technical and organizational measures to ensure that the processing is carried out in compliance with the Regulation and to be able to demonstrate such compliance. These measures are reviewed and updated as necessary. The Administrator applies technical measures preventing the acquisition and modification of personal data transmitted electronically by unauthorized persons.

§  3 Udostępnianie danych

  1. The Administrator ensures that all collected personal data serve to fulfil obligations towards users. Such information shall not be disclosed to third parties except in situations where:

    a) prior explicit consent of the persons concerned has been given for such disclosure, or
    b) the obligation to disclose such data results from or will result from applicable provisions of law, e.g. to law enforcement authorities.

  2. In addition, personal data of service recipients and clients may be transferred to the following recipients or categories of recipients:

    a) service providers supplying the Administrator with technical, IT and organizational solutions enabling the Administrator to conduct its business activities, including the website and electronic services provided through it (in particular providers of computer software, marketing agencies, providers of e-mail and hosting services, providers of software for business management and for providing technical support to the Administrator, and product delivery operators) – the Administrator shall provide collected personal data of the Client to a selected provider acting on its behalf only where and to the extent necessary to achieve the relevant purpose of data processing in accordance with this privacy policy;
    b) providers of accounting, legal and advisory services supporting the Administrator in accounting, legal or advisory matters (in particular an accounting office, law firm or debt collection company) – the Administrator shall provide collected personal data of the Client to a selected provider acting on its behalf only where and to the extent necessary to achieve the relevant purpose of data processing in accordance with this privacy policy;
    c) providers of payment gateways and payment solutions used on the website – the Administrator shall provide collected personal data of the Client to a selected provider acting on its behalf only where and to the extent necessary to achieve the relevant purpose of data processing in accordance with this privacy policy.


    3. The Administrator may share anonymized data (i.e. data that do not identify specific Users) with external service providers to better recognize the attractiveness of advertisements and services for users, and in this context — due to the registered office of the software providers — data may be transferred, with due regard for data protection principles, to third countries, provided that such countries ensure compliance with the standard contractual clauses approved by the European Commission for personal data processing or have appropriate authorizations to do so under bilateral data processing agreements between the European Union and the given third country, not being a member of the European Economic Area. In the case of the Administrator, these entities are:
    • Google LLC (head office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) for the tools: Google Analytics (website traffic analysis), Google Tag Manager (managing scripts and tracking user actions on the website), Google Ads (displaying sponsored links in Google search results and on partner websites under the Google AdSense program), Google Workspace (comprehensive site editing and coordination of persons working on it, including Google Drive, Gmail, Google Sheets, Google Forms, Google Looker Studio);
    • WordPress (head office: CT Corporation System, 330 N Brand Blvd., Glendale, California 91023-2336) for the purposes of hosting and construction of the website as well as website traffic analysis and tracking of user activity on the website.


4. The Administrator continuously carries out risk analyses to ensure that personal data are processed securely — primarily ensuring that access to the data is granted only to authorized persons and only to the extent necessary for the tasks they perform. The Administrator ensures that all operations on personal data are recorded and carried out only by authorized employees and collaborators.

5. The Administrator takes all necessary steps to ensure that its subcontractors and other cooperating entities also guarantee the use of appropriate security measures whenever they process personal data on behalf of the Administrator.

6. The Administrator’s website may use the functionality of Google Analytics, a web analytics service provided by Google LLC (“Google”). Google Analytics uses cookies to help website operators analyze how visitors use the website. Information generated by cookies regarding a visitor’s use of the website is generally transmitted to and stored by Google on servers in the United States. In line with current IT standards, the IP addresses of users visiting the Administrator’s website are shortened. Only in exceptional cases is the full IP address transmitted to a Google server in the United States and shortened there. On behalf of the Administrator, Google will use this information to evaluate the website for its users, to compile reports on website traffic and to provide other services related to website traffic and internet usage to website operators. Google will not combine the IP address transmitted in the context of Google Analytics with any other data held by Google. More information on how Google Analytics collects and uses data can be found on Google’s official website at: [www.google.com/policies/privacy/partners](http://www.google.com/policies/privacy/partners). In addition, each User may prevent the collection and processing by Google of data concerning their use of the website by downloading and installing a browser plug-in available at the following link: [http://tools.google.com/dlpage/gaoptout](http://tools.google.com/dlpage/gaoptout).

7. When sharing data with third parties, the Administrator makes every effort to ensure that such disclosure is limited to entities meeting the criteria and requirements set out in Articles 46 or 49 GDPR. Where applicable, the Administrator shall rely on the EU standard contractual clauses and other safeguards to enable transfers outside the EEA. In accordance with the judgment of the Court of Justice of the European Union of 16 July 2020, the Administrator continues to assess the legal systems of countries to which data are transferred and, where necessary, updates measures aimed at ensuring adequate levels of protection.

8. With respect to data transferred to the United States, the Administrator, when sharing data with third parties, makes every effort to ensure that this is done, in line with the European Commission Decision of 10 July 2023, only to entities and organizations in the USA that comply with the new **EU-U.S. Data Privacy Framework**. The list of such organizations has been published by the U.S. Department of Commerce. Transfers of personal data from the EEA to organizations that have joined the EU-U.S. Data Privacy Framework program and are included on this list may take place without the need to obtain additional authorizations or apply such legal instruments as standard contractual clauses or binding corporate rules. However, where a given data importer in the USA has not joined the EU-U.S. Data Privacy Framework, transfers of personal data to it are possible and shall take place subject to the conditions set forth in Articles 46 or 49 GDPR. In such cases, the Administrator shall rely on the EU standard contractual clauses and other safeguards to enable transfers outside the EEA.

§ 4 Uprawnienia Użytkownika

  1. Użytkownik, którego dane osobowe są przetwarzane ma prawo do:

    – dostępu, sprostowania, ograniczenia, usunięcia lub przenoszenia
    – osoba, której dane dotyczą, ma prawo żądania od Administratora dostępu do swoich danych osobowych, ich sprostowania, usunięcia („prawo do bycia zapomnianym”) lub ograniczenia przetwarzania oraz ma prawo do wniesienia sprzeciwu wobec przetwarzania, a także ma prawo do przenoszenia swoich danych. Szczegółowe warunki wykonywania wskazanych wyżej praw wskazane są w art. 15-21 Rozporządzenia RODO. 

    – cofnięcia zgody w dowolnym momencie – osoba, której dane przetwarzane są przez Administratora na podstawie wyrażonej zgody (na podstawie art. 6 ust. 1 lit. a) lub art. 9 ust. 2 lit. a) Rozporządzenia RODO), to ma ona prawo do cofnięcia zgody w dowolnym momencie bez wpływu na zgodność z prawem przetwarzania, którego dokonano na podstawie zgody przed jej cofnięciem.

    – wniesienia skargi do organu nadzorczego – osoba, której dane przetwarzane są przez Administratora, ma prawo wniesienia skargi do organu nadzorczego w sposób i trybie określonym w przepisach Rozporządzenia RODO oraz prawa polskiego, w szczególności ustawy o ochronie danych osobowych. Organem nadzorczym w Polsce jest Prezes Urzędu Ochrony Danych Osobowych w Warszawie. 

    – sprzeciwu – osoba, której dane dotyczą, ma prawo w dowolnym momencie wnieść sprzeciw – z przyczyn związanych z jej szczególną sytuacją – wobec przetwarzania dotyczących jej danych osobowych opartego na art. 6 ust. 1 lit. e) (interes lub zadania publiczne) lub f) (prawnie uzasadniony interes administratora), w tym profilowania na podstawie tych przepisów. Administratorowi w takim przypadku nie wolno już przetwarzać tych danych osobowych, chyba że wykaże on istnienie ważnych prawnie uzasadnionych podstaw do przetwarzania, nadrzędnych wobec interesów, praw i wolności osoby, której dane dotyczą, lub podstaw do ustalenia, dochodzenia lub obrony roszczeń.

    – sprzeciwu dot. marketingu bezpośredniego – jeżeli dane osobowe są przeA User whose personal data are processed has the right to:

    a) access, rectification, restriction, erasure or portability – the data subject has the right to request from the Administrator access to their personal data, their rectification, erasure (“right to be forgotten”) or restriction of processing, as well as the right to object to processing, and the right to data portability. Detailed conditions for exercising the above rights are set out in Articles 15–21 of the GDPR;

    b) withdraw consent at any time – where data are processed by the Administrator on the basis of consent (pursuant to Article 6(1)(a) or Article 9(2)(a) GDPR), the data subject has the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal;

    c) lodge a complaint with a supervisory authority – the data subject has the right to lodge a complaint with a supervisory authority in the manner and under the procedure set out in the provisions of the GDPR and Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office in Warsaw;

    d) object – the data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data based on Article 6(1)(e) (public interest or tasks) or (f) (legitimate interest of the administrator), including profiling on the basis of these provisions. In such a case, the Administrator may no longer process the personal data unless it demonstrates the existence of compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defense of legal claims;

    e) object to direct marketing – where personal data are processed for direct marketing purposes (based on the legitimate interest of the Administrator, not on the consent of the data subject), the data subject has the right to object at any time to the processing of their personal data for such marketing purposes, including profiling, insofar as the processing is related to such direct marketing.

  2. The exercise of the above rights takes place on the basis of a user’s request sent to the Administrator’s e-mail address indicated above. Such a request should include the user’s first and last name.
  3. The User warrants that the data provided or published by them on the service are accurate.

§ 5 Cookies

  1. “Cookies” shall be understood as IT data, in particular text files, stored on users’ end devices (usually on the computer’s hard drive or on a mobile device), used by the user’s browser to store certain settings and data for the purpose of using websites. These files make it possible to recognize the user’s device and display the website appropriately, ensuring convenience when using it. The storage of “cookies” therefore enables the website and its offer to be properly tailored to the user’s preferences – the server recognizes the user and remembers, among other things, preferences such as visits, clicks, previous actions.
  2. “Cookies” contain, in particular, the name of the domain of the website from which they originate, the time of their storage on the end device, and a unique number used to identify the browser connecting to the website.
  3. “Cookies” are used for the purpose of:

    a) adjusting the content of websites to the user’s preferences and optimizing the use of websites;
    b) creating anonymous statistics which, by helping to determine how users use websites, enable improvements in their structure and content;
    c) delivering advertising content to website users tailored to their interests.

Cookies are not used to identify the user, and the user’s identity is not determined on their basis.

4. The fundamental division of “cookies” consists in distinguishing between:

a) Strictly necessary cookies – absolutely essential for the proper functioning of the website or functionalities which the user wishes to use, since without them many of the services we offer could not be provided. Some also ensure the security of services provided electronically;
b) Functional cookies – important for the operation of the website because:

* they enrich website functionality; without them the website will work correctly, but will not be adapted to the user’s preferences,

* they ensure a high level of website functionality; without them the level of functionality may be reduced, though their absence should not make the site completely unusable,

* they serve most website functionalities; blocking them will cause selected functions not to work properly;

c) Business cookies – enable implementation of the business model on which the website is made available; blocking them will not render the entire website unavailable, but may reduce the quality of the service due to the owner’s inability to generate revenue subsidizing its operation. Advertising cookies belong to this category;
d) Configuration cookies – enable the settings of functions and services on websites;
e) Security and reliability cookies – enable verification of authenticity and optimization of website performance;
f) Session state cookies – store information about how users use the website. They may relate to the most frequently visited pages or error messages displayed on certain pages. “Session state” cookies help improve services and increase browsing comfort;
g) Process cookies – enable efficient operation of the website and the functionalities available on it;
h) Analytical, research or audit cookies – enable the website owner to better understand users’ preferences and, through analysis, to improve and develop products and services. Typically, the website owner or a research company collects information anonymously and processes data on trends without identifying individual users’ personal data.

  1. The use of cookies to adapt website content to user preferences does not in principle mean collecting any information that would allow the user to be identified, although such information may sometimes constitute personal data, i.e. data enabling the attribution of certain behavior to a specific user. Personal data collected by means of cookies may be gathered solely for the purpose of performing specific functions for the user. Such data are encrypted in a way that prevents unauthorized persons from accessing them.
  2. Cookies used by this website are not harmful either to the user or to the end device used by them; therefore, for the correct functioning of the service, it is recommended not to disable their support in browsers. In many cases, software for browsing websites (internet browser) by default allows the storage of information in the form of “cookies” and other similar technologies on the user’s end device. The user may at any time change the way cookies are handled by their browser. To do this, the browser settings must be changed. The method of changing settings varies depending on the software used (browser). Appropriate instructions can be found on subpages depending on the browser used.
  3. The Administrator may use internet log files (which contain technical data such as the user’s IP address) to monitor traffic within its services, troubleshoot technical problems, detect and prevent fraud, and enforce the provisions of the User Agreement.
  4. The Administrator informs that the website does not respond to “DNT” (Do Not Track) signals; however, the user may disable certain forms of online tracking, including some analytics and personalized advertising, by changing cookie settings in their browser or via our cookie consent management tools (if applicable).
  5. Detailed information on changing cookie settings and deleting them independently in the most popular web browsers is available in the help section of the given browser and at the following pages (clickable links):

    a) Google Chrome
    b) Mozilla Firefox
    c) Microsoft Edge
    d) Opera
    e) Safari macOS
    f) Safari iOS/iPadOS

  1. Detailed information on managing cookies on a mobile phone or other mobile device should be included in the user manual of the given mobile device.



Create a Fully Tailored Experience

Choose from our highest-rated tours crafted for unforgettable memories, or design a custom trip that matches your interests, pace and style. Whether you want nature, culture or adventure — we’ll shape the perfect itinerary just for you.