Information Clauses
Dear Sir or Madam,
Due to the entry into force of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), we provide you with all information in this regard in the following information clauses, referred to in Articles 13 and 14 of the GDPR, regarding the processing of personal data.
The information obligations have been tailored to the groups of people whose personal data we process, so that you can easily find the information addressed directly to you. Please read this information carefully and, if necessary, If you have any doubts or would like to obtain more information regarding the processing of your personal data, please contact the Data Protection Officer appointed by the Data Controller in accordance with Article 37 of the GDPR – Ms. Agnieszka Dworak at the following email address: iod@malinowehotele.pl.
GENERAL INFORMATION CLAUSE
PURPOSE: INFORMATION FOR INDIVIDUALS FROM WHOM PERSONAL DATA HAS BEEN COLLECTED
Dear Sir or Madam,
Pursuant to Article 13 paragraphs 1 and 2 of the Regulation (EU) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter referred to as the GDPR, we inform you that:
1. The controller of your personal data is Malinowe Hotele Sp. z o.o. with its registered office in Solec-Zdrój (28-131), at 7 Leśna Street, NIP: 678-14-01-345, REGON: 351061573.
2. Malinowe Hotele Sp. z o.o. in Solec-Zdrój includes the following entities:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balneokosmetyki
3. The contact person for matters related to the processing of your personal data and the exercise of rights arising from the GDPR is the Data Protection Officer - Ms. Agnieszka Dworak. You can contact the Data Protection Officer by e-mail: iod@malinowehotele.pl or by writing to the address indicated in point 1 above.
4. Your personal data will be processed for the purposes of:
- providing medical services,
- providing hotel services,
- direct marketing of the Controller's own products and services, presenting commercial offers, and participating in the loyalty program,
- protection of persons and property.
5. The legal basis for data processing is:
- legal obligation (Article 6, paragraph 1, letter a) of the GDPR c) GDPR),
- conclusion and performance of the contract (Article 6 paragraph 1 letter b) GDPR),
- consent of the data subject in the case of participation in a loyalty program, presentation of a commercial offer, and use of treatments without medical consultation (Article 6 paragraph 1 letter a) GDPR),
- legitimate interest of the Controller in the case of: direct marketing and video surveillance (Article 6 paragraph 1 letter f) GDPR).
6. Your personal data:
- may be transferred only to recipients - entities that cooperate with the Controller or their subcontractors on the basis of a concluded cooperation agreement, including a personal data processing agreement, entities authorized to obtain your personal data on the basis of applicable law, and authorized employees of the Controller,
- will not be transferred to third countries or international organizations.
7. Your personal data will be stored:
- in the case of the provision of medical services - 20 years,
- 6 years to secure any claims,
- in other cases, for the period necessary to achieve the purposes of processing or to withdraw consent to further processing, if processing was based on consent.
8. You have the right to:
- access, rectify, erase, or restrict the processing of your personal data,
- object to the further processing of your personal data,
- withdraw consent to data processing at any time without affecting the lawfulness of processing carried out before its withdrawal,
- you also have the right to request that the Controller transfer your data to another Controller, provided that this does not adversely affect the rights and freedoms of others.
9. You have the right to lodge a complaint with the supervisory authority, which is the President of the Personal Data Protection Office.
10. Providing your personal data required by the Controller is a condition for concluding and performing a contract for the services provided, a condition for joining a loyalty program, a condition for presenting a commercial offer, and a statutory requirement. In other cases, providing personal data is voluntary.
11. Your personal data is not subject to automated decision-making, including profiling, except in the case of consent to such processing for commercial purposes and participation in a loyalty program.
We also inform you that:
The Administrator makes every effort to ensure all physical, technical, and organizational measures to protect personal data against accidental or intentional destruction, accidental loss, alteration, unauthorized disclosure, use, or access, in accordance with all applicable regulations.
INFORMATION CLAUSE
PURPOSE: FOR HOTEL GUESTS - USE OF ACCOMMODATION SERVICES
Pursuant to Art. 13 of the General Data Protection Regulation of 27 April 2016 (OJ L 119, 4.05.2016), we would like to inform you that:
12. The controller of your personal data is Malinowe Hotele Sp. z o.o. with its registered office in Solec-Zdrój (28-131), at 7 Leśna Street, NIP: 678-14-01-345, REGON: 351061573.
13. Malinowe Hotele Sp. z o.o. The following entities are located in Solec-Zdrój:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balnekosmetyki
14. The contact person for matters related to the processing of your personal data and the exercise of rights under the GDPR is the Data Protection Officer, Ms. Agnieszka Dworak. The Data Protection Supervisor can be contacted by e-mail: iod@malinowehotele.pl or by writing to the address indicated in point 1 above.
15. For the purpose of providing accommodation services, the Controller will process personal data in the following scope: first name and last name, contact number (in the case of a telephone reservation), and identity document number (as a legitimate legal interest in the case of establishing, pursuing, and defending mutual claims).
16. Providing personal data is necessary for the conclusion and performance of the contract and the provision of the service.
17. Your personal data will be processed for the purpose of using accommodation services - pursuant to Article 6, paragraph 1 letter b) and letter f) of the General Data Protection Regulation of 27 April 2016.
18. The recipients of your personal data will be authorized employees of the Controller, entities authorized to obtain personal data under the law, as well as entities participating in the provision of services based on a concluded personal data processing agreement or cooperation agreement.
19. Your personal data will be stored by the Controller in the event of issuing a VAT invoice for a period of 6 years, and in the reception system after the service is completed, the data will be stored only on the basis of your consent to further processing for the purpose of accelerating registration in the event of your use of the accommodation service.
20. You have the right to request from the Controller access to your personal data, the right to rectify, erase, or limit the processing of your personal data, and the right to data portability.
21. You have the right to lodge a complaint with the supervisory authority - the President of the Office for Personal Data Protection Personal Data.
22. Your personal data is not subject to automated decision-making, including profiling.
INFORMATION CLAUSE
PURPOSE: USING THE SERVICES OF THE REHABILITATION CENTER WITH MEDICAL CONSULTATION
In connection with the implementation of the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation "GDPR"), we hereby inform you about the principles of processing your personal data and your related rights.
23. The controller of your personal data is Malinowe Hotele Sp. z o.o. with its registered office in Solec-Zdrój (28-131), at 7 Leśna Street, NIP: 678-14-01-345, REGON: 351061573.
24. Malinowe Hotele Sp. z o.o. in Solec-Zdrój includes the following entities:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balnekosmetyki
25. The contact person for matters related to the processing of your personal data and the exercise of rights under the GDPR is the Data Protection Officer - Ms. Agnieszka Dworak. You can contact the Data Protection Officer by e-mail: iod@malinowehotele.pl or by writing to the address indicated in point 1 above.
26. Patient personal data are used for the following purposes and on the following legal basis:
a. establishing the identity of patients in accordance with the requirements of the Act on Patients' Rights and the Patient Ombudsman, which is a legal obligation (Article 6 paragraph 1 letter c of the GDPR in conjunction with Article 9 paragraph 2 letter h of the GDPR),
b. maintaining medical records in accordance with the requirements of relevant legal provisions, including the Act on Patients' Rights and the Patient Ombudsman and the Regulation of the Minister of Health of 9 November 2015 on the types, scope and templates of medical records and the method of their processing, which is a legal obligation (Article 6 paragraph 1 letter c of the GDPR in conjunction with Article 9 paragraph 2 letter h of the GDPR),
c. contacting in connection with the conducted business activity, and services provided, including scheduled visits, which constitutes a legitimate legal interest (Article 6, paragraph 1, letter f of the GDPR).
4. The personal data processed may include any personal data necessary to conduct medical activities, including health data, and in particular the following data will be processed for the above-mentioned purpose: name and surname, address, PESEL number, telephone number. The Data Controller has a statutory obligation to keep personal data confidential.
5. The Data Controller informs that providing personal data required to maintain medical records is mandatory – without providing personal data, the Data Controller will not be able to fulfill its obligations and, consequently, may refuse to schedule an appointment or provide medical services.
6. The Data Controller informs that, due to legal regulations, personal data will be stored for at least 20 years from the date of the last entry in the medical records (including data stored in the reception system for this period).
7. The Data Controller may transfer patient data to entities that provide business support services to the Data Controller or to entities with which the Data Controller has concluded a personal data processing agreement. This particularly applies to IT support services or support for the Data Controller's business. Furthermore, personal data may be made available to persons designated by the patient.
8. The Data Controller informs about the right to lodge a complaint with the supervisory authority, which is the President of the Personal Data Protection Office. The Data Controller also informs about the right to access personal data, the right to erase it, and the right to limit its processing. The Controller also informs you of the right to object to processing and the right to transfer data to another controller.
9. Providing personal data is mandatory under the law and is otherwise voluntary.
10. Your personal data is not subject to automated decision-making, including profiling.
INFORMATION CLAUSE
PURPOSE: USING SPA/BEAUTY STUDIO/REHABILITATION CENTER SERVICES WITHOUT MEDICAL CONSULTATION
Pursuant to Art. 13 sec. 1 and 2 of the Regulation (EU) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter referred to as the GDPR, we inform you that:
27. The controller of your personal data is Malinowe Hotele Sp. z o.o. with its registered office in Solec-Zdrój (28-131-) at 7 Leśna Street, NIP: 678-14-01-345, REGON: 351061573.
28. Malinowe Hotele Sp. z o.o. In Solec-Zdrój, the following entities are represented:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balnekosmetyki
29. The contact person for matters related to the processing of your personal data and the exercise of your rights under the GDPR is Data Protection Supervisor - Ms. Agnieszka Dworak. You can contact the Data Protection Supervisor by e-mail: iod@malinowehotele.pl or by writing to the address indicated in point 1 above.
30. Your personal data will be processed for the purpose of providing a service consisting in performing treatments without a medical consultation at a SPA, Beauty Studio, or Rehabilitation Center, including: first and last name, room number (if you are a hotel guest), address, telephone number, and e-mail address.
31. Providing your personal data is voluntary, but necessary to achieve the purpose listed above in point 4, and failure to provide the data will result in a refusal to provide the service.
32. The basis for the processing of your personal data is your consent to the processing of your personal data, voluntarily granted pursuant to Article 6 paragraph 1 letter a) of the GDPR and Article 6 paragraph 1 letter b) of the GDPR. f) GDPR for purposes arising from legitimate interests pursued by Malinowe Hotele Sp. z o.o., including in particular for the purpose of considering complaints and establishing, pursuing, and defending mutual claims.
33. The recipients of your personal data will be authorized employees of the Controller, entities cooperating with the Controller and processing your personal data on the Controller's instructions based on a personal data processing authorization, or entities with which the Controller has concluded a personal data processing agreement. In particular, this applies to IT support services or support for the controller's business activities.
34. Personal data collected from you will not be transferred to entities outside the European Union or the European Economic Area.
35. You have the right to access your data and the right to rectify, erase, restrict processing, the right to data portability, the right to object, and the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
36. You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the provisions of the GDPR or other regulations specifying the processing and protection of personal data.
37. The personal data you provide will not be used for automated decision-making and will not be profiled.
INFORMATION CLAUSE
PURPOSE: FOR PARTICIPANTS OF THE "MALINOWY RAJ" LOYALTY PROGRAM AND FOR THE PURPOSE OF PRESENTING A COMMERCIAL OFFER
Pursuant to Article 13 paragraphs 1 and 2 of the Regulation (EU) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the GDPR), we hereby inform you that:
1. The controller of the personal data provided by you as part of your participation in the "Malinowy Raj" loyalty program is Malinowe Hotele Sp. z o.o. with its registered office in Solec-Zdrój (28-131), ul. Leśna 7, NIP: 678-14-01-345, REGON: 351061573.
2. Malinowe Hotele Sp. z o.o. in Solec-Zdrój includes the following entities:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balneokosmetyki
3. Your personal data will be processed for the purpose of participating in the "Malinowy Raj" loyalty program and for commercial purposes, including: name and surname, address, PESEL (for the purposes of identifying the cardholder and calculating and granting a discount), e-mail address, telephone number on the basis of consent granted in accordance with art. 6 sec. 1 letter a) of the GDPR and for purposes resulting from legitimate interests pursued by Malinowe Hotele Sp. z o.o. in accordance with art. 6 sec. 1 letter a) of the GDPR. f) GDPR, in particular for the purpose of implementing participation in the loyalty program, presenting a commercial offer, considering complaints, and establishing, pursuing, and defending mutual claims.
4. Your personal data will be processed for the period of participation in the "Malinowy Raj" loyalty program and presenting a commercial offer until you withdraw your consent to further processing or until mutual claims arising from participation in the loyalty program expire.
5. The recipients of your personal data will be authorized employees of the Controller, entities providing IT services to the Controller based on a concluded data processing agreement, and cooperation entities. with the Controller and processing personal data on the Controller's instructions based on authorization to process personal data.
6. Personal data collected from you will not be transferred to entities outside the European Union or the European Economic Area.
7. You have the right to access your data and the right to rectify, erase, limit processing, the right to data portability, the right to object, the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
8. You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the provisions of the GDPR or other regulations specifying the method of processing and protection of personal data.
9. Providing your personal data is voluntary and results from participation in the "Malinowy Raj" loyalty program. Failure to provide your data will result in the loss of participation in the loyalty program.
10. The data provided by you Your personal data will be used to make decisions in an automated manner based on personal data processed as part of the "Malinowy Raj" loyalty program (using profiling), and the consequence of such processing will be the possibility of determining your personal preferences and purchasing behavior based on your personal data and the history of your transactions as part of the loyalty program. Profiling will be used for the purposes of preparing and presenting you with an individually tailored commercial offer.
11. You may contact our Data Protection Officer, Ms. Agnieszka Dworak, regarding the processing of your personal data by sending an email to iod@malinowehotele.pl or by sending a letter to the address indicated in point 1 of this clause.
INFORMATION CLAUSE
PURPOSE: FOR THE CONTRACTOR
Pursuant to Article 13, paragraphs 1 and 2, and Article 14, paragraph 1 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), we inform you of the following matters.
If, as part of a contract, you have provided us with the personal data of your employees or associates, we hereby inform you that, in accordance with Article 14(1) of the GDPR, this information clause also applies to them and should be made available to them by you.
1. The controller of your personal data is Malinowe Hotele Sp. z o. o. with its registered office in Solec-Zdrój at ul. Leśna 7, 28-131 Solec-Zdrój, NIP: 678-14-01-345, REGON: 351061573
2. Malinowe Hotele Sp. z o.o. is a company consisting of: In Solec-Zdrój, the following entities are included:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balnekosmetyki (Balnecosmetics)
3. Any questions regarding the method and scope of processing of your personal data and your rights under the GDPR may be directed to the designated Data Protection Officer - Ms. Agnieszka Dworak at the following e-mail address: iod@malinowehotele.pl or by writing to the address indicated in point 1 above.
4. We process your personal data on the basis of applicable law in order to conclude and perform contracts with the Controller's contractors (Article 6 paragraph 1 letter b of the GDPR), as well as for the following purposes:
- for the duration of the contract and settlements after its termination (Article 6 paragraph 1 letter c of the GDPR);
- to fulfill the Controller's legal obligations;
- to establish, defend, and pursue legal claims (Article 6 paragraph 1 letter f of the GDPR) – for the period after which the claims become time-barred;
- to verify payment credibility (Article 6 paragraph 1 letter f of the GDPR) – for the period necessary to make such an assessment when concluding, extending, or extending the scope of the contract;
- detecting and preventing abuse (Article 6, paragraph 1, letter c and 1, letter f of the GDPR) – for the duration of the contract, and then for the period after which claims become time-barred or for the duration of proceedings conducted by competent public authorities;
- in other cases, your personal data are processed solely on the basis of previously granted consent, to the extent and for the purpose specified in the content of the consent (Article 6, paragraph 1, letter a of the GDPR) – for the period from consent granted until its withdrawal.
5. Providing personal data is voluntary, however, refusal to provide them may result in refusal to conclude the contract or inability to establish contact.
6. You can contact us with a request You have the right to access, rectify, transfer, delete, restrict processing of your data, and object to its further processing at any time.
7. The personal data you entrust to us is stored in our contractor database. It is appropriately secured against unauthorized access or loss. We will process the personal data contained therein until the purpose of processing ceases, i.e., until the end of the cooperation, after which we will archive it for 6 years.
8. The recipients of your personal data will be entities with which the Controller has concluded data processing agreements in accordance with Art. 28 GDPR, as well as entities authorized under superior legal provisions, or entities authorized to obtain them in connection with the performance of the contract.
9. We will not transfer your personal data to third countries or international organizations.
10. We would also like to inform you that if your personal data is processed in violation of the GDPR Regulation, you have the right to lodge a complaint with the President of the Personal Data Protection Office, with its registered office in Warsaw (00-923), at ul. Stawki 2.
11. Your personal data will not be subject to automated decision-making processes, including profiling.
INFORMATION CLAUSE
PURPOSE: RECRUITMENT
1. The controller of your data processed as part of the recruitment process is Malinowe Hotele Sp. z o.o., ul. Leśna 7, 28-131 Solec-Zdrój, NIP: 678-14-01-345,
REGON: 351061573 as an employer, for whom labor law activities are performed by the President of the Management Board.
2. Malinowe Hotele Sp. z o.o. In Solec-Zdrój, the following entities are represented:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balneokosmetyki
3. The Controller has appointed a Data Protection Supervisor, whom you can contact in matters related to the processing of your personal data at:
- Malinowe Hotele Sp. z o.o., ul. Leśna 7, 28-131 Solec-Zdrój
- e-mail: iod@malinowehotele.pl
4. The processing of your personal data will take place based on your consent (Article 6 paragraph 1 letter a) and, in the case of special categories of data, on the basis of Article 9 paragraph 2 letter a) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
5. The personal data provided will be processed for the purpose of conducting the current recruitment process and, if consent is granted, for future recruitment purposes. Providing your personal data for the purpose of conducting the current recruitment process is voluntary, but necessary to participate in the recruitment process.
6. Consent to the processing of personal data for the purpose of conducting future recruitment processes is voluntary. If you do not provide consent to participate in future recruitment processes, participation in future recruitment processes conducted by the Controller will be possible after completing and submitting the recruitment documents again.
7. Your personal data will be stored for the purposes of the current recruitment for a period of 3 months from the date of completion of this recruitment process, i.e., you will be informed of the recruitment results.
8. If you consent to the processing of personal data for the purpose of participating in future recruitment processes, the personal data provided will be stored for a period of 1 year from the date of completion of the current recruitment process, i.e., you will be informed of the recruitment results.
9. You have the right to access your personal data, the right to rectify it, the right to erase it, the right to request the restriction of processing or to object to processing, as well as the right to data portability.
10. You have the right to withdraw your consent to the processing of your personal data at any time, which does not affect the lawfulness of processing based on consent before its withdrawal.
If you have granted consent for multiple purposes, you have the right to withdraw each consent separately. After withdrawal of consent, your data will be immediately deleted from the candidate database.
11. The recipients of your personal data will be: the Administrator's associates authorized to participate in the recruitment process, entities operating ICT systems and providing information tools, entities providing maintenance services, entities maintaining and maintaining IT services, entities providing e-mail services, entities providing advisory, consulting, and auditing services.
12. In connection with the processing of your personal data, you have the right to lodge a complaint with the President of the Personal Data Protection Office.
13. Your personal data will not be used for automated decision-making and will not be profiled.
INFORMATION CLAUSE
PURPOSE: FOR INTERNSHIP/TRAINEES
Pursuant to Art. 13 sec. 1 and 2 of the Regulation (EU) of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter referred to as the GDPR, we inform you that:
38. The controller of your personal data is Malinowe Hotele Sp. z o.o. with its registered office in Solec-Zdrój (28-131-), at 7 Leśna Street, NIP: 678-14-01-345, REGON: 351061573.
39. Malinowe Hotele Sp. z o.o. The following entities are located in Solec-Zdrój:
- Malinowy Zdrój Hotel**** Medical Spa
- Malinowy Raj Mineral Hotel****
- Malinowy Dwór Hotel ****Medical Spa
- Solec-Zdrój Mineral Pools
- Balnekosmetyki
40. The contact person for matters related to the processing of your personal data and the exercise of rights arising from the GDPR is the Data Protection Officer - Ms. Agnieszka Dworak. You can contact the Data Protection Supervisor by email: iod@malinowehotele.pl or by writing to the address indicated in point 1 above.
41. Purposes of processing your personal data:
We will process your personal data to:
1) Conclude and implement a contract or agreement with you or another entity concerning your internship or apprenticeship at our company.
2) Fulfill our legal obligations and rights related to the implementation of the internship or apprenticeship arising from the regulations governing internships or apprenticeships.
3) Fulfill our obligations regarding you arising from tax and accounting regulations.
4) Ensure security on the premises used by Malinowe Hotele Sp. z o.o., including information security, through access control or monitoring.
42. Legal basis for processing your personal data:
We will process your personal data based on:
1) the fact that they are necessary for the conclusion and performance of a contract or agreement concerning your internship or traineeship;
2) relevant legal provisions:
• Act of December 14, 2016 - Education Law,
• Act of July 27, 2005 - Higher Education Law,
• Act of July 17, 2009 on Graduate Internships,
• Act of April 20, 2004 on Employment Promotion and Labor Market Institutions,
• Act of August 29, 1997 - Tax Ordinance,
• Act of July 26, 1991 on Personal Income Tax natural persons,
• Accounting Act of 29 September 1994;
3) our legitimate interests;
4) your consent.
43. Recipients of your personal data:
We will transfer your personal data:
1) To processors, in connection with the performance of contracts concluded by Malinowe Hotele Sp. z o.o. under which they have been entrusted with the processing of personal data, including, for example, IT service providers. Such entities process data based on an agreement with us and only in accordance with our instructions.
2) To entities to which our company shares personal data necessary to provide services to Malinowe Hotele Sp. z o.o. based on concluded contracts.
3) To our contractors (service providers, clients) in connection with the performance of your duties entrusted as part of your internship or apprenticeship.
44. Legitimate interests pursued by Malinowe Hotele Sp. z o.o. – if processing takes place on the basis of Article 6 paragraph 1 letter f):
The scope of personal data processed at Malinowe Hotele Sp. z o.o. regarding apprentices or trainees, for which the legal basis for processing is the company's legitimate interest, includes personal data processed in connection with ensuring security on the premises used by the company, including information security, through the use of video surveillance. The company's legitimate interest in processing such data is to ensure an appropriate level of security on the premises used by our company.
45. Period of storage of your personal data:
We will process your personal data in for the duration of the internship or traineeship. We will store your personal data contained in tax or accounting documentation until the data retention obligations arising from specific provisions expire.
46. Data transfer outside the European Economic Area.
Not applicable
47. Your rights related to personal data processing.
You have the following rights related to personal data processing:
1) the right to access your personal data;
2) the right to request rectification of your personal data;
3) the right to lodge a complaint with the supervisory authority responsible for personal data protection, i.e., the President of the Personal Data Protection Office;
4) the right to withdraw consent to the processing of your personal data;
5) the right to request the deletion of your personal data - if the basis for their processing is not a legal obligation;
6) the right to request the restriction of the processing of your personal data;
7) the right to object to the processing of your data due to your special situation - in cases where we process your data based on our legitimate interest,
8) the right to transfer your personal data, i.e., the right to receive your personal data from us in a structured, commonly used, machine-readable format. You can send this data to another Data Controller or request that we transmit your data to another Controller. However, we will only do so if such transmission is technically feasible. You only have the right to transfer personal data that we process on the basis of an agreement or an internship or apprenticeship contract concluded with you, or on the basis of your consent.
48. Obligation to provide data:
Your obligation to provide personal data results in particular from the legal provisions indicated in point 5.
49. Information on automated decision-making, including profiling:
Not applicable.
We also inform you that:
The Controller makes every effort to ensure all means of physical, technical, and organizational protection of personal data against accidental or intentional destruction, accidental loss, alteration, unauthorized disclosure, use, or access, in accordance with all applicable regulations.
