Skip to content
blissko
WellnessThe houseGalleryReviewsFAQ
PL
Contact
Michał+48 518 443 870
WhatsApp
Błażej+48 794 207 439
WhatsApp
Check dates

Blissko

Privacy notice

This notice explains how we process data in connection with the private rental of the Blissko house, enquiries and direct bookings.

Last updated: 11 September 2026

Controllers and contact

The joint controllers are Błażej Marciniak and Michał Czyrniański, who jointly operate the private rental of Blissko at Węgierskie 69, 62-025 Kostrzyn, Poland. Data requests may be sent to either of them through [email protected].

Data we process

We process data supplied in an enquiry, checkout, Reservation, and communication, especially name, contact details, stay dates and party, arrangements, and Payment or settlement data. After optional browser analytics and diagnostics consent, we may process aggregate booking-funnel events, limited campaign markers (`utm_source`, `utm_medium`, `utm_campaign`), a referring-site origin, and a minimised technical application error. We do not place a name, telephone number, email address, stay date, price, full URL, or persistent Guest identifier in those tools.

Purposes and legal bases

Data is used for steps before entering into and performing a contract (Article 6(1)(b) GDPR), tax, accounting and legal duties (point (c)), and security, service quality, and establishing or defending claims in our legitimate interests (point (f)). Server-side error diagnostics operates in that interest without reading or writing browser state. Optional browser analytics and diagnostics operates with consent (point (a) and Article 399 of the Polish Electronic Communications Law), is not required to use the site or make a Reservation, and uses one combined choice which expressly covers both purposes. The protected Operations panel has a separate choice only for error diagnostics; employee use requires a separate workplace-monitoring assessment.

Recipients

Where necessary, recipients may include hosting and VPS providers, Cloudflare, home.pl, Stripe, communication providers used by the Guest, Umami Cloud for optional analytics, Sentry for minimised application errors, and legal or accounting advisers. We select EU data regions and configure each service to minimise the information it receives. If a provider uses a subprocessor outside the EEA, it uses a legally required transfer mechanism, particularly an adequacy decision or standard contractual clauses. We do not sell data or use advertising trackers.

Retention

Reservation and settlement data is retained for periods required by law, claims data until the applicable limitation period expires, and technical data only as long as website security and operation require. Campaign data attached to a Reservation is removed after 13 months. Aggregate Umami data is retained for six months and minimised Sentry events for 30 days unless the provider plan provides a shorter period. The privacy preference remains until the choice or purpose version changes. Private payment_pending Hold data remains stored until Stripe confirms a safe terminal state, even after the local deadline. After a terminal unpaid outcome it is removed, leaving only non-identifying operational history; after Payment the necessary facts enter Reservation retention.

Instagram messages

To handle enquiries, we use Instagram (Meta), OpenAI to prepare replies, and a private Telegram group for the hosts. We process your account identifier, message content and the necessary conversation context. OpenAI may analyse an image related to your question; we do not forward images to Telegram. Messaging us does not constitute consent to marketing. We delete conversation history from our system after 30 days. This does not simultaneously delete copies held by Meta, OpenAI or Telegram, or in backups, which have separate retention rules. For questions about your data, contact [email protected].

Your rights

Depending on the circumstances, a person may request access, correction, deletion, restriction or portability, object to processing based on legitimate interests, and complain to the President of the Polish Personal Data Protection Office (UODO). Browser analytics and diagnostics consent can be withdrawn as easily as it was given through the privacy settings in the website footer. Withdrawal stops future sends and clears unsubmitted campaign data from the current session; it does not affect the lawfulness of earlier processing.

Back to the home page
Privacy