This page explains what data we collect when you use tujemy.com, why we process it, and what rights you have.
1. Data controller
The controller of your personal data is AUTH LTD (no. 17296846), a company registered in England and Wales at Suite A, 82 James Carter Road, Mildenhall, England, IP28 7DE, operating the tujemy.com service (“Tujemy”, “we”). On matters concerning personal data you can reach us at support@tujemy.com.
2. What data we collect
When you create an account, make a reservation or join a waiting list, we collect:
- first and last name,
- email address,
- phone number (optional),
- reservation details: venue, date and time, number of guests, special requests.
- company details: name, address, NIP and REGON. We check the NIP against the Ministry of Finance VAT register and may take the name and address from it,
- the content of your waiting-list entry: your answers to the form, and which partner referred you if you arrived through their link,
- a record of your consents: the date and time, IP address, browser and the version of the wording you accepted. We keep it because art. 7(1) GDPR requires us to be able to demonstrate that consent was given.
3. Legal basis and purpose of processing
We process your data in order to conclude and perform the reservation service agreement (Art. 6(1)(b) GDPR, art. 6 ust. 1 lit. b RODO) and in order to prevent abuse and keep the service secure, which is our legitimate interest (Art. 6(1)(f) GDPR, art. 6 ust. 1 lit. f RODO).
We contact you for commercial purposes only on the basis of your consent (art. 6(1)(a) GDPR, art. 10 of the Act on Providing Services by Electronic Means, and art. 398 of the Electronic Communications Law). You may withdraw it at any time by writing to privacy@tujemy.com. Withdrawal does not affect the lawfulness of processing carried out before it, and does not affect your place on the list.
4. How we store data
Data is stored in Firebase services (Google Cloud), including the sign-in service and the Firestore database. Passwords never reach our servers in plain form, because sign-in is handled directly by Firebase Authentication.
5. How long we keep data
We delete data once it is no longer needed for the purpose we collected it for. In practice:
- account data: for as long as the account exists. After deletion we erase it promptly, except for anything we must keep for the reasons below,
- reservation data: for 6 years after the reservation ends. That is the general limitation period for claims, and reservations with a deposit are also accounting records, which art. 74 of the Accounting Act requires to be kept for 5 years,
- waiting-list entries: for 24 months from submission, or until you object, whichever comes first,
- the consent record: for as long as the consent stands and for 3 years after it is withdrawn, so we can show the basis on which we contacted you earlier.
6. Who we share data with
We share reservation data (date and time, number of guests, special requests) only with the venue you are booking, and only to the extent needed to carry the reservation out. This sharing is governed by our data processing agreement (DPA) concluded with partner venues. Depending on the venue, a reservation is handled directly by the Tujemy system or passed on to the GetUp panel. In both cases the data reaches only the venue the reservation concerns. If a venue requires a deposit, we pass the data needed for the payment (without the card number, which is handled solely by Stripe) to our payment provider Stripe.
7. Venue offers and coupons
Venues may direct offers at their own guests. We show offers and coupons tied to your account in the app and on your account page on the basis of our legitimate interest in running the service (art. 6(1)(f) GDPR). For that we process your account data and your booking history at the venue in question.
Push notifications and emails carrying offers are sent only on the basis of your consent, given separately for each channel (art. 6(1)(a) GDPR, art. 10 of the Polish act on electronic services, art. 398 of the Polish electronic communications law). You can withdraw it in your account settings or by writing to privacy@tujemy.com. Withdrawal does not affect the lawfulness of processing carried out beforehand. You can also mute a single venue's offers without withdrawing consent for the rest.
The venue does not receive your contact details from us in order to send anything. The venue defines the offer; we are the ones who send it. The venue sees that a coupon was redeemed, and is a separate controller for that.
8. Transfers outside the EEA
AUTH LTD is a company registered in the United Kingdom, and our infrastructure providers (Google Cloud / Firebase) may process data outside the European Economic Area. In such cases we apply appropriate safeguards, including the standard contractual clauses approved by the European Commission, in accordance with Chapter V of the GDPR (rozdział V RODO).
9. Your rights
You have the right to access, rectify and erase your data and to restrict its processing, as well as the right to data portability and the right to object to processing. You can edit your profile data yourself in account settings. For any other request, including deletion of your account, write to support@tujemy.com. You also have the right to lodge a complaint with the supervisory authority competent for your place of residence (in Poland this is the President of the Personal Data Protection Office, Prezes Urzędu Ochrony Danych Osobowych).
10. Cookies
We use a single session cookie that is needed to keep you signed in. It does not require consent, because the service cannot work without it. On your first visit we ask for consent to any analytics cookies; you can change that choice at any time in the page footer (“Cookie settings”). We currently use no advertising or tracking cookies.