Wersja 2026-09-17

Privacy Policy

Opublikowano 17 września 2026 r.

To jest tłumaczenie pomocnicze. Wiążąca jest polska wersja dokumentu.

Wersja polska

§ 1. Controller

  1. 1.
    The controller of personal data processed in connection with the use of the tujemy.com website and the Tujemy mobile application (together, the “Service”) is AUTH LTD, a company incorporated under the law of England and Wales and registered at Companies House under number 17296846, with its registered office at Suite A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom (the “Controller”).
  2. 2.
    For any matter concerning personal data, the Controller can be contacted at privacy@tujemy.com or in writing at its registered office. The Controller has not appointed a data protection officer.
  3. 3.
    This privacy policy (the “Policy”) provides the information required by Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”). Capitalised terms not defined in the Policy have the meanings given to them in the Tujemy Terms of Service or the Terms for Venues.
  4. 4.
    The Polish version of the Policy is binding. The English version is a courtesy translation.

§ 2. The Controller, Venues and Stripe

  1. 1.
    The Controller determines the purposes and means of processing data connected with running the Service, in particular data relating to Accounts, Bookings received and passed on by the Service, Reviews, Offers and notifications.
  2. 2.
    The Venue that receives a Booking or a Booking Request processes the data it receives as a separate controller in order to perform its service. The Venue provides information about that processing.
  3. 3.
    Where a Venue itself enters guest data into the Service’s panel, for example bookings taken by telephone, walk-in guests or notes about guests, the Controller processes that data on the Venue’s behalf as a processor under a data processing agreement. On the same basis the Controller processes, on the Venue’s behalf, data about members of the Venue’s team as regards their roles, permissions and activity log in the panel. For that data the Venue is the controller. If the Venue has entered a guest’s email address, the Service sends the guest a confirmation of that booking on the Venue’s behalf.
  4. 4.
    Stripe Payments Europe, Limited processes payment-related data as a separate controller, on the terms set out in its own privacy policy.

§ 3. Purposes, legal bases and retention periods

  1. 1.
    Maintaining the Account.
    1. 1)Data: name, email address, telephone number (if given), profile photo (if added), Account settings and language. The password is protected by the Firebase Authentication service and the Controller never knows it in plain text.
    2. 2)Legal basis: performance of the contract for maintaining the Account (Article 6(1)(b) GDPR).
    3. 3)Retention: until the Account is deleted.
  2. 2.
    Bookings and Booking Requests.
    1. 1)Data: the Venue, date and time, number of people or length of stay, special requests, status and number of the Booking, history of changes, contact details given with the Booking and messages exchanged with the Venue.
    2. 2)Legal basis: performance of the contract for the Service’s services and steps taken at the person’s request before entering into a contract with the Venue (Article 6(1)(b) GDPR), and the Controller’s legitimate interest in establishing, pursuing and defending claims (Article 6(1)(f) GDPR).
    3. 3)Retention: 6 years from the day on which the Booking fell, including after the Account is deleted.
  3. 3.
    Health information in special requests.
    1. 1)Health information should not be entered in the special requests field unless the Venue needs it to perform the service, for example information about a food allergy. Providing such information is voluntary.
    2. 2)Legal basis: explicit consent given by providing the information so that it is passed on to the Venue (Article 9(2)(a) GDPR). The consent may be withdrawn by writing to privacy@tujemy.com; withdrawal does not affect the lawfulness of anything passed on earlier.
    3. 3)Retention: as for Booking data, or until the consent is withdrawn.
  4. 4.
    Deposits.
    1. 1)Data: amount, payment status and identifier, and information about refunds and disputes. The Controller does not process payment card details; only Stripe does.
    2. 2)Legal basis: performance of the contract (Article 6(1)(b) GDPR), obligations under accounting and tax law (Article 6(1)(c) GDPR) and the legitimate interest in handling payment disputes and defending against claims (Article 6(1)(f) GDPR).
    3. 3)Retention: 6 years from the end of the calendar year in which the payment was made.
  5. 5.
    Offers and coupons.
    1. 1)Data: Offers addressed to the Guest, coupons assigned to the Account, information about their redemption and information about which Venues the Guest has visited.
    2. 2)Legal basis: the Controller’s legitimate interest in running the Service and showing Guests Offers from Venues they have visited (Article 6(1)(f) GDPR) and, for issuing and redeeming a coupon, performance of a contract (Article 6(1)(b) GDPR).
    3. 3)Retention: until the Account is deleted; information about the redemption of a coupon, 6 years from redemption.
  6. 6.
    Marketing notifications.
    1. 1)The Controller sends push notifications and emails about Offers only with consent, given separately for each channel. Consent may be given by a person aged 16 or over.
    2. 2)Data: the state of consent for each channel, the dates on which it was given and withdrawn, the version of the consent wording, the IP address and information about the browser or device.
    3. 3)Legal basis: consent (Article 6(1)(a) GDPR) required by Article 398(1) of the Polish Electronic Communications Law of 12 July 2024, and, for the record of consent, the legitimate interest in being able to show that it was given (Article 6(1)(f) GDPR). Withdrawing consent does not affect the lawfulness of processing carried out before it was withdrawn.
    4. 4)Retention: until consent is withdrawn; the record of consent, 3 years from withdrawal.
  7. 7.
    Reviews.
    1. 1)Data: rating, comment, date of the visit, the name given in the Account, moderation status and the reasons for a decision, reports concerning Reviews and the list of Review authors blocked by the User. A Review is public and is published with the author’s name.
    2. 2)Legal basis: performance of the contract for publishing the Review (Article 6(1)(b) GDPR) and the legitimate interest in moderating Content and handling reports (Article 6(1)(f) GDPR).
    3. 3)Retention: until the Review is removed; after the Account is deleted the Review may remain in the Service without the author’s name.
  8. 8.
    Booking notifications and passes.
    1. 1)Data: the device token for push notifications, the platform and language, and the Booking details placed in an Apple Wallet or Google Wallet pass.
    2. 2)Legal basis: performance of a contract (Article 6(1)(b) GDPR).
    3. 3)Retention: until the User signs out on the device or deletes the Account.
  9. 9.
    Notification when a Venue opens.
    1. 1)Data: the Account and the Venue whose opening the Service is to notify the Guest about.
    2. 2)Legal basis: performance of a contract (Article 6(1)(b) GDPR).
    3. 3)Retention: until the Venue opens, its opening is called off or the Account is deleted.
  10. 10.
    Record of acceptance of documents.
    1. 1)Data: when the Tujemy Terms of Service, the Promotion Rules, the Terms for Venues or the data processing agreement are accepted, or reading of the Policy is confirmed, the Controller records the Account identifier or email address, the date and time, the document versions and cryptographic digests of their text, the wording of the declaration, the IP address, the approximate location derived from the IP address (country, region and town, never more precise), information about the browser or device, the application version, the language and the screen on which the declaration was made.
    2. 2)Legal basis: the Controller’s legitimate interest in being able to show that a contract was concluded and what it contained, and in defending against claims (Article 6(1)(f) GDPR).
    3. 3)Retention: for the duration of the contract and 6 years after it ends, including after the Account is deleted.
  11. 11.
    Security of the Service and Accounts.
    1. 1)Data: IP address, information about the browser or device, a digest of the device’s characteristics, sign-in dates and counters of attempts to perform operations.
    2. 2)Legal basis: the legitimate interest in keeping the Service and Accounts secure and preventing abuse (Article 6(1)(f) GDPR).
    3. 3)Retention: sign-in records until the Account is deleted; attempt counters until the period to which the limit applies has passed.
  12. 12.
    Correspondence, complaints and reports of Content.
    1. 1)Data: information given in correspondence, a complaint or a report of Content, including the IP address of the person reporting, and the decision taken.
    2. 2)Legal basis: the legitimate interest in replying and defending against claims (Article 6(1)(f) GDPR) and obligations under Regulation (EU) 2022/2065 (Article 6(1)(c) GDPR).
    3. 3)Retention: 3 years from the close of the matter.
  13. 13.
    Venue accounts and their teams.
    1. 1)Data: name, email address and telephone number, the business name, tax identification number (NIP), REGON, address and VAT status of the business, the Venue’s address, two-factor authentication settings, subscription and billing data, including the invoices and credit notes issued, and correspondence. The NIP is checked against the register of VAT taxpayers kept by the Head of the National Revenue Administration, from which the business name, address and VAT status may be taken. The Venue’s address is sent to the Nominatim service run by the OpenStreetMap Foundation to place the Venue on the map. Verification for accepting payments is carried out by Stripe as a separate controller.
    2. 2)Legal basis: performance of the contract with the Venue (Article 6(1)(b) GDPR) and, for people acting on the Venue’s behalf, the legitimate interest in performing that contract and communicating with the Venue (Article 6(1)(f) GDPR), obligations under accounting and tax law (Article 6(1)(c) GDPR) and defending against claims (Article 6(1)(f) GDPR).
    3. 3)Retention: for the duration of the contract with the Venue and 6 years after it ends; accounting records for the period required by law.
  14. 14.
    Waiting lists for businesses.
    1. 1)Data: company details (name, address, NIP and REGON), details of the person submitting, answers to the form’s questions, information about the partner whose link the submission came from, and the record of consents. The NIP is checked against the register of VAT taxpayers kept by the Head of the National Revenue Administration, from which the company’s name and address may be taken.
    2. 2)Legal basis: steps taken at the person’s request before entering into a contract and the legitimate interest in running the list (Article 6(1)(b) and (f) GDPR); commercial contact by email or telephone is based on consent (Article 6(1)(a) GDPR).
    3. 3)Retention: 24 months from submission or until an objection is made; the record of consent, 3 years from withdrawal.
  15. 15.
    Partner programme. Data about partners and about people named in referrals is processed as described in separate notices: the notice for partners and the notice for referred persons.
  16. 16.
    Statistics about visits to Venue pages. The Service counts views of Venue pages and uses of their elements, such as the telephone number or the menu, as aggregate counters, without recording anything that identifies the visitor. These counters are not personal data.

§ 4. Sources of data

  1. 1.
    The Controller obtains data directly from the people it concerns, except for data provided by a Venue as described in § 2(3), data provided by a partner in the partner programme as described in a separate notice, the approximate location derived from the IP address, and the company name and address taken from the register of VAT taxpayers.

§ 5. Recipients of data

  1. 1.
    Venues receive data about Bookings, Booking Requests, messages and coupon redemptions relating to that Venue. A Venue does not receive Guests’ contact details from the Controller for the purpose of sending them commercial communications.
  2. 2.
    The following providers process data on the Controller’s instructions:
    1. 1)Google Ireland Limited and Google LLC – Firebase services: authentication, database and file storage; the database and files are stored in data centres within the European Economic Area;
    2. 2)Vercel Inc. – hosting and running the application in the Frankfurt am Main region (Germany);
    3. 3)Resend – sending emails;
    4. 4)650 Industries, Inc. (Expo) – delivering push notifications to the mobile application;
    5. 5)Cloudflare, Inc. – protecting selected forms against automated programs (Turnstile).
  3. 3.
    Data may also be received by:
    1. 1)Stripe Payments Europe, Limited – for processing payments and subscriptions and for issuing invoices and credit notes;
    2. 2)Google LLC – if the Guest adds a Booking pass to Google Wallet; an Apple Wallet pass is downloaded directly to the Guest’s device;
    3. 3)the operator of the GetUp booking system – for Venues whose Bookings are handled in that system;
    4. 4)the OpenStreetMap Foundation – only the Venue’s address, to place it on the map;
    5. 5)the Controller’s legal, tax and accounting advisers, and bodies entitled to the data by law.

§ 6. Transfers outside the European Economic Area

  1. 1.
    The Controller is established in the United Kingdom. Access to data from the United Kingdom takes place on the basis of the European Commission’s decision finding an adequate level of protection of personal data in the United Kingdom.
  2. 2.
    Google LLC, Vercel Inc., Resend, 650 Industries, Inc. and Cloudflare, Inc. may process data in the United States. Transfers to them take place on the basis of Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework where the recipient participates in that framework, and otherwise on the basis of standard contractual clauses adopted by the European Commission.
  3. 3.
    A copy of the safeguards applied can be obtained by writing to privacy@tujemy.com.

§ 7. Rights of data subjects

  1. 1.
    Every data subject has the right:
    1. 1)of access to the data (Article 15 GDPR);
    2. 2)to rectification (Article 16 GDPR);
    3. 3)to erasure (Article 17 GDPR);
    4. 4)to restriction of processing (Article 18 GDPR);
    5. 5)to data portability (Article 20 GDPR);
    6. 6)to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
  2. 2.
    Right to object. Every person has the right to object at any time, on grounds relating to their particular situation, to processing of their data based on the Controller’s legitimate interest (Article 6(1)(f) GDPR). An objection to processing for direct marketing may be made at any time without giving reasons, and the Controller then stops processing the data for that purpose.
  3. 3.
    The rights can be exercised by writing to privacy@tujemy.com. Some of them can be exercised directly: profile data and notification consents are changed in the Account settings, a copy of the data can be downloaded in the application, and the Account can be deleted in the application. The Controller responds without undue delay and in any event within one month of receiving the request; where justified, that period may be extended by two further months, and the Controller will say so.
  4. 4.
    Every person has the right to lodge a complaint with a supervisory authority: in Poland, the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw), and with the supervisory authority in the Member State of their habitual residence, place of work or place of the alleged infringement. In the United Kingdom, the supervisory authority is the Information Commissioner’s Office.

§ 8. Whether data must be provided, and automated decisions

  1. 1.
    Providing data is voluntary but necessary to create an Account, make a Booking or claim an Offer. Giving a telephone number and adding a profile photo are optional. Giving marketing consents is voluntary and is not a condition of using the Service.
  2. 2.
    The Controller does not take decisions based solely on automated processing, including profiling, that produce legal effects concerning a person or similarly significantly affect them. Automatic limits on the number of attempts, used to protect the Service, are not such decisions.

§ 9. Cookies and similar technologies

  1. 1.
    The Service stores information on the User’s device and accesses it only as described in this section.
  2. 2.
    Without consent, because this is necessary to provide the service the User is using:
    1. 1)the tujemy_session cookie – keeping the session after sign-in;
    2. 2)the tujemy_locale cookie – remembering the chosen language;
    3. 3)the tujemy_app cookie – recognising that the Service is being used as an application added to the device’s home screen;
    4. 4)the tujemy_active_venue, tujemy_asid and tujemy_admin_device cookies – in the Venue panel and the Tujemy team panel, to remember the selected Venue and to keep a secure session and a trusted device;
    5. 5)entries in browser storage – remembering the choice about cookies and interface settings;
    6. 6)the Cloudflare Turnstile script on selected forms – telling a person apart from an automated program;
    7. 7)in the mobile application – sign-in session data kept in the operating system’s secure storage.
  3. 3.
    With the User’s consent, in the “Statistics” category: an entry in the browser’s session storage that prevents the same visit to a Venue page from being counted more than once. Without consent, the visit is counted without storing anything on the device.
  4. 4.
    The Service does not use advertising cookies or third-party analytics or tracking tools.
  5. 5.
    The choice about cookies can be changed at any time using the “Ustawienia cookies” (cookie settings) link in the Service’s footer.

§ 10. Changes to the Policy

  1. 1.
    Each version of the Policy is identified by its version date, and earlier versions are available in the version archive in the Service.
  2. 2.
    The Service informs a User of a change to the Policy the next time the User uses the Account, makes a Booking or claims an Offer, and informs a Venue in the Venue panel and by email.
  3. 3.
    This version of the Policy applies from 17 September 2026.

SHA-256 tekstu polskiego

fbf70054080343f0133eeeef7b70331d9b358f5ab6b421c800fb3831e93db6f1

Skrót pozwala sprawdzić, że ten tekst jest dokładnie tym, który zapisano przy akceptacji.