This policy explains how Polish Travel Quo Vadis Sp. z o.o. processes personal data in connection with its websites, in particular polishtravel.com.pl and visitpoland.com, communications, proposals, bookings, business and leisure travel, and events. VisitPoland is a brand of the same company, not a separate data controller.
The policy covers website visitors, people making inquiries, customers, travelers, event participants and business contacts. It applies where PTQV acts as controller. Where we act solely as a processor on a customer’s instructions for a particular service, the relevant privacy notice comes from that customer; this policy does not change the allocation of roles.
We provide this information under Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”). This policy is the core privacy notice for PTQV websites, campaign landing pages, forms and correspondence that refer to it, within the scope of services described here. Notices for particular bookings, events or forms supplement it, especially where additional purposes or recipients are involved. It does not replace separate notices for employment, recruitment or processing by another controller.
The website tools used may differ between domains. Section X and the register at the end describe the common rules; the relevant consent panel and cookie declaration identify tools actually activated on a particular website. Describing a tool in this policy does not itself mean that it is active or that the user has consented.
I. Controller and contact details
The controller is Polish Travel Quo Vadis Sp. z o.o., ul. Ptasia 2, 00-138 Warsaw, Poland, National Court Register (KRS) number 0000148731, tax identification number (NIP) 5260211386 (“PTQV”, “Controller”, “we” or “us”).
For privacy questions, withdrawal of consent and requests to exercise your rights, contact the Controller using our contact form or by post at the address above. You may begin your message with “Personal data protection” to help us route your request, but this is not required. The form can be used for matters concerning both Polish Travel and VisitPoland.
II. Purposes and legal bases
We process only the data needed for a specified purpose, using the appropriate legal basis:
1. Inquiries, proposals and contracts
Preparing a proposal at your request, entering into and performing a contract, handling bookings and making arrangements for tickets, accommodations, transportation, car rentals, travel insurance, individual and business travel, DMC services, conferences, meetings, incentives and events — Article 6(1)(b) GDPR, where you are the contracting party or request steps before entering into a contract.
2. Business contacts and travel booked by others
Communicating with company and partner representatives and arranging services for people designated by an employer, event organizer or person making a booking — Article 6(1)(f) GDPR. The legitimate interest is to coordinate arrangements, fulfill the order and support the people covered by the service. We do not automatically apply the contractual basis in paragraph 1 to every traveler who is not a party to a contract with us.
3. Legal obligations
Settlements, accounting and tax records, invoicing and obligations applicable to the particular service — Article 6(1)(c) GDPR, including under applicable accounting, tax and tourism legislation.
4. Correspondence, service quality and legal claims
Answering questions not directly related to a proposed contract, addressing feedback, keeping necessary records of arrangements, reviewing service quality, and establishing, exercising or defending legal claims — Article 6(1)(f) GDPR. The legitimate interests are communication, service improvement and protection of rights. Where handling a matter fulfills a specific legal obligation, Article 6(1)(c) GDPR applies to that part of the processing.
5. Marketing our own services
Marketing our own services may rely on Article 6(1)(f) GDPR where the circumstances, assessment of interests and rules for the relevant channel permit. That interest does not replace consent required for marketing communications or tracking technologies.
We send requested newsletters and other marketing emails or make marketing telephone calls on the basis of the appropriate voluntary consent — Article 6(1)(a) GDPR and Article 398 of the Polish Electronic Communications Law of July 12, 2024 (“PKE”). The consent identifies the purpose and communication channel. Answering a specific inquiry does not sign you up for subsequent marketing campaigns.
6. Website operation and security
Providing the websites, technical maintenance, detecting errors and misuse, and protecting systems — Article 6(1)(f) GDPR. The legitimate interest is maintaining service availability and security. Rules on storing information on your device are addressed separately in section X.
7. Rights requests and consent records
Fulfilling GDPR obligations, including handling requests and demonstrating compliance — Article 6(1)(c) GDPR. A limited record of an objection or opt-out may be needed to avoid resuming unwanted marketing. The basis is compliance with legal obligations and, to the extent necessary for the protection of legal claims, Article 6(1)(f) GDPR.
8. Special categories of data
If the service you request requires information about health, disability, allergies or other specific needs that reveal data covered by Article 9 GDPR, we process the necessary information on the basis of explicit consent — Articles 6(1)(a) and 9(2)(a) GDPR. A dietary preference is not necessarily health data or another special category of data.
Where vital interests are at risk, Articles 6(1)(d) and 9(2)(c) GDPR may apply; for special categories, this requires that the person is physically or legally incapable of giving consent. Such data may also be processed where necessary for legal claims under Articles 6(1)(f) and 9(2)(f) GDPR. Please do not send unnecessary medical records or identity-document copies with general inquiries.
9. Website analytics and usability
Measuring traffic, referral sources, content and campaign performance, actions leading to service inquiries, and website usability using the tools described in section X — on the basis of consent, Article 6(1)(a) GDPR, taking account of Article 399 PKE. This also covers linking events to a pseudonymous identifier where used. We do not treat analytics as necessary merely to display an offer.
10. Information materials and follow-up
Providing a guide, itinerary, presentation or other material you request and responding to a need you expressly communicate — Article 6(1)(b) GDPR where we provide the requested service or take pre-contractual steps; otherwise Article 6(1)(f), namely our legitimate interest in answering a request for information. Adding your details to a newsletter or subsequent campaigns unrelated to the inquiry requires a separate basis and appropriate consent for the communication channel.
III. Whether you need to provide data
You do not need to provide your name to browse publicly available content. When you contact us, we need details that allow us to respond; when you make a booking, we need the data required for that particular service. Without the required information, we may be unable to respond, enter into a contract or fulfill the booking. Invoicing data may be required by law.
Additional information and marketing consent are voluntary. Declining marketing does not prevent us from handling an inquiry, providing a purchased service or delivering material you requested. Forms distinguish required fields from optional ones. Withdrawing consent to data needed for specific assistance may prevent us from providing that assistance, but does not justify collecting additional unnecessary data.
IV. Categories and sources of personal data
Depending on the communication and service, we process:
- identification and contact details: name, address, email and telephone number, and, for business contacts, organization, position or role;
- booking information: dates, itineraries, participants, services required, preferences, booking references and necessary travel-document details; date of birth, age or nationality only where required for the service or by law;
- billing information and records of arrangements: invoice details, payment status, correspondence, complaints and records of service delivery;
- information about specific needs, as described in section II, paragraph 8;
- technical connection data: IP address, request time, page address, browser and device information, and error information, to the extent recorded by the website infrastructure;
- the content and date of consents, withdrawals and objections, where relevant to the process.
We receive data directly from you or from a person booking on your behalf, an employer, a group or event organizer, or a partner handling the booking. Business contact information may also come from professional information you have made available. We receive only the categories needed for the communication or requested service.
Where data does not come directly from you, we provide the required information under Article 14 GDPR, normally within one month. If we contact you or disclose the data to another recipient sooner, we provide it at the first communication or first disclosure, as applicable, unless a statutory exception applies. Publishing a policy on a website does not itself replace the required provision of that information.
Analytics may involve pseudonymous browser and session identifiers, referral sources, visited pages, clicks, scrolling, activity duration, device type, language and approximate location. Such information is not anonymous by definition. Measuring a form submission only requires recording the event; message contents, names, emails, telephone numbers and travel details should not be sent to analytics tools or included in URLs used for measurement.
We obtain necessary data about children traveling with a family or group from an authorized parent, guardian or organizer, for example for tickets or accommodations. Describing family travel does not invite children to submit information independently or authorize advertising profiling of children.
V. Recipients of personal data
Where necessary for the relevant purpose, data may be shared with:
- hotels and other accommodation providers; air, rail, ferry and coach carriers; transportation and car-rental companies; and insurers;
- reservation and global distribution system (GDS) providers, and organizations supporting ticket issuance and settlement;
- guides, tour leaders, local partners, conference venues and other providers delivering a travel or event program;
- the employer or organizer funding the service, to the extent needed for the agreed booking and settlement, without automatic access to all additional traveler information;
- hosting, IT support and communication-tool providers, accountants, legal advisers, banks and payment providers;
- competent public authorities and, for requested visa services, relevant consular offices, only on an appropriate basis and to the extent necessary.
Not every recipient receives data for every service. We share only what is needed for a specified task. Providers acting on our instructions are processors, while carriers, hotels, insurers or other service providers may be independent controllers for their services and obligations. We provide the relevant information about particular providers during booking support.
We use Microsoft 365 for communications and document-related work. Bookings and settlements also use travel-industry, service-management and accounting systems. A software product’s name does not mean its developer receives all data processed in it. Recipients are the entities actually providing hosting, maintenance, support or data-processing services. Google Analytics 4, Cookiebot and Microsoft Clarity are addressed in section X and the tools register.
For Clarity, Microsoft acts as an independent data controller to the extent described by the provider, rather than solely as a processor acting on our instructions. We distinguish the Clarity terms from the terms for Microsoft 365 services. Details appear in section X.4.
We do not sell customer databases. For promotional activities co-funded by the Polish Tourism Organisation (POT), reporting uses aggregated, anonymized results; submitting an inquiry through VisitPoland does not itself result in the lead’s contact details being provided to POT.
VI. Processing and retention periods
Retention depends on the purpose and category of data. We adopt the rules below; longer retention requires the separate reason described, not simply the possibility that the data might be useful later:
- Inquiries and proposals without a contract: during active discussions and for up to 12 months after the last substantive contact, to allow a return to arrangements for the trip or event. Unnecessary data is removed earlier. After that, only data necessary for a legal obligation or a specific claim is retained.
- Contracts and bookings: during preparation, delivery and settlement of the service. We then keep records necessary for legal obligations and the protection of claims; this does not automatically include all travel-document details, specific-needs information or complete traveler profiles.
- Business contacts: for the business relationship and while the person acts as a contact, until we learn of a change or receive an effective objection, subject to retaining necessary contract and claims records.
- Legal claims: for the applicable limitation period and, in a dispute, through its final resolution and enforcement. The general period under Article 118 of the Polish Civil Code is 6 years, or 3 years for periodic obligations and claims connected with business activity, unless a special rule applies. The start, end, suspension or interruption of the period is assessed for the particular case.
- Accounting and tax records: for the period required by applicable law. As a general rule, accounting books and many supporting records are kept for 5 years, calculated under Article 74 of the Polish Accounting Act. Tax records are kept until the liability becomes time-barred; the general period is 5 years from the end of the calendar year in which payment was due, subject to statutory exceptions. Invoices covered by Article 112aa of the Polish VAT Act are stored in KSeF for 10 years from the end of the year of issue. The KSeF period does not automatically apply to other customer data.
- Consent-based marketing: until consent is withdrawn or the purpose ends earlier. For legitimate-interest marketing, until an effective objection or the end of the interest. A minimal opt-out or objection record is kept as long as needed to respect that choice, without using it for further marketing.
- Consent and rights-request records: while relying on consent or handling the matter, and afterwards while necessary to demonstrate compliance or defend a specific claim; we retain the evidence needed, not the entire activity history. Consent data handled by Cookiebot follows the provider’s separate cycle described in section X.
- Health and specific-needs data: until the relevant service and any matters raised about it are concluded, or consent is withdrawn earlier. Further retention requires a separate basis, for example Article 9(2)(f) GDPR for a specific legal claim.
- Public-website logs: standard access and error logs for up to 30 days after the event; separate security logs for up to 90 days. Incident-related entries may be isolated while investigating, remedying consequences and protecting necessary claims. These periods do not apply to accounting or booking records.
- Analytics and usability research: under the GA4 and Microsoft Clarity rules in section X. Irreversibly anonymized results that do not allow a person to be reidentified may be retained longer as statistics.
- Cookies and browser storage: for the periods disclosed for individual mechanisms in the declaration for the relevant domain. A cookie’s expiry is not the retention period for all data held by the provider.
At the end of the applicable period, we delete or irreversibly anonymize data. Data scheduled for deletion may remain in isolated operational backups of public websites until the backup overwrite cycle ends, for no longer than 90 days; it is not used in routine service or marketing. Restoring a backup does not restore a basis for using previously deleted data. Copies of documents subject to statutory retention are kept in accordance with the obligations applying to those documents.
VII. Profiling and automated decisions
Our website measurement assesses visibility, traffic sources, content usability and the effectiveness of generating inquiries. We do not run remarketing campaigns that target people again because of earlier visits to our websites. We do not use automated assessments of website activity to set an individual price, refuse a service or assess a user’s economic situation or health.
The absence of remarketing by PTQV does not mean that the Clarity provider acts solely on our instructions or has no purposes of its own. Section X.4 explains Microsoft’s independent role, its purposes and privacy choices.
Analytics tools may distinguish sessions and link interactions to a pseudonymous identifier. To the extent that automated analysis evaluates an individual’s behavior, it may constitute profiling under Article 4(4) GDPR. Within the scope described, its purpose is to understand website use and remove usability obstacles, not to make decisions about a person’s rights. Such analysis is limited to the consent given for the specific tool and purpose. You may decline or withdraw that consent without losing the ability to make an inquiry.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you within Article 22 GDPR. Our team handles and qualifies inquiries. Automated acknowledgments, routing inquiries to the appropriate department or searching for services according to supplied parameters are not, by themselves, such decisions.
VIII. Your rights
Subject to the conditions in the GDPR, you have rights of access and a copy of your data, rectification, erasure and restriction of processing. Erasure does not override legal retention duties or the need to keep relevant data for legal claims.
Data portability: where processing is based on consent or a contract and is carried out by automated means, you may receive data you provided to us in a structured, commonly used, machine-readable format and, where technically feasible, request its transfer to another controller.
Objection: you may object to processing under Article 6(1)(f) on grounds relating to your particular situation. You may object at any time, without giving a reason, to direct marketing, including related profiling. We will then stop that marketing.
Withdrawal of consent: you may withdraw consent at any time without affecting the lawfulness of earlier processing. Use the available opt-out mechanism or contact us using section I. Withdrawal does not remove your rights or automatically erase data retained on another valid basis.
We respond without undue delay, normally within one month. Where the GDPR permits, this period may be extended by two further months; we explain the reason within the first month. If we have reasonable doubts, we may request the information necessary to confirm your identity. Rights requests are normally handled free of charge, subject to the GDPR’s exceptions.
You may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) — information at uodo.gov.pl/en — or another competent supervisory authority, particularly in the EU Member State of your habitual residence, workplace or the alleged infringement. You do not need to complain to us first.
IX. Transfers outside the European Economic Area
Data relating to cloud services, analytics or international bookings may be transferred outside the European Economic Area (“EEA”), including through remote access by a provider’s personnel. Hosting a primary server in the EU does not rule out such access.
Use of Microsoft 365 and Google Analytics 4 may involve transfers to Microsoft and Google group entities, particularly in the United States, as part of providing and securing the services. The providers’ terms include transfer mechanisms, including European Commission Standard Contractual Clauses where applicable. Documentation: Microsoft Data Protection Addendum and Google Data Processing Terms.
For Microsoft Clarity, the provider identifies Microsoft Ireland Operations Limited (Ireland) as the contracting entity for EU customers and describes transfers to Microsoft Corporation (United States) under Standard Contractual Clauses between those entities. Data is processed using Microsoft Azure infrastructure. We do not state that all Clarity data is stored exclusively in the EEA. The service-specific terms and the Microsoft Privacy Statement apply; using Microsoft 365 does not determine the terms for Clarity.
We assess the appropriate basis for each transfer: a European Commission adequacy decision within its applicable scope, or safeguards under Article 46 GDPR, particularly Standard Contractual Clauses, together with a transfer assessment and supplementary measures where needed. We do not assume that every overseas entity in a familiar corporate group is automatically covered by an adequacy decision.
For a particular trip, data is sent to recipients in countries connected with the itinerary, for example a carrier or hotel. Where neither adequacy nor appropriate safeguards are available, Article 49 GDPR exceptions may be used only when their conditions are met, for example where a transfer is necessary for a particular travel contract with you or a contract concluded in your interest. This is not a general basis for routine use of overseas cloud or marketing tools.
Information about a particular recipient, country, transfer basis and how to obtain a copy of the safeguards can be requested through our contact form. We provide safeguards with appropriate protection for others’ rights and legitimate confidentiality. Section X and the current tools register provide further information about website tools.
X. Cookies, similar technologies and consent
1. Purposes and rules for technologies
Cookies, browser local storage, pixels and similar technologies may support website operation, save privacy choices, measure traffic and assess usability. Technical data necessary to handle a server connection is distinguished from additional activity tracking.
Under Article 399 PKE, storing or accessing information on a device requires prior consent unless strictly necessary for transmission or a service expressly requested by the user. Article 6(1)(a) GDPR applies to personal data analyzed in this context. Newsletter consent, an inquiry or continued browsing does not replace consent to these technologies.
2. Choosing and changing consent — Cookiebot
Cookiebot by Usercentrics is the solution designated to manage privacy choices on our websites. On a domain where its panel has been deployed, you may accept selected purposes, decline optional technologies and reopen the settings using the privacy button or the “Ustawienia cookies” / “Cookie settings” link. Declining consent does not disable basic content or communication with us. We do not activate optional tools requiring consent until the domain’s panel is available and checked.
Cookiebot handles data needed to remember and document choices, including a consent identifier, the choice, date and relevant technical information. Demonstrating consent relies on Article 6(1)(c) in conjunction with Article 7(1) GDPR; mechanisms needed to save the user’s choice are not advertising. The provider, Usercentrics A/S, Denmark, describes deletion of end-user data on a 12-month cycle from registration. A separate minimal record retained by PTQV follows section VI. More information: Cookiebot privacy policy.
Withdrawing consent stops further use of the optional tools concerned but does not affect the lawfulness of processing before withdrawal. Erasure of data already sent to a provider requires the appropriate mechanisms or an erasure request. Browser settings are an additional option, not a substitute for choices provided by the website.
3. Google Analytics 4
We use Google Analytics 4 (GA4), a service of Google Ireland Limited, Ireland, to measure traffic, referral sources, content popularity and actions leading to inquiries. Analysis may include browser and session identifiers, device information, language, approximate location, visited pages and events such as a button click or form submission. Clicking an email address or telephone number does not itself mean that a message was sent or a conversation occurred.
GA4 operates within the analytics consent given. We do not deliberately send correspondence, names, emails, telephone numbers, identity-document details or booking data to GA4. We do not use GA4 data for remarketing campaigns. The provider states that GA4 does not log or store individual IP addresses; this does not make all other data anonymous.
For user and event data covered by the GA4 retention setting, we adopt a 14-month period without resetting identifier retention on new activity. Data is removed in the provider’s monthly deletion cycle after the period expires. This setting does not cover standard aggregated reports and is not the lifespan of cookies. Individual rights and earlier erasure apply independently of the setting. Documentation: GA4 data retention and Google privacy policy.
4. Usability research — Microsoft Clarity
Purpose and activation. Microsoft Clarity is the tool selected for usability research on PTQV’s public websites. Where deployed, we use it only after prior consent covering this analysis and the disclosure of data to Microsoft. We assess which content is clear and where users encounter difficulties. This is not intended to record conversations or evaluate an individual customer.
Data collected. Analysis includes clicks, scrolling, pointer movements, navigation between pages, device and browser information, activity timing, referral sources, approximate location and pseudonymous identifiers. This information supports heatmaps and replays of website use. A session replay reconstructs the page view and interactions; it is not a recording from your camera or microphone. Pseudonymous data is not automatically anonymous.
Limitations. Clarity does not cover logged-in areas, payment areas, booking details or pages intended for children. Form contents and other personal data displayed on a page are excluded from capture or masked before transmission. We do not send names, emails, phone numbers, message contents, travel-document details or health information to Clarity. We do not link replays to CRM records, names, travel histories or individual lead scores. These restrictions also cover URLs, parameters and custom tags sent to the tool.
Provider and role. For EU customers, the provider identifies Microsoft Ireland Operations Limited, with Microsoft Corporation and other group entities involved in service delivery. Microsoft processes Clarity data as a controller under its own privacy statement. That statement also describes Microsoft’s own purposes, including security, development and improvement of services, and advertising, subject to applicable terms and privacy choices. We do not present Clarity as a tool acting solely on our instructions. More information about purposes, recipients and rights: Microsoft Privacy Statement.
Retention. According to Clarity documentation, ordinary session playback data is retained for 30 days from recording. Click data, heatmaps and sessions labeled or marked as favorites may be retained for 9 months. Microsoft also describes retaining a randomly selected sample of recordings for up to 9 months. Within the adopted scope, PTQV does not favorite or label sessions to extend their retention and does not create its own replay archive. This does not prevent longer retention of click data, heatmaps or the sample retained by the service. 30 days is not a deletion deadline for all Clarity data. Click data may include a user identifier, so we do not describe all of it as anonymous. Details: Clarity data retention and the Clarity FAQ.
Consent and opting out. Declining or withdrawing Clarity consent does not prevent you from accessing our offers or contacting us. Under our adopted model, we do not activate Clarity data collection without that consent, including its limited cookieless mode. Analytics consent does not amount to consent for advertising purposes. Choices are made in the domain’s privacy panel; we send the tool signals reflecting the actual choice. Within the scope described, PTQV does not activate Clarity integration with Microsoft Advertising or run remarketing campaigns.
Erasure and contact. Withdrawal stops future collection but does not automatically erase data already transmitted. Please submit requests about data processed by PTQV through our contact form. Microsoft provides a separate rights-request route in its privacy statement. Clarity documentation describes limitations on deleting individual recordings and an individual’s data through the dashboard; action concerning the entire project or a request to Microsoft may be needed. A tool’s limitations do not remove GDPR rights.
5. Scope of consent and the current declaration
A choice on one website does not automatically authorize every other domain and purpose. The detailed cookie declaration associated with each panel identifies the mechanisms actually used on that domain, their providers, purposes and lifespans. The tools register at the end of the policy is an additional information layer, not a replacement for an accurate technical declaration. A new purpose, tool or transfer requires updated information and, where existing consent does not cover it, appropriate consent before activation.
XI. Security, other websites and policy changes
We apply technical and organizational measures appropriate to the risks, including access restrictions, protected communications, system safeguards and arrangements for secure handling of data. Access is provided to people and providers who need it for their tasks. We do not claim that all risk can be eliminated.
Links to external websites lead to environments with separate privacy notices. Embedded maps, videos and other external components require a separate assessment of data flows and an appropriate basis; linking to a provider’s notice does not replace information and consent required on our side.
We update the policy when services, purposes, legal bases or processing actually change. Website-tool details may be updated in the register and cookie declaration without rewriting the other sections. We give notice of material changes before the relevant processing; a new document is not the user’s consent. The language versions describe the same rules and do not restrict mandatory rights under applicable law.
Tools register and deployment scope
Scope covered by this version — September 13, 2026.
The register below identifies the tools covered by this policy. Their presence and current operation on a particular domain are shown in the relevant consent panel and cookie declaration. Optional tools remain inactive until correctly deployed and the required consent is obtained.
Google Analytics 4 — traffic and inquiry measurement. Provider: Google Ireland Limited, Ireland, with possible involvement of Google LLC and other group entities, including in the United States. Consent-based analytics, without PTQV remarketing. Data covered by the retention setting: 14 months, without resetting identifier retention on new activity. Details: X.3.
Microsoft Clarity — usability research. Selected for deployment on public pages after the conditions in X.4 are met; this description does not mean that it is active on every domain. For EU customers: Microsoft Ireland Operations Limited; Microsoft Corporation in the United States may be involved. Ordinary replays: 30 days; click data, heatmaps and certain retained sessions: up to 9 months. Microsoft acts as a controller within the scope it describes. We do not link replays to CRM or booking records.
Cookiebot — consent management. Provider: Usercentrics A/S, Denmark. The panel deployed for each domain handles privacy choices and cookie declarations. The provider describes deletion of end-user data after 12 months from registration; a separate, necessary consent record held by PTQV is governed by section VI. Details: X.2.
Remarketing and automated lead scoring based on visits — outside PTQV’s current scope. Activation requires a separately defined process, information and an appropriate basis, not merely an additional tag. Microsoft’s independent purposes in connection with Clarity are described in X.4.
Contact about any of these tools: contact form.
