This AI translation underwent a separate AI review. The Polish version is the source text. Polski
Privacy Policy
Protecting your personal data is important to us. Below, we explain what data we collect, why we collect it and what your rights are.
1. Who is the data controller?
VITA Waldemar Podgrudny
ul. Rajgrodzka 140, 16-300 Augustów
NIP: 8461052803 | REGON: 790316116
2. How can you contact us?
If you have questions about your data or wish to correct or delete it, contact us:
- Email: biuro@vita.augustow.pl
- Address: ul. Rajgrodzka 140, 16-300 Augustów
3. What data do we collect and why?
We collect the data you provide when booking: first name, surname, email address and telephone number. We also record your IP address while you use the website.
We use them to:
- processing accommodation bookings through the vita.augustow.pl website
- contact you regarding your booking
- send information about our offering and promotions (if you consent to this)
- conduct statistical analysis and improve the operation of the website
If necessary to implement child protection standards, we may also process data required to confirm the child's identity, the child's relationship with the adult, the consent of a parent or guardian, and information concerning a reported incident that threatens the child's welfare.
In such cases, we apply the principle of data minimisation. Identity documents may be presented for inspection, but we do not make copies unless required by law or requested by an authorised body.
4. Newsletter and PDF material recipients
If you have provided us with your email address and first name for this purpose, we provide a newsletter or PDF material delivery service, which consists of providing information about planning your stay, the accommodation services we offer and promotions. In the forms, we may also ask for the planned month of your stay, the number of adults and children, and an optional telephone number so that we can better tailor our subsequent response. Providing this data is voluntary but necessary to send the material or contact you in response.
Personal data is processed:
- where marketing content is sent as part of the newsletter – the legal basis for processing is our legitimate interest in connection with the consent given by the User
- for analytical and statistical purposes – the legal basis for processing is our legitimate interest in analysing user activity in order to improve the functions we use and enhance our offering
- for the purpose of establishing, pursuing or defending against potential claims – the legal basis for processing is our legitimate interest in protecting our rights
5. Contact by email
When the User contacts us by email, they also provide us with their email address as the sender of the message. They may also include other personal data in the message.
We may ask the User to provide additional data only where it is necessary to handle the matter to which the contact relates.
In this case, the legal basis is our legitimate interest in connection with the consent given, consisting in the need to resolve the reported matter relating to the service and, where applicable, to pursue and defend against potential claims.
6. How long do we retain data?
We retain data:
- for the duration of the service (booking and stay)
- until consent is withdrawn
- until an objection is lodged
- until a request to delete the data is made
The retention period may be extended if required by law or if necessary to establish, pursue or defend against claims.
7. What are your rights?
You have the right to:
- access your data (including obtaining a copy)
- rectify your data
- erase your data
- restrict processing
- data portability
- withdraw consent at any time
- object to processing
- lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa)
8. Who do we share data with?
We disclose data only to trusted partners who process it on our behalf, in accordance with our instructions and subject to confidentiality. Otherwise, data may only be disclosed to entities authorised under applicable law.
9. Cookies
Cookies are small text files that our website stores in your browser during your visit. Each cookie contains the name of the website from which it originates, its expiry date and a unique number identifying your browser.
| Type | Purpose |
|---|---|
| Essential | Enable the use of essential website functions, e.g. logging in to the booking system |
| Functional | Remember your settings (e.g. language, region) and personalise the appearance of the website |
| Analytics | Help us understand how you use the website so that we can improve it |
| Advertising | Enable the display of advertising content tailored to your interests |
We do not retain any information about your computer's configuration or installed software.
How can you disable cookies?
You can disable or restrict cookies at any time in your browser settings:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Settings → Privacy and Security → Cookies
- Safari: Preferences → Privacy → Cookies
- Edge: Settings → Cookies and site permissions
- Opera: Settings → Privacy and security → Cookies
Disabling cookies may limit some website functions.
10. Partner tools
We use tools provided by external partners to deliver and improve our services:
Brevo (Sendinblue)
A tool for sending newsletters, PDF materials and information about our offering (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France). This involves storing your email address, first name and the data provided in the form in the Brevo system. Data is stored on servers in the European Union.
Google Analytics
A tool for analysing website traffic (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). It collects anonymous data about visits, traffic sources and behaviour on the website. It uses cookies. Activated only after consent has been given (Consent Mode v2).
Google Ads
A tool for targeting advertisements on Google Search and the Google Display Network (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). We use it to promote our accommodation services. Google Ads may store cookies to measure advertising effectiveness and for remarketing. Activated only after consent has been given (Consent Mode v2).
To measure advertising effectiveness, we use conversion measurement, including offline conversions: after you make a booking, we may provide Google — only if you have previously consented — with information about the booking, together with the advertising click identifier (gclid) and the value of the booking. For this purpose, we do not provide your first name, surname, email address or telephone number. Data may also be processed outside the European Economic Area (including in the USA) subject to appropriate safeguards (standard contractual clauses / Data Privacy Framework).
Microsoft Clarity
A tool for analysing user behaviour on the website (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA). It creates heat maps and anonymous session recordings. It uses cookies. Activated only after consent has been given.
Google Maps
A map of the property on the contact page (Google Ireland Ltd.). Loading the map involves sending your IP address to Google's servers.
Google Fonts
Fonts loaded from Google's servers (Google Ireland Ltd.). When the page loads, the browser sends a request to Google, which involves transmitting the IP address.
Facebook Pixel
A tool for targeting personalised advertisements on Facebook (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland). We use it to promote our accommodation services. The pixel is activated only after consent has been given (Consent Mode v2).
We also use the Meta Conversions API — server-side conversion measurement: after you make a booking, we may provide Meta — only if you have previously consented — with information about the booking event, together with the technical click identifier (fbclid) and the value of the booking, in order to measure advertising effectiveness. Data may also be processed outside the European Economic Area (including in the USA) subject to appropriate safeguards.
11. Data protection
We use appropriate technical and organisational measures to protect your data against unauthorised access, loss or destruction.
12. Changes to the Privacy Policy
If anything changes, we will publish an updated version on this page.
The current version of this policy is effective from:
13. Copyright
All content, photographs and materials published on the vita.augustow.pl website are the property of VITA Waldemar Podgrudny and are protected by copyright under the Act of 4 February 1994 on Copyright and Related Rights.
Copying, distributing or using materials without the owner's written consent is prohibited.
14. The August chatbot and artificial intelligence
August is an automated assistant that uses artificial intelligence. You can talk to it through the widget on vita.augustow.pl and in messages sent to VITA through Messenger and Instagram DM. In each of these channels, the controller of the data processed by VITA remains the entity identified in section 1.
What data we process and why
Depending on the channel, we process:
- the content of questions and answers required to provide an answer and retain a short conversation context,
- a temporary session identifier, the selected language and the identifier of the page on which the chat was opened,
- in Messenger and Instagram — the user and channel identifier provided by Meta,
- a short-lived, rotating technical identifier derived from the IP address, required solely to limit requests and prevent misuse; this identifier remains only in RAM, and the full IP address is not stored in August application data,
- limited technical data needed to diagnose errors and produce anonymous usage statistics.
We use the data to answer questions about stays and the VITA offer, maintain the continuity of a short conversation, protect the service and measure its reliability. The chat is not used for marketing without a separate legal basis.
Providing data in your question is voluntary, but August cannot answer unless you submit a question.
AI model provider and processing location
After the new version is launched, the technical service provider used to generate responses will be Amazon Web Services (AWS), through the Amazon Bedrock service. The deployment candidate pins the source region to eu-central-1 (Frankfurt) and uses inference profiles with the prefix eu.. The new version will not be launched until the list of effective destination regions for both profiles in use has been checked and confirmed to be limited to the European Union.
VITA will send the content of the question and a short context to Amazon Bedrock to generate a response. AWS processes these data in accordance with the service terms and documentation and may apply security and abuse-detection mechanisms. In the planned configuration, according to AWS documentation, input and output data are not used to train foundation models. However, the effective mode of data retention and any disclosure of data to the model provider depend on the account, project, model and invocation method. VITA therefore does not make an unconditional statement that AWS never stores or discloses any data. Before the new version is launched, this mode will be verified for both models in use.
More information: data retention in Amazon Bedrock, AWS geographic profiles.
How long we retain August data
After the new version is launched, the following periods will apply:
- WWW, Messenger and Instagram conversation context: held only in RAM, for no more than 30 minutes after the last activity; VITA will not create a permanent archive of conversation content,
- browser: the current session history in
sessionStorage, which expires automatically after 30 minutes, - anti-abuse identifiers: held only in RAM and only for the relevant protection window: up to 60 seconds for the per-minute limit, up to 10 minutes for noise events, up to 1 hour for a short block and no later than the end of the current UTC day for the daily counter,
- August application logs: for no more than 14 days, without the content of questions and answers, the full IP address or the full Meta user identifier,
- anonymous usage counters: no longer than 90 days; without conversation content or user identifiers.
Infrastructure logs: Cloudflare logs (including logs from the tunnel or Worker in use), reverse proxy, system service and operating system logs — as well as Caddy logs, if Caddy is part of the effective chain — are separate from August's application logs. They may contain network identifiers. Until the production settings have been inventoried, we do not state that these logs are free of identifiers or that the 14-day application-log retention period applies to them. Publication blocker: the actual scope, file permissions, operation of the deletion mechanisms, monitoring and retention of these logs must be verified before the coordinated launch of the new version.
The retention periods above apply to systems controlled by VITA. Messages sent through Messenger or Instagram also remain in Meta's systems and are subject to that platform's rules, deletion functions, retention periods and data transfers. See the Meta Privacy Policy for details.
Data from the current legacy version and historical data
Until the migration, the current production version may store samples of questions in statistics, as well as the IP address, Meta user identifiers and fragments of questions or answers in logs. In addition, the Polish widget stores the session identifier, chat history and widget settings in the browser's localStorage; these data remain until they are overwritten or the user clears the website data. The system may also send Telegram notifications containing the content of Messenger or Instagram messages and, for the feedback form, the submission content, page address and voluntarily provided email address. The project repository does not confirm a single uniform retention period for these legacy data. Copies of notifications may remain in Telegram in accordance with that service's settings and retention.
The new runtime will not append conversation content to those historical files or send conversations to Telegram, but it deliberately does not delete or overwrite them automatically. Before the new version is launched, VITA will inventory the actual production resources and copies in Telegram and then — in a controlled operation — delete or anonymise data for which there is no basis for continued retention, or document their scope, basis and retention period. The new version will remain blocked until this work is completed. You may request the deletion of data concerning you in accordance with section 15.
Separate feedback form on the website
The feedback button displayed on the website uses a separate form and is not part of the conversation with August. The 30-minute chat-context rules described above do not apply to it.
After the new version of the form is launched, the local register will store the category and content of the submission, an optional email address, the page address, date and time, a technical record identifier and a project tag. The new register does not store the IP address or browser information. The data are used to receive and handle feedback or reports concerning the website, protect the form against abuse and — if you voluntarily provide an email address — enable a reply.
The retention period for the new register is 90 UTC calendar days: we retain entries from the current day and the previous 89 UTC calendar days. Older entries are deleted automatically when another submission is stored and every 60 seconds while the service is running.
We send Telegram only a notification containing the record identifier, project tag and category. We do not send the feedback content, email address or page address.
The existing register is a historical register. It may contain data stored by the previous version of the form, including the content, an optional email address, page address, shortened IP address hash and browser information. Once the new version is launched, it will not be used for new entries. The new mechanism does not automatically migrate or modify it, and the new register's 90-day retention period does not apply to it. Reviewing and deleting historical data is a separate, controlled operation; you may request the deletion of data concerning you in accordance with section 15.
What not to enter and how to treat the answers
August does not make decisions that produce legal effects and does not enter into contracts on your behalf. A bot response does not itself confirm a booking, price, availability or payment. Only information confirmed by reception or the relevant booking system is binding.
Legal bases and your rights
If you ask about our offer or the possibility of making a booking, processing is based on taking steps at your request before entering into a contract (Article 6(1)(b) GDPR). For handling other enquiries, ensuring security, preventing misuse and maintaining anonymous statistics, processing is based on VITA's legitimate interests (Article 6(1)(f) GDPR).
You have the rights described in section 7. The procedure for submitting a request concerning August data is also described in section 15.
15. Data deletion — instructions (website / Facebook / Instagram)
Under the GDPR and the requirements of the Meta platforms (Facebook, Instagram), you have the right to request deletion of data that we collected in connection with your interaction with the “August” chatbot on the website, our company page on Facebook (VITA Augustów), our Instagram profile (@vitaaugustow), or August in Messenger and Instagram DM.
What data we process
- first name and surname, email address, telephone number — if you have made a booking (RoomAdmin system),
- the content of messages sent to us via Messenger or Instagram DM,
- comments and reactions to our posts on Facebook and Instagram,
- the Facebook/Instagram user identifier (Page-Scoped User ID),
- the temporary website chat session identifier and related technical data — provided that the applicable retention period has not already expired.
How to request data deletion
- Send an email to biuro@vita.augustow.pl with the subject „Data deletion request”.
- In your request, include your full name and the email address linked to the booking (if applicable), your Facebook/Instagram username, or the approximate date and time of the conversation on the website. Do not resend the conversation content or any sensitive data.
- Alternatively, call +48 661 549 377 (Ms Iwona).
- We will acknowledge receipt of your request within 3 working days.
- We will delete your data within 30 days of confirming your identity, in accordance with Article 17 of the GDPR. We will notify you by email when the process has been completed.
What will not be deleted
Data required by law (e.g. accounting documents — invoices, retained for 5 years in accordance with the Accounting Act) will remain in our system until the end of the mandatory retention period. It will be deleted automatically after that period.
A request made to VITA covers data under our control. Copies of messages retained by Meta under that platform's rules must be deleted using the Messenger or Instagram settings or the procedures provided by Meta.
Removing the app from your Facebook account
You can also disconnect our app from your Facebook account yourself: Settings and privacy → Settings → Apps and websites → find „VITA Augustów” → Remove.
Data controller: VITA Waldemar Podgrudny, ul. Rajgrodzka 140, 16-300 Augustów, NIP 8461052803.
Contact regarding the GDPR: biuro@vita.augustow.pl, +48 661 549 377.