PRIVACY POLICY OF PRZYJEDNYMSTOLE.PL
1. Data controller
The controller of the personal data of users of PrzyJednymStole.pl is Adam Cygal Consulting Group.
For personal-data matters, contact kontakt@przyjednymstole.pl. If no Data Protection Officer has been appointed, contact the Controller directly.
2. Data we process
The scope depends on how the Service is used.
A. Account data
- first name or displayed name, email address, cryptographically protected password, email-verification information, Account identifier and Account-creation date.
The Service does not store passwords in plain text.
B. Profile data
- age, town or city, gender, profile photographs, profile description, interests, meeting goals, budget or venue preferences, preferences regarding people the User wants to meet and other information voluntarily provided in the Profile.
C. Planned-outing data
- chosen venue and city, date, time or time range, type of outing, preferred age and participant preferences, meeting goal, interests used for matching and participation in a Themed Table or group.
D. Activity data
- liked and followed people; followed or favourite venues; outing invitations and their status; matches; participation in groups and Themed Tables; votes on venue or date; visits to venue pages by logged-in Users; interest in a specific place, date and time; and information used for Service activity statistics.
E. Messages
- message content, sender and recipient identifiers, sending date and time, read status, and the identifier of the match or group to which a message relates.
F. Technical data
- IP address, connection date and time, browser and device information, server logs, session and login information, anti-abuse data, cookies and browser local-storage information.
3. Google sign-in
Where a User selects Google sign-in, the Service uses Google OAuth/OpenID Connect. Depending on the granted permission, the Service may receive a Google account identifier, email address, name or profile name and profile photo. The sign-in scope covers basic profile data and email. Google processes data independently under Google’s own rules. Google sign-in is voluntary; where standard email registration is available, it may be used instead.
4. Purposes and legal bases
4.1. Account and services
We process data to create and operate Accounts and Profiles, provide Service features, manage outing declarations, matches, invitations, messaging, Themed Tables and Account settings. Legal basis: Article 6(1)(b) GDPR, performance of the electronic-services contract.
4.2. Personalisation, recommendations and matching
Preferences, activity and planned outings may be analysed to determine matching scores or ordering, suggest venues and Themed Tables, and personalise results. The legal basis is Article 6(1)(b) GDPR where this analysis is necessary for a feature requested by the User, Article 6(1)(f) GDPR for the Controller’s legitimate interest in improving quality and usefulness, or consent where required by law.
4.3. Security and abuse prevention
Data may be used to secure Accounts, limit spam and automated registrations, detect abuse, protect users, handle reports, and establish, pursue or defend claims. Legal basis: Article 6(1)(f) GDPR.
4.4. Legal obligations
Data may be processed where needed to meet a legal obligation; legal basis: Article 6(1)(c) GDPR.
4.5. Email notifications
Service emails, including email confirmation, security information, invitations and significant Account events, may be sent to perform the contract. Extra messages, such as summaries, followed-person activity and marketing, are sent only where there is a proper legal basis and, where required, the User’s consent.
5. Special categories of data
The Service does not require Users to disclose health data, religious beliefs, political opinions, racial or ethnic origin, sex life or sexual orientation. Users should not place such information in their Profile description or messages unless needed for use of the Service. Matching preferences can indirectly permit inferences about private life; the Controller does not use them to determine or assign sexual orientation, health, beliefs or other special-category data. If a future feature requires processing Article 9 GDPR data, the Controller will provide a suitable legal basis, including explicit consent where required.
6. Profiling and automated matching
The Service uses automated mechanisms to order results and match users. The algorithm may compare city, date and time, age and preferred age range, gender or participant preferences, meeting goal, outing type, budget, interests, preferred venue character, common favourite or followed venues and previous venue activity. It may set an indicative score or ordering. This is only a recommendation: it does not decide whether users may meet and produces no legal or similarly significant effects under Article 22 GDPR. Users decide whether to invite, accept contact and meet.
7. Data visible to other users
Depending on the feature, other users may see a profile name, age, city, photo, description, interests, planned outing, venue, date and time range, meeting goal or selected preferences, participation in Themed Tables and a matching result where displayed. Email address and password are not public. Private messages are intended for participants in that conversation, subject to access necessary for security, handling a report or a legal obligation.
8. Recipients
Data may be entrusted to or disclosed to entities supporting the Service: hosting and server-infrastructure providers, email providers, IT and security providers, the content-management-system provider and necessary components, Google for Google sign-in and used Google services, lawfully implemented analytics or statistics providers, advisers or entities helping establish, pursue or defend claims, and public authorities where disclosure is legally required.
The Controller does not sell users’ personal data. Restaurant owners using the business panel do not automatically receive Users’ personal data merely because they promote a venue. Business statistics should be aggregated unless a User consciously uses a feature requiring disclosure of specific data.
9. Venue data and Google services
The Service may use Google Places or other Google services to obtain public venue information such as name, address, rating, review count, photos, opening hours and place identifier. This primarily concerns businesses and places, not Users’ profile data.
10. Transfers outside the EEA
Some technology providers, especially Google, may process data outside the European Economic Area. Where such a transfer occurs, the Controller uses GDPR safeguards appropriate to the provider, including an adequacy decision, standard contractual clauses or other legally permitted safeguards.
11. Retention periods
Data are not retained longer than necessary for their purpose. In principle, Account and Profile data are retained while an Account exists; Account-activity data while the Service is used and as needed for history, matches and security; messages while the conversation or Account exists and afterwards as needed for abuse prevention and claims; report data for handling the matter and securing claims; claims data until relevant limitation periods expire; accounting or tax data for statutory periods; consent-based data until consent is withdrawn or the purpose ends unless another basis applies; and security logs for a period justified by Service security, then deleted or anonymised. The Controller reviews retention rules periodically.
12. User rights
Subject to GDPR conditions, Users may access their data, obtain a copy, rectify or erase data, restrict processing, receive data portability, object to processing based on legitimate interests, withdraw consent, obtain information about profiling and lodge a complaint with the President of the Polish Personal Data Protection Office. Withdrawal does not affect the lawfulness of prior processing. To exercise rights, contact kontakt@przyjednymstole.pl.
13. Complaint to the supervisory authority
If a User considers data processing unlawful, they may lodge a complaint with the President of the Polish Personal Data Protection Office. Current contact information is available at https://uodo.gov.pl.
14. Cookies and browser storage
The Service may use cookies and browser local storage. Necessary cookies may maintain logged-in sessions, security, settings, WordPress functions and language choice or similar preferences. Non-essential mechanisms, particularly analytics or advertising cookies, may be used only after any consent required by law. Users may change cookie choices in Service settings or their browser. Refusing non-essential cookies should not prevent use of basic features.
15. Security
The Controller uses appropriate technical and organisational measures to protect data against unauthorised access, loss, destruction, alteration and disclosure. The Service uses access-control, authentication and safeguards appropriate for its infrastructure. Users should also protect their password and not share their Account.
16. Other people’s data
Users should not publish third-party personal data without a proper legal basis, particularly other people’s photographs, telephone numbers, addresses, contact details or private correspondence.
17. Changes to this Policy
This Privacy Policy may change because of changes to Service features, data-processing methods, new providers or legal requirements. The current version is always available in the Service. If a change materially affects processing of Account holders’ data, the Controller may additionally notify them through the Service or by email.
