PRIVACY POLICY AND COOKIES POLICY OF TRAVELATO.PL
TABLE OF CONTENTS:
- Definitions
- Information about the Administrator
- Contact Details of the Data Protection Officer
- Scope and Categories of Processed Personal Data
- Purposes and Legal Basis for Data Processing
- Rules for Sharing and Transferring Data
- Rights of the Data Subjects
- Cookies and Operational Data
- Joint Controllership and External Links
- Final Provisions
I. DEFINITIONS
We want the content of this Policy to be fully understandable and precise for you, allowing for the correct interpretation of our actions. Therefore, we present a dictionary of terms used in this document:
- Service – the internet platform available at Travelato.pl, constituting an advanced technological tool (aggregator) used for searching, comparing, and initiating bookings of tourist offers.
- User – any natural person using the functionalities of the Service, in particular a person searching for information about tourist offers or sending a booking inquiry.
- Administrator (Data Controller - DC) – the entity deciding on the purposes and methods of processing personal data, which within the Travelato.pl Service.
- Platform Owner – the entity providing technical infrastructure and the Travelato.pl domain for the purpose of conducting business by the Administrator.
- Organizer (Tour Operator) – a travel agency (e.g., Itaka, Rainbow, Coral Travel, etc.) whose offers are presented in the Service and which is the direct provider of tourist services covered by the booking.
- Booking Inquiry – a form filled out by the User in the Service, constituting an expression of interest in purchasing a specific tourist offer and initiating the service process by the Administrator.
- Personal Data – any information regarding an identified or identifiable natural person, processed for the purposes described in this Policy (e.g., name, surname, phone number, e-mail address).
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- DPO or Inspector – means the Data Protection Officer appointed by the Administrator.
II. INFORMATION ABOUT THE ADMINISTRATOR
We inform you that the Travelato.pl service is a technological platform. Based on concluded operational agreements, the entities responsible for user service and the exclusive Data Controllers (hereinafter: "Administrator") of data collected through the service are the website partners processing tour bookings and tour operators.
The Administrator processes your personal data in accordance with the GDPR. Fulfilling the information obligation specified in Articles 13 and 14 of the GDPR, we present the detailed rules for data processing.
III. CONTACT DETAILS OF THE DATA PROTECTION OFFICER
In matters related to the processing of personal data and the exercise of rights granted to you under the GDPR, you may contact the Administrator or the appointed Inspector:
- Via e-mail: rodo@travelato.pl
- In writing to the registered office address of the Administrator indicated in point II above.
IV. SCOPE AND CATEGORIES OF PROCESSED PERSONAL DATA
Within the operation of the Travelato.pl Service, the Administrator collects and processes personal data to the extent necessary to provide search and booking services for tourist offers. The scope of processed data includes:
- Identification data (Name and Surname) – processed for contact personalization, handling booking inquiries, and correctly assigning offers to a specific User. This data may be transmitted via forms, e-mail, or telephone conversation.
- Contact data (Phone number, e-mail address) – crucial for the customer service process in the aggregator model. Used to send availability confirmations, responses to technical queries, and (subject to separate consent) to send marketing information.
- Address data (Residential / correspondence address) – necessary to complete formalities related to concluding an agreement with the chosen Organizer, including issuing travel documents or invoices.
- Technical data (Device IP address) – information resulting from general principles of internet connections, such as IP address and other information contained in system logs. Used for technical, security, and statistical purposes (e.g., determining the connection region to optimize departure airports).
- Travel preferences – data concerning preferred destinations, dates, and service standards, allowing the presentation of the most relevant offers from various Organizers.
- Other voluntarily provided data – any information (e.g., special requirements, dietary restrictions) provided by you via e-mail, forms, or telephone contact.
V. PURPOSES AND LEGAL BASIS FOR DATA PROCESSING
The Administrator processes Users' personal data for the following purposes:
- a) Handling booking processes and providing services (Article 6(1)(b) of the GDPR): Processing necessary to take action at the User's request prior to concluding an agreement (initiating bookings). Retention period: until the full execution of the agreement or the completion of the inquiry processing.
- b) Maintaining an individual user account (Article 6(1)(b) of the GDPR): If login functionality is provided, to ensure access to search history and saved offers. Retention period: until the User deletes the account.
- c) Fulfillment of legal, tax, and accounting obligations (Article 6(1)(c) of the GDPR): Maintaining documentation, issuing invoices, and keeping accounting records. Retention period: according to statutory deadlines (generally 5 years from the end of the calendar year).
- d) Current communication and user support (Article 6(1)(f) of the GDPR – legitimate interest): Providing answers to questions regarding the platform's operation and support in selecting an offer. Retention period: until communication is concluded.
- e) Securing interests and pursuing claims (Article 6(1)(f) of the GDPR – legitimate interest): Protection against claims and pursuing debts. Retention period: until the limitation period for claims expires (generally 3 years, in some cases up to 6 years).
- f) Analytics and platform optimization (Article 6(1)(f) of the GDPR – legitimate interest): Traffic monitoring and behavior analysis to improve search algorithms. Retention period: until the usefulness of the data for analytical purposes expires.
VI. RULES FOR SHARING AND TRANSFERRING DATA
- Data source: Data comes directly from you. Providing data is voluntary, but necessary to use the Service's functionality (e.g., sending an inquiry).
- Transfer to third countries: Data is processed within the EEA. Within the tools of Google Ireland Ltd. and Meta Platforms Ireland Ltd., data may be processed on Irish servers, however, providers may be obliged to disclose it outside the EEA based on legal provisions.
- Sharing: We do not share data with third parties without express consent, except for:
- Public law entities (e.g., tax authorities, law enforcement).
- Tour Organizers (Tour Operators) to execute the chosen booking.
- Entrustment (Article 28 of the GDPR): We entrust data to entities acting on our behalf: hosting providers, CRM systems, IT services, and partners supporting customer service. The Administrator enters into appropriate entrustment agreements with them. Without entrusting this data, the execution of services within the Service would be impossible.
- Profiling: Data is not subject to profiling resulting in automated legal decisions. We only analyze interests to better sort search results.
VII. RIGHTS OF THE DATA SUBJECTS
According to the GDPR provisions, every person has the right to:
- Access data (Art. 15), correct and rectify (Art. 16).
- Be informed about processing (Art. 12).
- Delete data ("right to be forgotten" – Art. 17).
- Restrict processing (Art. 18) and data portability (Art. 20).
- Object to processing (Art. 21).
- Withdraw consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal).
- Lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warszawa, Poland).
To exercise your rights, please contact us at: rodo@travelato.pl. Every case of a security breach is documented, and in case of risk, the data subjects are informed.
VIII. COOKIES AND OPERATIONAL DATA
- Mechanism: The Service uses Cookies saved on the User's device. These solutions are safe for your devices and do not allow for downloading confidential data or malicious software.
- Purposes: Technical optimization, remembering settings (language, filters), traffic analytics (Google Analytics), and marketing activities (Meta/Google remarketing).
- Cookies types:
- Session: Deleted after closing the browser.
- Persistent: Remain until deleted or their parameters expire.
- First-party: Generated directly by Travelato.pl.
- Third-party: Information from partners' servers (Google, Meta).
- Classification: Necessary (technical), Analytical (traffic study), Functional (remembering preferences), Marketing (ad adjustment), Social (integration with profiles).
- Management: The User can independently change settings in the browser (Chrome, Firefox, Edge) or use the consent management mechanism available in the Service. Restricting cookies may affect the Service's functionality. Below are links to instructions for deleting cookies in popular browsers:
- Google Chrome
- Mozilla Firefox
- Microsoft Edge
- Opera
- Safari
IX. JOINT CONTROLLERSHIP AND EXTERNAL LINKS
- In the case of hyperlinks to external websites or social media services, a relationship of joint controllership exists between the Administrator of this Service and the Administrator of the external site.
- Joint controllership is limited exclusively to data within the scope necessary for operations related to the functioning of a given button or plugin. The Administrator is not responsible for policies regarding further processing of personal data by other entities and organizations or social media service providers.
- Our Joint Controllers within this Service are:
- Meta Platforms Ireland Ltd. (Facebook, Instagram) located at: 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
- Google Ireland Ltd. (YouTube, Google Maps, Google Analytics) located at: Gordon House, Barrow Street, Dublin 4, D04 V4X7, Ireland.
- To obtain detailed information about privacy principles applied by our Joint Controllers, we recommend directly reviewing the privacy policies published on their websites.
X. FINAL PROVISIONS
- The Administrator reserves the right to make changes to this Policy resulting from technological development or changes in the law.
- Changes are published by making a new version of the document available in the Service.
- In matters not regulated, the provisions of the Civil Code and the GDPR apply.
- The Policy comes into force on: 01.06.2026