Datenschutz-Bestimmungen

1. WHO ARE WE

We are Throdi Sp.z o.o. residing at Czorsztyńska 2 60-474 Poznan Poland with company registration number PL 9721302428.  We care about your privacy and every time we deal with your personal data we do so in accordance with the provisions of the general data protection regulation and the national law relating to the processing of personal data. We are required under data protection legislation to make the information contained in this privacy policy accessible to you. This privacy policy sets out which measures are taken to protect your privacy when using our services or products, and what rights you have in this respect. When processing your personal data we are in most cases the „data controller“. This means that we determine the purpose and means of the processing. By using our services and/or products, you agree to the collection and processing of some of your personal data in accordance with the purpose described in our privacy policy. You are invited to read this privacy policy carefully and familiarize yourself with its content. Pascal Hochedé is our Privacy Coordinator and you can reach them at pascal@throdi.app for any questions or to exercise your rights. Future amendments to this policy cannot be excluded. We therefore ask that you read the privacy policy from time to time.

2. PROCESSING OF YOUR PERSONAL DATA

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We try to collect as little personal information as possible in order to achieve our goals. We comply with data protection laws which require that the personal information we process about you must be:

  • Collected only for valid purpose(s) that we have clearly explained to you.
  • Used lawfully, fairly and in a transparent way which means in a way that is relevant to the purpose(s) we informed you about, limited only to those purpose(s) and in no way incompatible with those purpose(s).
  • Accurate and kept up to date, kept only as long as necessary for the purpose(s) we have told you about and handled securely.

We may request certain information from you in order to enable you to use or purchase our services or products. If have processes in place to obtain your personal information in a different way, we will state this in this privacy policy. If you have any questions do contact our privacy coordinator. More specifically we will collect any or all of the following data elements :

  • Birthday / Age
  • Claim specific information
  • Company address
  • Correspondence content
  • Customer name
  • Date & time
  • Date and duration of stay
  • Drivers license
  • Electronic identification data
  • Essential cookies
  • Home address
  • Hotel
  • ID card
  • Involved party name
  • Payment balance data
  • Personal email address
  • Personal phone number
  • Purchase history data
  • Room number
  • Survey answers
  • Table number
  • VAT number
  • Work email address
  • Work phone number

We rely on you to provide us with correct data. If the data changes, we invite you to let us know, so we can keep the data up to date. We process the data to allow us to deliver the services/products, and to continually improve the services/products available to you and adapt them to your needs. More specifically we perform the below processing:

  • Throdi app use

Description: Use of the Throdi app by hotel guests

Purpose: To ensure execution of contract with end user

Legal basis: Legitimate interests

Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action

Data is processed in the EU

  • Customer appointments

Description: Register customer appointments either on paper on a computer

Purpose: To manage availability and calendar

Legal basis: Contract

Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action

Data is processed in the EU

  • Customer invoicing & accounting

Description: Calculating the fee owed, sending out invoices and ensuring payment

Purpose: To ensure proper payment

Legal basis: Contract

Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action

Data is processed in the EU

  • Client intake and dossier handling

Description: Starting a client account and handling of the customer instruction

Purpose: To ensure execution of the service to the client

Legal basis: Contract

Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action

Data is processed in the EU

  • Corporate website

Description: Corporate website for consultation by client or prospective client

Purpose: To inform client or prospective client

Legal basis: Legitimate interests

Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action

Data is processed in the EU

  • Customer Support

Description: Receiving and answering customer questions, complaints etc.

Purpose: To solve problems and optimize the functioning of the company

Legal basis: Contract

Retention period: As from termination of contract, retention during the legal period and/or period relevant for legal action

Data is processed in the EU

In the above processing we are the data controller. Where you provided consent, you have the right to revoke it. You have the right to withdraw your consent at any time. In case you object to the processing of your data, please contact us so we can evaluate together if a contractual relation is possible and a continuation of the use of our services is possible. We also handle supplier data. When we collect, process and store supplier data, we want to make sure we only collect, process and store data we really need and are entitled to handle in this way. In dealing with our suppliers we typically collect, process and store the name, work email and work phone of the person(s) interacting with us. We also collect, process and store the VAT number of our suppliers. If we provide parking space or access to our business area to suppliers‘ vehicles, we might collect, process and store the license plate number and timing of the visit for purposes of organization and security. Our security measures are functionally and technically in line with industry best practices. We retain the information during the legal period and/or period relevant for legal action.

3. PROCESSING OF PERSONAL DATA ON YOUR BEHALF

The specific nature of our relationship makes it unlikely that we will process other people’s personal data on yout behalf. In the exceptional case that this nevertheless occurs, we are the processor and you are the controller. We will then carry out your instructions for the processing, possible subcontracting, the fate of the data at the end of the agreement and the possible transfer of data. We will therefore take the necessary security measures and assist you in fulfilling your obligations under the GDPR.

4. TRANSFER OF PERSONAL DATA

In order to provide certain services or products we might work with third parties such as IT partners, insurance partners, accounting partners, legal advisors… More specifically we reserve the right to transfer your personal data to our partners.

  • Facebook Ireland Ltd. because they act as a data processor for:
    • Social media – Facebook / Instagram (Customer name, Electronic localisation data, Date & time, )
  • Twitter International Company because they act as a data processor for:
    • Social media – Twitter (Electronic localisation data, Electronic identification data, Date & time, )
  • LinkedIn Ireland Unlimited Company because they act as a data processor for:
    • Sociale media – Linkedin (Electronic localisation data, Staff member name, Pictures / images, Date & time, )

If we receive personal data from a third party referring you to us, we assume this data is obtained directly from you or with your consent. If this is not the case, please advise us immediately. In case you object to the transfer of your data, please contact us so we can evaluate together if a contractual relation is possible and a continuation of the use of our services is possible. Please do note that we may be required by law to process certain data and, as the case may be, to transmit them to the relevant authorities. As this is a legal obligation you can not object this transfer.

5. SECURITY & CONFIDENTIALITY

We undertake to keep your personal data secure & confidential and have established security procedures to avoid any loss, abuse or alteration to this personal data in line with industry best practices.

6. WEBSITE & COOKIES

Navigation on our website may result in cookies being saved to your computer. They simplify the visit and improve your experience. When visiting our website you will be informed of the cookies being used and we will ask you for your consent. Furthermore, each time you visit our website, the webserver automatically processes your IP address and/or your domain name. We may publish links to websites owned and operated by third parties. If you click on such a link you will navigate to another website. Please make sure you read and understand the privacy policy of that website, as it may differ from our policy and is outside of our control. If you feel unsure or cannot agree with the policy, we suggest you leave that website.

7. SOCIAL MEDIA

If you use the social media functions such as eg “like” or “share” button that may be on our website, or if you visit our social media page, please know that your personal data will be processed by the social media platform. In this processing, the European regulator considers us and the social media platform both to be joint data controllers, which means that we jointly determine why and how your personal data is processed. You can find out how we process your personal data in this privacy statement. You can find information about the processing by the relevant social media platform in their privacy statement. We ask you to read the privacy statement of the social media platform carefully before visiting the social media items on our page or our page on the social media platform.

8. EXERCISING YOUR RIGHTS

In accordance with the general data protection regulation you have the right to:

  • Request access to your personal information (commonly known as a „data subject access request“). This enables you to receive a copy of the personal information we hold about you.
  • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal information. This enables you to ask us to remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to remove your personal information where you have exercised your right to object to processing (see below). Object to processing of your personal information where we are relying on a egitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
  • You also have the right to object where we are processing your personal. information for direct marketing purposes.
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Withdraw your prior consent to processing at any time.
  • The right to object to a decision based solely on automated processing, including profiling.
  • The right to receive your personal data in a structured, commonly used and machine-readable format and have transmit those data to another controller.

We sometimes need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it. You can exercises your rights by contacting our Privacy Coordinator Pascal Hochedé via privacy@throdi.app or at the below company address:

Throdi Sp.z o.o.

c/o Pascal Hochedé

Czorsztyńska 2 60-474 Poznan Poland

9. DATA PROTECTION AUTHORITY

You can direct any complaints and comments to the competent data protection authority at the below address:

Urzad Ochrony Danych Osobowich – UODO

ul. Stawki 2, 00-193 Warszawa https://uodo.gov.pl/

This privacy policy was generated with the help of HTTPS://GDPRWISE.EU