SeaSide Sopot privacy policy
This information covers the website, contact, reservations and stays at SeaSide Sopot. Version prepared on 9 September 2026.
1. Controller and contact
The controller is PH OMEGA Dagmara Szamborska, Polish tax number (NIP) 5842032374, the operator of SeaSide Sopot. For personal data enquiries, email hotel@seasidesopot.com. Property correspondence address: Plac Zdrojowy 3, 81-726 Sopot, Poland.
2. Data we process
When you contact us, we process your name, email address and message, your existing booking number if supplied, plus your telephone number and planned arrival and departure dates if you provide them. For bookings and stays, this includes details required in the booking and check-in forms, stay details, payments and invoice information. Do not include payment card numbers, identity document scans or health information in the contact form. The rehabilitation website is a separate service.
3. Purposes and legal bases
We process data to prepare an offer at your request, enter into a contract, book and provide your stay under Article 6(1)(b) GDPR. Accounting and tax records are processed to comply with legal obligations under Article 6(1)(c). General correspondence, prevention of abuse, establishing or defending claims, and the safety of people and property rely on our legitimate interests under Article 6(1)(f). Where specific processing requires consent, we request it separately under Article 6(1)(a).
4. Contact form
Form details are used to answer your enquiry. Your name, email and message are required; other fields are optional. The form sends an email to the Property and a receipt to the address supplied. A contact receipt is not a booking confirmation.
5. Reservations, vouchers and payments
RoomAdmin provides the reservation and voucher purchase forms. They load automatically on pages where they are embedded unless you disable external services in privacy settings. Your browser then connects to the provider and shares technical connection data. Information entered in the form is handled in the reservation system. Payments are handled by the payment provider identified during checkout; the Property’s Terms identify PayPro SA. We do not collect payment card details through the contact form. Read the information displayed during booking and payment before completing a transaction. A separate personalised voucher generator processes the giver and recipient names or signatures, optional dedication, code, amount, expiry date, chosen design and email address. It creates a PDF at your request and sends it through Google Workspace to the address supplied. It does not purchase a voucher or change its value or expiry date.
6. Reviews and external links
The Elfsight reviews service loads automatically in the reviews section unless you disable external services in privacy settings. The provider receives technical details including IP address, browser type and operating system; the widget may use the elfsight_viewed_recently cookie to count views. The provider’s policy states that technical data is retained for 7 days for operation and security. Further information: https://elfsight.com/privacy-policy/. Links to Google Maps, social media and other websites lead to services with their own privacy rules.
7. Cookies and settings
The basic website does not load analytics or advertising pixels. Images and fonts are served from the same server as the website. Using the contact form creates the necessary seaside_contact session cookie to protect submissions. The PDF generator uses the necessary seaside_voucher session cookie to protect the form and access to your download. External reviews, reservations, vouchers and the map load automatically. The map uses Google Maps and sends connection data, including your IP address, to its provider. Privacy settings in the footer let you deactivate them by reloading the page. This does not erase data already shared with providers or their cookies; you can remove those cookies in your browser settings. Your choice is saved in this browser’s localStorage under seaside_external. Analytics and marketing permissions are separate. Basic analytics and marketing are preselected in settings. Additional tools do not run before you save a choice. Your choice is saved for 180 days in localStorage under seaside_consent. You can withdraw permission in the footer settings. No analytics or advertising tools are currently configured. Adding such tools will require a new choice. These permissions do not change the automatic loading of embedded services described above; those services can be disabled separately. Clearing site data also removes these settings.
8. Recipients
To the extent necessary for these purposes, data may be received by hosting and email providers, IT and reservation services, payment operators, accountants, legal advisers and parties cooperating in service delivery. Authorised staff have access appropriate to their duties. Public authorities receive data where there is a legal basis. Depending on the service, providers may act as processors on our behalf or as independent controllers.
9. Processing outside the EEA
External services may involve processing outside the European Economic Area. The scope depends on the module you activate and its provider. Where we transfer data outside the EEA, the conditions of Chapter V GDPR must be met, for example an adequacy decision or standard contractual clauses with the required safeguards. You can request information about recipients and applicable safeguards at hotel@seasidesopot.com.
10. Retention
Reservation data is kept during performance of the contract and afterwards for the periods required for accounting and legal claims. Tax documents are retained for the period required by tax law; records concerning tax liabilities are generally kept until the relevant limitation period expires. Correspondence is retained while we handle the matter and, where it provides evidence of a contract, complaint or claim, for the relevant limitation period. It is not retained indefinitely. Contact form tokens are valid for one hour. Abuse protection counts attempts over one hour and stores a hash of the IP address; files older than one day are removed on the next submission attempt. Your personalised voucher download link is available for one hour in the browser where it was created. Temporary PDFs and delivery status records are removed after one hour on the next use of the generator. Abuse protection stores one-way hashes of the IP address and email address with attempt counts; files older than a day are removed on the next use. Sent emails follow the correspondence retention rules above. Backups and hosting logs follow the service provider’s retention schedule.
11. CCTV at the Property
Common areas are monitored for the safety of people and property. Rooms and bathrooms are not monitored. The controller is PH OMEGA Dagmara Szamborska. Recordings are kept for up to 30 days unless longer retention is required by law or as evidence for claims.
12. Your rights
Subject to the GDPR, you may request access and a copy, rectification, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Not every right applies in every situation; for example, tax obligations may require continued retention of a document. Send requests to hotel@seasidesopot.com. We may ask for information needed to verify your identity.
13. Complaints, optional provision and automated decisions
You may complain to the President of the Polish Personal Data Protection Office (UODO): https://uodo.gov.pl/, or another competent supervisory authority. Providing data is voluntary, but required fields are needed to respond, make a reservation or provide the service. We do not make solely automated decisions with legal effects through this website and do not use marketing profiling.
14. Policy changes
This policy should be updated when services, providers or processing practices change. It describes the current website configuration. Adding analytics or marketing requires separate updates to the information and appropriate consent settings.

