SeaSide Sopot privacy policy
This information covers the website, contact, reservations and stays at SeaSide Sopot. Updated on 20 September 2026.
1. Controller and contact
The controller is PH OMEGA Dagmara Szamborska, Polish tax number (NIP) 5842032374, the operator of SeaSide Sopot. For personal data enquiries, email hotel@seasidesopot.com. Property correspondence address: Plac Zdrojowy 3, 81-726 Sopot, Poland.
2. Data we process
When you contact us, we process your first name, email, enquiry topic and message, plus the following if supplied: an existing booking number, telephone number, stay dates, the number of adults and children, and children’s ages to help select a sleeping arrangement. For bookings and stays, we also process details required by booking and check-in forms, stay and payment details, and invoice information. Do not include card numbers, access codes, identity document scans or health information. The rehabilitation website is a separate service.
3. Purposes and legal bases
We process data to prepare an offer at your request, enter into a contract, book and provide your stay under Article 6(1)(b) GDPR. Accounting and tax records are processed to comply with legal obligations under Article 6(1)(c). General correspondence, prevention of abuse, establishing or defending claims, and the safety of people and property rely on our legitimate interests under Article 6(1)(f). Where specific processing requires consent, we request it separately under Article 6(1)(a).
4. Contact form
Form details are used to answer your enquiry. Your first name, email, topic and message are required; other fields are optional. The form sends your enquiry to the property through Google Workspace and sends a receipt with a copy of your message to the address provided. A contact receipt is not a booking confirmation.
5. Reservations, vouchers and payments
RoomAdmin provides the reservation and voucher purchase forms. The reservation form loads after you select dates and click “Check availability”; the voucher purchase form loads when you click “Enable form”. These actions open the service needed to place your order. Analytics and review/map consent are not required. Your browser then connects to the provider and shares technical connection data. Information entered in the form is handled in the reservation system. Payments are handled by the payment provider identified during checkout; the Property’s Terms identify PayPro SA. We do not collect payment card details through the contact form. Read the information displayed during booking and payment before completing a transaction. A separate personalised voucher generator processes the giver and recipient names or signatures, optional dedication, code, amount, expiry date, chosen design and email address. For the custom-image design, we also process the photo or artwork you upload. It creates a PDF at your request and sends it through Google Workspace to the address supplied. It does not purchase a voucher or change its value or expiry date.
5a. Mandatory online check-in
At SeaSide Sopot, check-in takes place entirely remotely through the RoomAdmin system.
Online check-in replaces traditional on-site check-in and is a mandatory part of providing your stay.
It allows us to prepare for your arrival and provide independent access to the property and your room.
The data controller is the entity identified at the beginning of this privacy policy.
Purposes and legal bases for processing
We process the data needed for check-in to link the Guest to the reservation, prepare and manage the stay, provide access details for the property and room, and communicate about the stay. The legal basis is the performance of the accommodation contract under Article 6(1)(b) GDPR.
Where necessary to establish, pursue or settle claims, or defend against claims, processing is based on our legitimate interest in protecting rights connected with the provision of the stay, under Article 6(1)(f) GDPR. Where retaining particular data is required by law, processing is based on Article 6(1)(c) GDPR.
Providing your data
Providing the data required for check-in is a contractual requirement connected with the remote handling of your stay. Failure to complete check-in may prevent us from making your room available and providing your stay. Required fields are marked in the form. Not providing optional data does not affect your ability to check in.
If you have difficulty using the form, contact us before arrival at hotel@seasidesopot.com or +48 513 122 041.
6. Reviews and external links
Elfsight provides reviews and Google Maps provides the embedded map. Both are off by default. They load after you save “External reviews and map” consent or explicitly load an individual service next to its description. Providers receive technical connection data, including IP address and browser details, and may use their own cookies. Details: https://elfsight.com/privacy-policy/ and https://policies.google.com/privacy. Ordinary links to Google Maps, social media and other websites lead to services with their own privacy rules. The illustrated neighbourhood map does not connect to Google.
7. Cookies and settings
Optional analytics, reviews and the map start switched off. Google Analytics loads only after you save analytics consent. It measures visits, selected interactions, submitted enquiries and booking steps. A submitted booking form is recorded as booking_submitted, not as a confirmed purchase or payment. We send its technical identifier, value and currency. We do not send contact details, message content or voucher personalisation. The provider is Google Ireland Limited; _ga and _ga_* cookies have a configured lifetime of 180 days, renewed when you use the site. More: https://policies.google.com/privacy. We do not load advertising pixels or personalised advertising. Images and fonts come from our server. Necessary session cookies seaside_contact and seaside_voucher protect forms and access to your own PDF. Optional choices are saved for 180 days in localStorage under seaside_consent. Withdraw them through “Privacy settings” in the footer. Withdrawal reloads the page, stops further optional connections and removes analytics cookies accessible to our domain. It does not erase data already shared with providers or their cookies on other domains; remove those in your browser settings. A change to tools requiring consent prompts a new choice. Language, text size, dismissed notices and chosen dates may be saved in your browser to support those features.
8. Recipients
To the extent necessary for these purposes, data may be received by hosting and email providers, IT and reservation services, payment operators, accountants, legal advisers and parties cooperating in service delivery. Authorised staff have access appropriate to their duties. Public authorities receive data where there is a legal basis. Depending on the service, providers may act as processors on our behalf or as independent controllers.
9. Processing outside the EEA
External services may involve processing outside the European Economic Area. The scope depends on the module you activate and its provider. Where we transfer data outside the EEA, the conditions of Chapter V GDPR must be met, for example an adequacy decision or standard contractual clauses with the required safeguards. You can request information about recipients and applicable safeguards at hotel@seasidesopot.com.
10. Retention
Reservation data is kept during performance of the contract and afterwards for the periods required for accounting and legal claims. Tax documents are retained for the period required by tax law; records concerning tax liabilities are generally kept until the relevant limitation period expires. Correspondence is retained while we handle the matter and, where it provides evidence of a contract, complaint or claim, for the relevant limitation period. It is not retained indefinitely. Contact form tokens are valid for one hour. Abuse protection counts attempts over one hour and stores a hash of the IP address; files older than one day are removed on the next submission attempt. Your personalised voucher download link is available for one hour in the browser where it was created. Your uploaded image is included in the PDF and follows the same retention rules. Temporary PDFs and delivery status records are removed after one hour on the next use of the generator. Abuse protection stores one-way hashes of the IP address and email address with attempt counts; files older than a day are removed on the next use. Sent emails follow the correspondence retention rules above. Backups and hosting logs follow the service provider’s retention schedule.
11. CCTV at the Property
Common areas are monitored for the safety of people and property. Rooms and bathrooms are not monitored. The controller is PH OMEGA Dagmara Szamborska. Recordings are kept for up to 30 days unless longer retention is required by law or as evidence for claims.
12. Your rights
Subject to the GDPR, you may request access and a copy, rectification, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Not every right applies in every situation; for example, tax obligations may require continued retention of a document. Send requests to hotel@seasidesopot.com. We may ask for information needed to verify your identity.
13. Complaints, optional provision and automated decisions
You may complain to the President of the Polish Personal Data Protection Office (UODO): https://uodo.gov.pl/, or another competent supervisory authority. Providing data through the contact form is voluntary, but fields marked as required are needed for us to reply. Data necessary to book and provide your stay is a contractual requirement. Mandatory online check-in is described in section 5a. We do not make solely automated decisions with legal effects through this website and do not use marketing profiling.
14. Policy changes
This policy should be updated when services, providers or processing practices change. It describes the current website configuration. Adding analytics or marketing requires separate updates to the information and appropriate consent settings.

