Privacy Policy
Mergen Bike & Ski Resort · Black Apart · GDPR
This is a translation for guests’ convenience. In case of any discrepancy, the Polish version is legally binding.
This document describes how Black Apart (the operator of Mergen Bike & Ski Resort) collects, processes and protects your personal data, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
This document contains a skeleton privacy policy. The final content requires verification and legal consultation.
Personal data controller
The controller of your personal data is: Black Apart
- Full name: Black Apart
- Registered office address: ul. Cisowa 5, 34-441 Niedzica Zamek
- NIP (Polish Tax ID): as per the operator's registration data
- KRS / CEIDG (Polish business register): as per the operator's registration data
- Contact email: blackapart@interia.pl
- Phone: +48 505 923 455
If the controller has appointed a Data Protection Officer (DPO), their contact details will be provided here.
What personal data do we collect?
We collect personal data only to the extent necessary to provide our services. This may include:
- Booking form and enquiry data: first and last name, email address, phone number, stay dates, number of guests, message content.
- Guest registration data (required by law): first and last name, ID document series and number - collected at check-in under the Population Register Act.
- Technical data (automatic): IP address, browser type, operating system, date and time of the visit - details in the Cookie Policy.
- Correspondence data: the content of emails, SMS messages, or messages sent via booking platforms.
We collect booking form data when you choose dates and cabins on our cabins page.
Purposes and legal bases for processing
We process your data for the following purposes — to prepare your stay in our cozy cabins with access to amenities and attractions nearby.
| Purpose | Legal basis (GDPR) |
|---|---|
| Processing of bookings and the rental agreement | Art. 6(1)(b) GDPR - performance of a contract |
| Statutory guest registration obligation (Population Register Act) | Art. 6(1)(c) GDPR - legal obligation |
| Contact before and after the stay, handling enquiries | Art. 6(1)(b) or (f) GDPR - legitimate interest |
| Direct marketing and newsletter (if applicable) | Art. 6(1)(a) GDPR - consent |
| Defence against claims and property security | Art. 6(1)(f) GDPR - legitimate interest |
| Tax and accounting settlements | Art. 6(1)(c) GDPR - legal obligation |
Bookings and stay details (including the cabin amenities) can be found in our cabin calendar.
Data retention period
We store personal data for as long as necessary to fulfil the purpose for which it was collected, and afterwards for the period required by law:
- Booking and contract data - for 5 years from the end of the year in which the service was provided (or longer if required by tax law).
- Guest registration data - for the period specified in the Population Register regulations.
- Contact form and booking enquiry data (name, email, phone, message) — for up to 12 months from receipt of the enquiry (technical server retention), unless longer retention is necessary to defend against claims or is required by law; on request, we delete it earlier (right to erasure — contact the controller).
- Other email/phone correspondence — for the period required by law or until consent is withdrawn / an objection is raised.
- Marketing data - until consent is withdrawn or an objection is raised.
Recipients of personal data
Your data may only be shared with entities that are authorised or necessary for the provision of the service:
- The booking system provider (Hotres - online booking and payment system).
- Hosting and IT systems providers (under a data processing agreement).
- The accounting office or tax advisor - to the extent required by law.
- Public authorities and law enforcement bodies - solely on the basis of applicable law.
We do not sell or share your data with third parties for marketing purposes without your explicit consent.
For visit analytics we use Umami, self-hosted on the operator's own VPS server - it works without cookies, and the data collected does not leave the European Economic Area (EEA).
Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of accessYou have the right to find out whether we process your data and, if so, to access it and receive a copy.
- Right to rectificationYou may request the correction of outdated or inaccurate personal data.
- Right to erasure ("right to be forgotten")You have the right to request the deletion of your data if there is no legal basis for its further processing.
- Right to restriction of processingYou may request the suspension of data processing in the specific situations provided for by the GDPR.
- Right to data portabilityYou have the right to receive your data in a structured, commonly used, machine-readable format.
- Right to objectYou may object to the processing of your data based on the controller's legitimate interest.
- Right to lodge a complaint with a supervisory authorityIf you believe we are processing your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (UODO).
To exercise your rights, contact the controller at the following email address: blackapart@interia.pl or in writing to the registered office address.
You have the right to withdraw your consent to data processing at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Data security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or disclosure, including:
- Encryption of data transmission (HTTPS / TLS).
- Access control to IT systems.
- Regular backups.
- Data processing agreements with subcontractors.
Detailed security measures are described in the controller's internal documentation. [CONTENT TO BE COMPLETED / SUBJECT TO LEGAL CONSULTATION]
Changes to the Privacy Policy
The controller reserves the right to update this policy in the event of changes to the law or to the way data is processed.
The current version of this document is always available at: https://mergen-resort.pl/en/polityka-prywatnosci
Last updated:
We base this policy on the day-to-day practice of hosting guests at a resort run by Black Apart — we know the real processes of booking, check-in and guest service, which is why these provisions are concrete and useful.
Contact for data protection matters
For all matters relating to the processing of personal data, you can contact the controller:
- Email: blackapart@interia.pl
- Phone: +48 505 923 455
- Correspondence address: ul. Cisowa 5, 34-441 Niedzica Zamek
You also have the right to lodge a complaint with a supervisory authority - in Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, website: uodo.gov.pl.