Dwór Hubertus · RODO / GDPR

Privacy policy

Privacy policy for the Dwór Hubertus website, Event Studio and the AI concierge.

Last updated: 2026-07-19
01

Controller

The controller is KAN JAN 2 CIVIL LAW PARTNERSHIP — URSZULA KANDORA, JAN KANDORA, SONIA KANDORA-KACPRZAK, WIRGINIA KANDORA-RAJTAR, JESSICA STOKŁOSA, ul. Inwalidów Wojennych 72, 41-940 Piekary Śląskie, Poland, tax ID (NIP) 4980190039, BDO 000438490 (“Controller”).

Privacy contact: info@dworhubertus.pl, +48 32 767 85 55, or the postal address above.

02

Scope

This policy covers the main Dwór Hubertus website, Event Studio, correspondence initiated through an email link and the digital concierge. Table reservations and orders are handled by the external hubertusonline.pl service, which provides its own privacy information before collecting data.

03

Data we process

  • Technical data: IP address, request date and time, requested URL, response code, browser and operating-system type, and diagnostics.
  • Correspondence: contact details and message content voluntarily provided by email or phone.
  • Event Studio: event type, estimated guest count and suggested room. The configurator opens a draft in the user’s email application; the website does not send or store it.
  • Concierge: the question, up to six recent conversation excerpts, language and connection data. We do not ask for a name, email, phone number, payment details or special-category data.
04

Purposes and legal bases

PurposeLegal basis
Website delivery, security, diagnostics and abuse preventionGDPR Art. 6(1)(f): legitimate interest in operating a secure service
Answering an enquiry and preparing an offer or reservationArt. 6(1)(b): steps before entering a contract; otherwise Art. 6(1)(f)
Providing information through the AI conciergeArt. 6(1)(f): efficient assistance; also Art. 6(1)(b) where the question concerns a contract
Compliance with legal obligationsArt. 6(1)(c)
Establishing, pursuing or defending claimsArt. 6(1)(f)
Any future marketing or optional analyticsPrior consent only: Art. 6(1)(a) and Polish Electronic Communications Law Art. 399

The website currently uses no analytics or advertising cookies and performs no advertising profiling.

05

AI concierge

The user is clearly told that they are interacting with an AI system. The concierge only retrieves information and suggests a contact route. It cannot see the calendar, confirm availability, conclude contracts or make decisions with legal effect.

In demo mode, questions are processed locally and are not sent to OpenAI. Once full AI is activated, the question, limited conversation history and matched public website excerpts may be sent to OpenAI to generate a response. The API request uses store: false and the application creates no conversation database. OpenAI may nevertheless retain content and metadata in default abuse-monitoring logs for up to 30 days unless an approved shorter-retention control is enabled or longer retention is required by law or service protection. Do not enter personal, payment, medical or other sensitive data.

06

Recipients and international transfers

Recipients may include VPS hosting and IT administration providers, email and security providers, legal advisers and competent authorities. If full AI is enabled, OpenAI also receives the chat content as the model service provider.

Reservation, map and social-media links open separate services governed by their operators. Where a provider processes data outside the EEA, the Controller uses an applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses. Full AI should not be enabled until the required data-processing agreement and transfer assessment are in place.

07

Retention

  • server logs: normally up to 30 days, unless an incident or claim record is isolated for longer;
  • concierge rate limiting: IP address in server memory for 10 minutes;
  • concierge conversations: no application database; in full AI mode provider abuse-monitoring logs may be retained for up to 30 days;
  • enquiries not leading to a contract: for handling and up to 12 months afterwards;
  • contract-related data: for performance and then for statutory tax, accounting and claim-limitation periods;
  • consent-based data: until withdrawal; consent evidence until relevant claims expire.
08

Your rights

Subject to GDPR conditions, you may request access, rectification, erasure, restriction, portability, withdrawal of consent and object to processing based on legitimate interests. Withdrawal does not affect prior lawful processing.

Contact info@dworhubertus.pl. You may also complain to the Polish supervisory authority (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl.

09

Voluntary provision and automated decisions

Ordinary browsing requires only technical transmission data. Correspondence details are voluntary, but without them we may not be able to reply or prepare an offer. The Controller does not make solely automated decisions producing legal or similarly significant effects.

10

Changes

We update this policy when functions, providers or law change. Material new purposes or consent-based technologies will be presented before such processing begins. In case of inconsistency, the Polish reference text prevails to the extent permitted by law.