Your privacy matters wherever in the world you are browsing from.
This Privacy Policy explains how personal data may be processed when you use HaveYouSeenTheWorld.com, contact us or interact with website features. The Website is operated from Poland and this policy is based primarily on European Union and Polish data-protection law.
The essentials before the legal detail.
Controller in Poland
The Website is operated by a controller established in Poland and subject to EU and Polish data-protection rules.
Google Analytics 4
GA4 is used for website analytics only after the required Analytics consent has been provided.
CookieYes consent
CookieYes is used to display the consent banner, store cookie preferences and record consent choices.
Your GDPR rights
You may have rights of access, rectification, erasure, restriction, objection and data portability.
Who is responsible for your personal data?
The controller of personal data processed in connection with HaveYouSeenTheWorld.com (the “Website”) is Dawid Gicala, conducting business activity in Poland, operating the Have You Seen The World? travel portal.
You can contact the controller regarding privacy or personal-data matters at: contact@haveyouseentheworld.com.
No Data Protection Officer has been appointed unless information about such appointment is published on the Website in the future.
EU and Polish privacy law applies.
Because the controller is established in Poland, personal-data processing is governed primarily by Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR” or “RODO”) and applicable Polish law, including the Polish Act of 10 May 2018 on the Protection of Personal Data.
Rules concerning storing information on, or accessing information from, a user’s terminal equipment — including cookies and similar technologies — are also subject to the Polish Act of 12 July 2024 – Electronic Communications Law (Prawo komunikacji elektronicznej), including Article 399.
The Website is intended for an international audience, but operating from Poland does not reduce the protections available under mandatory laws that may additionally apply to users in their place of residence.
What personal data may be processed?
Technical and server data
When you visit the Website, servers and security systems may automatically process technical information such as:
- IP address and approximate network information;
- date and time of a request;
- requested page or resource;
- browser, operating system and device information;
- referrer information and basic technical event data;
- security, error and diagnostic information.
Google Analytics 4 data
If you consent to Analytics cookies, the Website uses Google Analytics 4 (“GA4”) to understand how the Website is used. Depending on the GA4 configuration, measurement data may include page views, session and event information, approximate location, device and browser characteristics, referral/source information and identifiers stored in analytics cookies.
For users in the EU, Switzerland and the United Kingdom, Google states that Google Analytics does not log or store individual IP addresses. IP information may be used temporarily to derive coarse geolocation before being discarded.
CookieYes consent data
CookieYes is used as the Website’s consent-management platform. It may process information necessary to display the banner, remember your choices and maintain a record of consent, including a consent identifier, consent status, consent categories, time of the consent action and relevant technical information needed to demonstrate and manage consent.
Data contained in correspondence
If you contact us by email, we may process your email address, name or other identifiers you provide, the content of your message, attachments and information necessary to respond to the enquiry.
Please do not send special-category personal data or other highly sensitive information unless it is genuinely necessary for your request.
Why may we process personal data?
Where processing is based on legitimate interests, we consider the necessity of the processing and the impact on the rights and freedoms of the individuals concerned.
How long is personal data kept?
Personal data is retained only for as long as necessary for the purpose for which it was collected or for the period required by applicable law.
- Google Analytics 4: event- and user-level retention follows the settings configured in the GA4 property. Google currently provides standard GA4 retention settings such as 2 or 14 months for relevant user/event data, while aggregated reporting may be retained differently by the service.
- CookieYes: consent choices are stored for the period configured in CookieYes. CookieYes may also retain consent-log data according to the selected CookieYes plan and service configuration so that consent can be demonstrated and managed.
- Correspondence: for the time necessary to handle the enquiry and afterwards where reasonably necessary to document the matter, establish or defend claims, or comply with legal obligations.
- Technical and server logs: for the period necessary for security, troubleshooting, abuse prevention and system administration, subject to the configuration and retention rules of the hosting infrastructure.
When retention is no longer necessary, data is deleted, anonymised or otherwise removed from active processing, subject to technically justified backup cycles and legal retention requirements.
Who may receive personal data?
Personal data may be disclosed only where necessary and on an appropriate legal basis. Categories of recipients may include:
- hosting, server and infrastructure providers;
- email and communication service providers;
- IT support, website maintenance and security providers;
- Google Ireland Limited and other relevant Google entities in connection with Google Analytics 4;
- CookieYes Limited in connection with the cookie-consent banner, preference management and consent records;
- professional advisers where necessary, for example legal or accounting advisers;
- public authorities or other entities where disclosure is required by law.
Where a service provider acts as a processor, the controller uses the provider under appropriate data-processing terms as required by Article 28 GDPR. The exact role of a provider may depend on the relevant service and processing operation.
Can data leave the European Economic Area?
Google and CookieYes operate internationally. Personal data processed in connection with GA4 or consent management may therefore be processed in, or accessed from, countries outside the European Economic Area (“EEA”).
Where GDPR requires safeguards for a transfer outside the EEA, the transfer is made using a mechanism permitted by GDPR, such as an adequacy decision adopted by the European Commission, Standard Contractual Clauses under Article 46 GDPR, or another lawful transfer mechanism together with supplementary safeguards where necessary.
Google identifies Google Ireland Limited as the relevant Google end controller for European controller personal data under its measurement data-protection terms. CookieYes Limited is established in the United Kingdom. Transfers or access involving other countries depend on each provider’s infrastructure and contractual arrangements.
Information about safeguards applicable to a specific transfer may be requested using contact@haveyouseentheworld.com.
How does the Website use cookies?
Cookies are small pieces of information stored on or accessed from a user’s device. Similar technologies may perform comparable functions.
CookieYes consent banner
CookieYes is used to display the cookie banner and preference centre. You can accept or reject non-essential categories and later change or withdraw your choices using the cookie-settings control available on the Website.
Prior consent for GA4
Google Analytics 4 is classified as an Analytics service. The Website is intended to be configured so that GA4 analytics cookies and Analytics processing do not start before the required Analytics consent has been provided. If Analytics consent is refused or withdrawn, Analytics cookies should remain blocked or be disabled in accordance with the consent configuration.
Under Article 399 of the Polish Electronic Communications Law, storing information on a user’s terminal device or accessing information already stored there generally requires clear prior information and consent, unless the statutory exception for strictly necessary operations applies.
Browser settings may also allow you to delete or block cookies. Blocking strictly necessary technologies can affect website functionality. Deleting cookies may also cause the CookieYes banner to appear again because the Website can no longer read your previous preference from the device.
Which third-party services are currently planned?
Google Analytics 4
The Website uses Google Analytics 4, a web-analytics service provided within the Google group. GA4 helps us understand how visitors use the Website, for example which pages are viewed, how sessions progress and how users reach the Website.
GA4 is used subject to the consent choices described in Section 8. For users in the EU, Switzerland and the United Kingdom, Google states that Analytics does not log or store individual IP addresses and uses IP information only temporarily for coarse geolocation before discarding it.
More information about Google’s privacy practices can be found in Google’s own privacy and Analytics documentation.
CookieYes
The Website uses CookieYes, provided by CookieYes Limited, as a consent-management platform (“CMP”). CookieYes displays the consent banner, stores cookie preferences, supports changing or withdrawing consent and may maintain consent logs so the Website can demonstr