Your privacy matters wherever in the world you are browsing from.
This Privacy Policy explains how personal data may be processed when you use HaveYouSeenTheWorld.com, contact us or interact with website features. The Website is operated from Poland and this policy is based primarily on European Union and Polish data-protection law.
The essentials before the legal detail.
Controller in Poland
The Website is operated by a controller established in Poland and subject to EU and Polish data-protection rules.
Google Analytics 4
GA4 is used for website analytics only after the required Analytics consent has been provided.
CookieYes consent
CookieYes is used to display the consent banner, store cookie preferences and record consent choices.
Your GDPR rights
You may have rights of access, rectification, erasure, restriction, objection and data portability.
Who is responsible for your personal data?
The controller of personal data processed in connection with HaveYouSeenTheWorld.com (the βWebsiteβ) is Dawid Gicala, conducting business activity in Poland, operating the Have You Seen The World? travel portal.
You can contact the controller regarding privacy or personal-data matters at: contact@haveyouseentheworld.com.
No Data Protection Officer has been appointed unless information about such appointment is published on the Website in the future.
EU and Polish privacy law applies.
Because the controller is established in Poland, personal-data processing is governed primarily by Regulation (EU) 2016/679 (the General Data Protection Regulation, βGDPRβ or βRODOβ) and applicable Polish law, including the Polish Act of 10 May 2018 on the Protection of Personal Data.
Rules concerning storing information on, or accessing information from, a user’s terminal equipment β including cookies and similar technologies β are also subject to the Polish Act of 12 July 2024 β Electronic Communications Law (Prawo komunikacji elektronicznej), including Article 399.
The Website is intended for an international audience, but operating from Poland does not reduce the protections available under mandatory laws that may additionally apply to users in their place of residence.
What personal data may be processed?
Technical and server data
When you visit the Website, servers and security systems may automatically process technical information such as:
- IP address and approximate network information;
- date and time of a request;
- requested page or resource;
- browser, operating system and device information;
- referrer information and basic technical event data;
- security, error and diagnostic information.
Google Analytics 4 data
If you consent to Analytics cookies, the Website uses Google Analytics 4 (βGA4β) to understand how the Website is used. Depending on the GA4 configuration, measurement data may include page views, session and event information, approximate location, device and browser characteristics, referral/source information and identifiers stored in analytics cookies.
For users in the EU, Switzerland and the United Kingdom, Google states that Google Analytics does not log or store individual IP addresses. IP information may be used temporarily to derive coarse geolocation before being discarded.
CookieYes consent data
CookieYes is used as the Website’s consent-management platform. It may process information necessary to display the banner, remember your choices and maintain a record of consent, including a consent identifier, consent status, consent categories, time of the consent action and relevant technical information needed to demonstrate and manage consent.
Data contained in correspondence
If you contact us by email, we may process your email address, name or other identifiers you provide, the content of your message, attachments and information necessary to respond to the enquiry.
Please do not send special-category personal data or other highly sensitive information unless it is genuinely necessary for your request.
Why may we process personal data?
Where processing is based on legitimate interests, we consider the necessity of the processing and the impact on the rights and freedoms of the individuals concerned.
How long is personal data kept?
Personal data is retained only for as long as necessary for the purpose for which it was collected or for the period required by applicable law.
- Google Analytics 4: event- and user-level retention follows the settings configured in the GA4 property. Google currently provides standard GA4 retention settings such as 2 or 14 months for relevant user/event data, while aggregated reporting may be retained differently by the service.
- CookieYes: consent choices are stored for the period configured in CookieYes. CookieYes may also retain consent-log data according to the selected CookieYes plan and service configuration so that consent can be demonstrated and managed.
- Correspondence: for the time necessary to handle the enquiry and afterwards where reasonably necessary to document the matter, establish or defend claims, or comply with legal obligations.
- Technical and server logs: for the period necessary for security, troubleshooting, abuse prevention and system administration, subject to the configuration and retention rules of the hosting infrastructure.
When retention is no longer necessary, data is deleted, anonymised or otherwise removed from active processing, subject to technically justified backup cycles and legal retention requirements.
Who may receive personal data?
Personal data may be disclosed only where necessary and on an appropriate legal basis. Categories of recipients may include:
- hosting, server and infrastructure providers;
- email and communication service providers;
- IT support, website maintenance and security providers;
- Google Ireland Limited and other relevant Google entities in connection with Google Analytics 4;
- CookieYes Limited in connection with the cookie-consent banner, preference management and consent records;
- professional advisers where necessary, for example legal or accounting advisers;
- public authorities or other entities where disclosure is required by law.
Where a service provider acts as a processor, the controller uses the provider under appropriate data-processing terms as required by Article 28 GDPR. The exact role of a provider may depend on the relevant service and processing operation.
Can data leave the European Economic Area?
Google and CookieYes operate internationally. Personal data processed in connection with GA4 or consent management may therefore be processed in, or accessed from, countries outside the European Economic Area (βEEAβ).
Where GDPR requires safeguards for a transfer outside the EEA, the transfer is made using a mechanism permitted by GDPR, such as an adequacy decision adopted by the European Commission, Standard Contractual Clauses under Article 46 GDPR, or another lawful transfer mechanism together with supplementary safeguards where necessary.
Google identifies Google Ireland Limited as the relevant Google end controller for European controller personal data under its measurement data-protection terms. CookieYes Limited is established in the United Kingdom. Transfers or access involving other countries depend on each provider’s infrastructure and contractual arrangements.
Information about safeguards applicable to a specific transfer may be requested using contact@haveyouseentheworld.com.
How does the Website use cookies?
Cookies are small pieces of information stored on or accessed from a user’s device. Similar technologies may perform comparable functions.
CookieYes consent banner
CookieYes is used to display the cookie banner and preference centre. You can accept or reject non-essential categories and later change or withdraw your choices using the cookie-settings control available on the Website.
Prior consent for GA4
Google Analytics 4 is classified as an Analytics service. The Website is intended to be configured so that GA4 analytics cookies and Analytics processing do not start before the required Analytics consent has been provided. If Analytics consent is refused or withdrawn, Analytics cookies should remain blocked or be disabled in accordance with the consent configuration.
Under Article 399 of the Polish Electronic Communications Law, storing information on a user’s terminal device or accessing information already stored there generally requires clear prior information and consent, unless the statutory exception for strictly necessary operations applies.
Browser settings may also allow you to delete or block cookies. Blocking strictly necessary technologies can affect website functionality. Deleting cookies may also cause the CookieYes banner to appear again because the Website can no longer read your previous preference from the device.
Which third-party services are currently planned?
Google Analytics 4
The Website uses Google Analytics 4, a web-analytics service provided within the Google group. GA4 helps us understand how visitors use the Website, for example which pages are viewed, how sessions progress and how users reach the Website.
GA4 is used subject to the consent choices described in Section 8. For users in the EU, Switzerland and the United Kingdom, Google states that Analytics does not log or store individual IP addresses and uses IP information only temporarily for coarse geolocation before discarding it.
More information about Google’s privacy practices can be found in Google’s own privacy and Analytics documentation.
CookieYes
The Website uses CookieYes, provided by CookieYes Limited, as a consent-management platform (βCMPβ). CookieYes displays the consent banner, stores cookie preferences, supports changing or withdrawing consent and may maintain consent logs so the Website can demonstrate and respect users’ choices.
Other external services
The Website may contain standard links to third-party websites. If additional embedded services such as maps, video players, social widgets, advertising tools or other tracking technologies are introduced, this Privacy Policy and the CookieYes configuration will be reviewed and updated as necessary before or when those services are activated.
Clicking a standard external link takes you to a third party’s website. The controller of HaveYouSeenTheWorld.com does not determine how that third party processes personal data on its own website.
What rights do you have?
Subject to the conditions and limitations set out in GDPR, you may exercise the following rights:
Ask whether your personal data is processed and request access to it.
Ask for inaccurate personal data to be corrected or incomplete data supplemented.
Ask for deletion where the conditions for the right to erasure are met.
Request restriction of processing in situations provided for by GDPR.
Receive certain data in a structured format where the GDPR conditions apply.
Object to processing based on legitimate interests in accordance with Article 21 GDPR.
Withdraw consent at any time where processing is based on consent.
Lodge a complaint with a competent data-protection supervisory authority.
Benefit from protections concerning certain solely automated decisions where Article 22 GDPR applies.
To exercise a privacy right, email contact@haveyouseentheworld.com. We may request additional information where reasonably necessary to verify identity and protect personal data from unauthorised disclosure.
You can complain to the Polish data-protection authority.
If you believe that the processing of your personal data infringes GDPR, you have the right to lodge a complaint with a competent supervisory authority.
In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes UrzΔdu Ochrony Danych Osobowych β Prezes UODO).
Official information about data-protection rights and filing a complaint is available at uodo.gov.pl.
GDPR may also allow you to lodge a complaint with a supervisory authority in another EU/EEA Member State, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.
How is personal data protected?
The controller applies technical and organisational measures appropriate to the nature of the Website, the categories of data processed and the risks associated with processing.
Measures may include encrypted connections, access controls, software updates, security monitoring, backups and limiting access to personal data to persons or service providers who need it for a legitimate purpose.
No internet transmission or storage system can be guaranteed to be completely risk-free. Security measures are therefore reviewed and adjusted as the Website and its infrastructure change.
The Website is a general travel-information service.
HaveYouSeenTheWorld.com is not designed to intentionally collect personal data from children. If you believe that a child has provided personal data through the Website in circumstances requiring action, contact us at contact@haveyouseentheworld.com.
No decisions with legal or similarly significant effects.
The Website does not use personal data to make decisions based solely on automated processing that produce legal effects concerning users or similarly significantly affect them within the meaning of Article 22 GDPR.
If this changes in the future, this Privacy Policy will be updated with the information required by applicable law.
The policy may change as the Website develops.
This Privacy Policy may be updated when the Website adds or changes services, technology providers, data-processing activities or where legal requirements change.
The current version will be published on this page. Where a change materially affects how personal data is processed, additional notice may be provided where required or appropriate.
4 September 2026
Contact the controller directly.
For access requests, corrections, deletion requests, objections or any question about this Privacy Policy, email contact@haveyouseentheworld.com.
