Privacy and Cookie Policy
Last updated: October 3, 2026
1. Data Controller and Contact Information
The controller of the personal data processed in connection with the use of the website https://www.galar.org, contact with us, and the booking and provision of services is the “Galar Gdański” Foundation, ul. Szafarnia 11/F8, 80-755 Gdańsk, NIP: 9571101331, hereinafter referred to as the “Foundation” or “we.”
For matters regarding personal data and the exercise of your rights, you can contact us at hello@galar.org or by mail at the Foundation’s address.
This policy applies to the Foundation’s data processing activities. Third-party service providers may also process certain data as separate data controllers, in accordance with their own privacy policies.
2. What data do we process?
The scope of the data depends on how you use our services. Not every use of the website requires you to provide all of the information described.
Contact information: first and last name, email address, phone number, the content of the correspondence, and the information contained in the attached files.
Reservations: the person making the reservation’s information, contact information, selected service and date, number of participants, ticket categories, language, and other information needed to process the specific order.
Payments and settlements: transaction amount and currency, payment ID and status, billing information, and information necessary to process a refund. Detailed information about payment instruments is handled by the payment processor as applicable to the selected method.
Website usage: IP address, device and browser information, pages visited, duration of the visit, referral source, and actions taken, as well as identifiers from cookies and similar technologies. The scope depends on the operation of the services and consent choices.
Chatbot: conversation content, data voluntarily provided in messages, and technical information necessary for the operation and security of the application.
We collect data directly from users, automatically when they use the website, or from intermediaries and systems through which reservations were made. When making a reservation on behalf of others, please provide only the necessary information and inform the participants about this policy.
3. Objectives and Legal Basis
Reservation and Service Provision. We process data for the purpose of presenting an offer, accepting an order, carrying out a cruise or other service, processing payments, and providing organizational information. The legal basis is Article 6(1)(b) of the GDPR—pre-contractual measures taken at the user’s request and the performance of a contract. We process the data of other participants in the reservation to the extent necessary based on Article 6(1)(f) of the GDPR—a legitimate interest consisting of organizing the requested service.
Contact. We respond to inquiries and handle correspondence pursuant to Article 6(1)(b) of the GDPR when they relate to the conclusion or performance of a contract. In all other cases, the legal basis is Article 6(1)(f) of the GDPR—a legitimate interest consisting of handling correspondence.
Legal Obligations. We process the data necessary for accounting and tax purposes, as well as for fulfilling our obligations related to customer rights, pursuant to Article 6(1)(c) of the GDPR.
Complaints and Claims. The legal basis for handling complaints is Article 6(1)(b) or (c) of the GDPR, depending on the case. The establishment, pursuit, and defense of claims are based on Article 6(1)(f) of the GDPR—the legitimate interest in protecting the Foundation’s rights.
Safety. We process the technical data necessary for maintaining the website, detecting errors, and preventing abuse pursuant to Article 6(1)(f) of the GDPR—based on our legitimate interest in protecting and ensuring the proper functioning of our services.
Analytics and Advertising. The processing of personal data based on optional analytics and advertising technologies requires appropriate consent. The legal basis is Article 6(1)(a) of the GDPR. The purposes include analyzing website usage, measuring the effectiveness of advertisements, and tailoring advertisements.
We do not currently send out newsletters or promotional emails or text messages. Messages regarding orders, payments, cruise dates, or complaints are sent for service purposes.
4. Bókun Reservations and Stripe Payments
We use Bókun to process reservations. Forms may be displayed on galar.org or on the provider’s website. The data is used to the extent necessary to accept reservations, provide customer service, and fulfill and bill for the service.
Bókun processes data on our behalf within the scope of the service provided and the terms of the data processing agreement. The provider describes its own purposes for processing data in its policy:
https://www.bokun.io/privacy-policy
Electronic payments are processed by Stripe. The provider may process data as a separate data controller, including for the purposes of processing payments, preventing fraud, and complying with legal obligations. Details:
https://stripe.com/privacy
5. Chatbots and Artificial Intelligence
The chatbot helps you get information about offers, availability, and reservations. Message content is processed by an application that uses OpenAI technology as well as Vercel and Supabase services. The information needed to check availability or process reservations may be forwarded to Bókun.
The legal basis is Article 6(1)(b) of the GDPR if the conversation concerns an order or the provision of a service, or Article 6(1)(f) of the GDPR—a legitimate interest consisting of providing responses, protecting the application, and troubleshooting errors in its operation.
Do not enter credit card numbers, passwords, identification information, or unnecessary health-related information. Responses are generated automatically and may contain errors. For matters requiring confirmation, please contact us at: hello@galar.org.
We have established a target retention period of 90 days for conversation content and related logs, starting from the date they are recorded. The mechanism for deleting data after this period is currently being implemented; as of the date of this policy update, we do not yet confirm that data will be automatically deleted after 90 days. Inquiries regarding current data retention and requests for data deletion can be directed to hello@galar.org.
6. Data Recipients
Data may be provided to reservation system providers, payment processors and banks, hosting, email, and IT service providers, accounting and legal service providers, and intermediaries involved in a specific reservation. Public authorities may receive data in accordance with applicable laws.
In connection with the operation of the website, recipients may also include providers of Google and Meta tools, Trustindex, and services used by the chatbot. The scope of data sharing depends on the features, service configurations, and required consents.
Data processors acting on our behalf receive data only to the extent necessary to perform the service. Providers who independently determine their own purposes and means of processing act as separate data controllers in this regard.
7. Transfer of Data Outside the EEA
Services provided by international vendors may involve the transfer of data outside the European Economic Area, including to the United States. Depending on the service, this may also involve processing by subcontractors or technical access to the data.
Such a transfer requires a legal basis as provided for in Chapter V of the GDPR, such as a relevant European Commission decision confirming an adequate level of protection, or standard contractual clauses and the required additional safeguards. The appropriate mechanism depends on the recipient and the specific transfer.
Information about recipients, countries, and safeguards related to a specific service, as well as how to obtain a copy of the safeguards, is available at hello@galar.org.
8. How long do we retain data?
We retain reservation data for as long as necessary to process and fulfill the contract, and thereafter to the extent required by law or necessary to protect against claims.
We retain accounting and tax records for the period required by the regulations applicable to each document. We retain data related to claims until the expiration of the applicable statutes of limitations, and, if legal proceedings are initiated, also for the time necessary to conclude the proceedings and enforce the ruling.
We retain correspondence for as long as it takes to resolve the matter. If the correspondence relates to a contract, a complaint, or a claim, we apply the retention period appropriate for that matter.
We retain data processed solely on the basis of consent until such consent is withdrawn, the retention period established for a given service expires, or the purpose of processing is fulfilled earlier. Evidence of the granting and withdrawal of consent may be needed for a longer period to demonstrate compliance with regulations and to protect against claims.
We retain security logs for the period necessary to detect and investigate errors or incidents. Cookie retention periods depend on the behavior of individual cookies; analytics data retention periods depend on the tool’s settings. The rules governing chatbot conversations are described in Section 5.
9. Cookies and Similar Technologies
Cookies and similar technologies store information on the user’s device or allow access to information already stored there. They may be used to enable the website to function and process reservations, remember settings, analyze traffic, and measure the effectiveness of advertisements. Device identifiers and activity information may constitute personal data.
Essential technologies are used to provide the functions requested by the user, to ensure security, and to store consent decisions. Consent to storage or access is not required only to the extent covered by the statutory exception for essential technologies.
Functional technologies store additional preferences. If they are not necessary for the requested service, they require appropriate consent.
Analytics technologies, including Google Analytics 4, are used to analyze visits and events, including those related to reservations. Google Ads and Meta advertising technologies are used to measure campaign effectiveness, create audience groups, and tailor ads. Optional technologies require appropriate consent.
Bókun forms, Trustindex reviews, Google Maps, and other external content may, once loaded, transmit your IP address and technical data to the provider and use cookies or similar technologies. Consent requirements depend on how each service operates.
Cookies can be session cookies or remain on your device for a specified period of time. The actual durations depend on the provider, the file, and the service settings. Information about the technologies used and their durations is available at hello@galar.org.
10. Consent Management
Consent for optional technologies is voluntary. You may accept selected categories, decline optional technologies, and change your selection later. Withdrawing your consent does not affect the lawfulness of processing carried out prior to its withdrawal.
You can reopen the cookie preferences panel by clicking the “Cookie Settings” link at the top of this page. You can also delete and block cookies in your browser. Blocking essential technologies may interfere with certain features, including the booking process.
11. Voluntary Provision of Data
Providing data is generally voluntary, but certain information is required to respond to your inquiry, make a reservation, provide a service, process a payment, or issue an invoice. Failure to provide the necessary information may prevent us from performing the requested action. Required fields are marked on the forms.
Consent to optional analytics and advertising is not a requirement for purchasing a cruise.
12. User Rights
In the cases specified in the GDPR, you have the right to access your data and receive a copy of it, as well as the right to rectification, erasure, restriction of processing, and data portability. Data portability applies to data provided by the user that is processed automatically on the basis of consent or a contract.
You may object to processing based on a legitimate interest for reasons related to your particular situation. You may object to direct marketing, including related profiling, at any time; once you object, your data will no longer be processed for that purpose.
You may withdraw your consent at any time. It is not always possible to delete data, for example, when its continued storage is required by law or is necessary to establish, assert, or defend legal claims.
Applications should be sent to hello@galar.org. If we have reasonable doubts regarding your identity, we may ask you to provide the information necessary to verify it. We will respond without undue delay, generally within one month. We will inform you of any permissible extension of this deadline and the reasons for it within the first month.
You may file a complaint with the President of the Office for Personal Data Protection. Information:
https://uodo.gov.pl
13. Profiling and Automated Decisions
Once the required consent has been obtained, advertising tools may assign users to audience groups based on their activity. This may constitute profiling for the purpose of tailoring advertisements.
We do not make decisions regarding users based solely on automated processing that produce legal effects or similarly significantly affect them. The mere fact that a chatbot automatically generates responses does not constitute such decision-making.
14. Security and Updates
We implement technical and organizational measures appropriate to the nature of the data and the risks involved to protect the data from unauthorized access, loss, alteration, or disclosure. We tailor access permissions to the responsibilities of the individuals and entities providing the services. No IT system can provide a complete guarantee of security.
We update this policy in the event of changes to our services, processing methods, or regulations. The date of the update is listed at the beginning of the document. If a change requires additional information or new consent, we will take the necessary steps before beginning any processing that requires such information or consent.
