1.Data controller
The controller of your personal data is Filip Piątek, the operator of pewnawoda.pl (“we”).
For matters concerning personal data, email kontakt@pewnawoda.pl or choose the “Personal data (GDPR)” topic in the form at pewnawoda.pl/kontakt. We have not appointed a data protection officer because we are not required to — contact us directly about any matter.
Fishery owners to whom we pass the data needed to fulfil bookings, e-permits and competitions are separate controllers of that data.
Beta version
2.What data we process
- Account: full name (or business name), email address, password stored as a cryptographic hash and, if you add them, profile photo, phone number, town and profile description. When you log in with a Google account: your name, email and profile photo provided by Google.
- Owner account: additionally phone number, company name and NIP (tax ID), and fishery details.
- Bookings: dates, peg, number of people, contact details provided when booking, notes for the fishery, amounts and payment status.
- Payments: transaction identifiers and status received from Stripe. We do not receive full payment card numbers.
- E-permits: the holder's full name, the validity period and the permit code.
- Activity on the site: reviews, photos, catch log entries, favourite fisheries, competition entries and notifications.
- Contact form: full name, email, subject and content of the message.
- Technical data: IP address, browser and device information and request times — in server logs and login session data.
- Location: only when you use the nearby fishery search yourself and allow it in your browser. Your location is then used only for the search and is not saved in your account.
3.Purposes and legal bases
- Running your account and providing the site's services (bookings, e-permits, competitions, Premium) — Art. 6(1)(b) GDPR (contract).
- Billing, accounting and tax obligations — Art. 6(1)(c) GDPR (legal obligation).
- Verifying fishery owners, site security, preventing abuse (e.g. attempt limits, account blocks) and content moderation — Art. 6(1)(f) GDPR (our legitimate interest).
- Replying to messages sent through the contact form — Art. 6(1)(a) GDPR (your consent) and, where the message concerns a contract already concluded, Art. 6(1)(b) GDPR.
- Cookie-free visit statistics (Umami) — Art. 6(1)(f) GDPR (our interest in improving the site).
- Google Analytics — only with your consent: Art. 6(1)(a) GDPR.
- News and offers — only if you turn them on in your notification settings: Art. 6(1)(a) GDPR.
- Establishing, pursuing and defending legal claims — Art. 6(1)(f) GDPR.
4.Where we store data
The site runs on servers in the European Union — in a Hetzner Online GmbH data centre in Finland, on our own installation managed with Coolify. This is where the site's database and uploaded files, including photos, are stored.
We maintain the database and files ourselves — we do not use external database providers or application hosting platforms.
5.Who we share data with
- Fishery owners — data from bookings, e-permits and competition entries, to the extent needed to handle your stay.
- Stripe Payments Europe, Ltd. (Dublin, Ireland) — online payment processing.
- Hetzner Online GmbH (Germany) — the provider of the servers the site runs on (processor).
- PB Devs — the team that builds and maintains the site, including its own email sending service (mail.pbdevs.com) and visit statistics (umami.pbdevs.com); it acts on our behalf as a processor.
- Google Ireland Limited — only when you log in with a Google account or consent to Google Analytics.
- OpenStreetMap Foundation (United Kingdom) — when you view the map, your browser downloads map tiles from OpenStreetMap servers, which receive your IP address.
- Public authorities — where required by law.
We do not sell personal data or share it for advertising purposes.
6.Transfers outside the EEA
We process data in the European Economic Area. Stripe and Google may transfer data to the USA — on the basis of a European Commission adequacy decision (EU-US Data Privacy Framework) or standard contractual clauses. The United Kingdom, where the OpenStreetMap Foundation operates, is covered by a Commission adequacy decision.
7.How long we keep data
- Account data — until the account is deleted.
- Bookings and transactions — 5 years from the end of the calendar year in which the tax payment deadline fell (a requirement of tax law).
- Reviews, photos and entries — until they are deleted or the account is deleted.
- Contact form messages — up to 12 months after the correspondence ends.
- Server logs — for as long as needed to ensure security, and no longer than 90 days.
- Google Analytics data — up to 14 months.
- Data processed on the basis of consent — until consent is withdrawn.
We keep data for longer only when it is needed to establish, pursue or defend legal claims — until those claims become time-barred.
9.Your rights
- Access to your data and receiving a copy of it.
- Rectification of inaccurate data.
- Erasure of data (the “right to be forgotten”).
- Restriction of processing.
- Portability of the data you have provided to us, in a machine-readable format.
- Objection to processing based on our legitimate interest.
- Withdrawal of consent at any time — without affecting the lawfulness of processing carried out before its withdrawal.
- Lodging a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
We respond to requests without undue delay, and at the latest within one month. You can download a copy of your data (a JSON file) yourself in your account settings, where you can also delete your account.
10.Do you have to provide your data?
Providing data is voluntary, but without the data marked as required you cannot create an account, make a booking, buy an e-permit or send a message.
11.Automated decisions
We do not make decisions based solely on automated processing, including profiling, that would produce legal effects concerning you or similarly significantly affect you. Automatic attempt limits (e.g. in the contact form) apply only temporarily.
12.Security
Connections to the site are encrypted (HTTPS). We store passwords only as cryptographic hashes. Only people who need access to data have it, and we check permissions on every operation. E-permit codes are cryptographically signed.
13.Changes to this privacy policy
We update this policy when the way the site works or the law changes. We announce significant changes on the site or by email.
14.Contact
Send questions about personal data to kontakt@pewnawoda.pl or use the form at pewnawoda.pl/kontakt.