My Kraków Tourist Card
Szybciej, wygodniej, zawsze pod ręką
Otwórz

Download App

apple app store google play store
  • Home
  • PRIVACY POLICY FOR THE “MY KRAKÓW TOURIST CARD” PROJECT

PRIVACY POLICY FOR THE “MY KRAKÓW TOURIST CARD” PROJECT

Effective date: 9 March 2026
(hereinafter: the “Policy”)

TABLE OF CONTENTS

I. GENERAL PROVISIONS
II. PERSONAL DATA CONTROLLER
III. PURPOSE AND LEGAL BASIS OF PROCESSING
IV. TRANSFER OF PERSONAL DATA
V. RIGHTS OF DATA SUBJECTS
VI. SECURITY MEASURES
VII. PROFILING
VIII. DATA RETENTION PERIOD
IX. COOKIES
X. FINAL PROVISIONS

I. GENERAL PROVISIONS

1. Capitalised terms that are not defined in this Policy shall have the meaning assigned to them in the Terms and Conditions of the “My Kraków Tourist Card” project.
2. Terms relating to the processing of personal data that are not defined in this Policy shall have the meaning assigned to them in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: “GDPR”).
3. The purpose of this Policy is to fulfil the information obligations arising under the GDPR in connection with the processing of personal data within the Project.

II. PERSONAL DATA CONTROLLER
1. The Personal Data Controller is Stowarzyszenie Organizacja Turystyczna Stołecznego Królewskiego Miasta Krakowa (Kraków Tourism Alliance), with its registered office in Kraków, at ul. Bracka 1, 31-005 Kraków, Poland, registered by the District Court for Kraków-Śródmieście, 11th Commercial Division of the National Court Register, entered in the register of associations, other social and professional organisations, foundations, and independent public healthcare institutions, as well as in the register of entrepreneurs, under KRS court register No. 0001062716, REGON statistical No. 526676428, and NIP tax identification No. 6762653896 (hereinafter: the “Controller”).
2. The Controller’s contact details are:
Address: ul. Bracka 1, 31-005 Kraków, Poland
Telephone: +48 12 26 33 142
E-mail: office@krakowtourism.pl

III. PURPOSE AND LEGAL BASIS OF PROCESSING
1. The Controller indicates the purposes and legal bases for the processing of personal data:
Purpose of processing Legal basis for processing
The ongoing processing of Users’ orders relating to the purchase and handling of Packages by the Organiser. Registration of Users in the System. Management of the Account and the System. Contact relating to the delivery of Packages. The necessity of performing an agreement – Article 6(1)(b) GDPR, i.e. processing is necessary for the performance of an agreement to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into an agreement.
Marketing purposes, promotion of the Project, including the sending of commercial information. Processing of personal data related to Cookies. Consent of the data subject – Article 6(1)(a) GDPR, i.e. the data subject has consented to the processing of his or her personal data for one or more specific purposes.
Processing of personal data for analytical and statistical purposes. The Controller’s legitimate interest – Article 6(1)(f) GDPR, comprising a business interest consisting in improving the quality of the services provided while ensuring the security and proper functioning of the Application.
Fulfilment of legal obligations: archiving documentation, fulfilling accounting and tax obligations, and fulfilling obligations towards public authorities. Fulfilment of obligations arising from provisions of law – Article 6(1)(c) GDPR. 
Handling complaints and claims. Responding to enquiries submitted by e-mail.  The Controller’s legitimate interest – Article 6(1)(f) GDPR, comprising the proper delivery of services, prevention of abuse, defence against unfounded claims, and conducting ongoing communication relating to the implementation of the programme.
2. The provision of personal data by the User is voluntary; however, the Controller reserves the right to refuse to Activate the Package and to provide services within the Project if personal data are not provided.
3. The Controller does not process special categories of personal data.

IV. TRANSFER OF PERSONAL DATA
1. The Controller transfers personal data to the following recipients and categories of recipients:
a. QB sp. z o.o., with its registered office in Gdynia, KRS: 0000814615 being the provider of digital services enabling the implementation of the Project and the operation of the Application.
b. Subcontractors of QB sp. z o.o., with its registered office in Gdynia being, as on the effective date of this Policy: Dataspace P.S.A., with its registered office in Toruń, KRS: 0000969744.
c. Partners, that is entities working with the Controller on the basis of an agreement, offering benefits under the Project (discounts, reductions, special services) and honouring the Card.
d. Entities providing electronic payment services.
e. Entities providing legal and accounting services.
2. The Controller does not transfer personal data to third countries.

V. RIGHTS OF DATA SUBJECTS
1. The Controller informs data subjects of the rights they have in connection with the processing of their personal data by the Controller:
a. the right to request access to their personal data from the Controller
b. the right to rectification of personal data, erasure of personal data, or restriction of the processing of personal data
c. the right to object to processing
d. the right to data portability
e. where the processing of data is based on consent – the right to withdraw consent to processing, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal
f. where personal data are processed on the basis of consent – the right to object to the processing of personal data for the purposes of such marketing
g. the right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office. The contact details of the supervisory authority are:
Address: ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland
Telephone: +48 22 531 0300
E-mail: kancelaria@uodo.gov.pl
2. The rights referred to in points a. to f. in 1. above may be exercised by contacting the Controller directly.

VI. SECURITY MEASURES
1. The Controller applies appropriate technical and organisational measures to ensure data security:
a. encryption of data transmission (SSL/TLS 2.1)
b. encryption of passwords in the database
c. control of access to data (multi-level authorisation – login using a one-time authorisation code sent by SMS)
d. regular backups (at least once a day)
e. security monitoring and incident detection
f. regular security audits
g. employee training in data protection.
2. In the event of a personal data breach:
a. the Controller assesses whether the breach may have resulted in a risk to the rights or freedoms of natural persons.
b. Where there is a risk to the rights or freedoms of natural persons, the Controller shall notify the President of the Personal Data Protection Office without undue delay (within 72 hours).
b. Users shall be informed of the breach if the breach is likely to result in a high risk to their rights.
c. The Controller shall take appropriate and proportionate remedial and preventive measures.

VII. PROFILING
1. The Controller profiles some of the personal data processed. The purpose of profiling is to tailor content as closely as possible and to present Users with dedicated marketing materials and offers, including notifications concerning products, services, and promotions, on the basis of Users’ interests, preferences, and demographic characteristics (in particular age and history of activity in the System).
2. The Controller does not process personal data for the purpose of profiling that would lead to automated decision-making producing legal effects concerning Users or similarly significantly affecting Users.

VIII. DATA RETENTION PERIOD
1. The Controller stores personal data for the period necessary to achieve the purposes for which they were collected and does not store them indefinitely.
2. The retention period is determined on the basis of applicable provisions of law, including limitation periods for claims, and the Controller’s legitimate interest. This also applies to the need to provide maintenance services for the System and the Application, as well as User support.
3. The data retention period may be extended where this follows from a legal obligation, in particular in connection with pending court or administrative proceedings.

IX. COOKIES
1. The Controller informs Users that, in connection with the use of the System, cookies (i.e. text files containing information concerning, among other things: device data, the time of use of the System, location data, and IP address data) (hereinafter: Cookies) may be stored on the User’s terminal devices.
2. Cookies may constitute personal data because they contain information that may be used to identify the User.
3. When visiting the website www.mykrakowcard.krakowtourism.pl, the User may consent to the use of Cookies. The User may withdraw consent at any time by changing the settings of the web browser that allow Cookie preferences to be changed, including those indicated below. The Controller notes that if the User uses a different terminal device, their Cookie settings may need to be updated again in order to give consent or change Cookie settings.
4. The Controller indicates the following typology of Cookies used by it:
a. Category I – session cookies and persistent cookies. Session cookies are files temporarily stored on the User’s terminal device and deleted when the User leaves the System. Persistent cookies are files stored for a longer period on the User’s terminal device, depending on the duration of the session or until they are deleted by the User.
b. Category II – first-party and third-party cookies. First-party cookies are cookies originating from the Organiser. Third-party cookies are cookies used by the Organiser but originating from third parties whose services the Organiser uses within the System.
c. Category III – necessary, analytical, functional, advertising, and social media cookies. Necessary cookies are files required for the proper operation of the System, including the portal www.mykrakowcard.krakowtourism.pl. Analytical cookies allow the Organiser to collect information about the User’s use of websites in order to improve the services provided. Functional cookies allow certain User interface settings to be saved. Advertising cookies enable tailored advertising content to be delivered to Users. Social media cookies are used to share content via social networks.
5. The table below contains information on the cookies used by the Controller:
 
Cookie provider Cookie name Validity Session/Persistent First-party/Third-party Type (necessary, analytical, functional, advertising, social media)
Qb sp. z o.o. Ciasteczko sesyjne 30 minutes Session cookie - Necessary

6. The User may change the settings of the web browser in order to delete Cookies from the terminal device. Instructions on how to do this are provided below:
Google Chrome – Deleting, allowing, and managing cookies in Chrome – Computer – Google Chrome Help https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en
Mozilla Firefox – Clearing cookies and site data in Firefox | Firefox Help https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
Safari – Clearing Safari browsing history, cache, and cookies on iPhone – Apple Support https://support.apple.com/en-us/105082
Opera – Web preferences – Opera Help https://help.opera.com/en/latest/web-preferences/
Microsoft Edge – Manage cookies in Microsoft Edge: view, allow, block, delete, and use – Microsoft Support https://support.microsoft.com/en-gb/windows/manage-cookies-in-microsoft-edge-view-allow-block-delete-and-use-168dab11-0753-043d-7c16-ede5947fc64d

X. FINAL PROVISIONS
1. The Controller reserves the right to amend the Policy.
2. This Policy enters into force on 9 March 2026.