Privacy Policy
SPA FOR YOU VIOLETTA PACYNO
Effective date: 1 March 2026
- Data Controller
The controller of personal data is:
Spa For You Violetta Pacyno
ul. Senatorska 13/15
00-075 Warsaw, Poland
NIP: 8881605083
e-mail: info@spaforyou.com.pl
tel.: +48 695 342 434
(hereinafter referred to as the “Controller”).
The Controller processes personal data in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
- the Polish Personal Data Protection Act,
- other applicable legal provisions.
- Scope of Processed Data
Depending on the purpose of processing, the Controller may process the following data:
In connection with voucher purchases:
- first and last name,
- e-mail address,
- phone number,
- delivery address (for paper vouchers),
- invoicing details (if applicable),
- voucher personalization data (e.g. recipient’s name, dedication message).
In connection with appointment booking (Versum system):
- first and last name,
- phone number,
- e-mail address,
- information regarding the selected service and appointment date,
- appointment history.
In connection with contact:
- name,
- e-mail address,
- phone number,
- message content.
Data collected automatically:
- IP address,
- browser and device data,
- statistical data (cookies).
- Purposes and Legal Bases for Data Processing
Personal data is processed for the following purposes:
Performance of voucher sales agreements
Legal basis: Article 6(1)(b) GDPR.
Handling appointment bookings and SPA services (Versum)
Legal basis: Article 6(1)(b) GDPR.
Accounting and tax documentation
Legal basis: Article 6(1)(c) GDPR.
Handling complaints and pursuing claims
Legal basis: Article 6(1)(f) GDPR (legitimate interest of the Controller).
Responding to inquiries
Legal basis: Article 6(1)(f) GDPR.
Marketing of the Controller’s own services (if consent is given)
Legal basis: Article 6(1)(a) GDPR.
- Versum Booking System
The Controller uses the Versum booking system (Booksy Biz sp. z o.o.), which enables:
- online appointment booking,
- appointment calendar management,
- sending SMS or e-mail reminders.
Versum processes personal data as a data processor based on a data processing agreement concluded with the Controller.
Data transferred to the Versum system includes only the data necessary to complete the booking.
Detailed information on data processing by Versum is available in the provider’s privacy policy.
- Data Retention Period
Personal data is stored:
- for the duration of the agreement and thereafter for the period required by law (e.g. accounting records – 5 years),
- until the limitation period for claims expires,
- in the case of marketing consent – until it is withdrawn.
Data related to appointment history may be stored in the booking system to facilitate future bookings and ensure continuity of service.
- Data Recipients
Personal data may be transferred to entities cooperating with the Controller, in particular:
- the Versum booking system provider (Booksy Biz),
- accounting service providers,
- electronic payment operators,
- hosting providers,
- courier companies (for paper voucher delivery),
- IT service providers.
These entities process data based on appropriate agreements and solely in accordance with the Controller’s instructions.
- Data Subject Rights
Each individual has the right to:
- access their data,
- rectify their data,
- erase their data,
- restrict processing,
- data portability,
- object to processing,
- withdraw consent (if processing is based on consent).
To exercise these rights, please contact the Controller at: info@spaforyou.com.pl
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).
- Cookies
The website may use cookies for the purpose of:
- ensuring proper functioning of the website,
- processing orders,
- integration with the Versum booking system,
- statistical analysis.
Users may change cookie settings at any time in their browser.
If the website uses additional tools such as Google Analytics or Meta Pixel, they should be specified in this Policy.
- Voluntary Provision of Data
Providing personal data is voluntary, but necessary for:
- purchasing a voucher,
- booking an appointment,
- service provision,
- issuing an invoice.
Failure to provide data may prevent the service from being delivered.
- Data Security
The Controller implements appropriate technical and organizational measures, including:
- securing the website with an SSL certificate,
- restricted access to the Versum system,
- password-protected devices,
- regular system updates.
- Changes to the Privacy Policy
The Controller reserves the right to update this Privacy Policy in the event of changes in legal regulations or the operation of the website.
The current version is published on the website.