Service Administrator
1. This Privacy Policy describes the rules governing the processing of data, in particular personal data, by Flyspot Group Sp. z o.o., with its registered office in Warsaw, 00-090, Al. Solidarności 75/26, entered in the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 12th Commercial Division of the National Court Register, under KRS number 0000821632, Tax Identification Number (NIP): 5252533508, with share capital of 19,000,000 PLN (hereinafter:“Flyspot Group” or “Administrator”).
2. The Privacy Policy describes the rules for data processing in connection with the services offered by the FlySpot Group, in particular those available at the wind tunnel facilities operated under the name “FlySpot” (“FlySpot”) and the facility featuring a deep-diving pool, operating under the name “ DeepSpot’), and the rules described in this document also apply to additional services or features related to the operations of FlySpot and DeepSpot, such as, in particular, services and content made available through the Administrator’s websites, including www.flyspot.com (the “Website”) and processes related to the sale of products and services in brick-and-mortar and online stores (all of the above services and activities will hereinafter be collectively referred to as “Services, ”and persons using or expressing an intention to purchase or use such Services as “Users”).
(3) The Administrator can be contacted on all issues related to data processing, including personal data, at e-mail address: [email protected].
Personal data – general provisions
(1) Personal data is any information about an identified or identifiable natural person, by which is meant a person who can be identified directly or indirectly, in particular on the basis of an identifier such as a name, an identification number, location data, an online identifier or one or more specific factors that determine the physical, physiological, genetic, mental, economic, cultural or social identity of a natural person.
2. The controller of Users’ personal data will be Flyspot Group Spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw (other details are provided in Article I, paragraphs 1 and 3 above).
3. Flyspot Group will process, including collect and store, personal data in accordance with applicable law, in particular the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”), as well as in accordance with this Privacy Policy.
4. Providing personal data is always voluntary; however, it may be a condition for purchasing or using the Services or for using certain features available on the Website. In particular, purchasing the Services, booking an appointment through the Website, and actually using the Services at FlySpot or DeepSpot requires the User to provide personal data. When using the flight services in the FlySpot wind tunnel or the DeepSpot pool, the personal data of each person actually using such Services must be provided, even if the Services were purchased by another person. Providing personal data in the above situation is necessary, in particular, to confirm that the User has read the important information provided by FlySpot Group in the standard declaration forms or other documents, to confirm the User’s acceptance of such information, and to verify that there are no contraindications to using the Service.
How we collect your personal information
1. Flyspot Group will collect and store Users’ personal data in connection with the provision of the Services or in connection with the User’s expression of intent to use the Services, including, in particular, through:
A) information entered by the User when creating an account on the Website
B) information entered by the User in forms filled out in connection with the use of the Services
C) information provided by the User for the purpose of carrying out purchases of Services through the Website
D) information provided by the User when contacting Flyspot Group, including in connection with complaints, inquiries regarding the Services, etc.
E) saving in the final devices used by the User, cookie files
F) collection of web server logs
G) obtaining data from publicly available sources or from external parties
H) The service may record information about connection parameters (time stamp, IP address).
I) For what purposes we process your personal data
J) Flyspot Group may process Users’ personal data in the following ways and for the following purposes:
K) accept and manage reservations made by the User with respect to the Services
L) enable the User to use the Service
M) to carry out other activities related to the performance of the Service, such as receiving and processing complaints, answering Users’ questions about the Services, etc.
N) issuing an invoice or other purposes related to bookkeeping, as well as fulfilling the obligations required by applicable law
O) promoting Flyspot Group’s Services
2. Flyspot Group may also process the User’s personal data for purposes other than those specified in paragraph 1 above, provided that the User gives appropriate consent or that the Controller has another legal basis for such processing, as well as provided that the User is given appropriate additional information about such processing of personal data if it were to take place for purposes other than those set forth in this Privacy Policy or under terms different from those set forth herein.
(3) The processing of personal data referred to above may be carried out on the following grounds provided for by the RODO:
A) processing is necessary for the performance of a contract to which the User is a party, or to take action at the User’s request, prior to the conclusion of the contract (Article 6(1)(a) RODO)
B) on the basis of the consent expressed by the User (Art. 6.1.b. RODO)
C) for the purpose of fulfilling a legal obligation incumbent on the Administrator (Art. 6.1.c. RODO)
D) for the purposes of legitimate interests pursued by the Administrator or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the User (Article 6.1.f. RODO).
E) The legitimate interests pursued by the Controller, as referred to in paragraph 3(d) above, include, in particular: contacting the User in connection with the provision of Services, responding to Users’ questions or other similar communication with the User, pursuing claims by Flyspot Group, or defending against claims filed by the User.
4. Given that certain Services provided by Flyspot Group may involve significant risks, particularly if the User uses them despite having health-related contraindications, Flyspot Group may collect certain personal data regarding the User’s health, habits, or lifestyle that may affect the User’s health or psychophysical abilities. Such data may include so-called special categories of personal data referred to in Article 9(1) of the GDPR. The processing of this type of data is related to ensuring the User’s safety, and, in particular, to inform the User about contraindications related to the use of a given Service and to obtain a statement from the User confirming that no such contraindications exist on their part or—if they do exist — for the purposes of any further communication with the User, including providing additional explanations, verifying any medical certificates, and similar purposes related to ensuring the safe use of the Services by Users.
(5) Special categories of personal data will be processed only if the User expressly agrees.
6. The Controller may process Users’ personal data for the purposes of marketing the Services, including profiling personal data for the aforementioned purposes, pursuant to Article 6(1)(f) of the GDPR, i.e., provided that the User may object to such processing at any time. Any processing of the User’s personal data for the purposes of third-party marketing may take place only with the User’s explicit consent.
(7) The Administrator’s sending of commercial information to the User by electronic means, if any, including the use of terminal equipment for the above purposes, shall be based on the consent given by the User.
8. In order to best tailor marketing messages and content on the Website to the User’s preferences, the Administrator may profile the User’s personal data. As part of this profiling, the Administrator may, in particular, analyze a given User’s activity history on the Website in order to send the User an offer to use the Service, a notification about an event, or other similar marketing information which, in the opinion of Flyspot Group —based on the profiling described above—is best suited to the User’s needs or interests.
9. In addition, Flyspot Group may process the User’s personal data, including profiling such data, for the purposes of compiling statistics, conducting market research, and analyzing consumer preferences, habits, and choices.
10. The profiling of Users’ personal data by Flyspot Group for the purposes indicated above will be based on Article 6(1)(f) of the GDPR, i.e., it may take place in situations where it is necessary for purposes arising from the legitimate interests pursued by the Controller or a third party, provided that such interests are not? subordinate to the User’s interests or fundamental rights and freedoms.
11. The profiling of personal data will not result in any legal effects for the User as referred to in Article 22(1) of the GDPR, nor will it otherwise have a similar significant impact on the User.
(12) You have the right to object at any time to the use of your personal data for the Administrator’s marketing purposes, including regarding the profiling of your personal data.
What personal data we process
1. The scope of personal data that Flyspot Group will actually process with respect to a given User will depend, in particular, on:
A) the extent of the data actually provided by the User
B) the nature of the Service or action that Flyspot Group performs at the User’s request; for example, sending a voucher in the form of a plastic card will require the User to provide a home address or other mailing address, whereas delivering a voucher in electronic form will require only an email address
C) the requirements of applicable laws, for example, the issuance of an invoice at the request of the User will require the provision of the relevant data required by the regulations, including the Taxpayer Identification Number or PESEL number.
D) the type of Service the User is using, such as:
(E) the use of the Boeing flight simulator, which does not involve any specific risks, will require a relatively narrower range of data than the use of DeepSpot deep pool diving services
F) the use of diving in DeepSpot does not require the User’s gender or size, but if the User additionally wishes to use the Foam Rental Service, the Administrator may process such data (gender, size) for the purpose of performing the above Service
G) additional features, offers, or other similar benefits that the User may wish to take advantage of in connection with the Services, e.g., The Administrator may offer the User a free T-shirt in connection with the purchase of another Service and ask the User about their gender or size in order to select the appropriate product (providing this type of data is always voluntary, and any refusal to provide it does not affect the User’s right to use the Services; at most, it may result in the User being unable to take advantage of additional offers or in those offers being less well-suited to the User).
2. Depending, in particular, on the aspects mentioned in paragraph 1 above, Flyspot Group may process all or some of the following personal data of the User:
A) name or nickname
B) residential or mailing address
C) e-mail address
D) telephone number
E) date of birth
F) gender
G) size
H) data on health status or habits or activities affecting health status
I) Tax ID or PESEL number
J) data from diving licenses or other similar documents proving the User’s authority, in particular, the license number, the organization under which it was issued, etc.
K) image
L) data generated by the Flyspot Group system, such as the customer number
M) data on the details of the User’s use of the Services, including the type of Services, the dates of their use, the cost of the Services purchased, etc.
N) for individuals who receive training services from Flyspot Group—additional data related to the certifications they are obtaining, such as their training history, number of dives, training progress, exam results, etc.
Who may be the recipient of your personal data
(1) Personal data may be entrusted or shared with the following categories of entities:
A) entities that Flyspot Group engages in connection with the provision of Services, for the purpose of carrying out processes related to the performance of the Services, such as IT system providers, couriers, instructors, and other entities with which Flyspot Group cooperates in this regard
B) other personal data controllers, in particular providers of training formats on the basis of which Flyspot Group provides its Services
(C) to persons or authorities who are authorized to access personal data in accordance with applicable law.
2. Flyspot Group may transfer Users’ personal data outside the European Economic Area (EEA). In such cases, Flyspot Group will ensure that a comparable level of data protection is provided in the third country by implementing one of the following safeguards:
(A) the transfer of personal data will take place to countries that the European Commission has recognized as providing an adequate level of protection for personal data
(B) The Administrator will use appropriate standard contractual clauses.
(C) As part of the exercise of Users’ rights, the Administrator will also ensure that a copy of appropriate safeguards for personal data can be obtained in the event of transfer to third countries.
User Rights
1. In connection with the processing of personal data by Flyspot Group, the User has the rights set forth in the GDPR.
(2) In particular, under the terms of the RODO, you have the right to:
A) access to personal data processed by the Administrator
B) request rectification of personal data – in case the data is incorrect or incomplete
C) requests to erase personal data (the so-called “right to be forgotten”) – where: (i) the User’s data is no longer necessary for the purposes for which it was collected or otherwise processed, (ii) the User has objected to the processing of personal data based on the Controller’s legitimate interest, including profiling, (iii) the User has withdrawn the consent on which the processing is based and there is no other legal basis for the processing, (iv) the data was processed unlawfully, (v) the data must be erased to comply with a legal obligation, (vi) the personal data was collected in connection with the provision of information society services referred to in Article 8(1) of the GDPR
D) to request the restriction of the processing of personal data if (i) the User disputes the accuracy of the personal data (for a period sufficient to allow the Controller to verify the accuracy of such data), (ii) the processing is unlawful, and the User objects to the erasure of the personal data, requesting instead that its use be restricted, (iii) the Controller no longer needs the personal data for the purposes of processing, but the User needs it to establish, exercise, or defend legal claims, (iv) the User has objected to the processing pursuant to Article 21(1) of the GDPR (until it is determined whether the Controller’s legitimate grounds override the User’s grounds for objection)
E) portability of personal data, in case the processing is carried out by automated means, on the basis of a contract concluded with the User or on the basis of consent expressed by the User
F) object to the processing of personal data, including profiling, in the case of the processing of personal data used for the purposes of realizing the legitimate interests of the Controller
G) to file a complaint with the supervisory authority, i.e., the President of the Personal Data Protection Office, if the User believes that the Controller’s processing of the User’s personal data violates the provisions of the GDPR.
3. To the extent that the User has consented to the processing of personal data, the User has the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of data processing carried out on the basis of consent prior to its withdrawal.
4. The user may submit requests or make statements regarding the exercise of the rights referred to in paragraphs 2 and 3 above, in particular to the Administrator’s email address specified in Article I, paragraph 3 of this Privacy Policy.
How long we will keep your personal information
1. For Users who have entered into a contract with the Administrator, personal data will be stored for the duration of the contract and, after its expiration, for a period no longer than that required by applicable law. In particular, if a User has requested that the Administrator issue an invoice, personal data will be stored for a period of five years from the end of the calendar year in which the invoice was issued.
2. If the User has filed a complaint regarding the provision of Services by the Administrator, or if it is justified for other reasons from the perspective of protecting the Administrator’s interests, the Administrator will retain the User’s personal data until the statute of limitations for the User’s claims against the Administrator expires. In the event of a dispute between Flyspot Group and the User, personal data will be retained until the dispute is finally resolved and any obligations awarded by a final court judgment or final administrative decision have been fulfilled, and, if necessary, until the statute of limitations for such awarded claims expires.
(3) To the extent that the processing of personal data is based on the premise of the necessity of the processing for purposes arising from legitimate interests pursued by the Administrator or by a? third party, the personal data will be stored no longer than until the User objects to the processing of his/her personal data (including their profiling), unless the Administrator demonstrates the existence of valid legitimate grounds for processing that override the interests, rights and freedoms of the User, such as, in particular, the establishment or assertion of claims or the defense against claims.
(4) To the extent that the processing of personal data is based on the premise of the User’s consent, personal data will be stored no longer than until the User revokes such consent, unless the Administrator has another valid legal basis for processing, including the storage of personal data.
(5) In the case of Users who have registered with the Service, personal data will be kept for the period of use of the Service, but the Administrator may delete personal data and the User’s account on the Service if the User has not used the Service for a period of 12 months or longer, including not logging into his/her account on the Service.
Image monitoring
1. If the User participates in flights in the FlySpot wind tunnel, the User’s image will be recorded by FlySpot Group to enable the User to obtain videos of the flight, which may also be sent, at the User’s request, to the email address provided by the User or may be copied by the User at the FlySpot facility onto a storage medium of the User’s choice, depending on the options currently offered by FlySpot Group in this regard. Video footage containing the User’s image is deleted 14 days after the date of recording.
2. Additional Services may also be available to Users at FlySpot and DeepSpot facilities, including the recording of the User’s image, e.g., while diving. Recordings containing images captured in connection with the provision of such additional Services will be deleted after 1 month.
3. A video surveillance system is in operation on the premises of FlySpot and DeepSpot to ensure the safety of individuals on the premises and to protect their property as well as that of the FlySpot Group. Personal data collected through video surveillance may be disclosed to entities authorized by law to access such data. The data controller retains surveillance recordings for a period not exceeding 3 months, with the proviso that recordings that may serve as evidence in legal proceedings may be retained for a longer period, until the proceedings are legally concluded. Upon the expiration of the above periods, video recordings obtained as a result of monitoring that contain personal data shall be destroyed, unless otherwise provided by separate regulations.
Relevant marketing techniques
1. The Administrator uses the Facebook pixel on the Website. The use of this technology allows Facebook to determine that a given User with a Facebook account is using the Website. In this case, Facebook relies on data for which it is the controller; that is, Flyspot Group does not transfer any additional personal data to Facebook for the aforementioned purposes. This technology relies on the use of cookies on the end device from which the User logs in to the Website. The collected data may be transferred outside the European Economic Area in accordance with the terms described in this Policy. The Facebook Pixel is activated only after the User consents to marketing cookies.
2. On the Website, the Administrator uses the TikTok Pixel, provided by TikTok Technology Limited (a TikTok group company that acts as the data controller for users in the European Economic Area). The use of this technology allows the provider to determine that a given User is using the Website, specifically visiting certain pages or performing certain actions (e.g., making a purchase, registering), and, in the case of Users with a TikTok account, it can associate these events with their account. In this case, the Provider relies on data for which it is the controller. The technology relies on the use of cookies (first-party and third-party) stored on the User’s device, which are used for advertising purposes, including measuring campaign effectiveness, creating audience groups (including remarketing and similar audience groups), and tailoring ads. The collected data may be transferred outside the European Economic Area in accordance with the terms described in this Policy. The TikTok pixel is activated only after the User has consented to marketing cookies.
3. On the Website, the Administrator uses the Snapchat pixel (Snap Pixel), provided by Snap Inc. The use of this technology allows Snap Inc. to obtain information indicating that a given User is using the Website, specifically, that they visit certain pages or perform specific actions (e.g., a purchase or registration), and in the case of Users with a Snapchat account, it may associate these events with their account. In this case, Snap Inc. relies on data for which it is the controller. The technology relies on the use of cookies (both first-party and third-party) stored on the User’s device, used for advertising purposes, including measuring campaign effectiveness, creating audience segments, and tailoring the ads displayed to the User. The collected data may be transferred outside the European Economic Area in accordance with the terms described in this Policy. The Snapchat pixel is activated only after the User has consented to marketing cookies.
4. On the Website, the Administrator uses the Reddit Pixel, provided by Reddit Inc. The use of this technology allows Reddit Inc. to obtain information indicating that a given User is using the Website, specifically, that they visit certain subpages or perform specific actions (e.g., a purchase, registration), and in the case of Users with a Reddit account, it may associate these events with their account. Reddit Inc. relies in this case on data for which it is the controller. The technology relies on the use of cookies (both first-party and third-party) stored on the User’s device, which are used for advertising purposes, including measuring campaign effectiveness, creating audience groups (including remarketing and lookalike audiences), and tailoring ads. The collected data may be transferred outside the European Economic Area in accordance with the terms described in this Policy. The Reddit pixel is activated only after the User has consented to marketing cookies.
Information about the use of cookies
1 The service uses cookies.
2. Cookies are IT data—specifically, text files—that are stored on a Website User’s end device and are intended for use with the Website’s pages. Cookies typically contain the name of the website they come from, their storage duration on the end device, and a unique number.
3. Flyspot Group is the entity that places cookies on the Website User’s end device and accesses them.
4. Cookies are used for the following purposes:
A) creation of statistics that help to understand how Users use the content of the Website, which allows to improve its structure and content
B) maintaining a session of the Service User (after logging in), so that the User does not have to re-enter his/her login and password on each sub-page of the Service.
C) determine the User’s profile in order to display content tailored to the User’s preferences on advertising networks, in particular the Google network.
D) The Website uses two main types of cookies: “session” cookies and “persistent” cookies.“Session” cookies are temporary files that are stored on the User’s device until the User logs out, leaves the website, or closes the software (web browser). “Persistent” cookies are stored on the User’s device for the period specified in the cookie settings or until the User deletes them.
5. Web browsing software (web browser) typically allows cookies to be stored on the User’s device by default. Website users can change these settings. The web browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this topic can be found in the web browser’s help section or documentation.
6. Restrictions on the use of cookies may affect certain features available on the Website.
7. If the User does not wish to receive cookies, they can change their browser settings. Disabling cookies that are necessary for authentication, security, and maintaining the User’s preferences may make it difficult—and in extreme cases, impossible—to use the Website.
8. To manage your cookie settings, select your web browser or operating system from the list below and follow the instructions:
A) Internet Explorer
B) Chrome
C) Safari
D) Firefox style=’>.
E) Opera
F) Android
G) Safari (iOS)
H) Windows Phone
9. Information about certain User behaviors is logged at the server level. This data is used solely for the purpose of administering the Website and ensuring the best possible quality of the Services provided.
10. the viewed resources of the Service are identified by URLs. In addition, the record may be subject to:
A) the arrival time of the query
(B) the time to send a response
C) the name of the User’s station – identification carried out by the http protocol
D) information about errors that occurred in the execution of http transactions
E) the URL address of the page previously visited by the User ( referer link) – in case the access to the Site was through a link
F) information about the user’s browser
G) IP address information.
(11) The above data are not associated with specific Users browsing the sites and are used only for the purpose of server administration.
Final provisions
(1) To the extent not regulated in the Privacy Policy, applicable laws, in particular the RODO, shall apply to the principles of personal data processing.