This is an English translation provided for convenience. In the event of any discrepancy, the Polish version of the Privacy Policy prevails.
I. General provisions
- This Privacy Policy sets out the rules for collecting, processing, storing and protecting the personal data of Users of the website available at www.ferryconnect.pl (the “Website”).
- The Controller declares that it processes Users' personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, “GDPR”), and the Polish Act of 10 May 2018 on the Protection of Personal Data.
- The Controller takes particular care to protect the interests of data subjects and, in particular, ensures that the data it collects are processed lawfully, for specified and legitimate purposes, and are not further processed in a manner incompatible with those purposes.
II. Data controller
The controller of the personal data of Website Users is Affinity Poland Sp. z o.o. with its registered office in Warsaw, address: ul. Marszałkowska 107, 00-110 Warsaw, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0001251874, Tax ID (NIP): 5253096837, Statistical no. (REGON): 545220834 (the “Controller”). The Controller can be contacted by e-mail at support@ferryconnect.pl.
III. Purposes and legal bases of processing
- Registering and maintaining a User account on the Website and enabling sign-in – legal basis: Article 6(1)(b) GDPR (necessary for the performance of a contract for the provision of services by electronic means).
- Providing services, e-services, orders or carriage/booking contracts offered on the Website, including processing payments – legal basis: Article 6(1)(b) GDPR (necessary for the performance of a contract).
- Communicating with the User, including responding to quote requests submitted via contact forms – legal basis: Article 6(1)(f) GDPR (the Controller's legitimate interest in building customer relationships).
- Handling complaints – legal basis: Article 6(1)(c) GDPR (compliance with a legal obligation to which the Controller is subject).
- Fulfilling tax and accounting obligations (issuing invoices, keeping accounts) – legal basis: Article 6(1)(c) GDPR in conjunction with tax law.
- Sending newsletters and marketing information – legal basis: Article 6(1)(a) GDPR (the User's voluntary, explicit consent) in conjunction with the rules on the provision of services by electronic means and telecommunications law.
- The Controller's legitimate interest, including analytical and statistical activities, personalisation of offers (with consent), and pursuing or defending against claims (debt recovery) – legal basis: Article 6(1)(f) GDPR.
- Providing data is voluntary but necessary to conclude a contract or to use other features of the Website.
IV. Categories of personal data processed
Depending on how the Website is used, the Controller processes the following categories of Users' personal data: first and last name, home or company address, e-mail address, telephone number, Tax ID (NIP, for businesses), bank account number, masked payment card details (processed by the payment operator), and vehicle registration number (where required to book a ferry crossing).
V. Retention period
Personal data will be stored for as long as is necessary to achieve the purposes set out in section III:
- Data processed to perform a contract (including bookings) – for the duration of the contract and until the limitation periods for claims arising from it expire (generally 3 years for claims connected with business activity, in accordance with Article 118 of the Polish Civil Code).
- Data processed on the basis of consent (e.g. marketing, newsletter) – until the User withdraws consent.
- Data processed to comply with legal obligations (accounting, tax) – for the period required by tax law (as a rule 5 years from the end of the calendar year in which the tax payment deadline fell).
VI. Recipients of personal data
- Users' personal data may be disclosed only to entities authorised to receive them under the law and to trusted entities cooperating with the Controller in order to provide the services.
- Recipients may include, in particular: ferry/transport operators (necessary to complete a booking), electronic payment providers, IT and hosting providers, courier and postal companies, the accounting office and law firms.
- The Controller declares that Users' personal data are not transferred outside the European Economic Area (EEA). Should the nature of a booking (e.g. a ferry line outside the EEA) require it, any transfer will take place only with the appropriate safeguards required by the GDPR (Articles 44–49 GDPR), of which the User will be informed separately.
VII. Users' rights
- Every User has the right to:
- access their personal data and obtain a copy of it,
- rectify (correct) their data,
- have their data erased (the “right to be forgotten”) where there is no basis for further processing,
- restrict processing of their data,
- have their data transferred to another controller (data portability),
- object to processing (including profiling) based on the Controller's legitimate interest or carried out for direct marketing purposes,
- withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
- To exercise these rights, the User may contact the Controller by e-mail at support@ferryconnect.pl.
- The Controller responds to User requests without undue delay and no later than one month after receiving the request. In complex cases this period may be extended by a further two months, of which the User will be notified.
- The User has the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland) – if they consider that the processing of their personal data infringes the GDPR.
VIII. Cookies
- The Website uses cookies, i.e. small text files stored on the User's terminal device (e.g. computer, tablet, smartphone).
- Both session cookies (deleted when the browser is closed) and persistent cookies (stored for a defined period) are used. They serve to ensure the proper functioning of the Website and for statistical, analytical and marketing purposes.
- On the first visit to the Website the User is informed about the use of cookies and asked to consent to their installation.
- The User may change their cookie settings in their web browser or delete cookies at any time. Restricting the use of cookies may, however, affect some features available on the Website.
Detailed information about the cookies used on the Website is set out in the Cookie Policy.
IX. Automated decision-making and profiling
- Users' personal data will not be used to make decisions based solely on automated processing that would produce legal effects concerning the User or similarly significantly affect them.
- In order to tailor its offer and personalise content on the Website, the Controller may use profiling. Such profiling consists in analysing the User's behaviour on the site and does not produce any adverse legal effects for the User.
X. Final provisions
- The Controller reserves the right to amend this Privacy Policy, for example due to technological developments or changes in the law.
- Users will be informed of any changes in advance by publication of the new text of the Privacy Policy on the Website and, in the case of registered Users, by e-mail.
- This Privacy Policy applies from 24 August 2026.
Last updated: