Version 1
Effective from: 3 September 2026

Privacy Policy

The purpose of this Privacy Policy is to provide information about the principles of privacy protection when using the website and services offered by Skybar49.

Data Controller

The controller of personal data is KPK INVESTMENTS Sp. z o.o., with its registered office in Wrocław (50-062) at: Pl. Solny 15, tax ID (NIP) 8971931231, statistical number (REGON) 527228910, court register number (KRS) 0001076226.

The venue to which the services relate is located on the 49th floor of Sky Tower at ul. Gwiaździsta 64, 53-413 Wrocław, Poland.

The Data Controller informs that the personal data provided will be processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, namely in accordance with the General Data Protection Regulation (GDPR).

Purpose of Data Collection

The collected personal data is necessary to prepare an offer, contact the Guest or Client, make a reservation, and provide the services offered by Skybar49.

Providing personal data and consenting to its processing is voluntary, however it may be necessary in order to make a reservation, obtain a response to an inquiry, or perform a service.

Legal Basis for Processing

Personal data may be processed in particular in connection with:

  • the reservation process carried out through the website skybar49.pl,
  • the reservation process carried out by phone, email, or in person,
  • contact via the contact form,
  • handling inquiries regarding the offer, events, reservations, or services,
  • organizing events, meetings, special occasions, or other services offered by Skybar49,
  • data obtained from business partners or external booking systems (if applicable).

Scope of Processed Data

The Controller may process the following personal data:

  • first and last name,
  • phone number,
  • email address,
  • data necessary to make a reservation: date, time, number of guests, selected table or zone, language of correspondence,
  • the IP address of the device used to make the reservation — recorded for technical reasons, to prevent the same booking being submitted more than once,
  • for reservations covered by a prepayment: the amount, status and date of the transfer, and the information needed to match it to the reservation,
  • data provided in the message content or contact form,
  • other data voluntarily provided by the Guest or Client in connection with a reservation or contact, including booking notes.

Please do not enter health information, including food allergies, in the notes field. Such data falls into the special category under Article 9 GDPR and is subject to stricter protection. Please pass anything relevant to our staff by phone when confirming the reservation.

Purposes of Processing

Personal data will be processed for the purpose of:

  • responding to submitted inquiries,
  • making and handling reservations,
  • providing services offered by Skybar49,
  • contacting the Client regarding a reservation or service,
  • fulfilling obligations arising from legal provisions, including accounting obligations,
  • possible establishment, exercise, or defense of legal claims.

Data Sharing

Personal data may be transferred to entities cooperating with the Controller only to the extent necessary to achieve the above purposes, in particular entities providing:

  • IT services,
  • hosting and data storage services,
  • accounting services,
  • legal services,
  • reservation services,
  • SMS and email delivery services,
  • payment services (if applicable).

A current list of the processors acting on the Controller's behalf is available on request, at the address given in the "Contact" section.

Data Retention Period

Personal data will be stored for the period necessary to achieve the purpose for which it was collected, as well as for the period required by law or necessary to secure possible claims. In particular:

  • data identifying the Guest (name, phone number, email address, booking notes, IP address) is erased automatically 12 months after the reservation date, or, for cancelled reservations, 12 months after the cancellation;
  • accounting records relating to prepayments (amount, date and status of the transfer) are retained for the period required by accounting law, with the Guest's identifying data removed;
  • backup copies of the system are retained for 30 days and then permanently deleted.

Identifying data is erased by permanently overwriting it rather than by deleting the reservation record. After this operation the system retains the fact that a reservation took place and was settled, with no way to establish whom it concerned.

Backups

The Controller performs daily backups. They are stored in a separate, non-public repository within the European Union, and access to them requires authentication.

Fulfilling an erasure request does not immediately remove the data from backups made earlier — those backups are deleted automatically after 30 days. At the same time, restoring the system from a backup does not bring erased data back: the Controller maintains a record of completed erasures, on the basis of which the data covered by a request is erased again, automatically, after every restore.

Rights of Data Subjects

Every person whose data is processed has the right to:

  • access their data,
  • rectify their data,
  • erase their data,
  • restrict the processing of their data,
  • transfer their data,
  • object to the processing of their data,
  • withdraw consent at any time, if processing is based on consent,
  • lodge a complaint with the President of the Personal Data Protection Office.

Exercising the right to erasure

An erasure request is carried out promptly after it is submitted to the address given in the "Contact" section. Please quote the reservation code or the phone number used to book — this allows all of that person's reservations to be found.

Fulfilment of a request is subject to two limitations arising from Article 17(3) GDPR:

  • if the reservation has not yet taken place, erasing the data cancels it, because it cannot be serviced without contact details;
  • if an unsettled prepayment is attached to the reservation, the request is deferred until the transfer is booked or cancelled. Without identifying data it would be impossible to match the transfer to the reservation, or to refund it.

The name of the person making a bank transfer also appears in the Controller's banking records, which form a separate set governed by accounting law and are not covered by this Policy.

Contact

In matters related to the processing of personal data, you may contact the Controller by email at skybarwroclaw@gmail.com or by phone at +48 795 222 777.