Privacy Policy
We pay attention to every detail of your story, and protecting your data is a natural extension of our hospitality.
Privacy Policy of Dzień i Noc
Website: dzieninoc.com
Effective Date: March 1, 2025
1. Data Controller
The controller of your personal data is DZIEN I NOC sp. z o.o., headquartered in Warsaw at ul. Twarda 18, 00-105 Warsaw, entered into the Register of Entrepreneurs of the National Court Register (KRS) under number 0000859829, NIP: 5252836315, REGON: 387060108.
Contact for data protection matters: hello@dzieninoc.com
The Controller conducts restaurant, entertainment, and event operations (Dzień i Noc restaurant and club in Hala Mirowska).
2. Scope of Processed Data
We process data to the extent necessary to serve our guests and provide our services:
- Identification and contact details (e.g., table reservations or event inquiries).
- Billing and invoicing data.
- Data regarding reservations and participation in events hosted at the venue.
- Technical data, including IP address, device identifiers, and cookie data.
- Image captured in photos and event recordings.
- Data contained in email correspondence and contact forms.
3. Purposes and Legal Bases of Processing
Data is processed for the following purposes:
- Accepting reservations, delivering catering services, and organizing events pursuant to Art. 6(1)(b) GDPR.
- Fulfilling accounting and tax obligations pursuant to Art. 6(1)(c) GDPR.
- Establishing, pursuing, or defending legal claims pursuant to Art. 6(1)(f) GDPR.
- Marketing our own services based on Art. 6(1)(f) GDPR (our legitimate interest).
- Sending newsletters based on Art. 6(1)(a) GDPR (where consent has been given).
- Ensuring safety of individuals and property pursuant to Art. 6(1)(f) GDPR.
4. Video Surveillance (CCTV)
The restaurant, bar, club, and event spaces at Dzień i Noc are monitored via video surveillance.
Monitoring is conducted to:
- Ensure the safety of guests and staff,
- Protect the Controller’s property,
- Prevent unlawful acts,
- Secure evidence for potential claims.
Recordings are stored for up to 30 days unless required as evidence in proceedings. Video surveillance does not cover restroom facilities. Any person present in the monitored area acknowledges the recording of their image.
5. Image Publication
During weekend club nights, live performances, and selected venue events, promotional photos and videos may be taken. The Controller may publish this material on social media, the website, and marketing collateral.
Any guest who does not consent to the publication of their image should report this directly to the photographer, floor manager, or staff during the event.
6. Data Recipients
Data may be shared with external partners solely to the extent necessary to operate the venue and provide services:
- Reservation system providers,
- Electronic payment processors,
- Hosting and IT infrastructure providers,
- Accounting agency,
- Security firm,
- Event co-organizers (e.g., event agencies for private functions).
These parties process data on the basis of data processing agreements.
7. Data Transfers Outside the EEA
As a rule, data is not transferred outside the European Economic Area (EEA). If global vendor tools are used (e.g., website analytics, social media), transfers take place using Standard Contractual Clauses or other GDPR-compliant mechanisms.
8. Data Retention Period
Data is stored:
- For the duration of the reservation/contract and until the expiration of potential legal claims,
- For the period required by tax regulations (billing data),
- Until consent is withdrawn in the case of marketing activities,
- For the duration necessary to ensure safety (CCTV up to 30 days).
9. Data Subject Rights
Every individual has the right to:
- Access their data,
- Rectify data,
- Erase data (“right to be forgotten”),
- Restrict processing,
- Data portability,
- Object to processing,
- Withdraw consent at any time,
- File a complaint with the President of the Personal Data Protection Office (UODO).
10. Limitation of Liability
The Controller is not liable for:
- False data provided by the user in the contact form,
- Data shared with third parties directly by the user,
- Actions of external payment processors compliant with their terms and conditions.
Using the website and placing reservations implies acceptance of this policy.
11. Data Security
The Controller applies technical and organizational measures to ensure a high level of protection, including SSL certificates on the website, access control to reservation systems, restricted staff privileges, and regular system backups.
12. Amendments to this Document
The Controller reserves the right to update this Privacy Policy. The current version is always available on the website.
