Personal Data Processing Information (GDPR)

Below you will find privacy notices for each category of data subjects. Select the notice that applies to you. This document fulfils the information obligations under Articles 13 and 14 GDPR (Regulation (EU) 2016/679). Questions about data processing: rodo@etravel.pl.

This notice is addressed to individuals representing business entities (B2B clients or suppliers) – in particular: persons signing agreements with eTravel S.A., attorneys-in-fact, proxies, board members and other persons authorised to represent an organisation.

Your personal data was provided to us by the entity you represent – the company entering into or maintaining a business relationship with eTravel S.A. We are required to inform you about how we process that data (Article 14 GDPR).

Controller
eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Contact
Tel. +48 22 492 08 60, e-mail: sekretariat@etravel.pl
Data Protection Officer (DPO)
Contact the DPO at: rodo@etravel.pl

Your personal data (name, surname, job title, business e-mail address, phone number, information about your role and powers of attorney) was provided to us by the entity you represent, in connection with entering into or performing an agreement with eTravel S.A.

PurposeLegal basis (GDPR)
Verifying your authority to represent the entity (checking powers of attorney, proxy, company register entries)Art. 6(1)(f) – legitimate interests of the controller (ensuring legal security of agreements)
Entering into and performing an agreement: correspondence, document exchange, monitoring performance, settlements, issuing powers of attorney to act on behalf of eTravel S.A.Art. 6(1)(f) – legitimate interests of the controller (proper performance of the agreement with the entity you represent)
Asserting and defending claims (e.g. arising from non-performance of the agreement)Art. 6(1)(f) – legitimate interests of the controller
Anti-abuse, anti-corruption and conflict-of-interest complianceArt. 6(1)(f) – legitimate interests of the controller (business ethics and security)
Fulfilment of legal obligations (tax law, accounting, AML/CFT, construction law, market abuse regulation)Art. 6(1)(c) – legal obligation incumbent on eTravel S.A.

We may share your data with the following categories of recipients:

  • companies affiliated with eTravel S.A. within the capital group – where necessary for the performance of the agreement
  • IT service providers, document archiving and destruction providers, law firms and advisors
  • postal and courier service providers
  • financial institutions involved in settlements
  • public authorities – where required by law

We process your data for the duration of the agreement with the entity you represent and thereafter for the period necessary to settle the agreement and pursue potential claims (generally no longer than 6 years from the end of the agreement, in view of general limitation periods and archiving obligations). Data processed to fulfil legal obligations (e.g. accounting records) is retained for the periods required by applicable law.

  • right of access to your data (Art. 15 GDPR)
  • right to rectification of inaccurate data (Art. 16 GDPR)
  • right to erasure – to the extent permitted by law (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to object to processing based on legitimate interests – on grounds relating to your particular situation (Art. 21 GDPR)
  • right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl

To exercise your rights, contact us at: rodo@etravel.pl or in writing to the registered address of eTravel S.A.

This notice is addressed to individuals using travel services provided by eTravel S.A. – both those who make reservations themselves and those whose bookings are made by another person (e.g. a travel booker employed by a company that has an agreement with eTravel S.A.).

If you did not make your booking yourself, your personal data may have been provided to us by your employer or by the person who made the booking. In that case, this notice fulfils the information obligation under Article 14 GDPR.

Controller
eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Contact
Tel. +48 22 492 08 60, e-mail: sekretariat@etravel.pl
Data Protection Officer (DPO)
Contact the DPO at: rodo@etravel.pl

Depending on the type of service ordered, we process data including:

  • identity data: name, surname, date of birth, gender, identity document/passport number, nationality
  • contact data: e-mail address, phone number
  • travel data: seat preferences, hotel preferences, meal preferences, special requirements arising from health conditions (e.g. special diet, gluten-free meal, wheelchair assistance – these may constitute special category data)
  • payment data: to the extent necessary to settle the service
  • loyalty programme data (if provided)

Health-related data (e.g. special diet, gluten-free meal, need for boarding assistance) constitutes special category data within the meaning of Art. 9 GDPR. We process such data only on the basis of your explicit consent (Art. 9(2)(a) GDPR) or where necessary to protect your vital interests (Art. 9(2)(c) GDPR).

PurposeLegal basis (GDPR)
Preparing a quote, making reservations (flights, hotels, transport, transfers, insurance) and performing the travel service orderedArt. 6(1)(b) – performance of a contract / pre-contractual steps
Transferring data to service providers (airlines, hotels, car rental companies, insurers) – required to fulfil the bookingArt. 6(1)(b) – performance of a contract
After-sales support: amendments, cancellations, complaints, claims handling, call centre and emergency helplineArt. 6(1)(b) – performance of a contract; Art. 6(1)(f) – legitimate interests (customer service and claims)
Protecting your health, life and property during travel (e.g. emergency line, crisis situations)Art. 6(1)(d) – protection of the vital interests of the data subject
Running loyalty programmes (our own or those of service providers)Art. 6(1)(a) – consent
Direct marketing (offers to existing clients)Art. 6(1)(f) – legitimate interests (marketing to existing clients); you have the right to object
Sending commercial information electronically (if you have given consent)Art. 6(1)(a) – consent (Electronic Services Act)
Administrative purposes, sales reporting, fraud prevention, service improvementArt. 6(1)(f) – legitimate interests of the controller
Complying with requirements of competent public authoritiesArt. 6(1)(c) – legal obligation

To fulfil your booking, data is transferred to:

  • airlines, hotels, hotel chains, car rental companies, transport companies, shipping companies, rail operators
  • insurance companies
  • reservation system providers (GDS: Amadeus, Sabre, Galileo and others)
  • visa intermediaries (where applicable)
  • financial institutions handling payments
  • IT and call centre service providers
  • law firms
  • public administration authorities

Transfers outside the European Economic Area (EEA): Providing travel services frequently requires transferring data to countries outside the EEA (e.g. airlines, hotels or reservation systems headquartered outside the EU). Such transfers are made with appropriate safeguards in place: Standard Contractual Clauses approved by the European Commission or, where necessary, on the basis of the derogation under Art. 49(1)(b) GDPR (performance of a contract with the data subject). You are entitled to obtain information about the safeguards applied – please contact us.

We retain your data for the period necessary to perform the service and thereafter:

  • for the limitation period for claims under the agreement (generally 3 years for travel service claims, 6 years for general civil claims)
  • financial records: 5 years from the end of the financial year, in accordance with accounting legislation
  • data processed on the basis of consent: until consent is withdrawn
  • upon expiry of the above periods, data is deleted or anonymised

  • right of access to data (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR) – subject to exceptions, e.g. where processing is necessary to assert claims
  • right to restriction of processing (Art. 18 GDPR)
  • right to data portability (Art. 20 GDPR)
  • right to object to processing based on legitimate interests (Art. 21 GDPR)
  • right to withdraw consent at any time – without affecting the lawfulness of processing carried out before withdrawal
  • right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland

Providing your data is voluntary but necessary to fulfil the travel service you have ordered. Without your data, we cannot complete the booking.

Contact for data protection matters: rodo@etravel.pl

This notice is addressed to individuals holding a user account on the CTA (Corporate Travel Application) platform – an online travel booking system offered by eTravel S.A. in a SaaS model.

CTA is an online platform for managing corporate travel bookings. Your user account is created by a system administrator on your employer's side or by eTravel S.A. under its agreement with your employer.

Controller
eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Contact
Tel. +48 22 492 08 60, e-mail: sekretariat@etravel.pl
Data Protection Officer (DPO)
Contact the DPO at: rodo@etravel.pl
Relationship with your employer
eTravel S.A. is the data controller for platform user data. Your employer, as an eTravel S.A. B2B client, may be a separate controller for data relating to your travel policy and authorisations.

As part of your CTA user account, we process:

  • identity data: name, surname, login (e-mail address or work identifier)
  • travel document data: passport/ID number, expiry date, nationality
  • travel preferences: travel class, seat preferences, meal preferences, hotel chain preferences, loyalty programme numbers
  • contact data: work phone number, work e-mail address
  • data required by your employer's travel policy: cost centre, project code, department, approver
  • history of bookings and transactions made via the platform
  • login and activity data (system logs, date of last login)

PurposeLegal basis (GDPR)
Providing the SaaS service – maintaining the user account, enabling travel search and booking, managing profile preferencesArt. 6(1)(b) – performance of a contract (between eTravel S.A. and your employer, the services of which you use as a user)
Automatic application of your employer's travel policy during search and booking (e.g. displaying only in-policy options)Art. 6(1)(f) – legitimate interests of the controller (fulfilling the agreement with your employer and ensuring travel policy compliance)
Generating travel reports and analytics (for your employer and system administrators)Art. 6(1)(f) – legitimate interests (travel programme management and settlements)
Ensuring system security and preventing abuse (access logs, activity monitoring)Art. 6(1)(f) – legitimate interests (IT system security)
Improving platform functionality and providing technical supportArt. 6(1)(f) – legitimate interests of the controller
Handling support tickets and help desk requestsArt. 6(1)(b) – performance of a contract / Art. 6(1)(f) – legitimate interests
Fulfilling legal obligations (transaction records, tax settlements)Art. 6(1)(c) – legal obligation

Your data may be shared with:

  • your employer (eTravel S.A.'s client) – in the scope of travel reports, authorisations and travel programme management
  • travel service providers (airlines, hotels, car rental companies) – solely for the purpose of making a booking
  • reservation system providers (GDS)
  • IT and hosting service providers (processing data under data processing agreements)
  • public administration authorities – as required by law

Data may be processed on servers located within the EEA or outside the EEA, with appropriate data transfer mechanisms in place (Standard Contractual Clauses). Detailed information about data processing locations and safeguards is available on request at: rodo@etravel.pl.

  • user account data: for the duration of the active account and for 12 months after deactivation (for potential claims and audits)
  • booking and transaction history: 6 years from the end of the financial year (tax and accounting obligations)
  • system logs and activity data: 12 months, extendable in the event of a security incident
  • data processed on the basis of consent: until consent is withdrawn

  • right to access and view your profile data (Art. 15 GDPR)
  • right to rectify inaccurate or incomplete data (Art. 16 GDPR)
  • right to erasure of data after account deactivation – to the extent legally permissible (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to object to processing based on legitimate interests (Art. 21 GDPR)
  • right to lodge a complaint with the President of the Personal Data Protection Office (UODO)

Contact: rodo@etravel.pl or in writing to the registered address of eTravel S.A.

This notice is addressed to employees and associates of companies (B2B clients of eTravel S.A.) who are not representatives signing agreements but who participate in the performance of the agreement – in particular: persons placing orders for travel services, persons designated as contact points with eTravel S.A., persons receiving invoices and correspondence, persons approving bookings, travel coordinators.

Your personal data was provided to us by your employer – the company that has entered into an agreement with eTravel S.A. We are fulfilling our information obligation towards you under Article 14 GDPR.

Controller
eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Contact
Tel. +48 22 492 08 60, e-mail: sekretariat@etravel.pl
Data Protection Officer (DPO)
Contact the DPO at: rodo@etravel.pl

Your contact details (name, surname, job title, work e-mail, phone number) were provided to us by your employer in connection with the performance of a cooperation agreement. This data is necessary for the proper handling of orders and delivery of services.

PurposeLegal basis (GDPR)
Handling orders and bookings placed on behalf of your employer (or for your employer's employees)Art. 6(1)(f) – legitimate interests of the controller (performance of the agreement with your employer)
Day-to-day contact in matters related to the performance of the agreement (correspondence, phone, e-mail)Art. 6(1)(f) – legitimate interests of the controller
Issuing, sending and processing invoices and settlement documentationArt. 6(1)(f) – legitimate interests / Art. 6(1)(c) – legal obligation (accounting legislation)
Sending information related to ordered services (confirmations, amendments, notifications)Art. 6(1)(f) – legitimate interests of the controller
Handling complaints and claimsArt. 6(1)(f) – legitimate interests of the controller
Archiving documentation related to the performance of the agreementArt. 6(1)(c) – legal obligation (accounting legislation) / Art. 6(1)(f) – legitimate interests

Your data may be shared with:

  • travel service providers – to the extent necessary to deliver the services ordered
  • IT system service providers supporting eTravel S.A.
  • postal and courier service providers
  • law firms acting for eTravel S.A.
  • public administration authorities – as required by law

We process your data for the duration of the agreement with your employer and for the period necessary after its termination:

  • for the purpose of asserting claims: for the duration of the limitation period (generally 3–6 years)
  • financial and accounting records: 5 years from the end of the financial year
  • upon expiry of these periods, data is deleted or anonymised

  • right of access to data (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR) – to the extent legally permissible
  • right to restriction of processing (Art. 18 GDPR)
  • right to object to processing based on legitimate interests (Art. 21 GDPR)
  • right to lodge a complaint with the President of the Personal Data Protection Office (UODO)

Contact: rodo@etravel.pl or in writing to the registered address of eTravel S.A.

This notice is addressed to individuals participating in recruitment processes conducted by eTravel S.A.

Controller
eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Contact
Tel. +48 22 492 08 60, e-mail: sekretariat@etravel.pl
Data Protection Officer (DPO)
Contact the DPO at: rodo@etravel.pl

We process the data you provide during the recruitment process, including:

  • identity and contact data: name, surname, e-mail address, phone number, residential address
  • professional data: career history, qualifications, education, language skills, experience, references
  • other data voluntarily provided in your CV or during a recruitment interview

Please do not provide us with special category data (e.g. relating to health, religion or political affiliation) unless required by law. Polish Labour Code provisions define a closed list of data we may request from candidates. We collect only data that is necessary to assess your application.

PurposeLegal basis (GDPR)
Conducting the recruitment process for a specific position – verifying and assessing the applicationArt. 6(1)(b) – pre-contractual steps at the request of the data subject; Art. 6(1)(c) – legal obligation (Polish Labour Code, Art. 22¹)
Conducting future recruitment processes (talent pool) – only with the applicant's separate consentArt. 6(1)(a) – consent (separate and voluntary)
Defending against potential claims arising from the recruitment processArt. 6(1)(f) – legitimate interests of the controller

Providing data covered by Art. 22¹ of the Labour Code is voluntary but necessary to participate in the recruitment process. Providing data beyond that scope (e.g. for inclusion in a talent pool) is voluntary and requires your separate consent.

Your data may be shared with:

  • applicant tracking system (ATS) providers – under data processing agreements
  • external recruitment agencies cooperating with eTravel S.A. (where the recruitment is conducted in cooperation with an agency)
  • public administration authorities – as required by law

  • data of candidates participating in the current recruitment: for the duration of the recruitment process and up to 3 months after its conclusion (potential limitation period for equal treatment claims)
  • data of candidates who consented to future recruitment: for 12 months from the date of consent or until consent is withdrawn

  • right of access to data (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to object to processing based on legitimate interests (Art. 21 GDPR)
  • right to withdraw consent at any time – without affecting the lawfulness of processing before withdrawal
  • right to lodge a complaint with the President of the Personal Data Protection Office (UODO)

Contact: rodo@etravel.pl or in writing to the registered address of eTravel S.A.

This notice is addressed to individuals who have subscribed to the eTravel S.A. newsletter or have consented to receiving commercial and marketing information electronically.

Controller
eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Contact
Tel. +48 22 492 08 60, e-mail: sekretariat@etravel.pl
Data Protection Officer (DPO)
Contact the DPO at: rodo@etravel.pl

  • e-mail address (required to send the newsletter)
  • first name (optional – for message personalisation)
  • date and time of subscription and confirmation (double opt-in)
  • technical data: content preferences (if provided at the time of sign-up)

PurposeLegal basis (GDPR)
Sending the newsletter – information about services, promotions and the current offer of eTravel S.A. and affiliated entitiesArt. 6(1)(a) GDPR – your consent; Art. 10(2) of the Act on Electronic Services – consent to e-mail marketing communication
Analysing the effectiveness of communications sent (open and click statistics) – to improve newsletter contentArt. 6(1)(f) – legitimate interests (optimising communications); you have the right to object
Documenting consents given (defending against potential claims)Art. 6(1)(f) – legitimate interests of the controller

Consenting to receive the newsletter is voluntary and you may withdraw your consent at any time by clicking the unsubscribe link in any e-mail or by writing to us at rodo@etravel.pl. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Your data may be shared with:

  • e-mail delivery and marketing automation platform providers – under data processing agreements
  • analytics service providers (in the scope of newsletter statistics)

Where marketing tool providers process data outside the EEA, we apply appropriate safeguards (Standard Contractual Clauses).

  • active subscriber data: for the entire duration of the subscription
  • after unsubscribing: data is deleted or anonymised within 30 days, except for data required to document consent history and unsubscription (retained for 3 years after unsubscription – for evidentiary purposes)

  • right of access to data (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to object to processing based on legitimate interests – e.g. analytical profiling (Art. 21 GDPR)
  • right to withdraw consent at any time (without affecting prior processing)
  • right to lodge a complaint with the President of the Personal Data Protection Office (UODO)

Contact: rodo@etravel.pl or in writing to the registered address of eTravel S.A.

This notice is addressed to individuals with whom eTravel S.A. establishes contact for business purposes (networking, business development, industry partners), and to participants of events, conferences and meetings organised or co-organised by eTravel S.A. (including as part of MICE activities).

Controller
eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Contact
Tel. +48 22 492 08 60, e-mail: sekretariat@etravel.pl
Data Protection Officer (DPO)
Contact the DPO at: rodo@etravel.pl

Your data may originate from:

  • directly from you – when you contact us, leave a business card or register for an event
  • public sources – e.g. LinkedIn, company websites, public registers
  • the event organiser – if you attend an event that eTravel S.A. co-organises

Scope of data processed: name, surname, job title, company, work e-mail address, work phone number, information about participation in the event.

PurposeLegal basis (GDPR)
Establishing and maintaining business relationships, contact regarding eTravel S.A.'s offerArt. 6(1)(f) – legitimate interests (B2B marketing, business relationships); you have the right to object
Organising events or conferences and managing participants (logistics, communications, materials)Art. 6(1)(b) – pre-contractual steps / Art. 6(1)(f) – legitimate interests
Sending information about future events, training sessions and webinars to previous attendeesArt. 6(1)(f) – legitimate interests (B2B marketing to existing contacts); you have the right to object
Photo or video documentation of an event (if you were present and did not object)Art. 6(1)(f) – legitimate interests (event documentation and promotion)
Sending commercial information electronically – with your consentArt. 6(1)(a) – consent (Electronic Services Act)

  • event and MICE service providers cooperating with eTravel S.A.
  • IT and event management system providers (CRM, webinar platforms)
  • entities within the eTravel S.A. capital group

  • business contact data: 3 years from the last contact or until an objection is raised
  • event participant data: 2 years from the conclusion of the event (statistics, attendee lists)
  • data processed on the basis of consent: until consent is withdrawn

  • right of access to data (Art. 15 GDPR)
  • right to rectification (Art. 16 GDPR)
  • right to erasure (Art. 17 GDPR)
  • right to restriction of processing (Art. 18 GDPR)
  • right to object to processing based on legitimate interests – in particular to direct marketing (Art. 21 GDPR)
  • right to withdraw consent (where processing is based on consent)
  • right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, www.uodo.gov.pl

Contact: rodo@etravel.pl or in writing to the registered address of eTravel S.A.

Final Notes – Legal Information

Legal Basis of This Document

This document fulfils information obligations arising from:

  • Art. 13 GDPR – where data is collected directly from the data subject
  • Art. 14 GDPR – where data is collected from another person or entity (e.g. the traveller's employer, the client company)
  • Art. 12 GDPR – requirement for transparency and intelligibility of information

Updates to This Document

eTravel S.A. reserves the right to update this document in the event of changes to its data processing activities, changes in applicable law or guidance issued by supervisory authorities. The current version is always available at: etravel.pl/en/rodo. We will communicate material changes in a manner appropriate for each category of data subjects (e.g. by e-mail for CTA users, by a notice on our website for others).

Contact and Exercising Your Rights

E-mail (recommended)
rodo@etravel.pl
Phone
+48 22 492 08 05
Postal address
Data Protection Officer, eTravel S.A., Al. Jerozolimskie 96, 00-807 Warsaw, Poland
Response time
No later than 30 days of receiving a request (Art. 12 GDPR); in complex cases the period may be extended by a further 2 months
Supervisory authority
President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, tel. +48 606 950 000, www.uodo.gov.pl