Privacy Policy

Privacy Policy

Mystery Inc. spolka z ograniczona odpowiedzialnoscia spolka komandytowa

(hereinafter: the "Policy")

§ 1. General provisions

  1. The provisions of this Policy set out the rules for processing and protecting the personal data of customers who are natural persons ("Personal Data") using the www.mysteryexpress.pl website (the "Website") to book an escape room and in connection with entering into and performing an agreement for access to a room under the Escape Room Terms and Conditions. They also apply to other data obtained in connection with use of the Website and services provided by the Controller, including the type, method and purpose of obtaining cookies.
  2. The controller of Personal Data is Mystery Inc. spolka z ograniczona odpowiedzialnoscia spolka komandytowa, with its registered office in Warsaw, address: ul. Przyjazni 79 A, 04-544 Warsaw, KRS No. 0000842615, NIP No. 9522206395 (the "Controller").
  3. Personal Data collected by the Controller is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR").
  4. For matters concerning Personal Data, the Controller may be contacted at ul. Przyjazni 79 A, 04-544 Warsaw or by e-mail at kontakt@mysteryexpress.pl.
  5. The Controller has implemented appropriate technical and organisational measures to ensure the security of data processing.
  6. Unless this Policy states otherwise, defined terms have the meanings assigned to them in the Escape Room Terms and Conditions.

§ 2. Legal basis, purposes and types of Personal Data processing

  1. The Controller collects information about natural persons in connection with their use of the Website, bookings, entering into and performing agreements, purchasing vouchers and using other services.
  2. Personal Data is processed for the following purposes:
    1. responding to enquiries, newsletters, cookies and use of a person's image, on the basis of consent under Article 6(1)(a) GDPR;
    2. entering into and performing an agreement, booking management and communication, under Article 6(1)(b) GDPR;
    3. compliance with legal obligations, including tax and accounting obligations, under Article 6(1)(c) GDPR;
    4. the Controller's legitimate interests, including:
      • pursuing and defending claims,
      • handling complaints,
      • marketing the Controller's own services,
      • statistical analysis and service development.
  3. The Controller processes data including:
    • first name and surname,
    • company details, where applicable,
    • NIP/REGON identification numbers,
    • e-mail address, telephone number and postal address,
    • payment data,
    • technical data, including IP address, browser and operating system,
    • image and voice data for monitoring or, with consent, marketing.
  4. Personal Data is not subject to profiling or automated decision-making.

§ 3. Disclosure and retention of Personal Data

  1. Personal Data may be disclosed to:
    • employees and contractors,
    • service providers, including IT, hosting, marketing and accounting providers,
    • public authorities,
    • the LockMe platform.
  2. Personal Data is retained:
    • until consent is withdrawn,
    • until an objection is raised,
    • for the duration of the agreement and related claims,
    • for periods required by law,
    • until the applicable limitation periods expire.
  3. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.

§ 4. Rights of data subjects

  1. The Customer has the right to:
    • access their Personal Data,
    • rectify it,
    • erase it,
    • restrict its processing,
    • data portability,
    • withdraw consent.
  2. The Customer has the right to object to processing.
  3. In the case of direct marketing, an objection results in the processing being stopped.
  4. The Controller responds to requests within one month, or within three months in exceptional cases.
  5. Complaints may be lodged with the President of the Polish Personal Data Protection Office (UODO).

§ 5. Source of Personal Data and requirement to provide it

  1. Personal Data is obtained from the Customer or from the LockMe platform.
  2. Providing Personal Data is voluntary but necessary to use the services.
  3. Failure to provide the required data prevents an agreement from being entered into or the services from being used.

§ 6. Cookies

  1. Cookies are files stored on a user's device to enable the Website to function correctly.
  2. The Controller uses cookies to:
    • maintain sessions,
    • personalise content,
    • perform statistical analysis.
  3. Types of cookies:
    • session cookies,
    • persistent cookies.
  4. Cookies do not identify a user without additional data.
  5. Cookies may be deleted or blocked in the browser:
  6. Disabling cookies may limit the functionality of the Website.
  7. Leaving browser settings unchanged constitutes consent to the use of cookies.
  8. The Controller is also the controller of data obtained through cookies.