Pricing About me Contact Booking
TomProPhoto · Legal documents

Privacy
Policy

Data ControllerOLWOT Mariusz Rusecki, ul. Panny 7, 03-668 Warsaw
NIP / REGON5242518039 / 360993752
Last updated18 February 2026
Contacthello@tomprophoto.pl

This Privacy Policy of OLWOT Mariusz Rusecki ("we", "us" or "our") describes how and why we may access, collect, store, use and/or share ("process") your personal data when you use our services, including when you visit tomprophoto.pl or any other of our sites that links to this Policy.

How do we protect your data? We have appropriate organisational and technical measures in place to protect personal data. However, no transmission over the internet or storage technology can guarantee 100% security.

What are your rights? Depending on your location, applicable law may grant you certain rights regarding your personal data. The simplest way to exercise them is to contact us at hello@tomprophoto.pl.

[01]

What information do we collect?

In short: we collect personal data that you provide to us, and certain data automatically.

We collect personal data that you voluntarily provide to us when you express interest in obtaining information about our services or otherwise contact us. We may collect the following data:

  • first and last names
  • email addresses
  • postal addresses
  • phone numbers
  • Transaction data: order number, transaction value, payment status — payment card details are processed directly by the payment operator Mollie B.V. (Keizersgracht 313, 1016 EE Amsterdam) and are not stored by the Controller

Sensitive data. We do not process sensitive data.

Information collected automatically

We automatically collect certain information when you visit our sites: IP address, browser and device characteristics, operating system, language preferences, referring URLs, country, location and other technical data.

  • Log and usage data — service-related, diagnostic and performance information recorded by the servers
  • Device data — hardware model, operating system, internet provider, system configuration
  • Location data — approximate geolocation data based on your IP address or device settings
Google API

Our use of data obtained through Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.

[02]

How do we process your information?

In short: we process data to provide our services, communicate with you and meet our legal obligations.

We process your personal data for various reasons, depending on how you use our services:

  • Providing services — operating the Amelia online booking system, issuing gift vouchers and carrying out photo sessions
  • Communication between users — processing data when you use the contact features
  • Protecting vital interests — where necessary for a person's safety
[03]

Which legal bases do we rely on?

In short: we only process data when we have a valid legal reason to do so — your consent, performance of a contract, a legal obligation or a vital interest.

The GDPR requires us to explain the legal bases for processing. We rely on the following bases:

  • Consent — we may process your data if you have given consent for a specific purpose; you can withdraw it at any time
  • Performance of a contract — where processing is necessary to perform a contract concluded with you or to provide services
  • Legal obligations — where processing is necessary to fulfil legal obligations, e.g. cooperation with law enforcement authorities
  • Vital interests — where processing is necessary to protect your vital interests or those of a third party
[04]

When and with whom do we share data?

In short: we may share data in specific situations and with selected categories of third parties.

We may share data with external vendors, service providers or agents who perform services on our behalf. We have agreements requiring them to protect your data and not to share it with third parties.

  • Hosting service providers — to the extent necessary to maintain the site
  • Mollie B.V. (Keizersgracht 313, 1016 EE Amsterdam) — payment operator; your transaction data (first name, last name, email) is shared in order to process payments for bookings and vouchers; Mollie acts as an independent data controller
  • Google Maps Platform — we may share data with certain Google Maps APIs
  • Business transactions — in connection with a possible merger, sale of assets or acquisition of the business
[05]

Do we use cookies?

In short: we may use cookies and similar tracking technologies.

We may use cookies and similar technologies (web beacons, pixels) to collect information when you use our services. They help provide security, prevent failures, remember preferences and support the site's core functions.

We also permit third parties to use tracking technologies for analytics and advertising purposes, including tailoring content to your interests. Detailed information is contained in our Cookie Notice available on the site.

Google Analytics

We may share data with Google Analytics to monitor and analyse how our services are used, including remarketing, Display Network impression reporting and demographic reports.

To opt out of tracking by Google Analytics, visit tools.google.com/dlpage/gaoptout. More information: Google Privacy & Terms.

[06]

How long do we keep data?

In short: we keep data for as long as necessary to fulfil the purposes set out in this policy.

We will retain your personal data only for as long as necessary to fulfil the purposes set out in this Policy, unless a longer period is required or permitted by law (e.g. tax or accounting regulations).

When we no longer have a legitimate need to continue processing, we will delete or anonymise the data. If this is not possible (e.g. data held in backups), we will store it securely and isolate it from any further processing until deletion becomes possible.

[07]

How do we protect your data?

In short: we make efforts to protect data through organisational and technical measures.

We have implemented appropriate technical and organisational measures designed to protect the personal data we process. Despite our safeguards, we cannot guarantee that data transmission over the internet will be 100% secure.

We recommend using our services only in a secure environment.

[08]

Do we collect data from minors?

In short: we do not knowingly collect data from children under 18 years of age.

We do not knowingly collect, solicit or market to children under 18 years of age. By using our services, you represent that you are at least 18 years old or that you are the parent/guardian of a minor and consent to their use of the services.

If we learn that we have collected data from a person under 18 years of age, we will deactivate the account and promptly delete that data. If you suspect this to be the case, please contact us: hello@tomprophoto.pl.

[09]

What privacy rights do you have?

In short: in the EEA, UK and Switzerland you have rights that give you access to and control over your data.

In certain regions (EEA, UK, Switzerland) you have rights under data protection law:

  • to request access to and obtain a copy of your personal data
  • to request rectification or erasure of your data
  • to restrict the processing of your data
  • to data portability (where applicable)
  • to object to decisions based solely on automated processing

If you reside in the EEA or UK and believe we are processing your data unlawfully, you may lodge a complaint with your national data protection authority or the UK data protection authority (ICO). In Switzerland: the Federal Data Protection Commissioner.

Withdrawing consent: if we process your data on the basis of consent, you may withdraw it at any time by contacting us. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

Opting out of marketing communications: you can opt out by clicking the unsubscribe link in emails or by contacting us. We may still contact you on matters necessary to operate the services.

Cookies: most browsers accept cookies by default. You can set your browser to delete or reject them — however, this may affect certain site functions.

Questions about your privacy rights: hello@tomprophoto.pl

[10]

Control of the "Do Not Track" feature

Most browsers and some operating systems include a "Do Not Track" (DNT) feature. At present, no uniform technological standard has been established for recognising it, so we do not respond to browser DNT signals.

If an online tracking standard is adopted that we must observe, we will inform you in an updated version of this Policy.

[11]

Do we update this policy?

In short: yes, we will update the policy as needed to stay compliant with the law.

We may update this Privacy Policy from time to time. The updated version will be marked with a revised "Last updated" date at the top of the document. If we make material changes, we will notify you either by prominently posting a notice or by sending you a direct notification.

We encourage you to review this Policy regularly to stay informed about how we protect your data.

[12]

How can you contact us?

Personal Data Controller
CompanyOLWOT Mariusz Rusecki
Addressul. Panny 7, 03-668 Warsaw
NIP / REGON5242518039 / 360993752
[13]

How to review, update or delete your data?

Under applicable law you may have the right to request access to the personal data we collect from you, to obtain information about how it is processed, to correct inaccuracies or to have your data deleted. You may also withdraw your consent to processing.

In some cases these rights may be limited by applicable law. To submit a request, contact us directly: hello@tomprophoto.pl.