This is a courtesy translation. The legally binding version is the Polish one — Polityka prywatności. In case of any discrepancy, the Polish text prevails.
In accordance with EU Regulation 2016/679 (“GDPR”), the information below concerns the processing of personal data of users (“user”) in connection with the use of the Wi-Fi network made available by ANACRON – Tomasz Motyliński. Terms not defined here have the meaning given to them in the GDPR.
1. Data controller
The controller is ANACRON – Tomasz Motyliński, ul. Pogodna 1/224, 87-800 Włocławek, Poland, VAT ID (NIP) 888-234-77-08 (the “Controller”), entered in the register of telecommunications undertakings kept by the President of the Office of Electronic Communications (UKE) under number 13769. Contact regarding personal data: anacron@anacron.pl.
2. Data protection officer
The Controller has not appointed a data protection officer (DPO), as the conditions of Article 37 GDPR do not apply. For all matters concerning personal data, please contact the Controller directly: anacron@anacron.pl.
3. Purposes and legal bases of processing
- a) providing and billing the Service (performance of the contract) — Article 6(1)(b) GDPR;
- b) ensuring the security and proper operation of the network and establishing, pursuing or defending claims (the Controller’s legitimate interest) — Article 6(1)(f) GDPR;
- c) fulfilling legal obligations, including the obligation to retain and disclose data under the Electronic Communications Law and tax obligations — Article 6(1)(c) GDPR;
- d) producing statistics and improving service quality on the basis of anonymised data (fully anonymised data do not constitute personal data).
4. Categories of data processed
- the device’s MAC address,
- IP address,
- the date and time the connection started and ended, and the resulting duration of use,
- volume of data transferred (including average packet size),
- technical characteristics of establishing/terminating the connection,
- identifier/name of the access point (location),
- device type and manufacturer,
- operating system and browser data, including language and time zone,
- payment transaction data (for billing and complaint handling).
Providing the data is necessary to use the Service; failure to provide it prevents the Service from being provided in whole or in part.
5. Data recipients
Data may be disclosed to: (a) IT service providers and the payment operator acting on the Controller’s instructions as processors, under data processing agreements ensuring appropriate technical and organisational measures, and to the provider of Internet connectivity; nationwide operators include, among others: Orange Polska S.A., P4 sp. z o.o. (Play), Netia S.A., Polkomtel sp. z o.o. (Plus), T-Mobile Polska S.A., Vectra S.A.; (b) authorised public authorities and institutions (including the Police, prosecutors, courts, services and supervisory authorities) where there is a legal obligation or authorisation to do so. Access to the data is limited to persons acting on behalf of the Controller or the processor.
6. Transfers outside the EEA
As a rule, the Controller does not transfer data outside the European Economic Area (EEA). If it uses providers outside the EEA, the transfer takes place solely on the basis of appropriate safeguards — in particular an adequacy decision of the European Commission (e.g. the EU–US Data Privacy Framework) or standard contractual clauses (SCC), with any supplementary measures (e.g. pseudonymisation).
7. Retention period
Data subject to the statutory retention obligation (including the MAC address and other data identifying the device and the user, traffic data and payment transaction data) are stored for 12 months in accordance with the Electronic Communications Law, and are then deleted or anonymised. Billing data are stored for the period required by tax law. Other data are stored for no longer than is necessary for the purposes for which they were collected and until the expiry of limitation periods for claims.
8. Rights of data subjects
The User has the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection to processing based on Article 6(1)(f) (Article 21), and — where processing is based on consent — to withdraw it at any time (without affecting the lawfulness of processing before withdrawal).
These rights are subject to limitations arising from law; in particular, a request for erasure does not cover data which the Controller is obliged to retain under the law (Article 17(3)(b) GDPR) — including data covered by the statutory retention obligation — for the period required by those provisions. The User exercises their rights by contacting the Controller (point 1). The User also has the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).
9. Changes to this Policy
The Controller may update this Policy in the event of changes in law or in the manner of processing data. Changes are communicated in an appropriate manner, in particular by publishing the current version on the login page.
See also the Terms of the Wi-Fi service (hotspot).
Last updated: 10 July 2026