Privacy Policy
Version in force from 20.08.2025:
I. Introduction
- The controller of the personal data of users of the "I must visit" Platform (hereinafter "Platform") is: PERFECTCLUE Sp. z o.o., with its registered office in Rzeszów, ul. Zimowit 42, 35-605 Rzeszów, Poland, NIP (Tax ID): PL8133882813, REGON (Business ID): 522791227, KRS (National Court Register): 0000986621, e-mail address: [email protected] (hereinafter "Controller").
- This Privacy Policy (hereinafter "Policy") aims to explain in detail how the Controller collects, processes, stores, and protects the personal data of Platform users, and how users can exercise their rights in connection with this processing.
- In the interest of the security of the entrusted data, the Controller applies appropriate procedures and recommendations to prevent their unauthorized disclosure. All actions are consistent with applicable laws, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: GDPR).
- Using the Platform constitutes acceptance of this Policy. If a user does not agree to the terms of the Policy, they should not use the Platform.
II. Scope of Personal Data Collected
-
During registration on the Platform and use of its services, the Controller may collect the following personal data:
- First and last name or company name
- E-mail address
- Image (e.g., in videos or profile picture)
- Geolocation data (latitude and longitude) assigned to added Videos, if the user chooses to provide it.
-
The Controller may also automatically collect technical and activity data, such as:
- IP address
- Browser and operating system type
- Device information (e.g., type of mobile device or computer)
- Time spent on the Platform and pages visited
- User preferences regarding settings and configuration
- Actions performed (e.g., clicks, adding Videos)
- Data related to Paid Plans, including payment data, are processed by an external payment provider (Stripe). The Controller does not have access to users' credit card data.
- The Platform is not intended for persons under 18 years of age. The Controller does not knowingly collect or process the personal data of children. If information is obtained that such data has been collected without the consent of legal guardians, the Controller will take immediate steps to delete it.
Processing of Personal Data
-
Users' personal data are processed for the following purposes:
- Providing services on the Platform: To enable registration, login, profile creation, and use of all Platform features. Legal basis: Art. 6(1)(b) GDPR.
- Personalizing services: To tailor the Platform's content and recommendations to the user's preferences. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller).
- Communicating with the user: To send messages regarding the account, activity on the Platform, and important changes to the Platform. Marketing information (e.g., newsletters) is sent only if the user has consented to it. Legal basis: Art. 6(1)(f) GDPR and Art. 6(1)(a) GDPR (user's consent).
- Processing payments: To handle transactions for Paid Plans. Legal basis: Art. 6(1)(b) GDPR.
- Analysis and statistics: To conduct statistical research to improve the quality and functionality of the Platform. Legal basis: Art. 6(1)(f) GDPR.
- Fulfilling legal obligations: To ensure compliance with regulations, including tax and personal data protection laws. Legal basis: Art. 6(1)(c) GDPR.
- Legitimate interest of the Controller: To ensure the security of the Platform, protect against abuse, and defend against possible legal claims. Legal basis: Art. 6(1)(f) GDPR.
- Users' personal data will be stored for the period necessary to achieve the purposes for which they were collected. User account data is stored for the entire time the Account is held on the Platform. After the Account is deleted by the user, their data will be immediately deleted or permanently anonymized, unless the law requires the Controller to store it for a longer period (e.g., billing data for tax purposes for 5 years) or it is necessary to pursue or defend against claims (for a period not longer than the statute of limitations for claims).
-
Users' personal data may be shared with:
- Technical and hosting service providers: To ensure the proper functioning of the Platform.
- External payment providers: In the case of payments for Paid Plans.
- Law firms and debt collection agencies, in case of pursuing claims.
- Public authorities: To fulfill legal obligations or defend the rights of the Controller.
- Cooperating entities: If it is necessary for the provision of services.
- As a rule, personal data will not be transferred to countries outside the European Union or the European Economic Area. If such a transfer were necessary (e.g., due to the use of services from an entity located outside the EEA), it would be carried out with the safeguards required by the GDPR.
IV. User Rights
-
The user has the right to:
- Access their data: Request information about the personal data being processed.
- Rectify data: Correct incorrect or incomplete data.
- Erase data ("right to be forgotten"): Request the deletion of data if it is no longer necessary for the purposes for which it was collected, or if the user has withdrawn consent for its processing.
- Restrict processing: Request the suspension of processing in certain situations.
- Data portability: Transfer their data to another controller.
- Object to processing: Object to the processing of data based on a legitimate interest.
- Withdraw consent: Withdraw consent for data processing at any time.
- To exercise these rights, the user should contact the Controller via e-mail: [email protected] or by traditional mail to the registered office address. To protect personal data, the Controller may request additional information to verify identity.
- Every person whose personal data is processed has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). Contact with UODO: ul. Stawki 2, 00-193 Warsaw, Poland, tel. +48 22 531-03-00.
V. Data Security
- The Controller uses appropriate technical and organizational measures, such as encryption, protection against unauthorized access, and regular audits, to ensure data security.
- Despite the measures taken, the Controller cannot guarantee the complete security of data on the Internet. Users should also take care of their own security by using strong passwords and protecting their login details.
VI. Essential Cookies and Similar Technologies
- The Platform uses cookies (small text files) and Local Storage technology, which are necessary for the proper provision of the Service requested by the User. This means that these technologies are crucial for the basic functions of the Platform, such as authentication, session maintenance, and ensuring security.
- In accordance with applicable law, the use of this type of technology does not require the User's prior consent. The legal basis for their use is Art. 173(3)(2) of the Telecommunications Law and Art. 6(1)(b) and (f) of the GDPR (necessity to perform the contract and the legitimate interest of the Controller, which is to ensure the technical operation and security of the service).
- The Platform does not use analytical or marketing (advertising) cookies that would require the User's consent.
-
The essential cookies we use include:
- .AspNetCore.Cookies / .Web.Session: Crucial for the authentication process and maintaining the session of a logged-in User.
- __cf_bm: A security cookie (provided by Cloudflare) used to protect against automated bots.
- language: Allow remembering the User's basic preferences regarding language to provide the appropriate version of the service.
- The User can manage cookies from their web browser settings, but blocking cookies that are necessary for the Platform's operation may prevent or significantly hinder the use of the Service.
VII. Final Provisions
- The Controller reserves the right to make changes to the Policy. Changes will be announced on the website https://imustvisit.com/es/privacy and will come into effect 7 days after the date of announcement. In the case of significant changes, registered users may be additionally informed by e-mail.
- The Platform may contain links to other websites that are not under the control of the Controller. Users should familiarize themselves with the privacy policies of those sites.
- Contact with the Controller regarding the Privacy Policy is possible at the e-mail address: [email protected].
- In the event of any discrepancies between the Polish language version and translations into other languages, the Polish version shall prevail.




