Privacy Policy

INTRODUCTION                      

The protection of personal data is one of the key aspects of the ZygZak go-kart track's operations.

This Privacy Policy explains how and for what purposes the Data Controller processes personal data, where it obtains such data, to whom it may disclose it, how long it retains it, and what rights data subjects have. In particular, this Policy takes into account Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 („GDPR”), the Act of May 10, 2018, on the Protection of Personal Data, and, with regard to electronic marketing and cookies, the Act of July 12, 2024—the Electronic Communications Act.

We assure you that we exercise due diligence to protect the interests of the individuals whose personal data we process. In particular, we ensure that we process data in accordance with the GDPR and the UODO, for specific, lawful purposes about which we inform you. Personal data is factually accurate and relevant to the purposes for which it is processed and stored, and is retained no longer than is necessary to achieve the purpose of processing and to comply with legal requirements.

When does this Privacy Policy apply?

This Privacy Policy applies to situations in which Apena-Remont sp. z o.o. independently determines the purposes and means of processing personal data in connection with the operation of the ZygZak Karting Track, the sale or reservation of services and goods, the operation of the Website, and related communications.

If a separate privacy notice is provided in a specific process, its provisions supplement this Policy, and in the event of any conflict, they take precedence with respect to that process .

PERSONAL DATA CONTROLLER

The controller of your personal data is Apena-Remont Sp. z o.o., with its registered office in Bielsko-Biała at ul. Partyzantów 61a, 43-300 Bielsko-Biała, registered with the 8th Commercial Division of the District Court in Bielsko-Biała under KRS number 0000140697, with Tax Identification Number (NIP) 937-21-76-881 and Statistical Identification Number (REGON) 072161448, owner of the ZygZak Karting Track, hereinafter referred to as the „Controller.”.

For all matters related to the processing of personal data, including exercising your rights, you may contact the Data Controller via email at rodo@apena-remont.com.pl (preferred method of contact) or in writing to the specified address of the company’s headquarters. The email address provided may also be used to submit requests regarding the exercise of rights under the GDPR.

The administrator may use tools that automate payment processing, code generation, and the sending of confirmations, as well as—after obtaining the required consent—analytics or the selection of marketing content. These automated tools are intended solely to improve the operation of the Website. They do not make independent decisions that would have legal consequences for you or otherwise significantly affect your rights or your ability to use the services. Detailed information can be found in the section „Automated Processing of Personal Data.”. 

How do we obtain data, and what types of personal data do we collect?

Data is collected directly from the data subject, from the data subject’s legal representative, or from the person making a reservation or purchase on behalf of other participants. In the latter case, the person providing the data must be authorized to do so, and the Controller shall provide the data subject with the required information no later than at the time of the first contact, unless an exception provided for in Article 14 of the GDPR applies. Technical data is collected from the device, browser, cookies, and server logs; payment data is obtained from the Przelewy24 provider; and data regarding the progress of service delivery and results is collected during the session at the go-kart track.

Depending on the selected service, the Administrator may process: identification data, first and last name, age or year of birth of the participant, contact information, user account data, reservation, order, payment, and accounting document data, the content of correspondence, complaints, and other reports, data regarding consents granted, images (if separate consent has been provided), as well as online identifiers and technical device data, including IP address, information about the browser, operating system, activity on the Website, and files cookies . Not every category listed is processed in every case. A detailed breakdown of how data is categorized for processing purposes is provided in the table below.

The administrator does not request the provision of special categories of personal data as defined in Article 9 of the GDPR, in particular health-related data. The mere voluntary provision of such information does not constitute explicit consent to its processing. Please do not include such data in general fields or in correspondence unless necessary. If such information is provided, the Controller will limit its use and delete it, unless its temporary retention is necessary pursuant to the exception provided for in Article 9(2) of the GDPR, in particular to establish, exercise, or defend legal claims or to protect the vital interests of a natural person. 

As a general rule, scoreboards and public rankings display a one-time username chosen by the participant and the participant’s lap time. The nickname should not contain a first and last name, address, phone number, or any other information that would allow third parties to identify the participant. The administrator may hide or change the nickname if it reveals personal information, violates the rights of others, or breaches the Terms of Use. A participant’s first and last name will be publicly displayed only if it is necessary for a specific event or if the participant has provided separate consent, where required.

DATA ON MINORS

In the case of a service provided to a minor, the Controller processes only the data necessary to organize and safely provide the service, in particular the first name, last name, nickname, age or year of birth, reservation details, and, if required, the first and last name and contact information of a parent or legal guardian, as well as information regarding the guardian’s consent to the minor’s participation in the service.

Minors’ data are not used for direct marketing or marketing profiling. The person providing a minor’s data should limit such data to what is strictly necessary and make this Policy available to the minor or his or her representative. 

Whether Providing Data Is Mandatory or Voluntary

Providing the data marked as required is necessary to enter into or perform a contract, make a reservation, complete a sale, issue an accounting document, or process a complaint. Failure to provide this data may prevent the specified action from being carried out. Providing data in optional fields and granting consent for marketing, analytics, or the use of your image is voluntary and does not condition your use of the basic service, unless a given function, by its very nature, requires the use of specific data . If an order or reservation is made on behalf of another person, you must provide only the information necessary to perform the service and ensure that it is accurate. 

Purposes of processing and the legal basis for processing

We process data in various situations described in our privacy policy. Below, we provide information on the purposes of processing and the legal bases. The specific purpose and legal basis for processing are provided in a separate information notice addressed to data subjects at the time their data is collected.

The scope of data depends on the action taken by the user. The controller applies the principle of data minimization, which means that it does not collect data that is not necessary for the specified purpose, and processes optional data only if it is provided voluntarily and there is an appropriate legal basis.

The sending of newsletters, text messages, and other commercial communications via electronic means takes place only after obtaining the consent required by the GDPR and the Electronic Communications Act. Failure to provide consent does not affect your ability to place an Order or use the basic service.

If the basis for processing is Article 6(1)(f) of the GDPR, the Controller’s legitimate interest consists, depending on the process, handling correspondence, ensuring the security of the Website and transactions, preventing abuse, organizing services and rankings, compiling statistics that do not require consent, and establishing, pursuing, or defending claims. The Controller takes into account the rights and interests of the data subject in each case.

The table below shows what data may be processed in each process, for what purpose, on what legal basis, and for how long. The controller processes only those items in a given row that are actually necessary to perform the selected action or to comply with a legal obligation. 

Process and PurposeWhat personal data may be processedLegal BasisRetention period
Use of the Website
Ensuring the proper functioning of the website, sessions, shopping cart, and reservations; diagnostics; fraud prevention and security.
IP address; date and time of the connection; URL of the requested page; session ID or necessary cookie; browser, device, and operating system type; resolution; referring URL; response codes, errors, and security events.Article 6(1)(b) of the GDPR—the provision of a service by electronic means; Article 6(1)(f) of the GDPR—the Controller’s legitimate interest in ensuring the efficiency and security of the Website. For essential cookies, see also Article 399(3) of the Electronic Communications Act.Session data — until the end of the session. Essential cookies — for the period specified in the privacy settings panel. Logs — generally no longer than 12 months, unless longer retention is necessary to investigate an incident, defend against claims, or pursue legal remedies.
Inquiries and Contact Information
Providing responses, handling inquiries via forms, email, phone, or social media, and taking action prior to entering into a contract.
First and last name or username, if provided; email address; phone number; social media profile ID; message content and attachments; date of contact; and details regarding the matter.Article 6(1)(b) of the GDPR—actions taken at the request of an individual prior to entering into a contract; Article 6(1)(f) of the GDPR—legitimate interest consisting of handling correspondence and providing responses.Until the matter is resolved, and thereafter, generally, for 12 months. If the correspondence leads to the conclusion of a contract, a complaint, or a dispute—for the period appropriate to that process and until the statute of limitations for claims expires.
User account — if this feature becomes available
Creating, maintaining, and managing an account, as well as saving its settings and history.
 
First and last name or username; email address; phone number, if required; account ID; password hash; settings, consents, and history of activity, reservations, and orders associated with the account.Article 6(1)(b) of the GDPR—performance of the account agreement; Article 6(1)(f) of the GDPR—account security, prevention of fraud, and defense against claims.Until the account is deleted or the service is terminated, and thereafter to the extent necessary for accounting purposes, to demonstrate the correctness of actions, and until the statute of limitations on claims expires.
Reservations, Orders, and Service Provision
Conclusion and performance of the contract; sale and electronic delivery of a Ticket, Voucher, or Pass; booking of a trip or event; organizational contact; verification of eligibility for redemption.
First and last name; email address; phone number; order number, date, and details; type of product or service; reservation date; number of participants; QR code or other transaction code; product usage history; participant data necessary for the selected service, such as first name or nickname, age or year of birth, and height; legal representative’s information, when required.Article 6(1)(b) of the GDPR — the conclusion and performance of a contract. With regard to participant data provided by the purchaser or the organizer: Article 6(1)(b) of the GDPR, when the participant is a party to the contract, or Article 6(1)(f) of the GDPR—organization of the service, verification of eligibility, and security of its performance.For the duration of the contract, the product’s shelf life, and after-sales service, and thereafter until the expiration of the applicable statute of limitations for claims. Data recorded in accounting records—for the period required by law.
Payments and Returns
Receiving payment confirmation, processing the order, identifying the transaction, preventing fraud, and issuing a refund.
Transaction number and ID; amount and currency; date; status and selected payment method; payer ID provided by the operator; bank account number or other information necessary for the refund. As a general rule, the administrator does not receive bank login credentials or full payment card details.Article 6(1)(b) of the GDPR — performance of a contract and billing; Article 6(1)(c) of the GDPR — legal obligations; Article 6(1)(f) of the GDPR — prevention of fraud and verification of the accuracy of billing.Until the settlement or refund is finalized, and thereafter for the period required by financial and tax regulations, and until the statute of limitations on claims expires.
Sales Documents and Tax Returns
Issuing and providing receipts or invoices, maintaining accounting records, and fulfilling tax obligations.
First and last name or company name; address; tax ID number (NIP)—if it is to appear on the invoice; order, payment, and sales document details; email address for document delivery; information about corrections.Article 6(1)(c) of the GDPR — compliance with obligations under tax and accounting laws; additionally, Article 6(1)(b) of the GDPR — performance of a contract.For the period required by tax and accounting regulations—generally 5 years, counting from the end of the calendar year relevant to the obligation in question, unless a specific provision requires a longer period.
Complaints, Cancellations, and Claims
Processing a complaint, fulfilling consumer obligations, and establishing, pursuing, or defending claims.
Identification and contact information; order number, ticket number, voucher number, pass number, or reservation number; description and date of the incident; request; correspondence; evidence and attachments; payment and refund account information; information needed to resolve the matter.Article 6(1)(b) of the GDPR—performance of a contract; Article 6(1)(c) of the GDPR—consumer obligations; Article 6(1)(f) of the GDPR — legitimate interest in establishing, pursuing, and defending claims.Until the completion of the complaint process or the completion of the withdrawal, and thereafter until the expiration of the applicable statute of limitations for claims; in the event of a dispute—until its final resolution and the enforcement of the decision.
Race Results, Rankings, and Events
Organizing races and competitions, determining results, and presenting them without unnecessarily revealing participants' identities.
Nickname chosen by the participant; go-kart or run number; lap time and result; category or event; date. First and last name only if necessary for organizing the event or if the participant has separately consented to their public disclosure.Article 6(1)(b) of the GDPR — the performance of a service or compliance with the rules of an event; Article 6(1)(f) of the GDPR — the organization of competitions and the maintenance of results lists; Article 6(1)(a) of the GDPR — public disclosure of a person’s first and last name, if based on consent.Service-related results — for the time required to settle the service and handle claims. Public rankings — for as long as they remain current or until a valid objection is raised; data published based on consent — until such consent is withdrawn.
Digital Marketing
Newsletters, information about promotions, competitions, and events sent via email or text message; managing consents and opt-outs.
First name, if provided; email address; phone number; content, scope, date, source, and status of consent; opt-out information; basic data regarding the delivery or opening of messages—if such measurements are tracked and included in the information.Article 6(1)(a) of the GDPR—consent, and Article 398 of the Electronic Communications Act. Data used to demonstrate the granting or withdrawal of consent: Article 6(1)(f) of the GDPR — accountability and defense against claims.To withdraw consent or unsubscribe from a given channel. Information regarding consent, withdrawal, or objection may then be retained for the period necessary to demonstrate compliance and until the statute of limitations for claims expires.
Photos and coverage of the events
The creation and publication of photos or videos featuring a participant on the Website or on social media—only to the extent covered by separate consent, if such consent is required.
 
Image and voice; first name, last name, or pseudonym, if included in the consent; name, location, and date of the event; the content of the consent given.Article 6(1)(a) of the GDPR — consent. Regardless of the GDPR, the publication of an image must comply with the provisions on the protection of images and the exceptions provided for by law.Until consent is withdrawn or until the end of the period specified in the consent. Withdrawal does not affect the lawfulness of prior processing; materials already shared by recipients or recorded by the platform operator may remain outside the Controller’s direct control.
Analytics and Optional Cookies
Measuring how the Website is used, compiling statistics, and improving its features; tailoring content or marketing—only if such features are used and the user has previously given consent.
Cookie and device identifiers; IP address, to the extent provided to the tool; approximate location derived from the IP address; device type, operating system, and browser; pages visited; referral source; clicks, events, and time spent on the site; campaign ID. The scope depends on the categories you have accepted.Article 6(1)(a) of the GDPR—consent—and Article 399 of the Electronic Communications Act. Consent does not apply to cookies that are necessary for the service requested by the user.Until consent is withdrawn, files are deleted, or the expiration period specified for a given tool in the privacy settings panel expires—whichever occurs first—taking into account data that has already been aggregated or anonymized.

The period for which the data will be retained

The retention periods applicable to specific purposes are listed in the table. Once these periods have expired, the data is either deleted or permanently anonymized, unless further retention is required by law or necessary to establish, exercise, or defend legal claims. The same data may be retained for different periods if it serves several independent purposes.

In the event of an objection to direct marketing, the Controller shall cease processing data for this purpose, including profiling related to such marketing. In the case of other processing operations based on Article 6(1)(f) of the GDPR, an objection may be raised on grounds relating to a particular situation; The Controller will cease processing unless it demonstrates compelling legitimate grounds for the processing that override the rights and freedoms of the data subject, or grounds related to the establishment, exercise, or defense of legal claims.

If processing is based on consent, consent may be withdrawn at any time just as easily as it was given. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal or processing carried out on another, independent legal basis.

Consents for marketing, analytics, optional cookies, and the use of your image are voluntary and separate from consent to the Terms of Service. You may withdraw them by using the opt-out link in the message, contacting the Administrator, or through the privacy settings panel. Withdrawing consent to the publication of your image applies to the future use of the material; it does not automatically result in the removal of copies previously shared by other users or stored by the operator of an external platform in accordance with its own terms.

RECIPIENTS OF PERSONAL DATA

• Access to the data is granted only to persons authorized by the Administrator and only to the extent necessary to perform their assigned duties.

• Data may be disclosed to providers of hosting, IT maintenance and security, email, reservation and sales systems, code generation and distribution, customer service tools, accounting, archiving, legal support, and debt collection services. Entities acting on behalf of the Controller process data pursuant to a contract and in accordance with the Controller’s instructions.

• With regard to payments, data is received by Przelewy24 (PayPro S.A.), which processes the data necessary to provide the payment service and also acts as a separate data controller in accordance with its own legal obligations. Once you are redirected to the operator’s website, its privacy policy also applies. 

• If the user consents to analytics, marketing, or the publication of their image, the recipients may include the providers of these tools and social media operators, in particular Google Ireland Limited in connection with the Google Analytics service and the operator of the platform on which the material was published. The scope and role of a given entity are determined by the features actually enabled on the Website and the terms of service.

• Data may be disclosed to public authorities, courts, or other authorized entities if the obligation or right to disclose such data is provided for by law. The data controller does not sell personal data.

TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA 

As a general rule, the Controller selects data processors located within the European Economic Area. However, the use of global analytics, cloud, or social media services may result in data being accessed from a third country. In such cases, the transfer is based on a European Commission decision recognizing an adequate level of protection, including, where applicable, the EU-U.S. Privacy Shield, or it is carried out using appropriate safeguards, in particular standard contractual clauses. Information about the mechanism used and the possibility of obtaining a copy of the safeguards can be found at rodo@apena-remont.com.pl.

The Rights of Data Subjects and How to Exercise Them 

Within the limits set forth by the GDPR, you have the following rights:

1. Right of access to data — You have the right to obtain confirmation as to whether we are processing your data, to access your data and obtain a copy of it, as well as to receive information about the processing.

2. The Right to Rectification, Erasure, and Restriction of Processing — You may request that incorrect data be corrected, incomplete data be supplemented, data be erased in the cases provided for in Article 17 of the GDPR, or that the use of your data be temporarily restricted in the cases provided for in Article 18 of the GDPR.

3. Right to withdraw consent — if the processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of the processing that took place prior to the withdrawal.

4. Right to data portability — this applies to data you have provided that is processed automatically based on consent or a contract. You may receive this data in a structured, commonly used, machine-readable format or, if technically feasible, request that it be transmitted to another controller.

5. Right to object — You may object to direct marketing at any time. You may object to other processing activities based on Article 6(1)(f) of the GDPR on grounds relating to your particular situation.

6. You have the right to file a complaint with the President of the Personal Data Protection Office if you believe that the processing violates the GDPR. The Office’s current contact information: 1A Stanisława Moniuszki St., 00-014 Warsaw, uodo.gov.pl.

Requests may be submitted via email to rodo@apena-remont.com.pl or in writing to the Controller’s registered office. If necessary to protect data, the Controller may request additional information to reasonably verify the applicant’s identity; it will not request any unnecessary data.

The Data Controller shall provide information regarding the actions taken in connection with the request without undue delay, generally within one month of receiving it. If the requests are complex or numerous, the deadline may be extended by an additional two months; the Controller will notify the data subject of the extension and its reasons within the first month. The exercise of these rights is generally free of charge, with the exceptions provided for in the GDPR.

Automated Processing of Personal Data

The Administrator does not make decisions regarding users based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect them within the meaning of Article 22 of the GDPR. Automatic payment confirmation, code generation, and order submission serve to execute the transaction selected by the Customer and do not constitute such a decision.

If the user accepts analytical or marketing cookies, the Administrator may analyze the subpages visited, the referral source, clicks, and basic device parameters to generate statistics or assign the user to a general category of interests. The logic involves grouping similar events and selecting content based on them; the intended result is merely a change in the content displayed or in how its effectiveness is measured. Such analytics and profiling are activated only after consent is given and do not result in denial of access to the core service.

PERSONAL DATA PROTECTION

Personal data is processed using the technical and organizational measures required by law to ensure a level of protection appropriate to the risks and the categories of data being protected, and is safeguarded against processing that violates applicable laws.

The controller restricts access to data to authorized persons who are bound by confidentiality obligations; implements appropriate access controls, backups, and incident response procedures; regularly reviews the scope of data and access permissions; and enters into contracts with processors as required by Article 28 of the GDPR. Security measures are selected taking into account the state of the art, the cost of implementation, the nature and scope of the processing, and the risk to the rights and freedoms of natural persons. No method of transmission or storage can guarantee the complete elimination of risk; therefore, security measures are updated periodically.

Cookies

This website uses cookies and similar technologies, which are pieces of information stored on or retrieved from the user’s device. Depending on the technology, these may constitute personal data, particularly when linked to an IP address, device identifier, account, or session.

• Essential cookies — these enable data transmission and features explicitly requested by the user, such as security, session management, shopping cart, reservations, payment, and saving privacy settings. They are active without consent to the extent permitted by Article 399(3) of the Electronic Communications Act.

• Functional or preference cookies — these cookies remember your selected settings that are not necessary for the basic functioning of the service. They are used after consent is obtained, unless a specific feature has been explicitly requested by the user and cannot be provided without this technology. 

• Analytical cookies — these cookies allow us to measure traffic, referral sources, pages visited, and events on the Website in order to generate statistics and improve the Website. They are activated only after you have given your consent.

• Marketing cookies — these enable us to measure the effectiveness of campaigns, limit the number of impressions, and tailor content or ads to general interests. If used, they are activated only after you have given your consent.

Before non-essential cookies are activated, the user receives clear information about the categories in a banner or privacy settings panel and can accept or reject them with equal ease. Inaction, scrolling the page, or continued use of the Site are not considered consent.

In connection with cookies, the following data may be processed: cookie and session IDs, IP address, date and time, device type, operating system and browser, approximate location based on IP address, the address of the visited subpage and the referring page, clicks, events, usage time, and campaign identifiers. The specific scope depends on the accepted category and the configuration of the given tool.

This website uses Google Analytics, provided by Google Ireland Limited, to analyze traffic. The tool is activated only after you consent to analytical cookies. Advertising features or additional Google signals remain disabled unless they are specifically described and you have made an informed choice regarding them in the marketing category.

The administrator provides an up-to-date list of cookies and similar technologies used before consent is given in the „Privacy Settings” panel. The list includes, at a minimum, the name of the technology, its provider, purpose, category, and duration. The administrator updates the list whenever there is a change to the tools or their configuration.

You can withdraw or change your consent at any time in the „Privacy Settings” panel. The change applies going forward and does not affect the lawfulness of prior processing. Re-enabling optional categories requires another informed choice by the user.

Users can also delete and block cookies in their browser settings. However, browser settings may not delete the consent stored on the Website’s end; therefore, to fully change your preferences, you should also use the privacy settings panel.

Rejecting analytical, functional, or marketing cookies does not block access to basic content or the ability to make a purchase. However, disabling essential cookies may prevent sessions, shopping carts, reservations, logins, or payments from working.

After being redirected to the Przelewy24 website, the payment provider may use its own cookies and similar technologies in accordance with the terms described in its privacy policy. Cookie settings on the Administrator’s website do not necessarily change the settings on the payment provider’s website. 

Links to external websites or social media platforms do not, in and of themselves, result in the transfer of data beyond what is technically necessary to display the link. Once you visit an external website, the privacy policy of that website’s operator applies.

Access logs

The following information may be recorded in the server logs: IP address, date and time of the request, URL of the requested page, referring URL, browser, device, and operating system type, response code, error information, and security-related events. This data is used to ensure the proper functioning of the Website, for diagnostics, to detect abuse, to analyze incidents, and to compile aggregated statistics. The legal basis is Article 6(1)(f) of the GDPR—the Controller’s legitimate interest in maintaining the Website’s performance and security. Logs are generally stored for no longer than 12 months, unless a longer period is necessary to investigate an incident or to establish, pursue, or defend against claims.

Log data may be disclosed to authorized public authorities only in the cases and to the extent provided for by applicable law. For statistical purposes, the Controller uses aggregated or anonymized data whenever possible.

CHANGES TO THE PRIVACY POLICY

This Policy may be updated, in particular, due to changes in the law, guidelines from supervisory authorities, applicable technologies, vendors, the Website’s functionality, or the purposes or legal bases for processing. The current version is published on the Website along with its effective date. If a change significantly affects how data is used or requires new consent, the Controller will provide appropriate information before the new processing begins and—when required—will request consent again. 

This document was last updated on July 28, 2026.