Privacy Policy
Политика конфиденциальности
1. INTRODUCTION
This Privacy Policy ("Privacy Policy") explains how IMPULSE ("Company", "we", "our" or "us") collects, uses, stores, shares and protects Personal Data obtained from customers, prospective customers, website visitors and other individuals ("Customer", "you" or "your") in connection with the provision of our premium booking, concierge, reservation and luxury automotive experience services.
The Company is committed to protecting the privacy of all individuals whose Personal Data we process and to ensuring that such processing complies with the applicable provisions of Regulation (EU) 2016/679 (General Data Protection Regulation – "GDPR"), the Polish Personal Data Protection Act and any other applicable privacy legislation.
This Privacy Policy applies to:
- our website;
- booking requests;
- customer accounts;
- payment processing;
- correspondence;
- electronic communications;
- reservations;
- concierge services;
- supplier coordination;
- marketing communications;
- all other services provided by the Company.
By submitting a Booking Request, using our Services or otherwise providing Personal Data to the Company, you acknowledge that you have read and understood this Privacy Policy.
2. DATA CONTROLLER
The controller of your Personal Data is:
IMPULSE
Registered in the Republic of Poland
Registered office: ul. Olenki 3/1, Marki, 05-270, Poland
NIP: 5214069753
Email: contact@impulse-grandtour.com
Website: https://impulse-grandtour.com/sportcarstour
The Company determines the purposes and means of processing Personal Data described in this Privacy Policy.
3. SCOPE OF THIS POLICY
This Privacy Policy applies to all Personal Data processed by the Company regardless of whether such data is collected:
- through our website;
- through Stripe or another payment processor;
- by email;
- via WhatsApp;
- via Telegram;
- via Signal;
- via social media;
- by telephone;
- during customer meetings;
- through booking platforms;
- from Third-Party Suppliers;
- from publicly available sources where legally permitted.
This Policy applies before, during and after the provision of our Services.
4. CATEGORIES OF PERSONAL DATA
Depending upon the nature of the Booking and Services requested, we may process the following categories of Personal Data:
Identification Data
- full name;
- date of birth;
- nationality;
- passport details;
- identity document details;
- driver’s licence information.
Contact Data
- email address;
- telephone number;
- postal address;
- billing address;
- emergency contact details.
Booking Information
- travel itinerary;
- accommodation preferences;
- restaurant reservations;
- activity selections;
- vehicle reservations;
- travel companions;
- booking history.
Payment Information The Company does not store complete payment card information.
Payments are processed by independent payment providers including Stripe and banking institutions.
We may receive limited payment-related information, including:
- transaction identifiers;
- payment status;
- payment amount;
- billing information;
- partial card details (where provided by the payment processor);
- fraud prevention information.
Technical Data We may automatically collect:
- IP address;
- browser type;
- operating system;
- device identifiers;
- cookies;
- language preferences;
- website usage information;
- timestamps;
- session information.
Communication Data We may retain:
- emails;
- WhatsApp messages;
- Telegram communications;
- Signal communications;
- CRM notes;
- customer service requests;
- complaints;
- electronic signatures;
- Booking Confirmations;
- invoices.
Marketing Data Where permitted by applicable law, we may process:
- newsletter preferences;
- marketing consents;
- responses to promotional campaigns;
- participation in surveys.
5. HOW WE COLLECT PERSONAL DATA
Personal Data may be collected:
- directly from the Customer;
- from payment processors;
- from Third-Party Suppliers;
- through our website;
- through cookies;
- through booking forms;
- through Booking Requests;
- during customer support;
- through electronic communications;
- from publicly available registers where legally permitted;
- from travel companions where authorized by the Customer.
6. PURPOSES OF PROCESSING
We may process Personal Data for the following purposes:
- preparing commercial offers;
- confirming reservations;
- arranging accommodation;
- arranging vehicle reservations;
- coordinating Third-Party Suppliers;
- organizing travel experiences;
- providing concierge services;
- issuing invoices;
- processing payments;
- communicating with Customers;
- responding to enquiries;
- customer support;
- identity verification;
- fraud detection;
- preventing unauthorized transactions;
- preventing chargebacks;
- maintaining booking history;
- complying with legal obligations;
- enforcing contractual rights;
- improving Services;
- protecting Company property;
- protecting Customers;
- maintaining internal records;
- resolving disputes;
- defending legal claims;
- marketing where permitted by law.
The Company shall not process Personal Data for purposes incompatible with those described in this Privacy Policy unless required or permitted by applicable law.
7. LEGAL BASES FOR PROCESSING
We process Personal Data where necessary:
- to perform a contract with you;
- to take steps at your request before entering into a contract;
- to comply with legal obligations;
- for the purposes of legitimate interests pursued by the Company, such as business administration, fraud prevention, security, and dispute resolution;
- where consent is required, based on your consent.
8. PAYMENT PROCESSING
The Company uses independent payment service providers to securely process payments.
These providers may include:
- Stripe;
- Visa;
- Mastercard;
- American Express;
- banking institutions;
- other authorized payment processors.
The Company does not store complete payment card numbers, CVV codes or other sensitive authentication data.
Payment processors may independently collect and process Personal Data necessary to:
- authorize transactions;
- prevent fraud;
- comply with financial regulations;
- detect suspicious activity;
- manage disputes;
- process refunds;
- verify card ownership.
9. DISCLOSURE OF PERSONAL DATA
We may disclose Personal Data to:
- payment processors;
- Third-Party Suppliers;
- IT and hosting providers;
- customer service tools;
- legal advisers;
- accountants;
- authorities where required by law;
- other entities necessary to provide the Services.
10. INTERNATIONAL TRANSFERS
Where Personal Data is transferred outside the European Economic Area, the Company shall take reasonable steps to ensure an adequate level of protection in accordance with applicable law.
11. DATA RETENTION
We retain Personal Data for as long as necessary for the purposes set out in this Policy, including:
- performance of the contract;
- compliance with legal obligations;
- accounting and tax requirements;
- fraud prevention;
- dispute resolution;
- defence of legal claims.
12. RIGHTS OF DATA SUBJECTS
Subject to applicable law, you may have the right to:
- access your Personal Data;
- rectify inaccurate data;
- erase your Personal Data;
- restrict processing;
- object to processing;
- data portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with a supervisory authority.
12.1 Right of Access
You may request confirmation of whether we process your Personal Data and request a copy of that data.
12.2 Right to Rectification
You may request correction of inaccurate or incomplete Personal Data.
12.3 Right to Erasure
You may request deletion of Personal Data where legally permitted.
12.4 Right to Restriction
You may request restriction of processing in certain circumstances.
12.5 Right to Object
Where processing is based on legitimate interests, you may object to such processing.
The Company may continue processing only where compelling legitimate grounds exist or where necessary for legal claims.
12.6 Right to Withdraw Consent
Where processing is based on consent, such consent may be withdrawn at any time.
Withdrawal shall not affect the lawfulness of processing undertaken before withdrawal.
12.7 Right to Lodge a Complaint
The Customer has the right to submit a complaint to the competent supervisory authority responsible for data protection in the country of habitual residence or in the Republic of Poland.
13. COOKIES AND SIMILAR TECHNOLOGIES
The Company’s website may use cookies and similar technologies to improve functionality, security and user experience.
Cookies may include:
- Essential Cookies — necessary for the operation of the website, account management, security and booking functionality;
- Functional Cookies — used to remember customer preferences, language settings and website configuration;
- Analytical Cookies — used to understand website traffic, improve performance and analyse customer interaction;
- Marketing Cookies — where permitted by applicable law and subject to consent where required, cookies may be used to measure advertising effectiveness and improve marketing campaigns.
Customers may configure browser settings to refuse or delete cookies.
Disabling certain cookies may affect the functionality of the website.
A separate Cookie Policy may provide additional information regarding the Company’s use of cookies and tracking technologies.
14. SECURITY OF PERSONAL DATA
The Company implements appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, accidental loss, destruction, alteration or unlawful disclosure.
Such measures may include:
- encrypted communications where appropriate;
- secure payment processing;
- restricted access controls;
- authentication procedures;
- regular software updates;
- firewall protection;
- malware protection;
- secure cloud infrastructure;
- contractual confidentiality obligations;
- employee access limitations;
- supplier security requirements.
Despite the implementation of appropriate safeguards, no method of electronic transmission or electronic storage can guarantee absolute security.
Accordingly, the Company cannot guarantee that unauthorized access will never occur.
15. AUTOMATED DECISION-MAKING AND FRAUD PREVENTION
The Company may use automated systems to assist in:
- payment verification;
- fraud detection;
- chargeback prevention;
- cybersecurity monitoring;
- identity verification;
- transaction risk assessment.
Such automated processing may include information received from payment processors, fraud prevention providers and security systems.
The Company does not make decisions producing legal effects solely on the basis of automated processing unless permitted by applicable law or necessary for the performance of the Agreement.
Customers may request additional information regarding any significant automated processing affecting them.
16. CHILDREN’S PRIVACY
The Company’s Services are intended exclusively for persons who are at least eighteen (18) years of age.
The Company does not knowingly collect Personal Data directly from children.
If the Company becomes aware that Personal Data has been collected from a child contrary to applicable law, such information shall be deleted without undue delay.
Parents or legal guardians who believe that a child has provided Personal Data to the Company may contact the Company using the contact details provided in this Privacy Policy.
17. DATA BREACHES
The Company maintains procedures designed to identify, investigate and respond to personal data breaches.
Where required by applicable law, the Company shall notify the competent supervisory authority and affected individuals without undue delay.
18. THIRD-PARTY WEBSITES
The Company’s website or communications may contain links to third-party websites or services.
The Company is not responsible for the privacy practices or content of such third-party websites. Customers are encouraged to review the applicable privacy policies before providing Personal Data.
19. CHANGES TO THIS PRIVACY POLICY
The Company may update this Privacy Policy from time to time to reflect changes in applicable law, business operations or the Services.
The updated version shall become effective upon publication on the Company’s website or other official communication channel.
Continued use of the Services after such publication constitutes acceptance of the updated Privacy Policy.
20. CONTACT INFORMATION
Questions regarding this Privacy Policy or the processing of Personal Data may be directed to the Company using the following contact details:
IMPULSE Mark Butkin
Address: ul. Olenki 3/1, Marki, 05-270, Poland
NIP: 5214069753
Email: contact@impulse-grandtour.com
Website: https://impulse-grandtour.com/sportcarstour
FINAL PROVISIONS
This Privacy Policy forms an integral part of the Company’s Global Terms of Service and shall be interpreted together with all other documents governing the provision of the Company’s Services, including the Cancellation & Refund Policy, Vehicle Use Agreement and any Booking Confirmation.
Where mandatory applicable law grants Customers additional rights, such rights shall prevail over any inconsistent provision of this Privacy Policy.
This Privacy Policy shall be governed by the laws of the Republic of Poland, without prejudice to any mandatory consumer protection or data protection provisions that may apply.
contact@impulse-grandtour.com · +48 883 488 689