Privacy policy

Version 1.1 · effective from 2 August 2026
Applies to the www.gazeleziranu.com website

Iran site Uganda site Wersja polska

Who processes your data

The controller of your personal data is Gazele z Iranu Bartosz Kapica, Polish tax number (NIP): 6351786294, statistical number (REGON): 242958320, address: ul. Tartaczna 8, 43-178 Ornontowice, Poland.

You can contact us:

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data. PECA means the Polish Act of 12 July 2024 — Electronic Communications Act (Prawo komunikacji elektronicznej), which implements the ePrivacy Directive in Poland.

Your rights

In relation to the processing of your data, you have the right to:

  • access your data and obtain a copy of it (Art. 15 GDPR)
  • rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • erasure of your data (Art. 17 GDPR) — where we have no remaining basis for processing it
  • restriction of processing (Art. 18 GDPR)
  • data portability — for data we process on the basis of a contract or your consent, in a machine-readable format (Art. 20 GDPR)
  • object to processing based on our legitimate interest (Art. 21 GDPR)
  • withdraw your consent at any time, without giving a reason, where processing is based on consent (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

You can change or withdraw your consent to data being stored in your browser at any time using the button available in the footer of every page. This is just as easy as giving consent, as required by Art. 7(3) GDPR.

You also have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.

Contacting us

There is no contact form on this website. Contact happens directly: by e-mail, by phone or via a messenger app (WhatsApp, Telegram) — always on your initiative, after you click a link or a phone number.

What data we process

Whatever you give us: your name or signature, e-mail address or phone number, the content of your message, and — for trip enquiries — information about the planned trip (dates, group size, preferences).

Legal basis and purpose

  • Art. 6(1)(b) GDPR — where your enquiry concerns entering into or performing a contract (trip quotation, booking, visa handling)
  • Art. 6(1)(f) GDPR — our legitimate interest in answering your question and in defending against possible claims

For how long

We keep correspondence until the matter is closed, and then for the limitation period for claims (as a rule 6 years under Polish law, and 3 years for claims connected with business activity; we apply the longer of the two).

Who else may have access

  • our hosting and e-mail provider: LH.PL Sp. z o.o.
  • our accountants — if the matter results in an accounting document being issued

Messenger apps. Clicking a WhatsApp or Telegram link takes you to that provider's app or service. From that moment your data is also processed by that provider. If you would rather avoid this, send us an e-mail or call.

Trip participation agreement

If you decide to travel with us, we enter into an agreement for participation in a package travel arrangement. To draw it up, and then to run the trip, we need data about every participant.

What data we collect

  • first name and surname
  • home address
  • e-mail address and phone number
  • passport series and number, and its expiry date
  • a copy of the passport

Providing this data is voluntary but necessary in order to conclude the agreement. Without it we cannot draw up the document or book flights and accommodation — airlines and hotels require the participant's passport details.

Why, and on what legal basis

  • Art. 6(1)(b) GDPR — preparing and performing the package travel agreement: booking flights, accommodation, transport and services on the ground, and keeping in touch with you before and during the trip
  • Art. 6(1)(c) GDPR — obligations arising from law, in particular tax and accounting rules and the Polish Act of 24 November 2017 on package travel and linked travel arrangements
  • Art. 6(1)(f) GDPR — our legitimate interest in establishing, pursuing or defending against claims

Who we pass it to

  • hotels, and partners and carriers in the destination country — to the extent needed to make the bookings
  • the insurer — if the trip includes insurance
  • our accountants and our hosting and e-mail provider (LH.PL Sp. z o.o.)

Transfers outside the European Economic Area. A trip to Uganda or Iran requires passing participant data to partners operating in those countries. Neither Uganda nor Iran is covered by a European Commission adequacy decision, and the level of protection there may differ from the GDPR standard — as may your ability to enforce your rights before a local authority.

The transfer takes place on the basis of Art. 49(1)(b) GDPR: it is necessary for the performance of the contract you conclude with us. Without it, booking in the destination country is not possible.

How long we keep it

  • passport copy — a scan or photo — up to 90 days after the package travel arrangement ends. We need that window to handle complaints, report a claim to the insurer and settle matters with partners in the destination country. After that the file is deleted — the agreement itself does not need a copy of the document.
  • agreement data, including the passport series, number and expiry date — for the duration of the agreement and then for the limitation period for a traveller's claims, which is 3 years (Art. 50(5) of the Polish Act on package travel and linked travel arrangements)
  • accounting documents — 5 years from the end of the year in which the tax payment deadline fell

We keep these three periods deliberately separate. A copy of a document is far more sensitive than its number alone, so it has the shortest life. The minimisation principle (Art. 5(1)(c) and (e) GDPR) does not allow data to be kept incidentally, merely because other information in the same case has to stay longer.

Application for an Iranian visa code

This is the most sensitive part of the website, so we describe it in the most detail. It applies only to people who fill in and submit the application form.

What the service covers

We act as an intermediary in obtaining a visa code (visa code, also called a visa authorisation) — the vetting of the applicant and the Iranian authorities' approval for a visa to be issued. The visa itself is collected at an Iranian consulate or at an Iranian international airport. Holding a visa code is what the visa is issued on the basis of.

What data we collect

Only what the Iranian visa system requires — you will find the full list of fields in the form. By category, these are:

  • identification and family data — including your father's name and marital status, which the Iranian form requires
  • contact and address data
  • passport data
  • employment and education data
  • data about the planned trip — together with details of your travel companion, if you are travelling together
  • a photograph of your face and a scan or photo of the passport page with your personal data
  • technical data — your IP address and browser information (user agent), recorded automatically together with the application; you do not enter these yourself

The form automatically flags applications from people in occupations that Iranian visa authorities scrutinise more closely. The flag exists so that we can warn you about a raised risk of refusal and prepare the application more carefully — what such a flag means for the refund guarantee is set out in the visa service terms. This is not automated decision-making within the meaning of Art. 22 GDPR — the flag alone produces no legal effects concerning you and does not determine the outcome. We do not profile you for any other purpose.

Your photo and passport scan are checked inside your browser. Before anything is sent, the form assesses file quality itself: sharpness, brightness, background, glare, and whether a face is present and correctly positioned. All of this analysis runs on your own device, using code downloaded from our server — the files are not transmitted to anyone for this purpose and are not passed to any image recognition service. They reach us only once you click “Submit”.

Why, and on what legal basis

  • Art. 6(1)(b) GDPR — performance of the contract for intermediation in obtaining a visa code, which you enter into with us by submitting the application. This is the main basis: without this data, submitting the application is physically impossible. Providing the data is voluntary but necessary to use the service.
  • Art. 6(1)(c) GDPR — compliance with tax and accounting obligations relating to payment for the service
  • Art. 6(1)(f) GDPR — our legitimate interest in protecting the form against abuse and in defending against claims
  • Art. 49(1)(a) and (b) GDPR — transfer of data to Iran (see below)

Transfer of your data to Iran. Submitting a visa code application requires transferring the above data, including your photograph and passport scan, to the Iranian visa authorities.

Iran is a third country for which the European Commission has not issued an adequacy decision, and we do not apply standard contractual clauses to this transfer. This means that once the data has been transferred:

  • a level of protection equivalent to the GDPR does not apply there,
  • there is no supervisory authority equivalent to the Polish DPA to which you could complain,
  • your ability to enforce your rights and obtain an effective legal remedy may be significantly limited or unavailable in practice,
  • Iranian state authorities may gain access to the data under local law.

The transfer takes place on the basis of Art. 49(1)(b) GDPR (it is necessary for the performance of a contract concluded at your request) and your explicit consent under Art. 49(1)(a) GDPR, given together with the completed form. You may withhold that consent — but then applying for a visa code will not be possible. You may withdraw the consent until the data has been transferred to Iran; after that moment withdrawal is no longer possible.

How long we keep it

Type of dataPeriodWhy this long
All application data — including the photograph, passport scan, IP address and browser information 90 days at most after the matter is closed After that we delete every copy — from the server and from the e-mail account. We do not keep this data “just in case”: data minimisation (Art. 5(1)(e) GDPR).
Register of declarations made — case number, name, e-mail address, mode chosen, amount, IP address and date of submission 6 years We must be able to demonstrate that you gave consent (Art. 7(1) GDPR) and requested that performance begin. That is the limitation period for your claims under Polish law (Art. 118 of the Civil Code), so only after it does the evidence stop being needed. The register contains no passport data, photograph or scan — only what is necessary to defend against a claim.
Billing data (accounting documents) 5 years from the end of the year in which the tax payment deadline fell The only period required outright by law — Polish tax and accounting obligations. It covers invoices and payment confirmations, not the content of the application.

Who has access to application data

  • the controller — the full application data, the photograph and the passport scan reach him in an archive encrypted with AES-256. This means nothing travels electronically in a form readable along the way. The working copy on the server is not accessible from the internet and is deleted right after delivery.
  • our hosting and e-mail provider LH.PL Sp. z o.o. — as a processor, under a data processing agreement
  • the Iranian visa authorities — see the box on transfers to Iran above
  • our accountants — as regards billing data

Other people's data that you provide in the application

The Iranian visa application requires your father's name and your mother's full name and, depending on your situation, also your spouse's details and those of your travel companion. This is third-party data which we do not collect from those people directly — we receive it from you.

We process it solely in order to handle your application, to the extent the Iranian form requires, on the basis of Art. 6(1)(b) and (f) GDPR (performance of the contract concluded with you, and our legitimate interest in carrying it out properly). The same retention periods, the same recipients and the same rules on transfers to Iran apply to their data as to yours.

Please inform those people. As we have no direct contact with them, we fulfil the information obligation through you (Art. 14(5)(b) GDPR). When you provide someone else's data, tell them that it reaches us and the Iranian visa authorities in connection with your application, and point them to this document. Those people have the same rights towards us as you do.

What the form stores in your browser

The application you are filling in is saved in the memory of the open tab (key visaDraft) so that what you typed is not lost if the page reloads. That record does not include the photograph or the passport scan, is not sent anywhere, and disappears the moment you close the tab.

Separately, in browser storage, we remember the form language you chose (key visaLang) so that the form opens in the same language on your next visit.

Both records are necessary to provide the service you have requested, so they require no consent (Art. 399(3) PECA). The full list of what goes into your browser — together with how long each item lives — is in Data stored in your browser.

Payment

You pay for the service by ordinary bank transfer. The QR code containing the transfer details is generated inside your browser from our account number and the amount due — there is no payment gateway, we do not redirect you to a payment provider, and we do not process any card details or online banking credentials.

Self-drive trip planner (Uganda)

The planner lets you design a route, choose a car, dates and add-ons, and see a price. All of this data stays in your browser — we do not send it to our server and we cannot see what you are putting together.

We store your plan in your browser's storage (key sdKreator) so that you can come back to it later. Because that storage is meant to survive closing your browser, it requires your consent — the “functional” category in . If you do not consent, the planner works in exactly the same way, but your plan will disappear when you close your browser.

You can send us your finished quotation by e-mail or via WhatsApp — the button opens your mail program or messenger with the message prepared for you. You are the one who sends that message, so the data reaches us only once you send it; we then process it as described in section 3.

The website contains a currently inactive feature under which downloading the full day-by-day plan would require an e-mail address or phone number. The feature is switched off and collects no data. If we ever enable it, providing contact details will be voluntary and based on your consent (Art. 6(1)(a) GDPR), and we will update this document before launching it.

“Do you know where Iran is?” survey

At /uganda/ankieta-iran we run a short, anonymous survey of geographical knowledge: we show a map with no country names and ask you to point out where Iran is. Taking part is voluntary and requires no account and no personal data whatsoever. We do not ask for your name, e-mail address or phone number.

What we record from your answer: a random answer identifier, the date and time, the coordinates of your click on the map, the country calculated from them, whether the answer was correct, and your age bracket, whether you have had contact with Iran, how often you follow news about Iran, and whether you are from Poland. Answering those four questions is a condition of casting a vote; taking part in the survey itself remains voluntary. None of this can be linked back to you.

How we make sure one person answers once. The result would mean little if the same person could vote repeatedly. We use three technical measures:

  • A random identifier in your browser — a technical cookie ank_s (not readable by scripts, valid for 400 days) and a copy of it in browser storage (key ankieta-iran-echo). Both contain nothing but a random string; they say nothing about you and work nowhere else.
  • A hash of your device parameters — the page reads four general values: screen size, colour depth, number of supported touch points and time zone. The server adds the type of operating system (Android, iOS, Windows…) and your IP address. From all of it we compute an irreversible cryptographic hash and store only that — never the values themselves. The hash is deleted after 30 days.
  • A limit on answers from one internet connection — handled the same way, as a hash deleted after 24 hours.

What we do not do. We use no techniques capable of recognising your specific device or tracking you outside this survey — in particular no canvas fingerprinting, audio analysis, font enumeration or graphics card data. The four parameters above are general enough that tens of thousands of people with similar hardware share them with you. We also never store your IP address or full browser identification — only irreversible hashes.

Legal basis. The answers themselves do not allow you to be identified, so they are not personal data within the meaning of Article 4(1) GDPR. Should the hashes described above nonetheless be regarded as personal data, we process them on the basis of our legitimate interest (Article 6(1)(f) GDPR) in the integrity of the survey result. Storing and reading information on your device is strictly necessary to provide the service you requested — taking part in a survey where everyone answers once — and falls within the exemption in Article 399(3) of the Polish Electronic Communications Law. That is why we do not ask for cookie consent here; the survey uses no analytics or advertising tools.

How long we keep it. Answers are kept indefinitely as research material, in a form that identifies no one. The device hash is deleted after 30 days, the connection hash after 24 hours, and the record that “this browser has already answered” after ten years at the latest. Aggregate results are published at /uganda/ankieta-wyniki.

Server logs and security

Like any web server, ours records technical information about requests: IP address, date and time, the address of the page visited, browser and operating system type. This is done automatically by the hosting provider in order to maintain and secure the service.

In addition, to protect the visa form against bots and abuse, we use:

  • a shortened, one-way hash of the IP address, which we use to count submissions from a single address within a short period — the original IP address cannot be recovered from the hash
  • a hidden trap field and a measurement of how long the form took to complete — both detect bots, not you

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the website secure. Data from the protective mechanisms is kept for no longer than 30 days; server logs are kept according to the hosting provider's policy.

Our social media profiles

We run profiles on Instagram and Facebook, to which the website links with ordinary hyperlinks. There are no tracking pixels, social plugins or embedded “like” buttons on this website — unless you click a link yourself, no data goes to Meta.

What happens when you click such a button. You leave our website and arrive at Instagram or Facebook. From that moment your data — including your IP address, device information and the fact that you came from our site — is processed by Meta Platforms Ireland Ltd. on its own terms and for its own purposes. If you are logged into your account, Meta will link that visit to your profile. We have no influence over this and receive no data about you from Meta. Meta also transfers data to the United States, under the European Commission's implementing decision of 10 July 2023 (EU–US Data Privacy Framework).

If you message us through a profile or comment on a post, we process the data visible to us within that social network in order to reply and to run the profile, on the basis of Art. 6(1)(f) GDPR. As regards profile statistics we are joint controllers with Meta (Art. 26 GDPR) — the terms of that arrangement are set by Meta in its Page Controller Addendum.

Data stored in your browser (“cookies”)

With one exception, the site sets no cookies. The exception is the technical cookie used by the “Do you know where Iran is?” survey, described in its own section. To remember what the pages need in order to work we use browser storage (localStorage and sessionStorage). The only cookies that may appear are set by Google Analytics — and only if you consent to it (see below).

This does not change your legal position: Art. 399 PECA refers to “storing information or gaining access to information already stored in a telecommunications terminal device” and is technology-neutral — it covers browser storage exactly as it covers cookies. That is why we ask for your consent on the same terms.

We use two Google tools described below: Google Analytics (visit statistics) and Google Ads (advert performance). Both run only with your consent, which we ask for separately.

Google Analytics

We use Google Analytics 4 to see which pages are viewed, where visitors come from and what devices they browse on. It helps us improve the content and layout. We do not link this data to your name, e-mail address or to anything from your visa code application.

  • Legal basis: your consent — Art. 6(1)(a) GDPR and Art. 399(1) of the Polish Electronic Communications Act.
  • Recipient: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and, for infrastructure, Google LLC in the USA.
  • Transfer outside the EEA: the United States, under the European Commission's implementing decision of 10 July 2023 on the adequate level of protection (EU–US Data Privacy Framework), under which Google is certified.
  • Scope: IP address (shortened by Google automatically before it is stored), page address, referral source, device and browser type, approximate city-level location.
  • Retention: _ga cookies — 2 years; data in the Google Analytics panel — 14 months (the shortest period Google offers for user and event data).
  • Google Signals — enabled, but only with your marketing consent. If you are signed in to a Google account with ad personalisation switched on, Google will link your visit to that account and give us aggregated reports: the approximate age, gender and interests of our visitors, plus the information that the same person visited us from a phone and from a computer. We only ever see summaries, never individual people — and where a group is too small to stay anonymous, Google withholds the data entirely.
    Signals starts only once you also accept the “marketing” category. Consent to statistics alone means ordinary visit measurement without this feature. You can also switch off ad personalisation in your own Google account — Signals then collects nothing, regardless of what you choose here.
  • Link with Google Ads: our Google Analytics account is linked to our Google Ads account. This lets us see which adverts lead to contact with us. We do not buy data about you from other sources and we do not connect the statistics with your name, e-mail address or anything from your visa code application.

Google Ads

We advertise in Google Search. The Google Ads tag lets us check whether a click on an advert ended in contact with us. This tells us which campaigns work, so we do not spend the budget on those that bring no result.

  • Legal basis: your consent — Art. 6(1)(a) GDPR and Art. 399(1) of the Polish Electronic Communications Act.
  • Recipient and transfer: Google Ireland Limited and Google LLC in the USA — on the same basis as Google Analytics (European Commission decision of 10 July 2023, EU–US Data Privacy Framework).
  • Scope: the fact that you arrived from an advert, which advert was clicked, and whether contact followed. Without your name or e-mail address.
  • Retention: Google Ads cookies — 90 days.
  • Audience lists. Once you accept the “marketing” category, information about your visit may be used to build an audience list in Google Ads — for example so that the same advert is not shown to you over and over. We do not build profiles outside Google's system on that basis and we do not share such lists with anyone. If you refuse the marketing category, your browser sends Google a signal prohibiting the use of that data for ad personalisation.
  • Segments created by Google. Independently of us, Google may create audience segments in our advertising account on the basis of interactions with our adverts across its own services (Search, YouTube). We have no influence over their creation and we do not use them to target adverts.
  • We do not upload customer lists to Google, nor any contact details of our customers, for advertising purposes.

Exactly what we store

What we rememberWhereCategoryWhyHow long
Your consent choice
cookieConsent
browser storage strictly necessary So that we do not ask you the same question again on your next visit 12 months
Selected form language
visaLang
browser storage strictly necessary So the visa form opens in Polish or English — whichever you chose until you clear your browser
Draft of your visa code application
visaDraft
open-tab storage strictly necessary So what you typed is not lost if the page reloads. Does not include your photo or passport scan until you close the browser tab
Your trip plan from the planner
sdKreator
browser storage functional So you can come back to the route, car, dates and add-ons you picked, instead of starting over 12 months
Recognising your browser
_ga
cookie (Google) analytics A random number so the statistics do not count you twice. Contains no name or e-mail address of yours 2 years
Current visit number
_ga_…
cookie (Google) analytics Lets one visit be counted as a whole rather than each page you open separately 2 years
Advert click trace
_gcl_au
cookie (Google) marketing Remembers that you reached us from an advert, so we know which campaign works and do not show it to you again 90 days
Linking adverts to statistics
_gac_…
cookie (Google) marketing Connects a visit with a specific advert in the reports 90 days

Strictly necessary items require no consent, because without them the service you have requested cannot be provided properly — the exemption in Art. 399(3) PECA. Functional, analytics and marketing items require your consent, are off by default, and each of them can be accepted or refused independently of the others.

How to manage your consent and data

  • On this website: the button in the page footer. You can change your choice or withdraw consent there — withdrawal immediately deletes the data in the category you refused.
  • In your browser: you can delete all site data at any time. In Chrome and Edge: Settings → Privacy and security → Cookies and site data. In Firefox: Settings → Privacy & Security → Cookies and Site Data. In Safari: Preferences → Privacy → Manage Website Data. Deleting site data also erases the record of your choice, so we will ask for consent again on your next visit.

What happens if you refuse. The website will work normally — all content and tools remain available. The only consequences are that the plan saved in the trip planner will be lost when you close your browser, and your visit will not be counted in our statistics.

Changes to this policy

We update this policy whenever the way we process data changes — for example when we add a new tool or a new website feature. The current version and its effective date are always shown at the top of this page.

If a change affects the scope you consented to, we will ask for your consent again — the banner will then reappear despite your earlier decision.