Privacy policy
Contents
1. Who processes your data
The controller of your personal data is Bartosz Kapica, a sole trader operating as Gazele z Iranu Bartosz Kapica, Polish tax number (NIP) 6351786294, statistical number (REGON) 242958320, address: ul. Tartaczna 8, 43-178 Ornontowice, Poland.
You can contact us about any data protection matter:
- by e-mail: kontakt@gazeleziranu.com (visa matters: wiza@gazeleziranu.com)
- by phone: +48 506 55 77 38
- by post — at the address above
GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data. PECA means the Polish Act of 12 July 2024 — Electronic Communications Act (Prawo komunikacji elektronicznej), which implements the ePrivacy Directive in Poland.
2. Your rights
In relation to the processing of your data, you have the right to:
- access your data and obtain a copy of it (Art. 15 GDPR)
- rectification of inaccurate or incomplete data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR) — where we have no remaining basis for processing it
- restriction of processing (Art. 18 GDPR)
- data portability — for data we process on the basis of a contract or your consent, in a machine-readable format (Art. 20 GDPR)
- object to processing based on our legitimate interest (Art. 21 GDPR)
- withdraw your consent at any time, without giving a reason, where processing is based on consent (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
You can change or withdraw your consent to data being stored in your browser at any time using the button available in the footer of every page. This is just as easy as giving consent, as required by Art. 7(3) GDPR.
You also have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.
3. Contacting us
There is no contact form on this website. Contact happens directly: by e-mail, by phone or via a messenger app (WhatsApp, Telegram) — always on your initiative, after you click a link or a phone number.
What data we process
Whatever you give us: your name or signature, e-mail address or phone number, the content of your message, and — for trip enquiries — information about the planned trip (dates, group size, preferences).
Legal basis and purpose
- Art. 6(1)(b) GDPR — where your enquiry concerns entering into or performing a contract (trip quotation, booking, visa handling)
- Art. 6(1)(f) GDPR — our legitimate interest in answering your question and in defending against possible claims
For how long
We keep correspondence until the matter is closed, and then for the limitation period for claims (as a rule 6 years under Polish law, and 3 years for claims connected with business activity; we apply the longer of the two).
Who else may have access
- our hosting and e-mail provider: LH.PL Sp. z o.o.
- our accountants — if the matter results in an accounting document being issued
Messenger apps. Clicking a WhatsApp or Telegram link takes you to that provider's app or service. From that moment your data is also processed by that provider. If you would rather avoid this, send us an e-mail or call.
4. Iranian visa code application
This is the most sensitive part of the website, so we describe it in the most detail. It applies only to people who fill in and submit the application form.
What the service actually is. We act as an intermediary in obtaining a visa code (also called a visa authorisation or grant notice) — the Iranian authorities' approval for a visa to be issued. The visa itself is issued later by a consulate or on arrival in Iran, on the basis of that code. We do not issue visas and do not decide whether they are granted.
What data we collect
- Identification data: first name, surname, father's name, gender, date and place of birth (country and city), nationality, marital status and — if you are married — your spouse's name
- Employment and education data: occupation, industry or company name, position, education level and field of study
- Contact data: e-mail address, phone number, home address, postal code
- Passport data: passport number and type, date and place of issue, expiry date, information about other passports held
- Travel data: planned entry and departure dates, length of stay, visa type, entry type, previous visits to Iran, chosen visa collection office, details of your travel companion and their relationship to you
- A photograph of your face and a scan or photo of your passport data page
- Technical data: your IP address and browser information (user agent), stored together with the application
The form automatically flags applications from people in occupations that Iranian visa authorities scrutinise more closely. The flag exists solely so that we can warn you about a possibly longer processing time and prepare the application more carefully. This is not automated decision-making within the meaning of Art. 22 GDPR — the flag alone produces no legal effects concerning you and does not determine the outcome. We do not profile you for any other purpose.
Your photo and passport scan are checked inside your browser. Before anything is sent, the form assesses file quality itself: sharpness, brightness, background, glare, and whether a face is present and correctly positioned. All of this analysis runs on your own device, using code downloaded from our server — the files are not transmitted to anyone for this purpose and are not passed to any image recognition service. They reach us only once you click “Submit”.
Why, and on what legal basis
- Art. 6(1)(b) GDPR — performance of the contract for intermediation in obtaining a visa code, which you enter into with us by submitting the application. This is the main basis: without this data, submitting the application is physically impossible. Providing the data is voluntary but necessary to use the service.
- Art. 6(1)(c) GDPR — compliance with tax and accounting obligations relating to payment for the service
- Art. 6(1)(f) GDPR — our legitimate interest in protecting the form against abuse and in defending against claims
- Art. 49(1)(a) and (b) GDPR — transfer of data to Iran (see below)
Transfer of your data to Iran. Submitting a visa code application requires transferring the above data, including your photograph and passport scan, to the Iranian visa authorities.
Iran is a third country for which the European Commission has not issued an adequacy decision, and we do not apply standard contractual clauses to this transfer. This means that once the data has been transferred:
- a level of protection equivalent to the GDPR does not apply there,
- there is no supervisory authority equivalent to the Polish DPA to which you could complain,
- your ability to enforce your rights and obtain an effective legal remedy may be significantly limited or unavailable in practice,
- Iranian state authorities may gain access to the data under local law.
The transfer takes place on the basis of Art. 49(1)(b) GDPR (it is necessary for the performance of a contract concluded at your request) and your explicit consent under Art. 49(1)(a) GDPR, given together with the completed form. You may withhold that consent — but then we cannot submit a visa application on your behalf. You may withdraw the consent until the data has been transferred to Iran; after that moment withdrawal is no longer possible.
How long we keep it
| Type of data | Period | Why this long |
|---|---|---|
| All application data — including the photograph, passport scan, IP address and browser information | 30 days at most after the matter is closed | A short window for complaints or resubmission. After that we delete every copy — from the server and from the e-mail account. We do not keep this data “just in case”: data minimisation (Art. 5(1)(e) GDPR). |
| Billing data (accounting documents) | 5 years from the end of the year in which the tax payment deadline fell | The only period required outright by law — Polish tax and accounting obligations. It covers invoices and payment confirmations, not the content of the application. |
Who has access to application data
- the controller — the full application data, the photograph and the passport scan reach him in a single archive encrypted with AES-256, whose password only he knows. This means nothing travels electronically in a form readable along the way. The working copy on the server is not accessible from the internet and is deleted right after delivery.
- our hosting and e-mail provider LH.PL Sp. z o.o. — as a processor, under a data processing agreement
- the Iranian visa authorities — see the box on transfers to Iran above
- our accountants — as regards billing data
Payment
You pay for the service by ordinary bank transfer. The QR code containing the transfer details is generated inside your browser from our account number and the amount due — there is no payment gateway, we do not redirect you to a payment provider, and we do not process any card details or online banking credentials. The payment confirmation you send us is kept together with the accounting records.
5. Self-drive trip planner (Uganda)
The planner lets you design a route, choose a car, dates and add-ons, and see a price. All of this data stays in your browser — we do not send it to our server and we cannot see what you are putting together.
We store your plan in your browser's storage (key sdKreator) so that you
can come back to it later. Because that storage is meant to survive closing your
browser, it requires your consent — the “functional” category in
. If you do not consent,
the planner works in exactly the same way, but your plan will disappear when you close
your browser.
You can send us your finished quotation by e-mail or via WhatsApp — the button opens your mail program or messenger with the message prepared for you. You are the one who sends that message, so the data reaches us only once you send it; we then process it as described in section 3.
The website contains a currently inactive feature under which downloading the full day-by-day plan would require an e-mail address or phone number. The feature is switched off and collects no data. If we ever enable it, providing contact details will be voluntary and based on your consent (Art. 6(1)(a) GDPR), and we will update this document before launching it.
6. Server logs and security
Like any web server, ours records technical information about requests: IP address, date and time, the address of the page visited, browser and operating system type. This is done automatically by the hosting provider in order to maintain and secure the service.
In addition, to protect the visa form against bots and abuse, we use:
- a shortened, one-way hash of the IP address, which we use to count submissions from a single address within a short period — the original IP address cannot be recovered from the hash
- a hidden trap field and a measurement of how long the form took to complete — both detect bots, not you
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the website secure. Data from the protective mechanisms is kept for no longer than 30 days; server logs are kept according to the hosting provider's policy.
9. Changes to this policy
We update this policy whenever the way we process data changes — for example when we add a new tool or a new website feature. The current version and its effective date are always shown at the top of this page.
If a change affects the scope you consented to, we will ask for your consent again — the banner will then reappear despite your earlier decision.
7. Our social media profiles
We run profiles on Instagram and Facebook, to which the website links with ordinary hyperlinks. There are no tracking pixels, social plugins or embedded “like” buttons on this website — unless you click a link yourself, no data goes to Meta.
What happens when you click such a button. You leave our website and arrive at Instagram or Facebook. From that moment your data — including your IP address, device information and the fact that you came from our site — is processed by Meta Platforms Ireland Ltd. on its own terms and for its own purposes. If you are logged into your account, Meta will link that visit to your profile. We have no influence over this and receive no data about you from Meta. Meta also transfers data to the United States, under the European Commission's implementing decision of 10 July 2023 (EU–US Data Privacy Framework).
If you message us through a profile or comment on a post, we process the data visible to us within that social network in order to reply and to run the profile, on the basis of Art. 6(1)(f) GDPR. As regards profile statistics we are joint controllers with Meta (Art. 26 GDPR) — the terms of that arrangement are set by Meta in its Page Controller Addendum.