Contents
Who processes your data
The controller of your personal data is Gazele z Iranu Bartosz Kapica, Polish tax number (NIP): 6351786294, statistical number (REGON): 242958320, address: ul. Tartaczna 8, 43-178 Ornontowice, Poland.
You can contact us:
- by e-mail: kontakt@gazeleziranu.com (visa matters: wiza@gazeleziranu.com)
- by phone: +48 506 55 77 38
GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data. PECA means the Polish Act of 12 July 2024 — Electronic Communications Act (Prawo komunikacji elektronicznej), which implements the ePrivacy Directive in Poland.
Your rights
In relation to the processing of your data, you have the right to:
- access your data and obtain a copy of it (Art. 15 GDPR)
- rectification of inaccurate or incomplete data (Art. 16 GDPR)
- erasure of your data (Art. 17 GDPR) — where we have no remaining basis for processing it
- restriction of processing (Art. 18 GDPR)
- data portability — for data we process on the basis of a contract or your consent, in a machine-readable format (Art. 20 GDPR)
- object to processing based on our legitimate interest (Art. 21 GDPR)
- withdraw your consent at any time, without giving a reason, where processing is based on consent (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
You can change or withdraw your consent to data being stored in your browser at any time using the button available in the footer of every page. This is just as easy as giving consent, as required by Art. 7(3) GDPR.
You also have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.
Contacting us
There is no contact form on this website. Contact happens directly: by e-mail, by phone or via a messenger app (WhatsApp, Telegram) — always on your initiative, after you click a link or a phone number.
What data we process
Whatever you give us: your name or signature, e-mail address or phone number, the content of your message, and — for trip enquiries — information about the planned trip (dates, group size, preferences).
Legal basis and purpose
- Art. 6(1)(b) GDPR — where your enquiry concerns entering into or performing a contract (trip quotation, booking, visa handling)
- Art. 6(1)(f) GDPR — our legitimate interest in answering your question and in defending against possible claims
For how long
We keep correspondence until the matter is closed, and then for the limitation period for claims (as a rule 6 years under Polish law, and 3 years for claims connected with business activity; we apply the longer of the two).
Who else may have access
- our hosting and e-mail provider: LH.PL Sp. z o.o.
- our accountants — if the matter results in an accounting document being issued
Messenger apps. Clicking a WhatsApp or Telegram link takes you to that provider's app or service. From that moment your data is also processed by that provider. If you would rather avoid this, send us an e-mail or call.
Trip participation agreement
If you decide to travel with us, we enter into an agreement for participation in a package travel arrangement. To draw it up, and then to run the trip, we need data about every participant.
What data we collect
- first name and surname
- home address
- e-mail address and phone number
- passport series and number, and its expiry date
- a copy of the passport
Providing this data is voluntary but necessary in order to conclude the agreement. Without it we cannot draw up the document or book flights and accommodation — airlines and hotels require the participant's passport details.
Why, and on what legal basis
- Art. 6(1)(b) GDPR — preparing and performing the package travel agreement: booking flights, accommodation, transport and services on the ground, and keeping in touch with you before and during the trip
- Art. 6(1)(c) GDPR — obligations arising from law, in particular tax and accounting rules and the Polish Act of 24 November 2017 on package travel and linked travel arrangements
- Art. 6(1)(f) GDPR — our legitimate interest in establishing, pursuing or defending against claims
Who we pass it to
- hotels, and partners and carriers in the destination country — to the extent needed to make the bookings
- the insurer — if the trip includes insurance
- our accountants and our hosting and e-mail provider (LH.PL Sp. z o.o.)
Transfers outside the European Economic Area. A trip to Uganda or Iran requires passing participant data to partners operating in those countries. Neither Uganda nor Iran is covered by a European Commission adequacy decision, and the level of protection there may differ from the GDPR standard — as may your ability to enforce your rights before a local authority.
The transfer takes place on the basis of Art. 49(1)(b) GDPR: it is necessary for the performance of the contract you conclude with us. Without it, booking in the destination country is not possible.
How long we keep it
- passport copy — a scan or photo — up to 90 days after the package travel arrangement ends. We need that window to handle complaints, report a claim to the insurer and settle matters with partners in the destination country. After that the file is deleted — the agreement itself does not need a copy of the document.
- agreement data, including the passport series, number and expiry date — for the duration of the agreement and then for the limitation period for a traveller's claims, which is 3 years (Art. 50(5) of the Polish Act on package travel and linked travel arrangements)
- accounting documents — 5 years from the end of the year in which the tax payment deadline fell
We keep these three periods deliberately separate. A copy of a document is far more sensitive than its number alone, so it has the shortest life. The minimisation principle (Art. 5(1)(c) and (e) GDPR) does not allow data to be kept incidentally, merely because other information in the same case has to stay longer.
Application for an Iranian visa code
This is the most sensitive part of the website, so we describe it in the most detail. It applies only to people who fill in and submit the application form.
What the service covers
We act as an intermediary in obtaining a visa code (visa code, also called a visa authorisation) — the vetting of the applicant and the Iranian authorities' approval for a visa to be issued. The visa itself is collected at an Iranian consulate or at an Iranian international airport. Holding a visa code is what the visa is issued on the basis of.
What data we collect
Only what the Iranian visa system requires — you will find the full list of fields in the form. By category, these are:
- identification and family data — including your father's name and marital status, which the Iranian form requires
- contact and address data
- passport data
- employment and education data
- data about the planned trip — together with details of your travel companion, if you are travelling together
- a photograph of your face and a scan or photo of the passport page with your personal data
- technical data — your IP address and browser information (user agent), recorded automatically together with the application; you do not enter these yourself
The form automatically flags applications from people in occupations that Iranian visa authorities scrutinise more closely. The flag exists so that we can warn you about a raised risk of refusal and prepare the application more carefully — what such a flag means for the refund guarantee is set out in the visa service terms. This is not automated decision-making within the meaning of Art. 22 GDPR — the flag alone produces no legal effects concerning you and does not determine the outcome. We do not profile you for any other purpose.
Your photo and passport scan are checked inside your browser. Before anything is sent, the form assesses file quality itself: sharpness, brightness, background, glare, and whether a face is present and correctly positioned. All of this analysis runs on your own device, using code downloaded from our server — the files are not transmitted to anyone for this purpose and are not passed to any image recognition service. They reach us only once you click “Submit”.
Why, and on what legal basis
- Art. 6(1)(b) GDPR — performance of the contract for intermediation in obtaining a visa code, which you enter into with us by submitting the application. This is the main basis: without this data, submitting the application is physically impossible. Providing the data is voluntary but necessary to use the service.
- Art. 6(1)(c) GDPR — compliance with tax and accounting obligations relating to payment for the service
- Art. 6(1)(f) GDPR — our legitimate interest in protecting the form against abuse and in defending against claims
- Art. 49(1)(a) and (b) GDPR — transfer of data to Iran (see below)
Transfer of your data to Iran. Submitting a visa code application requires transferring the above data, including your photograph and passport scan, to the Iranian visa authorities.
Iran is a third country for which the European Commission has not issued an adequacy decision, and we do not apply standard contractual clauses to this transfer. This means that once the data has been transferred:
- a level of protection equivalent to the GDPR does not apply there,
- there is no supervisory authority equivalent to the Polish DPA to which you could complain,
- your ability to enforce your rights and obtain an effective legal remedy may be significantly limited or unavailable in practice,
- Iranian state authorities may gain access to the data under local law.
The transfer takes place on the basis of Art. 49(1)(b) GDPR (it is necessary for the performance of a contract concluded at your request) and your explicit consent under Art. 49(1)(a) GDPR, given together with the completed form. You may withhold that consent — but then applying for a visa code will not be possible. You may withdraw the consent until the data has been transferred to Iran; after that moment withdrawal is no longer possible.
How long we keep it
| Type of data | Period | Why this long |
|---|---|---|
| All application data — including the photograph, passport scan, IP address and browser information | 90 days at most after the matter is closed | After that we delete every copy — from the server and from the e-mail account. We do not keep this data “just in case”: data minimisation (Art. 5(1)(e) GDPR). |
| Register of declarations made — case number, name, e-mail address, mode chosen, amount, IP address and date of submission | 6 years | We must be able to demonstrate that you gave consent (Art. 7(1) GDPR) and requested that performance begin. That is the limitation period for your claims under Polish law (Art. 118 of the Civil Code), so only after it does the evidence stop being needed. The register contains no passport data, photograph or scan — only what is necessary to defend against a claim. |
| Billing data (accounting documents) | 5 years from the end of the year in which the tax payment deadline fell | The only period required outright by law — Polish tax and accounting obligations. It covers invoices and payment confirmations, not the content of the application. |
Who has access to application data
- the controller — the full application data, the photograph and the passport scan reach him in an archive encrypted with AES-256. This means nothing travels electronically in a form readable along the way. The working copy on the server is not accessible from the internet and is deleted right after delivery.
- our hosting and e-mail provider LH.PL Sp. z o.o. — as a processor, under a data processing agreement
- the Iranian visa authorities — see the box on transfers to Iran above
- our accountants — as regards billing data
Other people's data that you provide in the application
The Iranian visa application requires your father's name and your mother's full name and, depending on your situation, also your spouse's details and those of your travel companion. This is third-party data which we do not collect from those people directly — we receive it from you.
We process it solely in order to handle your application, to the extent the Iranian form requires, on the basis of Art. 6(1)(b) and (f) GDPR (performance of the contract concluded with you, and our legitimate interest in carrying it out properly). The same retention periods, the same recipients and the same rules on transfers to Iran apply to their data as to yours.
Please inform those people. As we have no direct contact with them, we fulfil the information obligation through you (Art. 14(5)(b) GDPR). When you provide someone else's data, tell them that it reaches us and the Iranian visa authorities in connection with your application, and point them to this document. Those people have the same rights towards us as you do.
What the form stores in your browser
The application you are filling in is saved in the memory of the open
tab (key visaDraft) so that what you typed is not lost if the
page reloads. That record does not include the photograph or the passport
scan, is not sent anywhere, and disappears the moment you close the tab.
Separately, in browser storage, we remember the form language you
chose (key visaLang) so that the form opens in the same
language on your next visit.
Both records are necessary to provide the service you have requested, so they require no consent (Art. 399(3) PECA). The full list of what goes into your browser — together with how long each item lives — is in Data stored in your browser.
Payment
You pay for the service by ordinary bank transfer. The QR code containing the transfer details is generated inside your browser from our account number and the amount due — there is no payment gateway, we do not redirect you to a payment provider, and we do not process any card details or online banking credentials.
Self-drive trip planner (Uganda)
The planner lets you design a route, choose a car, dates and add-ons, and see a price. All of this data stays in your browser — we do not send it to our server and we cannot see what you are putting together.
We store your plan in your browser's storage (key sdKreator) so that you
can come back to it later. Because that storage is meant to survive closing your
browser, it requires your consent — the “functional” category in
. If you do not consent,
the planner works in exactly the same way, but your plan will disappear when you close
your browser.
You can send us your finished quotation by e-mail or via WhatsApp — the button opens your mail program or messenger with the message prepared for you. You are the one who sends that message, so the data reaches us only once you send it; we then process it as described in section 3.
The website contains a currently inactive feature under which downloading the full day-by-day plan would require an e-mail address or phone number. The feature is switched off and collects no data. If we ever enable it, providing contact details will be voluntary and based on your consent (Art. 6(1)(a) GDPR), and we will update this document before launching it.
“Do you know where Iran is?” survey
At /uganda/ankieta-iran we run a short, anonymous survey
of geographical knowledge: we show a map with no country names and ask you to point out
where Iran is. Taking part is voluntary and requires no account and no personal data
whatsoever. We do not ask for your name, e-mail address or phone number.
What we record from your answer: a random answer identifier, the date and time, the coordinates of your click on the map, the country calculated from them, whether the answer was correct, and your age bracket, whether you have had contact with Iran, how often you follow news about Iran, and whether you are from Poland. Answering those four questions is a condition of casting a vote; taking part in the survey itself remains voluntary. None of this can be linked back to you.
How we make sure one person answers once. The result would mean little if the same person could vote repeatedly. We use three technical measures:
- A random identifier in your browser — a technical cookie
ank_s(not readable by scripts, valid for 400 days) and a copy of it in browser storage (keyankieta-iran-echo). Both contain nothing but a random string; they say nothing about you and work nowhere else. - A hash of your device parameters — the page reads four general values: screen size, colour depth, number of supported touch points and time zone. The server adds the type of operating system (Android, iOS, Windows…) and your IP address. From all of it we compute an irreversible cryptographic hash and store only that — never the values themselves. The hash is deleted after 30 days.
- A limit on answers from one internet connection — handled the same way, as a hash deleted after 24 hours.
What we do not do. We use no techniques capable of recognising your specific device or tracking you outside this survey — in particular no canvas fingerprinting, audio analysis, font enumeration or graphics card data. The four parameters above are general enough that tens of thousands of people with similar hardware share them with you. We also never store your IP address or full browser identification — only irreversible hashes.
Legal basis. The answers themselves do not allow you to be identified, so they are not personal data within the meaning of Article 4(1) GDPR. Should the hashes described above nonetheless be regarded as personal data, we process them on the basis of our legitimate interest (Article 6(1)(f) GDPR) in the integrity of the survey result. Storing and reading information on your device is strictly necessary to provide the service you requested — taking part in a survey where everyone answers once — and falls within the exemption in Article 399(3) of the Polish Electronic Communications Law. That is why we do not ask for cookie consent here; the survey uses no analytics or advertising tools.
How long we keep it. Answers are kept indefinitely as research material,
in a form that identifies no one. The device hash is deleted after 30 days, the connection
hash after 24 hours, and the record that “this browser has already answered” after ten
years at the latest. Aggregate results are published at
/uganda/ankieta-wyniki.
Server logs and security
Like any web server, ours records technical information about requests: IP address, date and time, the address of the page visited, browser and operating system type. This is done automatically by the hosting provider in order to maintain and secure the service.
In addition, to protect the visa form against bots and abuse, we use:
- a shortened, one-way hash of the IP address, which we use to count submissions from a single address within a short period — the original IP address cannot be recovered from the hash
- a hidden trap field and a measurement of how long the form took to complete — both detect bots, not you
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the website secure. Data from the protective mechanisms is kept for no longer than 30 days; server logs are kept according to the hosting provider's policy.
Changes to this policy
We update this policy whenever the way we process data changes — for example when we add a new tool or a new website feature. The current version and its effective date are always shown at the top of this page.
If a change affects the scope you consented to, we will ask for your consent again — the banner will then reappear despite your earlier decision.
Our social media profiles
We run profiles on Instagram and Facebook, to which the website links with ordinary hyperlinks. There are no tracking pixels, social plugins or embedded “like” buttons on this website — unless you click a link yourself, no data goes to Meta.
What happens when you click such a button. You leave our website and arrive at Instagram or Facebook. From that moment your data — including your IP address, device information and the fact that you came from our site — is processed by Meta Platforms Ireland Ltd. on its own terms and for its own purposes. If you are logged into your account, Meta will link that visit to your profile. We have no influence over this and receive no data about you from Meta. Meta also transfers data to the United States, under the European Commission's implementing decision of 10 July 2023 (EU–US Data Privacy Framework).
If you message us through a profile or comment on a post, we process the data visible to us within that social network in order to reply and to run the profile, on the basis of Art. 6(1)(f) GDPR. As regards profile statistics we are joint controllers with Meta (Art. 26 GDPR) — the terms of that arrangement are set by Meta in its Page Controller Addendum.