Wersja polska ← Home

Privacy policy

Version 1.0 · effective from 1 August 2026
Applies to the www.gazeleziranu.com website, including the “Uganda” and “Iran” sections and the visa code application form.

This is an English translation provided for your convenience. The Polish version is the authoritative text: Polityka prywatności.

1. Who processes your data

The controller of your personal data is Bartosz Kapica, a sole trader operating as Gazele z Iranu Bartosz Kapica, Polish tax number (NIP) 6351786294, statistical number (REGON) 242958320, address: ul. Tartaczna 8, 43-178 Ornontowice, Poland.

You can contact us about any data protection matter:

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of personal data. PECA means the Polish Act of 12 July 2024 — Electronic Communications Act (Prawo komunikacji elektronicznej), which implements the ePrivacy Directive in Poland.

2. Your rights

In relation to the processing of your data, you have the right to:

  • access your data and obtain a copy of it (Art. 15 GDPR)
  • rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • erasure of your data (Art. 17 GDPR) — where we have no remaining basis for processing it
  • restriction of processing (Art. 18 GDPR)
  • data portability — for data we process on the basis of a contract or your consent, in a machine-readable format (Art. 20 GDPR)
  • object to processing based on our legitimate interest (Art. 21 GDPR)
  • withdraw your consent at any time, without giving a reason, where processing is based on consent (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

You can change or withdraw your consent to data being stored in your browser at any time using the button available in the footer of every page. This is just as easy as giving consent, as required by Art. 7(3) GDPR.

You also have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.

3. Contacting us

There is no contact form on this website. Contact happens directly: by e-mail, by phone or via a messenger app (WhatsApp, Telegram) — always on your initiative, after you click a link or a phone number.

What data we process

Whatever you give us: your name or signature, e-mail address or phone number, the content of your message, and — for trip enquiries — information about the planned trip (dates, group size, preferences).

Legal basis and purpose

  • Art. 6(1)(b) GDPR — where your enquiry concerns entering into or performing a contract (trip quotation, booking, visa handling)
  • Art. 6(1)(f) GDPR — our legitimate interest in answering your question and in defending against possible claims

For how long

We keep correspondence until the matter is closed, and then for the limitation period for claims (as a rule 6 years under Polish law, and 3 years for claims connected with business activity; we apply the longer of the two).

Who else may have access

  • our hosting and e-mail provider: LH.PL Sp. z o.o.
  • our accountants — if the matter results in an accounting document being issued

Messenger apps. Clicking a WhatsApp or Telegram link takes you to that provider's app or service. From that moment your data is also processed by that provider. If you would rather avoid this, send us an e-mail or call.

4. Iranian visa code application

This is the most sensitive part of the website, so we describe it in the most detail. It applies only to people who fill in and submit the application form.

What the service actually is. We act as an intermediary in obtaining a visa code (also called a visa authorisation or grant notice) — the Iranian authorities' approval for a visa to be issued. The visa itself is issued later by a consulate or on arrival in Iran, on the basis of that code. We do not issue visas and do not decide whether they are granted.

What data we collect

  • Identification data: first name, surname, father's name, gender, date and place of birth (country and city), nationality, marital status and — if you are married — your spouse's name
  • Employment and education data: occupation, industry or company name, position, education level and field of study
  • Contact data: e-mail address, phone number, home address, postal code
  • Passport data: passport number and type, date and place of issue, expiry date, information about other passports held
  • Travel data: planned entry and departure dates, length of stay, visa type, entry type, previous visits to Iran, chosen visa collection office, details of your travel companion and their relationship to you
  • A photograph of your face and a scan or photo of your passport data page
  • Technical data: your IP address and browser information (user agent), stored together with the application

The form automatically flags applications from people in occupations that Iranian visa authorities scrutinise more closely. The flag exists solely so that we can warn you about a possibly longer processing time and prepare the application more carefully. This is not automated decision-making within the meaning of Art. 22 GDPR — the flag alone produces no legal effects concerning you and does not determine the outcome. We do not profile you for any other purpose.

Your photo and passport scan are checked inside your browser. Before anything is sent, the form assesses file quality itself: sharpness, brightness, background, glare, and whether a face is present and correctly positioned. All of this analysis runs on your own device, using code downloaded from our server — the files are not transmitted to anyone for this purpose and are not passed to any image recognition service. They reach us only once you click “Submit”.

Why, and on what legal basis

  • Art. 6(1)(b) GDPR — performance of the contract for intermediation in obtaining a visa code, which you enter into with us by submitting the application. This is the main basis: without this data, submitting the application is physically impossible. Providing the data is voluntary but necessary to use the service.
  • Art. 6(1)(c) GDPR — compliance with tax and accounting obligations relating to payment for the service
  • Art. 6(1)(f) GDPR — our legitimate interest in protecting the form against abuse and in defending against claims
  • Art. 49(1)(a) and (b) GDPR — transfer of data to Iran (see below)

Transfer of your data to Iran. Submitting a visa code application requires transferring the above data, including your photograph and passport scan, to the Iranian visa authorities.

Iran is a third country for which the European Commission has not issued an adequacy decision, and we do not apply standard contractual clauses to this transfer. This means that once the data has been transferred:

  • a level of protection equivalent to the GDPR does not apply there,
  • there is no supervisory authority equivalent to the Polish DPA to which you could complain,
  • your ability to enforce your rights and obtain an effective legal remedy may be significantly limited or unavailable in practice,
  • Iranian state authorities may gain access to the data under local law.

The transfer takes place on the basis of Art. 49(1)(b) GDPR (it is necessary for the performance of a contract concluded at your request) and your explicit consent under Art. 49(1)(a) GDPR, given together with the completed form. You may withhold that consent — but then we cannot submit a visa application on your behalf. You may withdraw the consent until the data has been transferred to Iran; after that moment withdrawal is no longer possible.

How long we keep it

Type of dataPeriodWhy this long
All application data — including the photograph, passport scan, IP address and browser information 30 days at most after the matter is closed A short window for complaints or resubmission. After that we delete every copy — from the server and from the e-mail account. We do not keep this data “just in case”: data minimisation (Art. 5(1)(e) GDPR).
Billing data (accounting documents) 5 years from the end of the year in which the tax payment deadline fell The only period required outright by law — Polish tax and accounting obligations. It covers invoices and payment confirmations, not the content of the application.

Who has access to application data

  • the controller — the full application data, the photograph and the passport scan reach him in a single archive encrypted with AES-256, whose password only he knows. This means nothing travels electronically in a form readable along the way. The working copy on the server is not accessible from the internet and is deleted right after delivery.
  • our hosting and e-mail provider LH.PL Sp. z o.o. — as a processor, under a data processing agreement
  • the Iranian visa authorities — see the box on transfers to Iran above
  • our accountants — as regards billing data

Payment

You pay for the service by ordinary bank transfer. The QR code containing the transfer details is generated inside your browser from our account number and the amount due — there is no payment gateway, we do not redirect you to a payment provider, and we do not process any card details or online banking credentials. The payment confirmation you send us is kept together with the accounting records.

5. Self-drive trip planner (Uganda)

The planner lets you design a route, choose a car, dates and add-ons, and see a price. All of this data stays in your browser — we do not send it to our server and we cannot see what you are putting together.

We store your plan in your browser's storage (key sdKreator) so that you can come back to it later. Because that storage is meant to survive closing your browser, it requires your consent — the “functional” category in . If you do not consent, the planner works in exactly the same way, but your plan will disappear when you close your browser.

You can send us your finished quotation by e-mail or via WhatsApp — the button opens your mail program or messenger with the message prepared for you. You are the one who sends that message, so the data reaches us only once you send it; we then process it as described in section 3.

The website contains a currently inactive feature under which downloading the full day-by-day plan would require an e-mail address or phone number. The feature is switched off and collects no data. If we ever enable it, providing contact details will be voluntary and based on your consent (Art. 6(1)(a) GDPR), and we will update this document before launching it.

6. Server logs and security

Like any web server, ours records technical information about requests: IP address, date and time, the address of the page visited, browser and operating system type. This is done automatically by the hosting provider in order to maintain and secure the service.

In addition, to protect the visa form against bots and abuse, we use:

  • a shortened, one-way hash of the IP address, which we use to count submissions from a single address within a short period — the original IP address cannot be recovered from the hash
  • a hidden trap field and a measurement of how long the form took to complete — both detect bots, not you

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in keeping the website secure. Data from the protective mechanisms is kept for no longer than 30 days; server logs are kept according to the hosting provider's policy.

7. Our social media profiles

We run profiles on Instagram and Facebook, to which the website links with ordinary hyperlinks. There are no tracking pixels, social plugins or embedded “like” buttons on this website — unless you click a link yourself, no data goes to Meta.

What happens when you click such a button. You leave our website and arrive at Instagram or Facebook. From that moment your data — including your IP address, device information and the fact that you came from our site — is processed by Meta Platforms Ireland Ltd. on its own terms and for its own purposes. If you are logged into your account, Meta will link that visit to your profile. We have no influence over this and receive no data about you from Meta. Meta also transfers data to the United States, under the European Commission's implementing decision of 10 July 2023 (EU–US Data Privacy Framework).

If you message us through a profile or comment on a post, we process the data visible to us within that social network in order to reply and to run the profile, on the basis of Art. 6(1)(f) GDPR. As regards profile statistics we are joint controllers with Meta (Art. 26 GDPR) — the terms of that arrangement are set by Meta in its Page Controller Addendum.

8. Data stored in your browser (“cookies”)

The site itself sets no cookies at all. To remember what the pages need in order to work we use browser storage (localStorage and sessionStorage). The only cookies that may appear are set by Google Analytics — and only if you consent to it (see below).

This does not change your legal position: Art. 399 PECA refers to “storing information or gaining access to information already stored in a telecommunications terminal device” and is technology-neutral — it covers browser storage exactly as it covers cookies. That is why we ask for your consent on the same terms.

We use two Google tools described below: Google Analytics (visit statistics) and Google Ads (advert performance). Both run only with your consent, which we ask for separately.

Google Analytics 4

We use Google Analytics 4 to see which pages are viewed, where visitors come from and what devices they browse on. It helps us improve the content and layout. We do not link this data to your name, e-mail address or to anything from your visa code application.

  • Legal basis: your consent — Art. 6(1)(a) GDPR and Art. 399(1) of the Polish Electronic Communications Act.
  • Recipient: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and, for infrastructure, Google LLC in the USA.
  • Transfer outside the EEA: the United States, under the European Commission's implementing decision of 10 July 2023 on the adequate level of protection (EU–US Data Privacy Framework), under which Google is certified.
  • Scope: IP address (shortened by Google automatically before it is stored), page address, referral source, device and browser type, approximate city-level location.
  • Retention: _ga cookies — 2 years; data in the Google Analytics panel — 14 months (the shortest period Google offers for user and event data).
  • Google Signals — enabled, but only with your marketing consent. If you are signed in to a Google account with ad personalisation switched on, Google will link your visit to that account and give us aggregated reports: the approximate age, gender and interests of our visitors, plus the information that the same person visited us from a phone and from a computer. We only ever see summaries, never individual people — and where a group is too small to stay anonymous, Google withholds the data entirely.
    Signals starts only once you also accept the “marketing” category. Consent to statistics alone means ordinary visit measurement without this feature. You can also switch off ad personalisation in your own Google account — Signals then collects nothing, regardless of what you choose here.
  • Link with Google Ads: our Google Analytics account is linked to our Google Ads account. This lets us see which adverts lead to contact with us. We do not buy data about you from other sources and we do not connect the statistics with your name, e-mail address or anything from your visa code application.

Google Ads

We advertise in Google Search. The Google Ads tag lets us check whether a click on an advert ended in contact with us. This tells us which campaigns work, so we do not spend the budget on those that bring no result.

This is a separate consent from statistics. If you enable only the “analytics” category in the settings, the advertising tag will not run — and vice versa.

  • Legal basis: your consent — Art. 6(1)(a) GDPR and Art. 399(1) of the Polish Electronic Communications Act.
  • Recipient and transfer: Google Ireland Limited and Google LLC in the USA — on the same basis as Google Analytics (European Commission decision of 10 July 2023, EU–US Data Privacy Framework).
  • Scope: the fact that you arrived from an advert, which advert was clicked, and whether contact followed. Without your name or e-mail address.
  • Retention: Google Ads cookies — 90 days.
  • Audience lists. Once you accept the “marketing” category, information about your visit may be used to build an audience list in Google Ads — for example so that the same advert is not shown to you over and over. We do not build profiles outside Google's system on that basis and we do not share such lists with anyone. If you refuse the marketing category, your browser sends Google a signal prohibiting the use of that data for ad personalisation.
  • Segments created by Google. Independently of us, Google may create audience segments in our advertising account on the basis of interactions with our adverts across its own services (Search, YouTube). We have no influence over their creation and we do not use them to target adverts.
  • We do not upload customer lists to Google, nor any contact details of our customers, for advertising purposes.

Exactly what we store

What we rememberWhereCategoryWhyHow long
Your consent choice
cookieConsent
browser storage strictly necessary So that we do not ask you the same question again on your next visit 12 months
Selected form language
visaLang
browser storage strictly necessary So the visa form opens in Polish or English — whichever you chose until you clear your browser
Draft of your visa code application
visaDraft
open-tab storage strictly necessary So what you typed is not lost if the page reloads. Does not include your photo or passport scan until you close the browser tab
Your trip plan from the planner
sdKreator
browser storage functional So you can come back to the route, car, dates and add-ons you picked, instead of starting over 12 months
Recognising your browser
_ga
cookie (Google) analytics A random number so the statistics do not count you twice. Contains no name or e-mail address of yours 2 years
Current visit number
_ga_…
cookie (Google) analytics Lets one visit be counted as a whole rather than each page you open separately 2 years
Advert click trace
_gcl_au
cookie (Google) marketing Remembers that you reached us from an advert, so we know which campaign works and do not show it to you again 90 days
Linking adverts to statistics
_gac_…
cookie (Google) marketing Connects a visit with a specific advert in the reports 90 days

Strictly necessary items require no consent, because without them the service you have requested cannot be provided properly — the exemption in Art. 399(3) PECA. Functional, analytics and marketing items require your consent, are off by default, and each of them can be accepted or refused independently of the others.

How to manage your consent and data

  • On this website: the button in the page footer. You can change your choice or withdraw consent there — withdrawal immediately deletes the data in the category you refused.
  • In your browser: you can delete all site data at any time. In Chrome and Edge: Settings → Privacy and security → Cookies and site data. In Firefox: Settings → Privacy & Security → Cookies and Site Data. In Safari: Preferences → Privacy → Manage Website Data. Deleting site data also erases the record of your choice, so we will ask for consent again on your next visit.

What happens if you refuse. The website will work normally — all content and tools remain available. The only consequences are that the plan saved in the trip planner will be lost when you close your browser, and your visit will not be counted in our statistics.

9. Changes to this policy

We update this policy whenever the way we process data changes — for example when we add a new tool or a new website feature. The current version and its effective date are always shown at the top of this page.

If a change affects the scope you consented to, we will ask for your consent again — the banner will then reappear despite your earlier decision.