Privacy Policy
This Privacy Policy explains how Casa Dominicana sp. z o.o. collects, uses, and protects the personal data of users of the website www.casa-dominicana.com. This document fulfills the information obligation arising from Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
1. Personal Data Controller
The controller of your personal data is:
CASA DOMINICANA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
- Prosta 70, 00-838 Warsaw
KRS: 0000890333 | NIP: 7011025906 | REGON: 388469220
Email: andrzej@casa-dominicana.com
Phone: +48 782 942 023
(hereinafter: “Controller”)
The Controller has not appointed a Data Protection Officer. For matters concerning the processing of personal data, please contact the Controller directly at the email address provided. [TO BE COMPLETED if a DPO has been appointed]
2. Purposes and Legal Bases for Data Processing
The Controller processes personal data for the following purposes:
2.1 Contact Form / Inquiry About Offer
Purpose: handling inquiries submitted via contact form, email, phone, WhatsApp, or other communication channel.
Scope of data: first and last name (optional), email address, phone number (optional), message content.
Legal basis: Article 6(1)(b) GDPR – taking steps at the request of the data subject prior to entering into a contract; Article 6(1)(f) GDPR – legitimate interest of the Controller (providing a response to the inquiry).
Retention period: for the time necessary to handle the inquiry, no longer than 3 years from the last contact, unless a contract resulted from the inquiry (in which case until the expiration of claims arising from the contract).
2.2 Newsletter
Purpose: sending commercial information, property offers, and marketing materials electronically.
Scope of data: email address, optionally first name.
Legal basis: Article 6(1)(a) GDPR – consent given during newsletter subscription.
Retention period: until consent is withdrawn or unsubscription from the newsletter. Proof of consent for 3 years from the end of subscription.
Right to withdraw consent: consent may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal.
2.3 Email / Phone / SMS Marketing
Purpose: sending offers and marketing materials through channels other than newsletter (direct email, phone, SMS).
Legal basis: Article 6(1)(a) GDPR – separately given consent, or Article 6(1)(f) GDPR – legitimate interest of the Controller (marketing of own services to clients).
2.4 Conclusion and Performance of Brokerage Agreement
Purpose: performance of real estate brokerage agreement, including conducting investment consultations, presenting offers, preparing documentation.
Scope of data: first and last name, PESEL or passport number, residential address, contact details, financial data necessary for transaction execution.
Legal basis: Article 6(1)(b) GDPR – performance of contract; Article 6(1)(c) GDPR – legal obligations (tax regulations, AML).
Retention period: 5 years from the end of the year in which the contractual relationship ended, or longer if required by specific regulations.
2.5 Website Analytics (Google Analytics)
Purpose: analyzing how the website is used, improving its functionality and content.
Scope of data: data on user behavior on the website, IP address (anonymized), device and browser type, entry source.
Legal basis: Article 6(1)(a) GDPR – consent given via cookie banner; Article 6(1)(f) GDPR – legitimate interest (traffic analysis).
Tool operator: Google LLC (United States) – data transfer outside the EEA based on standard contractual clauses (SCCs).
2.6 Marketing and Remarketing (Meta Pixel / Facebook Ads)
Purpose: displaying personalized advertisements on Meta services (Facebook, Instagram), remarketing to website users.
Scope of data: browser/device identifiers, event data (visits, clicks), information about behavior on the website.
Legal basis: Article 6(1)(a) GDPR – consent given via cookie banner.
Tool operator: Meta Platforms Ireland Ltd. (Ireland) / Meta Platforms Inc. (United States) – data transfer outside the EEA based on SCCs.
[TO BE COMPLETED: if other advertising tools are used: Google Ads, TikTok Pixel, Hotjar, etc.]
2.7 Communication via WhatsApp
Purpose: handling inquiries and communication with clients via WhatsApp messenger.
Scope of data: phone number, message content, possibly data provided by the user during conversation.
Legal basis: Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
Note: using WhatsApp involves data processing by Meta Platforms Inc. The Controller recommends reviewing WhatsApp’s privacy policy.
3. Categories of Data Recipients
The Controller may transfer personal data to the following categories of recipients:
- IT systems and software providers (CRM, mailing systems, hosting) – based on data processing agreements;
- analytical and marketing service providers (Google, Meta) – as separate controllers or processors;
- law firms and notaries – to the extent necessary for real estate transactions;
- public administration authorities – based on generally applicable legal provisions (e.g., tax offices, AML authorities);
- business partners (developers, agents in the Dominican Republic) – only with the person’s consent or to the extent necessary to handle the inquiry.
4. Data Transfers Outside the EEA
Personal data may be transferred outside the European Economic Area in connection with the use of services from Google LLC and Meta Platforms Inc. The transfer is based on standard contractual clauses (SCCs) adopted by the European Commission. A copy of the clauses can be obtained by contacting the Controller.
5. Rights of the Data Subject
You have the following rights:
- right of access to your data (Article 15 GDPR);
- right to rectification of data (Article 16 GDPR);
- right to erasure of data (“right to be forgotten”) (Article 17 GDPR);
- right to restriction of processing (Article 18 GDPR);
- right to data portability (Article 20 GDPR);
- right to object to processing (Article 21 GDPR) – applies to processing based on legitimate interest;
- right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise the above rights, please contact the Controller: andrzej@casa-dominicana.com.
The Controller will provide a response within 30 days of receiving the request. In complex cases, this period may be extended by an additional 60 days (with notification to the applicant of the reason for the delay).
6. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, tel. 606 950 000, email: kancelaria@uodo.gov.pl, www.uodo.gov.pl – if you believe that the processing of your data violates GDPR provisions.
7. Profiling
The Controller may use profiling for marketing purposes (e.g., displaying advertisements tailored to user interests using Meta Pixel or Google Ads). Profiling does not produce legal effects concerning the data subject, nor does it similarly significantly affect them.
The user may withdraw consent for marketing cookies at any time via the consent banner or by managing cookie settings on the website.
8. Contact Principles via Individual Channels
The Controller processes personal data obtained through:
- contact form on the website https://www.casa-dominicana.com – data is stored in the Controller’s email system and/or CRM;
- email (andrzej@casa-dominicana.com) – messages are stored on the email server;
- phone (+48 782 942 023) – the Controller does not record phone conversations; any notes from conversations are stored in the CRM;
- WhatsApp messenger – conversation history is available in the application on the Controller’s devices;
- newsletter – data is stored in the mailing system (provider: [TO BE COMPLETED, e.g., Mailchimp/Brevo/GetResponse]).
9. Data Security
The Controller applies appropriate technical and organizational measures ensuring the security of personal data, including protection against unauthorized access, loss, destruction, or disclosure. The measures applied include: connection encryption (HTTPS/SSL), access control to systems, regular software updates, employee training.
10. Changes to the Privacy Policy
This Privacy Policy may be updated. Date of last update: June 1, 2026. In case of significant changes, the Controller will inform users via the website or by email.
