Privacy Policy and Cookie Policy
1. General information
1.1. This Privacy Policy and Cookies Policy (hereinafter referred to as the "Policy") sets out the rules for the processing of personal data of users using the Platform available at the following addresses: Cowork-booker.com, Sport-booker.com, Events-booker.com, Parking-booker.com and Workfriendlycafe.com.
1.2. The platform is intended in particular for searching and booking services and facilities, including: coworking spaces, conference rooms, sports facilities, parking spaces and work-friendly cafe services, in accordance with the definitions and principles described in the Platform Regulations.
1.3. The platform is one integrated system available under various trade names and domains. User registration on the website at any of these addresses is equivalent to registration in the entire system and allows you to use all the mentioned websites using one Account.
1.4. The Administrator takes due care to ensure that personal data is processed in accordance with the applicable provisions of Polish and European Union law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"), provisions on the provision of services by electronic means, protection of privacy in electronic communications and other relevant regulations relating to the activities of the Platform.
1.5. Capitalized terms that are not separately defined in this Policy have the meaning given to them in the Platform Regulations.
2. Data administrator and contact details
2.1. The administrator of Users' personal data is NexLink Technologies sp. z o.o. (hereinafter also: "Operator" or "Administrator"), running the Platform.
2.2. In matters related to the protection of personal data and the exercise of the rights of data subjects, you can contact the Administrator via e-mail at: [email protected] and using other contact details indicated on the Platform.
2.3. The administrator may appoint a person responsible for handling personal data protection matters. Information about current contact details in this regard may be published on the Platform.
3. Purposes and legal basis for data processing
3.1. Users' personal data are processed by the Administrator for various purposes, using appropriate legal bases under Art. 6 section 1 GDPR, in particular in the scope of providing services electronically, processing Reservations, handling payments, fulfilling legal obligations as well as marketing and analytics.
3.2. Personal data may be processed for the following purposes:
a) setting up and operating a User Account on the Platform, including registration, logging in, profile management and providing access to the Account functionality - pursuant to Art. 6 section 1 letter b GDPR;
b) implementation of the Reservation and handling of the relationship between the Customer and the Partner, including handling the process of Reservation of Partner Offers, communication related to the implementation of the Reservation and transfer of data necessary to conclude and perform the Agreement between the Customer and the Partner - pursuant to Art. 6 section 1 letter b GDPR;
c) maintaining contact with Users, responding to inquiries, handling complaints and notifications, communicating via contact forms and tools available on the Platform - pursuant to Art. 6 section 1 letter b and/or letter f GDPR;
d) issuing accounting documents and fulfilling tax and accounting obligations, including storing documentation required by law - pursuant to Art. 6 section 1 letter c GDPR;
e) conducting direct marketing of the Administrator's services, including sending commercial information electronically, presenting offers of the Administrator's and/or selected Partners' services - pursuant to Art. 6 section 1 letter a GDPR and, where applicable, also Art. 6 section 1 letter f GDPR;
f) conducting the Administrator's own marketing in a non-invasive form, e.g. presenting recommended content on the Platform, displaying offers tailored to the User's profile within the Account - pursuant to Art. 6 section 1 letter f GDPR;
g) statistical analysis, satisfaction survey, improvement of service quality and development of the Platform's functionality - pursuant to Art. 6 section 1 letter f GDPR;
h) ensuring IT security and counteracting abuse, including detecting attempts to breach security, preventing fraud, pursuing or defending against claims and the use of cookies and similar technologies in accordance with this Policy - pursuant to Art. 6 section 1 letter f GDPR and relevant provisions on privacy in electronic communications;
i) carrying out verification procedures, including verification of identity, credibility and compliance with the requirements of payment providers, legal provisions, security rules or anti-abuse policies - pursuant to Art. 6 section 1 letter c, letter b and/or letter f GDPR, depending on the nature of the given activity.
3.3. If data processing is based on consent, the User has the right to withdraw consent at any time, without affecting the lawfulness of the processing carried out before its withdrawal.
4. Scope of processed data
4.1. The Platform obtains information about Users and their behavior primarily through data voluntarily provided in forms, data provided during the implementation of Agreements, records in cookies and similar technologies, and technical data related to the use of the Platform.
4.2. The scope of processed data may include in particular:
a) identification and contact details - in particular name and surname, e-mail address, telephone number, and in the case of Partners or corporate entities, also the company name and basic company data;
b) billing and accounting data - invoice data, including address, entity name, Tax Identification Number, information on payment and settlement status;
c) data related to Reservations and User Account - including: information about selected Offers, dates, number of people, additional requirements, Reservation history and settings and preferences saved in the Account;
d) data from communication with the Administrator and Partners - the content of inquiries submitted by the Customer, responses from the Administrator and Partners, information on the status of the Reservation, complaints and after-sales service;
e) payment data to the extent necessary on the part of the Administrator - transaction identifiers, payment status and basic billing information; full payment card details are generally processed only by external payment operators;
f) technical and operational data - IP address, information about the device, browser and operating system, system logs, cookie identifiers or other local technologies.
4.3. When using the AI Assistant functionality, the scope of data may additionally include data entered by the User in the conversation, including operational data regarding Offers, Reservations, facilities, price plans, calendars, communication with customers, as well as other content provided voluntarily by the User as part of the use of this functionality.
4.4. The User may enter end customer data, contact details, Reservation details or other data necessary to perform operational activities within the Platform into the conversation with the AI Assistant. The user should always comply with the principle of data adequacy and minimization, i.e. provide the AI Assistant only with data necessary to perform a given activity.
4.5. As a rule, the Administrator does not expect special categories of personal data to be transferred via the Platform, unless it is exceptionally justified by the nature of the service and permissible under the law. The user should not provide such data without a clear need and an appropriate legal basis.
5. AI assistants, chat conversations and automation
5.1. The Administrator may provide all logged in Users with AI Assistants as a functionality supporting the use of the Platform.
5.2. AI assistants can be used in particular for:
a) searching for coworking spaces, obtaining Offers, checking availability and price conditions;
b) configuring facilities, defining pricing plans and managing availability;
c) customer service, preparing offers and proposed responses;
d) preparing a shopping cart, Reservation parameters or proposals for selecting Offers;
e) calendar management;
f) preparing e-mail communication proposals;
g) supporting the User in navigating the Platform and using its features.
5.3. Conversations with the AI Assistant are recorded. They include, in particular, the content of commands, questions, answers, input and output data, results generated by the model and technical metadata related to the use of this functionality.
5.4. Conversations with the AI Assistant may be processed for the following purposes:
a) implementing the User's instructions and ensuring the operation of the service;
b) maintaining conversation continuity and history of interactions within the functionality;
c) handling reports, complaints and disputes;
d) ensuring security, auditing, detecting abuse and preventing circumvention of the Platform;
e) improving the quality of the Platform's operation and developing the functionality of the Administrator's own product;
f) testing, validation and improvement of solutions implemented by the Administrator within its own systems and services;
g) fulfilling legal obligations and pursuing or defending against claims.
5.5. The legal basis for data processing during conversations with the AI Assistant is, in principle, Art. 6 section 1 letter b GDPR - to the extent necessary to provide the functionality requested by the User - and Art. 6 section 1 letter f GDPR - in the field of security, audit, anti-abuse, development and improvement of the Administrator's own product.
5.6. Data entered by the User into the AI Assistant may be processed using language models and technological infrastructure of suppliers such as, in particular, Google, OpenAI, Microsoft, Anthropic or other technology providers, as well as based on the Administrator's own infrastructure and open source models.
5.7. The use of third-party technology providers may mean that conversation content, commands, operational data and other information you enter into the chat will be transferred to these providers to the extent necessary to generate a response, perform a technical function or ensure the operation of the service.
5.8. The Administrator declares that the data from Conversations with the AI Assistant are not used by the Administrator to train models of external suppliers for their own products, but only for the operation of the service, security and development of the Administrator's own product, subject to technical and contractual limitations related to the use of the services of these suppliers.
5.9. If the AI Assistant supports the preparation of the content of Offers, facility data, price plans, calendar, response proposals, e-mail proposals or shopping cart, the User remains responsible for their final verification and approval before publication, shipment or purchase.
6. Data recipients
6.1. Users' personal data may be transferred and made available only to entities authorized or cooperating with the Administrator, to the extent necessary to achieve the purposes described in this Policy.
6.2. The recipients of the data may be in particular:
a) Partners – owners or managers of facilities or service providers to whom the Customer's data is transferred to the extent necessary to prepare and implement the Agreement and handle any complaints;
b) providers of IT, hosting, mailing, communication and system services acting on behalf of the Administrator - processing data only on the basis of appropriate contracts and to the extent necessary to provide services;
c) external payment operators and financial service providers – handling electronic payments and settlements;
d) providers of language models, cloud services, artificial intelligence tools, automation and analytics - to the extent necessary for the operation of the AI Assistant functionality and related services;
e) law firms, advisors, auditors, accountants and entities supporting the Administrator in fulfilling legal obligations, protecting rights and pursuing claims;
f) public authorities, courts, law enforcement authorities, tax authorities and other entities authorized by law.
6.3. Depending on the nature of the cooperation, individual recipients may act as processors or as separate data controllers.
7. Data storage period
7.1. Users' personal data are stored for the period necessary to achieve the purposes for which they were collected, and then for the time required by law or justified by the limitation period for potential claims.
7.2. As a rule:
a) data related to Reservations and accounting documentation are stored for a period of 6 years from the end of the calendar year in which the tax obligation arose, unless legal provisions require a longer period;
b) data processed on the basis of consent - until it is withdrawn;
c) data related to the User Account - for the duration of its activity and the necessary period after its deletion;
d) technical data and logs - usually up to 12 months, unless longer storage is necessary for security or legal reasons;
e) data related to verification procedures - for the period necessary to achieve the purpose of verification, fulfill legal obligations, demonstrate compliance or defend against claims;
f) data from Conversations with the AI Assistant - for the period necessary to achieve operational goals, security, audit, development of the Administrator's own product and consideration of disputes, complaints and claims, unless applicable regulations require longer storage or earlier deletion.
8. User Rights
8.1. The data subject has the rights specified in Art. 15–22 GDPR, including:
a) the right to access your personal data;
b) the right to rectify data;
c) the right to delete data in cases provided for by law;
d) the right to restrict processing;
e) the right to transfer data;
f) the right to object to processing based on Art. 6 section 1 letter f GDPR;
g) the right to object to the processing of data for direct marketing purposes;
h) the right to withdraw consent at any time if processing is based on consent;
i) the right not to be subject to a decision based solely on automated processing, including profiling, if it produces legal effects for the User or similarly significantly affects him, subject to exceptions provided for by law;
j) the right to lodge a complaint with the President of the Personal Data Protection Office.
8.2. In order to exercise their rights, the User may contact the Administrator in accordance with section 2 above.
9. Cookies and similar technologies
9.1. The Platform uses cookies and similar technologies to ensure proper operation and security of the website, improve user comfort, analyze traffic, including through Google Analytics 4 and Microsoft Clarity, and conduct marketing activities.
9.2. Cookies are IT data, most often text files, which are stored on the User's end device and allow the user's browser to be recognized and certain information to be stored.
9.3. The Platform may use:
a) technical and necessary cookies - required for the proper operation of the Platform, in particular logging in, maintaining sessions, security and basic functions of the website;
b) functional cookies - enabling remembering selected settings and personalizing the interface;
c) analytical and statistical cookies - used to analyze traffic on the Platform, create website usage statistics, as well as improve operation and adapt services to the needs of Users;
d) marketing and remarketing cookies - enabling the conduct of marketing activities, including displaying advertisements tailored to the User's interests and measuring the effectiveness of advertising campaigns.
9.4. During the first visit to the Platform, a cookie consent management banner is displayed, informing about the use of cookies and allowing the User to accept all categories, reject optional cookies or choose individual categories.
9.5. The User may change cookie preferences at any time using the “Cookie settings” link available in the Platform footer or by changing the web browser settings.
9.6. Restricting the use of certain cookies may affect the operation of selected functionalities of the Platform.
10. Automated processing and profiling
10.1. As part of the use of the Platform, partially automated processing of Users' data may occur, including profiling, in particular in order to adjust the presented Offers, improve searches, recommend content and conduct the Administrator's marketing activities.
10.2. Such processing is generally carried out on the basis of Art. 6 section 1 letter b GDPR, if it is necessary to perform the contract or provide functionality requested by the User, and Art. 6 section 1 letter f GDPR, if it serves the legitimate interest of the Administrator consisting in adapting services, improving the usability of the Platform and protecting security.
10.3. In the case of marketing activities that go beyond the functionality necessary for the operation of the service, the basis for processing may be the User's consent.
10.4. The Administrator does not make solely automated decisions that produce legal effects for the User or significantly affect him in a similar way, without the possibility of questioning such a decision, unless it is permissible under applicable law.
11. Verification of credibility and counteracting fraud
11.1. The Administrator may process personal data of Users and Partners in order to verify credibility, in particular in connection with assessing transaction risk, preventing abuse and circumvention of the Platform, ensuring security of settlements and pursuing and defending claims.
11.2. Verification of credibility is based mainly on the legally justified interest of the Administrator, and in justified cases also on the necessity to perform a contract or legal obligation.
11.3. Verification may use data obtained from the User, from the history of using the Platform and from legally available sources, including public registers, economic information offices, sanction lists or payment providers' systems.
12. Transfer of data outside the EEA
12.1. Users' personal data may be transferred outside the European Economic Area, including, for example, the United States, in connection with the Administrator's use of the services of technological, cloud, analytical, payment providers or language model providers storing or processing data on servers located outside the EEA.
12.2. In such cases, the Administrator applies appropriate security measures required by the GDPR, in particular decisions confirming the appropriate level of protection, standard contractual clauses or other legally permissible data transfer mechanisms.
12.3. The User may obtain additional information about the security measures used by contacting the Administrator.
13. Message on AI functionality
13.1. The Administrator may display a short information message next to the chat window or other functionality of the AI Assistant, e.g. with content indicating that the User is talking to the AI assistant, and the conversation may be recorded and analyzed for the purposes of case management, security, auditing and improving the quality of the service.
13.2. Such a message is informative and supplements the provisions of this Policy and the Regulations, without replacing their content.
14. Location data
14.1. To improve the usability of the Platform and to present search results tailored to the User's location, the Administrator may process data concerning the User's location.
14.2. Location data may include in particular:
a) location provided directly by the User;
b) approximate location determined on the basis of device or browser settings or the IP address;
c) location determined automatically — only where the User has given the appropriate consent.
14.3. Providing location data is voluntary; however, failure to provide it may limit the operation of certain Platform functionalities.
14.4. Location data is processed only to the extent necessary to:
a) enable nearby search;
b) improve the relevance of search results;
c) ensure continuity of service;
d) improve Platform functionality (in aggregated or anonymised form).
14.5. Location data may be stored locally on the User's device, in particular in cookies or similar technologies.
14.6. The legal basis for processing is:
a) the User's consent;
b) the legitimate interest of the Administrator.
14.7. The User may disable location access at any time via browser or device settings.
15. Policy changes
15.1. This Policy may be updated, in particular in the event of changes in legal provisions, changes in case law or guidelines of supervisory authorities, changes in the functionalities or operating model of the Platform, implementation of new services or technological tools, including AI tools.
15.2. The updated version of the Policy will be published on the Platform along with the date of entry into force, and in the event of significant changes, Users may be informed about them in advance.
15.3. Policy version 1.03 is effective from 22 April 2026.
Policy version 1.03 is effective from 22 April 2026.