Trust & Digital Security

Privacy Policy

Transparent rules for data processing, digital security, and full GDPR compliance for the 2026 season.

update Last updated: 15.07.2026 | lock 256-bit TLS Encryption
GDPR Compliance & Privacy

Protecting Your Privacy in Practice
A digital transparency handbook for our Users

"At kos.tucoo.pl, we follow a simple rule: your privacy is not subject to compromises. Since we do not run user accounts, newsletters, or registration forms, we limit data collection to the necessary, fully anonymized statistical minimum."

info 1. General Information and Data Administrator

The Data Controller (ADO) for data collected automatically via the kos.tucoo.pl website is the Owner of the tucoo.pl internet domain. To ensure high cybersecurity standards, communication with the administrator is handled exclusively via electronic mail.

All activities within this website are carried out in strict accordance with current national and EU legislation, particularly the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679 of the European Parliament and of the Council). Our website is designed by default to protect user privacy, applying data minimization methods directly within the underlying source code architecture.

database 2. Personal Data, Method and Purpose of Processing

The kos.tucoo.pl platform is a purely informational website. This means that we do not collect, store, or process any sensitive personal data directly. You will not find invasive contact forms, logging comment sections, or subscription fields here. The only data stream consists of information processed automatically by external analytics and advertising services provided by Google Ireland Limited.

Factual Correction (GA4 & Consent Mode v2 implementation):

Our website operates exclusively on Google Analytics 4 (GA4). Unlike legacy analytic tools, GA4 by default does not log or store IP addresses on its final servers; it redacts them immediately upon collection. Furthermore, we have deployed the advanced Google Consent Mode v2 system, which strictly conditions the execution of analytical and tracking tags on your explicit, granular consent, prioritizing your digital preferences.

Quick Privacy Audit:

Why is our portal secure?

  • Zero Forms: No raw personal database vulnerability risks.
  • IP Masking: GA4 algorithms automatically protect your networking identity.
  • Consent Mode v2: Total script block prior to cookie banner selection.
  • TLS Encryption: Secure, green padlocks active across all URLs.
External Service Data Scope (Fully Anonymized) Purpose of Website Processing Legal Basis (GDPR)
Google Analytics 4 Shortened (anonymized) IP address, rough geographic location, device parameters, click paths, session duration Statistical analysis, performance optimization, content refinement of local travel modules Legitimate interest of the Controller (Art. 6(1)(f) GDPR) backed by voluntary cookie consent
Google AdSense Anonymized ad identifiers (cookies), interactions with contextual and dynamic display elements Displaying non-intrusive contextual or sponored ads that fund our free-to-use informational guides Explicit, voluntary User consent granted via the interactive banner UI (Art. 6(1)(a) GDPR)
gavel
International Transfers Framework Verification (E-E-A-T Note)

Legal Update: Please note that data transmission to the US relies on the European Commission's adequacy decision regarding the EU-US Data Privacy Framework adopted in 2023, for which Google maintains active certification. Standard Contractual Clauses (SCCs) remain integrated as a redundant, complementary safeguarding mechanism.

Cookie Mechanisms

3. Pliki Cookies and Modern Consent Management

Pliki Cookies (cookies) are small string fragments stored temporarily inside your browser data layers. The platform utilizes them strictly for technical optimization, traffic metrics, and contextual monetization.

analyticsTraffic Metrics

Analytical cookies compile aggregated website patterns. They reveal whether our Kos travel blueprints are readable, which guides generate the highest engagement, and how to fine-tune mobile UI responses.

ads_clickContextual Monetization

Google AdSense marketing cookies allow ad matching based on your broad browsing history. If you opt-out on our initial privacy banner, the script drops generic contextual banners only.

tuneGranular Choice

In adherence to the "Privacy by Default" philosophy, no operational tracking cookies are initialized before your conscious approval. You can flush stored cookies at any time via your browser settings.

Your Rights

4. Comprehensive Directory of User Rights Under GDPR

Even though we collect metrics in a manner that completely prevents us from linking networking indicators to real-world names or identities, GDPR guarantees you a broad array of regulatory controls:

visibility Right to Access and Review

You possess the right to verify which scripts run within the site background layers. This Privacy Document fulfills that explicit transparent requirement.

block Objection and Revocation

You can easily object to behavioral tracking. Simply refuse consent on the landing screen popup or employ the official Google Analytics Opt-out browser extension.

gavel Regulatory Complaints

If you believe automated Google dependencies mishandle metrics, you retain the right to lodge a formal complaint with the President of the Personal Data Protection Office (PUODO).

Technical Safeguards

5. Cryptographic Infrastructure and TLS Security

https

Full Data Channel Encryption (SSL/TLS)

All data transitions within the kos.tucoo.pl cluster are strictly enveloped by modern SSL/TLS public key cryptography with 256-bit parameters. This thoroughly deters packet sniffing or session interception on public wi-fi hotspots.

🔒 Secured Connection Verified: HTTPS://KOS.TUCOO.PL
Communication

6. Privacy Contacts and Disclosures

Should you have any inquiries regarding data masking, cookie scripts, or general privacy safeguards on this portal, please direct your email to the Head Administrator of the tucoo.pl web network. We address all valid requests promptly.

verified Core Privacy Commitments Summary:

  • Fully Passive Platform: We do not require, record, or lease real-world names, phones, or email addresses.
  • Google Analytics 4 Framework: Native, server-side masking of connection strings active by default.
  • Consent Mode v2 Compliant: Granular user switches override automated metric collection.
  • Cryptographic Enforcement: Mandatory global redirection to secure HTTPS links across all endpoints.
  • GDPR Centric: Perfect legal compliance aligned with modern European data transparency requirements.

Have additional questions about privacy?

We are happy to answer any tech queries regarding tracking cookies or automated analytics functionality across our platform layers.