Home About me The Experience Portfolio Privacy Getting here FAQ Contact
A frame that suggests discretion
Privacy

Photographs no one ever has to see. Except you.

Five rules

Set down in black and white

  1. Complete confidentiality by default. We publish nothing, anywhere. You never have to ask for privacy — we would have to ask you for an exception.
  2. Publication only with separate, written consent. Which you can withdraw at any time, without giving a reason.
  3. An encrypted, password-protected gallery. You are the only one with access.
  4. A clear lifecycle for every file. You know where they are kept, for how long, and when they are permanently deleted.
  5. Sessions in boutique hotels I know personally. Private and secure.
A frame in natural window light — calm and discretion
The contract

Rules in writing, not just in conversation.

Before the session we sign a short, plain contract: what happens to your photographs, who has access to them, how long we keep them, and on what terms you might ever agree to publication. Nothing hidden in small print.

Frequently asked about

Privacy

Who will see my photographs?

By default: only you. We publish nothing without your separate, written consent — and our starting assumption is that there is none. The gallery is encrypted and password-protected.

This question in the full list of questions

What happens to the files after the session?

You know exactly where they are stored, for how long, and when they will be permanently deleted — it is written into the contract.

This question in the full list of questions

See all the questions

The document

Privacy policy

The full text of the document — open the section you need.
Last updated: 2 September 2026

Data controller

The controller of your personal data is Synergia Digital Solutions sp. z o.o., with its registered office at Plac Kaszubski 8/311, 81-350 Gdynia, Poland, entered in the register of entrepreneurs of the National Court Register under KRS number 0000935429 (KRS — the Polish company register), NIP 5862374681 (Polish tax number), REGON 520563485 (Polish statistical number) — the company behind the Boudoir.Voyage brand. For data protection matters, contact: hello@boudoir-voyage.com.

We have not appointed a data protection officer — for all matters concerning your data, write to the address above.

What we collect and why

This site collects personal data only when you choose to give it — by sending the contact form. The form asks for your first name, e-mail address, where you are travelling from, your preferred quarter for the session and an optional message. We use that data solely to answer your enquiry and, if it comes to that, to plan the session you are asking about.

We treat the quarter you indicate purely as an indication of your preferred timing — it helps us plan the first conversation and is not a booking of a date.

The legal basis is your consent (Article 6(1)(a) GDPR), given by ticking the box beside the form, and — to the extent needed to prepare an offer at your request — Article 6(1)(b) GDPR (steps taken before entering into a contract).

Providing your data is voluntary, but it is necessary for us to reply — without it we have no way of reaching you.

How long we keep your data

The content of your enquiry and your e-mail address stay in the controller's mailbox for as long as it takes to handle the enquiry and any correspondence that follows — until the booking is finalised or you decide not to go ahead, and for as long as the law requires. If an enquiry does not turn into a booking and the correspondence simply stops without a conclusion, we delete it 12 months after the last contact. You can ask us to delete your data sooner at any time.

Who we share your data with

We do not sell your data or pass it to third parties for marketing purposes. Only the controller has access to the content of your enquiry. The message passes through the infrastructure of our hosting provider, which acts as a processor and technically handles the delivery of the e-mail.

Protecting the form against abuse

To limit spam, the server temporarily stores — in hashed, irreversible form — the time of the last submission linked to an IP address, for the sole purpose of enforcing a minimum 20-second gap between submissions from the same address. This is not a permanent log or a profile: each submission overwrites the previous entry for that IP address. Legal basis: the controller's legitimate interest (Article 6(1)(f) GDPR) — protection against abuse.

Server logs

Like almost every website, the hosting server records basic technical details of visits (IP address, timestamp, browser type) in its access logs, for security and technical diagnostics. We do not link those logs to any data from the form. The basis is our legitimate interest (Article 6(1)(f) GDPR) — keeping the site secure and diagnosing faults.

Cookies

This site shows a banner asking for consent to analytics cookies. Since 29 July 2026, clicking "Accept" starts Google Analytics 4 (GA4) — declining, or not answering, means no analytics script or cookie runs at all. The only cookie we store regardless of your choice is a technical record of that choice (bv_cookie_consent, valid for 180 days) — its sole purpose is to avoid asking you again on every visit.

GA4 collects: the pages you visit, time spent on the site, device and browser type, approximate location at country/city level (based on an IP address that GA4 does not store in raw form), and how you arrived at the site. We do not use this data to identify you personally and we never combine it with the contact form data described above. The processor is Google Ireland Limited (part of Google LLC); as Google is a US company, some data may be transferred to the United States under the EU-U.S. Data Privacy Framework. Data is retained only for the period configured in our Google Analytics account. You can withdraw consent at any time by clearing the bv_cookie_consent cookie in your browser, or by installing the Google Analytics opt-out add-on.

The site also stores your chosen language version in your browser's memory (localStorage, not a cookie) under bv_lang_manual — this is not personal data, only a technical preference setting.

Meta Pixel remains inactive on this site. If we ever activate it, this policy will be updated BEFORE activation, with a full description of the data collected.

Your rights

You have the right to: access your data, rectify it, erase it, restrict its processing, port it, and object to processing. You can withdraw the consent given in the form at any time — write to hello@boudoir-voyage.com. You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (uodo.gov.pl) if you believe the processing breaches data protection law.

We do not use profiling or automated decision-making — nothing and no one assesses you automatically on the basis of this data.

Any questions?

Just ask — I answer within a day.

Write to us
Enquire about a date