Terms in capital letters have the meaning indicated in regulations of this Online Store.
Personal data collected by the Administrator of the Online Store is processed in accordance with Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (Journal of Laws, EU L 119, p. 1), hereinafter: GDPR.
Online Store Administrator puts special efforts in order to protect privacy and provided information regarding Online Store Clients. Administrator shall with due diligence select and apply appropriate technical measures, including those of a programming and organisational manner, ensuring protection of processed data and in particular shall protect data against unauthorised access, disclosure, loss and destruction, unauthorised modification, as well as against their processing in breach of the applicable laws.
Children under the age of 16 shall not be recipients of Goods and Services available on the website. Data controller does not foresee collecting data on purpose regarding children below 16 years old.
Personal data controller
Your personal data controller shall be:
Szymon Tomaszewski Sp. z o.o.
ul. Kasztelańska 16, 86-014 Dąbrówka Nowa
Regarding your personal data, you can contact
Personal data controller by means of:
• e-mail: email@example.com
• correspondence: ul. Kasztelańska 16, 86-014 Dąbrówka Nowa
• phone number: +48 509 585 956
Representative of Personal data controller
Personal data controller appointed Representative for representation purposes within the scope of obligations resulting from GDPR.
Personal data controller representative shall be:
Regarding your personal data, you can contact Personal Data Controller Representative by means of:
Data Protection Officer (DPO)
Personal data controller appointed Data Protection Officer (DPO) who can be contacted regarding personal data protection by means of:
Purposes and legal framework for personal data processing
Personal data controller processes your personal data for the following purposes and scope:
- taking action prior to concluding an agreement upon your request (e.g. setting up an account), i.e. data provided in the registration form in the Online Store, i.e. e-mail address and password, gender; if the Account is registered through an external authentication service (e.g. Google+, Facebook), we collect your name and surname, and if you register while purchasing the Goods, we collect your name, surname and data provided for the purpose of completing the order, such as your shipping address; for the purpose of providing Services that require an Account, such as order history, information on the order status, we process your data provided in the Account and while purchasing Goods;
- in order to provide Services that do not require setting up an Account and purchasing Goods, i.e. browsing the web pages of the Online Store or using search engine, we process personal data concerning your activity in the Online Store, i.e. data concerning browsed Goods, session data of your device, operating system, browser, location and unique ID, IP address;
- in order to perform sales agreement of the Goods (e.g. delivery of the ordered Goods), we process personal data provided by you while purchasing the Goods, such as your name and surname, e-mail address, address details, payment data, and if you make a purchase through an Account, an additionally established password;
- for statistics of using particular functionalities available in the Online Store, to facilitate using Online Store and ensuring IT security, we process personal data concerning your activity in the Online Store and the amount of time spent on each of the subpages in the Online Store, your search history, location, IP address, device ID, data concerning your Internet browser and operating system;
- for the purpose of determining, pursuing and enforcing claims and defending against claims in court proceedings and other enforcement authorities, we may process your personal data provided when you purchased the Goods or created the Account and other data necessary to prove the existence of a claim or if it arises from a legal requirement, court order or other legal procedure;
- for the purpose of considering complaints, claims and requests and answers to Clients’ enquiries, we process personal data provided in the contact form, complaints and requests or while answering questions in another form and selected personal data provided in the Account, as well as data related to the order of Goods and other provided Services that contribute to complaints, claims or requests and data contained in documents enclosed to complaints, claims or requests;
- for the purpose of marketing of our Goods and Services and our customers and partners, including remarketing, we process the personal data provided while creating and updating your Account, data concerning your activity in the Online Store, including orders that are registered and stored by means of cookies, and in particular your order history, search history, clicks in the Online Store, logging and registration dates, history and your activity concerning our communication with you. In case of remarketing, we use data on your activity in order to reach you with our marketing messages outside of your Online Store and we use third party suppliers for this purpose. Those services include displaying our messages on internet websites other than in the Online Store. You will find more details on records regarding Cookie files;
- for the purpose of organising competitions and loyalty programmes, i.e. notifications on collected points, notifications on won prices and advertising our offer, we use your personal data provided in the Account and during registration in the competition or loyalty programme. Detailed information on this matter is provided each time in regulations of participating in a certain competition or loyalty programme;
- for purposes of market and opinion surveys conducted by us or our partners, i.e. order information, your data provided in the Account or during Goods purchase, e-mail address. Data collected within the scope of market and opinion survey are not used for advertising purposes. Accurate guidance is provided in the information on a specific survey or in location of the data input.
Relevant personal data categories
Personal data controller processes the following categories of relevant personal data categories:
- contact details;
- data regarding Online Store activity;
- data regarding Online Store orders;
- data regarding complaints, claims and applications;
- data regarding marketing services.
Voluntary submission of personal data
Providing required personal data is voluntary and constitutes a condition of providing services by the Personal data controller by means of Online Store.
Data processing time
Personal data shall be processed for period required to perform orders, services, marketing activities and other services performed for the Client. Personal data shall be removed in the following cases:
- data subject applies for the removal or withdraws granted consent;
- data subject does not undertake activities for over 10 years (inactive contact);
- after obtaining information that stored data is inactive or inaccurate.
Selected data within the scope of: e-mail address, full name, can be stored for the period of the following 3 years for evidence purposes, handling complaints and claims related to services provided by the Online Store - this data shall not be used for marketing purposes.
Data regarding orders of Goods and payable services, competitions and loyalty programmes shall be stored for 5 years from delivering the order.
We store the data concerning the Customers who have not logged in for the period corresponding to the life cycle of the cookies stored on devices or until the Customer removes it from the device.
Your personal data regarding preferences, behaviours and marketing content can be used as a basis to make automated decisions for the purpose of defining sales possibilities of Online Stores.
Personal data recipients
We provide your personal data to the following categories of the recipients:
- state authorities, e.g. prosecutor's office, Police, President of the Personal Data Protection Office (PUODO), Office of Competition and Consumer Protection (UOKiK), in case of their requests,
- service providers, who were used to conduct Online Store, e.g. for the purpose of order completion. Depending on the contractual arrangements and circumstances, these entities either act on our behalf or determine the purposes and means of processing independently.
Rights of the data subjects
On the basis of GDPR, you have the right to:
- access your data,
- demand rectification of your personal data,
- demand deleting personal data,
- restrict data processing,
- object to data processing,
Personal data controller shall without undue delay - and in any case within one month of receipt of the request – undertake action regarding your request.
If necessary, the monthly period may be extended by a further two months due to the complexity of the request or the number of requests.
In any case, the Personal Data Controller will notify you of such delay within one month from receiving the request, stating the reasons.
Access to your personal data (art. 15 GDPR)
You have the right to obtain information from the personal data controller on whether your personal data is being processed.
If Data Controller processes your personal data, you have the right to:
- personal data access;
- obtain information on the purposes of the processing, categories of processed personal data, recipients or categories of data recipients, intended storage period of your data or criteria for determining this period, your rights under the GDPR and the right to lodge a complaint with a supervisory authority, data source, automated decision-making, including profiling and the safeguards applicable to the data transfer outside the European Union;
- obtain copies of your personal data.
If you wish to access to your personal data, please send your request to: firstname.lastname@example.org
Right to rectify your personal data (art. 16 GDPR)
If your personal data is incorrect, you have the right to request from the Controller to immediately rectify your personal data.
You also have the right to demand from the Controller to complete your personal data.
If you wish to rectify your personal data or complete them, please send your request to: email@example.com
If you registered in the Online Store, you can rectify your personal data and complete it independently after logging in the Online Store.
Right to delete your personal data, i.e. “right to be forgotten” (art. 17 GDPR)
You have the right to request from the Personal Data Controller to immediately delete your personal data, if:
- your personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- you withdrew defined consent regarding the scope of personal data being processed on the basis of your consent;
- your personal data was processed in breach of the law;
- you objected to your personal data processing for the purposes of direct marketing, including profiling, in the scope of personal data processing being related to direct marketing;
- you objected to personal data processing with regard to processing required to perform a task implemented in public interest or processing required for the purposes arising out of legal interest implemented by personal data controller or a third party.
Despite reported request to delete personal data, personal data controller might keep processing your data to establish, investigate or defend your claims, of which you will be informed.
If you wish to delete your personal data, please send your request to: firstname.lastname@example.org
Right to request restricting data processing (art. 18 GDPR)
You have the right to demand restriction of your personal data processing, if:
- you are questioning correctness of your personal data – Personal data controller shall restrict personal data processing for a period enabling controlling correctness of data;
- your personal data processing is in breach of the law and instead of deleting personal data, you will request to restrict your personal data processing;
- your personal data is no longer required for the processing purposes, but it is required to establish, investigate or defend your claims;
- you objected to personal data processing – until decision whether legal interest of the personal data controller is superior to framework indicated in your objection.
If you wish to request limiting personal data processing, please send your request to: email@example.com
Right to object to personal data processing (art. 21 GDPR)
At any time, you have the right to object to
personal data processing, including profiling, regarding
- processing required to perform a task implemented in public interest or processing required for the purposes arising out of legal interest implemented by personal data controller or a third party;
- processing for the purposes of direct marketing.
If you wish to object to limiting personal data processing, please send your request to: firstname.lastname@example.org
Right to demand transferring your personal data (art. 20 GDPR)
You have the right to receive your personal data from the Controller in a structured, commonly used and machine-readable form and send it to another personal data controller.
You can also request from Personal data controller to send your personal data directly to another controller (if technically possible).
If you wish to transfer your personal data, please send your request to: email@example.com
Right to withdraw your consent
You can withdraw consent to personal data processing at any time.
Withdrawing your consent does not affect the legality of the prior processing on the basis of your consent.
If you wish to withdraw your consent to personal data processing, please send your request to: firstname.lastname@example.org or use appropriate functions in the Account.
Complaint with a supervisory authority
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority, in particular in the Member State of your residence, place of work or place of alleged infringement.
In Poland, the supervisory authority within the meaning of the GDPR is the President of the Office for Personal Data Protection (PUODO).
When you browse the online store, cookies are used, hereinafter referred to as Cookies, i.e. small text information stored on your end device regarding your use of the Online Store. Their purpose is to ensure correct functioning of the Online Store websites.
These files enable identifying used software and tailoring the Online Store to your individual needs.
"Cookies" usually include the originating website name, storage time and assigned value.
Used "cookies" are safe for your devices. In particular, it not possible to reach your devices by „cookies” of the viruses or other unwanted software or malware.
Types of „cookies”
We use two types of cookies:
• Session Cookies: stored on your device remaining until the end of the browser’s session. Saved information is then permanently removed from the memory. Mechanism of session cookies does not enable downloading any personal data or confidential information from your device.
• Permanent Cookies: stored on your device until they are deleted. Ending session of a certain browser or turning off the device does not cause removing data from your device. Permanent cookies mechanism does not enable downloading any personal data or any confidential information from your device.
- configuring the Online Store;
- drawing up statistics which enable understanding how Online Store Clients use the websites in order to improve their structure and content by means of Google Analytics analytical tools administrated by Google Inc with its registered seat in the USA, Privacy security policy Google is available at:
- defining Client’s profile in order to display tailored materials in advertising networks, using online advertisement tools of Google Adwords administrated by Google Inc. with its registered seat in the USA, Google privacy security policy is available at:
- popularization of the Online Store by means of social media Facebook.com, administrator of which being Facebook Inc. with its registered seat in the USA or Facebook Ireland with its registered seat in Ireland, Privacy security policy of Facebook is available at: https://www.facebook.com/help/cookies/.
- popularization of the Online Store by means of social media Instagram.com, administrator of which being Instagram LLC. with its registered seat in the USA, Privacy security policy of Instagram.com is available at: https://help.instagram.com/155833707900388.
In order to acknowledge rules of using Cookies, we recommend reading privacy policies of aforementioned companies.
Cookies can be used by advertising networks, in particular Google network to display advertisements tailored to your preferences. For this purpose, information about your manner of using the web or time of use may be stored.
To browse and edit information about your preferences collected by the Google Display Network, you can use the tool at https://www.google.com/ads/preferences/.
Using the settings of your web browser or by configuring the service, you can modify Cookie settings by yourself and at any time, specifying storage conditions and access by Cookies to your device. You can change these settings to block the automatic handling of cookies in your browser settings or to notify you every time when Cookies are placed on your device. Detailed information about the possibilities and methods of handling Cookies is available in the settings of your software (web browser).