- The administrator of personal data collected via the www.spraypeptides.com Online Store is Karol Witański who performs business activity entered in the Central Register and Information on Economic Activity of the Republic of Poland kept by the minister responsible for economy, place of business and address for service: ul. Consent 42, 43-100 Tychy, NIP: 6462912891, REGON: 385688110, e-mail address (e-mail): email@example.com, hereinafter referred to as the “Administrator” and being also the “Service Provider”.
- Personal data collected by the Administrator via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46 / EC (General Data Protection Regulation), hereinafter referred to as
TYPE OF PROCESSED PERSONAL DATA, PURPOSE AND SCOPE OF DATA COLLECTION
- PURPOSE OF PROCESSING AND LEGAL BASIS. The administrator processes the personal data of the Service Users of the Store www.spraypeptides.com in the case of:
- Account registration in the Store, in order to create an individual account and manage this Account, pursuant to art. 6 sec. 1 lit. b GDPR (performance of the contract for the provision of electronic services in accordance with the Store Regulations),
- placing an order in the Store, in order to perform the sales contract, pursuant to art. 6 sec. 1 lit. b GDPR (performance of the sales contract).
- TYPE OF PROCESSED PERSONAL DATA. In case of:
- The Customer’s accounts are provided by:
- First name and last name,
- E-mail adress.
- The orders are provided by the Client:
- First name and last name,
- NIP (tax identification number),
- E-mail adress,
- Phone number.
- PERIOD OF PERSONAL DATA ARCHIVING. The personal data of the Customers is stored by the Administrator:
- if the basis for data processing is the performance of the contract, as long as it is necessary to perform the contract, and after that time for a period corresponding to the period of limitation of claims. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business – three years.
- in the event that the basis for data processing is consent, as long as the consent is not revoked, and after revocation of consent for a period of time corresponding to the period of limitation of claims that may be raised by the Administrator and which may be raised against him. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business – three years.
- When using the Store, additional information may be downloaded, in particular: the IP address assigned to the Customer’s computer or the external IP address of the Internet provider, domain name, browser type, access time, type of operating system.
- After expressing a separate consent, pursuant to art. 6 sec. 1 lit. a) GDPR, data may also be processed for the purpose of sending commercial information by electronic means or making telephone calls for direct marketing purposes – in connection with art. 10 sec. 2 of the Act of July 18, 2002 on the provision of electronic services or art. 172 sec. 1 of the Act of July 16, 2004 – Telecommunications Law, including those directed as a result of profiling, provided that the Service Recipient has consented.
- Navigational data may also be collected from the Customers, including information about links and references in which they decide to click or other activities undertaken in the Store. The legal basis for this type of activity is the Controller’s legitimate interest (Article 6 (1) (f) of the GDPR), consisting in facilitating the use of electronic services and improving the functionality of these services.
- Providing personal data by the Customer is voluntary.
- The administrator takes special care to protect the interests of data subjects, and in particular ensures that the data collected by him are:
- processed in accordance with the law,
- collected for specified, lawful purposes and not subjected to further processing incompatible with these purposes,
- factually correct and adequate in relation to the purposes for which they are processed and stored in a form that allows the identification of persons to whom they relate, no longer than it is necessary to achieve the purpose of processing.
SHARING OF PERSONAL DATA
- The personal data of the Service Users are provided to service providers used by the Administrator when running the Store, in particular to:
- entities delivering Products,
- payment system providers,
- accounting office,
- hosting providers,
- software providers that enable business operations (e.g. accounting software),
- entities providing the mailing system,
- software provider needed to run an online store.
- Service providers referred to in point 1 of this paragraph to which personal data are transferred, depending on contractual arrangements and circumstances, or are subject to the Administrator’s instructions as to the purposes and methods of processing this data (processors) or independently define the purposes and methods of their processing (administrators).
THE RIGHT OF CONTROL, ACCESS TO THE CONTENTS OF OWN DATA AND THEIR CORRECTION
- The data subject has the right to access their personal data and the right to rectify, delete, limit processing, the right to transfer data, the right to object, the right to withdraw consent at any time without affecting the lawfulness of the processing that was carried out on the basis of consent before its withdrawal.
- Legal grounds for the Service Recipient’s request:
- Access to data – art. 15 GDPR.
- Data rectification – art. 16 GDPR.
- Deletion of data (the so-called right to be forgotten) – art. 17 GDPR.
- Restriction of processing – art. 18 GDPR.
- Data transfer – art. 20 GDPR.
- Objection – Art. 21 GDPR
- Withdrawal of consent – art. 7 sec. 3 GDPR.
- In order to exercise the rights referred to in point 2, you can send an appropriate e-mail to the following address: firstname.lastname@example.org
- In the event that the Service Recipient has the right resulting from the above rights, the Administrator fulfills the request or refuses to meet it immediately, but not later than within one month after receiving it. However, if – due to the complexity of the request or the number of requests – the Administrator will not be able to meet the request within a month, it will meet them within the next two months, informing the Customer within one month of receiving the request – about the intended extension and its reasons.
- If it is found that the processing of personal data violates the provisions of the GDPR, the data subject has the right to lodge a complaint with the President of the Office for Personal Data Protection.
- The Administrator’s website uses ” cookies” .
- The installation of ” cookies ” is necessary for the proper provision of services on the Store’s website. The ” cookies ” files contain information necessary for the proper functioning of the website, and also provide the opportunity to compile general statistics of website visits.
- The website uses two types of ” cookies “: “session” and “permanent”.
- ” Session ” cookies are temporary files that are stored on the User’s end device until logging out (leaving the page).
- “Persistent” cookies are stored in the Customer’s end device for the time specified in the parameters of ” cookies ” or until they are deleted by the Customer.
- The administrator uses his own cookies in order to better understand how the Customers interact with the content of the website. The files collect information about the way the website is used by the Service Recipient, the type of website from which the Service Recipient was redirected, and the number of visits and time spent by the Service Recipient on the website. This information does not record specific personal data of the Service Recipient, but is used to compile statistics on the use of the website.
- The administrator uses external cookies to collect general and anonymous static data via Google Analytics analytical tools (external cookie administrator: Google Inc. based in the USA).
- Cookies may also be used by advertising networks, in particular the Google network, to display advertisements tailored to the manner in which the Customer uses the Store. For this purpose, they may keep information about the User’s navigation path or the time spent on a given page.
- The Service Recipient has the right to decide on the access of ” cookies ” to his computer by selecting them in his browser window. Detailed information on the possibilities and methods of handling ” cookies ” is available in the software (web browser) settings.
ADDITIONAL SERVICES RELATED TO THE USER’S ACTIVITY IN THE STORE
- The so-called social plug-ins (“plug-ins”) of social networks. By displaying the website www.spraypeptides.com containing such a plug, the Service Recipient’s browser will establish a direct connection with Facebook servers.
- The content of the plugin is transferred by a given service provider directly to the User’s browser and integrated with the website. Thanks to this integration, service providers receive information that the Service Recipient’s browser has displayed the website www.spraypeptides.com, even if the Service Recipient does not have a profile with a given service provider or is not currently logged in with him. Such information (along with the Customer’s IP address) is sent by the browser directly to the server of a given service provider (some servers are located in the USA) and stored there.
- If the Service Recipient logs in to one of the above social networking sites, the service provider will be able to directly assign the visit to the website www.spraypeptides.com to the Service Recipient’s profile on the given social networking site.
- If the Service Recipient uses a given plug-in, eg by clicking on the “Like” button or the “Share” button, the relevant information will also be sent directly to the server of the given service provider and stored there.
- If the Service Recipient does not want social networking sites to assign data collected during visits to the website www.spraypeptides.com directly to his profile on a given website, then before visiting the website www.spraypeptides.com, he must log out of this website. The Service Recipient may also completely prevent the loading of plug-ins on the website by using appropriate extensions for the browser, eg blocking scripts using “NoScript”.
- The administrator uses remarketing tools on his website, i.e. Google AdWords, this involves the use of Google LLC cookies for the Google AdWords service. As part of the mechanism for managing cookie settings, the Service Recipient has the option to decide whether the Service Provider will be able to use Google AdWords (external cookie administrator: Google Inc. based in the USA) in relation to him.
- The administrator uses technical and organizational measures to ensure the protection of the processed personal data appropriate to the threats and categories of data protected, in particular, protects the data against unauthorized disclosure, removal by an unauthorized person, processing in violation of applicable regulations and change, loss, damage or destruction.
- The administrator provides appropriate technical measures to prevent the acquisition and modification by unauthorized persons of personal data sent electronically.