PRIVACY POLICY OF THE ONLINE STORE
§1 GENERAL PROVISIONS
The administrator of personal data collected via the online store www.blubom.com is Daniel Dębiński, conducting business under the name Firma Produkcyjno-Handlowo-Usługowa "SZKLANA GWIAZDA" Daniel Dębiński, registered in the Central Registration and Information on Economic Activity of the Republic of Poland conducted by the Minister of Economy. The business address and mailing address is ul. Ludwika Solskiego 37, 32-800 Brzesko, NIP: 8691247692, REGON: 852486129, email address: biuro@szklanagwiazda.pl, phone number: +48 14 68 64 046, hereinafter referred to as the "Administrator" and being also the "Service Provider."
The personal data collected by the Administrator through the website is processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as "GDPR."
All words or expressions capitalized in this Privacy Policy should be understood in accordance with their definition in the Terms and Conditions of the online store www.blubom.com.
§2 TYPE OF PERSONAL DATA PROCESSED, PURPOSE, AND SCOPE OF DATA COLLECTION
PURPOSE OF PROCESSING AND LEGAL BASIS. The Administrator processes the personal data of the Users of www.blubom.com in the case of:
- Registration of an Account in the Store to create an individual account and manage it, based on Article 6(1)(b) of GDPR (performance of a contract for electronic services according to the Store's Terms and Conditions),
- Placing an Order in the Store to execute the Sales Agreement, based on Article 6(1)(b) of GDPR (performance of the sales agreement),
- Signing up for the Newsletter to send commercial information via email. Personal data is processed based on the separate consent of the User, under Article 6(1)(a) of GDPR,
- Using the Contact Form to send messages to the Administrator, based on Article 6(1)(f) of GDPR (legitimate interest of the entrepreneur).
TYPE OF PERSONAL DATA PROCESSED. The User provides, in the case of:
- Account: name, login, address, email address,
- Order: name, address, NIP (tax ID), email address, phone number,
- Newsletter: name, email address,
- Contact Form: name, email address.
DATA STORAGE PERIOD. The personal data of the Users are stored by the Administrator:
- In the case where the legal basis for processing is the performance of a contract, as long as it is necessary to perform the contract, and after that, for the period corresponding to the statute of limitations for claims. If a specific provision does not state otherwise, the statute of limitations is six years, and for periodic benefits and claims related to business activities, it is three years,
- In the case where the legal basis for processing is consent, until the consent is revoked, and after revocation, for a period corresponding to the statute of limitations for claims that the Administrator may assert or that may be asserted against him. If a specific provision does not state otherwise, the statute of limitations is six years, and for periodic benefits and claims related to business activities, it is three years.
Additional information may be collected during the use of the Store, in particular: the IP address assigned to the User’s computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type.
Upon separate consent, based on Article 6(1)(a) of GDPR, data may also be processed for sending commercial information electronically or making telephone calls for direct marketing purposes – pursuant to Article 10(2) of the Act of 18 July 2002 on the provision of electronic services or Article 172(1) of the Telecommunications Act of 16 July 2004, including profiling, if the User has given the appropriate consent.
Navigation data may also be collected from the Users, including information about the links and references they choose to click on, or other actions taken in the Store. The legal basis for such activities is the legitimate interest of the Administrator (Article 6(1)(f) of GDPR), aiming to facilitate the use of electronically provided services and improve their functionality.
The provision of personal data by the User is voluntary.
The Administrator takes special care to protect the interests of the persons whose data is collected, and in particular ensures that the data collected is:
- processed lawfully,
- collected for specified, lawful purposes and not subjected to further processing incompatible with those purposes,
- substantively correct and adequate in relation to the purposes for which it is processed and stored in a form that permits the identification of the persons concerned, no longer than is necessary to achieve the purpose of processing.
§3 SHARING OF PERSONAL DATA
Personal data of the Users may be shared with service providers used by the Administrator in the operation of the Store, particularly:
- entities delivering Products,
- payment system providers,
- accounting services,
- hosting providers,
- software providers that facilitate the business operation,
- mailing system providers,
- software providers necessary for running the online store.
The service providers referred to in point 1 of this paragraph, to whom personal data is shared, depending on contractual arrangements and circumstances, either act on the instructions of the Administrator regarding the purposes and means of processing such data (data processors) or independently determine the purposes and means of their processing (controllers).
Personal data of the Users is stored only within the European Economic Area (EEA), subject to § 5 point 5 of the Privacy Policy.
§4 RIGHT TO CONTROL, ACCESS, AND CORRECT YOUR DATA
The person whose data is processed has the right to access their personal data and the right to rectify, delete, restrict processing, transfer data, object to processing, and withdraw consent at any time without affecting the legality of the processing that was performed based on consent before its withdrawal.
The legal grounds for the User's requests:
- Access to data – Article 15 GDPR,
- Rectification of data – Article 16 GDPR,
- Deletion of data (the "right to be forgotten") – Article 17 GDPR,
- Restriction of processing – Article 18 GDPR,
- Data transfer – Article 20 GDPR,
- Objection – Article 21 GDPR,
- Withdrawal of consent – Article 7(3) GDPR.
To exercise the rights referred to in point 2, an appropriate email can be sent to the following address: biuro@szklanagwiazda.pl.
In the event of a User exercising any of the above rights, the Administrator shall fulfill the request or refuse to do so immediately, no later than within one month of receiving the request. If the request is complex or the number of requests is high, the Administrator may extend the response time by a further two months, but will inform the User within one month of receiving the request, explaining the reasons for the delay.
If it is determined that the processing of personal data violates GDPR, the person affected has the right to lodge a complaint with the President of the Personal Data Protection Office.
§5 COOKIES
The Administrator's website uses "cookies."
The installation of cookies is necessary for the proper provision of services on the website of the Store. Cookies contain information necessary for the proper functioning of the website, and they also allow for the compilation of general statistics on website visits.
The Store uses two types of cookies: "session" and "permanent."
- "Session" cookies are temporary files stored on the User's device until logging out (leaving the site),
- "Permanent" cookies are stored on the User's device for the time specified in the cookie parameters or until they are deleted by the User.
The Administrator uses its own cookies to better understand how Users interact with the content of the website. Cookies collect information on the use of the website by the User, the type of site from which the User was redirected, and the number of visits and time spent on the website. These cookies do not record personal data about the User but are used to compile statistics on the use of the website.
The Administrator also uses external cookies to collect general and anonymous static data via analytical tools such as Google Analytics (external cookies administrator: Google LLC based in the USA).
Cookies may also be used by advertising networks, in particular, the Google network, to display ads tailored to the way the User uses the Store. To do this, they may store information about the User's navigation path or time spent on a given page.
The User has the right to decide on the access of cookies to their computer by:
- Choosing the types of cookies to which they consent right after entering the Store and seeing the cookie information message,
- Changing the settings in their browser window. Detailed information on the possibilities and methods of handling cookies is also available in the browser settings.
§6 FINAL PROVISIONS
The Administrator applies technical and organizational measures to ensure the protection of the processed personal data, appropriate to the threats and the category of data under protection, and in particular, secures the data against unauthorized access, acquisition by an unauthorized person, processing in violation of applicable regulations, and alteration, loss, damage, or destruction.
The Administrator provides appropriate technical measures to prevent the unauthorized acquisition and modification of personal data transmitted electronically.
In matters not covered by this Privacy Policy, the provisions of GDPR and other relevant provisions of Polish law