The administrator of personal data responsible for its processing is:

Marcin Broniszewski

Promienna, 17

Warsaw Wesoła

wespromx@gmail.com

Thank you for your interest in our online store. Protecting your privacy is very important to us. Below you will find detailed information regarding the handling of your data.

1. access data and hosting

You can visit our websites without providing personal data. For each web page call-up, the server automatically saves only so-called server logs, e.g. the name of the requested file, your IP address, the date and time of the call-up, the amount of data transferred and the requesting ISP (so-called access logs) and documents the web page call-up.

This data is analyzed for the sole purpose of ensuring the proper functioning of our website and improving our offerings. The above serves, in accordance with Article 6 (1) (f) RODO, to safeguard our legitimate interest in the optimal, correct presentation of our websites and offerings. All access data is deleted within seven days after the end of your visit to the website.

Hosting

Website hosting and display services are partially provided on our behalf by our service providers under a data processing entrustment. Unless otherwise stated in this privacy policy, all access data and data collected in the forms provided for this purpose on our site will be processed on their servers. If you have any questions about our service providers and the basis of our cooperation with them, please contact us. You can find our contact information under "Our contact information and your rights".

2. collection and processing of data for the purpose of contract execution, contact and customer account creation

We collect personal data only when you voluntarily provide it to us by placing your order or by contacting us (e.g., using the contact form or by e-mail). Mandatory fields are marked as such because the data they contain are necessary for the performance of the contract or the processing of the matter on which you are contacting us. Without providing them, you cannot complete your order or contact us. What data is collected is a direct result of the forms into which the data is entered. We use the data you provide in accordance with Article 6(1)(b) of the RODO to perform the contract and respond to your inquiries. In addition, if pursuant to Article 6(1)(a) of the RODO you provide your consent to set up a customer account - we will process your personal data necessary for this purpose. For further information regarding the processing of your data, in particular with regard to the transfer of data to our service providers for order processing, payment and shipping, please refer to the following sections of this privacy policy.

After the complete execution of the contract or deletion of your customer account, the processing of your data will be restricted, and after the expiration of the retention periods specified in the Tax Law and the Accounting Law, your data will be deleted (Article 6(1)(c) of the DPA), unless you expressly consent (Article 6(1)(a) of the DPA) to the continued use of such data or, in accordance with applicable law, we reserve the right to continue to use your data for culpable purposes, in which case we inform you of this privacy policy. Your customer account can be deleted at any time. To do this, please send a message to our contact address indicated under "Our contact details and your rights" or use the corresponding function in the settings of your customer account.

3. Transmission of data for the purpose of delivery

In order to perform the contract (Article 6(1)(b) of the RODO), we will transfer your data to the shipping company selected by you in the ordering process and commissioned to deliver the ordered products.

4. Processing of data for the purpose of payment processing

In order to process payments in our online store, we cooperate with external service providers handling electronic online payments and provide your data to the payment processing company selected by you in the ordering process. The above is for the purpose of fulfilling the contract (Article 6(1)(b) of the RODO).

Data processing to prevent fraud and optimize payments

In certain situations, we may provide our service providers with additional information that can be used by them along with the information necessary to process payments. These service providers then act on our behalf as processors and provide us with services for fraud prevention and payment process optimization (e.g. invoicing, analysis of disputed payments, accounting support). Pursuant to Article 6(1)(f) of the RODO, this serves our legitimate interests in protecting against fraud and abuse and in the effective management of payments.

5. Channels of marketing activities: email (e.g. newsletter)

Advertising sent by email when you sign up for the newsletter

If you sign up for our newsletter, then we will use the data you provide to us necessary for the purpose of sending you our newsletter by email on a regular basis based on the consent you have given us (Article 6(1)(a) of the RODO). You may unsubscribe from the newsletter at any time by sending us a message to our contact address indicated under "Our contact information and your rights" or by using the relevant link provided in the newsletter. After unsubscribing, we will delete your e-mail address unless you expressly consent to the continued use of your data for other purposes or we reserve the right to continue using your data in statutorily permitted cases, in which case we inform you of this privacy policy.

Sending of the newsletter

The newsletter is sent as part of the entrustment of data processing on our behalf by an external service provider. If you have questions about our service providers and the basis of our cooperation with them, please contact us. You will find contact information under "Our contact information and your rights".

6 Cookies and similar technologies

General information

In order to make your visit to our website more attractive and to enable you to use its key features, we use technological tools for this purpose, including so-called cookies. Cookies are small text files that are automatically stored on your terminal device. Some cookies we use are deleted when your browser session ends, i.e. when you close it (so-called session cookies). Other cookies are retained on your end device and enable us to recognize your browser the next time you visit the site (so-called persistent cookies). We use technologies that are absolutely necessary to ensure the correct and optimal use of the necessary functions of our website (e.g. the shopping cart function). These technologies process data such as, for example, your IP address, the time of your visit to the website, device and browser information, as well as information about your use of our website (e.g., the contents of your shopping cart). This serves, in accordance with Article 6(1)(f) of the DPA, to fulfill our legitimate interest in optimally presenting our offerings.

In addition, we also use technological tools to fulfill legal obligations to which we are subject (e.g., to prove receipt of consent to process your personal data), as well as for web analytics and online marketing. For further information on this, including the relevant legal basis for processing your data, please refer to the following sections of this privacy policy.

In your browser's help menu, you will find explanations on how to change your cookie settings. These are available at the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™.

When consent has been given to us by you for the use of certain technological tools (Article 6(1)(a) of the RODO), it can be withdrawn by you at any time. To withdraw your consent, please contact us via the contact address indicated under "Our contact details and your rights".

7. use of cookies and similar technological tools for web analytics and marketing purposes

Insofar as you have given us your consent to do so (Article 6(1)(a) of the RODO), we use the cookies and other similar technological tools of third-party service providers indicated below on our website. Once the purpose of the processing has been fulfilled and the use of the respective technological tool has been terminated, the data collected through the use of these tools will be deleted. The consent you have given may be revoked by you at any time. For details on the possibility to revoke consent and your right to object, please see "Cookies and similar technologies". You will find further information on the pages of the individual service providers. If you have questions about our service providers and the basis of our cooperation with them, please contact us. You will find contact information under "Our contact information and your rights".

Use of Google services

We use the technology tools of Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland ("Google") indicated below. The information automatically collected by Google's technologies regarding the use of our website is usually transferred to a server of Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA and stored there. The European Commission has not issued a decision for the US on the adequacy of data protection. Our cooperation is based on standard data protection clauses adopted by the European Commission. In the event that processing of your IP address occurs as part of the use of Google's technological tools, then, thanks to IP anonymization enabled, your address is truncated before being stored on Google's servers. Only in exceptional cases will the full IP address be transferred to a Google server and shortened there. Unless otherwise specified for the individual Google technologies described in this privacy policy, data processing is carried out on the basis of a personal data co-management agreement with Google in accordance with Article 26 of the DPA. For further information on Google's data processing, please refer to the privacy policy on Google's website.

Google Analytics

For the purpose of analyzing the use of our website, we use Google Analytics, a web analytics tool from Google, which automatically processes your data for this purpose (IP address, time of visit, device and browser information, as well as information on the use of our website) and creates pseudonymized user profiles based on this data. Cookies may be used for this purpose. As a rule, your IP address is not combined with other data collected by Google. The processing of data as part of Google Analytics is carried out on the basis of a data entrustment agreement with Google.

Google Fonts

In order to ensure consistent presentation of content on our websites, a script called "Google Fonts" is integrated with our website, which processes your data (IP address, time of website visit, device and browser information, as well as information regarding the use of our website). We have no influence over the above data processing by Google.

YouTube Video Plugin

In order to integrate third-party content using the YouTube video plugin - the following data is processed by Google when the video is played: IP address, time of visit, information about your device and browser.

Use of Facebook services

Facebook Analytics

Within the framework of Facebook Analytics - based on the data collected by the Facebook Pixel tool regarding your use of our website, statistics are created on user activity on our website. Data processing by Facebook takes place on the basis of the concluded data entrustment agreement. Analysis of the data (website usage statistics) is used to optimize and make our website more attractive.

8. integration with Trusted Shops Trustbadge

In order to display our Trusted Shops Seal of Approval, as well as the collected customer reviews and the Trusted Shops offer available to buyers after ordering - Trusted Shops' Trustbadge is integrated with our website.

The integration of Trusted Shops Trustbadge serves our legitimate interests (Art. 6(1)(f) RODO) of optimizing the marketing of our offerings by enabling secure purchases. Trustbadge (the so-called trust identifier) and the services advertised with it constitute an offer by Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne, Germany. Trustbadge is put at our disposal as part of the CDN (Content-Delivery-Network) services. Trusted Shops GmbH uses, among others, US providers for this purpose. An appropriate level of data protection is ensured in this process. You can find more information about the data protection principles of Trusted Shops GmbH here.

When Trustbadge is called up, the server automatically saves so-called server logs (log files) containing, for example, your IP address, the date and time of the call, the amount of data transferred and the Internet service provider making the request (access data/so-called server logs) and documents the call. The server logs are stored for vulnerability analysis and are automatically deleted no later than 90 days after they are created. Other personal data is transferred to Trusted Shops GmbH only if you voluntarily decide to use Trusted Shops products after placing an order in our store or have previously registered to use them. In such cases, the contractual agreement between you and Trusted Shops applies. For this purpose, your personal data is automatically extracted from your order data. Whether or not you, as a buyer, are already registered to use Trusted Shops products is checked automatically on the basis of a neutral parameter - an email address encrypted with one-way cryptologic encryption. The email address is encrypted before it is transmitted using a hash value in such a way that it cannot be decrypted by Trusted Shops. Once compliance is verified, the parameter is automatically removed. The above is necessary for the purposes of our and Trusted Shops' legitimate interests (Article 6(1)(f) of the DPA) in providing services linked each time to a specific order, i.e. the buyer protection service (Trusted Shops guarantee) and the rating service. Other information, including your rights, is contained in the Trusted Shops privacy policy available above and through the Trustbadge tool.

9. social media

Social media plugins: Facebook, Instagram

So-called social media plug-ins (buttons) are used on our website. These plug-ins are accessible via an HTML link, which ensures that when you visit our site containing such plug-ins (buttons), you do not establish an automatic, direct connection to the servers of the operator of the respective social network. When you click on one of the buttons (plug-ins), a new window of your browser opens displaying the page of the respective social network, where you can approve the use of the button, such as "Like" or "Share".

Our activity on social networks: Facebook, Instagram

If you have given your consent to the respective social network in this regard (Article 6(1)(a) of the RODO), when you visit our account/profile on the aforementioned social networks, your data will be automatically collected and stored for web analytics and marketing purposes. Based on this data, pseudonymized user profiles are created. These can be used, for example, to place so-called personalized advertisements within and outside the social networks, which are likely to match your interests. Cookies are usually used for this purpose.

Detailed information regarding the processing and use of your data by individual social networks, as well as information regarding your rights and the possibility of configuring your privacy settings, as well as contact information for the purpose of submitting an inquiry, are described in the privacy policies of the individual social networks linked below. Should you need assistance in this regard, you can also contact us.

Facebook is a social network offered by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). Automatically processed information regarding your activity and use of our fanpage on Facebook is generally transmitted to the server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025 in the USA and stored there. With respect to the U.S., the European Commission has not issued a decision finding an adequate level of data protection. Our cooperation is based on the standard data protection clauses adopted by the European Commission. The processing of data in the context of Facebook fanpage visits is carried out in accordance with Article 26 of the RODO on the basis of the concluded joint arrangements of the joint controllers, which are available here. Further information regarding the processing of your personal data within the scope of your Facebook fanpage visit (information regarding the page statistics function) is available here.

Instagram is a social networking service offered by Facebook Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook Ireland"). Automatically processed information regarding your activity and use of our fanpage account on Instagram is generally transmitted to the server of Facebook, Inc., 1601 Willow Road, Menlo Park, California 94025 in the USA and stored there. With respect to the U.S., the European Commission has not issued a decision finding an adequate level of data protection. Our cooperation is based on the standard data protection clauses adopted by the European Commission. The processing of data in the context of visits to the fanpage account on Instagram is carried out in accordance with Article 26 of the RODO on the basis of the concluded joint arrangements of the joint controllers. Further information regarding the processing of your personal data within the framework of your Facebook fanpage visit (information regarding the page statistics function) is available here.

10 Our contact information and your rights

Data subjects have the following rights:

  • pursuant to Article 15 of the RODO: the right to be informed about the processing of your data to the extent specified therein;
  • pursuant to Article 16 of the RODO: the right to rectify your inaccurate or incomplete personal data;
  • in accordance with Article 17 of the RODO: the so-called "right to be forgotten," i.e. the right to delete your personal data stored with us, unless further processing is necessary:
  • to exercise your right to freedom of expression and information;
  • to fulfill a legal obligation;
  • for reasons of public interest;
  • to establish, assert or defend claims;
  • Pursuant to Article 18 RODO: the right to restrict the processing of your personal data, provided that:
  • the accuracy of such personal data is contested by you;
  • the processing is unlawful and you object to its erasure;
  • we no longer need the personal data, but you need it to establish, assert or defend your claims;
  • you have lodged an objection under Article 21 to the processing;
  • pursuant to Article 20 RODO: the right to receive the data provided to us in a structured, commonly used, machine-readable format and to have it sent to another controller;
  • pursuant to Article 77 of the RODO: the right to lodge a complaint with a supervisory authority (the President of the Office for Personal Data Protection "DPA").

If you have any questions about the collection, processing and use of your personal data, or if you wish to request information, rectification, restriction of processing or deletion of your data, or to revoke consents granted or to object to the use of certain data, please contact the data controller indicated at the beginning of this privacy policy directly.

Right to object

If we process personal data in the manner described in this privacy policy in order to safeguard our legitimate interests, then you may object to the processing of your data for this purpose - with effect for the future. If the processing takes place for direct marketing purposes, you may exercise your right to object at any time. If the processing takes place for other purposes, you have the right to object only for reasons arising from your particular situation.

Once you have exercised your right to object, we will not continue to process your personal data unless we demonstrate the existence of valid, legitimate grounds for the processing and they override your interests and rights, or if the processing is for the assertion, exercise or defense of legal claims.

The above sentence does not apply when the processing is done for direct marketing purposes. In this case, we will always cease further processing of your personal data after you have expressed your objection.