PRIVACY POLICY
OF THE STORE.SMSEAGLE.EU ONLINE STORE
TABLE OF CONTENTS:
- GENERAL PROVISIONS
- BASIS FOR DATA PROCESSING
- PURPOSE, BASIS, PERIOD AND SCOPE OF DATA PROCESSING IN THE ONLINE STORE
- DATA RECIPIENTS IN THE ONLINE STORE
- RIGHTS OF DATA SUBJECTS
- ONLINE STORE COOKIES, OPERATING DATA AND ANALYTICS
- FINAL PROVISIONS
1. GENERAL PROVISIONS
1.1. This privacy policy of the Online Store is of an informational nature, which means that it is not a source of obligations for Service Recipients or Customers of the Online Store. The privacy policy contains, above all, the rules regarding the processing of personal data by the Controller in the Online Store, including the grounds, purposes, and period of personal data processing and the rights of data subjects, as well as information on the use of Cookies and analytical tools in the Online Store.
1.2. The controller of personal data collected via the Online Store is PROXIMUS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ [PROXIMUS LIMITED LIABILITY COMPANY], with its registered office in Poznań (registered office address and address for service: ul. Piątkowska 163, 60-650 Poznań, Poland), entered into the Register of Entrepreneurs of the National Court Register under KRS number: 0000956902, registry court: District Court Poznań – Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the National Court Register, share capital: PLN 400,000.00; NIP (Tax ID): 7812032643, REGON (Statistical ID): 521369644, contact telephone number: +48 616 713 413 – hereinafter referred to as the "Controller" and being, at the same time, the Service Provider of the Online Store and the Seller.
1.3. Personal data in the Online Store is processed by the Controller in accordance with applicable legal provisions, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as the "GDPR" or the "GDPR Regulation". The official text of the GDPR Regulation: http://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679
1.4. Use of the Online Store, including making purchases, is voluntary. Similarly, the provision of personal data in this connection by the Service Recipient or Customer using the Online Store is voluntary, subject to two exceptions: (1) concluding agreements with the Controller – failure to provide, in the cases and to the extent indicated on the Online Store's website and in the Online Store's Terms and Conditions and this privacy policy, personal data necessary for the conclusion and performance of the Sales Agreement or an agreement for the provision of an Electronic Service with the Controller results in the inability to conclude such agreement. The provision of personal data is, in such a case, a contractual requirement, and if the data subject wishes to conclude a given agreement with the Controller, they are obliged to provide the required data. The scope of data required to conclude the agreement is indicated in advance, in each case, on the Online Store's website and in the Online Store's Terms and Conditions; (2) the Controller's statutory obligations – the provision of personal data is a statutory requirement arising from generally applicable legal provisions imposing on the Controller an obligation to process personal data (e.g. processing data for the purpose of keeping tax or accounting books), and failure to provide it will prevent the Controller from fulfilling those obligations.
1.5. The Controller exercises particular diligence in order to protect the interests of the data subjects whose personal data it processes, and, in particular, is responsible for, and ensures, that the data it collects is: (1) processed lawfully; (2) collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes; (3) substantively correct and adequate in relation to the purposes for which it is processed; (4) stored in a form which permits identification of the data subjects for no longer than is necessary for the purposes for which the data is processed; and (5) processed in a manner ensuring appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, by means of appropriate technical or organizational measures.
1.6. Taking into account the nature, scope, context, and purposes of processing, as well as the risk of a violation of the rights or freedoms of natural persons of varying likelihood and severity, the Controller implements appropriate technical and organizational measures to ensure that processing is carried out in accordance with the GDPR Regulation and to be able to demonstrate this. These measures are reviewed and updated as necessary. The Controller applies technical measures to prevent the acquisition and modification, by unauthorized persons, of personal data transmitted electronically.
1.7. Any words, phrases, and acronyms appearing in this privacy policy and beginning with a capital letter (e.g. Seller, Online Store, Electronic Service) should be understood in accordance with their definitions contained in the Online Store's Terms and Conditions available on the Online Store's website.
2. GROUNDS FOR DATA PROCESSING
2.1. The Controller is entitled to process personal data in cases where – and to the extent that – at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specific purposes; (2) processing is necessary for the performance of an agreement to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into an agreement; (3) processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) processing is necessary for the purposes of legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
2.2. The processing of personal data by the Controller requires, in each case, the existence of at least one of the grounds indicated in point 2.1 of the privacy policy. The specific grounds for the processing of personal data of Service Recipients and Customers of the Online Store by the Controller are indicated in the next point of the privacy policy, in relation to the given purpose of the processing of personal data by the Controller.
3. PURPOSE, BASIS, AND PERIOD OF DATA PROCESSING IN THE ONLINE STORE
3.1. In each case, the purpose, basis, and period, as well as the recipients of the personal data processed by the Controller, result from the actions taken by the given Service Recipient or Customer in the Online Store, or by the Controller. For example, if the Customer decides to make purchases in the Online Store and chooses personal collection of the purchased Product instead of a courier shipment, their personal data will be processed for the purpose of performing the concluded Sales Agreement, but will no longer be shared with the carrier delivering shipments on the Controller's order.
3.2. The Controller may process personal data within the Online Store for the following purposes, on the bases, and for the periods indicated in the table below:
| Purpose of data processing | Legal basis for data processing | Data retention period |
|---|---|---|
| Performance of the Sales Agreement or an agreement for the provision of an Electronic Service, or taking action at the request of the data subject prior to the conclusion of the above agreements | Article 6(1)(b) of the GDPR Regulation (performance of an agreement) – processing is necessary for the performance of an agreement to which the data subject is a party, or in order to take action at the request of the data subject prior to entering into an agreement | Data is stored for the period necessary for the performance, termination, or other expiry of the concluded Sales Agreement or agreement for the provision of an Electronic Service. |
| Sending commercial information, including direct marketing, using telecommunications terminal equipment (e.g. e-mail, telephone) or automated calling systems | Article 6(1)(a) of the GDPR Regulation (consent) – in such case, processing is carried out on the basis of consent given by the data subject (e.g. when subscribing to the Newsletter) for sending commercial information using telecommunications terminal equipment, such as e-mail or telephone, depending on the scope of the consent given | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for claims. Data is stored until the data subject withdraws their consent to further processing of their data for the purpose specified in that consent, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal. |
| Expression by the Customer of an opinion on the concluded Sales Agreement | Article 6(1)(a) of the GDPR Regulation – the data subject has given consent to the processing of their personal data for the purpose of expressing an opinion | Data is stored until the data subject withdraws their consent to further processing of their data for this purpose. |
| Keeping accounting books | Article 6(1)(c) of the GDPR Regulation in conjunction with Article 74(2) of the Accounting Act of 30 January 2018 (consolidated text) – processing is necessary for compliance with a legal obligation to which the Controller is subject | Data is stored for the period required by legal provisions obliging the Controller to keep accounting books (5 years, counted from the beginning of the year following the financial year to which the data relates). |
| Establishment, exercise, or defense of claims that may be raised by the Controller, or that may be raised against the Controller | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests of the Controller, consisting of the establishment, exercise, or defense of claims that may be raised by the Controller or that may be raised against the Controller | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for claims that may be raised against the Controller (the basic limitation period for claims against the Controller is six years). |
| Use of the Online Store's website and ensuring its proper functioning | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests of the Controller, consisting of operating and maintaining the Online Store's website | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for the Controller's claims against the data subject arising from the business activity conducted by the Controller. The limitation period is determined by legal provisions, in particular the Civil Code (the basic limitation period for claims related to conducting business activity is three years, and for the Sales Agreement, two years). |
| Keeping statistics and analyzing traffic in the Online Store | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests of the Controller, consisting of keeping statistics and analyzing traffic in the Online Store in order to improve the functioning of the Online Store and increase the sale of Products | Data is stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for the Controller's claims against the data subject arising from the business activity conducted by the Controller. The limitation period is determined by legal provisions, in particular the Civil Code (the basic limitation period for claims related to conducting business activity is three years, and for the Sales Agreement, two years). |
4. RECIPIENTS OF DATA IN THE ONLINE STORE
4.1. For the proper functioning of the Online Store, including for the performance of concluded Sales Agreements, it is necessary for the Controller to use the services of external entities (such as, for example, a software provider, a courier, or a payment processing entity). The Controller uses only the services of such processing entities that provide sufficient guarantees of implementing appropriate technical and organizational measures, so that processing meets the requirements of the GDPR Regulation and protects the rights of data subjects.
4.2. As a rule, the personal data of Service Recipients and Customers is processed within the European Economic Area (EEA). However, the transfer of personal data outside the EEA may take place where necessary for the implementation of the purposes indicated in this Privacy Policy, in particular in connection with the Controller's use of tools and services provided by entities established or processing data outside the EEA (e.g. providers of analytical, marketing, cloud, or communication services). The Controller transfers personal data outside the EEA only where necessary, and while ensuring an appropriate degree of data protection, in particular through: (1) transfer to an entity in a country in respect of which the European Commission has issued a decision confirming an adequate level of data protection (e.g. to an entity in the United States certified under the EU-U.S. Data Privacy Framework); (2) the use of standard contractual clauses for data protection adopted by the European Commission; or (3) on the basis of another instrument compliant with Chapter V of the GDPR Regulation. The data subject may obtain a copy of the data transferred to a third country and information on where the applied safeguards are made available, by contacting the Controller in the manner indicated in this Privacy Policy. The transfer of data outside the EEA may also concern countries in respect of which the European Commission has not issued a decision on an adequate level of protection. In such cases, the Controller transfers data only in the cases and on the terms permitted by law.
4.3. The transfer of data by the Controller does not take place in every case, and not to all recipients or categories of recipients indicated in the privacy policy – the Controller transfers data only where this is necessary for the implementation of a given purpose of personal data processing, and only to the extent necessary for its implementation. For example, if the Customer uses personal collection, their data will not be transferred to the carrier cooperating with the Controller.
4.4. The personal data of Service Recipients and Customers of the Online Store may be transferred to the following recipients or categories of recipients:
4.4.1. carriers / forwarders / courier brokers / entities operating the warehouse and/or shipping process – in the case of a Customer who uses, in the Online Store, a method of Product delivery by postal shipment or courier shipment, the Controller makes the Customer's collected personal data available to the selected carrier, forwarder, or intermediary carrying out shipments on the Controller's order, and, if shipment takes place from an external warehouse, to the entity operating the warehouse and/or shipping process, to the extent necessary to carry out the delivery of the Product to the Customer.
4.4.2. entities handling electronic payments or payment card payments – in the case of a Customer who uses, in the Online Store, a method of electronic payment or payment card payment, the Controller makes the Customer's collected personal data available to the selected entity handling the above payments in the Online Store on the Controller's order, to the extent necessary to handle the payment made by the Customer.
4.4.3. service providers supplying the Controller with technical, IT, and organizational solutions enabling the Controller to conduct its business activity, including the Online Store and the Electronic Services provided through it (in particular, providers of computer software for running the Online Store, providers of e-mail and hosting, and providers of software for company management and providing technical support to the Controller) – the Controller makes the Customer's collected personal data available to the selected provider acting on its order only in the case, and to the extent, necessary to implement the given purpose of data processing consistent with this privacy policy.
4.4.4. providers of accounting, legal, and advisory services providing the Controller with accounting, legal, or advisory support (in particular, an accounting office, a law firm, or a debt collection company) – the Controller makes the Customer's collected personal data available to the selected provider acting on its order only in the case, and to the extent, necessary to implement the given purpose of data processing consistent with this privacy policy.
5. PROFILING IN THE ONLINE STORE
5.1. The GDPR Regulation imposes on the Controller an obligation to provide information about automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR Regulation, and – at least in those cases – meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject. With this in mind, the Controller provides, in this point of the privacy policy, information regarding possible profiling.
5.2. The Controller may use profiling in the Online Store for direct marketing purposes, but the decisions made on this basis by the Controller do not concern the conclusion or refusal to conclude the Sales Agreement, or the possibility of using the Electronic Services in the Online Store. The effect of using profiling in the Online Store may be, for example, granting a given person a discount, sending them a discount code, a reminder of unfinished purchases, sending a Product suggestion that may correspond to the interests or preferences of the given person, or offering better conditions compared to the standard offer of the Online Store. Despite the profiling, the given person freely decides whether they wish to take advantage of the discount or better conditions received in this way and make a purchase in the Online Store.
5.3. Profiling in the Online Store consists of the automatic analysis or forecasting of the behavior of a given person on the Online Store's website, e.g. by adding a specific Product to the cart, browsing the page of a specific Product in the Online Store, or by analyzing the history of purchases previously made in the Online Store. A condition for such profiling is that the Controller holds the personal data of the given person, so as to be able to subsequently send them, for example, a discount code.
5.4. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
6. RIGHTS OF THE DATA SUBJECT
6.1. Right of access, rectification, restriction, erasure, or portability – the data subject has the right to request from the Controller access to their personal data, its rectification, erasure ("the right to be forgotten"), or restriction of processing, and has the right to object to processing, and also has the right to data portability. The detailed conditions for exercising the above-mentioned rights are set out in Articles 15-21 of the GDPR Regulation.
6.2. Right to withdraw consent at any time – a data subject whose data is processed by the Controller on the basis of consent given (pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR Regulation) has the right to withdraw their consent at any time, without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal.
6.3. Right to lodge a complaint with a supervisory authority – a data subject whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and procedure specified in the provisions of the GDPR Regulation and Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office (UODO).
6.4. Right to object – the data subject has the right, at any time, on grounds relating to their particular situation, to object to the processing of their personal data based on Article 6(1)(e) (public interest or public tasks) or (f) (legitimate interest of the controller), including profiling based on these provisions. In such a case, the Controller may no longer process this personal data unless it demonstrates the existence of compelling legitimate grounds for processing that override the interests, rights, and freedoms of the data subject, or grounds for the establishment, exercise, or defense of claims.
6.5. Right to object regarding direct marketing – if personal data is processed for the purposes of direct marketing, the data subject has the right, at any time, to object to the processing of their personal data for the purposes of such marketing, including profiling, to the extent that the processing is related to such direct marketing.
6.6. In order to exercise the rights referred to in this point of the privacy policy, one may contact the Controller by sending an appropriate message in writing or by e-mail to the Controller's address indicated at the beginning of the privacy policy, or by using the contact form available on the Online Store's website.
7. COOKIES IN THE ONLINE STORE AND ANALYTICS
Information regarding Cookies and analytical tools used in the Online Store is contained in the separate Cookie Policy of the Online Store.
8. FINAL PROVISIONS
7.1. The Online Store may contain links to other websites. The Controller encourages that, after moving to other websites, one become familiar with the privacy policy established there. This privacy policy applies only to the Controller's Online Store.
This document was reviewed by the lawyers of the Prokonsumencki.pl service for compliance with legal provisions and is protected by copyright.