PRIVACY POLICY
Privacy policy and personal data protection (hereinafter "Policy")
- Introduction
The administrator of personal data collected in accordance with this Policy is Coco Bowls Piotr Garbacki with its registered office in Starachowice 27-200, ul. Tatrzańska 4, NIP: 6642063956, e-mail address: cocobowlswarsaw@gmail.com (hereinafter "Administrator", "Seller").
- Definitions
For the purposes of this Policy, the following definitions mean:
- Personal data - means information about an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- User, Users, Customer, Customers - means any person who uses the Store available at: www.cocobowls.pl
- Processing of personal data - means an operation or set of operations performed on Personal data or sets of Personal data by automated or non-automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Regulation or GDPR - means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Regulations - means the Regulations for the provision of services by electronic means within the Store operating at: www.cocobowls.pl
- Store - means the online store operating at www.cocobowls.pl
- Scope of personal data collection
The Administrator makes every effort to ensure that Personal Data is processed in accordance with applicable law and that it is protected against loss, destruction, disclosure, unauthorized access or improper use. The Administrator guarantees the confidentiality of all data provided to it, by taking effective security and Personal Data protection measures. In case of suspicion that the User's Personal Data is not properly secured or if there is evidence of abuse, please contact us at: cocobowlswarsaw@gmail.com
In each case, the purpose, scope and recipients of Personal Data processed by the Administrator
1
result from the User's consent or legal provisions and are specified as a result of actions taken by the User in the Store or through other channels of communication with the Customer.
The Administrator may process the following Personal Data of Customers using the Store:
- surname and first name,
- correspondence address,
- delivery address (street, house number, apartment number, postal code, city, country),
- residence/business address (if different from delivery address),
- email address,
- phone number,
- bank account number,
- data/information about payments made by the User,
- IP address.
In the case of Customers who are not consumers, the Administrator may additionally process the company name and tax identification number (NIP) of the Customer.
- Purpose of personal data processing
Providing Personal Data is necessary to conclude and execute a sales contract. Each time, the scope of Personal Data required to conclude an appropriate contract is indicated in advance in the Store and in the Regulations. Failure to provide data results in the inability to conclude a contract between the Customer and the Seller.
Possible purposes of collecting and processing Customers' Personal Data by the Administrator:
a. conclusion and execution of a sales contract or service contract and
receiving and handling complaints;
The main purpose of processing Personal Data and other information by the Seller is to maintain the Store, ensure safe and guaranteed performance of services for Users and execute product sales contracts. Providing certain data is also necessary to use the services and functionalities of the Store. The consequence of not providing them is the inability of the Seller to provide certain services and functionalities. In addition to data marked as "obligatory", providing other data is voluntary. The legal basis for processing will be Article 6(1)(b) of the GDPR (necessity for the performance of a contract for the provision of electronic services).
- performing financial settlements
In order to perform financial settlements, the Seller processes Users' Personal Data to the extent necessary to make settlements, e.g. issuing an invoice. The legal basis for processing Users' Personal Data contained in settlement documents is Article 6(1)(c) of the GDPR (fulfilment of a legal obligation incumbent on the Administrator, e.g. issuing an invoice). Data in this respect will be processed until the claims arising from sales contracts become time-barred. In addition, all issued accounting documents, e.g. invoices, are included in the accounting documentation kept by the Seller, and therefore Users' data
Transaction data, including personal data, may be transferred to PayPro S.A. with its registered office in Poznań at ul. Pastelowa 8, 60-198 Poznań, KRS 0000347935, NIP 7792369887, to the extent necessary to process payment for the order.
2
will be processed in this respect for the period required by generally applicable legal provisions.
- security of claims
In order to establish, pursue and enforce claims, the Seller may process certain Personal Data provided by the User, in particular name and surname, contact details (e-mail address, phone number), data on the use of the Store and other data that will be necessary to prove the existence of the claim, its enforcement and defence against claims in proceedings before courts and other state authorities. The legal basis for data processing is Article 6(1)(f) of the GDPR, i.e. the legitimate interest of the Seller. Data in this respect are processed for the statutory limitation period of claims. However, data processing will only include their storage, excluding any other operations on these data, subject to other obligations of the Seller indicated in applicable provisions or imposed on the Seller by authorized bodies.
- creating statistics on the use of Store pages and profiling
The Administrator monitors the quality of services it provides, as it strives to meet customer expectations. For this purpose, statistics on the use of individual functions and subpages of the Store are kept using:
- ➢internal analytical tools,
- ➢statistical tools provided by partners providing analytical services. To achieve this goal, data on the User's activity on the Store's website are processed (e.g., pages and subpages of the Store visited by the User, time spent on the page, User's IP address, location, device ID, and data on the browser and operating system used by the User).
Analyzing online behavior helps the Administrator better understand User habits and expectations and adapt to their needs and interests. Thanks to this technology, the Administrator can not only present the User with an advertisement tailored to them, but also, among the available offers, primarily present those that will best meet the User's needs. Information collected and contained in cookies may be stored after the browser session ends, which allows, for example, for their use during subsequent User visits to the Store.
The legal basis for data processing is Article 6(1)(f) of the GDPR, i.e., the legitimate interest of the Seller, consisting in facilitating Users' use of services provided by the Seller by electronic means and in improving the functionality of these services.
- Cookies and profiling
The Store uses technology that stores and accesses information on the Customer's computer or other network-connected device (in particular using cookies), in order to ensure the Customer maximum comfort while using the Store, including for statistical purposes and to adapt advertising content presented to the Customer's interests, including the Administrator's partners and advertisers. During the Customer's visit to the Store, data regarding the visit may be automatically collected, in the form of the domain name of the website from which the Customer was referred to the Store's website, browser type, operating system type, IP address, Customer ID, other information transmitted by the http protocol. Additionally, the Administrator may process operational data or location information of the device through which access to the Store is made.
Cookies used in the Store are not harmful to either the Customer or the computer/end device used by the Customer, therefore it is recommended not to disable their support in browsers.
3
The Store uses two types of cookies: session cookies, which remain saved on the Customer's computer or mobile device until logging out of the website or turning off the software (web browser), and persistent cookies, which remain on the Customer's device for the time specified in the cookie parameters or until they are manually deleted in the web browser.
Cookies used by the Administrator primarily serve to optimize User service when using the Store. The Administrator also cooperates with other companies in terms of their marketing (advertising) activities. For the purpose of this cooperation, the browser or other software installed on the User's device also saves cookies from entities conducting such marketing activities, which may become the administrator of the User's personal data. Cookies sent by these entities are intended to ensure that the User is presented only with advertisements that match their individual interests and needs. As part of its marketing activities, the Administrator uses the services of the following entities that use cookies in the Store:
- GOOGLE LLC
More information about the cookies of the above-mentioned entities can be found in their privacy policies.
- Possible recipients of Customers' Personal Data:
Customer data may be transferred to entities processing Personal Data on behalf of the Administrator, including:
- IT service providers,
b. courier companies,
c. marketing agencies, marketing partners and platform providers
marketing,
- entities processing and coordinating payment processing;
- Transaction data, including personal data, may be transferred to PayPro S.A. with its registered office in Poznań at ul. Pastelowa 8, 60-198 Poznań, KRS 0000347935, NIP 7792369887, to the extent necessary to process payment for the order
- cloud service providers,
f. data analysis service providers,
g. consultants, lawyers, accountants and other professional service providers,
h. entities related to the Administrator personally and by capital, which help him
provide services or perform data processing tasks on its behalf
– provided that such entities process data on the basis of an agreement concluded with the Administrator and solely in accordance with its instructions.
The Administrator also makes Personal Data available to authorized state bodies if they request it in connection with their tasks. These may include, in particular, organizational units of the prosecutor's office, the Police, the General Inspector for Personal Data Protection (in the future, the President of the Office for Personal Data Protection), the President of the Office of Competition and Consumer Protection or the President of the Office of Electronic Communications.
The Administrator also cooperates with external partners who help it improve services and products, or use business tools, such as Facebook (Pixel), Google, Shopify.
- Transfer of data to third countries (outside the European Economic Area)
4
As part of the Administrator's use of tools supporting its ongoing operations, made available, for example, to the entities indicated in point 4 d, such as Google, the User's Personal Data may be transferred to a country outside the European Economic Area, in particular to the United States of America (USA) or another country where the entity cooperating with it maintains tools for processing Personal Data in cooperation with the Administrator.
Appropriate safeguards for the Personal Data transferred by Users have been ensured by the Administrator through the application of data protection clauses meeting the requirements of the GDPR. In the case of data transfer from Europe to the USA, some entities located there may additionally ensure an adequate level of data protection within the framework of the so-called Privacy Shield program (more information at: https://www.privacyshield.gov/).
- Period of personal data retention
The Administrator guarantees that Users' Personal Data will not be processed for a period longer than required by law or provided for in the Administrator's internal regulations. The criteria for determining the data processing time for specific purposes are described in point 4 of the Policy.
- Access and correction of stored Personal Data
In connection with the processing of Personal Data by the Seller, Users have the following rights:
- the right to request access to their Personal Data, its rectification, erasure or restriction of processing,
- the right to object to processing,
- the right to data portability,
- the right to withdraw consent to the processing of Personal Data for a specific purpose, if the User has previously given such consent,
- the right to lodge a complaint with a supervisory authority in connection with the Administrator's processing of the User's Personal Data.
Users can exercise the above rights in accordance with the principles described in Articles 16 – 21 of the GDPR, by sending an e-mail to: cocobowlswarsaw@gmail.com
All received requests will be handled as quickly as possible. In the case of some requests (of a complex nature), the processing time may be extended, however, in each case, within one month, the User will be informed of the actions taken by the Administrator to fulfill the request. When providing a response and in order to ensure that the Administrator properly handles the request, the Administrator reserves the right to verify the User's identity.
- Risks associated with using services provided electronically
The Personal Data Administrator would like to inform Users that by using services provided electronically without proper care for the security of their data, they expose themselves, among others, to the risk of:
- interference with User data by unauthorized persons who may view, copy, modify and delete User data,
- receiving unwanted email,
- phishing for User data,
- interference by third parties in the transmission of information between the User's system and the system
5
Administrator,
- infection of the User's system with malware,
- forgery of security protocols and certificates.
To minimize the above risks:
a. always use up-to-date software versions, e.g. browser, b. check the certificate before logging in to the Store.
- Communication
The Administrator may communicate with the User via system information, notifications, email, social media messages, SMS messages, phone or traditionally via letters and parcels.
Commercial information related to the commercial activity conducted by the Administrator or entities cooperating with it may be sent only in accordance with the Customer's expressed will for the purpose of fulfilling the Newsletter service agreement.
The Customer may contact the Administrator directly at any time by sending an appropriate message in writing or by e-mail to the Administrator's address indicated at the beginning of the Policy.
The Administrator stores correspondence with the Customer for statistical purposes and for the best and fastest response to emerging inquiries, as well as for resolving complaints and any decisions on administrative interventions in the indicated Account made on the basis of notifications. Addresses and data collected in this way will not be used for communication with the Customer for any purpose other than the fulfillment of the request.
When the Client contacts the Administrator to perform certain actions (e.g., submit a complaint), the Administrator may again ask the Client to provide data, including personal data, such as first name, last name, e-mail address, etc., in order to confirm the Client's identity and enable reciprocal contact in the matter. This applies to the same data, including personal data, that was previously provided by the Client and for the processing of which the Client consented. Providing this data is not mandatory but may be necessary to perform actions or obtain information that interests the Client.
- Security
The Administrator applies technical and organizational measures ensuring the protection of processed Personal Data appropriate to the threats and categories of data covered by protection, and in particular secures data against unauthorized access, unauthorized acquisition, processing in violation of applicable regulations, and alteration, loss, damage or destruction, such as, among others:
- securing the data set against unauthorized access,
- SSL certificate on the Shop's pages where Client data is provided.
- Final Provisions
The Administrator reserves the right to change the Policy in the future – this may occur, among other reasons, for the following important reasons:
- changes in applicable law, in particular regarding the protection of Personal Data, telecommunications law, electronic services, and consumer rights, affecting the rights and obligations or the rights and obligations of the Client;
6
- development of functionalities or electronic services dictated by advances in internet technology, including the use/implementation of new technological or technical solutions, affecting the scope of the Policy.
The Administrator will always post information about changes to the Policy on the Shop's website. With each change, a new version of the Policy will appear with a new date.
In case of doubts or discrepancies between the Policy and the consents given by the Client, regardless of the provisions of the Policy, the basis for the Administrator's actions and the determination of their scope will always be the consents voluntarily given by the Client or legal provisions. This document is, however, general in nature, for informational purposes only (it is not a contract or regulations).
This version of the Policy is effective from: October 22, 2018.
The Shop may contain links to other websites. The Administrator encourages users to familiarize themselves with the privacy policy established there after navigating to other websites. This Policy applies only to the specified activities of the Administrator.