PRIVACY POLICY
Privacy Policy
§ 1 Definitions.
All capitalized terms/phrases herein shall have the meaning set forth in the Store`s Terms of Use available at https://seboradin.pl/en/regulamin unless otherwise indicated below.
1) Data Controller – the controller of personal data within the meaning of Article 4(7) of the RODO, which herein is the Seller.
2) Cookie – a small piece of information stored by the server on the User`s computer, which can be read by the server when the User reconnects from that computer.
3) Personal data – personal data concerning Users collected witihin the use of the Store/Newsletter/ in connection with the Seller`s activities conducted through the Store.
4) Google LLC – Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
5) Google Ireland – Google Ireland Limited, Gordon House, Barrow Street, Dublin, D04 E5W5, Dublin, Ireland.
6) Google – altogether Google LLC i Google Ireland.
7) Privacy Policy – this document setting out the terms and conditions for the collection, use and disclosure of Personal Data.
8) RODO – Regulation (UE) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
9) User – a customer using the Store.
§ 2 Preliminary issues.
1. Privacy policy concerns the processing and protection of Personal data ragarding Users in connection with their use of the Store/Newsletter.
2. Data Controller independently determines the purposes and means of processing Personal Data.
3. Seller informs that external links may be placed witihin the Store, allowing Users to directly access other websites, or that during the use of the Store Cookies from the other entites may additionally be placed in Users` devices. For security reasons, the Seller recommends that, before using tge resources offered by other websites or services, each User should read the document concerning privacy policy and the use of the cookies if they have been made avaiable, and if they have not been made avaiable contact the administrator of the given website or service in order to obtain information in this regard.
§ 3 Purpose and legal basis for processing Personal Data.
Personal Data are processed on the basis of:
1) placing and processing of the Order in the Store – processing takes place on the basis of Article 6(1)(b) RODO and is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
2) answering a question via the contact form available on the website – processing takes place on the basis of Article 6(1)(b) RODO and is necessary in order to take steps at the request of the data subject prior to entering into a contract;
3) providing advice via an online chat with a Consultant - processing takes place on the basis of Article 6(1)(b) RODO and is necessary in order to take steps at the request of the data subject prior to entering into a contract;
4) setting up an Account in the Store - processing takes place on the basis of Article 6(1)(a) RODO – the data subject has given consent to the processing of his or her personal data;
5) Newsletter and related (on the basis of consent granted in accordance with Article 7(5) of the Terms and Conditions) commercial and marketing information – processing takes place on the basis of Article 6(1)(a) RODO – the data subject has given consent to the processing of his or her personal data; the Seller sends Newsletter only to persons who have confirmed their subscription and expressed their wish to receive commercial or marketing information;
6) evaluating the Products and the Store/Seller by the User – processing takes place on the basis of Article 6(1)(a) RODO – the data subject has given consent to the processing of his or her personal data; processing takes place in order to receive a survey examining the level of satisfaction with purchases; consent may also be given in order to perform evalutation on other websites, in which case, however, the User`s Personal Data are processed on the basis of a separate consent given by the User to the relevant third party;
7) marketing of the Data Controller`s own Products and services – processing takes place on the basis of Article 6(1)(f) RODO – processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data;
8) asserting and defending the rights and claims of the Data Controller, the data subject or a third – processing takes place on the basis of Article 6(1)(f) RODO – processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
§ 4 Data collection and processing.
1. The Seller in the Store collects and stores the following User data, including Personal data such as:
1) information provided by the User:
a) during the registration of the Account, placing and processing the Order and complaints concerning the Products (incl. name, surname, delivery address, other contact details);
b) by means of forms available on the website;
c) during/in connection with the provision of Advice (incl. data on health status, possible skin problems, used preparations);
2) data collected automatically by the Data Controller, which may (not necessarily) include:
a) identifiers of the devices used by Users and their parameters, such as resolution, screen size and device status e.g. a screen orientation, network connection status;
b) other unique identifiers e.g. an IP adress;
c) information about the browser used by the User;
d) information on the User`s use of the Store, including any searches the User have made.
2. Personal data are processed in the Data Controller`s ICT systems.
§ 5 Use of Data.
The data indicated in Article 4 above, including Personal Data, are processed by the Data Controller in order to provide Users possibilty to use the Store and to ensure the efficient functioning of the Store, including:
1) the execution of Orders;
2) providing Advice;
3) Newsletter (with the consent of the User);
4) providing assistance for the User;
5) analysis of the activities undertaken by Users in the Store.
§ 6 Disclosure of Personal Data.
1.The Seller shall not transfer collected Personal Data to other entities unless the obligation to do so results from generally applicable laws or when the Personal Data are needed in order to provide services for Users, for specific purposes and on the terms described below:
1) entities entrusted with the processing of Personal Data belong to category of infrastructure solutions suppliers and technical support service providers; these entities may process Personal Data in accordance with RODO in a third country; these entities may also use further entities to process Personal Data in a third country;
2) in case of transfering Personal Data outside the European Economic Area, the Seller shall ensure that the data are transferred in accordance with the Privacy Policy and generally applicable laws; generally the Seller does not intend to transfer Personal Data outside the European Economic Area.
2. Data collected through:
1) Google Analytics (see below) are mostly transmitted by Google LLC to servers in the United States and stored there;
2) Google Ads (see below) are transmitted by Google Ireland to servers in Ireland.
§ 7 Period of processing Personal Data.
Personal Data will be processed for the period necessary to fulfilL the purposes referred to in Article 3 of the Privacy Policy.
§ 8 Rights and information concerning Users.
(1) The purpose of the RODO is to ensure that each individual has the possibility to control the processing of Personal Data concerning him or her. The User (natural person), whose Personal Data are processed by the Seller in connection with his/her use of the Store, has the right to access to his/her Personal Data and the right to rectification, erasure or restriction of processing of Personal Data – to the extent and under the conditions set out in Articles 15, 16, 17 and 18 of the RODO respectively.
(2) Right to access to Personal Data – the User (natural person) has the right to obtain information concerning i.a which of his/her Personal Data are processed, the purposes of the processing and to obtain a copy of Personal Data undergoing processing. An individual may turn to the Seller with request for information whether the Seller process Personal Data concerning him/her
(3) Right to erasure Personal Data (right to be forgotten) – the User (natural person), has the right to indicate the Seller which Personal Data should be erased and the circumstances justifying the requested erasure of Personal Data, e.g. Personal Data are no longer necessary in relation to the purposes for which they were collected and there are no overriding legitimate grounds for the processing; Personal Data have been unlawfully processed. The right to erasure of Personal Data may be exercised in cases when the Seller has no legal basis for processing.
(4) Right to data portability – the User (natural person) has the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format. A request for transffering Personal Data may be made by the User in relations to Personal Data concerning him/her. The information shall be transffered in a form of a digitial file in manner that ensures the security of its transmission.
(5) Right to restriction of processing – the User (natural person) may indicate that the prerequisites set out in Article 18 of RODO for restricting the processing of his/her Personal Data have occurred, e.g. the Seller does not need certain Personal data, there are no prerequisites for further processing, and the User (natural person) requests that operations on his/her Personal Data be stopped or not deleted.
(6) Right to rectification of Personal Data – at any time when the need arises, the User (natual person) may inform the Seller about changing his/her Personal Data. The User (natural person) has the right to request from the Seller to rectify inaccurte Personal data concerning him/her or to complete his/her incomplete Personal data.
(7) Right to object – the User (natural personal) has the right to object at any time to the procesing of Personal data concerning him in an automated manner, including profiling and also to object to processing of his/her Personal Data for marketing purposes (if any). An objection to processing of Personal Data may be lodged e.g. at the registered office of the Seller, by letter to the address of the Seller1s registered office or by e-mail to: [email protected]
(8) The User (natural person) whose Personal Data are processed by the Seller has the right to lodge a complaint to the lead supervisory authority – the President of the Office of Competition and Consumer Protection (contact- UODO), if he/she considers that the processing of his/her Personal Data violates the provisions of the RODO.
(9) In cases where consent to process Personal Data are required and the Seller obtains such consent, the User (natural person) whose Personal Data are processed by the Seller has the right to withdraw consent at any time without any negative consequences. Withdrawal of consent for the processing of Personal Data is possible only in cases where consent is the exclusive legal basis for the processing of Personal Data (e.g. it is not possible to withdraw consent for the processing of data when they are processed for the purpose of the Seller's investigation of claims related to the User's use of the Shop).
(10) All consents are given voluntarily and can always be withdrawn. The withdrawal of consent does not affect the Seller's right to process Personal Data until it is withdrawn.
(11) At any time (during the Seller's operating hours), if you wish to obtain additional information relating to the protection of your Personal Data or wish to exercise your rights, you may contact the Seller by email: [email protected]
§ 9 Safeguards.
The Seller shall apply appropriate safeguards, technological and management processes to protect Personal Data from loss, theft, unauthorised access, use or modification.
§ 10 Rules for the use of Cookies.
1. Cookies may be used by the Store to allow users to use the Store more efficiently.
2. The law states that the Seller may store cookies on the User's device if it is necessary for the functioning of the Store. For all other types of Cookies, the Store needs the User`s permission.
3. The Store uses different types of Cookies. Some cookies are placed by third party services that appear on our website (the Store).
4. The Store uses Cookies to personalize content and ads, to provide social media features, and to analyze traffic in the Store. Information about how the User uses the Store is shared by the Seller with social, advertising, and analytics partners (listed below). These partners may combine this information with other data received from the User or obtained while using their services.
5. During the first visit to the Store (understood as visiting the website), the User is shown information about the use of Cookies with the option to consent to their use for purposes specified in the consent form, including the use of advertising tools for handling remarketing campaigns. The User can also withdraw/modify their consent at any time by changing the settings in their web browser regarding the handling of Cookies, so as to adjust it to their needs, and in particular, to completely disable this handling. Browsers manage Cookie settings in different ways. The help menu in the web browser contains explanations on how to change Cookie settings. Blocking Cookies may, however, prevent the use of the Store or certain functions of it.
6. Accepting the use of Cookies by the Store for purposes specified when giving consent means consenting to the use of Cookies in accordance with the information contained in the consent form.
7. The following types of Cookies are used within the Store:
1) Necessary.
Necessary Cookies contribute to the usability of the Store by enabling basic functions such as navigation in the Store and access to secure areas of the Store. The Store cannot function properly without these Cookies.
2) Preferences.
Preference Cookies enable the Store to remember information that changes the way the Store behaves or looks, such as the preferred language or the region where the User is located.
3) Statistics.
Statistical Cookies help the Seller understand how different Users behave on the website (Store) by collecting and reporting anonymous information.
4) Marketing.
Marketing Cookies are used to track users across websites, including the Store. The purpose is to display ads that may be more relevant and interesting to individual users, including the User, and thus more valuable to third-party publishers and advertisers.
5) Conversion.
Cookies described in § 13 of the Privacy Policy.
6) Unclassified.
Unclassified Cookies are those that are in the process of being classified together with their providers (the Seller cannot classify them into any of the above categories).
8. Cookies and information obtained through them are in no way combined with Personal Data and are not used to determine the User's identity. The scope of information collected automatically depends on the settings of the User's web browser and the scope of the consent given by the User.
§ 11. Server logs.
1. Information about some User behaviors is logged at the Seller's server layer. This data is used solely for administering the Store and ensuring the most efficient service to Users. The viewed resources are identified by URL addresses. Additionally, the following data may be logged:
1) time of request arrival,
2) time of response dispatch,
3) client station name – identification performed by the HTTP protocol,
4) information about errors that occurred during the HTTP transaction,
5) URL address of the previously visited page (referer) in case the transition to the Service was made via link,
6) information about the User's browser,
7) information about the IP address.
2. The above data:
1) is not associated with specific Users;
2) is used only for server administration purposes.
§ 12. Google Analytics.
1. Google Analytics is an online tool for analyzing website statistics, which automatically collects information about the User's use of the Store. The Seller uses Google Tag Manager to manage Google Analytics.
2. The Seller has activated IP address anonymization. The User's IP address is shortened before further transmission. Only in exceptional cases is the full IP address transmitted to a Google LLC server and shortened there. The anonymized IP address transmitted by the User's browser within Google Analytics is generally not combined with other data by Google LLC.
3. The User can prevent the recording of data collected by Cookies regarding the User's use of the Store by Google, as well as the processing of this data by Google, by installing the browser plugin available at the following address: https://tools.google.com/dlpage/gaoptout
4. The User can learn more about data processing within Google Analytics (explanations provided by Google): https://support.google.com/analytics/answer/6004245
§ 13. Google Ads.
1. The Seller uses the Google Ads advertising system to create remarketing campaigns. Remarketing allows the display of ads related to the Seller's products to Users who have previously visited the Store. Users can read about how ads are displayed through the Google Ads service on the page: https://policies.google.com/technologies/ads?hl=pl
2. The Seller also uses within Google Ads the conversion tracking service. Google Ads places a conversion tracking cookie (called a conversion cookie) on the User's hard drive following each click on an ad delivered by Google. These cookies are not used to identify the user. When the User visits certain subpages of the Store, Google and the Seller can determine that the User was redirected to these pages after clicking on an ad.
3. The data obtained through the use of conversion cookies is used for statistical reporting purposes by the Seller. Such statistical data informs about the total number of users who clicked on an ad delivered by Google and opened a website containing the conversion tracking tag. However, the Seller does not receive any information that allows the identification of such Users. The Store is unable to link the received data to specific Users.
4. The User can adjust ads in the Google ad network by changing ad settings (including blocking selected ads) on the page: https://www.google.com/settings/ads.
Detailed instructions on how to do this are available at: https://support.google.com/ads/answer/2662856?hl=pl&co=GENIE.Platform%3DDesktop&oco=0.
However, even if the User disables ad personalization, they may still see ads based on their general location (based on IP address), browser type, and search terms.