Privacy Policy
§ 1 General Provisions
-
This Privacy Policy outlines the rules for processing personal data collected via the website www.inventia.sklep.pl (hereinafter referred to as the "Online Store").
-
The data administrator is the online store Inventia Sklep, operated by INVENTIA TECHNOLOGIES SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, located at ul. Leśna 11, 83-041 Żuławka, registered in the National Court Register by the District Court Gdańsk-Północ, VII Commercial Division of the National Court Register under the number KRS 0000983002, NIP: 6040232180, REGON: 522624156.
-
Personal data collected by INVENTIA TECHNOLOGIES SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ through the online store Inventia Sklep (hereinafter referred to as the "Administrator") is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as "GDPR".
-
The Administrator ensures special care for the privacy of Users visiting the Online Store.
§ 2 Type and Purpose of Data Processing
-
The Administrator collects information about natural persons conducting business or professional activity on their own behalf and natural persons representing legal entities or organizational units that are not legal entities, but to which the law grants legal capacity, collectively referred to as "Users".
-
Personal data of Users is collected in the following cases: a) Registration of an account in the Online Store to create an individual account and manage that account. Legal basis: necessity to perform the contract for the provision of Account services. b) Placing an order in the Online Store to execute the contract. Legal basis: necessity to perform the contract for the provision of services.
-
During the account registration in the Online Store, the User provides: a) Email address, b) Address details, c) First and last name, d) Phone number.
-
For Entrepreneurs, the above scope of data is additionally extended to include the Entrepreneur's company name and VAT identification number (NIP).
-
During the registration of an account in the Online Store, the User sets an individual password to access their account. The User can change the password later.
-
When placing an order in the Online Store, the User provides the following data: a) Email address, b) Address details, c) First and last name, d) Phone number, e) Data necessary for shipping, varying depending on the chosen delivery method.
-
For Entrepreneurs, the above scope of data is additionally extended to include the Entrepreneur's company name and VAT identification number (NIP).
-
Providing personal data to the Store is voluntary but necessary for the conclusion and execution of the sales contract. However, failure to provide certain data specified in the forms will prevent the User from placing and processing an order.
§ 3 Selected Data Protection Methods Used by the Administrator
-
Places for logging in and entering personal data are protected at the transmission layer (SSL certificate). This ensures that personal and login data entered on the website are encrypted on the User's computer and can only be read on the target server.
-
The operator periodically changes its administrative passwords.
-
To protect data, the Operator regularly performs security backups.
-
An important element of data protection is the regular updating of all software used by the Operator to process personal data, which includes regular updates of programming components.
§ 4 Data Sharing and Entrustment
-
User personal data is transferred to service providers used by the Administrator in operating the Online Store. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, are either subject to the Administrator's instructions regarding the purposes and methods of data processing (processors) or determine the purposes and methods of processing data themselves (controllers).
a) Processors: The Administrator uses service providers who process personal data only at the Administrator's request. These include providers of hosting services, accounting services, marketing systems, web traffic analysis systems, and marketing campaign effectiveness analysis systems.
b) Controllers: The Administrator uses service providers who do not act solely on the Administrator's instructions and determine the purposes and methods of using Users' personal data themselves. They provide electronic payment services and banking services.
-
Users' personal data is stored: a) When the basis for data processing is the User's consent, personal data is processed by the Administrator until the consent is withdrawn, and after the consent is withdrawn, for a period corresponding to the statute of limitations for claims that the Administrator may assert and that may be asserted against him. If a specific provision does not state otherwise, the limitation period is six years, and for periodic performance claims and claims related to business activity, it is three years.
b) When the basis for data processing is the execution of a contract, personal data is processed by the Administrator as long as it is necessary to execute the contract, and after that, for a period corresponding to the statute of limitations for claims. If a specific provision does not state otherwise, the limitation period is six years, and for periodic performance claims and claims related to business activity, it is three years.
-
Upon request, the Administrator provides personal data to authorized state authorities, in particular organizational units of the Prosecutor's Office, the Police, the President of the Office for Personal Data Protection, the President of the Office for Competition and Consumer Protection, or the President of the Office of Electronic Communications.
§ 5 Rights of Data Subjects
-
Right to withdraw consent: a) The User has the right to withdraw any consent given to the Administrator. b) Withdrawal of consent takes effect from the moment the consent is withdrawn. c) Withdrawal of consent does not affect the processing carried out by the Administrator in accordance with the law before its withdrawal. d) Withdrawal of consent does not have any negative consequences for the User but may prevent further use of services or functionalities that the Administrator can legally provide only with consent.
-
Right to object to data processing: a) The User has the right to object at any time – for reasons related to their particular situation – to the processing of their personal data, including profiling, if the Administrator processes their data based on a legitimate interest, usage statistics of particular functionalities of the Online Store, and facilitation of using the Online Store, as well as satisfaction surveys. b) Opting out via email from receiving marketing communications about products or services will mean the User objects to the processing of their personal data, including profiling for these purposes. c) If the User's objection is justified and the Administrator has no other legal basis for processing personal data, the User's personal data will be deleted against the processing of which the User objected.
-
Right to data deletion: a) The User has the right to request the deletion of all or some of their personal data. b) The User has the right to request the deletion of personal data if:
- The personal data is no longer necessary for the purposes for which it was collected or processed,
- The User has withdrawn specific consent to the extent that personal data was processed based on this consent,
- The User has objected to the use of their data for marketing purposes,
- The personal data is processed unlawfully,
- The personal data must be deleted to comply with a legal obligation under the law of the European Union or the law of a Member State to which the Administrator is subject.
c) Despite the request for deletion of personal data due to objection or withdrawal of consent, the Administrator may retain certain personal data to the extent that processing is necessary to establish, pursue, or defend claims, as well as to comply with a legal obligation requiring processing under the law of the European Union or the law of a Member State to which the Administrator is subject. This particularly applies to personal data including the User's name, email address, and data retained for handling complaints and claims related to the use of the services of the Online Store.
-
Right to restrict data processing: a) The User has the right to request the restriction of the processing of their personal data. Submitting a request prevents the use of specific functionalities or services involving the processing of the data covered by the request. The Administrator will not send any communications, including marketing communications. b) The User has the right to request the restriction of the use of personal data in the following cases:
- When the accuracy of the personal data is disputed by the User – in such a case, the Administrator limits its use for the time necessary to verify the accuracy of the data, no longer than 7 days,
- When the processing is unlawful, and the User opposes the deletion of personal data and requests the restriction of its use instead,
- When personal data is no longer necessary for the purposes for which it was collected or used, but it is necessary for the User to establish, pursue, or defend claims,
- When the User has objected to the use of their data – the restriction is effective for the time necessary to determine whether the protection of the User's interests, rights, and freedoms prevails over the interests pursued by the Administrator in processing the User's personal data.
-
Right to access data: a) The User has the right to obtain confirmation from the Administrator as to whether their personal data is being processed, and if so, the User has the right to:
- Access their personal data,
- Obtain information about the purposes of processing, categories of personal data being processed, recipients or categories of recipients of the data, the planned period of storing the User's data, or the criteria for determining this period (when determining the planned period of data processing is not possible), the User's rights under GDPR, and the right to lodge a complaint with a supervisory authority, the source of this data, the automated decision-making, including profiling, and the safeguards applied in connection with the transfer of these data outside the European Union,
- Obtain a copy of their personal data.
-
Right to data portability: a) The User has the right to receive their personal data that they provided to the Administrator and then send it to another personal data administrator of their choice. The User also has the right to request that their personal data be sent by the Administrator directly to such an administrator if it is technically possible. In this case, the Administrator sends the User's personal data in a structured, commonly used, machine-readable format that allows the received data to be used by another administrator. This right applies only to data processed based on the agreement with the User or the User's consent.
§ 6
Additional Information on the Use of Data
-
In certain situations, the Administrator has the right to transfer your personal data to other recipients if it is necessary to perform the contract concluded with you or to fulfill the obligations of the Administrator. This concerns the following groups of recipients:
a) Postal operators
b) Couriers
c) Hosting companies on an entrusted basis
d) Payment operators
e) Public authorities
f) Operators of comment and review systems
g) Authorized employees and collaborators who use the data to achieve the purposes of the website.
§ 7
Additional Use of Personal Data
-
The website additionally uses personal data for the following purposes:
a) Managing the comment and review system
b) Handling inquiries through the form
c) Preparing, packing, and shipping goods
d) Providing ordered services
e) Debt collection
f) Presenting offers or information
g) Running a newsletter
-
The website gathers information about users and their behavior in the following ways:
a) Through data voluntarily entered in forms, which are entered into the Operator's systems.
b) By saving cookies on end devices.
§ 8
Security Management
-
The Administrator ensures that Users have a secure and encrypted connection when transmitting personal data and when logging into the User Account on the website.
-
The Administrator uses an SSL certificate issued by one of the leading global companies in the field of internet security and data encryption.
-
If a User with an account on the website www.inventia.sklep.pl loses their access password in any way, the website allows for the generation of a new password. The Administrator does not send password reminders. The password is stored in an encrypted form, making it impossible to read. To generate a new password, the User must provide their email address in the form available via the "Forgot your password" link provided on the login form on the website. The User will receive an email at the address provided during registration or the last profile update containing a link to a dedicated form on the website, where the User can set a new password.
-
The Administrator does not send any correspondence, including electronic correspondence, requesting login details, especially the User Account access password.
§ 9
Consent to the Processing of Personal Data
- The User consents to the processing of personal data by INVENTIA TECHNOLOGIES SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ for the purposes of direct marketing of its own products and services. Data for this purpose will be processed based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR).