PERSONAL DATA PRIVACY POLICY (RODO)

www.velesnails.co.uk

Effective from: 1 September 2024

§1

Identity of the data controller

  1. The administrator of the personal data provided during the use of the Website and/or the Online Shop operated under the name www.velesnails.pl is the company:Hanna Poddubnykh, address: ul.Retoryka 24 loc.II, 31-107 Kraków, contact details: biuro@velesnails.ua, also, registration details: NIP 9452290610 , REGON 528406390.
  2. Data shall be processed in accordance with the currently applicable legislation; i.e. Regulation 2016/679 of the European Parliament and of the Council of the EU of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (hereinafter: RODO), the Data Protection Act of 10 May 2018, as well as the Act of 18 July 2002 on the provision of electronic services.
  3. The following Privacy Policy covers the rules for the processing of the data of the Users of the Site, as well as of persons entering into contracts with the Data Controller, including those related to the fulfilment of an Order in the Online Shop, as well as data collected through contact with the Data Controller (e-mail address or telephone) or traditional correspondence, as well as of persons who like and/or observe the Data Controller's fanpage on social media, if it operates.

§2

Definitions used

  1. The following definitions apply in this policy:
  1. Service/shop - internet service available at www.velesnails.pl through which the User can: [delete those not applicable to you] browse its contents (blog, online shop), contact the data controller (telephone, e-mail), place orders for products and goods (online shop), order commercial and marketing information (newsletter), make an appointment for a consultation or visit (online enrolment).
  2. Personal data controller - the entity which decides the purpose and means of the data processing, in this policy it is understood to be: the company Hanna Poddubnykh, ul.Retoryka 24 loc.II, 31-107 Krakow
  3. User - the natural person to whom the data relates who uses the services available on the Website/Store.
  4. Personal data - any information that, without unreasonable time and cost, can lead to the identification of an individual, including their identification, address and contact details.
  5. Third countries - countries outside the European Economic Area (EEA).

§3

Purposes of data processing personal

  1. The Personal Data Controller shall only process personal data where this is permitted by current legislation, including for the purpose of:
  1. the preparation and performance of the concluded sales contract, including the conclusion of a distance contract through an online shop to which the person is a party, as well as the exercise of the rights arising therefrom, and this processing takes place on the basis of Article 6(1)(b) of the RODO,
  2. to document the performance of contracts, including the issuing of a bill or invoice to an individual, the keeping of accounting and tax records, on the basis of Article 6(1)(c) RODO, i.e. for the purpose of fulfilling legal obligations incumbent on the Personal Data Administrator, on the basis of Article 70 of the Tax Ordinance Act of 29 August 1997,
  3. to take action at the request of the data subject, including to respond to enquiries made by means of electronic communication or to handle traditional correspondence, and this processing is based on Article 6(1)(b) of the DPA,
  4. to send requested marketing information by electronic means (newsletter) to the email address provided by the User for this purpose, and this processing takes place on the basis of Article 6(1)(a) RODO, i.e. the consent of the data subject,
  5. registration and setting up of an Account in the Store, and this processing takes place on the basis of Article 6(1)(a) RODO, i.e. the consent of the data subject,
  6. marketing of the Controller's own products and services by traditional means, on the basis of Article 6(1)(f) RODO, i.e. for the legitimate interests of the Controller or the data subject,
  1. for the purpose of sending an email requesting an assessment of the Shop and/or the Goods/Product is carried out on the basis of Article 6(1)(f) RODO, and this processing is carried out for the legitimate purpose of the data controller (Seller), which is to improve the offer and/or the Goods/Product and/or the Shop by collecting reliable opinions about them by the Shop owner,
  2. to send a request for feedback on the Data Controller's services and goods/products through external satisfaction survey services such as [e.g. Opineo, Ceneo, etc.,.] with the data subject's consent, i.e. on the basis of Article 6(1)(a) of the RODO, [note: the sending of a request for feedback directly by a vendor/company owner to a customer takes place on a different basis than the customer's use of satisfaction survey services].
  3. the assertion of rights and claims by the Controller or the data subject on the basis of Article 6(1)(f) of the RODO and is done for a legitimate purpose.
  4. The provision of personal data is necessary for the performance of a distance contract, including the dispatch of goods or the provision of a digital product and the issuing of an accounting document, the assertion of claims and the answering of questions. Otherwise, the provision of personal data is voluntary.
  5. Failure to provide the required data makes it impossible to fulfil a distance contract, to issue a bill or invoice or to make contact at the request of the data subject.

§4

Means of data extraction

  1. User personal data is collected directly from data subjects, i.e. through:
  1. filling in your contact details when submitting an enquiry via the form on the website,
  2. filling in the newsletter subscription form,
  3. filling in the order form in the shop-online,
  4. registration of an account on the Website,
  5. the provision of data for the preparation and conclusion of the contract,
  6. direct contact with the data controller using the contact details available on the website or in traditional form at the place of business.

§5

Scope of data processing

  1. The extent of the personal data processed has been limited to the minimum necessary for the provision of services in terms of: [delete those that are not present in your case, complete the data you collect bearing in mind the principle of data minimisation].
  2. submit an enquiry via the contact form or by using the contact details available on the website: e-mail address telephone number, e-mail address, first name, any other data provided voluntarily by the data subject,
  1. to subscribe to the newsletter: name, e-mail address,
  2. placing an order in the online shop: your name, e-mail address, telephone number, delivery address and, if applicable, the address of the collection point,
  3. registration of an account on the Website or online shop: name and surname, e-mail address, password, login,
  4. to issue the bill or invoice: name and surname or name of the entity, registered office address, Tax Identification Number,
  5. preparation and conclusion of the contract: name, address, identity card number, etc.

§6

Period of data processing

  1. The processing period depends on the purpose for which the data were collected and is for the purpose:
  1. concluding and performing a sales agreement, including distance sales - for the period necessary to document the agreement performed, including issuing a bill or invoice - 5 years, counting from the end of the calendar year in which the tax deadline expired, pursuant to Article 112 of the Act of 11 March 2004 on tax on goods and services, in connection with Article 70 of the Act of 29 August 1997. - Tax Ordinance,
  2. for the purpose of sending commercial information by electronic means (newsletter) and/or for the setting up of an Account in the Shop/submission of a request for opinion by external satisfaction survey services - until the consent is revoked, without affecting the compatibility of the processing carried out prior to revocation,
  3. for the period necessary to answer a question asked via a contact form or by telephone, but for no longer than 6 months, unless the person decides to conclude a contract with the Data Controller,
  4. for the purpose of asserting claims, pursuant to the Act under Article 118 of the Act of 23 April 1964. - Civil Code. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to the conduct of business activity - three years.

§7

Recipients of data

  1. Your personal data may be entrusted to other entities for the purpose of performing services on behalf of the data controller, in particular to entities within the scope of: [delete those not applicable to you].
  1. website hosting,
  2. the servicing and maintenance of the IT systems in which the data are processed, including for newsletter automation, invoicing, order processing, etc,
  1. Your personal data may also be shared with entities that support the data controller, including those providing [delete those not applicable to you] courier and postal services, online payment processing.
  2. Your personal data is not transferred to third countries or international organisations.

§8

Controller's social media fanpage

  1. The data controller is also at the same time the co-controllers of the data of its observers in social media - especially those who use electronic means of communication on the fanpage - Facebook - #Velesnails.co.uk and Instagram under the account name @Velesnails.co.ukmaintained by the Data Controller on these social networks.
  1. For the rest, the controller of the data of the users of these social networks is Meta Platforms, Inc, (formerly: Facebook Inc., headquartered at 1 Hacker Way, Menlo Park, CA 94025, USA), and the processing of this data is carried out in accordance with the terms and conditions described in the rules and privacy policies of the users of these websites, including: https://www.facebook.com/privacy
  2. Personal data of the User who likes and/or follows the Administrator's fanpage on social media will be processed outside the European Economic Area in a so-called third country, in particular in the United States of America due to the use of IT solutions whose servers are located outside the European Economic Area.
  3. Your personal data will be processed in a third country, i.e. the United States of America (USA). The transfer of data to the USA takes place on the basis of a decision of the European Commission dated 10 July 2023 stating an adequate level of protection of personal data provided by the so-called "EU-US Data Privacy Framework" in relation to providers listed by the US Department of Commerce, such as: Meta Platforms, Inc., Menlo Park,California, USA.

§9

Rights of data subjects

  1. Data subjects are entitled to:
  • access to the content of personal data, including receiving a first copy of the content of personal data free of charge,
  • to rectify data,
  • the right to erasure, unless there are other legal provisions in force which oblige the data controller to archive the data for a specific period of time,
  • the right to data portability, insofar as the processing is based on a contract or on the consent of the data subject and the processing is carried out by automated means,
  • to withdraw consent to the processing of personal data - where the processing was based on the consent of the data subject. The revocation of consent does not affect the compatibility of the processing carried out before its withdrawal,
  • to object to the processing - on grounds relating to your particular situation against the processing of personal data concerning you based on Article 6(1)(e) or (f) of the RODO, as well as the right to restrict processing,
  • the right not to be subject to automated profiling, where the controller would make decisions based solely on automated profiling with legal consequences for or similarly affecting the data subject,
  • the right to control the processing of the data and to be informed of who the controller is and to be informed of the purpose, scope and means of the processing, the content of the data, the source of the data, and the manner of disclosure, including the recipients or categories of recipients of the data,
  1. In order to exercise your right to information, access to the content of your data, correction of your data, as well as other rights, you can contact the Data Controller.
  2. The data subject also has the right to lodge a complaint with the Data Protection Authority (DPA) if the processing of data violates the provisions of the General Data Protection Regulation (GDPR). The complaint may be lodged electronically or by post to: Office for Personal Data Protection, 2 Stawki Street, 00-193 Warsaw.

§10

Final provisions

In the event that the applicable privacy policy changes, in particular if the technical solutions used or changes to the law in the area of data subjects' privacy so require, appropriate modifications to this Privacy Policy will be made, which will be effective within 14 days of their publication on the Website/Shop.