Privacy policy
Privacy Policy of the ZbylutGaleria Store
https://sklep.zbylutgaleria.pl
("Store")
Dear User!
We care about your privacy and want you to feel comfortable when using our services. Below we present the most important information about the rules for processing your personal data and the cookies used by our Store. These details have been prepared with the GDPR (General Data Protection Regulation) in mind.
PERSONAL DATA ADMINISTRATOR
BOGUSŁAW JAN ŻUREK, an entrepreneur conducting business under the name BOGUSŁAW ŻUREK IT&MORE, entered into the Central Register and Information on Economic Activity (CEIDG) kept by the minister competent for the economy, NIP 5861514453, REGON 147385463, ul. Zgrupowania AK "Żmija" 13A/5, 01-875 Warszawa.
If you want to contact us about the processing of your personal data, please email: sklep@zbylutgaleria.pl.
YOUR RIGHTS
- You have the right to request:
- access to your personal data, including obtaining a copy of your data (Art. 15 GDPR or—if applicable—Art. 13(1)(f) GDPR);
- rectification of the data (Art. 16 GDPR);
- erasure (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability to another controller (Art. 20 GDPR).
- You also have the right:
- to object at any time, for reasons related to your particular situation, to the processing of your personal data based on Art. 6(1)(f) GDPR (i.e. our legitimate interests), including profiling (Art. 21(1) GDPR);
- to object if personal data are processed for direct marketing purposes, including profiling to the extent that the processing is related to such direct marketing (Art. 21(2) GDPR).
Contact us if you want to exercise your rights. You can express your objection to our use of cookies (described below) in particular by using the appropriate settings of your browser.
If you believe that your data are processed unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (UODO).
PERSONAL DATA AND PRIVACY
Below you will find detailed information about how we process your data depending on what actions you take.
1. Placing an order in the Store
- For what purpose?
- to fulfil your order
- On what legal basis?
- sales contract or contract for the supply of digital content (Art. 6(1)(b) GDPR)
- legal obligation related to accounting requiring us to process your personal data (Art. 6(1)(c) GDPR)
- For how long?
- for the duration of the above contract
- until the expiration of our legal obligation related to accounting
- in addition, your data will be processed until the end of the limitation period in which claims may be pursued—by you or by us
- What happens if you do not provide the data?
- you will not be able to place an order
2. Creating an account in the Store
- For what purpose?
- to perform the contract for the provision of the account service in the Store
- On what legal basis?
- contract for the provision of services (Art. 6(1)(b) GDPR)
- For how long?
- for the duration of the above contract
- in addition, your data will be processed until the end of the limitation period in which claims may be pursued—by you or by us
- What happens if you do not provide the data?
- you will not be able to create an account or use its features such as viewing order history or checking order status
3. Contacting us (e.g. to ask a question)
- For what purpose?
- to handle your inquiries or submissions
- On what legal basis?
- contract or actions at your request aimed at concluding it (Art. 6(1)(b) GDPR) — if your inquiry or submission concerns a contract to which we are or may be a party
- our legitimate interest consisting in processing your data for the purpose of communicating with you (Art. 6(1)(f) GDPR) — if your inquiry or submission is not related to a contract
- For how long?
- for the duration of the contract binding us, or—if the contract is not concluded—until the end of the limitation period for claims
- until the end of the limitation period for claims, or until we accept your objection to processing
- What happens if you do not provide the data?
- we will be unable to respond to your inquiry or submission
4. Browser settings or a similar action allowing marketing activities
- For what purpose?
- direct marketing consisting of displaying personalised ads (see the “Profiling” and “Cookies” sections of this Privacy Policy for more details)
- On what legal basis?
- our legitimate interest consisting in processing data for the above purpose (Art. 6(1)(f) GDPR)
- For how long?
- until the expiry or deletion by you of cookies used for marketing purposes
- What happens if you do not provide the data?
- you will not receive suggestions of products or services you may be interested in
5. Browser settings or a similar action allowing analytical activities
- For what purpose?
- analysis of how you use and navigate the Store website in order to improve its functionality (see the “Analytical activities” and “Cookies” sections for more details)
- On what legal basis?
- our legitimate interest consisting in processing data for the above purpose (Art. 6(1)(f) GDPR)
- For how long?
- until the expiry or deletion by you of cookies used for analytical purposes
- What happens if you do not provide the data?
- we will not take into account how you use and navigate our Store when working on its development
6. Your consent to receive marketing content from us (e.g. information about special offers)
- For what purpose?
- sending marketing information, especially special offers
- analysing the effectiveness of messages we send in order to establish general principles for effective mailouts in our business (see the “Analytical activities” section)
- On what legal basis?
- your consent to our marketing activities (Art. 6(1)(a) GDPR)
- our legitimate interest consisting in processing data for the above purpose (Art. 6(1)(f) GDPR)
- For how long?
- until you withdraw your consent—remember, you can withdraw it at any time. Processing that took place before withdrawal remains lawful.
- until we accept your objection to processing
- in addition, your data will be processed until the end of the limitation period in which claims may be pursued—by you or by us
- What happens if you do not provide the data?
- you will not receive our marketing materials, including information about our special offers
7. Signing up for the newsletter
- For what purpose?
- sending the newsletter
- analysing the effectiveness of the content we send to establish general principles for effective mailouts in our business (see the “Analytical activities” section)
- On what legal basis?
- contract for the provision of the newsletter service (Art. 6(1)(b) GDPR)
- our legitimate interest consisting in processing data for the above purpose (Art. 6(1)(f) GDPR)
- For how long?
- until you unsubscribe from our newsletter
- until we accept your objection to processing
- in addition, your data will be processed until the end of the limitation period in which claims may be pursued—by you or by us
- What happens if you do not provide the data?
- you will not be able to receive information concerning the Store and our services
8. Taking an action or omission that may give rise to claims related to the Store or our services
- For what purpose?
- establishing, exercising or defending possible claims related to the concluded contract or services provided
- On what legal basis?
- our legitimate interest consisting in processing personal data for the above purpose (Art. 6(1)(f) GDPR)
- For how long?
- until the end of the limitation period for claims, or until we accept your objection to processing
- What happens if you do not provide the data?
- we may be unable to establish, pursue or defend claims
PROFILING
Within the Store we carry out profiling—this will apply to you if you allow such activities. Profiling consists of the automated assessment of which products or services you may be interested in, using information about the content you view. Thanks to this, advertisements for products or services displayed within the online services you use will be better tailored to you and your needs.
The profiling we perform does not result in decisions that produce legal effects concerning you or similarly significantly affect you.
ANALYTICAL ACTIVITIES
On the Store website we conduct analytical activities aimed at increasing its intuitiveness and accessibility—this will apply to you if you allow such activities. As part of the analysis, we will consider the way you navigate the Store—for example, how much time you spend on a given subpage or where you click. Thanks to this, while working on the Store’s development, we can optimise its layout, appearance and content to improve its functionality.
Additionally, if you express your wish to receive marketing messages or the newsletter from us, we may analyse the effectiveness of our mailouts. For example, we may check whether and how they affected activity in our Store. Such actions help us establish general rules for sending such messages in our business—e.g. optimal sending times or how to formulate effective content.
DATA SECURITY
When processing your personal data we apply organisational and technical measures in accordance with applicable law, including encrypting the connection using an SSL/TLS certificate.
COOKIES
Like most websites, our Store uses so‑called cookies. These files:
- are stored in the memory of your device (computer, phone, etc.);
- do not cause changes to your device’s settings.
In this Store cookies are used for:
- remembering your session;
- statistical purposes;
- marketing purposes;
- providing Store features.
To learn how to manage cookies, including how to disable them in your browser, please use your browser’s help file. You can do this by pressing the F1 key in your browser. You will also find appropriate guidance at the following pages, depending on the browser you use:
- Google Chrome
- Opera
- Safari
- Mozilla Firefox
- Microsoft Edge
Cookies will not be processed by us for longer than 15 minutes from your last visit to the Store.
Using the appropriate options of your browser, you can at any time:
- delete cookies;
- block the use of cookies in the future.
In such cases, we will no longer process them.
EXTERNAL SERVICES / DATA RECIPIENTS
We use external entities that support us in running our business. We entrust them with processing your data—these entities process the data solely on our documented instructions.
Below you will find a list of recipients of your data:
|
ACTION |
DATA RECIPIENTS |
TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION |
|
any activity related to the Store |
hosting provider |
does not take place |
|
any activity related to the Store |
IT/technical support provider |
does not take place |
|
any activity related to the Store |
persons cooperating with us under civil‑law contracts, supporting our ongoing operations |
does not take place |
|
any activity related to the Store |
sales software provider (e.g. Enzo Sp. z o.o.) |
does not take place |
|
browsing the Store website with settings allowing marketing activities |
marketing services provider |
does not take place |
|
browsing the Store website with settings allowing analytical activities |
analytics provider |
does not take place |
|
placing an order in the Store |
payment provider |
does not take place |
|
placing an order in the Store |
entity delivering the product to you—unless you chose personal pickup |
does not take place |
|
placing an order in the Store / contacting us |
standard office software provider (including email account) |
does not take place |
|
subscribing to the newsletter or consenting to receive marketing messages |
newsletter or marketing messaging provider |
does not take place |
Additionally: the relevant public authorities insofar as we are obliged to disclose data to them.