1. GENERAL PROVISIONS

  1. The controller of personal data collected via the website akcesoria-plandekowe.pl is a business under the name Autotrans Piotr Jamski, with its registered office address: ul. Słoneczna 20/42, 27-200 Starachowice, Tax Identification Number (NIP): 6641084620, entered into the Central Registration and Information on Business, hereinafter referred to as the "Controller," who is also the Service Provider. Place of business: ul. Lipie-Henryk Szyb 1C, Lipie 27-230 Brody, service address: ul. Lipie-Henryk Szyb 1C, Lipie 27-230 Brody, e-mail address: sklep@akcesoria-plandekowe.pl.
  2. Personal data collected by the Administrator via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR, and the Personal Data Protection Act of 10 May 2018.

2. TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION

  1. The Administrator processes personal data via the akcesoria-plandekowe.pl website in the following cases:
    • the user uses the contact form. Personal data are processed pursuant to Article 6(1)(f) of the GDPR as the Controller's legitimate interest.
    • the user signs up for the Newsletter to receive commercial information electronically. Personal data are processed after expressing separate consent pursuant to Article 6(1)(f) of the GDPR. 1 letter a) of the GDPR.
    • Registering in the akcesoria-plandekowe.pl online store using the registration form. Personal data are processed pursuant to Article 6 paragraph 1 letter f) of the GDPR as a legitimate interest of the Controller.
    • Making a purchase as a guest without registering and providing the data necessary to complete the order. Personal data are processed pursuant to Article 6 paragraph 1 letter f) of the GDPR as a legitimate interest of the Controller.
  2. The Administrator processes the following categories of user personal data:
    • Company name,
    • First name and last name,
    • Date of birth,
    • Address (residence),
    • Email address,
    • Telephone number,
    • Taxpayer's Identification Number (NIP)

3. PERSONAL DATA ARCHIVING PERIOD

  1. Users' personal data are stored by the Administrator:
    • If the basis for data processing is the performance of a contract, for as long as necessary to perform the contract, and thereafter for a period corresponding to the limitation period for claims. Unless a specific provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business, three years.
    • If the basis for data processing is consent, for as long as consent is not revoked, and after revocation of consent, for a period corresponding to the limitation period for claims that the Controller may raise and that may be brought against it. Unless a specific provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business, three years.
  2. When using the website, additional information may be collected, in particular: the IP address assigned to the user's computer or the external IP address of the internet service provider, domain name, browser type, access time, and operating system type.
  3. Navigational data may also be collected from users, including information about the links and hyperlinks they choose to click or other actions they take on the website. The legal basis for this activity is the Controller's legitimate interest (Article 6, Section 1, Letter f of the GDPR), which consists in facilitating the use of services provided electronically and improving the functionality of these services.
  4. Providing personal data by the user is voluntary.
  5. Personal data will also be processed in an automated manner in the form of profiling, provided the user consents pursuant to Article 6, Section 1, Letter a of the GDPR. Profiling will result in assigning a profile to a given individual for the purpose of making decisions about them or analysing or predicting their preferences, behaviours, and attitudes.
  6. The Administrator exercises due diligence to protect the interests of data subjects, and in particular ensures that the data it collects are:
    • processed lawfully, collected for specified,
    • lawful purposes and not further processed incompatible with those purposes,
    • substantively accurate and adequate in relation to the purposes for which they are processed, and stored in a form that permits the identification of data subjects for no longer than is necessary to achieve the purpose of processing.

4. DISCLOSURE OF PERSONAL DATA

  1. Users' personal data is transferred to service providers used by the Administrator to operate the website. Depending on contractual arrangements and circumstances, the service providers to whom personal data is transferred are either subject to the Administrator's instructions regarding the purposes and methods of processing such data (processors) or independently determine the purposes and methods of processing (controllers).
  2. Users' personal data is stored exclusively within the European Economic Area (EEA).

5. RIGHT OF CONTROL, ACCESS, AND CORRECTION OF PERSONAL DATA

  1. The data subject has the right to access their personal data and the right to rectify, erase, restrict processing, transfer, object, and withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
    • Legal basis for the user's request:
    • Access to data – Article 15 of the GDPR
    • Rectification of data – Article 16 of the GDPR
    • Deletion of data (so-called right to be forgotten) – Article 17 of the GDPR
    • Restriction of processing – Article 18 of the GDPR
    • Data portability – Article 20 of the GDPR
    • Objection – Article 21 of the GDPR
    • Withdrawal of consent – ​​Article 7(3) of the GDPR
  2. To exercise the rights referred to in point 2, you can send an appropriate email to: sklep@akcesoria-plandekowe.pl.
  3. If a user asserts the rights arising from the above rights, the Administrator will either comply with the request or refuse to comply with it immediately, but no later than one month after receiving it. However, if – due to the complex nature of the request or the number of requests – the Administrator is unable to comply within one month, the Administrator will comply within the next two months, informing the user within one month of receiving the request of the intended extension and the reasons for it.
  4. If it is determined that the processing of personal data violates the provisions of the GDPR, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office.

6. COOKIES

  1. The Administrator's website uses cookies.
  2. The installation of cookies is necessary for the proper provision of services on the website. Cookies contain information necessary for the proper functioning of the website and also enable the development of general website visitor statistics.
  3. The website uses session and persistent cookies:
    • Session cookies are temporary files that are stored on the user's end device until they log out (leave the website).
    • Persistent cookies are stored on the user's end device for the time specified in the cookie parameters or until they are deleted by the user.
  4. The Administrator uses its own cookies to better understand how users interact with the website's content. These cookies collect information about how users use the website, the type of website from which the user was redirected, and the number and duration of the user's visits to the website. This information does not record specific personal data of the user but is used to compile website usage statistics. The user has the right to control the access of cookies to their computer by selecting them in their browser window. Detailed information about the possibilities and ways of handling cookies is available in the software (web browser) settings.

7. FINAL PROVISIONS

  1. The Administrator employs technical and organizational measures to ensure the protection of processed personal data appropriate to the threats and categories of data being protected. In particular, the Administrator protects data against unauthorized access, unauthorized removal, processing in violation of applicable regulations, and alteration, loss, damage, or destruction.
  2. The Administrator provides appropriate technical measures to prevent unauthorized access and modification of personal data transmitted electronically.
  3. In matters not covered by this privacy policy, the provisions of the GDPR and other relevant provisions of Polish law shall apply accordingly.