Privacy policy
I. DEFINITIONS
- Administrator - a company under the name mybox Sp. z o.o., ul. Jana Henryka Dąbrowskiego 77A, 60-529 Poznań, VAT: PL7812017336, REGON: 388090732, KRS: 0000881122.
- Personal data - any information relating to an identified or identifiable natural person, in particular by reference to factors such as physical, physiological, genetic, mental, economic, cultural or social identity.
- Data Subject - a natural person to whom the Personal Data processed by the Administrator relates, in particular a User and a person who is not a User, but, for example, sends an inquiry to the Administrator by e-mail.
- Policy - this Privacy Policy.
- Regulations - Regulations of the promotional campaign.
- GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
- Website - an internet service that will be available to Users.
- Services - hosting services provided electronically by the Administrator in accordance with the Regulations.
- User - a person selected by the Administrator who will receive test access to the Website.
II. PERSONAL DATA PROCESSING
- In connection with the conducted business activity, including in particular via the Website, the Administrator collects and processes Personal Data in accordance with the applicable regulations, including in particular the GDPR, and the data processing principles provided for therein.
- Administrator:
- ensures transparency in the processing of Personal Data;
- informs about the processing of Personal Data at the time of their collection, in particular about the purpose and legal basis of the processing of Personal Data, unless it is not obliged to do so under separate provisions;
- ensures that Personal Data is collected only to the extent necessary for the indicated purpose and is processed only for the period necessary.
- When processing Personal Data, the Administrator ensures their security and confidentiality, as well as Data Subjects' access to information about their processing. If, despite the security measures in place, a Personal Data breach occurs (e.g., data leak or loss) and such a breach could pose a high risk to the rights or freedoms of Data Subjects, the Administrator will notify Data Subjects of such an event in a manner consistent with applicable regulations.
III. GENERAL RULES REGARDING PERSONAL DATA SECURITY
- Confidentiality and security of Personal Data are a priority for the Administrator.
- In order to ensure the integrity and confidentiality of Personal Data, the Administrator has implemented procedures that allow access to Personal Data only to authorized persons and only to the extent necessary for the tasks they perform.
- The Administrator uses organizational and technical solutions to ensure that all operations on Personal Data are recorded and performed only by authorized persons.
IV. PURPOSES AND LEGAL BASIS FOR PROCESSING
- USER PARTICIPATION IN TEST USE OF THE SERVICE
- In order to enable the User to test use of the Website, the Administrator collects data regarding the electronic mail address (e-mail).
- The basis for the processing of Personal Data related to the concluded contract is the necessity to perform the contract or to take action at the User's request before concluding it (Art. 6, par. 1, letter b) of the GDPR).
- ANALYTICAL, STATISTICAL AND RESEARCH PURPOSES
- The Administrator may process Personal Data of Data Subjects for analytical, statistical and research purposes, in particular by analysing Users' activity on the Website and how they use the Website, as well as their preferences in order to improve the functionalities of the Website.
- The legal basis for processing is the legitimate interest of the Administrator (Art. 6, par. 1, letter f of the GDPR).
- E-MAIL AND TRADITIONAL CORRESPONDENCE
- In the event that Data Subjects send correspondence to the Administrator via e-mail or traditional mail, the Personal Data contained in this correspondence are processed solely for the purpose of communication and resolving the matter to which the correspondence relates.
- The legal basis for processing is the legitimate interest of the Administrator (Art. 6, par. 1, letter f of the GDPR) consisting in conducting correspondence addressed to it in connection with its business activities.
- CLAIM SETTLEMENT
- In order to establish, pursue and enforce any claims arising from the manner in which the User uses the Website, the Administrator may process certain Personal Data if it is necessary to prove the existence of the Administrator's claim, including the extent of the damage suffered.
- In such a case, the legal basis is the legitimate interest of the Administrator (Art. 6, par. 1, letter f of the GDPR), consisting in the establishment, pursuit and enforcement of claims and defense against claims in proceedings before courts and other state authorities.
- EXERCISE OF DATA SUBJECTS' RIGHTS
- In order to enable the exercise of rights arising from the GDPR, in particular the possibility of submitting complaints, inquiries and requests, the Administrator has the right to process certain Personal Data for this purpose.
- In such a case, the legal basis is the legitimate interest of the Administrator (Art. 6, par. 1, letter f of the GDPR), consisting in enabling the User to exercise the rights arising from the GDPR.
V. NECESSITY TO PROVIDE PERSONAL DATA
Providing Personal Data is voluntary, but necessary to use the Website.
VI. DATA RECIPIENTS
- In connection with conducting business activities requiring the processing of Personal Data, Personal Data may be disclosed to external entities, including in particular suppliers responsible for the operation of IT systems and equipment, postal operators, couriers, providers of accounting, legal and advisory services and marketing agencies.
- The Administrator may share anonymised data (i.e. data that does not identify specific Data Subjects) with external service providers in order to better identify the attractiveness of advertisements and services offered by the Administrator.
- The Administrator reserves the right to disclose selected information concerning the User to competent authorities or third parties who submit a request for such information, based on an appropriate legal basis and in accordance with applicable law.
VII. AUTOMATIC DECISION-MAKING, INCLUDING PROFILING
No automated decision-making is used in relation to Users.
VIII. PERSONAL DATA PROCESSING PERIOD
- Except in cases that impose a different period of storage of Personal Data on the Administrator, the Administrator stores the Personal Data of Users for the period of the User's use of the System as well as for a period of 3 years after the end of use of the System.
- The period of processing of Personal Data may be extended if processing is necessary to establish, pursue or defend against claims, and after this period - only if and to the extent required by law.
- If Personal Data are processed on the basis of the Administrator 's legitimate interest, the Administrator processes such data until an effective objection to the processing of Personal Data for the above-mentioned purposes is raised.
- Where Personal Data is processed based on the consent of the Data Subject, such consent may be withdrawn at any time. Personal Data will be processed until the consent is withdrawn. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
IX. DATA SUBJECT RIGHTS
Data Subjects have the following rights:
- the right to information on the processing of personal data - on this basis, the Administrator provides the natural person submitting the request with information on the processing of Personal Data, including in particular the purposes and legal basis of processing, the scope of the data held, the entities to which they are disclosed and the planned date of data deletion.
- the right to obtain a copy of the data - on this basis, the Administrator provides a copy of the processed Personal Data relating to the natural person submitting the request.
- the right to rectification - the Administrator is obliged to remove any inconsistencies or errors in the Personal Data being processed and to supplement them if they are incomplete.
- the right to delete data - on this basis, you can request the deletion of Personal Data, the processing of which is no longer necessary to achieve any of the purposes for which they were collected.
- the right to limit processing - in the event of such a request, the Administrator ceases to perform operations on Personal Data - with the exception of operations to which the Data Subject has consented - and to store them, in accordance with the adopted retention principles or until the reasons for limiting data processing cease to exist (e.g. a decision of the supervisory authority is issued permitting further data processing).
- The right to data portability - on this basis, to the extent that Personal Data is processed by automated means in connection with a concluded contract or expressed consent, the Administrator releases the data provided by the Data Subject in a machine-readable format. It is also possible to request that this data be transferred to another entity, provided, however, that the technical capabilities of both the Administrator and the designated entity are available.
- the right to object to the processing of data for marketing purposes - the Data Subject may object to the processing of Personal Data for marketing purposes at any time, without having to justify such objection.
- the right to object to other purposes of data processing - the Data Subject may at any time object - for reasons relating to their particular situation - to the processing of Personal Data which is carried out on the basis of the Administrator's legitimate interest (e.g. for analytical or statistical purposes or for reasons related to the protection of property); the objection in this respect should contain a justification.
- the right to withdraw consent - if data are processed on the basis of expressed consent, the Data Subject has the right to withdraw it at any time, which, however, does not affect the lawfulness of the processing carried out before its withdrawal.
- The right to complain - if the processing of Personal Data is deemed to violate the provisions of the GDPR or other provisions regarding the protection of Personal Data, the Data Subject may file a complaint with the authority supervising the processing of Personal Data, with jurisdiction over the Data Subject's place of habitual residence, place of work, or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office.
X. SUBMITTING REQUESTS RELATED TO THE EXERCISE OF RIGHTS
- A request regarding the exercise of the rights of Data Subjects may be submitted:
- in writing to the following address: mybox Sp. z o.o., Jana Henryka Dąbrowskiego 77A, 60-529 Poznań;
- by e-mail to the following address: [email protected].
- If the Administrator is unable to identify an individual based on the submitted request, it will request additional information from the requestor. Providing such Personal Data is not mandatory, but failure to provide it will result in the request being refused.
- The request may be submitted in person or through a proxy (e.g., a family member). For data security reasons, the Administrator encourages the use of a power of attorney certified by a notary or authorized legal counsel or attorney, which will significantly speed up verification of the request's authenticity.
- A response to a request should be provided within one month of its receipt. If an extension is necessary, the Administrator will inform the requester of the reasons for doing so.
- If a request is submitted to the Administrator electronically, the response will be provided in the same form, unless the requestor has requested a response in a different form. In other cases, the response will be provided in writing. If the deadline for fulfilling the request prevents a written response, and the scope of the requestor's data processed by the Administrator allows for electronic contact, the response should be provided electronically.
- The Administrator stores information regarding the submitted request and the person who submitted the request in order to ensure the possibility of demonstrating compliance and to establish, defend or pursue any claims of Data Subjects.
XI. DATA PROTECTION INSPECTOR
- The Administrator has appointed a Personal Data Inspector.
- Contact with the Personal Data Inspector is possible via: [email protected].
XII. COOKIES
- The website automatically collects information contained in cookies to collect data related to the use of the website by Data Subjects and the User. Cookies are small pieces of text that the website sends to the Data Subjects browser and which the browser sends back upon subsequent visits to the website. They are primarily used to maintain sessions, for example, by generating and returning a temporary identifier after logging in. The website uses "session" cookies, which are stored on the Data Subject's end device until they log out, exit the website, or close the web browser. "Persistent" cookies are stored on the Data Subject's end device for the period specified in the cookie parameters or until they are deleted by the Data Subjects.
- Cookies customize and optimize the Website and its offerings to meet Data Subjects needs through activities such as generating statistics on Website views and ensuring Website security. Cookies are also necessary to maintain a Data Subject's session after they leave the website. They allow them to return to the contents of their shopping cart without losing its parameters, which would require them to re-select Products.
- The Administrator processes the data contained in Cookies each time the website is visited by visitors for the following purposes:
- optimizing the use of the Website pages;
- identifying Users as currently logged in to the Website and displaying, adapting graphics, selection options and any other content of the Website page to the User's individual preferences;
- remembering the data entered automatically and manually from order forms or the login details to the Website provided by the visitor;
- collecting and analysing anonymous statistics showing how the Website is used in the administration panel, Google Analytics, HotJar and Heap Analytics;
- collecting and analysing statistics in order to contact the User via the chat built into the Freshdesk tool ;
- creating remarketing lists based on information about preferences, behavior, use of the Website and interests, and collecting demographic data, and then sharing these lists in Google Ads and Facebook Ads ;
- remembering all products added to your cart to facilitate ordering;
- creating data segments based on demographic information, interests, preferences in the selection of viewed products/services;
- use of demographic and interest data in Google Analytics reports.
- Users may disable or delete cookies at any time using their web browser settings.
- Blocking the ability of the User to collect Cookies on his/her device may make it difficult or impossible for the User to use certain functionalities of the Website, to which the User is fully entitled, but in such a situation he/she must be aware of the functional limitations of the Website.
- Users who do not wish to use cookies for the purposes described above may manually delete them at any time. For detailed instructions, please visit the website of the manufacturer of the web browser you are currently using.
XIII. PRIVACY POLICY UPDATE
This Privacy Policy may be subject to change, either due to changes in generally applicable regulations or as a result of changes in the scope of services provided by the Administrator. The Administrator will notify about changes to the Privacy Policy on the websites or on the Website, informing you of the date of implementation of the changes, so that you can exercise your rights under the GDPR, in particular the withdrawal of consent or the filing of an objection.