PRIVACY & COOKIES POLICY
GENERAL PROVISIONS
- This Privacy Policy of the Online Store is informational in nature, which means it is not a source of obligations for Customers of the Online Store.
- The controller of personal data collected via the Online Store is BAUND Spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw at ul. Marszałkowska 58, entered into the Register of Entrepreneurs maintained by the District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS number 0001232808, NIP: 7011306545, REGON: 544385125, e-mail address: customercare@pattmond.com – hereinafter referred to as the “Controller” and acting at the same time as the service provider of the Online Store and the Seller.
- The personal data of the Customer is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as “GDPR” – and with the relevant national provisions, in particular the Personal Data Protection Act and the Act on the Provision of Electronic Services of 18 July 2002 (Journal of Laws 2002 No. 144, item 1204, as amended).
- The Controller exercises particular care to protect the interests of the data subjects, and in particular ensures that the data collected by it are: processed lawfully; collected for specified, lawful purposes and not subjected to further processing incompatible with those purposes; substantively correct and adequate in relation to the purposes for which they are processed; and stored in a form which permits identification of the data subjects no longer than is necessary to achieve the purpose of the processing.
- All words, expressions and acronyms used on this page and starting with a capital letter (e.g. Seller, Online Store, Electronic Service) shall be understood in accordance with their definition contained in the Terms and Conditions of the Online Store available on the Online Store website.
PURPOSE AND SCOPE OF DATA COLLECTION AND DATA RECIPIENTS
- On each occasion, the purpose, scope and recipients of the data processed by the Controller result from the actions taken by the Customer in the Online Store. By way of example, if the Customer chooses personal collection rather than courier delivery when placing the Order, their personal data will be processed for the purpose of conclusion and performance of the Sales Agreement, but will no longer be made available to the carrier delivering shipments on behalf of the Controller.
- Purposes of processing the personal data of Customers by the Controller:
- conclusion and performance of the Sales Agreement or the agreement for the provision of Electronic Services (Article 6(1)(b) GDPR);
- direct marketing of the Controller’s own products or services (Article 6(1)(f) GDPR);
- handling of complaints (Article 6(1)(b) GDPR).
- Possible recipients of the personal data of Customers of the Online Store:
- In the case of the Customer, the Controller makes the collected personal data of the Customer available to its selected hosting service provider of the website;
- In the case of a Customer who uses postal or courier delivery in the Online Store, the Controller makes the collected personal data of the Customer available to the selected carrier or forwarder delivering shipments on behalf of the Controller.
- In the case of a Customer who uses electronic payments or payment by payment card in the Online Store, the Controller makes the collected personal data of the Customer available to the selected entity handling the above-mentioned payments in the Online Store.
- The Controller may process the following personal data of Customers using the Online Store: first name and surname; e-mail address; contact telephone number; delivery address (street, house number, apartment number, postal code, town, country); residence/business/registered office address (if different from the delivery address).
- Provision of the personal data referred to in the point above may be necessary for the conclusion and performance of the Sales Agreement or the agreement for the provision of an Electronic Service in the Online Store. On each occasion, the scope of data required for the conclusion of the agreement is indicated in advance on the Online Store website and in the Terms and Conditions of the Online Store.
LEGAL BASIS FOR DATA PROCESSING
- Provision of personal data by the Customer is voluntary, however, the failure to provide the personal data indicated on the Online Store website and in the Terms and Conditions of the Online Store, necessary for the conclusion and performance of the Sales Agreement or the agreement for the provision of an Electronic Service, results in the inability to conclude such an agreement.
- The basis for the processing of the Customer’s personal data is the necessity to perform the agreement to which they are a party, or to take steps at their request prior to entering into such an agreement. In the case of processing of data for the purpose of direct marketing of the Controller’s own products or services, the basis for such processing is (1) the prior consent of the Customer, or (2) the pursuit of the legitimate interests of the Controller.
RIGHT TO CONTROL, ACCESS TO AND CORRECTION OF DATA, AND OTHER RIGHTS UNDER THE GDPR
- The Customer has the right to request from the Controller access to the personal data concerning the data subject, their rectification, erasure or restriction of processing, the right to object to processing, and the right to data portability.
- Where the Customer has given consent to the processing of data – the consent may be withdrawn at any time without affecting the lawfulness of the processing carried out on the basis of the consent before its withdrawal.
- In order to exercise the rights referred to above, the Customer may contact the Controller by sending an appropriate message in writing or by electronic mail to the Controller’s address indicated at the beginning of this Privacy Policy.
- The Customer has the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
PERIOD OF PROCESSING OF PERSONAL DATA
The Customer’s personal data are processed for the time necessary to perform the agreement with the Controller, however not longer than the periods resulting from generally applicable provisions of law (tax settlements / limitation of potential claims).
FINAL PROVISIONS
- The Online Store may contain links to other websites. The Controller encourages the visitor, after navigating to other websites, to read the privacy policy applicable there. This Privacy Policy concerns only this Online Store.
- The Controller applies technical and organisational measures ensuring the protection of the processed personal data appropriate to the threats and the categories of data covered by the protection, and in particular secures the data against being made available to unauthorised persons, against being taken by an unauthorised person, against processing in breach of applicable provisions, and against alteration, loss, damage or destruction.
- The Controller makes available the following technical measures preventing the acquisition and modification by unauthorised persons of personal data transmitted electronically:
- Securing the data set against unauthorised access.
- Access to the Account only after providing an individual login and password.