Introduction
In this document, we define the principles of the Privacy Policy in the online store www.saxos.eu (hereinafter: the Online Store) and on the Fanpage of the Online Store in social media available at: instagram.com/saxos_eu (hereinafter: Saxos Social Media)
From May 25, 2018, Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46 / EC (General Data Protection Regulation) (hereinafter: GDPR).
We ensure that personal data collected by the Administrator are processed in accordance with the provisions of the GDPR. Below we present information on the principles of processing your personal data.
Who is the administrator of your personal data?
The administrator of personal data is PPUH SAXOS S.C. Sulnowo 42a, 86-100 Swiecie, Poland.
Where do we get your data from?
We process your personal data that we receive from you:
a. in connection with Sales Agreements and other agreements concluded with us;
b. during your contact with us, including as part of the complaint process or declaration of withdrawal from the Sales Agreement or other contracts, or in connection with your use of the saxos_eu Social Media profile;
c. in connection with you subscribing to our newsletter;
d. for the purposes of setting up an Account in the Online Store.
In addition, we obtain the data received from you when exchanging sales documents, such as: bills; invoices etc.
We may also process your data: regarding activity in the Online Store, i.e.: products viewed, IP addresses, device identifiers; cookie data; data on the amount of time you spend on each subpage. We would like to point out that we only collect data that is necessary to achieve the purposes described below.
For what purposes and on what legal basis do we process your personal data?
We process your personal data for and on the basis of:
a. conclusion and performance of the Sales Agreement concluded with you and other contracts concluded by us, including for the purpose of contacting you regarding their implementation, as well as taking actions at your request aimed at concluding the Agreement (legal basis: Article 6 para. 1 letter b GDPR),
b. answering your questions contained in the contact form on the Online Store website, as well as handling complaints and returns that you submit to us (legal basis: Article 6(1)(f) of the GDPR; our legitimate interest: communication with users Online Store and handling complaints and returns reported by customers),
c. performance of obligations arising from the warranty for defects and the Consumer’s right to withdraw from the Sales Agreement and other contracts concluded remotely or off-premises (legal basis: Article 6(1)(c) of the GDPR in connection with the relevant provisions of the Civil Code or the Act on consumer rights),
d. archiving documentation, in particular: contracts, invoices and other settlement documents for the purpose of accounting (legal basis: Article 6(1)(c) of the GDPR in connection with the relevant accounting regulations),
e. determining, investigating and defending against possible claims (legal basis: Article 6(1)(f) of the GDPR; our legitimate interest: investigation,
f. creating lists, analyzes and statistics for our internal needs, in particular research and planning the development of our products and services and improving their quality (legal basis: Article 6(1)(f) of the GDPR; our legitimate interest: development of the Online Store and improving the quality of services; facilitating the use of the Online Store),
g. Customer service of the Online Store and User of saxos_eu Social Media profiles, in particular in order to: adapt this service to the needs reported by you; provide you with information about our products, offers, promotions; researching and planning the development of our services and improving their quality – also by saving data in “cookies” and collecting data from websites for direct marketing (legal basis: Article 6(1)(f) of the GDPR); our legitimate interest: improving the quality of services; development of the Online Store and the saxos_eu Social Media profile, including facilitating the use of the Online Store and the saxos_eu Social Media profile; marketing of our products and services)
h. conducting marketing communication regarding the activities of the Online Store, in particular in the field of: presenting the Online Store’s offer, information about products, offers, promotions, including sending a newsletter via e-mail (legal basis: Article 6(1)(f) of the GDPR, our legitimate interest: marketing of our products and services),
i. enabling you to use the content shared on the saxos_eu Social Media profile, including in particular the function of: posting comments under posts published on the saxos_eu Social Media profile, sharing the above-mentioned posts on your profile and the possibility of “liking” these posts (legal basis: art. 6(1)(f) of the GDPR; our legitimate interest: providing Users with the ability to use social functions of saxos_eu Social Media profiles),
j. respond to your: questions, comments, statements submitted to us via the messaging messenger available on instagram.com and in the comment mode under posts posted on the saxos_eu Social Media profile (legal basis: Article 6(1)(f) of the GDPR ; our legitimate interest: communication with Users).
Who do we share your personal data with?
We care about the confidentiality of your data, therefore we share it with others only when it is necessary to ensure the proper functioning of the Online Store, the saxos_eu profile and the Administrator. We may share your personal data with entities supporting us in our activities, such as:
a. service providers supplying the Administrator with technical and organizational solutions, including those supporting us in the provision of electronic services, in particular those who provide payment services, mediate in e-commerce services, providers of e-mail, hosting and analytical tools for marketing purposes,
b. providers of HR and payroll as well as accounting and bookkeeping services,
c. providers of legal and advisory services,
d. persons authorized by you,
e. public administration authorities or other entities authorized under the law, in order to fulfill our obligations, e.g.: Tax Office, Social Insurance Institution, local government authorities. The administrator may disclose your personal data to the above-mentioned entities only in the case of processing this data for one of the purposes consistent with this Privacy Policy and to the extent necessary to achieve this goal.
Is providing us with personal data voluntary?
Providing us with your personal data is voluntary. Remember, however, that if you do not provide us with your data, we will not be able to take actions that require the processing of your personal data. For example, in order for us to conclude a Sales Agreement with you, you will have to provide us with your personal data when placing an order.
Providing us with data in order to subscribe to our newsletter is completely voluntary – failure to subscribe to the newsletter does not prevent the use of other services we offer, in particular the conclusion of the Sales Agreement.
In the case of saxos_eu Social Media profiles, providing us with your data is also voluntary, but remember that due to the rules applied by Meta Platforms Ireland Ltd. and Meta Platforms Inc., we will see your name, surname and profile picture if: you write to us comment on our post or share our post – as long as you share this personal data on your Instagram profile.
What are your rights regarding the processing of personal data?
You have the following rights: the right to access the content of the processed personal data, as well as the right to: rectify, delete, request processing restrictions, transfer your personal data and object to the processing of personal data, as well as the right to withdraw consent at any time without affecting on the lawfulness of processing based on consent before its withdrawal, provided that the specific processing is based on your consent.
In addition, in a situation where the processing of personal data that we perform violates the provisions of the GDPR, you also have the right to lodge a complaint with the supervisory body, i.e. the President of the Office for Personal Data Protection (PUODO).
How long can we store your personal data?
Due to tax regulations, we will, as a rule, store your personal data for a maximum of 5 years from the end of the year in which we concluded the Sales Agreement with you.
We may store your personal data processed in order to pursue our legitimate interests, in particular for marketing purposes, until you submit an effective objection, but in any case no longer than it is necessary to pursue these interests. We store personal data of unregistered Customers for a time corresponding to the life cycle of “cookies” saved on devices or until you delete them on your device.
We may store personal data that we obtain from you in messages via the Instagram messenger sent to saxos_eu Social Media profiles as long as they are available in these messengers. In the case of personal data processed in connection with posting a comment by you under the post of the saxos_eu Social Media profile or in connection with sharing the post of the saxos_eu Social Media profile on your profile or by “liking” the post of the saxos_eu Social Media profile, it will be processed accordingly: until the comment is deleted by you or the Administrator under the post or you stop sharing the post on your profile or by disabling the “like” option of the post.
If we consider that your data is necessary for us to establish, pursue or defend against claims, we may process this data up to the end of the limitation period for these claims, which is generally 6 years.
We also point out that the parallel administrator of your data collected by Meta Platforms Ireland Ltd. and Meta Platforms Inc. (e.g. history of posts on the Instagram portal, list of followed profiles) are Meta Platforms Ireland Ltd. and Meta Platforms Inc., which process this data independently of PPUH Saxos S.C. as the Administrator, on the terms set out in the regulations and privacy policies of Meta Platforms Ireland Ltd. and Meta Platforms Inc.
Do we transfer your data to countries outside the European Economic Area?
Because we can use tools supporting our activities provided, for example, by Google Inc. and Meta Platforms Ireland Limited, your personal data may be transferred to countries outside the European Economic Area. In such cases, we use appropriate legal safeguards, i.e. standard contractual clauses for the protection of personal data, approved by the European Commission, or the decision of the European Commission on the adequacy of the level of protection, if it has been taken.
Will my personal data be used for automated decision making?
Your personal data will not be subject to automated processing, including profiling, which would result in a decision that would have legal effects on you or similarly significantly affect you.
What are your rights regarding the processing of personal data?
In connection with the processing of your personal data by us, you have the following rights:
a. the right to access your personal data,
b. the right to rectify your personal data,
c. the right to delete your personal data,
d. the right to request limitation of the processing of your personal data,
e. the right to transfer your personal data,
f. in the case of your data processed in order to pursue our legitimate interests (i.e. pursuant to Article 6(1)(f) of the GDPR) – the right to object to the processing of personal data,
g. in the case of your data processed on the basis of consent (i.e. pursuant to Article 6(1)(a) of the GDPR) – the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its consent undo.
In addition, if you believe that we process your personal data in violation of the provisions of the GDPR or other legal acts, you have the right to lodge a complaint with the supervisory body, i.e. the President of the Office for Personal Data Protection.
„Cookies“
The Online Store also uses “cookies” that are saved on your device. Cookies provide us with information about your activity for: statistical purposes regarding the activity of users on the Online Store website and the use of individual subpages of the Online Store; matching the offer to your needs; optimizing the use of the Online Store; identifying the user logged in to the Online Store and displaying a login message; remembering Products added to the Basket in order to place an Order; remembering the data provided by you in the Order, contact form or when logging in. The administrator may receive data contained in “cookies” when you use the Online Store website.
You can disable the option of accepting “cookies” in your web browser at any time by replacing the automatic handling of “cookies” with a service consistent with individual preferences. Detailed information in this regard is provided by the providers of individual web browsers. Please note that disabling the option of accepting “cookies” in your web browser may prevent or hinder the use of the Online Store.
The Administrator may use Google Analytics and Universal Analytics services provided by Google Inc. in the Online Store. and from Meta Platforms analytics services provided by Meta Platforms Ireland Limited. These services help the Administrator to analyze traffic in the Online Store and on the Online Store profile on Instagram. The collected data is processed as part of the above services in an anonymous manner (these are the so-called operational data that prevent the unambiguous identification of a person) to generate statistics helpful in administering the Online Store. These data are aggregate and anonymous, i.e. they do not contain information that uniquely identifies people visiting the Online Store website or the Online Store profile on Instagram. The Administrator, using the above services in the Online Store, collects such data as: sources and media of obtaining people visiting the Online Store and activities undertaken by them on the Online Store website, information on devices and browsers from which they visit the website, IP and domain, geographic data, demographics and interests.
To the extent described in the paragraph above, you can block the possibility of sharing by anyone, including the Administrator, information about your activity on the Online Store website at any time – by installing the appropriate “plug-in” to your web browser, provided by both Google and Meta Platforms (Instagram ) free of charge on the websites of these entities. This does not apply to data that we obtain directly from saxos_eu Social Media profiles.
I do not consent to the storage of cookies.
Final remarks
The Online Store may contain links to other websites. We recommend that after going to other websites, you read the privacy policy or other information about the processing of personal data available on these websites. This privacy policy applies only to the processing of data by the Administrator of PPUH Saxos S.C.