Privacy policy

Definitions

Controller: PUROMEDICA SP. Z O.O. SP. K. with its registered seat in Dąbrowa at the address: ul. Batorowska 30 , registered in the register of entrepreneurs with KRS no. 0000733586 and NIP no. 7773322531

Personal data/Data: all information concerning an identified or identifiable natural person using one or several individual indicators including device IP, location data, online ID and information collected via cookie files or other similar technologies.

Policy: this “Privacy policy”.

GDPR: Regulation of the European Parliament and the Council (EU) 2016/679 of April 27th 2016 on the protection of individuals with regard to the processing of personal data and on the free flow of such data and on repealing directive 95/46/EC.

Websites: the administrator’s websites and online store,

User: any natural person/entrepreneur visiting the website or using one or more services or functionalities offered by the website.

Profiling: automated processing of personal data, which consists in using personal data for assessment of certain personal factors of a natural person – in particular for analyses or forecasts,

We collect and process your personal data as you use our websites. Below you’ll find the detailed rules and purposes of processing your personal data.

Consent settings

FOR WHAT PURPOSE AND ON WHAT BASIS WE PROCESS YOUR DATA

Your personal data such as IP address or other IDs and information are collected via cookie files or other similar technologies when you visit our websites (also without logging in). We process them for the following purposes:

  • to share the contents gathered on the website – in this case the legal basis of processing is our legitimate interest consisting in spreading our contents (art. 6 section 1 item f of GDPR);
  • for analytical and statistical purposes – in this case the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR) consisting in conducting analyses of user activity and preferences in order to improve the applied functionalities and the provided services;
  • in order to identify, assert or defend ourselves against potential claims – the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR) consisting in defence of our rights;
  • for our own and third party marketing purposes, the principles of processing personal data for marketing purposes have been laid down below in MARKETING section.

Your activity on the website, including your personal data, is registered in system logs (a special computer programme used to store chronological record of information on the events and actions related to the IT system used for providing the services) and using analytic scripts. We use that data mostly for purposes related to providing our services, for technical and administrative purposes, to protect and manage the IT system and for analytical and statistical purposes.In this respect, the legal basis of processing personal data is our legitimate interest (art. 6 section 1 item f of GDPR).

Registration on the website

In order to open an account on the website, you shall be asked to provide your data necessary to open and run your account, that is, your e-mail address, full name, address of residence, address for correspondence (where different) and telephone number. Moreover, to make provision of services easier, a user might provide additional data that they might remove at any time. Providing data indicated as obligatory is required to open and run an account and a refusal to provide them prevents a user from opening an account. As a result of opening and running an account we process your data for the following purposes:

  • to provide services related to opening and running your account on the website – the legal basis of processing is the indispensability to process data for the purpose of exercising the agreement (art. 6 section 1 item b of GDPR) and the optionally provided data are processed based on your consent (art. 6 section 1 item a of GDPR);
  • for analytical and statistical purposes – the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR) consisting in conducting analyses of user activity on the website, the way they use their accounts and their preferences in order to improve the applied functionalities and the provided services;
  • in order to identify, assert or defend ourselves against potential claims – the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR) consisting in defence of our rights;
  • for our own and third party marketing purposes – the principles of processing personal data for marketing purposes have been laid down below in MARKETING section.

Submitting orders

Submitting and completion of an order (purchase of goods or a service) requires processing your personal data. Providing data indicated as obligatory is required for accepting and processing an order a refusal to provide them prevents us from accepting an order. Providing other data is voluntary.

Personal data are processed:

  • to complete a submitted order (including potential complaints) – the legal basis of processing is the indispensability to process data for the purpose of exercising the agreement (art. 6 section 1 item b of GDPR) and the optionally provided data are processed based on your consent (art. 6 section 1 item a of GDPR);
  • in order to perform the statutory obligations of an administrator, resulting in particular from tax laws and accounting laws – the legal basis of processing is the legal obligation (art. 6 section 1 item c of GDPR);
  • for analytical and statistical purposes – the legal basis of processing is the administrator’s legitimate interest (art. 6 section 1 item f of GDPR) consisting in conducting analyses of user activity on the website and their shopping preferences in order to improve the applied functionalities;
  • in order to identify, assert or defend ourselves against potential claims – the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR) consisting in defence of our rights.

Contact forms

Using a form requires providing personal data indicated as obligatory. A refusal to provide them makes processing an application impossible. Providing other data is voluntary.

Personal data given in the form are processed:

  • for the purpose of identifying the sender and processing the case described in the form – the legal base of processing is the indispensability to process data for the purpose of exercising the agreement (art. 6 section 1 item b of GDPR);
  • for analytical and statistical purposes – the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR consisting in keeping statistics of cases reported by users through the website, i.a. to improve its functionality.

Personalisation and adapting editorial content

We process your personal data to adapt editorial content, which might consist in:

  • displaying content adapted to your interests/areas;
  • undertake other types of activities related to adapting editorial content to your interests.

The legal basis of processing personal data for the purpose of personalising and adapting contents is our legitimate interest (art. 6 section 1 item f of GDPR).

We use profiling in certain cases to personalise and adapt contents to users. This means that automated data processing allows us to assess selected factors related to natural person to analyse or forecast their activities.

MARKETING

We process your data for the purpose of performing marketing activities, which might consist in:

  • displaying marketing contents not dependent on your preferences (including standard advertising);
  • displaying marketing contents corresponding to your interests (behavioural advertising);
  • sending e-mail notifications of interesting offers or contents, which in some cases include commercial information (newsletter service);
  • other types of actions related to direct marketing of goods and services (sending commercial information electronically and telemarketing activities).

We use profiling to perform marketing activities in certain cases. This means that automated data processing allows us to assess your selected activities or create forecasts of your future activities. Standard advertising

Standard advertising means advertising not dependent on user preferences. In case of emission of such advertisement your personal data are processed for marketing purposes with respect to acting according to our legitimate interest (that is, pursuant to art. 6 section 1 item f of GDPR). Behavioural advertising

Behavioural advertising means advertising adapted to the user’s preferences. Behavioural advertising is displayed based on profiling which means using your personal data collected through cookie files and other similar technologies. Profiling for marketing purposes takes place based on your consent (that means, pursuant to art. 6 section 1 item a of GDPR). This consent is voluntary. Consent might also be given by way of explicit activity confirming consent in a message displayed in the process of collecting consents. You can withdraw your consent at any time, but this has no influence on lawfulness of profiling for marketing purposes before withdrawing it. Newsletter

We send our newsletter to individuals who have provided their e-mail address for that purpose. Providing data indicated at subscription for the newsletter (e-mail address) is voluntary, but it is not necessary for sending the newsletter.

Personal data are processed:

  • for the purpose of sending the newsletter – the legal basis of processing is the indispensability to process data to exercise the agreement (art. 6 section 1 item b of GDPR);
  • in case of sending marketing contents to the user as part of the newsletter – the legal basis of processing, including profiling, is our legitimate interest (art. 6 section 1 item f of GDPR);
  • for analytical and statistical purposes – the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR) consisting in conducting analyses of user activity on the website in order to improve the applied functionalities;
  • in order to identify, assert or defend ourselves against potential claims – the legal basis of processing is our legitimate interest (art. 6 section 1 item f of GDPR).

Direct marketing

Direct marketing sent by e-mail, text or MMS messages or by telephone requires your consent (pursuant to art. 6 section 1 item a of GDPR). You can withdraw your consent at any time. COOKIE FILES AND SIMILAR TECHNOLOGIES

Cookie files are small text files installed on your device. Cookies usually include domain name of the website they come from, time of storage on the terminal device and a unique ID. As part of this policy, information on cookies also apply to other similar technologies used by the website. Service cookies

We use the so-called service cookies mostly to display contents and remember login data, to improve the quality of our services. Consequently, we and the entities that provide analytical and statistical services to us use cookie files and LocalStorage technology for storing information or accessing the information that is already stored in your own computer, telephone, tablet etc.

Cookie files used for that purpose include:

  • cookie files with data entered by you (the user input cookies);
  • authentication cookie files used for services that require authentication for the duration of a session;
  • cookie files used to ensure security, e.g. to detect frauds with respect to authentication (the user centric security cookies);
  • “marketing” cookies.

PERIOD OF PROCESSING PERSONAL DATA

The period of processing personal data depends on the type of service provided and the purpose of processing. As a rule, data are processed for the period of providing the given service or completing an order by the time of withdrawing a given consent or submitting an objection or an effective request for removal of the data.

The period of processing data might be extended if processing is necessary in order to identify, assert or defend ourselves against potential claims – the legal basis of processing is our legitimate interest and, after that period, only in case and to the extent, in which it is required by applicable laws. YOUR RIGHTS

You have the right to: access your data and demand corrections in them, removal, restrictions of processing, right to transfer the data to another administrator and the right to object against processing the data as well as the right to submit a complaint to a supervisory authority protecting personal data.

To the extent, in which your data are processed based on your consent, you can withdraw it at any moment by contacting us, pursuant to the data provided on the website Right to object

You have the right to object at any time against processing your data:

  •  for the purpose of direct marketing;
  • for reasons related to your particular situation if the legal basis of processing your data is our legitimate interest (e.g. our marketing, statistical or analytical purposes), that is, if your data are processed pursuant to art. 6 section 1 item f of GDPR;

You can find more information concerning your rights resulting from GDPR in the transparency policy (available here), which constitutes an enclosure to this privacy policy. DATA RECIPIENTS

In connection with provision of our services your personal data might be disclosed to third parties, in particular service providers responsible for operating IT systems used for providing the services, entities such as banks and payment operators, research companies, entities providing accounting services, companies providing courier and consignment services, marketing agencies (as regards marketing services).

Your data might be disclosed to competent authorities or third parties which submit a request for such information with an appropriate legal basis, which obliges us to provide the information pursuant to the laws in force.

TRANSFERRING DATA OUTSIDE THE EUROPEAN ECONOMIC AREA

Your data will not be transferred outside the EEA.

SECURITY OF PERSONAL DATA

Guarantees that personal data are processed by us in a safe way ensuring mostly that only authorised persons can access the data and only to the extent, in which it is necessary on account of their duties. We make sure that all operations using personal data are registered and performed only by authorised employees and associates.

CONTACT DETAILS

You can contact the PERSONAL DATA ADMINISTRATOR at the e-mail address: office@puromedica.com or in writing at the address: ul. Batorowska 30, 62-070 Dąbrowa.

CHANGES OF PRIVACY POLICY

The policy is verified on an ongoing basis and updated when necessary.