Privacy Policy
PRIVACY POLICY
This Privacy Policy has been drafted based on Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regards to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as “GDPR”).
§ 1 DATA CONTROLLER
- The Controller of your personal data is AS-PL Sp. z o.o. with its registered office in Gdańsk at Michałki 32 st., 80-716 Gdańsk, entered in the register of businesses of the National Court Register maintained by the District Court for Gdańsk-Północ in Gdańsk, 8th Commercial Division, under KRS number 0000656373, Tax ID No. (NIP): 9571090656, REGON: 366230765 (hereinafter referred to as the “Controller”.) You may contact the Controller by sending mail to the address mentioned above, calling them on +48 58-304-12-85 or by sending an e-mail to ado@as-pl.com
§ 2 DATA PROTECTION OFFICER
- 1. The Controller has appointed a Data Protection Officer. This Officer is a competent authority in matters related to the processing of personal data. You may contact the Data Protection Officer from Monday to Friday, 8 AM - 3 PM, by sending an e-mail to: ido@as-pl.com
§ 3 TYPES OF, PURPOSES OF, AND LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA. STORAGE PERIODS
- 1. This Privacy Policy determines the rules for processing the personal data obtained from the Customers of the online wholesale shop at www.as-pl.com or as-pl.com (hereinafter referred to as the “Online Shop”) or through any correspondence sent to the Controller via mail or e-mail. „*.*”@as-pl.com
- The personal data of the Customer are collected and processed for the purposes of:
- registering an account in the Online Shop (legal basis: processing is necessary for the performance of a contract for the provision of an account - Article 6(1)(b) of the GDPR);
- making an order in the Online Shop (legal basis: processing is necessary for the performance of a sales contract - Article 6(1)(b) of the GDPR);
- signing up for a newsletter (legal basis: processing is necessary for the performance of a contract for the provision of a newsletter - Article 6(1)(b) of the GDPR);
- using the chat service (legal basis: processing is necessary for the performance of a contract for the provision of a chat service - Article 6(1)(b) of the GDPR);
- pursuing legitimate interests of the Controller (legal basis - Article 6(1)(f) of the GDPR); this includes:
- establishing, seeking and enforcing claims, as well as defending themselves against any claims,
- producing summaries, analyses and statistics for the Controller’s internal purposes, which, in particular, includes reporting and research activities, as well as development planning for our products,
- ensuring the security of networks and information,
- using direct marketing;
- complying with legal obligations to which the Controller is subject (legal basis - Article 6(1)(c) of the GDPR); this includes:
- obligations arising from warranties for defects,
- obligations with respect to issuing and storing invoices and documents required by tax law and provisions on accounting,
- storage of data in order to prove that accountability obligations and other obligations arising from the provisions concerning personal data protection are fulfilled.
- Registering an account in the Online Shop requires providing the following:
- an e-mail address,
- the name of the Enterprise and its contact details,
- the Tax ID No. (NIP),
- a telephone number.
- Making an order in the Online Shop requires providing the following:
- an e-mail address,
- the name of the Enterprise and its contact details,
- the Tax ID No. (NIP),
- a telephone number.
- Using the chat service requires providing the following:
- the name of the Enterprise,
- an e-mail address.
- Using the newsletter requires providing the following:
- an e-mail address.
- an e-mail address.
- The personal data of the Customer are stored for the following periods, depending on the legal basis of the processing:
Legal basis |
Storage period |
Consent (Article 6(1)(a) of the GDPR) |
|
Performance of a contract (Article 6(1)(b) of the GDPR) |
|
Pursuit of legitimate interests (Article 6(1)(f) of the GDPR:) |
|
|
|
|
|
|
|
|
|
Complying with legal obligations (Article 6(1)(c) of the GDPR:) |
|
|
|
|
|
|
|
- Providing personal data to AS-PL Sp. z o.o. is voluntary, but necessary for concluding and performing a contract (e.g. implementing an order made in the Online Shop or registering the Customer’s account), sending a newsletter or using the chat service.
§ 4 TRANSFER OF PERSONAL DATA
- Customer’s personal data may be transferred to the following persons and entities:
- employees and co-workers of the Controller, for whom access to the Customer’s personal data is necessary in performing their obligations or the Controller’s activities for the benefit of the Customer,
- entities handling the Controller’s ICT systems or providing the Controller with ICT devices, including IT platforms, server space or web hosting space,
- providers of advisory, consultancy or audit services, as well as entities providing legal, tax and accounting assistance,
- providers of mail or courier services,
- providers of electronic payment services, such as PayU or PayPal.
- Upon relevant request, the Controller may have to make the personal data available to the state authorities, and especially to the units of the Prosecutor’s Office, the Police, to the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection or the President of the Office of Electronic Communications.
§ 5 COOKIES
- The Controller uses small text files that are saved on the terminal equipment of the person visiting the Online Shop (hereinafter referred to as the “User”.) Based on these files, so-called cookies, the Controller collects information that allows them to identify the User’s terminal equipment, its IP address and their browser.
- Cookies are safe for the User’s devices. Cookies cannot carry viruses, malicious or undesired software onto the User’s devices.
- The Users may adapt the settings of their browsers with regards to cookies, so that their automatic installation is switched off, their use is disabled, or so that they are removed from the terminal equipment. Below, the Users can find a list of instructions on how to change cookie settings in the most popular web browsers:
- The Controller uses two types of cookies:
- session cookies – cookies that are removed from the device’s memory after the browser session is ended or after the device is switched off,
- persistent cookies – cookies that are stored in the memory of the User’s terminal equipment until they expire or are deleted.
Neither session or persistent cookies allow any personal or confidential data to be obtained from the User’s devices.
- The Controller uses their own cookies especially for the purposes of authenticating the Users in the Online Shop and maintaining their sessions after they log in, so that they do not have to log in on every subpage of the Online Shop.
- The Controller uses external cookies for such purposes as:
- collecting general and anonymous statistical data using Google Analytics,
- promoting the Online Shop through Facebook,
- providing the live chat service to the Users.
§ 6 RIGHTS OF DATA SUBJECTS
- The Customers of the Online Shop have the following rights:
- the right to access their personal data, the right to be informed of their personal data, the right to obtain a copy of their personal data,
- the right to rectify their personal data if they are inaccurate, and the right to have incomplete personal data completed,
- the right to have their personal data erased (the so-called right to be forgotten),
- the right to restrict the processing of their personal data,
- the right to move their personal data,
- the right to lodge a complaint with the authority dealing with personal data protection (the President of the Office for Personal Data Protection), should they become aware of unlawful processing of their personal data,
- the right to withdraw their consent without providing any reason, and without prejudice to the processing that had been undertaken under such consent before it was withdrawn,
- the right to object to:
- the Controller’s processing for the purposes of marketing,
- the Controller’s processing for the purposes of pursuing their legitimate interests - in cases motivated by a special situation of the Customer.
If the Customer’s objection is reasonable, and the Controller has no other legal basis for the processing of the Customer’s personal data, such data will be removed with respect to the type of processing to which the customer objected.
- Each of the above rights and each situation in which they can be exercised is specified in applicable laws, and in particular, the GDPR.
- Should the Customer address the Controller with a demand to exercise one of the above rights, the Controller will immediately comply with the Customer’s request or refuse to comply with it, within no more than a month from receiving the request. If, however, the Controller is not able to comply with the Customer’s request within a month due to the complex nature of the Customer’s demands, they may do so within the next two months. The Controller must inform the Customer within one month of receiving the request that they intend to take more time to handle it, and must provide the reasons for this.
- The Customer may also exercise their rights by contacting the Personal Data Officer via e-mail.
§ 7 PERSONAL DATA SAFETY
- The Controller implements adequate technical and organisational measures aiming at protecting the personal data of the Customers against loss, misuse or modification. Access to the Customers’ personal data is restricted, so that no unauthorised persons come into their possession.
§ 8 CHANGES TO THE PRIVACY POLICY
- The Controller may introduce changes to this Privacy Policy.
- An up-to-date version of the Privacy Policy can be found on this subpage, together with a link to its previous version.
Gdańsk, 5 July 2018