Protection of the data is a priority for personal data base administrator, that’s why this document has been prepared. This document explains the rules and the scope of processing personal data of clients/users, rights of users and responsibilities of the personal data base administrator.
The personal data base administrator apply technical and organizational measures to ensure the highest level of protection of personal data and to secure personal data against unauthorized access.
I The personal data base administrator
The personal data base administrator is: Monika Kapłan-Gerc (address: ul. Janiny Porazińskiej nr 4 lok.37, Bydgoszcz) entered in the Central Register and Information on Economic Activity), NIP number: 7821538365, REGON number: 016624248.
II Purpose of personal data processing
Personal data base administrator is processing the data of users for the correct performance of sale contracts in the online store run on the website: http://thisiscommitment.com/, in particular:
– registration in the store,
– conclusion of the sale contract,
-making financial settlements,
-delivery ordered products to the user,
– use by the user of his rights provided by law, including withdrawal from the sale contract, warranty etc,
– if the user agrees to receive information about promotions from the store, user’s data is processed to send commercial information.
III Type of data processed by administrator
1. Administrator processes following personal data necessary to log in to the Website:
– first and last name,
– e-mail address.
2. Administrator processes following personal data necessary to shop on the Website:
– first and last name,
– e-mail address,
– shipping address,
– telephone number.
3. Administrator may process optionally following data:
– PESEL number – if an invoice is requested,
– NIP number – if an invoice is requested by entity conducting business activity.
– bank account number – in case of withdrawal from the sales contract or acknowledgement of complaint and the refund is to be paid directly to user’s bank account.
IV Legal grounds of the data processing
Personal data are processed in accordance with Regulation 2016/679 of the European Parliament and Council (EU) of 27 April 2016 on data protection. The data is processed with the consent of the user expressed during registration in the store and at the time of confirmation of purchase in the store. Expressing consent and providing data is voluntary, however, the lack of consent render impossible registration in the store and making purchases in the store.
- User has following rights:
- To withdraw consent to data processing – without giving any reason. Withdrawal of consent will delete the user’s account in the store and will stop processing data. Withdrawal of consent does not affect any actions already carried out.
- Access to data – the user can request at any time information which of his data is processed by the Administrator.
- To delete data – without indicating the reason. Deleting data will delete the user’s account in the store and will stop processing data. The request to delete data does not affect any actions already carried out.
- To rectify, correct or supplement incomplete data. Notwithstanding the above, it is possible for user to make corrections by himself after logging into the user’s account,
- To object to data processing – both in full and for the purpose indicated by the user. The exercise of the right to object does not affect any actions already carried out. Opposition shall delete the user’s account in the store and shall cease the data processing.
- To request the restriction of data processing for a specified period or to a certain extent. Such a request does not affect any actions already carried out. The administrator follows the user’s decision.
- Request to transfer data to another entity. The transfer takes place in electronic form after the user gives the name and address of the entity to whom the data are to be transferred and the scope of the data transfer is determined.
- The Administrator is obliged to inform about actions taken not later than 1 month from receipt of each of the requests indicated above. If it is necessary to extend the deadline, the reasons of delay will be given to the user. The User has the right to lodge a complaint with the President of the Office for Personal Data Protection in a situation where he believes that his personal data is being processed unlawfully.
V Entrusting of data processing
- The users personal data are not transferred outside the European Union.
VI The period of personal data processing
The data provided by the user is processed in the period:
a) Necessary for the implementation of the sales contract, as well as complaint claims, as well as confirmation of the Administrator’s obligations and the pursuit of claims or defense against claims that may be directed against the Administrator – however, no longer than 10 years from the date the user provides his data to the Administrator,
b) In the event of a request to delete an account in the store, the data is processed for the period necessary to confirm the fulfillment of the Administrator’s obligations and to pursue claims or defend against claims that may be directed against the Administrator – but no longer than 10 years from the date the User provides his data. The storage of data is archival and only related to applicable law and the user’s claims.
VI Data protection:
The administrator uses a number of IT and organizational security measures to minimize the risk of data leakage, destruction, disintegration, such as: firewall system, anti-virus and anti-spam security systems, internal access procedures, data processing and emergency recovery, as well as a multi-backup system levels.
IX Contact regarding personal data
Any notices related to personal data can be reported as follows:
- By e-mail: : contact@thisiscommitment,
- Contact form on the website: http://thisiscommitment.com/,
- By post: ul. Elektoralna 4/6 lok 71 00-139, Warszawa.