Privacy policy version 2.0 is effective as of 01/03/2023.
§ 1 GENERAL INFORMATION
-
The Privacy Policy of the Online Store is not a source of obligations for the Visitor (including Guest) and the Customer of the Online Store. It is for informational purposes and is not a contract or terms and conditions.
-
All expressions and words written with a capital letter (e.g., Online Store, Customer, etc.) shall be understood in accordance with the Terms and Conditions of the Online Store.
-
In the event of any discrepancy between this Privacy Policy and the consents given by an individual for the processing of personal data, the legal basis for determining the scope of the Administrator's activities shall be the voluntarily given consents or the provisions of law that apply to the factual situation.
§ 2 PERSONAL DATA CONTROLLER
-
The administrator of your personal data is Clematis Robert Włodarczyk spółka jawna ul. Seraf 13 in Wieliczka,NIP: 6832081650, KRS:0000472389, REGON:122914790(hereinafter: Administrator).
-
For all data protection issues, we encourage you to contact us at the above address or via email address: [email protected]
-
You can also send a request for access to information about what personal data we hold about you and for what purposes we process it to the address indicated.
-
The Administrator informs that it stores correspondence for statistical purposes and for the purpose of improving the support system in the scope of RODO, as well as for the resolution of complaints and possible decisions on administrative interventions made on the basis of notifications in the indicated Customer Account. Addresses and data thus collected will not be used for communication for any purpose other than the execution of the request, in particular, they will not be used for marketing purposes and transferred to third parties.
-
When contacting the Administrator to perform a specific action (e.g., filing a complaint, making a return), the Administrator may again ask the person to provide data, including personal data, e.g., in the form of name, surname, home address, e-mail address, in order to confirm his/her identity and enable the person to be contacted back on the matter and perform the requested action. Provision of such data is not mandatory, but may be necessary to perform an action or obtain information of interest to the person.
-
If you have given additional consent to our use of cookies, our trusted partners may also be the controllers of the data obtained from your online activities.
§ 3 DATA ACQUISITION AND PURPOSE OF DATA PROCESSING
-
We process personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC, (hereinafter: RODO) and other data protection laws currently in force at the time of processing certain data.
-
According to the wording of the legislation indicated, personal data is considered information about an identified or identifiable natural person. An identifiable natural person is one who can be identified directly or indirectly, in particular by means of an identifier such as a name, an identification number, location data, an Internet identifier or one or more specific factors that determine the physical, physiological, genetic, mental, economic, cultural or social identity of the natural person.
-
We ensure that the data we obtain from you is confidential, secure and processed only when necessary. We process data in accordance with the law, in a fair and transparent manner for the data subject. We process only such data and only with such content that is necessary for a legitimate purpose, i.e. the reason for processing. Personal data is collected with due diligence and adequately protected against access by unauthorized persons. We use appropriate and adequate security measures and state of the art technology to protect personal data from accidental loss and unauthorized access, use, alteration, or disclosure. We store personal data in a manner that allows identification of the data subject for no longer than is necessary for the purposes for which the data are processed.
-
The administrator obtains information about personal data in the following ways:
-
By making a purchase in the Store (online store) by the Customer;
-
By registering a Customer Account;
-
By voluntarily subscribing to the newsletter service;
-
By voluntarily entering information in an e-mail message;
-
by sending a complaint, application, inquiry or letter of any other nature;
-
by voluntarily entering information in an e-mail sent in connection with the desire to establish cooperation;
-
By posting product reviews;
-
through cookies, pixels or similar Internet technologies.
-
-
Please be advised that the purpose and scope of the data processed by the Administrator derives from the consent of the Website Visitor or Customer or the law, and in selected cases is further specified as a result of actions taken by such persons on the Online Store or through other communication channels.
-
Provision of personal data by a Visitor or Customer of the Online Store is voluntary, but necessary in order to use certain functionalities of the Online Store (e.g., placing an Order by a Customer and its settlement, registering a Customer Account or using contact forms).
-
In each case, the scope of data required to conclude the relevant contract is indicated in advance in the Online Store (we mark the data required to conclude a contract/use a specific functionality), within other channels of communication with the Visitor or Customer, or in the Terms and Conditions. The consequence of not providing personal data may be the inability to effectively use the functionality of the Website, such as the inability to place an order.
-
Your personal data is obtained by the Administrator for the following purpose:
Purpose of processing |
Legal basis |
Legally legitimate purpose, if any |
Keeping statistics. |
Article 6(1)(f) RODO. |
To have information about the statistics of our operations, which allows us to improve our business operations. |
Conducting marketing of its own products and services without the use of electronic communications. |
Article 6(1)(f) RODO. |
Conducting marketing activities to promote the business. |
Conducting marketing of its own products and services using electronic communications, including profiling. |
Article 6(1)(f) of the RODO, while these activities, due to other applicable regulations, in particular the Telecommunications Law and the Law on Provision of Electronic Services, are carried out only on the basis of consents held (Article 6(1)(a) of the RODO).
|
Conducting marketing activities to promote the business using e- mail addresses. Presenting advertisements, adjusting discounts and promotions. |
Posting reviews on the Online Store. |
Article 6(1)(a) of the RODO. |
Product Satisfaction Survey. |
Handling requests directed using the contact form, emails, complaints, other requests. |
Article 6(1)(a) RODO; Article 6(1)(c) RODO. |
Responding to requests and inquiries made using the contact form or in any other form, including storing sensitive requests and answers provided to maintain accountability. Handling requests, responding to consumer complaints. Investigation of claims, including from third parties, defense by them. |
Customer Account Maintenance. |
Article 6(1)(a) of the RODO. |
Conclusion and execution of the Service Agreement (Account) or taking action at the request of a future Customer prior to its conclusion. |
Conclusion and execution of the Sales Agreement. |
Article 6(1)(b) RODO. |
To conclude and execute the Sales Agreement or to take action at the request of the prospective Customer prior to its conclusion. |
Archiving of sales documents. |
Article 6(1)(c) RODO. |
Fulfillment of legal obligations under regulations, such as tax and accounting, especially in the case of paid contracts. |
-
Newsletter. If you wish to subscribe to our newsletter, it is mandatory to provide us with your e-mail address via the newsletter subscription form. Providing data is voluntary, but necessary to use the newsletter service. Subscribing to the newsletter is also possible at the stage of creating a Customer Account and placing an Order.
The data provided to us when signing up for the newsletter is used to send you the newsletter, in which we inform you about the company's activities, current collection, promotions and discounts. The legal basis for processing in this situation is your voluntary consent given when signing up for the newsletter.
Your data is processed in this case for the purpose of sending the newsletter periodically, and the basis for processing is Article 6(1)(a) of the RODO, i.e. your consent resulting from your desire to receive the service. The data will be processed for the duration of the newsletter, unless you opt out earlier, which will permanently delete your data from the database. In addition, you can correct your data stored in the newsletter database at any time, as well as request its deletion by opting out of receiving the newsletter. You also have the right to data portability, contained in Article 20 of the RODO.
The newsletter database is properly secured by the Administrator. The newsletter as a database is handled through an external entity. The
e-mails sent include links to hidden images (the so-called tracking pixel). In addition to its primary function of counting email opens, it is also optionally used to identify the Client and conduct marketing activities. -
Email contact. When you contact us by e-mail, you provide us with your e-mail address as the sender of the message. In addition, you may also include other personal information in the body of the message. Providing your data is voluntary, but necessary to get in touch with us.
Your data is processed in this case for the purpose of contacting you, and the basis for processing is Article 6(1)(a) of the RODO, i.e. your consent resulting from your desire to contact us. The legal basis for post-contact processing is the legitimate purpose of archiving correspondence for internal purposes (Article 6(1)(c) RODO).
The content of the correspondence may be subject to archiving and we are not able to clearly determine when it will be deleted however, this will be for a period of no more than 5 years. You have the right to request the history of the correspondence you have had with us (if it was subject to archiving), as well as to request its deletion, unless its archiving is justified due to our overriding interests. -
Customer Account. When you create a Customer Account on our Website, you provide us with your email address, first name and last name and telephone number. This is voluntary, but necessary in order to successfully register a Customer Account. Then, in the Customer Panel, you can also provide your address data.
Your data is processed in this case for the purpose of maintaining a Customer Account, and the basis for processing is Article 6(1)(a) of the RODO, i.e. your consent resulting from your desire to establish one. Your data will be processed for the duration of your Customer Account, unless you request its deletion beforehand, which will remove your data from the database. You can correct your data assigned to the Customer Account at any time, as well as request its deletion. You also have the right to data portability, contained in Article 20 of the RODO.
As part of setting up a Customer Account, you may - but are not required to - agree to subscribe to the newsletter service.
§ 4 CATEGORIES OF PERSONAL DATA
-
The controller may process the following categories of personal data:
-
personal data provided in the form when registering a Customer Account, placing Orders in the Online Store, in particular: e-mail address, name and surname, telephone number;
-
Personal data completed by the user while using the Customer Account, in particular: first and last name; e-mail address; address of residence [street, house number, apartment number, postal code, city, country], and in the case of non-consumer Customers, additionally company name and tax identification number [NIP];
-
Personal data necessary to place an order, in particular: name and surname; e-mail address; contact telephone number; address of residence [street, house number, apartment number, postal code, city, country], and in the case of Customers who are not consumers, additionally company name and tax identification number [NIP];
-
personal data provided for the use of the newsletter, provided when posting opinions and sent via e-mail; or provided when filing complaints, complaints or requests, in particular: name and surname; e-mail address; contact telephone number; address [street, house number, apartment number, postal code, city, country], bank account number;
-
Personal data provided for the purpose of participating in contests/promotional events: name and surname; e-mail address; contact telephone number; address of residence [street, house number, apartment number, postal code, city, country];
-
other data, in particular, obtained based on the Customer's activity on the Internet, including those obtained through the Online Store or other channels of communication with the Customer, using cookies and similar technologies.
-
§ 5 RECIPIENTS OF PERSONAL DATA
-
Your personal data may be processed by our partners and subcontractors, i.e. entities we use to process data and provide services to you. To the best of our knowledge, all entities to whom we entrust the processing of personal data guarantee the application of appropriate measures for the protection and security of personal data required by law.
-
Your personal data may be transferred by the Administrator:
-
to state authorities or other entities authorized under the law, in order to perform the obligations incumbent on us;
-
The Administrator's partners may be involved in the processing of personal data to a limited extent, in particular, those who technically help to run the Online Store efficiently (e.g., support us in sending e-mails and, in the case of advertising activities, also in marketing campaigns), providers of hosting or ICT services, carriers or intermediaries who deliver shipments of Orders, entities that process electronic payments or payment card payments in the Online Store, companies that service software, support the Administrator in marketing campaigns, as well as providers of legal and consulting services and external accounting;
-
In addition, we may share fully anonymized data (data that cannot identify you) with entities with whom we work.
-
-
As part of its marketing (advertising) activities, the Administrator uses the services of third parties that use cookies, pixels or marketing functions similar to cookies on the Online Store. The catalog of these entities is indicated in detail in § 8 of this Policy.
-
Our providers are mainly based in Poland or other countries in the European Economic Area (EEA), and also, for example in the case of Google Analytics, based outside the EEA. Due to the content of the CJEU ruling Schrems II (C-311/18), we have anonymization of your IP numbers enabled - we do not transfer this data to the US. Other data sent to Google do not have the characteristics of personal data, i.e. it is not possible to identify a specific natural person based on them.
§ 6 ARCHIVING OF PERSONAL DATA
-
The Administrator will retain your personal information only for as long as necessary for the purposes set forth in this Privacy Policy and/or to comply with legal and regulatory requirements. After this period, the Administrator will securely delete your personal data.
-
We retain the data for the periods indicated below:
Data related to the sales procedure. |
8 years |
Data for marketing purposes. |
In the case of data processing based on consent - until it is withdrawn. In the case of data processing on the basis of a legitimate purpose - until you object. |
Data provided using the contact form, e-mail. |
For a period of 3 years to maintain accountability. |
Opinion data. |
In the case of data processing based on consent - until it is withdrawn. In the case of data processing on the basis of a legitimate purpose - until you object. |
Personal data related to cookies and similar functions. |
Until the deletion of these files using the settings of the website / browser / device (while deletion of files is not always the same as deletion of Personal Data obtained through these files - in which case Personal Data will be deleted until you object). |
Data provided in the course of complaint and other procedures related to customer claims. |
6 years. |
The remaining category of data (with the exception of data from cookies, about which more in our Cookies Policy). |
5 years. |
-
In any case, personal data will also be stored if the law (e.g., accounting or tax law) obliges the Administrator to process them; we will keep personal data longer in case the Customer has any claims against the Administrator, for the Administrator to assert claims, or for the Administrator to assert or defend against third-party claims, for the period of limitation prescribed by law, in particular the Civil Code.
-
Thus, depending on the scope of personal data and the purposes for which they are processed, they may be kept for different periods. In each case, the longer term of storage of personal data is decisive.
§ 7 ENTITLEMENTS, ACCESSING AND UPDATING PERSONAL DATA, COMPLAINTS
Pursuant to Article 15 of the RODO, you have the right to obtain from the Data Controller information on whether your personal data is being processed.
If the Administrator processes your personal data, then you have the right to:
-
access to personal data;
-
obtain information about the purposes of processing, the categories of personal data processed, the recipients or categories of recipients of such data, the intended period of storage of your data or the criteria for determining that period, your rights under the RODO and your right to lodge a complaint with a supervisory authority, the source of such data, automated decision-making, including profiling, and the safeguards applied in connection with the transfer of such data outside the European Union;
-
obtain a copy of your personal data. In addition, you may request that your personal data be corrected (Article 16 of the RODO), have your personal data deleted (Article 17 of the RODO), object to the processing of your personal data (Article 21 of the RODO), and, where technically feasible, request that the personal data provided be transferred to another organization (Article 20 of the RODO).
In connection with the right to be forgotten, the Administrator will update or delete your data, unless it has a legal obligation to retain it for business purposes or to comply with the law. In some cases, you have the right to request the restriction of the processing of your personal data (Article 18 of the DPA). You may also contact the Administrator if you have concerns about the collection, storage or use of your personal data.
The Administrator endeavors to promptly process any requests regarding the aforementioned operations on your personal data, but no later than within 30 days of receiving the request. Due to the complex nature of the request, the Administrator has the right to consider your requests in excess of 30 days, of which it will inform you in advance.
The Administrator strives to resolve complaints conclusively, but if you are still dissatisfied with the response you receive, you may file a complaint with your local data protection supervisory authority. In Poland, the supervisory authority under the RODO is the President of the Office for Personal Data Protection.
§ 8 PROCESSING OF PERSONAL DATA BY AUTOMATED MEANS, COOKIE POLICY
-
Our Web Site, like almost all other Web sites, uses cookies, or "cookies". The cookie policy applies to both Customers of the Online Store and Visitors to the Online Store, i.e. users who browse the contents of the Store but do not make purchases.
-
The Cookie Policy is a document that is an integral part of this Privacy Policy, which can be found at this link https://lattemama.eu/pl/i/Polityka-cookies/13.
§ 9 PRIVACY POLICY CHANGES
-
This Privacy Policy 2.0. is effective as of 01/03/2023.
-
The Administrator declares that he has the right to make changes to this document for important reasons, among others:
-
.changes in applicable laws, in particular in the area of RODO, telecommunications law, electronically provided services and regulating consumer rights, affecting the rights and obligations of the Controller or the rights and obligations of the data subject;
-
developments in functionality or electronic services due to advances in Internet technology, including the implementation of new IT, technological or technical solutions on the Website, affecting the scope of this Privacy Policy
-
The Administrator undertakes to inform Users of any changes in good time, allowing them to familiarize themselves with the content of the amended document, e.g. by posting the consolidated text of the Privacy Policy on the homepage of the Website.
-
In the case of users using the newsletter function, if the Administrator makes substantial changes to the content of the Privacy Policy, the Administrator will inform the Users of such changes by e-mail. In case of any objections to the change of the Policy, the user has the right to stop using the newsletter by sending a request to unsubscribe from the newsletter or by requesting the deletion of his/her personal data.