PRINCIPLES OF PROCESSING PERSONAL DATA BY ALWERO Sp. z o.o. with its registered offices in Hecznarowice
We pay a lot of attention to protection of your personal data and handling it according to appropriate provisions of law, in particular according to the General Data Protection Regulation of 27 April 2016 (hereinafter “the GDPR”). Our purpose is to enable you to be fully informed and able to control in the scope of processing your personal data by us and to provide you with tools that help in exercising your rights resulting from provisions of law. Below you can find information on how we process your personal data, take care of its security and to whom we make it available. If you have any additional questions about how we use your personal data, please send us an email to the address: firstname.lastname@example.org
YOUR PERSONAL DATA OBTAINED BY US
We use your personal data, because you decided to make your purchase in our on-line store www.alwero.pl (“the Store”) or you agreed to receiving commercial information about the Store’s offer to the provided e-mail address, or you provided your data by the Store’s website. The Store conducts its activities according to the Regulations, which are available here.
THE CONTROLLER OF YOUR PERSONAL DATA
The Controller of your personal data is ALWERO Spółka z ograniczoną odpowiedzialnością, [limited liability company] located at Hecznarowice, ul. Krakowska 1, 43-330 Wilamowice, whose registration files are kept by the District Court in Bielsko-Biała, VIII Commercial Department of the National Court Register, KRS: 0000456429, NIP: 937 266 61 31. The share capital of the Company is: PLN 7 071,500.00 (paid up in whole) – (the „Controller” or „ALWERO”).
CONTACT WITH DATA PROTECTION REPRESENTATIVE
If you have any questions or doubts, you can always contact our Data Protection Representative by sending an email to the address: email@example.com or by traditional post to the address: Pełnomocnik ds. Ochrony Danych ALWERO Sp. z o.o. ul. Krakowska 1, 43-330 Hecznarowice.
PROCESSING YOUR PERSONAL DATA
If you use our Store, we will process your personal data in following purposes:
- a) performing contracts concluded with you for sale of products from the Store – the basis for processing your personal data in this case will be a contract concluded with the Controller expressed by accepting the Store’s Regulations. In this scope, we will require from you the largest amount of data, but only in the scope necessary to perform the sale contract and to deliver the purchased products; providing your personal data is not obligatory, but necessary to perform the contract,
- holding an account on the Store website – the basis for processing your personal data in this case will be the contract concluded with the Controller by creating an account and accepting the Store’s Regulations. Creating an account in Store enables you to gain access to the data provided by you, including your purchase history and to exercise some of the rights connected to data processing; providing your personal data is not obligatory, but necessary to perform the contract,
- conducting complaint processes – in this case the basis for processing is the Controller’s duty resulting from provisions of law, regarding statutory warranty for faults of the sold goods. Providing data in complaint form is obligatory to handle your complaint properly,
- commercial, if you provide a separate consent to that, by sending commercial information regarding products offered in the Store, including promotional offers to provided e-mail address – in this case the basis for processing is your consent which is not obligatory and you can revoke it at any time, by contacting at contact details listed above or by clicking the link, which is provided in every e-mail with commercial information. Revoking a consent has no impact on correctness of data processing in the period before the consent has been revoked.
- marketing by sending information on alwero.pl Store’s offer to provided e-mail address from time to time. The basis for processing your personal data in this scope will be our legitimate interest that is marketing of products indicated in the offer. You may object to processing your personal data in this purpose, and we will stop processing it. You may object by contacting us.
- statistical for interior needs of the Controller – in this case, the basis for processing is justified interest of the Controller, which consists in collecting information the enables developing business activity and adjusting services to the Store users’ needs.
- confirmation of performed duties and pursuing claims or for the defence from claims, which may be directed against us, preventing and detecting frauds – the basis for processing your personal data is legally justified interest of the Controller which is protection of rights, confirmation of performed duties and obtaining income due from clients for performed duties.
Your personal data will not be processed for the purposes of automated decision-making without your consent.
IS IT OBLIGATORY TO PROVIDE PERSONAL DATA?
It is your decision whether or not and what kind of data you provide, but you should remember that it will be obligatory to provide data to purchase products in the Store in order to perform sale contract, since without it we will not be able to process your order. Failure to provide the required data results in no order placed.
It is not obligatory to provide your consent to receive commercial information to the provided email address or telephone number for performance of the concluded sale contract. If you provide such a consent, you can revoke it at any time.
SHARING YOUR PERSONAL DATA
We will share your personal data with entities that cooperate with us while performing the sale contract of products purchased by you:
- depending on the selected manner of product delivery, we will share your data that is necessary to deliver goods to one of the following entities:
- GSL Poland Sp. z o.o.,
- Poczta Polska SA,
- other entities that in the future will deliver products purchased by you in the Store.
- depending on the selected payment method, we will share your data that is necessary to receive or provide payment to the following entities:
- one of the delivery companies listed above, if you have the selected „cash on delivery” payment,
- pl – if you have selected the payment system Cashbill/Paypal,
- mBank Polska SA – if you have selected a bank transfer as payment manner,
- other payment service providers, which will cooperate with us in order to provide us with price for products purchased by you.
- we may also share your personal data with other entities from above categories, which will cooperate with us,
PERIOD OF PROCESSING YOUR PERSONAL DATA
We will process personal data provided by you in the period:
- that is necessary to perform sale contract, as well as your complaint claims, and confirmation of performing our duties and pursuing claims, or in the defence from claims that may be directed against us – but no longer than 10 years from the date of providing us with your personal data,
- if you make a request for deleting your Store account we can process your data in the period that is necessary to confirm performing our duties, and pursuing claims, or in the defence of claims that may be directed against us – but no longer than 10 years from the date of providing us with your personal data.
PROTECTION OF YOUR PERSONAL DATA
We use various IT and organisational protections in order to minimise risk of data leakage, its damage, disintegration, such as: firewall system, antivirus and antispam software, internal procedures of access, data processing and disaster recovery, and also system of backups that operates on many levels. In our Store, we use high encryption level of HTTPS/SLL connections according to assumed best practices, we cooperate with a carefully selected web hosting service provider who holds certificates in quality management ISO 9001 and AQAP-2110 requirements, as well as certificate on management of information security pursuant to ISO/IEC 27001 norm. However, you should remember that using the Internet always poses a risk of some security incidents, but we assure you that due to implemented procedures of regular IT systems review, updating them and active monitoring of critical points of the system, we want to reduce this risk to the minimum.
RIGHTS RELATED TO PROCESSING YOUR PEROSNAL DATA BY US
Pursuant to GDPR, we have a number of rights with regard to providing us with your personal data, such as:
- the right to information on the manners in which data is processed – in case of any questions concerning whether and what kind of data we process, please contact us by shared on this website contact form or by sending information to the address of Data Protection Representative listed above: firstname.lastname@example.org or to email address: email@example.com, we will happily respond to your concerns,
- the right to access and update your data – you always have access to your personal data on your Store account. You can modify provided data and update it there. If you did not create an account, please contact us by contact form on this website or email our Data Protection Representative with request of accessing your data – we will provide you with information on which of your data is processed and we will update them upon your request.
- on principles determined in the GDPR, you also have the right to:
- remove your data – if you want us to stop processing your data, you can delete your Store account or send us a request to do so. However, you should remember that it is not an absolute right and we may object to remove your data, if we have a basis to process it (e.g. performing a legal duty or pursuing claims or in the defence from claims, which may be directed against us),
- request for reducing your data processing,
- object to processing your data, if the basis for processing is the legitimate interest of the Controller or performing tasks in public interest,
- revoke the consent, if the data is processed on the basis of your consent,
- data portability, if the data is processed on the basis of a contract or your consent.
INFORMATION ON A COMPETENT AUTHORITY FOR FILING A COMPLAINT
If you believe that we process your personal data unlawfully, you may file a complaint to The President of the Office of Data Protection
If you have any questions concerning processing of your personal data by us or you want to exercise your rights that result from the GDPR, please use contact form or contact our Data Protection Representative directly by: firstname.lastname@example.org or email@example.com