1. General Provisions
The controller of personal data collected through the website
The controller
You can contact us in the following ways:
• Email•
Your personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR).
In ensuring the protection of your personal data, we take special care to protect your interests, rights, and freedoms; in particular, we ensure that the data we collect is:
• Collected for specific, defined, and lawful purposes, only to the extent necessary to achieve those purposes, and not subject to further processing incompatible with those purposes.
• Processed in accordance with the law.
Purpose and scope of data collection
Your personal data is collected for the following purposes:
• To respond to inquiries submitted via the Contact Form. The legal basis for such processing is taking action at the request of the data subject prior to entering into a contract or contacting a party to a contract (GDPR Article 6(1)(b))
;• To fulfill an order placed through the online store. The legal basis for such processing is the processing of personal data of a person who is a party to a contract (GDPR Art. 6(1)(b));
• Storing data on commercial transactions for tax purposes. The legal basis for such processing is a legal obligation incumbent on the Controller (GDPR Art. 6(1)(c));
• Pursuing the controller’s legitimate interest in establishing, exercising, or defending potential claims (GDPR Article 6(1)(f)).
Categories of data we collect:
Regarding the user’s use of the website, we store HTTP requests sent to the server. The resources accessed are identified by their URLs and include:
• The public IP address of the end device from which the request originated;
• The user’s hostname—identification, if possible, is performed via the HTTP protocol;
• The time the request was received;
• The first line of the HTTP request;
• The HTTP response code;
• The amount of data sent by the server;
• Browser information;
• Information about errors that occurred during the execution of the HTTP transaction.
The above data is not associated with specific individuals browsing the www.laweczka.org website.
The website automatically collects only the information contained in cookies. The collected data is used for•
Server management.
• Analyzing aggregated user traffic on the website for statistical and marketing purposes, including through the use of Google Analytics and Facebook Pixel.
Categories of personal data processed in connection with responding to inquiries and order fulfillment:
• First and last name.
• Email address.
• Phone number.
• Residential address.
• Order delivery address.
• Order history• Bank
account number.
• Credit card number.
And in the case of entities making purchases in connection with business activities,
also• Company address and name.
• Tax ID number.
Providing this data is voluntary, but failure to do so will result in the inability to make a purchase through the store
Profiling and automated decision-making
The Controller uses cookies to track traffic on the website www.laweczka.org. Detailed information about cookies and profiling can be found in the Cookies section of this Privacy Policy.
Who may be recipients of your personal data Through our
contractor selection process, we ensure that every entity involved in the processing of your personal data has implemented appropriate technical and organizational measures commensurate with the risks associated with the entrusted activities.
In connection with payment processing, your data is transferred to the e-payment operator and the bank maintaining the Administrator’s account.
Additionally, for the purpose of printing materials and shipping the ordered design, the recipients of the data will be entities providing printing and logistics services to the Administrator.
We ensure that any person acting on our behalf and having access to your personal data keeps it confidential and processes it only on our instructions, unless other requirements arise from Union law or the law of a Member State.
How long will we process your data
? We minimize the retention period for your personal data that is no longer in use, meaning we process it only for the time necessary to decide whether further contact is appropriate, as well as for the time required to delete the data from backup copies.
Your personal data processed for the purpose of handling a request for quotation will be processed for the duration of the correspondence, after which, depending on the results of the negotiations, it will either be added to our customer database and processed in connection with the performance of the contract, or it will be deleted if it is not possible to establish cooperation.
Your personal data processed in connection with a purchase made via the website www.laweczka.org will be retained in the Administrator’s accounting records for a period of 7 years from the end of the calendar year in which the sale took place.
Data processed in connection with the establishment, pursuit, or defense of potential claims will be processed for the longest possible limitation period for claims arising from the concluded contract.
Rights of data subjects
Under the GDPR, you have the right to:
• request access to your data and receive a copy thereof;
• the right to rectify (correct) your data if it is incorrect or out of date, as well as the right to have it erased, provided that the processing is not necessary to fulfill a legal obligation;
• the right to data portability;
• the right to restrict or object to processing;
• the right to lodge a complaint with the President of the Personal Data Protection Office (at the address of the Personal Data Protection Office, ul. Stawki 2, 00–193 Warsaw).
How we ensure the processing of personal data
To meet legal requirements, we have developed and implemented detailed procedures covering issues such as
:• Risk analysis regarding the rights and freedoms of data subjects;
• Notification of breaches;
• Data retention;
• Record of data processing activities;
• Exercising the rights of data subjects;
• Selection of contractors. We
regularly review and update our documentation to demonstrate compliance with legal requirements in accordance with the principle of accountability set forth in the GDPR, but also, in the interest of data subjects, we strive to incorporate the recommendations of the Personal Data Protection Office and the European Data Protection Board (EDPB).
Cookies – draft list of cookies to be verified upon launching the website
Our website uses cookies. Cookies are stored on your device. They allow you to use all the features of the website. Cookies do not alter your device settings. The website’s cookies do not store confidential data such as your first name, last name, or address. To limit, block, or delete cookies from the website, use your web browser settings. Every browser is different, but you can find instructions on how to change your cookie preferences in the browser’s “Help” menu.
Cookies necessary for the website to function enable the use of its basic features, such as navigating the site. The website cannot function properly without these cookies.
_ connect.sid – a cookie that stores the user’s session, allowing the website to recognize the user and remember their actions, such as adding products to the cart, logging in (no need to log in every time you change pages), and browsing products. Without this cookie, the website may not function as intended. The cookie is stored in the browser for 30 days. The entity placing this file on the user’s device is the Administrator of the website www.laweczka.org. Statistical
cookies allow the website owner to observe and understand how visitors use the site by collecting and reporting anonymous information.
On the website www.laweczka.org, we use the following statistical cookies:
1. _ga – Used by the Google Analytics application. It records a unique identifier used to generate statistical data regarding how the user uses the website. This cookie is stored on the user’s device for 2 years.
2. _gat – Used by Google Analytics to throttle the request rate. This cookie is stored on the user’s device for
1 day. 3. _gid – Used by Google Analytics. It records a unique identifier used to generate statistical data regarding how the user uses the website. This cookie is stored for 1 day on the user’s device.
The administrator of the website www.laweczka.org does not profile the personal data of website users and does not subject them to automated decision-making processes. However, Google and Facebook may do so.
The website administrator uses the Google Analytics tool provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The legal basis for this activity is the administrator’s legitimate interest in creating and analyzing statistics to optimize the website’s performance.
Google Analytics collects information about website usage automatically.
The administrator has activated the function of partial anonymization of the user’s IP address, i.e., the website user’s IP address is truncated before being transferred outside the European Economic Area. The anonymized IP address transmitted by the user’s browser as part of Google Analytics is generally not combined with other Google data.
Since Google LLC is headquartered in the U.S. and uses technical infrastructure located in the U.S., it has joined the EU-U.S. Privacy Shield program to ensure the adequate level of personal data protection required by European regulations. Under the agreement between the U.S. and the European Commission, the latter has determined that Privacy Shield-certified companies provide an adequate level of data protection.
You can prevent Google from collecting data regarding your use of the website www.laweczka.org via cookies, as well as from processing this data, by installing the browser plugin available at the following address: https://tools.google.com/dlpage/gaoptout.
Details regarding data processing within Google Analytics can be found at: https://support.google.com/analytics/answer/6004245.
Facebook Pixel. The administrator of the www.housecollection.pl website uses marketing tools available through Facebook and provided by Facebook Inc., 1601 S. California Ave. Palo Alto, CA 94304, USA. As part of these tools, advertisements on Facebook are targeted to website users. Activities in this regard are carried out based on the Administrator’s legitimate interest in marketing its own products or services.
In order to target users with ads personalized based on their behavior on the website, the Administrator has implemented the Facebook Pixel, which automatically collects information about website usage regarding the pages viewed. The information collected in this manner is transmitted to Facebook’s servers in the United States or other countries and stored there.
The information collected by the Facebook Pixel does not allow the Administrator to identify website users; the Administrator receives only information regarding the actions the user has taken on the website. Facebook may combine this information with other information about the user collected through their use of the Facebook service and use it for its own purposes, including marketing. The Administrator has no influence over such actions by Facebook. Information about them can be found directly in Facebook’s privacy policy: https://www.facebook.com/privacy/explanation. You can also manage your privacy settings from your Facebook account.
Since Facebook Inc. is headquartered in the U.S. and uses technical infrastructure located in the U.S., it has joined the EU-U.S. Privacy Shield program to ensure the appropriate level of personal data protection required by European regulations. Under the agreement between the U.S. and the European Commission, the latter has determined that companies holding Privacy Shield certification provide an adequate level of data protection.
