This privacy policy (hereinafter: “Policy”) applies to the website with the domain www.POIfantastic.eu (hereinafter: “Website”) and serves to inform Users about the rules of processing their personal data as well as about their rights.
AND DEFINITIONS.
Personal data – all information about a natural person identified or identifiable by one or more specific factors determining physical, physiological, genetic, mental, economic, cultural or social identity. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC. User – any natural person visiting the Online Store or using one or more services or functionalities described in the Policy. Profiling – any form of automated processing of personal data, which consists in using personal data to evaluate certain personal factors of a natural person.
II STORAGE AND PROTECTION OF PERSONAL DATA.
Personal data is processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage, using appropriate technical or organizational measures. In order to ensure proper protection of personal data, the Website is secured with a certificate
III PERSONAL DATA ADMINISTRATOR
The administrator of personal data processed via the Website is the company: POIfantastic.eu, Marek Oleksiak, ul. Tysiąclecia 9/1 m 24, 09-400 Płock, conducting unregistered activity (hereinafter referred to as: “Administrator”). The representative of the Administrator is Marek Oleksiak. Contact with the Administrator is possible via the contact form available on the website or at kontakt@poifantastic.eu
IV PURPOSES AND LEGAL BASIS FOR DATA PROCESSING.
Below is a detailed description of Users’ personal data that will be processed by the Website when using its website, with an explanation of the purposes and legal basis for their processing.
In order to enable registration on the Website, the Administrator processes the following data:
1) Name and Surname,
2) e-mail address,
3) password.
Providing the above-mentioned personal data is voluntary, but necessary to set up a User account. Refusal to provide the above-mentioned personal data will result in the inability to conclude the contract.
Legal basis for data processing: taking action at the request of the data subject (Article 6(1)(b) of the GDPR).
Data storage period: the period of existence of the User’s account, and after this period, the data will be stored for the period resulting from the limitation of potential claims (e.g. three years if personal data relate to other entrepreneurs with whom contracts have been concluded in connection with conducting business activity – art. 118 CC).
In order to facilitate contact with the Administrator, Users may provide a telephone number.
Legal basis for data processing: User’s consent (Article 6(1)(a) of the GDPR).
Data storage period: data will be stored until the consent is withdrawn, but no longer than for the period resulting from the limitation of potential claims (e.g. three years if personal data relate to other entrepreneurs with whom contracts have been concluded in connection with conducting business activity – art. 118 CC).
In order to place an order, the User provides the following data:
1) Name and Surname,
2) e-mail address.
Providing the above-mentioned personal data is voluntary, but necessary to place an order. Refusal to provide data will result in the inability to conclude the contract.
Legal basis for data processing: the necessity of processing to perform the contract (Article 6(1)(b) of the GDPR).
Data storage period: the period necessary to perform the contract, and after this period, the data will be stored for the period resulting from the limitation of potential claims (e.g. three years if personal data relate to other entrepreneurs with whom contracts have been concluded in connection with conducting business activity – Article 118 of the Civil Code).
In order to make a payment for the placed order, the User provides the following data:
personal data required by payment systems through which the User can pay for the order placed.
The above-mentioned personal data is processed in accordance with the privacy policy of payment system owners.
In order to be able to issue a Bill, Users may provide:
1) full company name,
2) tax identification number.
Providing the above-mentioned data is not necessary for the performance of the contract.
Legal basis for data processing: User’s consent (Article 6(1)(a) of the GDPR), performance of the contract (Article 6 of the