Privacy policy
In order to ensure full transparency in the operation of the Winshop.pl online store we present below information on the principles and methods of processing personal data, as well as on the rights to which you are entitled in relation to data processing. We make every effort to ensure that personal data is processed in accordance with generally applicable laws, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27.04.2016, on the protection of natural persons in relation to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("RODO").
What is personal information?
Personal data is information about an identified or identifiable natural person (e.g., name, surname, telephone number, email address, home address, tax ID and REGON number, bank account number).
What is personal data processing?
Personal data processing is any activity performed on personal data (e.g. collection, storage, analysis, deletion). We collect and process personal data only to the extent necessary to fulfill the specified purposes.
Who is the Administrator of your personal data?
The administrator of your personal data is the entity operating the Winshop.pl online store: Adrian Chmiała, running business under the name of CSC Adrian Chmiała in Bielsko-Biała, Klemensa Matusiaka 9 lok. 5, 43-30 Bielsko-Biała, NIP: 5472159147, REGON: 363927840.
How can I contact you regarding the processing of personal data?
The Data Controller can be contacted:
- by post to the address: 27 Kasztelańska Street, 30-116 Kraków
- via email: info@winshop.pl
What is your personal data being processed, for what purposes and on what basis?
The Administrator offers various types of services to customers, related to the operation of the Online Store, and undertakes various activities related to sales. Depending on the type of activities the Administrator processes different personal data.
Purpose: Account registration in the Online Store.
By registering an Account with the Online Store you provide us with personal information in the form of your name, email address, telephone number, home or mailing address, as well as your business information (if applicable).
This data is processed in the case of a contract for electronic delivery:
- to which you are a party, on the basis of Article 6(1)(b). RODO
- which has been concluded with other entities for the purpose of realizing the legitimate legal interests of the Administrator consisting in the conclusion and execution of contracts, on the basis of Article 6(1)(f). RODO
Purpose: Fulfillment of the sales contract
When you make a purchase in the Online Store you provide us with personal data in the form of: your name, email address, telephone number, home or mailing address, business details (if applicable). When making a payment for products purchased in the Online Store using a bank account or other online payment method you provide us with personal data in the form of: transfer sender's data and bank account number or other data identifying the payment depending on the chosen payment method.
This data is processed in the case of a sales contract:
- to which you are a party, on the basis of Article 6(1)(b). RODO
- which has been concluded with other entities in order to realize the legitimate legal interests of the Administrator consisting in the conclusion, execution and settlement of contracts, on the basis of Article 6(1)(f). RODO
With regard to the fulfillment of the Administrator's legal obligations, and in particular with regard to invoicing/accounting, we process your personal data on the basis of Article 6(1)(b).c. RODO.
Purpose: Newsletter service
By using the Newsletter service, you provide us with personal data in the form of your email address.
This data is processed when you use the Newsletter service:
- by you personally, on the basis of Article 6(1)(b). RODO
- by another Entity where you are employed or which you represent for the purpose of realizing the legitimate legal interests of the Administrator to send the Newsletter in accordance with the Customer's request, on the basis of Article 6.1.f. RODO
- based on the consent given, on the basis of Article 6(1)(a). RODO
Purpose: Contacting customers and establishing cooperation, handling complaints
If you make contact with the Online Store we may also process other personal data provided by you in the content of directed correspondence or provided by telephone.
In the case of complaints we may also process other personal data provided by you in the content of the correspondence you send us.
This data is processed:
- to provide a response with reference to the consent you have given, on the basis of Article 6(1)(a). RODO
- to take action at the request of the data subject prior to entering into a contract, based on Article 6(1)(b). RODO
- for realization of the legitimate legal interests of the Administrator related to the investigation or defense against claims, related to the established contact and the actions taken in its course, on the basis of Article 6 (1) f. RODO
Personal data in all the above-mentioned spheres may additionally be processed with regard to the investigation, establishment, defense against claims and archiving of documentation relating to the services provided and to the performance of concluded contracts. In that case, we process your personal data due to the legitimate interest of the Administrator, based on Article 6(1)(f). RODO.
In addition, in connection with the operation of the Online Store, we may also obtain data of a technical nature, including those that are recorded automatically during the use of the Online Store. The rules for collecting this data are described in the Cookie Policy available on the website.
Do you have to share your personal information?
Providing data is voluntary but necessary to use the Account, make purchases in the Online Store, use the Newsletter service, also to process complaints.
How long will your personal data be processed?
The period of data processing depends on the legal basis for processing and is:
- data processed for the purpose of providing electronic services (Account, Newsletter): until the Account is deleted or until the Newsletter service is cancelled
- data processed for the purpose of performance and settlement of sales contracts, as well as on the basis of the legitimate legal interest of the Administrator, with regard to the investigation, establishment and defense against claims: up to 3 months after the statute of limitations for claims or until the data subject objects to further such processing - in situations where such objection is entitled under the law
- data processed due to legal obligations (including for tax and accounting purposes): for the period specified by generally applicable laws
To whom is your personal data transferred?
Personal data related to the functioning of the Online Store may be transferred to: entities providing hosting services, providing technical support for the website run by the Administrator, entities providing ICT services.
Personal data related to the conclusion and execution of sales contracts may be transferred to: entities handling the payment and delivery process, entities providing accounting and bookkeeping services, entities providing legal or tax services.
Personal data may also be transferred to public authorities in cases provided for by generally applicable laws. Personal data will not be transferred to a third country or international organization.
Based on the personal data no decisions will be made with respect to the Customers in an automated manner, including decisions resulting from profiling.
Personal data may also be transferred to public authorities in cases provided for by generally applicable laws.
Personal data will not be transferred to a third country or international organization.
Will personal data be processed by automated means?
The information we collect in connection with the use of the Online Store may be processed by automated means (including profiling), however, this will not have any legal effect or materially affect the individual. For automated data processing we use information about purchases made and cookie files. This information is used for analytical purposes related to improving the functioning of the Website and the Administrator's activities, as well as for marketing purposes and tailoring marketing information to individual preferences.
Will personal data be processed securely?
The Administrator shall take all security and data protection measures required by data protection regulations. Personal data are collected with due diligence and are properly protected from access by unauthorized persons. The Administrator's IT systems are secured through appropriate technical and organizational measures to protect data from loss or unlawful dissemination.
What are your rights?
You have rights regarding the processing of your personal data:
- The right to access the data and to receive a copy of the processed personal data
- The right to request rectification of data
- The right to request erasure of data, to object to data processing or to restrict data processing in cases provided by law
- The right to data portability
- The right to withdraw consent to the processing of personal data
- The right to lodge a complaint with the supervisory authority - the President of the Office for Personal Data Protection if it is determined that personal data is being processed illegally