PRIVACY POLICY
Dear Sirs, we are very pleased to welcome you to our website. We attach great importance to the protection of your personal data, and we want you to feel completely secure when visiting the CoolSens.eu website.
Below you will find an explanation of the type of personal data we collect when you visit the website and how we process it.
The following Privacy Policy is intended to inform you of our use of your personal data, in respect of which we comply with all the requirements of Regulation (EU) 2016/679 EU of the European Parliament and of the Council of 27 April 2016. (hereinafter: “RODO”).
Any comments concerning the Privacy Policy, processing of personal data or otherwise may be addressed to the Data Protection Officer: e-mail: abi@inventia.pl or directly to the address Inventia Sp. z o.o., Poleczki 23, 02-822 Warsaw.
PERSONAL DATA CONTROLLER
The Administrator of the Personal Data is Inventia Sp. z o.o. with its registered office in Warsaw (02-822), Poleczki No. 23, entered in the Register of Entrepreneurs of the National Court Register, kept by the District Court in Warsaw, 13th Commercial Division of the National Court Register under KRS number 0000023113, with the share capital of PLN 50,000, NIP 9512017534, REGON 017311391, hereinafter referred to as the “Administrator”.
GENERAL INFORMATION
The use of the website does not require you to provide any personal data. Your provision of personal data is voluntary, but may be necessary in order to use certain services, such as the Newsletter service.
The website contains links to other websites. We urge you, when you go to other sites, to read the privacy policy established there.
Please be advised that your use of the website implies your acceptance of this Privacy Policy.
If you wish to contact us without providing your personal data in electronic form, please send a letter to: Poleczki Street 23, 02-822 Warsaw.
SCOPE OF DATA PROCESSED
Personal data means information about an identified or identifiable natural person (website user).
These include direct user information such as:
- name;
- e-mail address;
- position;
- company name;
- business address;
- NIP number;
- telephone number;
- IP address.
PURPOSES OF DATA PROCESSING WITH LEGAL BASIS
Your personal data may be processed by the Administrator on the basis of:
- Necessity for the performance of the contract or for taking steps prior to the conclusion of the contract (Article 6(1)(b) RODO), including the processing of complaints or the operation of the User Account.
- consent (Article 6(1)(a) of the RODO), in order to:
-
- the provision of a newsletter service;
- the use of contact forms on the website;
- to carry out the Administrator’s marketing;
- sending surveys about the Administrator’s products or services;
- sending questionnaires to measure customer satisfaction;
-
- legitimate interest of the Administrator (Art. 6(1)(f) RODO), for the purpose of:
- defence against possible claims, where the Administrator’s legitimate interest is the assertion or defence of claims;
- create a list of contractors.
DATA TRANSMISSION
Personal data may be transferred to entities processing them on behalf of the Administrator on the basis of contracts concluded with the Administrator, but only for the purpose and to the extent necessary to fulfil the purposes listed in the PURPOSES OF DATA PROCESSING paragraph, with such entities processing the data only in accordance with the Administrator’s instructions.
If the transfer of personal data to an external service provider is necessary for the aforementioned purposes then the Controller will ensure, by means of appropriate technical and organisational measures, that the processing of the personal data complies with the data protection legislation (RODO). Furthermore, the Administrator will oblige the external service providers to comply with the applicable data protection legislation, to maintain the confidentiality of this personal data and to delete it without undue delay when it is no longer needed.
Personal data may be transferred to the following recipients or categories of recipients:
- service providers who supply the Administrator with technical, IT and organisational solutions which enable the Administrator to run his business, including the website (in particular e-mail and hosting providers, marketing activities, Newsletter sending and providing technical support to the Administrator);
- marketing service providers – marketing agencies providing support to the Administrator in marketing activities;
- providers of accounting, legal, advisory or translation services that provide accounting, legal, advisory or translation support to the Administrator (in particular an accountancy office, a law firm or a translation agency).
We may transfer data to entities in countries based outside the European Union (EU) or the European Economic Area (EEA) (so-called third countries) that act as a contract processor on behalf of the Controller (e.g. IT service providers or computing centres).
The Administrator then verifies whether an EU Commission decision on the applicable adequate level of data protection is available for the specific country. If a decision of the EU Commission on the adequate level of data protection applicable there is not available for a specific country, then we conclude agreements in accordance with the EU data protection guidelines that provide adequate protection and guarantee your rights and freedoms. Furthermore, we do not transfer personal data to other countries outside the EU or EEA or to international organisations.
SOCIAL PLUG-INS
Personal data is only transmitted to the social media sites if you take the active step of clicking on the relevant page element containing the social media link. When you click on the link, your internet browser will initiate a connection to the servers of the respective social network and you will be redirected to the website of the external service provider, i.e. the owner of the respective social network. At the same time, your internet browser will establish a direct connection to the servers of the selected social network. The use of these functions may involve the use of external cookies. From the moment you click on the respective link, your personal data is processed on the social network and the owner of the social network becomes the co-controllers of your personal data. The Administrator informs you that from the moment the plug-in button is actively clicked, the Administrator has no influence on the nature and scope of the personal data collected by the owner of the respective social network.
The data is transmitted irrespective of whether you have an account on the respective social network or whether you are logged in. In the event that you are logged in on the respective social media platform, the personal data collected will be directly assigned to the account (profile) used.
If you are a user of a particular social network and do not want the social network to collect data via this website or application and link this data to member data stored on the social network, you must log out of the social network before visiting the website or application.
Details of the individual privacy policies are available here:
YouTube: YouTube privacy settings – How YouTube works
LinkedIn: LinkedIn Privacy Policy
RETENTION PERIOD
The personal data you provide to us will be retained for the period required for the purposes for which it was collected or as required by law.
USERS' RIGHTS
To exercise the rights described below, please contact .abi@inventia.pl
Right of access to your personal data
You have the right to obtain information regarding the personal data we hold about you, including a copy of that data.
Your right to rectification of your personal data
You have the right to request the rectification of your personal data that is incorrect. Taking into account the purposes of the processing, you have the right to request the completion of incomplete personal data, including by providing an additional statement.
Right to erasure of your personal data
You have the right to request the deletion of your personal data held by us in the following cases:
- Your personal data is no longer necessary for the purposes for which it was collected;
- you have withdrawn the consent on which the processing is based and there is no other legal basis for the processing;
- you have lodged an objection to the processing and there are no overriding legitimate grounds for the processing;
- personal data were processed unlawfully;
- personal data must be deleted in order to comply with a legal obligation under Union or national law;
- personal data was collected in connection with the offering of information society services, as referred to in Article 8(1) of the RODO.
Your right to data portability
You have the right to receive in a structured, commonly used, readable format the personal data relating to you that you have provided to us, if the processing of this data is based on consent or contract and by automated means.
If you request that this data be sent to another data controller, this will be done, provided that this is technically possible.
Right to restrict the processing of your data
You have the right to request that the processing of your personal data be restricted, in the following cases:
1. you question the accuracy of your personal data, for a period allowing us to check the accuracy of the data;
2. processing is unlawful and you object to the erasure of the personal data, requesting instead that the use of the data be restricted;
3. we no longer need your personal data for the purposes of processing, but you need them to establish, assert or defend your claims;
4. you have raised an objection under Article 21(1) to the processing – until such time as it is determined whether the legitimate grounds on the part of the controller override the grounds for the objection.
The right to object to the processing of your personal data
If your personal data is processed on the basis of a legitimate interest of the controller, you have the right to object at any time to the processing, in accordance with Article 21 of the DPA.
Right to withdraw your consent to the processing of your personal data
You have the right to withdraw your consent to the processing of your personal data at any time. The withdrawal of your consent to processing will not affect the lawfulness of the processing carried out before the withdrawal.
Right to report violations of the RODO provisions
The security of your personal data is a priority for us, however, if you consider that we are in breach of the RODO by processing your personal data, you have the right to lodge a complaint with the President of the Data Protection Authority.
PROFILING
The administrator may automatically tailor certain content to your needs, i.e. perform profiling, using the personal data you have provided.
In the event that profiling could result in decisions that produce legal effects against you or affect you in a similarly significant manner, the Administrator will only carry out such profiling if you have given your consent.
SECURITY
The Administrator has implemented generally accepted technical and organisational security standards to protect personal data and information against loss, misuse, alteration and destruction. In particular, we ensure compliance with all relevant confidentiality obligations and technical and organisational security measures to prevent unauthorised and unlawful disclosure and processing of such information and data and their accidental loss, destruction or damage. Only authorised employees or associates of the controller, who have undertaken to maintain the confidentiality of such data, have access to identifying personal data.
The controller shall endeavour to ensure that data processing is carried out on the basis of the following principles :
- lawful, reliable and transparent;
- collected for specific and legitimate purposes and not further processed in a way incompatible with those purposes;
- adequate, relevant and limited to what is necessary for the purposes for which they are processed;
- correct and updated as necessary;
- kept in a form which permits identification of the data subject for no longer than is necessary for the purposes for which the data are processed;
- processed in a manner that ensures adequate security of personal data;
- in such a way as to ensure that the rights of data subjects are realised.
Your data is stored by the Administrator in a secure operating environment with no public access. It is a relational database maintained in the Amazon Web Services, Inc. cloud within the European Union. The online shop communicates with the database server and sends data via the secure https protocol. User data is secured and passwords are encrypted.
COOKIE POLICY
We use cookies and similar technologies to establish your preferences our and optimise the website. All details regarding cookies are available under the Cookie Policy link.
CHANGES TO THE PRIVACY POLICY
The Administrator reserves the right to update or change this Privacy Policy at any time by publishing a new version on the CoolSens.eu website, so please check the content of this Privacy Policy regularly.