NESTHOST.PL ONLINE STORE PRIVACY POLICY
Chapter I
General Provisions
§ 1
The Controller of personal data collected via the online store www.nesthost.pl is Nikodem Król, conducting business activity under the business name NestHost NIKODEM KRÓL, Tax Identification Number (NIP): 4970098510, REGON: 545737980, address for service: Przyczyna Dolna 59, 67-400 Wschowa, e-mail address: [email protected], hereinafter referred to as the “Controller” and also acting as the “Service Provider”.
§ 2
Personal data collected by the Controller via the website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR.
§ 3
Any words or expressions capitalised in this Privacy Policy shall be understood in accordance with their definitions set out in the Terms and Conditions of the www.nesthost.pl online store.
Chapter II
Types of Personal Data Processed, Purposes and Scope of Data Collection
§ 4
The Controller processes personal data of Service Users of the www.nesthost.pl online store, hereinafter referred to as the “Store”, in the following cases:
-
registration of an Account in the Store, for the purpose of creating an individual account and managing that Account, pursuant to Article 6(1)(b) of the GDPR (performance of an agreement for the provision of electronic services in accordance with the Store Terms and Conditions);
-
placing an Order in the Store, for the purpose of performing the sales agreement, pursuant to Article 6(1)(b) of the GDPR (performance of the sales agreement);
-
performance of statutory obligations imposed on the Controller, in particular tax and accounting obligations (e.g. maintaining sales records), pursuant to Article 6(1)(c) of the GDPR;
-
use of the Contact Form, for the purpose of sending a message to the Controller, pursuant to Article 6(1)(f) of the GDPR (legitimate interest of the business operator).
§ 5
The Service User provides the following data in the case of:
-
an Account: first and last name, login, address, e-mail address;
-
an Order: first and last name, address, Tax Identification Number (NIP), e-mail address, telephone number;
-
the Newsletter: first and last name, e-mail address;
-
the Contact Form: first name, e-mail address.
§ 6
Personal data of Service Users is stored by the Controller:
-
where the legal basis for processing is performance of an agreement, for as long as necessary to perform the agreement and thereafter for a period corresponding to the applicable limitation period for claims. Unless a specific provision provides otherwise, the limitation period is six years, and for claims concerning periodic benefits and claims related to conducting business activity – three years;
-
where the legal basis for processing is consent, until such consent is withdrawn, and after withdrawal of consent for a period corresponding to the limitation period for claims that may be raised by the Controller and claims that may be raised against the Controller. Unless a specific provision provides otherwise, the limitation period is six years, and for claims concerning periodic benefits and claims related to conducting business activity – three years.
§ 7
When using the Store, additional information may be collected, including in particular: the IP address assigned to the Service User’s computer or the external IP address of the Internet service provider, domain name, browser type, access time and operating system type.
§ 8
Upon giving separate consent, pursuant to Article 6(1)(a) of the GDPR, data may also be processed for the purpose of sending commercial information by electronic means or making telephone calls for direct marketing purposes – respectively in connection with Article 10(2) of the Act of 18 July 2002 on the Provision of Electronic Services or Article 172(1) of the Act of 16 July 2004 – Telecommunications Law, including communications directed as a result of profiling, provided that the Service User has given the appropriate consent.
§ 9
Navigation data may also be collected from Service Users, including information about links and references they choose to click and other activities undertaken in the Store. The legal basis for such processing is the Controller’s legitimate interest pursuant to Article 6(1)(f) of the GDPR, consisting in facilitating the use of services provided electronically and improving the functionality of such services.
§ 10
Providing personal data by the Service User is voluntary.
§ 11
The Controller exercises particular care to protect the interests of data subjects and, in particular, ensures that the data it collects is:
-
processed lawfully;
-
collected for specified and lawful purposes and not further processed in a manner incompatible with those purposes;
-
accurate and adequate in relation to the purposes for which it is processed and stored in a form enabling identification of data subjects for no longer than necessary to achieve the purpose of processing.
Chapter III
Disclosure of Personal Data
§ 12
Personal data of Service Users is transferred to service providers used by the Controller in connection with operating the Store, including in particular:
-
payment system providers, in particular operators of the HotPay and CashBill systems;
-
the accounting office;
-
the hosting provider;
-
providers of software enabling business operations;
-
entities providing mailing systems;
-
providers of software necessary for operating the online store;
-
analytics and advertising service providers, in particular Google Ireland Limited, in connection with the use of Google Ads.
§ 13
Depending on contractual arrangements and circumstances, the service providers referred to in § 12 to whom personal data is transferred either act under the Controller’s instructions with respect to the purposes and means of processing such data (processors) or independently determine the purposes and means of processing such data (controllers).
§ 14
In connection with the use of services provided by external suppliers, in particular Google Ads, data may be processed outside the European Economic Area. Data transfers are carried out using mechanisms required by applicable law, in particular on the basis of an adequacy decision, the EU-U.S. Data Privacy Framework or standard contractual clauses approved by the European Commission.
Chapter IV
Right to Control, Access and Rectify Personal Data
§ 15
The data subject has the right to access their personal data and the right to rectify or erase such data, restrict its processing, exercise the right to data portability, object to processing, and withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
§ 16
The legal bases for the Service User’s requests are:
-
access to data – Article 15 of the GDPR;
-
rectification of data – Article 16 of the GDPR;
-
erasure of data (the so-called “right to be forgotten”) – Article 17 of the GDPR;
-
restriction of processing – Article 18 of the GDPR;
-
data portability – Article 20 of the GDPR;
-
objection – Article 21 of the GDPR;
-
withdrawal of consent – Article 7(3) of the GDPR.
§ 17
In order to exercise the rights referred to in § 16, an appropriate e-mail may be sent to: [email protected].
§ 18
Where a Service User exercises any of the rights referred to above, the Controller shall comply with the request or refuse to comply without undue delay, and in any event no later than within one month of receiving the request. However, where due to the complexity or number of requests the Controller is unable to comply with the request within one month, it shall comply within a further two months, having first informed the Service User, within one month of receiving the request, of the intended extension of the deadline and the reasons for it.
§ 19
Where the data subject determines that the processing of personal data infringes the provisions of the GDPR, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office.
Chapter V
Cookies and Similar Technologies
§ 20
-
The NestHost.pl website uses cookies and similar technologies, including browser local storage.
-
Necessary cookies and similar technologies are used to ensure proper operation of the website, security, maintenance of the user session, login functionality, shopping cart functionality, payment processing and Order fulfilment.
-
Optional cookies and advertising technologies are used only after obtaining the user’s consent.
§ 21
- The website uses:
A. necessary cookies and similar technologies, the operation of which is required in order to use the website’s basic functions;
B. optional advertising and measurement technologies which help the Controller measure the effectiveness of advertising and improve its offer.
- Refusal to consent to optional advertising technologies does not restrict the ability to use the website or place Orders.
§ 22
-
After obtaining the user’s consent, the Controller uses Google Ads provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
-
Google Ads is used to determine whether a user’s visit resulting from an advertisement led to payment for an Order and to measure the effectiveness of advertising campaigns.
-
In connection with the use of Google Ads, information concerning the device and browser, IP address, advertising click identifier, information concerning interaction with the website, the value of the paid Order and the transaction identifier may be processed.
-
The Controller does not transmit the user’s first name, last name, e-mail address, login credentials or payment details as part of the conversion event.
-
Detailed information concerning data processing by Google is available at: https://policies.google.com/privacy
§ 23
-
The legal basis for processing data using optional advertising technologies is the user’s consent pursuant to Article 6(1)(a) of the GDPR.
-
Optional advertising technologies remain disabled by default until consent is given.
-
The user may accept or reject optional technologies using the notice displayed on the website.
-
The user’s decision is stored in the browser’s memory so that the notice is not displayed during every visit.
§ 24
-
The user may change or withdraw consent at any time using the “Privacy Settings” option available on the website.
-
Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
-
The user may also delete cookies and data stored in local storage using their browser settings.
Chapter VI
Final Provisions
§ 25
The Controller applies technical and organisational measures ensuring a level of protection of the processed personal data appropriate to the risks and categories of data being protected and, in particular, protects the data against disclosure to unauthorised persons, acquisition by unauthorised persons, processing in breach of applicable provisions, and alteration, loss, damage or destruction.
§ 26
The Controller provides appropriate technical measures to prevent unauthorised persons from obtaining or modifying personal data transmitted electronically. In matters not regulated by this Privacy Policy, the provisions of the GDPR and other applicable provisions of Polish law shall apply accordingly.