Privacy Policy
This Privacy Policy sets out the principles for processing personal data obtained through the website marlenabulak.pl, hereinafter referred to as the “Website.” The owner of the Website and the Data Controller is Merlin Hondentrimsalon, hereinafter referred to as the Administrator. Personal data collected by the Administrator via the Website is processed in accordance with the Regulation of the European Parliament and the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as GDPR. The Administrator takes special care to respect the privacy of the clients visiting the Website.
1. Types of Data Processed, Purposes, and Legal Basis
The Administrator collects information regarding natural persons performing a legal act not directly related to their business, natural persons conducting business or professional activity in their own name, and natural persons representing legal persons or organizational units that are not legal persons to whom the law grants legal capacity, conducting business or professional activity in their own name, hereinafter collectively referred to as Clients.
Personal data of Clients is collected in the case of:
- using the contact form service on the Website to perform an electronic service agreement. Legal basis: necessity to perform the contact form service agreement (Article 6(1)(b) GDPR).
In the case of using the contact form service, the Client provides the following data:
- email address
- name
- phone number
During the use of the Website, additional information may be collected, in particular: the IP address assigned to the Client’s computer or external IP address of the Internet provider, domain name, browser type, access time, type of operating system. Navigational data may also be collected from Clients, including information about links and references they decide to click or other actions taken on the Website. Legal basis: legitimate interest (Article 6(1)(f) GDPR), consisting in facilitating the use of electronic services and improving the functionality of these services. Providing personal data to the Administrator is voluntary.
2. To whom and for how long are data disclosed or entrusted?
Personal data of the Client is transferred to service providers used by the Administrator in operating the Website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either act on the Administrator’s instructions regarding the purposes and means of processing these data (processors) or determine the purposes and means of processing on their own (controllers).
2.1. Processors. The Administrator uses service providers who process personal data exclusively on the Administrator’s instructions. These include, among others, providers of hosting services, accounting services, marketing systems, web traffic analysis systems, and systems for analyzing the effectiveness of marketing campaigns.
2.2. Controllers. The Administrator uses service providers who do not act solely on the Administrator’s instructions and determine the purposes and means of using Clients’ personal data on their own. They provide electronic payment and banking services.
Location. Service providers are mainly based in Poland and other countries of the European Economic Area (EEA). Personal data of Clients is stored:
3.1. If the legal basis for processing personal data is consent, then the personal data of the Client is processed by the Administrator as long as the consent is not withdrawn, and after withdrawal of consent for the period corresponding to the statute of limitations for claims that may be raised by the Administrator and which may be raised against him. Unless a special provision states otherwise, the statute of limitations is six years, and for periodic benefits and claims related to business activity – three years.
3.2. If the legal basis for data processing is the performance of a contract, then the personal data of the Client is processed by the Administrator as long as it is necessary to perform the contract, and after that time for the period corresponding to the statute of limitations for claims. Unless a special provision states otherwise, the statute of limitations is six years, and for periodic benefits and claims related to business activity – three years.
Upon request, the Administrator provides personal data to authorized state authorities, in particular, organizational units of the Prosecutor’s Office, the Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
3. Cookies Mechanism, IP Address
The Website uses small files called cookies. They are saved by the Administrator on the end device of the person visiting the Website, if the web browser allows it. A cookie file usually contains the name of the domain it comes from, its “expiration time,” and an individual, randomly selected number identifying this file. The information collected by files of this type helps to adjust the products offered by the Administrator to the individual preferences and actual needs of the people visiting the Website. The Administrator uses two types of cookies:
3.1. Session cookies: after the end of a browser session or turning off the computer, the saved information is removed from the device’s memory. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from Clients’ computers.
3.2. Persistent cookies: they are stored in the memory of the Client’s end device and remain there until they are deleted or expire. The mechanism of persistent cookies does not allow the collection of any personal data or any confidential information from the Client’s computer.
The Administrator uses own cookies for the purpose of:
**3.1. Analysis, research, and audit of viewership, in particular to create anonymous statistics that help understand how Clients use the Website, which enables improving its structure and content.
The Administrator uses external cookies for the purpose of:
4.1. Presenting on the informational pages of the Website, a map indicating the location of the Administrator’s office, using the online service maps.google.com (administrator of external cookies: Google Inc. based in the USA).
The cookies mechanism is safe for the computers of the Clients visiting the Website. In particular, it is not possible for viruses or other unwanted or malicious software to enter Clients’ computers this way. Nevertheless, Clients have the option to restrict or disable the access of cookies to their computers in their web browsers. If this option is used, the use of the Website will be possible, except for functions that by their nature require cookies.
The Administrator may collect Clients’ IP addresses. An IP address is a number assigned to the computer of a person visiting the Website by the Internet service provider. The IP number allows access to the Internet. In most cases, it is assigned to the computer dynamically, i.e., it changes with each connection to the Internet and for this reason, it is commonly considered as non-personal identifying information. The IP address is used by the Administrator in diagnosing technical problems with the server, creating statistical analyses (e.g., determining from which regions we have the most visits), useful in managing and improving the Website, and also for security purposes and possible identification of unwanted automated programs for viewing the content of the Website.
4. Rights of Persons Whose Data is Processed
4.1. Right to withdraw consent – legal basis: Article 7(3) GDPR.
- The Client has the right to withdraw any consent they have given.
- The withdrawal of consent has an effect from the moment of withdrawal.
- The withdrawal of consent does not affect the processing carried out by the Administrator in accordance with the law before its withdrawal.
- Withdrawal of consent does not entail any negative consequences for the Client, but it may prevent further use of services or functionalities that the Administrator can only provide with consent.
4.2. Right to object to data processing – legal basis: Article 21 GDPR.
- The Client has the right to object at any time – for reasons related to their particular situation – to the processing of their personal data, including profiling, if the Administrator processes their data based on a legitimate interest, e.g., marketing products and services of the Administrator, keeping usage statistics of particular functionalities of the Website and facilitating the use of the Website, as well as satisfaction surveys.
- The resignation in the form of an email from receiving marketing communications regarding products or services will mean the Client’s objection to the processing of their personal data, including profiling for these purposes.
- If the Client’s objection turns out to be justified and the Administrator has no other legal basis for processing personal data, the Client’s personal data against the processing of which the objection was raised will be deleted.
4.3. Right to data erasure (“right to be forgotten”) – legal basis: Article 17 GDPR.
- The Client has the right to request the deletion of all or some personal data.
- The Client has the right to request the deletion of personal data if:
- The personal data are no longer necessary for the purposes for which they were collected or otherwise processed.
- The consent on which the processing is based has been withdrawn and there is no other legal ground for the processing.
- An objection has been raised to the use of the data for marketing purposes.
- The personal data are processed unlawfully.
- The personal data must be erased to comply with a legal obligation provided by the law of the Union or the Member State to which the Administrator is subject.
- The personal data have been collected in relation to the offer of information society services.
Despite the request to delete personal data, in connection with the objection or withdrawal of consent, the Administrator may retain certain personal data to the extent that the processing is necessary to establish, assert, or defend claims, as well as to comply with a legal obligation requiring processing under the law of the Union or the Member State to which the Administrator is subject. This applies in particular to personal data including: name, surname, email address, which are kept for the purpose of handling complaints and claims related to the use of the Administrator’s services, or additionally, address of residence/address for correspondence, order number, which are kept for the purpose of handling complaints and claims related to concluded sales agreements or the provision of services.
4.4. Right to restrict data processing – legal basis: Article 18 GDPR.
- The Client has the right to request the restriction of the processing of their personal data. Submitting a request prevents the use of certain functionalities or services that involve data processing covered by the request. The Administrator will not send any communications, including marketing ones.
- The Client has the right to request the restriction of the use of personal data in the following cases:
- When the accuracy of personal data is questioned – the Administrator will restrict their use for the time needed to verify the accuracy of the data, no longer than 7 days.
- When data processing is unlawful and instead of deleting the data, the Client requests the restriction of their use.
- When the personal data are no longer necessary for the purposes for which they were collected or used, but are needed by the Client to establish, assert, or defend claims.
- When an objection has been raised to the use of data – the restriction will take place for the time needed to consider whether – due to the special situation – the protection of the Client’s interests, rights, and freedoms prevails over the interests pursued by the Administrator, processing the Client’s personal data.
4.5. Right of access to data – legal basis: Article 15 GDPR.
- The Client has the right to obtain from the Administrator confirmation whether personal data concerning them are being processed, and if so, the Client has the right:
- To access their personal data.
- To obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of these data, the planned period of storage of the Client’s data or the criteria for determining this period (if it is not possible to determine the planned period of processing), the rights vested in the Client under GDPR and the right to lodge a complaint with a supervisory authority, the source of these data, automated decision-making, including profiling, and the safeguards used in connection with the transfer of these data outside the European Union.
- To obtain a copy of their personal data.
4.6. Right to rectify data – legal basis: Article 16 GDPR.
- The Client has the right to request the Administrator to promptly rectify their personal data that are inaccurate. Taking into account the purposes of processing, the Client has the right to request the completion of incomplete personal data, including by submitting an additional statement, by sending a request to the email address in accordance with §6 of the Privacy Policy.
4.7. Right to data portability – legal basis: Article 20 GDPR.
- The Client has the right to receive their personal data, which they have provided to the Administrator, and then send them to another data controller of their choice. The Client also has the right to request that personal data be sent directly by the Administrator to such a controller, if technically possible. In this case, the Administrator will send the Client’s personal data in the form of a csv file, which is a commonly used, machine-readable format and allows for the transfer of the received data to another data controller.
In the event of the Client exercising the rights arising from the above rights, the Administrator complies with the request or refuses to comply with it immediately, but no later than within a month of receiving it. If, due to the complex nature of the request or the number of requests, the Administrator is unable to comply with the request within a month, it will comply within the next two months, informing the Client in advance within a month of receiving the request – about the intended extension of the deadline and its reasons. The Client may submit complaints, inquiries, and requests to the Administrator regarding the processing of their personal data and the exercise of the rights granted to them. The Client has the right to lodge a complaint with the President of the Personal Data Protection Office, regarding the violation of their rights to the protection of personal data or other rights granted under GDPR.
5. Changes to the Privacy Policy
The Privacy Policy may change, about which the Administrator is not obliged to inform. Questions related to the Privacy Policy should be directed to: marlenitosss@gmail.com Date of the last modification: 30.07.2024