Privacy policy website

We care for the protection of personal data every day, hence, we passionately strive to care for the safety and comfort of the Users of our Website each day. And since we know, how important for you the protection of personal data and the right to privacy is – we also value our privacy.

For this reason, this document outlines important information on the issues of who, which, why and when shall process your personal data during your visits to Our Website.

Being aware of the significance of this document, in particular the content to be conveyed, and the form it is provided in, we strive for it to be understandable to Users.

 

1. Who is the personal data Controller?

The personal data Controller is the company Health and Beauty Media sp. z o. o., address Królowej Marysieńki 9/ 10, 02-954 Warsaw, Poland.

Should you wish to contact us, there are a few options that we indicate below:

- you can call us at 0048 22 858 79 55

- you can e-mail us at info@health-and-beauty.com.pl

- or send a letter to the address: Królowej Marysieńki 9/ 10, 02-954 Warsaw, Poland.

Have we appointed a Data Protection Representative?

Yes, because it is very important to Us to safeguard Your privacy. You may ask our appointed Data Protection Representative questions by writing to iod@health-and-beauty.com.pl, on every topic that applies to the processing of your personal data.

 

2. What kinds of personal data do we process?

If you are a User of the Website www.health-and-beauty.com.pl, and you do not use the electronic means of correspondence with us, then we shall collect exclusively the following data:

- IP address,

- data concerning the frequency of your visits and the time spent on our website – concerning your activity,

- data concerning the location and the device that you use to view our Website,

- the logs.

If you are a User of the Website www.health-and-beauty.com.pl, and you use the electronic means of correspondence that we provide, then we additionally collect the following data:

- First and last name or entity name,

- E-mail address and/ or phone number,

- Other data concerning the electronic or phone correspondence.

If you are a User of the Website www.health-and-beauty.com.pl, and have registered yourself in the contact database using the relevant forms, then we shall additionally collect the following information:

- First and last name and/ or entity name,

- Place of residence and/ or entity seat,

- E-mail address and/ or phone number,

- Status, type of services provided, industry branch,

- Entity registration data.

We collect the above described data from You.

 

3. What is the purpose of the processing of the personal data you provide?

We process the data primarily for the following reasons:

a) to keep visit statistics for our Website, which may entail such information as: the time spent, the activities, the qualities of the content displayed, your location or information on the device that you use to view Our Website,

b) in order to provide options of contact with us via the e-mail addresses or phone numbers available on the website, and through the provided contact form, or by interactions on social media sites of other companies (in line with their terms of service and the relevant privacy statements, including our social media privacy policy, and

c) in order to enable registration in Our contact database by way of the provided registration form, and

d) for the purpose of direct marketing, and in case of consent, also for the purpose of electronic marketing, and

e) to defend or raise claims, in line with our legal interests in relation to the business we conduct.

 

4. What is the legal basis for the processing of your personal data?

A. Contact (through the provided contact details, including e-mail)

The basis for the processing of personal data from the form is art. 6 section 1 letter f), pursuant to your activity of making contact with us with respect to a particular issue, any sort of response and/ or necessary clarifications.

B. Contact database (registration form)

The basis for the processing of personal data from the form is art. 6 section 1 letter a) – your consent provided in relation to signing up to the contact database in order to receive current information materials about our activity using traditional means (direct marketing) or should a separate consent also be provided with respect to electronic communication.

C. Visit statistics

The basis for the processing of the collected personal data is art. 6 section 1 letter f) – our legal interest in terms of the management of our Website, and provision of security to Users.

D. Direct marketing

The basis for the processing of the collected personal data is art. 6 section 1 letter f) – our legal interest in terms of the trade activities concerning our products and services.

E. Contact form (requests concerning personal data)

The basis for the processing of the collected personal data is art. 6 section 1 letter f) – our legal interest in terms of processing of the requests concerning the processing of your personal data.

 

5. Is it voluntary or obligatory to provide personal data?

It is not obligatory to provide personal data, however, certain processes require this for particular activities. Failure to provide personal data designated as necessary may result in the inability to provide a response should contact be made, to register in the contacts database or process your request concerning the processing of your personal data.

The provision of data described as not obligatory is voluntary, and failure to provide them does not result in any consequences or limitations.

 

6. What shall be the storage time of personal data?

It all depends on the purpose of processing and the basis, upon which the processing rests.

A. Contact (e-mail)

Over the period necessary to process your request and over the period of usage of the data for direct marketing, however, not later than until the submission of a complaint against the processing or a request to remove such data. However, if on the basis of the relation made, we should commence cooperation, the data storage time shall be extended to encompass the duration of this business relationship and the duration of further processing of the personal data in relation to this business, and over the period of limitations.

B. Contact database (registration form – direct marketing)

Over the period necessary to execute the purpose that is direct marketing, or until the time the consent to the processing of personal data provided in the data form is withdrawn, and/ or until a complaint is submitted, reserving the situation, in which we would commence a business relation, when accordingly the data storage time shall be extended to encompass the duration of this business relationship and the duration of further processing of the personal data in relation to this business, and over the period of limitations.

C. Contact database (registration form in case of separate consent to marketing using electronic means)

Over the period necessary to execute the purpose, for which the consent was granted, or until this consent is withdrawn.

Remember

You have the right to withdraw the consent you provide, at any time. The withdrawal of the consent does not influence the legality of processing that was performed on the basis of the consent before it was withdrawn. You can claim this right in the following ways:

- by e-mail, by sending a message to: iod@health-and-beauty.com.pl,

- using the provided form, under the link https://www.health-and-beauty.com.pl/dane-osobowe/wnioski-dot-danych-osobowych/

- or writing personally to the address: Health and Beauty Media sp. z o. o., address Królowej Marysieńki 9/ 10, 02-954 Warsaw, Poland (indicating that the case concerns protection of personal data)

D. Statistics (Website)

Over a period not exceeding three years, because we want to compare and watch the development of our website, whether we are progressing the right way.

E. Contact form (requests concerning personal data)

Over a period not exceeding three years, in line with legally substantiated interests in relation to retaining proof concerning the processing of any submitted requests and the provision of responses.

F. Defence and advancement of claims

Should we at any time come to the conclusion that the processed personal data is necessary for us to advance or defend claims, or should it be in line with provisions of the law, then we shall store such personal data longer than the periods indicated above, over the time necessary to achieve the objective of their processing, however, not longer than for three years.

 

7. Do we process the personal data of children?

Our website is not dedicated to children below the age of sixteen.

 

8. Whom can we provide personal data to, and why?

We do not disclose the personal data of our Website’s Users save for the following situations:

- when it is necessary with respect to the business we conduct, e. g. delivery services, telecommunications companies,

- in situations required or allowed by provisions of the law, whereby in such a case we provide personal data to companies, organisations and persons outside of Health and Beauty Media sp. z o. o., if we would conclude in good faith that the provision, usage, storage or disclosure of the data is substantiation with respect to:

– aiming to conform to requirements of the law in force, provisions, legal processes or legally binding requests of state authorities;

– enforcement to current website usage conditions (Website regulations), including the research of potential violations;

– oversight of Website traffic, visit times, etc.;

– detection of fraud and prevention thereof, as well as the solution of other problems concerning fraud, security and technical issues;

– protection of property or security rights of the Data Controller, the Users of the website health-and-beauty.com.pl and other parties in a manner required or allowed by the provisions of the law,

- or in any situation, in which you, as a data subject, would consent to such disclosure;

- or in any situation, when it is necessary to execute the contracted activities by third parties on the basis of concluded contracts. In such a case, in certain instances of provision of data processing, we may transfer the personal data acquired by us to cooperating suppliers so that it would be possible for them to process the personal data in our name.

We do not transfer data to third parties remaining in States outside of the European Economic Area (EEA) or to international organisations.

 

9. What rights do You have in relation to the processing of personal data?

You have rights that you should know of, so that you could make use of them, and which the GDPR guarantees you.

You have the following rights:

- to request access to own personal data (including to acquire a confirmation of whether they are being processed, and to acquire information e. g. on the objectives, sources, categories of the processed data or the period of their storage), which also includes the right to receive free of charge copies of own data (all further copies requested by the data subject may be subject to a reasonable fee covering processing costs);

- to correct the personal data (if they are wrong), also covering the provision and amendment of incomplete personal data, however, for this purpose we may ask you to present a further statement;

- to have the personal data removed (‘right to be forgotten’) if e. g. they are not necessary for the purposes, for which they were collected, if consent to their processing has been revoked or if there is no further legal basis for the processing;

- to have the processing limited, e. g. if you question the correctness of the personal data – covering the time we need to check the data correctness;

- to submit a complaint against processing;

- to transfer the data, including to receive from us the personal data you have provided us with in a structured, commonly used machine-readable format,

- to withdraw any consent you provided with respect to the processing of personal data (whereby the withdrawal of the consent does not influence the legality of processing that was performed on the basis of the consent before it was withdrawn);

- to submit a complaint to the President of the Polish Data Protection Office, should you conclude that the processing of the personal data violated the provisions on personal data protection.

 

10. How may you make use of your rights?

You can make use of your rights with respect to us at any time. We ask you to get acquainted with the necessary information on the mode of procedure – they can be found here.

Request submissions:

- by e-mail, by sending a message to: iod@health-and-beauty.com.pl,

- using the provided form, under the link https://www.health-and-beauty.com.pl/dane-osobowe/wnioski-dot-danych-osobowych/

- or writing personally to the address: Health and Beauty Media sp. z o. o., address Królowej Marysieńki 9/ 10, 02-954 Warsaw, Poland (indicating that the case concerns protection of personal data)

The right to complain, which can be made use of by writing to the President of the Polish Data Protection Office. All information can be found at www.uodo.gov.pl/en.

 

11. Automated processing, including profiling?

Important – the personal data can be processed automatically, however, they are not profiled in terms that would cause legal effects or affect our users significantly.

 

12. General information, which, however, may be useful

What is personal data and what does their processing mean?

Personal data is information about an identified or identifiable natural person. Personal data processing practically includes any activity that includes personal data, irrespective of whether it is performed automatically or not, e. g. collection, storage, archiving, bringing into order, modification, viewing, using, provision, limiting, removal or destruction. We process your specific personal data as described in this document for various purposes, whereby the processing may utilise various methods of collection, various legal grounds for the processing, usage, disclosure, and include various storage times that are always described with respect to the purpose, for which the data is processed by us.

When does this Privacy Policy apply?

The present privacy policy applies in all cases, in which we are the personal data controller. This applies both to cases, in which we process personal data acquired directly from the data subject, as well as instances, in which we acquire the personal data from other sources.

How do we care for personal data security?

We make every effort to protect users against unauthorised access, modification, disclosure and destruction of personal data, in particular:

- we use SSL encryption;

- we control our methods of collection, storage and processing of information, including physical security measures, to protect against unauthorised system access,

- we only provide access to personal data to those employees, business partners and representatives, who need to have access to them in order to process them for our business purposes. In addition, by contract, they are bound to maintain strict confidentiality,

- and in case they should not fulfil these requirements, they may bear consequences, up to and including termination of cooperation.

Do we want to process sensitive User data?

No, we do not, that is why we call on our users that they should be reasonable and never provide sensitive data, e. g. on their health, when giving information about themselves.