- The Privacy Policy sets out the rules for privacy and the processing of personal data of service users www.zabieginacialo.com operated on the Internet (hereinafter the "Service").
- The administrator of Users' personal data is Womenline Ewa Nieczypor, ul. Grodzka 13, 58-500 Jelenia Góra, REGON 0212192475, NIP 6912192475. The Administrator can be contacted via e-mail: ewa.nieczypor@gmail.com or by post to the following address: Womenline Ewa Nieczypor Mała Kamienica 81 58-512 Mała Kamienica.
- A Data Protection Officer has been appointed at the Controller, who can be contacted by email: ewa.nieczypor@gmail.com or by post to the following address: Womenline Ewa Nieczypor Mała Kamienica 81 58-512 Mała Kamienica.
- A separate administrator of Users' personal data in the scope of their use in the implementation of payment processes for services is Blue Media S.A. with its registered office in Sopot, ul. Powstańców Warszawy 6, 81-718 Sopot, entered in the register of entrepreneurs of the National Court Register kept by the District Court in Poznań - Nowe Miasto and Wilda in Poznań, VIII Economic Division of the National Court Register under KRS number 0000320590, REGON: 191781561, NIP: 5851351185. The administrator can be contacted via e-mail address: odo@bm.pl or in writing to Blue Media S.A. ul. Powstańców Warszawy 6, 81-718 Sopot.
- The Administrator shall act in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons in relation to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (hereinafter "RODO"), including in particular: adequately securing Users' personal data against unlawful access to personal data by third parties, in particular encrypting personal data, archiving personal data, evaluating personal data security measures, ensuring the confidentiality, integrity, availability and resilience of processing systems and services.
- The User Data entered into the Service is the property of the User.
- Within the scope of ordinary data such as first name, surname, date of birth, contact telephone, e-mail (in the case of expressing the wish to receive a VAT invoice confirming the purchase of services by the User the company name, address data of the company and the NIP and REGON numbers of the company), the User's data will be processed only to enable the use of the Website's functionalities, in order to provide comprehensive laser hair removal services, give advice and cosmetic consultations and other services, as well as to make settlements for the purchased services, to contact and maintain personal files, as well as for possible establishment, investigation or defence against claims, for evidential, analytical, archival, accounting and bookkeeping purposes, as well as for the Administrator to offer products and services directly (direct marketing), including selecting them according to the User's needs by means of profiling, which, however, will not significantly affect the situation of the User or produce legal effects towards him/her. Data for these purposes will be processed on the basis of Article 6(1)(b), (c) and (f) of the RODO, thus when:
- the processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract,
- processing is necessary for the fulfilment of a legal obligation incumbent on the Administrator,
- processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
- To the extent that the processed data may include special category data - health data - the Administrator processes the data for the sole purpose of providing comprehensive laser hair removal services, providing cosmetic advice and consultations and maintaining personal files, the legal basis for processing the User's data is consent in accordance with Article 9(2)(a) of the RODO. The provision of data and consent to the processing of health data is voluntary, however, failure to provide such data or to give consent will result in the inability to perform the Treatment. Such consent may be withdrawn at any time.
- Execution of direct marketing by the Administrator by means of terminal equipment (in particular mobile and landline telephones, tablets, computers) and automatic calling systems, to the telephone number and e-mail address provided by the User, consisting in receiving marketing messages about the Administrator's products and services and marketing actions organised by the Administrator and sending commercial information concerning the goods or services offered by the Administrator to the e-mail address provided by the User, within the meaning of the Act of 18 July 2002 on the provision of services by electronic means (Dz.U.2017.1219 t.j. of 2017.06.24) or telephone within the meaning of the Telecommunications Act of 16 July 2004 (Dz.U.2017.1907 t.j. of 2017.10.12) is subject to the User's separate consent pursuant to Article 6(1)(a) RODO. The provision of data and consent to data processing is voluntary. Such consent may be withdrawn at any time - the User may opt out of receiving further commercial information at any time by calling the hotline number provided on the website or by contacting the company at the following email address ewa.nieczypor@gmail.com or in writing by writing to the address indicated in paragraph 2 or 3 above.
- The user has the right to:
-
- access to their data and receive a copy of their data,
- rectification (amendment) of your data,
- erasure - if, in the opinion of the User, there are no grounds for the Administrator to process his/her data,
- limitation of data processing - if, in the opinion of the User, the Administrator has inaccurate data about him or her or processes them unduly; or the User does not consent to the deletion of data due to the need to establish, assert or defend claims; or for the duration of the User's objection to the processing of data,
- object to the processing of data for direct marketing purposes, including profiling, and the right to object to the processing of data on the basis of legitimate interests for purposes other than direct marketing, and where the processing is necessary for the Administrator to carry out a task carried out in the public interest or for the exercise of official authority vested in us,
- Data portability - The User has the right to receive from the Administrator in a structured, commonly used machine-readable format his/her personal data which he/she has provided to the Administrator on the basis of a contract or consent, or the User may instruct the Administrator to send this data directly to another entity;,
- lodge a complaint to a supervisory authority - if the User believes that the Administrator is processing his/her data unlawfully, he/she may lodge a complaint to the President of the Office for Personal Data Protection or any other competent supervisory authority,
- The right to withdraw consent to the processing of personal data - at any time, the User has the right to withdraw consent to the processing of those personal data which the Administrator processes on the basis of his/her consent; the withdrawal of consent will not affect the lawfulness of the processing carried out on the basis of consent before its withdrawal.
- The user provides all data voluntarily and knowingly.
- The following categories of entities may have access to the User's personal data:
- authorised employees and associates of the Administrator,
- service providers who supply the Administrator with technical and organisational solutions enabling the provision of functional services (in particular courier and postal services, IT services, marketing, legal and consultancy service providers and their authorised employees and associates),
- entities performing data analytics for the purpose of personalising advertisements and being separate controllers in this respect, in particular Google LLc.
- Data will also be transferred to recipients in third countries (countries outside the European Economic Area such as: as Google LLc. and The Rocket Science Group LLC d/b/a MailChimp, which are subject to certification under the EU-US Privacy Shield, which the User can check at any time at: https://www.
privacyshield.gov/list/. Other than in the cases indicated, the Administrator will not transfer or authorise the transfer of personal data provided by you outside the EEA unless it has taken the measures necessary to ensure that the transfer complies with the RODO. The measures in question may include, in particular, the transfer of personal data to a recipient in a country that, in accordance with a decision of the European Commission, ensures adequate protection of personal data or to a recipient in the United States that has certified compliance with the EU-US Privacy Shield programme. - In the course of running the Website, the Administrator uses the services of Google, where Google is a separate controller of the Users' personal data. The Administrator promotes the Services using Google AdWords. The data collected about Users is helpful in better targeting of advertisements and promotion of the Service Owner, and is also used to develop remarketing campaigns. The Administrator makes a special effort to encourage Users to visit the Service. Therefore, in order to improve its Services and enhance the Website, it collects information about the User's technical profile in impersonal form using Google Analytics.
- The Owner and Administrator may collect statistical data on the popularity and use of the various Services offered by the Website, sharing them with other entities. This data will be shared only anonymously and collectively, without the possibility of extracting Users' personal data on its basis. The Administrator may also use the collected statistical data for marketing, information, statistical purposes and publication in media such as the Internet, press, radio, television, mobile and landline telephony.
- The personal data provided by the User will be processed to the extent and for the duration necessary to fulfil the purposes for which they were collected. This period of time is not possible to determine explicitly and depends on the decisions regarding the use of the Administrator's services for which the data was collected. In connection with contracts that have expired or have been terminated, the duration of the Administrator's processing of personal data is determined by the limitation periods for Civil Code claims and tax and accounting law obligations, so we will not process the data for longer than 6 years after the end of the contract. Personal data processed for the purposes covered by the statement of consent will be processed for those purposes until the consent is revoked.
- This Service is not designed for or aimed at children under the age of sixteen.
- The website only collects the information contained in the cookies referred to below by automated means.
- As a result of your use of the Website, text files (so-called cookies) may be stored on your devices, the purpose of which is to facilitate your access to and use of the Website, as well as to study your preferences and behaviour in order to enable the delivery of personalised content on the Website and to improve the functioning of the Website. Data is also collected by cookies for statistical purposes.
- The user can deactivate the placement and storage of cookies from the level of the web browser he/she uses. How to disable cookies depends on the Internet browser used by the user. Detailed information on the possibility and methods of handling cookies is available in the settings of your software (web browser).
- Information on how to manage cookies in individual browsers can be found on the pages dedicated to the individual browsers:
- Firefox: http://support.
mozilla.org/en/kb/cookie, - Internet Explorer: http://support.
microsoft.com/kb/196955/en, - Chrome: http://support.google.
com/chrome/bin/answer.py?hl= en&answer=95647, - Opera: http://help.opera.com/
Linux/12.10/en/cookies.html, - Safari: http://support.apple.
com/kb/HT1677?viewlocale=en_ EN&locale=en_EN.
- Firefox: http://support.
- Womenline may collect cookies in two types - as "session" files and "permanent" files. The former are temporary files that remain on the user's device until the user logs out of the website or shuts down the software (web browser). "Permanent" files remain on the user's device for the time specified in the parameters of the "cookies" or until they are manually deleted by the user.
- Cookies are placed in the Service User's terminal equipment and may also be used by advertisers cooperating with the Administrator. Cookies may also be used, in particular, by Google for the purpose of displaying advertisements tailored to the manner in which a User uses the Website. For this purpose, they may store information about the User's navigation path or time spent on a given page. With regard to the information on the User's preferences collected by the Google advertising network, the User can view and edit the information resulting from the cookies using a tool: https://
adssettings.google.com/ authenticated?hl=en. The Owner of the Website additionally recommends that Users read the Google Analytics Privacy Policy to learn about the use of cookies used in statistics: Google Analytics Privacy Policy. https://www.google. com/analytics/learn/privacy. html?hl=en. - The Administrator stipulates that restricting the use of cookies may affect some of the functionalities available on the Website, and in extreme cases may make it impossible to use the Website.