1. The administrator of personal data collected via the https://ts2.shop/en/ online store is TS2 SPACE LIMITED LIABILITY COMPANY entered into the Register of Entrepreneurs by the District Court for the Capital City of Warsaw Warszawa in Warsaw, 12th Commercial Division of the National Court Register under KRS number: 0000635058, place of business and address for service: Aleje Jerozolimskie 65/79, apartment number: 15.03, 00-697 Warszawa, NIP: 7010612151, REGON: 365328479, e-mail address (e-mail): email@example.com, phone number: +48 223 645 800, , hereinafter referred to as the "Administrator" and being at the same time the "Service Provider".
2. Personal data collected by the Administrator via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as GDPR.
TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION
1. PURPOSE OF PROCESSING AND LEGAL BASIS. The administrator processes the personal data of the Service Recipients of the https://ts2.shop/en/ Store in the case of:
1.1. registering an Account in the Store, in order to create an individual account and manage this Account, pursuant to art. 6 sec. 1 lit. b) GDPR (implementation of the contract for the provision of electronic services in accordance with the Regulations of the Store),
1.2. placing an Order in the Store, in order to perform the sales contract, pursuant to art. 6 sec. 1 lit. b) GDPR (performance of the sales contract),
1.3. subscribing to the Newsletter in order to send commercial information by electronic means. Personal data is processed after expressing a separate consent, pursuant to art. 6 sec. 1 lit. a) GDPR,
1.4. use the Contact Form to send a message to the Administrator, pursuant to art. 6 sec. 1 lit. f) GDPR (legitimate interest of the entrepreneur).
2. TYPE OF PERSONAL DATA PROCESSED. The Service Recipient provides, in the case of:
2.1. Accounts: name and surname, e-mail address, date of birth.
2.2. Orders: name and surname, address, NIP, e-mail address, telephone number, PESEL number.
2.3. Newsletter: e-mail adress.
2.4. Contact Form: name, e-mail address.
3. PERSONAL DATA ARCHIVING PERIOD. The personal data of the Service Recipients are stored by the Administrator:
3.1. if the basis for data processing is the performance of the contract, as long as it is necessary to perform the contract, and after that time for a period corresponding to the period of limitation of claims. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business - three years.
3.2. if the basis for data processing is consent, as long as the consent is not revoked, and after revoking the consent for a period of time corresponding to the period of limitation of claims that may be raised by the Administrator and which may be raised against him. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to running a business - three years.
4. When using the Store, additional information may be downloaded, in particular: the IP address assigned to the Customer's computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type.
5. After expressing a separate consent, pursuant to art. 6 sec. 1 lit. a) GDPR, data may also be processed for the purpose of sending commercial information by electronic means or making telephone calls for direct marketing purposes - respectively in connection with art. 10 sec. 2 of the Act of July 18, 2002 on the provision of electronic services or art. 172 sec. 1 of the Act of July 16, 2004 - Telecommunications Law, including those directed as a result of profiling, provided that the Service Recipient has given the appropriate consent.
6. Navigational data may also be collected from the Service Recipients, including information about links and references that they decide to click or other activities undertaken in the Store. The legal basis for this type of activity is the Administrator's legitimate interest (Article 6(1)(f) of the GDPR), consisting in facilitating the use of services provided electronically and improving the functionality of these services.
7. Providing personal data by the Service Recipient is voluntary.
8. The administrator takes special care to protect the interests of data subjects, and in particular ensures that the data collected by him are:
8.1. processed in accordance with the law,
8.2. collected for specified, lawful purposes and not subjected to further processing incompatible with these purposes,
8.3. factually correct and adequate in relation to the purposes for which they are processed and stored in a form that allows the identification of the persons they concern, no longer than it is necessary to achieve the purpose of processing.
PROVISION OF PERSONAL DATA
1. The personal data of the Service Recipients are transferred to service providers used by the Administrator when running the Store, in particular to:
1.1. entities delivering the Products,
1.2. payment system providers,
1.3. accounting office,
1.4. hosting providers,
1.5. providers of software enabling business operations,
1.6. entities providing the mailing system,
1.7. software provider needed to run an online store.
2. Service providers referred to in point 1 of this paragraph to whom personal data are transferred, depending on contractual arrangements and circumstances, or are subject to the Administrator's instructions as to the purposes and methods of data processing (processing entities) or independently determine the purposes and methods of their processing (administrators).
THE RIGHT OF CONTROL, ACCESS TO OWN DATA AND CORRECTION
1. The data subject has the right to access their personal data and the right to rectify, delete, limit processing, the right to transfer data, the right to raise objections, the right to withdraw consent at any time without affecting the lawfulness of the processing that has been made on the basis of consent before its withdrawal.
2. Legal grounds for the Customer's request:
2.1. Access to the data - article 15 GDPR.
2.2. Correction of data - article 16 GDPR.
2.3. Deletion of data (the so-called right to be forgotten) - article 17 GDPR.
2.4. Processing restriction - article 18 GDPR.
2.5. Data transfer - article 20 GDPR.
2.6. Objection - article 21 GDPR
2.7. Withdrawal of consent - article 7 sec. 3 GDPR.
3. In order to exercise the rights referred to in point 2, you can send an appropriate e-mail to the following address: firstname.lastname@example.org
4. In the event of the Service Recipient's entitlement resulting from the above rights, the Administrator fulfills the request or refuses to comply with it immediately, but not later than within a month after receiving it. However, if - due to the complicated nature of the request or the number of requests - the Administrator will not be able to meet the request within a month, he will meet them within the next two months informing the Service Recipient in advance within one month of receiving the request - about the intended extension of the deadline and its reasons.
5. If it is found that the processing of personal data violates the provisions of the GDPR, the data subject has the right to lodge a complaint with the President of the Office for Personal Data Protection.
1. Admin pageuses files"cookies”.
2. Installation of files "cookiesIs necessary for the proper provision of services on the Store's website. In the files "cookies" contains information necessary for the proper functioning of the website, as well as they also provide the opportunity to develop general statistics of website visits.
3. Two types of files are used within the website:cookies": "session" and "permanent".
3.1. "Cookies"Session cookies" are temporary files that are stored on the Customer's end device until logging out (leaving the website).
3.2. "Permanent" filescookies" are stored in the Customer's end device for the time specified in the file parameters "cookies" or until they are removed by the Service Recipient.
4. The administrator uses its own cookies for the purpose to better understand how the Service Recipients interact with the content of the website. The files collect information about the way the Customer uses the website, the type of website from which the Customer was redirected and the number of visits and time of the Customer's visit to the website. This information does not register specific personal data of the Service Recipient, but is used to compile website usage statistics.
5. The administrator uses external cookies to collecting general and anonymous static data via Google Analytics analytical tools (administrator of external cookies: Google LLC. based in the USA).
6. Cookie files may also be used by advertising networks, in particular the Google network, in order to display advertisements tailored to the manner in which the Service Recipient uses the Store. For this purpose, they can keep information about the User's navigation path or the time of staying on a given page.
7. The service recipient has the right to decide on the access to files "cookiesTo your computer by selecting them in advance in your browser window. Detailed information about the possibilities and ways of handling files "cookies" are available in the software (web browser) settings.
ADDITIONAL SERVICES RELATED TO THE USER'S ACTIVITY IN THE STORE
1. The Store uses the so-called. social plugins ("plugins") of social networking sites. By displaying the https://ts2.shop/en/ website containing such a plug-in, the Customer's browser will establish a direct connection with the servers of Facebook, Instagram, Pinterest, Twitter, Google and YouTube.
2. The content of the plugin is transferred by the given service provider directly to the Service Recipient's browser and integrated with the website. Thanks to this integration, service providers receive information that the Customer's browser has displayed the page https://ts2.shop/en/, even if the Service Recipient does not have a profile with a given service provider or is not currently logged in to it. Such information (along with the IP address of the Service Recipient) is sent by the browser directly to the server of the given service provider (some servers are located in the USA) and stored there.
3. If the Service Recipient logs in to one of the above social networking sites, this service provider will be able to directly assign a visit to the website https://ts2.shop/en/ to the Service Recipient's profile on a given social networking site.
4. If the Service Recipient uses a given plug-in, e.g. by clicking the "Like" button or the "Share" button, the relevant information will also be sent directly to the server of the given service provider and stored there.
6. If the Service Recipient does not want social networking sites to assign data collected during visits to the website https://ts2.shop/en/ directly to his profile on a given website, before visiting the website https://ts2.shop/en/ must log out of this site. The service recipient may also completely prevent the loading of plug-ins on the website by using appropriate extensions for the browser, e.g. blocking scripts using "NoScript".
7. The administrator uses remarketing tools on his website, i.e. Google Ads, this involves the use of Google LLC cookies for the Google Ads service. As part of the mechanism for managing cookie settings, the Service Recipient has the option of deciding whether the Service Provider will be able to use Google Ads (administrator of external cookies: Google LLC. based in the USA) in relation to him.
1. The administrator uses technical and organizational measures to ensure the protection of processed personal data appropriate to the threats and categories of data protected, and in particular protects data against unauthorized access, removal by an unauthorized person, processing in violation of applicable regulations and change, loss, damage or destruction.
2. The administrator provides appropriate technical measures to prevent unauthorized persons from obtaining and modifying personal data sent electronically.