Privacy policy and the use of cookies in the Online Store

We would like to familiarize you with the details of the processing of your personal data by us to give you full knowledge and comfort in using our website.

As we operate in the internet industry ourselves, we know how important it is to protect your personal data. Therefore, we take special care to protect your privacy and the information you provide to us.

We carefully select and apply appropriate technical measures, in particular those of a programming and organizational nature, ensuring the protection of personal data processed. Our website uses encrypted data transmission (SSL), which ensures the protection of your identifying data.

In our Privacy Policy you will find all the most important information regarding the processing of your personal data by us.

Who is the administrator of the website enchanterium.com?

The administrator of the website enchanterium.com is Aleksandra Loska, running a business under the name “Aleksandra Loska Art” entered into the register of entrepreneurs of the Central Register and Information on Economic Activity kept by the Minister of Development, ul. Orzeszkowej 34/38, 43-100 Tychy, NIP 6462997717, REGON 522609270.

What legal act regulates the processing of your personal data?

Your personal data is collected and processed by us in accordance with the provisions of the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27/04/2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46/EC (general regulation on data protection) (OJ EU L 119, p. 1), commonly known as: GDPR. To the extent not regulated by the GDPR, the processing of personal data is governed by the Personal Data Protection Act of May 10, 2018.

Who is the administrator of your personal data?

The administrator of your personal data is:

Aleksandra Loska Art
Orzeszkowej 34/38, 43-100 Tychy, Poland
phone: +48 513744738
e-mail: enchanterium@gmail.com

In the matter of your personal data, you can contact the Administrator via traditional mail or email at the above adresses.

What personal data do we process and for what purposes do we process them?

We offer you many different services on our website, for the purposes of which we process different personal data on different legal bases.

1) conclusion and performance of a contract for the sale of goods

Personal data: name, surname, correspondence address, tax identification number (NIP), e-mail address, telephone number, bank account number, payment card number

Legal basis for processing: art. 6 sec. 1 lit. b) GDPR, i.e. processing in order to take action at your request, before concluding a contract and processing necessary for the performance of a contract to which you are a party

Duration of data storage: until the expiry of the limitation period for claims relating to the performance of the contract

2) newsletter

Personal data: e-mail address, name

Legal basis for processing: art. 6 sec. 1 lit. a) GDPR, i.e. processing based on your consent to the processing of your personal data

Duration of data storage: until you withdraw your consent to data processing

3) analysis of statistics, traffic analysis on the store's website

Personal data: name, surname, company, tax identification number or REGON, contact number, address correspondence number, IP number, account number banking, e-mail address

Legal basis for processing: Art. 6 sec. 1 lit. f) GDPR, i.e. processing for the purpose of implementation the Administrator's legitimate interest in analyzing customer traffic on the Store's website

Duration of data storage: until you object to the processing of personal data

4) direct marketing of own goods and services, including remarketing

Personal data: name, surname, image, company, e-mail address, IP address, information stored in cookies, location

Legal basis for processing: Art. 6 sec. 1 lit. f) GDPR, i.e. processing for the purpose of implementation the legitimate interest of the Administrator consisting in direct marketing of own services, including remarketing

Duration of data storage: until you object to the processing of personal data or determine that your data has become obsolete

5) determination, investigation and enforcement of claims and defense against claims in proceedings before courts and other state authorities

Personal data: name, surname, correspondence address, PESEL number, NIP number, REGON number, e-mail address, telephone number, IP number, bank account number, payment card number

Legal basis for processing: art. 6 sec. 1 lit. f) GDPR, i.e. processing in order to implement our legitimate interest, consisting in establishing, pursuing and enforcing claims and defending against claims in proceedings before courts and other state authorities

Duration of data storage: until the expiry of the limitation period for claims relating to the performance of the contrac

6) fulfillment of legal obligations resulting from legal regulations, in particular tax and accounting regulations

Personal data: name, surname, company, PESEL number, NIP or REGON number, e-mail address, telephone number, correspondence address, bank account number, payment card number

Legal basis for processing: Art. 6 sec. 1 lit. c) GDPR, i.e. processing is necessary to fulfill the legal obligations incumbent on the Administrator, resulting from legal provisions, in particular tax and accounting regulations

Duration of data storage: until the expiry of the legal obligations incumbent on the Administrator, which justified the processing of personal data

Voluntary provision of personal data

Providing the required personal data by you is voluntary, but it is a condition for us to provide services to you (e.g. creating an account, sending a newsletter).

Recipients of personal data

The current list of entities to which we disclose your personal data:

  • Paypal Polska sp.z o.o. with headquarters in Warsaw - Processing of payments

  • Google Inc. (Google Cloud, Google Analytics, Google Analytics 360, Fabric Software) based in the USA - Measure traffic on websites, reporting about application errors, creating statistics

  • Google Inc. based in the USA - Determining the profile of Google AdSense and Google Adwords customers

  • Google Inc. based in the USA - Analyzing customer activity

  • Google Ireland Ltd (Google Adwords, Double Click Manager, Double Click Search, Remarketing Service, Firebase) based in Ireland - Measuring the effectiveness of advertising campaigns, managing advertising campaigns

  • Facebook Ireland based in Ireland - Popularization of the Online Store using the Facebook.com social network

  • Instagram LLC. based in the USA - Popularization of the Online Store using the Instagram.com social networking site

Automated decision making (including profiling)

We use tools with which we target personalized advertising to you. Based on your actions in the store, in particular the choice of the content viewed and the time spent on the store's subpages, we adjust and display marketing content tailored to you. Thanks to such profiling, we can direct the marketing message more desired by you, which is a benefit both for us and for you, because in this way we limit the marketing message regarding goods and services that are not in the area of ​​your interests.

Will we transfer your personal data outside the EEA or to an international organization?

In order to use the measurement and marketing tools of Pixel Facebook, your personal data may be transferred to the United States, where Facebook Inc. servers are located.

Facebook Inc. is included in the list of entities participating in the Privacy Shield program (link: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active), therefore the protection of personal data is adequate in relation to the regulations in force in the European Union, in accordance with Commission Implementing Decision (EU) 2016/1250 of 12 July 2016 on the adequacy of the protection provided by the EU-US Privacy Shield (link: https://eur-lex.europa.eu/legal-content/PL/TXT/ HTML /? Uri = CELEX: 32016D1250 & from = EN).

What are your rights in relation to the processing of your personal data by us?

Under the GDPR, you have the right to:

  • request access to your personal data

  • request rectification of your personal data

  • request the deletion of your personal data

  • requests to limit the processing of personal data

  • object to the processing of personal data

  • requests for the transfer of personal data

If you submit any of the above-mentioned requests to us without undue delay - and in any case within one month of receiving the request - we will provide you with information about the actions taken in relation to your request.

If necessary, we can extend the monthly period by another two months due to the complex nature of the request or the number of requests.

In any case, we will inform you within one month of receiving the request to extend the deadline and provide you with the reasons for the delay.

The right to access personal data (Article 15 of the GDPR)

You have the right to obtain information as to whether we process your personal data.

If we process your personal data, you have the right to:

  • access to personal data,

  • obtain information about the purposes of processing, categories of personal data processed, about the recipients or categories of recipients of these data, the planned period of storage of your data or the criteria for determining this period, about your rights under the GDPR and the right to lodge a complaint with the President of the Office for Personal Data Protection, about the source of this data, about automated decision-making, including profiling, and about the security measures used in connection with the transfer of this data outside the European Union;

  • obtain a copy of your personal data.

If you want to request access to your personal data, please submit your request to: enchanterium@gmail.com

The right to rectify personal data (Article 16 of the GDPR)

If your personal data is incorrect, you have the right to demand that we correct your personal data immediately. You also have the right to request that we supplement your personal data.

If you want to request rectification or supplementation of your personal data, please submit your request to the following address: enchanterium@gmail.com

The right to delete personal data, the so-called "The right to be forgotten" (Article 17 of the GDPR)

You have the right to request the deletion of your personal data when:

  • Your personal data are no longer necessary for the purposes for which they were collected or otherwise processed;

  • you have withdrawn your specific consent to the extent to which personal data was processed based on your consent;

  • Your personal data has been processed unlawfully;

  • you have objected to the processing of your personal data for the purposes of direct marketing, including profiling, to the extent to which the processing of personal data is related to direct marketing;

  • you have objected to the processing of your personal data in connection with the processing necessary to perform a task carried out in the public interest or the processing necessary for the purposes of legitimate interests pursued by us or a third party.

Despite submitting a request to delete personal data, we may process your data further in order to establish, assert or defend claims about which you will be informed / informed.

If you want to request the deletion of your personal data, please submit your request to the following address: enchanterium@gmail.com

The right to submit a request to limit the processing of personal data (Article 18 of the GDPR)

You have the right to request the restriction of the processing of your personal data when:

  • you question the correctness of your personal data - in this case, we will limit the processing of your personal data for a period allowing for the verification of the correctness of this data;

  • the processing of your data is unlawful, and instead of deleting your personal data, you will request the restriction of the processing of your personal data;

  • Your personal data are no longer needed for the purposes of processing, but they are needed to establish, assert or defend your claims;

  • you have objected to the processing of your personal data - until it is determined whether our legitimate interests override the grounds indicated in your objection.

If you want to request a restriction of the processing of your personal data, please submit your request to the following address: enchanterium@gmail.com

The right to object to the processing of personal data (Article 21 of the GDPR)

You have the right to object to the processing of your personal data at any time in connection with:

  • processing necessary for the performance of a task carried out in the public interest or processing necessary for purposes arising from legitimate interests pursued by the Administrator of personal data or a third party;

  • processing for the purposes of direct marketing.

If you want to object to the processing of your personal data, please submit your request to the following address: enchanterium@gmail.com

The right to request the transfer of personal data (Article 20 of the GDPR)

You have the right to receive your personal data from us in a structured, commonly used and machine-readable format and to send it to another personal data controller.

As a standard, we will provide you with your personal data in CSV format. If you prefer the data to be made available to you in a different format, indicate the preferred format in your request. Where possible, we will try to provide you with the data in the format you prefer.

You can also request that we send your personal data directly to another administrator (if technically possible).

If you want to request the transfer of your personal data, please submit your request to the following address: enchanterium@gmail.com

Can you withdraw your consent to the processing of personal data?

You can withdraw your consent to the processing of your personal data at any time.

Withdrawal of consent to the processing of personal data does not affect the lawfulness of the processing carried out by us on the basis of your consent before its withdrawal.

If you want to withdraw your consent to the processing of your personal data, please submit your request to the following address: enchanterium@gmail.com

If you want to withdraw your consent to the processing of personal data for the purpose of providing the newsletter service, you can unsubscribe.

Complaint to the supervisory authority

If you believe that the processing of your personal data violates the provisions on the protection of personal data, you have the right to lodge a complaint with the supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.

In Poland, the supervisory body within the meaning of the GDPR is the President of the Personal Data Protection Office, who replaced GIODO on May 25, 2018.

Cookies

General information

When browsing the website of the online store, "cookies" are used, hereinafter referred to as Cookies, i.e. small text information that is stored on your end device in connection with the use of the online store. Their use is aimed at the correct operation of the online store websites.

These files allow you to identify the software used by you and adjust the Online Store individually to your needs.

Cookies usually contain the name of the domain they come from, their storage time on the device and the assigned value.

Security

The cookies we use are safe for your devices. In particular, it is not possible for viruses or other unwanted software or malware to enter your devices through cookies.

Types of cookies

We use two types of cookies:

Session cookies: they are stored on your device and remain there until the end of the browser session. The saved information is then permanently deleted from the memory of your device. The session cookies mechanism does not allow the collection of any personal data or any confidential information from your device.

Persistent cookies: they are stored on your device and remain there until they are deleted. Ending a browser session or turning off the device does not delete them from your device. The persistent cookies mechanism does not allow the collection of any personal data or any confidential information from your device.

Purpose

We also use third party cookies for the following purposes:

  • configuration of the online store;

  • popularizing the online store using Pixel Facebook, the administrator of which is Facebook Ireland Ltd. based in Ireland or Facebook Inc. based in the USA, the Fcebook privacy policy is available at: https://pl-pl.facebook.com/privacy/explanation;

To learn the rules of using Cookies, we recommend that you read the privacy policies of the above-mentioned companies.

Cookies may be used by advertising networks, in particular the Google network, to display advertisements tailored to your preferences. For this purpose, information about the way you navigate the web or the time you use the website may be stored.

To view and edit information about your preferences collected by the Google advertising network, you can use the tool available at https://www.google.com/ads/preferences/.

By using the web browser settings or by using the service configuration, you can change your Cookie settings at any time, specifying the conditions for their storage and access to your device via Cookies. You can change these settings so as to block the automatic handling of cookies in your web browser settings or to inform about them each time they are placed on your device. Detailed information on the possibilities and methods of handling cookies is available in the settings of your software (web browser).