Legal notice
Pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016
on the protection of natural persons with regard to the processing of personal data and on the free
movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”), we hereby inform you that:
Data Controller
1. The controller of the personal data processed within the online store AIME ROSE is:
AIME ROSE, ul. Kościelna 44A, 05-200 Wołomin, Poland NIP: 1251641429, REGON: 364284998.
2. The Controller may be contacted in writing at the following address:
ul. Kościelna 44A, 05-200 Wołomin, Poland
Purpose and legal basis of personal data processing
1. Your data will be processed for the following purposes:
a) carrying out transactions within the Store – based on Article 6(1)(b) GDPR, i.e. processing is necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract;
b) marketing of the Controller’s own services and products – based on Article 6(1)(f) GDPR, i.e. on the legitimate interest pursued by the Controller, which is direct marketing of its own products and services;
c) conducting marketing and promotional activities – based on separately granted consent (Article 6(1)(a) GDPR);
d) establishment, exercise or defence of possible claims between you and the Controller – based on Article 6(1)(f) GDPR, i.e. on the legitimate interest pursued by the Controller, which is the possibility of pursuing claims;
e) sending commercial information by electronic means in accordance with Article 10(2) of the Act of 18 July 2002 on the provision of services by electronic means (consolidated text: Journal of Laws of 2017, item 1219, as amended) – based on separately granted consent;
f) using terminal telecommunications equipment and automated calling systems for the purposes of direct marketing in accordance with Article 172 of the Act of 16 July 2004 – Telecommunications Law (consolidated text: Journal of Laws of 2017, item 1907, as amended) – based on separately granted consent.
Categories of recipients of personal data
1. Your personal data may be disclosed to the following entities:
employees and collaborators of the Controller, IT service providers, entities providing advisory and legal services.
2. Your personal data may be made available to entities and authorities authorised to process such data under provisions of law.
3. The Controller does not intend to transfer your personal data to countries outside the European Economic Area or to an international organisation.
Personal data storage period
1. Your personal data will be processed until the withdrawal of the consent given or lodging an objection to the processing of the data (which will also occur as a result of termination of the contract for the provision of an electronic service consisting in sending a newsletter) – in cases where your personal data are processed on the basis of a separate consent to send a newsletter or to conduct marketing activities, or on the basis indicated in Article 6(1)(e) or (f) GDPR, including for the purposes of direct marketing.
Your Rights
1. Providing data is voluntary, but necessary to carry out transactions within the Store. Failure to provide personal data makes it impossible to create your account in the Store and to carry out transactions within the Store. This does not apply to processing for commercial and marketing purposes, which is carried out only in the case of voluntarily granted consent, independently of transactions within the Store.
2. Your data may be processed in the form of analytical, sales and marketing profiling in order to tailor materials sent by the Controller to your needs and interests, and to perform measurements enabling the Controller to improve the services it provides. Binding decisions are not taken in an automated manner.
3. You have the right to request from the Controller access to your personal data, their rectification, erasure, restriction of processing or their portability.
4. To the extent that the processing of your personal data is based on consent, you have the right to withdraw your consent. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
5. To the extent that the processing of your personal data is based on the premise of the Controller’s legitimate interest, you have the right to object to the processing of your personal data.
6. In order to exercise the above rights, you should contact the Controller using the contact details indicated above (contact details indicated above – see point 2).
7. If you consider that the processing of personal data by the Controller violates the provisions of the GDPR, you have the right to lodge a complaint with the President of the Personal Data Protection Office.
8. More information on the rules of personal data processing is available in the Privacy Policy available in the Terms and Conditions section.