Privacy Policy
PRIVACY POLICY – TABLE OF CONTENTS
-
GENERAL PROVISIONS
-
LEGAL GROUNDS FOR DATA PROCESSING
-
PURPOSE, LEGAL BASIS, DURATION AND SCOPE OF DATA PROCESSING IN THE ONLINE STORE
-
DATA RECIPIENTS IN THE ONLINE STORE
-
PROFILING IN THE ONLINE STORE
-
RIGHTS OF THE DATA SUBJECT
-
COOKIES, OPERATING DATA AND ANALYTICS IN THE ONLINE STORE
-
FINAL PROVISIONS
1. GENERAL PROVISIONS
1.1. This Privacy Policy is for informational purposes only. It does not impose any obligations on the Customers or Users of the Online Store. It outlines the principles of personal data processing by the Controller, including legal grounds, purposes, scope of data processing, data subject rights, as well as the use of cookies and analytics tools.
1.2. The controller of personal data collected via the Online Store is Marcin Kryst, conducting business under the name Meditrendy Marcin Kryst, registered in the Central Register and Information on Economic Activity of the Republic of Poland. Business address and correspondence address: ul. Wręczycka 47/49, 42-202 Częstochowa, NIP: 9491520451, REGON: 241641465, email: [email protected], phone: (+48) 690-240-661 (hereinafter referred to as the “Controller”), who is also the Service Provider and Seller in the Online Store.
1.3. Personal data is processed in compliance with applicable laws, including Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR). Official text available at: EU Law Website
1.4. Using the Online Store and providing personal data is voluntary. However, providing certain data is required for:
(1) entering into agreements with the Controller – failure to provide required data may prevent concluding or executing such agreements;
(2) fulfilling legal obligations imposed on the Controller (e.g. accounting or tax regulations).
1.5. The Controller ensures that all processed data is:
(1) lawfully processed;
(2) collected for specific, lawful purposes and not processed beyond them;
(3) accurate and relevant;
(4) stored no longer than necessary;
(5) secured against unauthorized access, processing, or loss.
1.6. The Controller applies appropriate technical and organizational measures based on the nature, scope, context, and risks of processing. These measures are reviewed and updated regularly.
1.7. Capitalized terms (e.g., Seller, Online Store, Electronic Service) are defined in the Online Store’s Terms and Conditions.
2. LEGAL GROUNDS FOR DATA PROCESSING
2.1. The Controller is permitted to process personal data when at least one of the following applies:
(1) consent has been given;
(2) processing is necessary for the performance of a contract or pre-contractual actions;
(3) legal obligation;
(4) legitimate interests of the Controller or a third party, unless overridden by data subject rights.
2.2. Each specific basis for processing is detailed in Section 3 of this Privacy Policy.
3. PURPOSE, LEGAL BASIS, DURATION AND SCOPE OF DATA PROCESSING IN THE ONLINE STORE
3.1. The specific purpose, basis, duration, and scope of data processing depend on the user's activity in the Online Store. For instance, if the Customer opts for in-store pickup instead of courier delivery, their data will not be shared with shipping companies.
3.2. Detailed purposes, legal bases, processing periods, and data scopes are presented in context throughout the Policy.
4. DATA RECIPIENTS IN THE ONLINE STORE
4.1. The Controller may share data with external service providers (e.g. IT, courier, or payment services), only with entities that ensure GDPR-compliant safeguards.
4.2. Data is shared only when necessary for the intended purpose and to the minimal extent required.
4.3. Categories of potential recipients include:
-
Carriers/shipping companies – for delivery purposes;
-
Payment processors – for handling online transactions;
-
IT, software, hosting providers – to support Store operations;
-
Accounting/legal/consulting firms – for compliance and advisory purposes.
5. PROFILING IN THE ONLINE STORE
5.1. The GDPR requires notification of automated decision-making, including profiling.
5.2. Profiling may be used for direct marketing, e.g. personalized promotions, discount codes, or product suggestions. It does not affect the ability to conclude contracts or use services.
5.3. Profiling is based on customer behavior (e.g., browsing history, abandoned carts). It requires having prior data on the individual.
5.4. You have the right not to be subject to decisions based solely on automated processing that significantly affect you.
6. RIGHTS OF THE DATA SUBJECT
6.1. You have the right to access, rectify, erase, restrict processing, object to processing, and data portability (Articles 15–21 of the GDPR).
6.2. If processing is based on consent, you may withdraw it at any time without affecting previous processing.
6.3. You have the right to lodge a complaint with a supervisory authority – in Poland, this is the President of the Personal Data Protection Office (UODO).
6.4. You may object at any time to data processing based on legitimate interest or public interest (including profiling).
6.5. You may object at any time to the processing of your data for direct marketing purposes, including profiling.
6.6. To exercise your rights, contact the Controller via email, post, or the contact form on the Store website.
7. COOKIES, OPERATING DATA AND ANALYTICS
7.1. Cookies are small text files stored on a user’s device when visiting the Online Store.
7.2. Cookies are used for:
-
user authentication;
-
remembering cart contents;
-
pre-filling forms;
-
customizing Store layout;
-
generating anonymous statistics;
-
remarketing via Google and Facebook ad networks.
7.3. Most browsers accept cookies by default, but you can change this in your settings. Disabling cookies may affect Store functionality.
7.4. Browser settings determine consent for cookie use. If you do not agree, you must adjust these settings accordingly.
7.5. Instructions for managing cookies are available in your browser's help section or at:
-
Chrome
-
Firefox
-
Internet Explorer
-
Opera
-
Safari
-
Microsoft Edge
7.6. The Store may use Google Analytics (Google Ireland Ltd.) to generate anonymized usage statistics. This data does not allow identification of individuals.
7.7. You can block Google Analytics data collection by installing a browser add-on:
https://tools.google.com/dlpage/gaoptout?hl=en
8. FINAL PROVISIONS
8.1. The Online Store may include links to external websites. Users are advised to read the privacy policies of those sites. This Policy applies exclusively to this Online Store.