Processing of personal data
MISBHV processes personal data in accordance with the provisions of the Regulation of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (hereinafter: "RODO"). For the operation of the MISBHV website, through which Users can make purchases from the MISBH online store (hereinafter: the "Service"), it uses the required technical measures to ensure the protection of the processed personal data and the security of personal data against their access to unauthorized persons, acquisition by unauthorized persons, processing in violation of the law, and alteration, loss or destruction.
You have the right to ask us to obtain each time:
- 1. Information: about whether your data is being processed, and other information, in particular, about data protection violations of your data;
- 2. Access to your data;
- 3. Rectification of your data;
- 4. To be forgotten (removal of data from the service);
- 5. Restrictions on the processing of your data;
- 6. Portability of your data;
- 7. Object to the processing of your personal data, under the terms of Article 21 of the RODO;
- 8. Not to be subject to a decision based solely on automated processing (including profiling).
Personal data controller
The administrator of the personal data is MISBHV spółka z ograniczoną odpowiedzialnością with its registered office in Kraków (postal code number 30-719) at 46 Gromadzka Street, entered in the register of entrepreneurs of the National Court Register by the District Court for Kraków - Śródmieście, XI Economic Department under KRS number: 0000843876, NIP: 6762541281, REGON: 368958494, email address: [email protected] hereinafter referred to as "MISBHV" or "Administrator". The processing of personal data is understood as activities and operations performed on the personal data of Users, including storage or analysis for the services of the website misbhv.com. Personal data of Users will not be sold to third parties, including, in particular, will not be transferred to other entities for the purpose of sending third-party marketing materials.
MISBHV processes personal data of Users, in order to execute an order placed on Service, which is owned by the Administrator, and possible contact regarding the placed or initiated order process, User account registration and execution of the sales (purchase) agreement, on the basis of Article 6(1)(b) RODO and also in order to fulfill legal and fiscal obligations in connection with completed orders, on the basis of Article 6(1)(c) RODO. The personal data obtained may also be used in the legitimate interest of the Administrator, based on the premise indicated in Article 6(1)(f) RODO , e.g. for the purpose of claiming and defending in legal disputes and court proceedings, and direct marketing. Provision of data is voluntary, however, it is necessary to create an User account and complete the purchase.
In addition, if additional consents are given, personal data will be processed by the Administrator as follows:
The newsletter is available only to persons over 16 years of age. By ordering the service, the User declares that he is over 16 years old and can give such consent on his own. The data obtained will be processed for the purpose of distributing information about the Administrator's products and promotional actions, i.e. for marketing purposes (direct marketing), which is the realization of the Administrator's legitimate interest, in accordance with the premise indicated in Article 6(1)(f) RODO, or on the basis of the User's expressed consent, i.e. on the basis of the premise indicated in Article 6(1)(a) RODO. Provision of data is voluntary, however, it is necessary to subscribe to the newsletter.
Personal data obtained through the contact form will be used to fulfill the submitted inquiry and possible further contact, in accordance with the consent given, based on the premise indicated in Article 6(1)(a) of the RODO. The consent granted may be withdrawn at any time, which does not affect the legality of the processing performed on the basis of consent before its withdrawal. Provision of data is voluntary, however, it is necessary to execute/respond to the submitted application/question.
Personal data will be used for the proper execution of contracts concluded by the Administrator, on the basis of the premise indicated in Article 6(1)(b) of the RODO, or for the execution of legal and fiscal obligations on the basis of the premise indicated in Article 6(1)(c) of the RODO and also on the basis of Article 6(1)(f) of the RODO, on the basis of legitimate interest, which is the possibility of execution of contracts and maintenance of proper communication of the parties, in the case of personal data of persons indicated in concluded contracts who are not parties to those contracts. The provision of data is necessary for the conclusion and execution of the contract. The personal data in question may also be used in the legitimate interest of the Administrator, which is to be considered direct marketing of the Administrator's own products and services, on the basis of the premise indicated in Article 6(1)(f) of the RODO - in this regard, you have the right to object to the processing of your personal data for the purpose of direct marketing; lodging an objection will result in the fact that you will not receive marketing materials about the Administrator's own products and services.
In connection with pending litigation, enforcement proceedings, etc., to which the Administrator is a party, personal data of other participants in the aforementioned proceedings is processed in the Administrator's legitimate interest, which is the assertion of rights or defense against claims, in accordance with Article 6(1)(f) of the RODO.
We use Google Analytics and, if you agree, we process your data for analytical purposes.
To whom do we share your personal data ?
Your personal data may be transferred in order to perform the contract, provide the service, deliver the product, collect the fee, analyze the data, and provide marketing or customer service, to such entities as: postal operators and courier companies for delivery of shipments, banks and entities providing payment services, providing legal and accounting services to the administrator and other entities entrusted by the administrator with the processing of personal data on the basis of Article 28 and Article 29 RODO.
In addition, we transfer personal data to recipients in third countries (i.e. outside the European Economic Area), i.e. The Rocket Science Group LLC and Google LLC based in the United States, in relations with whom we have used the standard contractual clauses adopted by the European Commission and under which basic guarantees for the security of your data have been established.
Data Retention Period
The storage period for personal data may vary depending on the type of personal data collected and the purpose of processing.
Data processing shall be carried out either for (i) the period specified by law; (ii) or until the relevant purpose applicable to the specific data ceases. For example, data relating to your orders will be processed for as long as the Data Controller may be required to retain such data under applicable law, and will be deleted once this lawful purpose ceases.
The data will be stored until you withdraw your consent to its processing and opt out of receiving the newsletter, extended by the time it takes to fulfill the request made in the above regard, up to a maximum of 30 days.
The data will be processed until we respond to the submitted inquiry, end the contact.
Personal data will be processed until an instruction to delete the User account is submitted, extended by the time of implementation of the request made in the above regard, up to a maximum of 30 days. Further data in a limited scope may be stored until the statute of limitations for possible claims from historically made purchases.
And in the case of data processed for direct marketing purposes, including profiling, data for such purposes shall be processed until the data subject objects to further processing.
Anyone whose data is being processed is entitled under the RODO:
- The right to access your data and receive a copy of it;
- The right to rectification (correction) of your data if they are incorrect or outdated, as well as the right to erasure, when the processing of data does not take place for the purpose of fulfilling an obligation under the law or in the exercise of public authority;
- The right to restrict processing;
- The right to object to the processing of personal data concerning him/her on the basis of the Administrator's legitimate interest (Article 6(1)(f) RODO), including profiling under these provisions;
- The right to object to the processing of personal data concerning him/her for the purposes of direct marketing, including profiling, to the extent that the processing is related to such direct marketing;
- to the extent that the data are processed on the basis of consent or as part of the service provided (the data are necessary for the purpose of providing the service) - the right to withdraw consent to the extent that they are processed on that basis; withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal;
- The right to portability of personal data, i.e. to receive your personal data from the Administrator, in a structured, commonly used machine-readable format;
- The right to lodge a complaint with the President of the Office for Personal Data Protection (to the address of the Office for Personal Data Protection, 2 Stawki Street, 00-193 Warsaw).
To do so, contact us at: [email protected] or by mail to: MISBHV sp. z o.o. 46 Gromadzka St., 30-719 Krakow.
In order to market the Administrator's own products and services with the intention of preparing an individualized commercial offer, the Administrator may use profiling. Profiling means the processing of personal data involving the use of your personal data to evaluate some of your characteristics, in particular to analyze or forecast aspects of your personal preferences. Data subject to profiling include gender, first name, postal code and date of birth, which are used to select the commercial information sent to you about products tailored to your needs. Providing the aforementioned personal data and giving your consent to the personalization of commercial information is voluntary, but it is necessary if you wish to receive commercial information about products from us, as we only send personalized commercial information.
The website of the Service (MISBHV online store) uses "cookies". Cookies are small files that allow the device used to browse the Internet (e.g., computer, smartphone, etc.) to remember specific information about the device being used. The information recorded in cookies ensures the proper operation of Service and supports the use of its functionalities. Some cookies record statistical data and help to provide personalized content to users, and are used, among other things, for statistical purposes and to customize our services to your individual needs. You can change your cookie settings in your web browser. If you leave these settings unchanged, cookies will be stored in the memory of your device. Changing the settings regarding cookies may limit the functionality of Service.
Depending on the storage time of the files, we can distinguish the following cookies:
- a. temporary (session) files - files that are deleted automatically after you finish using the website;
- b. permanent - files stored in the memory of your device for a longer period of time, which allow us, among other things, to remember your preferred settings, which facilitates the use of Service.
Depending on the owner of the files, we can distinguish the following cookies:
- a. own - files placed on the user's device directly by their publisher, i.e. the owner of Service;
- b. Third parties - files sent via the Service by other entities.
Depending on the purpose of cookies, we can distinguish the following cookies:
- a. indispensable cookies - files that ensure proper operation of Service and simplify the shopping process (maintaining the session of the User after logging in, remembering the contents of the shopping cart). Such cookies cannot be deactivated, as this would limit the functionality of the website. These data do not store any personal data, as their function is limited to determining data protection settings, logging in or filling out forms;
- b. functional cookies - files enabling the use of all services available on the Website, including those provided by third parties, as well as files used for analytical and optimization purposes. These types of files store information about the popularity of individual subpages, the way the user uses the website, which allows, among other things, to adjust the navigation of the website to the user's needs. These files enable the creation of statistics and analysis of the effectiveness of marketing activities. Functional cookies do not contain information allowing to identify the user;
- c. marketing cookies - files that enable customization of marketing content displayed by us or our partners to the user's needs, as well as integration of Service with external services. Files of this type do not directly store information about the user's personal data, but serve only to identify the browser.
- a. proper operation of Service and simplify the purchasing process;
- b. advertising and marketing activities;
- c. creation of statistics on website viewing and collection of information on the manner of use of Service in order to improve its structure and content, as well as to analyze the effectiveness of advertising and marketing activities;
- d. Integration of the website with external services.
You can adjust your cookie settings accordingly by selecting "Settings" in the window that appears on the site whenever you visit the site for the first time or deactivate cookies via your web browser.
As a general rule, cookies do not contain data that identifies the identity of the user of the device, but in certain cases, when they are linked to other user data that uniquely identifies the user as a person, they may acquire the status of personal data. The website does not have the means or data to identify a specific person on the basis of the cookies used within the framework of the aforementioned tools, however, when transferred to the providers of these tools, they may be combined with other data located at the providers of these tools, obtaining as a result the nature of personal data. The controller of personal data in such cases will be the providers of the individual tools.
Google data protection notice Analytics
If the IP address anonymization function is enabled when you use our website, your IP address is shortened by Google. This applies to member states of the European Union and other countries listed in the Agreement on the European Economic Area. Only in exceptional cases is the full IP address sent to a Google server in the USA and shortened there. In this way, the IP address anonymization function will be active on our website. At the request of the website operator, Google uses the collected information to analyze the use of the website, to prepare reports on the use of the website and other services related to Internet use. The IP address provided by your browser as part of Google Analytics is not stored with other Google data. We only analyze your personal information based on your consent. If you do not want information about you to go to Google, simply do not give your consent when you access our website.
The information contained in this Privacy and Cookies Policy is subject to change, at our discretion. If we make any changes, we will notify users via e-mail and publishing on the website.