- This Privacy Policy defines the principles of processing personal data obtained through the online store feeby.pl (hereinafter referred to as the "Online Store").
- The owner of the Store and the Administrator of Personal Data is CARO SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ SPÓŁKA KOMANDYTOWA, headquartered in Zielona Góra (65-625), ul. Krośnieńska 12, registered in the National Court Register kept by the District Court in Zielona Góra, VIII Economic Division of the National Court Register under the number KRS 0000319417, NIP: 9291807679, Regon: 080303534, hereinafter referred to as CARO SP. Z O.O. SP.K., represented by the general partner: CARO SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, headquartered in Zielona Góra (65-625), ul. Krośnieńska 12, registered in the National Court Register kept by the District Court in Zielona Góra, VIII Economic Division of the National Court Register under the number KRS 0000289149 with share capital of 50,000 PLN, having NIP: 9291782732 and Regon: 080201578.
- Personal data collected by CARO SP. Z O.O. SP.K. through the Online Store is processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as GDPR.
- CARO SP. Z O.O. SP.K. takes special care to respect the privacy of Customers visiting the Online Store.
§ 1 Type of processed data, purposes and legal basis
- CARO SP. Z O.O. SP.K. collects information about natural persons performing a legal act not directly related to their business activity, natural persons conducting business or professional activity on their own behalf, and natural persons representing legal entities or organizational units that are not legal persons but are granted legal capacity by law, hereinafter collectively referred to as "Customers."
- Customer's personal data is collected in the following cases:
- when registering an account in the Online Store, in order to create an individual account and manage it. Legal basis: necessity for the performance of a contract for the provision of an Account service (Art. 6(1)(b) of the GDPR);
- when placing an order in the Online Store, in order to execute a sales contract. Legal basis: necessity for the performance of a sales contract (Art. 6(1)(b) of the GDPR);
- when subscribing to the information newsletter (Newsletter), to perform a contract for an electronic service. Legal basis: consent of the data subject to the performance of a Newsletter service contract (Art. 6(1)(a) of the GDPR);
- when using the contact form service in the Online Store, to perform a contract for an electronic service. Legal basis: necessity for the performance of a contract for the provision of the contact form service (Art. 6(1)(b) of the GDPR);
- when using the post a review service, to perform a contract for an electronic service. Legal basis: necessity for the performance of a post a review service contract (Art. 6(1)(b) of the GDPR).
- In the case of registering an account in the Online Store, the Customer provides:
- email address;
- first and last name.
- During the registration of an account in the Online Store, the Customer independently sets an individual password for access to their account. The Customer can change the password at a later time, following the rules described in §6.
- When placing an order in the Online Store, the Customer provides the following data:
- email address;
- address details:
- postal code and city;
- country;
- street with house/apartment number.
- first and last name;
- phone number.
- In the case of Entrepreneurs, the above scope of data is additionally extended to:
- Entrepreneur's company;
- NIP (Tax Identification Number).
- When using the Newsletter service, the Customer provides only their email address.
- When using the contact form service, the Customer provides only their email address.
- When using the post a review service, the Customer provides the following data:
- email address;
- first and last name.
- When using the Online Store website, additional information may be collected, in particular: the IP address assigned to the Customer's computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type.
- Customer's navigation data may also be collected, including information about links and references they decide to click on or other actions taken in the Online Store. Legal basis: legitimate interest (Art. 6(1)(f) of the GDPR), consisting of facilitating the use of services provided electronically and improving the functionality of these services.
- In order to establish, assert, or defend claims, some personal data provided by the Customer in the course of using the functionalities in the Online Store, such as name, surname, data regarding the use of services, if the claims arise from the way the Customer uses the services, and other data necessary to prove the existence of the claim, including the size of the damage suffered, may be processed. Legal basis: legitimate interest (Art. 6(1)(f) of the GDPR), consisting of establishing, asserting, and defending claims, as well as defending against claims in proceedings before courts and other state authorities.
- Providing personal data to CARO SP. Z O.O. SP.K. is voluntary, in connection with concluded sales contracts, or the provision of services through the Online Store. However, if certain data is not provided in the forms during the Registration process, it will make it impossible to Register and create a Customer Account, and in the case of placing an order, it will make it impossible to perform this order. The scope of data required for Registration is marked in the registration form. In the case of data provided voluntarily, the basis for processing is consent (Art. 6(1)(a) of the GDPR).
- In connection with the processing of personal data for the purposes referred to in point 2, CARO SP. Z O.O. SP.K. processes personal data:
- which are included in the forms and which CARO SP. Z O.O. SP.K. obtains through the Online Store;
- which are obtained during the Customer's use of the Online Store, including the Online Store's websites, as well as other functionalities made available by CARO SP. Z O.O. SP.K. to Customers through the Online Store;
- which CARO SP. Z O.O. SP.K. obtains as a result of technical processes, such as data saved in cookies, and which are transferred when using the Online Store's websites.
§ 2 Data Administrator
- The Administrator of personal data is CARO SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ SPÓŁKA KOMANDYTOWA, headquartered in Zielona Góra (65-625), ul. Krośnieńska 12, registered in the National Court Register kept by the District Court in Zielona Góra, VIII Economic Division of the National Court Register under the number KRS 0000319417, NIP: 9291807679, Regon: 080303534, hereinafter referred to as CARO SP. Z O.O. SP.K.
- The Administrator can be contacted in writing at the following address: ul. Krośnieńska 12, 65-625 Zielona Góra, or by e-mail: [email protected].
§ 3 Data Protection Officer
- CARO SP. Z O.O. SP.K. has appointed a Data Protection Officer (DPO).
- Contact with the Data Protection Officer is possible by electronic means at the following e-mail address: [email protected] or by post at the address of the Administrator's seat.
§ 4 Storage and Security of Personal Data
- Personal data collected by CARO SP. Z O.O. SP.K. is stored in accordance with the internal procedures and security policy of CARO SP. Z O.O. SP.K.
- Personal data is stored in electronic form with proper protection measures in place.
- Access to the personal database is provided only to persons authorized by CARO SP. Z O.O. SP.K.
§ 5 Purpose and Scope of Data Collection and Recipients of Personal Data
- The scope of personal data of the Customer collected by CARO SP. Z O.O. SP.K. includes data provided by the Customer when placing an order and creating an Account, as well as data collected automatically when using the Online Store, including the information saved in the form of cookies.
- CARO SP. Z O.O. SP.K. processes the following personal data of the Customers:
- email address;
- first and last name;
- address (postal code, city, country, street with house/apartment number);
- phone number;
- Entrepreneur's company (for Entrepreneurs);
- Tax Identification Number (NIP) (for Entrepreneurs).
- CARO SP. Z O.O. SP.K. may process the following data of the Customers:
- IP address;
- the beginning, end, and subject of the Customer's session on the Online Store;
- number of points and number of art placed in the cart;
- number of the order.
- The recipients of the Customer's personal data may be:
- in the case of a Customer who uses the Online Store with the method of delivery by post or courier, CARO SP. Z O.O. SP.K. provides the collected personal data of the Customer to the selected carrier or intermediary performing the shipment at the order of CARO SP. Z O.O. SP.K.;
- in the case of a Customer who uses electronic payments in the Online Store or payment card, CARO SP. Z O.O. SP.K. provides the collected personal data of the Customer to an entity handling the above payments in the Online Store;
- in the case of a Customer who selects payment by bank transfer or electronic payment, CARO SP. Z O.O. SP.K. provides the collected personal data of the Customer to the selected entity servicing the above payments;
- in the case of a Customer who uses the services of a professional agency delivering personalized cards, CARO SP. Z O.O. SP.K. provides the collected personal data of the Customer to the selected agency;
- in the case of a Customer who uses the Newsletter service, CARO SP. Z O.O. SP.K. provides the collected personal data of the Customer to the selected mailing service;
- in the case of a Customer who uses the form of collecting personal data by CARO SP. Z O.O. SP.K., CARO SP. Z O.O. SP.K. provides the collected personal data of the Customer to the selected service provider who provides CARO SP. Z O.O. SP.K. with marketing services.
§ 6 Cookies and other tracking technologies
- The Online Store uses cookies.
- Information collected in cookies is used for purposes of administrating the Online Store, in particular, to:
- recognize the Customer's device and display the Online Store's page according to their individual preferences;
- remember the Customer's settings;
- remember the login session;
- remember the products placed in the cart;
- create statistics, which help understand how the Customers use the websites, which allows for improvement of their structure and content;
- create a profile to display personalized advertising content, including in the Google network.
- Within the Online Store, two basic types of cookies are used: session cookies and persistent cookies. Session cookies are temporary files stored on the Customer's device until they log out, leave the website, or turn off the software (web browser). Persistent cookies are stored on the Customer's device for the time specified in the cookie file parameters or until they are deleted by the Customer.
- Web browsing software (web browser) usually allows for storage of cookies on the Customer's device by default. Customers of the Online Store can change their settings in this area. Internet browsers allow for the deletion of cookies. It is also possible to automatically block cookies. Detailed information on this subject is contained in the help section or documentation of the web browser.
- Restrictions on the use of cookies may affect some of the functionalities available on the Online Store's websites.
- Cookies placed on the Customer's device may also be used by entities cooperating with CARO SP. Z O.O. SP.K.
§ 7 Legal Basis for Data Processing
- Data processing for the purpose of creating an Account and provision of services electronically is necessary for the performance of the contract for the provision of services (Article 6(1)(b) of the GDPR).
- Data processing for the purpose of sending the Newsletter is based on the Customer's consent (Article 6(1)(a) of the GDPR).
- Data processing for the purpose of performing contracts for the sale of products is necessary for the performance of the contract for the sale of products (Article 6(1)(b) of the GDPR).
- Data processing for the purpose of the Seller's marketing of their own products or services is based on the legitimate purpose pursued by the Administrator (Article 6(1)(f) of the GDPR).
- Data processing for the purpose of the Administrator's marketing of their own products or services is based on the legitimate purpose pursued by the Administrator (Article 6(1)(f) of the GDPR).
- Data processing for the purpose of pursuing claims or defending against claims is based on the legitimate purpose pursued by the Administrator (Article 6(1)(f) of the GDPR).
- Data processing for the purpose of conducting statistical measurements and improving the quality of services provided by the Administrator is based on the legitimate purpose pursued by the Administrator (Article 6(1)(f) of the GDPR).
- Data processing for the purpose of conducting marketing activities by entities cooperating with the Administrator is based on the legitimate purpose pursued by the Administrator (Article 6(1)(f) of the GDPR).
§ 8 Rights of the Data Subject
- Right to access their data and receive a copy thereof;
- Right to rectification (correction) of their data;
- Right to data transfer;
- Right to request deletion of their data. CARO SP. Z O.O. SP.K. has the right to refuse to delete the data in the cases specified by law;
- Right to request a restriction on data processing;
- Right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing that was carried out on the basis of consent before its withdrawal;
- Right to object to data processing on the basis of a legitimate interest for reasons related to their particular situation, to the processing of personal data concerning them. CARO SP. Z O.O. SP.K. may refuse to cease processing if it can demonstrate that there are valid, legitimate grounds for processing that override the interests, rights, and freedoms of the data subject or grounds for establishing, pursuing, or defending claims;
- Right to lodge a complaint with a supervisory authority. The supervisory authority in Poland is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych).
§ 9 Final Provisions
- The Online Store may contain links to other websites. CARO SP. Z O.O. SP.K. encourages the Customer to read the privacy policies of those websites. This privacy policy applies only to the Online Store run by CARO SP. Z O.O. SP.K.
- CARO SP. Z O.O. SP.K. shall notify the Customer of any changes to this privacy policy by publishing the updated privacy policy on this page. The changes shall take effect from the moment of publication.
Latest update: October 6, 2023.
- Analysis of conversion campaigns in marketing conducted using the Facebook Pixel Code tool through the social media service facebook.com (external cookie administrator: Facebook Inc with headquarters in the USA or Facebook Ireland with headquarters in Ireland);
- Presentation of ads tailored to the Customer's preferences using the Google AdWords online advertising tool (external cookie administrator: Google Inc with headquarters in the USA);
- Presentation of the Reliable Regulations Certificate through the rzetelnyregulamin.pl website (external cookie administrator: Rzetelna Grupa sp. z o.o. with headquarters in Warsaw).
- The cookie mechanism is safe for the computers of Online Store Customers. In particular, this way it is not possible to introduce viruses or other unwanted software or malicious software into the computers of Customers. Nevertheless, Customers have the option to limit or disable access to cookie files on their browsers. If this option is used, the use of the Online Store will be possible, except for functions that inherently require cookies.
- Below, we present how to change the settings of popular web browsers regarding the use of cookies:
- Internet Explorer browser Internet Explorer;
- Microsoft EDGE browser Microsoft EDGE;
- Mozilla Firefox browser Mozilla Firefox;
- Chrome and Chrome Mobile browser Chrome and Chrome Mobile;
- Safari and Safari Mobile browser Safari and Safari Mobile;
- Opera browser Opera.
- CARO SP. Z O.O. SP.K. may collect Customer IP addresses. The IP address is a number assigned to the computer of the person visiting the Online Store by the internet service provider. The IP number enables access to the Internet. In most cases, it is assigned dynamically, meaning it changes with each internet connection. The IP address is used by CARO SP. Z O.O. SP.K. to diagnose technical problems with the server, create statistical analyses (e.g., determining from which regions we have the most visits), as useful information for administering and improving the Online Store, as well as for security and potential identification of servers, unwanted automated programs for browsing the content of the Online Store.
- The Online Store contains links and references to other websites. CARO SP. Z O.O. SP.K. is not responsible for the privacy protection rules applicable to them.
§ 4 Rights of data subjects
- Right to withdraw consent - legal basis: Art. 7(3) GDPR.
- The Customer has the right to withdraw any consent given to CARO SP. Z O.O. SP.K.
- Withdrawal of consent takes effect from the moment of withdrawal.
- Withdrawal of consent does not affect the processing carried out by CARO SP. Z O.O. SP.K. in accordance with the law before its withdrawal.
- Withdrawal of consent does not have any negative consequences for the Customer, but it may prevent further use of services or functionalities that CARO SP. Z O.O. SP.K. may provide only with consent.
Privacy Policy
§ 4 Rights related to personal data
- Right to object to data processing - legal basis: art. 21 of the GDPR.
- The Customer has the right to object at any time, for reasons related to their particular situation, to the processing of their personal data, including profiling if CARO SP. Z O.O. SP.K. processes their data based on a legitimate interest, e.g., marketing CARO SP. Z O.O. SP.K.'s products and services, maintaining statistics on the use of various functionalities of the Online Store, and facilitating the use of the Online Store, as well as conducting satisfaction surveys.
- Opting out of receiving marketing communications via email will constitute the Customer's objection to the processing of their personal data, including profiling for these purposes.
- If the Customer's objection proves to be valid, and CARO SP. Z O.O. SP.K. has no other legal basis for processing their personal data, the Customer's personal data for which they raised an objection will be deleted.
- Right to erasure of data ("right to be forgotten") - legal basis: art. 17 of the GDPR.
- The Customer has the right to request the erasure of all or some of their personal data.
- The Customer has the right to request the erasure of personal data if:
- The personal data is no longer necessary for the purposes for which it was collected or processed;
- The Customer has withdrawn a specific consent, to the extent the personal data has been processed based on their consent;
- The Customer has objected to the use of their data for marketing purposes;
- The personal data is being processed unlawfully;
- The personal data must be deleted to comply with a legal obligation provided by EU law or the law of a Member State to which CARO SP. Z O.O. SP.K. is subject;
- The personal data was collected in connection with offering information society services.
- Despite the request for erasure of personal data, in connection with an objection or withdrawal of consent, CARO SP. Z O.O. SP.K. may retain some personal data to the extent that processing is necessary to establish, assert, or defend against claims, as well as to fulfill a legal obligation requiring processing under the law of the Union or a Member State to which CARO SP. Z O.O. SP.K. is subject. This applies, in particular, to personal data including: first name, last name, email address, which are retained for the purpose of handling complaints and claims related to the use of CARO SP. Z O.O. SP.K.'s services, or additionally the residential/correspondence address, order number, which are retained for the purpose of handling complaints and claims related to concluded sales agreements or service provision.
- Right to restriction of processing - legal basis: art. 18 of the GDPR.
- The Customer has the right to request the restriction of the processing of their personal data. The submission of a request, pending its consideration, prevents the use of specific functionalities or services that involve the processing of the data covered by the request. CARO SP. Z O.O. SP.K. will not send any messages, including marketing messages, during this time.
- The Customer has the right to request the restriction of personal data usage in the following cases:
- When the Customer questions the accuracy of their personal data - in such cases, CARO SP. Z O.O. SP.K. limits their use for the time needed to verify the accuracy of the data, but not for longer than 7 days;
- When the processing of data is unlawful, and instead of deleting the data, the Customer requests a restriction of their use;
- When personal data is no longer necessary for the purposes for which it was collected or used but is needed by the Customer to establish, assert, or defend claims;
- When the Customer has objected to the use of their data - in this case, the restriction is imposed for the time needed to consider whether, due to the Customer's particular situation, the protection of their interests, rights, and freedoms prevails over the interests pursued by the Administrator when processing the Customer's personal data.
- Right of access to data - legal basis: art. 15 of the GDPR.
- The Customer has the right to obtain from the Administrator confirmation of whether personal data is being processed, and if so, the Customer has the right to:
- Access their personal data;
- Receive information about the purposes of processing, the categories of personal data being processed, the recipients or categories of recipients of this data, the intended period of storing the Customer's data, or the criteria for determining this period (if it is not possible to specify the planned data processing period), the Customer's rights under the GDPR, and the right to lodge a complaint with the supervisory authority, the source of this data, automated decision-making, including profiling, and security measures taken in connection with the transfer of this data outside the European Union;
- Obtain a copy of their personal data.
- The Customer has the right to obtain from the Administrator confirmation of whether personal data is being processed, and if so, the Customer has the right to:
- Right to rectification of data - legal basis: art. 16 of the GDPR.
- The Customer has the right to request the immediate rectification of their incorrect personal data. In consideration of the purposes of processing, the Customer whose data is concerned has the right to request the completion of incomplete personal data, including by providing an additional statement, by sending a request to the email address in accordance with §7 of the Privacy Policy.
- Right to data portability - legal basis: art. 20 of the GDPR.
- The Customer has the right to receive the personal data they have provided to the Administrator and then transmit it to another selected data controller. The Customer also has the right to request that the Administrator transmit their personal data directly to such a data controller, provided it is technically feasible. In this case, the Administrator will transmit the Customer's personal data in the form of a CSV file, which is a commonly used format suitable for machine reading and allows for the transfer of the received data to another data controller.
- If the Customer exercises the above rights, CARO SP. Z O.O. SP.K. will fulfill the request or refuse to fulfill it promptly, but no later than within one month of receiving it. However, if, due to the complex nature of the request or the number of requests, CARO SP. Z O.O. SP.K. is unable to fulfill the request within one month, it will do so within the next two months, informing the Customer in advance within one month of receiving the request of the intended extension and the reasons for it.
- The Customer can submit complaints, inquiries, and requests regarding the processing of their personal data and the exercise of their rights to the Administrator.
- The Customer has the right to request CARO SP. Z O.O. SP.K. to provide a copy of standard contractual clauses by sending a request as indicated in §7 of the Privacy Policy.
- The Customer has the right to lodge a complaint with the President of the Office for Personal Data Protection in cases of violation of their personal data protection rights or other rights granted under the GDPR.
§ 5 Services tailored to preferences and interests (profiling)
- Profiling means any form of automated personal data processing that involves using personal data to evaluate certain personal aspects of an individual, in particular, to analyze or forecast aspects related to their job performance, economic situation, health, personal preferences, interests, credibility, behavior, location, or movements.
- Customer personal data may be processed in an automated manner (profiling), but this will not have any legal consequences or similarly significantly affect Customers.
- The profiling of customer data by CARO SP. Z O.O. SP.K. involves processing customer data in an automated and manual manner, using them to assess certain customer information, particularly to analyze or forecast customer personal preferences and interests.
- In order to reach customers with marketing communications outside the Online Store, CARO SP. Z O.O. SP.K. uses external service providers. These services involve displaying marketing communications on sites other than the Online Store. To achieve this, external providers install suitable code or pixels to obtain information about customer activity on the Online Store's site. Details regarding the use of cookies are available in §3. Legal basis: legitimate interest (Art. 6, para. 1, letter f of the GDPR), consisting of tailoring marketing communications to preferences and interests.
- In order to reach customers with marketing communications through the Online Store's site, CARO SP. Z O.O. SP.K. uses external service providers. These services involve displaying marketing communications on the Online Store's pages. To achieve this, external providers install suitable code or pixels to obtain information about customer activity on the Online Store's site. Details regarding the use of cookies are available in §3. Legal basis: legitimate interest (Art. 6, para. 1, letter f of the GDPR), consisting of tailoring marketing communications to preferences and interests.
§ 6 Security management - password
- CARO SP. Z O.O. SP.K. ensures customers have a secure and encrypted connection when transmitting personal data and when logging into their customer account on the website. CARO SP. Z O.O. SP.K. uses an SSL certificate issued by one of the world's leading companies in the field of internet security and data encryption for data transmitted over the internet.
- In the event that a customer with an account on the Online Store loses their password in any way, the Online Store allows the generation of a new password. CARO SP. Z O.O. SP.K. does not send password reminders. Passwords are stored in an encrypted form, making them impossible to read. To generate a new password, the customer should provide the email address in the form available at the "Forgot your password?" link provided in the login form for the customer's account on the Online Store. The customer will receive an email to the email address provided during registration or saved in the last profile change, containing a link to the dedicated form available on the Online Store's website, where the customer will have the opportunity to set a new password.
- CARO SP. Z O.O. SP.K. never sends any correspondence, including electronic correspondence, requesting the submission of login data, including the access password to the customer's account.
§ 7 Changes to the Privacy Policy
- The Privacy Policy may be subject to change, and CARO SP. Z O.O. SP.K. will inform customers about this in advance, 7 days before the changes take effect.
- Questions related to the Privacy Policy should be addressed to our Data Protection Officer: Rafał Wielgus, email: [email protected], tel. 68 411 40 00.
- Last modification date: 30.03.2021