Privacy Policy
Privacy Policy
This privacy policy (“Privacy Policy”) constitutes an integral part of the carcosmetics.pl store’s Terms of Service. Acceptance of the Terms of Service is tantamount to acceptance of the Privacy Policy. Prior to using the carcosmetics.pl service, the Buyer should familiarize themselves with the Privacy Policy. The Privacy Policy specifies rules concerning the processing and protection of the personal data of persons using the carcosmetics.pl website.
1. Data Controller
1.1. The Controller of personal data of the persons using the carcosmetics.pl website, including Buyers and Users, is the company Endurance Sp. z o.o. with a registered office at ul. Daniłowskiego 9, 42-216 Częstochowa, entered by the District Court in Częstochowa into the entrepreneurs’ registry of the National Court Register under the number 0000581624, Tax ID: 9492203126; REGON 362787880 (“Controller”).
1.2. The Controller processes personal data in compliance with the requirements of the European Parliament and Council (EU) Regulation 2016/679 dated 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (further called “GDPR”).
2. Collected Data
Collected personal data include: name and surname, business name (company), Tax ID, business address, delivery address, telephone number, e-mail, credit card number, bank account number, the User’s login and password, IP address of the computer used to register or place an order. Personal data are collected on registration of a User, when filling out an Order form, a newsletter subscription form, during communication with the data subject.
3. Purpose of Data Processinh
Data shall be processed for the following purposes:
3.1. Provision of the Account service – for the period of holding an Account to the benefit of the User, until the time of User Account deletion at the request of the User – in compliance with art. 6 item 1 letter b) of GDPR;
3.2. Conclusion and performance of product sales contracts via the Website – until the completion of contract performance – in compliance with art. 6 item 1 letter b) and art. 9 item 2 letter h) of GDPR;
3.3. Performance of the Controller’s legal obligations, in particular arising from tax law regulations – for a period of 5 years from the end of a calendar year in which the payment deadline of the applicable tax related to the conclusion and performance of a product sales contract via the Website has expired, or longer, if so required by legal regulations – in compliance with art. 6 item 1 letter c) and art. 9 item 2 letter h) of GDPR;
3.4.Establishment and assertion of or defense against claims which the Controller or the Customer may have towards one another (including data contained in the User Account, data concerning product sales contracts via the Website) – in compliance with art. 6 item 1 letter f) and art. 9 item 2 letter h) of GDPR – for the limitation periods of claims, as specified in legal regulations;
3.6.Distribution of a newsletter with information concerning products offered by the Data Controller – until withdrawal of the User’s consent – in compliance with art. 6 item 1 letter a) of GDPR;
3.7. Display of personalized advertisements on the carcosmetics.pl website, including comprehension of purchase processes and correlations between products, on the basis of purchase history, products in the Customer’s cart, and the product browsing history – until the User’s objection – in compliance with art. 6 item 1 letter f) of GDPR;
4. Voluntary nature of providing data, consent to processing
4.1. Provision of data is voluntary. Within the scope specified in the Terms of Service, the provision of data is required for the purpose of Registration or placement and performance of an Order.
4.2. Customers may provide their personal data, simultaneously not giving consent to their processing for the purpose of receiving the newsletter.
4.3. In the event of giving consent to processing of the Customer’s data for the aforementioned purposes, the Customer may withdraw their consent at any time by contacting the Customer Service Office at the e-mail address sklep@carcosmetics.pl or tel. no.: +48 34 387 86 89. A Customer may also withdraw their consent to receive the newsletter by clicking the corresponding link included in each newsletter. Withdrawal of consent shall not affect the legitimacy of processing performed based on consent prior to its withdrawal.
5. Rights related to the processing of personal data
5.1. Each person whose personal data is processed has the right to access the personal data concerning them, to amend such data and to object to data processing (if it is possible in light of legal regulations), to limit processing, as well as to transfer their data. A person whose personal data is processed also has the right to submit a complaint with the personal data protection authority.
5.2.Customers may contact the Data Protection Officer (DPO) appointed by Endurance Sp. z o.o. via the tel. no.: +48 34 387 86 89 or electronic mail at sklep@carcosmetics.pl.
5.3. The expected recipients of data are entities whom the Controller has entrusted with the processing of data, including, for example, entities providing the technical infrastructure used for the purpose of operating the Website, logistic service providers, entities to which the Controller has outsourced customer service processes, employees and partners of the Controller or other entities – within the scope necessary to realize the aims stipulated in this Privacy Policy or arising from contracts which a Customer has concluded with the Controller.
5.4. The Data Controller may refuse to delete Data, if it is justified by legal regulations.
6. Data Security
6.1. The Data Controller uses appropriate technical and organizational means to ensure security of processed data, in particular, securing data against disclosure to unauthorized persons, processing in violation of the law or modification, loss, damage or destruction.
6.2. Only persons authorized by the Controller are allowed to process Customer data within the Controller’s organization.
7. Other Provisions
7.1. Data may be disclosed to entities authorized to obtain them in light of applicable legal regulations, including to appropriate law enforcement bodies. The Data Controller shall provide collected personal data to state administration bodies, law enforcement bodies and judicial bodies at their explicit request and only in circumstances specified by legal regulations.
7.2. Information concerning the use of cookies are included in the Cookie Policy.
7.3. The Data Controller reserves the right to make amendments to this Privacy Policy. Every person who uses the carcosmetics.pl service in any manner is bound by the current version of the Privacy Policy.