Privacy Policy

WHAT IS A PRIVACY POLICY?

We want to inform you about the details of how we process your personal data to give you full knowledge and comfort while using our website. Since we operate in the online industry ourselves, we know how important it is to protect your personal data. Therefore, we take special care to protect your privacy and the information you provide to us.

We carefully select and apply appropriate technical measures, especially those of a programming and organizational nature, to ensure the protection of processed personal data. Our website uses encrypted data transmission (SSL), which ensures the protection of your identifying data.

In our Privacy Policy, you will find all the essential information regarding how we process your personal data. We kindly ask you to read it, and we promise it will not take more than a few minutes.

Who is the administrator of the website www.halen.pl?

The administrator of the website is PODLASKIE TOWARZYSTWO HANDLOWE “HALEN” J.W. BUCZYŁKO SPÓŁKA JAWNA, based in Białystok, at ul. Handlowa 5, 15-399 Białystok, registered in the National Court Register by the District Court in Białystok, XII Commercial Division of the National Court Register, KRS 0000064380, NIP 5420013940, REGON 050250910, BDO 000175298 (i.e., we).

PERSONAL DATA

What legal act regulates the processing of your personal data?

Your personal data is collected and processed by us in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, p. 1), commonly known as GDPR. In areas not regulated by GDPR, the processing of personal data is governed by the Polish Personal Data Protection Act of 10 May 2018.

Who is the administrator of your personal data?

The administrator of your personal data is PODLASKIE TOWARZYSTWO HANDLOWE “HALEN” J.W. BUCZYŁKO SPÓŁKA JAWNA, based in Białystok, at ul. Handlowa 5, 15-399 Białystok, registered in the National Court Register by the District Court in Białystok, XII Commercial Division of the National Court Register, KRS 0000064380, NIP 5420013940, REGON 050250910, BDO 000175298, phone: +48 884311108, email: b2c@halen.pl.

You can contact us regarding your personal data via:

  • email: b2C@halen.pl,
  • traditional mail: ul. Handlowa 5, 15-399 Białystok,
  • phone: +48 884311108.

HOW DO WE PROCESS THE PERSONAL DATA YOU PROVIDE TO US?

What personal data do we process and for what purposes?

On our website, we offer you various services, for which we process different personal data based on various legal grounds.

PurposePersonal DataLegal BasisData Retention Period
Contract conclusion and executionname, surname, correspondence address, NIP, email, phone number, payment card numberArt. 6(1)(b) GDPR – processing necessary for contract performanceUntil the limitation period for claims arising from the contract ends
Account creation and managementname, surname, email, phone number, correspondence address, payment card numberArt. 6(1)(b) GDPR – processing necessary for contract performanceUntil the limitation period for claims arising from the contract ends
Adding reviewsnicknameArt. 6(1)(f) GDPR – legitimate interestUntil an objection to data processing is filed
Newsletteremail, name, surnameArt. 6(1)(a) GDPR – consentUntil consent is withdrawn
“Ask about product” formname, surname, email, phone numberArt. 6(1)(f) GDPR – legitimate interestUntil an objection to data processing is filed
Website traffic analysisname, residence address, IP address, browser dataArt. 6(1)(f) GDPR – legitimate interestUntil an objection to data processing is filed
Direct marketing of own goods and services, including remarketingname, residence address, IP address, browser dataArt. 6(1)(f) GDPR – legitimate interestUntil an objection to data processing is filed
Claim establishment, pursuit, and defensename, surname, residence address, PESEL, NIP, REGON, email, phone number, IP address, bank account number, payment card numberArt. 6(1)(f) GDPR – legitimate interestUntil the limitation period for claims arising from the contract ends
Compliance with legal obligationsname, surname, company, PESEL, NIP or REGON, email, phone number, correspondence address, payment card numberArt. 6(1)(c) GDPR – legal obligationUntil the expiration of the legal obligations that justified the data processing

Voluntary provision of personal data

Providing your required personal data is voluntary but necessary for us to provide services to you (e.g., sending newsletters or creating an account).

Recipients of personal data

You can find the current list of entities to which we disclose your personal data here.

Automated decision-making (including profiling)

We do not make decisions about you in an automated manner nor do we use profiling.

Will we transfer your personal data outside the EEA or to an international organization?

To use Google and YouTube tools, your personal data may be transferred to the United States, where Google LLC servers are located. Google LLC is listed in the Data Privacy Framework, ensuring adequate data protection according to EU regulations.

To use Facebook tools, your personal data may be transferred to the United States, where Meta Platforms Inc. servers are located. Meta Platforms Inc. is listed in the Data Privacy Framework, ensuring adequate data protection according to EU regulations.

To use Microsoft tools, your personal data may be transferred to the United States, where Microsoft Corporation servers are located. Microsoft Corporation is listed in the Data Privacy Framework, ensuring adequate data protection according to EU regulations.

HOW DO WE PROCESS PERSONAL DATA WE RECEIVE FROM OTHER DATA CONTROLLERS (E.G., FACEBOOK)?

Our store allows:

  • sharing store content on your Facebook profile.

In such cases, we receive your personal data not directly from you, but from services providing these functionalities, i.e., Facebook. To provide you with full control over your data, below are details on how we process your personal data.

  1. Categories of relevant personal data

We process the following categories of relevant personal data:

identification data (i.e., personal data you published on your Facebook profile, primarily name, surname, nickname, email address, and image).

  1. Source of personal data

Your personal data comes from the service:

  • Facebook, whose administrator is Meta Platforms Ireland Limited.
  1. Purposes and legal bases for processing personal data

Your personal data, which we obtained, will be processed for the following purposes:

PurposePersonal DataLegal BasisData Retention Period
Sharing content on your Facebook profilename, surname, imageArt. 6(1)(f) GDPR – legitimate interestUntil an objection to data processing is filed

YOUR RIGHTS REGARDING YOUR PERSONAL DATA PROCESSING

Based on GDPR, you have the right to:

  • request access to your personal data,
  • request correction of your personal data,
  • request deletion of your personal data,
  • request restriction of processing,
  • object to data processing,
  • request data portability.

If you submit any of the above requests, we will inform you of the actions taken regarding your request without undue delay – in any case, within one month of receiving the request.

If necessary, we may extend the monthly period by another two months due to the complex nature of the request or the number of requests.

In any case, we will inform you within one month of receiving the request about the extension of the period and provide the reasons for the delay.

Right to access personal data (Art. 15 GDPR)

You have the right to obtain information about whether we process your personal data. If we process your personal data, you have the right to:

  • access personal data,
  • obtain information about the purposes of processing, categories of processed personal data, recipients or categories of recipients of such data, the planned retention period of your data, or criteria for determining this period, the rights available to you under GDPR, and the right to lodge a complaint with the President of the Office for Personal Data Protection, the source of this data, automated decision-making, including profiling, and the safeguards used in connection with the transfer of data outside the European Union;
  • obtain a copy of your personal data.

If you wish to request access to your personal data, submit your request to: b2C@halen.pl.

Right to rectify personal data (Art. 16 GDPR)

If your personal data is incorrect, you have the right to request immediate rectification. You also have the right to request the completion of your personal data. If you wish to request rectification or completion of your personal data, submit your request to: b2C@halen

Right to delete personal data (Art. 17 GDPR)

You have the right to request the deletion of your personal data if:

  • the data is no longer necessary for the purposes for which it was collected or otherwise processed,
  • you have withdrawn your consent, and there is no other legal basis for processing,
  • you have objected to the processing of your data,
  • your data has been processed unlawfully,
  • the data must be deleted to comply with a legal obligation.

If you wish to request the deletion of your personal data, submit your request to: b2C@halen.pl.

Right to restrict processing (Art. 18 GDPR)

You have the right to request the restriction of your personal data processing if:

  • you contest the accuracy of your personal data,
  • the processing is unlawful, and you oppose the deletion of the data,
  • we no longer need the data, but you need it to establish, exercise, or defend claims,
  • you have objected to the processing.

If you wish to request the restriction of processing of your personal data, submit your request to: b2C@halen.pl.

Right to object to processing (Art. 21 GDPR)

You have the right to object to the processing of your personal data if:

  • the processing is based on legitimate interests or tasks carried out in the public interest,
  • your data is processed for direct marketing purposes.

If you wish to object to the processing of your personal data, submit your objection to: b2C@halen.pl.

Right to data portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit this data to another controller if the processing is based on consent or a contract and is carried out by automated means.

Standardly, we will provide your personal data in CSV format. If you prefer to receive your data in another format, please indicate your preferred format in your request. We will try to accommodate your preference to the best of our ability.

You can also request that we transfer your personal data directly to another controller (if technically possible).

If you wish to request data portability, submit your request to: b2C@halen.pl.

Can you withdraw your consent to the processing of personal data?

You can withdraw your consent to the processing of your personal data at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

If you wish to withdraw your consent to the processing of your personal data, submit your request to: b2C@halen.pl.

If you wish to withdraw your consent to the processing of personal data for the “Newsletter” service, you can unsubscribe here.

Complaint to a supervisory authority

If you believe that the processing of your personal data violates data protection regulations, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or place of the alleged infringement.

In Poland, the supervisory authority within the meaning of the GDPR is the President of the Office for Personal Data Protection, who replaced GIODO on May 25, 2018. More information can be found here.