DIRECT SALES ONLY WITHIN THE EUROPEAN UNION   |   SALES ONLY FOR BUSINESS ENTITIES - VIES VAT NUMBER REQUIRED FOR PURCHASE   |   MINIMUM QUANTITY ORDER – 5 EA (MIXED SIZES)

PRIVACY POLICY


PRIVACY POLICY OF THE ON-LINE STORE

In our activities, we place great emphasis on the implementation of data protection principles under the GDPR, i.e., Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

From the information below, you can learn in a clear and transparent manner how we process your personal data, how long we store it, and what rights you have in connection with the processing of your data.


Who is the controller of your personal data?

The controller of your personal data in connection with browsing and using the online store available at http://flebogrif-shop.balton.pl is Balton Sp. z o.o. with its registered office in Warsaw (00-496) at 7/14 Nowy Świat street, entered into

the register of entrepreneurs of the National Court Register (Krajowy Rejestr Sądowy), kept by the District Court for the capital city of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS number: 0000179860,

VIES VAT No.: PL5360015638.

In case of any doubts related to the processing of your data, please contact us at the following e-mail address: balton@balton.pl.

You can also contact our Data Protection Officer, Anna Walosińska, at iod.balton@dpag.pl.


Is providing data mandatory?

Providing us with your personal data in connection with using our online store and making purchases is completely voluntary. However, the provision of data is a contractual requirement in relation to sales contracts concluded via the online store and contracts for the provision of electronic services under the Terms and Conditions of the online store. Therefore, a refusal to provide data may prevent the conclusion and performance of the aforementioned contracts and hinder the use of our online store.


How do we protect your data?

We use appropriate technical and organizational measures to protect your data against unauthorized access, disclosure, loss, or destruction. However, it is important to be aware that no method of transmitting data over the Internet or method of electronic storage is completely free of risk. Therefore, we encourage you to exercise caution when using the Internet and request that you refrain from taking any actions that could undermine the effectiveness of our security measures.


For what purpose do we process your personal data?

We may process your personal data for the purpose of:

responding to inquiries directed to us via telephone, email, and via the contact form (data processing based on Article 6(1)(b) or (f) of the GDPR, as part of taking steps at the request of the data subject prior to entering into a contract, or as part of the pursuit of our legitimate interests);concluding and performing sales contracts and contracts for the provision of electronic services in accordance with the Terms and Conditions of the online store, i.e., in connection with the registration and maintenance of an account, placing orders, posting reviews (data processing based on Article 6(1)(b) of the GDPR);fulfilling legal obligations incumbent upon us, in particular, maintaining settlements and accounting records (data processing based on Article 6(1)(c) of the GDPR),ensuring the security, functionality, and ease of use of the online store, as well as for purposes related to improving work efficiency, the quality of services provided, and tailoring them to the recipients (Article 6(1)(f) of the GDPR, i.e., as part of the pursuit of our legitimate interests; details regarding the use of cookies can be found at the end of this Privacy Policy);establishing, pursuing, and enforcing claims available to us, or establishing and defending against claims directed against us (Article 6(1)(f) of the GDPR, i.e., as part of the pursuit of our legitimate interests).


How long will we store your data?

We will store your data for the period necessary to perform the concluded contracts, and thereafter until the limitation period for mutual claims expires.

When data is processed based on our legitimate interest, we plan to store it for the duration of the purposes described above (as a rule, this is the limitation period for claims). However, if you raise a valid objection to such processing (details regarding your rights can be found later in this privacy policy), it is possible to cease processing the data earlier than the moment the purpose is achieved.

Furthermore, if we issue a VAT invoice to you in connection with the conclusion of a sales contract, we will store your personal data for 5 years from the end of the calendar year in which the contract was performed, due to the requirements of Polish accounting and tax regulations.


Who may have access to your data?

Entities supporting our operations may have access to your data, including our service providers, subcontractors, as well as legal and tax advisory firms and, in connection with the fulfillment of order deliveries, also logistics and courier companies.

Under the GDPR, your data may also be disclosed to other entities when:

• the obligation to disclose them arises from legal provisions;

• it is our legitimate interest or the legitimate interest of a third party,

• you grant us your consent to do so.


In each case, we will strive to ensure that the scope of data disclosed to these entities is adequate and necessary for achieving the intended purposes.

Your personal data will generally be processed within the European Economic Area. In the event of a transfer of data outside the European Economic Area, the transfer will occur solely and exclusively based on one of the transfer mechanisms specified by the GDPR, in particular the Data Privacy Framework or standard contractual clauses. You have the right to obtain information about the occurrence of transfers, the applied transfer mechanisms, and the safeguards applied in this regard.


What rights do you have in connection with the processing of your data?

We want you to know that in connection with our processing of your personal data, you have the right to:

• access your data and receive a copy thereof (Article 15 of the GDPR)

You have the right to obtain from us confirmation as to whether or not we are processing your personal data and to obtain a copy of your personal data, and you may also access your personal data, obtain information about the purposes of processing, the categories of personal data concerned, the recipients or categories of recipients to whom the data have been or will be disclosed, the envisaged period for which the personal data will be stored, or the criteria used to determine that period, and about your rights under the GDPR.

• rectification of data (Article 16 of the GDPR)

You have the right to request from us the rectification of the data you have provided if it is inaccurate, and to have incomplete data completed.

• erasure of data (the so-called 'right to be forgotten', Article 17 of the GDPR)

If you believe there is no basis for us to process your personal data, you can request its erasure. This right is available to you in particular if:

the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;you have withdrawn your consent on which the processing is based,you have successfully objected to the processing of the data,the data is being processed unlawfully. We note, however, that the right to erasure is not absolute and, even as a result of its execution, we may retain certain personal data to the extent necessary for the purposes of establishing, pursuing, or defending claims, as we have a legitimate interest in doing so.

• restriction of processing (Article 18 of the GDPR)

You can request that we restrict the processing of your personal data solely to its storage or to performing actions agreed with you, if in your opinion we have incorrect data about you or are processing it without a basis, or if you do not want us to delete it because you need it to establish, pursue, or defend claims, or for the duration of the assessment of the validity of an objection to the processing of data.

• data portability (Article 20 of the GDPR)

You have the right to receive your personal data from us in a structured, commonly used, machine-readable format, the personal data concerning you which you have provided to us, based on your consent or in connection with the performance of a contract. Where technically feasible, you can request that we transmit your personal data directly to another entity.

• to object to the processing of data (Article 21 of the GDPR)

You have the right to object, on grounds relating to your particular situation, to the processing of your data if we process your data based on our legitimate interest. Following an objection, we will no longer process this data, unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise, or defence of legal claims.

• to lodge a complaint with a supervisory authority (Article 77 of the GDPR)

If you consider that the processing of your data violates the law, you can lodge a complaint on this matter with the supervisory authority, i.e., the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) with its seat at ul. Stawki 2, 00-193 Warsaw.

to withdraw consent to the processing of data (Article 7 of the GDPR)

If you have given us your consent to the processing of personal data, you can withdraw this consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.


Cookie Policy

In connection with providing the functionality of our online store, we automatically collect information contained in cookies. Cookies are IT data, in particular text files, which are stored on the device you use when using our online store.

We use the following types of cookies:

• Session cookies: used for the duration of a given browser session, after which they are permanently deleted from the device's memory.

• Persistent cookies: stored in the memory of your end device until they expire or are deleted (using your browser settings, you can delete persistent cookies or adjust their storage time).


We use Cookies for the purpose of:

• ensuring the basic functionality of our website, including, among others, adapting the website to the device you are using and maintaining your session during your use of the website (necessary cookies),

• conducting anonymous statistics and internal analyses which help us understand how users use the portal, enabling us to improve its structure and content (analytical cookies),

• remembering user preferences and tailoring the website content to their individual needs. Thanks to them, the website can offer a more personalized and convenient experience. They also allow user settings to be preserved on subsequent visits. They are not used for marketing purposes but improve the comfort of using the website (personalization cookies).

At any time, you can also change the settings of your web browser regarding the use of cookies. However, we inform you that restrictions on the use of cookies may affect the functionality of the Service. Information on how to manage cookies and the panel for modifying their settings are available in the settings of the web browser you are using.


Server Logs

We inform you that using our online store involves sending queries to the server on which our store is hosted. Each query directed to the server (every interaction with our website) is recorded in the server logs. These logs include, among other things, the User's IP address, the date and time of the query, information about the web browser and operating system you are using.

The logs are recorded and stored on the server. The data recorded in the server logs is not associated with specific individuals using the Website and is not used by us to identify you. Server logs are solely auxiliary material used for administering the Website, and their content is not disclosed to anyone except persons authorized to administer the server.


Changes to the Privacy Policy

Our activities will gradually evolve over time, as will the technologies, standards, and requirements associated with conducting business on the Internet. As a result, we will most likely regularly adjust our policy to such circumstances and requirements. A new version of this Policy will each time be published in our online store and will be effective from the date of its announcement. If you have registered in the online store, information about the update of the Policy will also be sent to your e-mail address used during registration.