Data Controller and contact information.
The Data Controller of the data collected in connection with the use of the Website is EXENO Sp. z o.o. with its registered office in Pruszków, ul. Stalowa 28/30, 05-800 Pruszków, Poland, entered into the register of entrepreneurs of the National Court Register kept by the District Court for Warsaw, 13th Commercial Division, under the KRS number: 0000868325, NIP: 5252842155, REGON: 38752066200000, e-mail [email protected]. In matters related to the processing of your data by the Controller, you can contact the Controller, contact information as above, or you can contact the Data Protection Officer appointed by the Controller at e-mail address:[email protected]
The scope of collected data.
The scope of the collected data may vary depending on how you use the EXENO website.
- The website allows you to contact the Controller and provide him with your identification data (name), contact data (email address) and information related to the content of the message.
- The Controller collects data related to your activity, such as time spent on the website, searched phrases, products, number of subpages displayed, date and source of the visit.
- You may register i.e. create an account on the EXENO website in which case you provide the Controller with identification data (name) and contact data (email address, delivery address, telephone number, country of residence).
- You may purchase items thought your account, in which case EXENO collects information about the order, payment and delivery of the products.
- If you contacted the Controller, the data was made available to us directly by you.
- If you created an account or purchased a product, the data was made available to us directly by you.
- If your data has been provided in connection with a matter handled by another person who referred the matter to the Controller, the source of the data is that person. In this case, the Controller receives identification data, address data and information related to the matter, such as a description of the case.
Purpose and legal basis for the processing of personal data.
Your data may be processed for the purpose of:
- network traffic analysis, ensuring security on the Website and adapting the content to the needs of users on the basis of the legitimate interest of the Controller (Article 6 (1) (f) of the GDPR);
- responding to questions asked by the user, forwarding the ordered goods and/or products, processing initiation of payments, and conducting correspondence in order to settle any issues, based on the consent of the user and the legitimate interest of the Controller in the fulfillment of users' requests (Article 6 (1) (a) and (f) of the GDPR).
- providing the user with marketing information in order to promote the goods and services of the Controller, based on the consent of the user (Article 6(1)(a) of the GDPR). Based on this consent, the Controller will be able to contact the user via telephone, SMS or e-mail (depending on what data the user provided during registration) in order to promote services or goods the Controller, including presenting information about current promotions or marketing campaigns. The user can unsubscribe from receiving marketing information from the Controller at any time by withdrawing consent.
- creating an account on the EXENO website for the user based on the consent of the user (Article 6(1)(a) of the GDPR).
- processing an order submitted by the user i.e. processing payment, delivering product to user, in which case processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) of the GDPR).
Right to withdraw consent.
You may withdraw your consent to the processing of contact data at any time by contacting the Controller. Withdrawal of consent may hinder or prevent contact with you.
You may withdraw your consent to the processing of data provided when creating an account by closing the account. If you have made any orders on the EXENO website, your identification data as well as data regarding past order (information concerning payment and delivery) will be stored until the expiry of the limitation period for the parties' claims related to the matter or until the expiry of any archiving obligation required by law.
You may withdraw your consent to receive marketing information from the Controller.
Obligation to provide data or voluntary provision of data.
- Providing data by you for purposes related to the opening of accounts and further the handling of any issues is voluntary, but necessary. Failure to provide it may make it difficult or impossible for the Controller to correspond with you and/or handle your matters.
- Providing the data necessary for the static analysis of the Website users is voluntary. You can use the so-called incognito mode in order to browse the website without providing the Controller with information about your visit to the Website. Using the incognito mode, and therefore not providing data, does not affect the possibility of using the Website.
- Providing the data necessary to receive marketing information is voluntary.
Rights resulting from the GDPR with regards to processing data.
You have the right to:
- request from the Controller access to your data, as well as receive a copy of the data (Article 15 of the GDPR);
- request that the Controller rectify or correct the data (Article 16 of the GDPR) – with regards to the request for rectification of data, when you notice that the data is incorrect or incomplete;
- request that the Controller delete data (Article 17 of the GDPR);
- request that the Controller limit processing (18 GDPR) - e.g. when you notice that the data is incorrect - you may request that the processing of your data be restricted for a period that allows us to check the correctness of this data;
- lodge a complaint regarding the processing of your personal data by the Controller to the President of the Personal Data Protection Office.
Recipients of your personal data.
The recipients of your personal data may only be entities that are entitled to receive the data under the law. In addition, your data may be made available to couriers, postal operators, hosting providers, mail servers, customer service operators, companies providing tools supporting the sales process as part of the online store (marketing automation), e.g. recommendation frames, chat functionality, newsletter.
Duration of data storage.
Your personal data will be stored until the consent is withdrawn. If you have made any orders on the EXENO website, your identification data as well as data regarding past order (information concerning payment and delivery) will be stored until the expiry of the limitation period for the parties' claims related to the matter or until the expiry of any archiving obligation required by law.
Data related to network traffic analysis collected through cookies and similar technologies may be stored until the cookie expires. Some cookies never expire, therefore the duration of data storage will be equivalent to the time needed by the controller to fulfill the purposes of the data collection, such as ensuring security and analyzing historical data related to website traffic.
Data transfer to a third country or to international organization.
Automated individual decision making
Personal data will be processed in an automated manner, including profiling, for which information about purchases, activities in the Controller’s sales channels (computer IP, cookies, preferred methods of purchase), sociodemographic data (e.g. gender, age, income, place of residence) are used, in order to adjust marketing information to individual preferences. The User has the right to object to the profiling of his data.
The website enables the collection of information about the user via cookies and similar technologies, the use of which most often involves the installation of this tool on the user's device (computer, smartphone, etc.). This information is used to remember the user's decisions (choosing the font, contrast, accepting the policy), maintaining the user's session (e.g. after logging in), remembering the password (with consent), collecting information about the user's device and his visit to ensure security, but also for the purposes of visit analysis and content customization.
Information obtained through cookies and similar technologies is not combined with other data of the Website users, nor is it used for their identification by the Controller.
The user can set the browser to block certain types of cookies and other technologies, by specifying, for example, that only those that are necessary for the correct display of the page will be allowed. By default, most browsers allow the use of all cookies, but the user can change these settings at any time and can also delete already installed cookies. Each of the browsers allows such operations through one of the options available in the settings or preferences.
The user also has the option to use the website in the so-called incognito mode, which blocks the possibility of collecting data about his visit.
By using the website without changing your browser settings, i.e. with the default acceptance of cookies and similar technologies, you consent to their use for the purposes set out above. The Controller does not use the obtained information for marketing purposes.