Privacy policy
§ 1– General provisions
-
The personal data controller collected via the website www.hms-fitness.pl is Abisal spółka z ograniczoną odpowiedzialnością entered into the register of entrepreneurs by the District Court Katowice-Wschód in Katowice, VIII Economic Department of the National Court Register, under the KRS no.: 0000156535, place of business and address for servings: ul. Świętej Elżbiety 6, 41-905 Bytom, NIP: 6260000945), REGON (statistical no.) 278046896, electronic mail address (e-mail): abisal@abisal.pl, tel. +48 32 307 07 91, hereinafter referred to as the controller.
-
Personal data collected by the controller via the website is processed acc. to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to processing of personal data and on the free transfer of such data, and repealing the Directive 95/46/EC (General Data Protection Regulation) hereinafter referred to as the RODO.
-
Any words or phrases capitalized in the body of this privacy policy shall be understood as defined in the terms and conditions of the www.hms-fitness.pl online store.
§ 2 Type of the personal data processed, purpose and scope of data collection
1. Purposes of processing and legal basis. The controller processes the personal data of service recipients of the www.hms-fitness.pl website for/to:
- Use the contact form to send a message to the service provider, based on Article 6(1)(F) RODO (legitimate business interest),
- Subscribing to the newsletter for the purpose of sending the commercial information electronically. Personal data is processed upon a separate consent, based on Article 6(1)(A) RODO,
- Use of the complaint form to send a message to the service provider, based on the Article 6 (1) (B) RODO (performance of the agreement),
- Use of the feedback system to send a message to the service provider, based on the Article 6 (1) (F) RODO (legitimate business interest).
2. Type of processed personal data The recipient shall provide, in:
-
Contact form: name, email address and the phone number,
-
Newsletter: email address,
-
Complaint form: name, email address, phone number, address,
-
Feedback system: name and surname.
3. Archiving period of the personal data. Personal data of service recipients is stored by the controller:
-
In case when the basis of the data processing is performance of the agreement, for as long as it is necessary for performance of the agreement, and thereafter for a period corresponding to the period of limitation of claims. Unless a special provision provides otherwise, the statute of limitations is six years, and for claims for periodic receivables and claims related to the conduct of business - three years,
-
In case when basis for data processing is a consent, as long as the consent is not revoked, and after revocation of consent for a period of time corresponding to the statute of limitations for claims that the controller may raise and that may be raised against the latter. Unless a special provision provides otherwise, the statute of limitations is six years, and for claims for periodic receivables and claims related to the conduct of business - three years,
4. When using the site, additional information may be collected, in particular: the IP address assigned to the recipient's computer or the external IP address of the Internet provider, domain name, browser type, access time and type of the operating system.
5. Upon separate consent, based on Article 6(1)(A) RODO, data may also be processed to send commercial information by electronic means or to make telephone calls for direct marketing purposes - respectively, in connection with the Article 10(2) of the Law dated 18 July 2002 on the provision of the electronic services or Article 172(1) of the Law dated 18 July 2004 - Telecommunications Law, including those directed as a result of profiling, if the service recipient has provided the appropriate consent.
6. Navigation data may also be collected from service recipients, including information about links and references they choose to click on or other actions they take on the site. The legal basis for such activities is the controller's legitimate interest (Article 6(1)(F) RODO) meaning facilitation of use of electronically provided services and improving functionality of these services.
7. Providing the personal data in question is voluntary.
8. The controller shall make all efforts to protect the interests of data subjects, and in particular ensure that the data it collects is:
-
processed in accordance with the law,
-
Collected for designated legitimate purposes and not subjected to further processing incompatible with those purposes,
-
Subject-matter correct and adequate in relation to the purposes for which data is processed, and stored in a form that enables identification of the persons whom the data relates to, for no longer than time necessary to achieve the goal of processing.
§ 3 Sharing the personal data
1. Personal data of service recipients are transferred to the service providers used by the controller when operating the website, in particular to:
-
Hosting providers,
-
Providers of software enabling the business,
-
Entities providing a mailing system,
-
Providers of the software needed to run the website.
2. The service providers referred to in clause 1 of this §, whom personal data is transferred to, depending on contractual arrangements and circumstances, are either subject to the instructions of the controller as to the goals and means of processing such data (processors) or they establish the goals and means of processing individually (controllers).
3. Personal data of service recipients is stored exclusively in the European Economic Area (EOG), subject to § 5.5 and § 6 of the Privacy Policy.
§ 4 Right to control, access the content of the data and the right to adjust it
1. The data subject has the right to access the content of his/her personal data and the right to adjust, delete, restrict the processing, the right to transfer the data as well as the right to raise objections or to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
2. Legal grounds for the service recipient's request:
-
Access to data - Article 15 RODO.
-
Data adjustment - Article 16 RODO.
-
Deletion of data (so-called Right to be forgotten) - Article 17 RODO.
-
Limitation of processing - Article 18 RODO.
-
Data transfer - Article 20 RODO.
-
Objection - Article 21 RODO
-
Withdrawal of the consent - Article 7 (3) RODO.
3. In order to exercise the rights referred to in clause 2 you can send a relevant email to: abisal@abisal.pl
4. In a situation where a service recipient makes a request under the above rights, the controller shall either fulfill the request or refuse to do so immediately, but no later than one month after receiving the request. However, if - due to the complexity of the request or the number of requests - the controller is not able to fulfill the request within one month, it will fulfill it within another two months informing the service recipient in advance - within one month of receiving the request - of the intended extension of the deadline and the reasons for it.
5. In case when processing of the personal data violates the RODO, the data subject has the right to file a complaint addressed to the president of the data protection authority.
§ 5 "Cookies" files
1. The site uses "cookies".
2. Installation of "cookies" is necessary for proper provision of services by the website. The "cookies" contain information necessary for the proper functioning of the website, and they also provide the opportunity to develop general statistics of website visits.
3. There are two main types of the cookies used by the Website: "session" and "regular".
-
Session cookies are temporary files stored at the end device of the service recipient until logging off (leaving the site),
-
Regular cookies are stored in the User's device for the time established in the parameters of the cookies or until they are deleted by the User.
4. The controller uses its own cookies to better understand how service recipients interact with the content of the website. The files collect information about the service recipient's use of the website, type of a website from which the service recipient was redirected, and number of visits and duration of the service recipient's visit to the website. This information does not record specific personal information about the service recipient, but is used to compile statistics on usage of the website.
5. The controller uses external cookies to collect general and anonymous statistical data via Google analytics tools (external cookies controller: Google llc. with its registered office in USA).
6. Cookies may also be used by advertising networks, in particular the Google network and Facebook (ads) in order to display ads tailored to the way the service recipient uses the site. For this purpose they may retain information about the service user's navigation path or time spent on a particular site.
7. The Customer has the right to decide on the access of "cookies" to his/her computer by selecting them in advance in his/her browser window. Detailed information about the possibility and methods of use of the cookies is available in your software (web browser) settings.
§ 6 Additional services related to user activity at the site
1. The website uses so-called social plug-ins ("plug-ins") of social networks/websites. By displaying the www.hms-fitness.pl website containing such a plug-in, the recipient's browser will establish a direct connection to the Facebook, Instagram, Twitter, Tiktok and Youtube servers.
2. The content of the plug-in is transmitted by the respective service provider directly to the recipient's browser and integrated into the site. Thanks to the integration in question service providers receive information that the recipient's browser has displayed the www.hms-fitness.pl site, even if the recipient does not have a profile at the service provider or is not logged in at the time. Such information (along with the recipient's IP address) is sent by the browser directly to the service provider's server (some servers are located in the USA) and stored there.
3. If the service recipient logs into one of the above-mentioned social networks, the service provider will be able to directly attribute the visit at www.hms-fitness.pl to the service recipient's profile in the respective social network.
4. If the recipient uses a particular plug-in, such as clicking on the "like" button or the "share" button, the corresponding information will also be sent directly to the server of the respective service provider and stored there.
5. The goal and scope of the data collection and its further processing and use by service providers, as well as possibility of contact and the rights of the service recipient in this regard and possibility of making settings to ensure the protection of the service recipient's privacy are described in the service providers' privacy policies:
-
Https://www.facebook.com/policy.php
-
Https://help.instagram.com/519522125107875?helpref=page_content
-
Https://help.twitter.com/en/rules-and-policies
-
Https://www.tiktok.com/legal/page/eea/privacy-policy/pl-pl
-
Https://policies.google.com/privacy?hl=pl&gl=zz.
6. If the service recipient does not want social networks to assign the data collected during a visit at www.hms-fitness.pl directly to his/her profile in the respective website, he/she must log out of the website before visiting www.hms-fitness.pl. The recipient can also completely prevent plug-ins from loading on the site by using appropriate extensions for the browser, such as blocking scripts with "noscript".
7. The controller uses re-marketing tools on the site, i.e. Google ads; this involves use of cookies from the Google llc regarding the Google ads service. As a part of the mechanism of management the settings of cookies, the recipient has the option to decide whether the service provider will be able to use Google ads (external cookies controller: Google llc. Seated in the USA) in relation to him/her.
§ 7 Miscellaneous
1. The controller shall apply technical means and organizational ones assuring data protection safety adjusted to the hazards and data category subject to protection, in particular protecting data from being disclosed to third parties, theft, processing in a way contrary to the (Personal Data Protection) law, loss, damage or destruction,
2. The Controller shall provide appropriate technical measures to prevent unauthorized persons from obtaining and modifying the personal data sent electronically.
3. To matters not regulated by this privacy policy, the provisions of RODO and other relevant provisions of Polish law shall apply accordingly.