PRIVACY AND COOKIES POLICY
OF THE STORE: WWW.COLOSTRUMPOLSKA.PL

  1. Scope of the Privacy and Cookies Policy

The data administrator is Colostrum Polska Sp. z o. o. with headquarters: ul. Grunwaldzka 14A/34, 10-345 Olsztyn, entered into the Register of Entrepreneurs of the National Court Register kept by the District Court for Łódź Śródmieście in Łódź, 20th Commercial Division of the National Court Register, under KRS number 0000676357, with NIP 5662018183 (hereinafter referred to as the "Administrator").

We are committed to doing the right thing when it comes to collecting, using and protecting personal data. We want you to be sure that your data is safe with us and that you fully understand how we use it to offer you better and more personalized services. That is why this Privacy and Cookies Policy (hereinafter "Policy") has been developed, which:

  • describes the types of personal data we collect;
  • explains how and why we collect and use your personal data;
  • explains when and why we will share your personal data with other organizations;
  • explains the rights and choices you have regarding your personal data.

Due to the range of products and services we offer, we want you to be clear about what this Policy covers. This Policy applies to you if you use our products and services (referred to in this Policy as “our Services”). Your use of our Services means:

  • Creating an account on our Website and using our Services offered as part of its functionality;
  • Shopping from us by telephone, online or otherwise using any website ("our Services") or mobile applications ("our mobile applications") where this policy is published;
  • This Policy also applies if you contact us or we contact you about our Services;

Our Services or mobile applications may contain links to other websites operated by other entities that have their own terms and privacy policies that explain how they use your personal information. In such situations, please read the said terms and conditions and privacy policies carefully before providing any personal information on such website,as we are not responsible for third party websites.

1.a.

The Administrator informs Users that he entrusts the processing of personal data to the following entities:
– Edrone Sp. z o. o., ul. Lekarska 1, 31-203 Kraków, NIP: 676-248-20-64, KRS: 0000537197 - in order to use the edrone.me mailing system for sending the newsletter,
- Edrone Sp. z o. o., ul. Lekarska 1, 31-203 Kraków, NIP: 676-248-20-64, KRS: 0000537197: - for marketing purposes only and exclusively for the needs of e-mail, SMS, social media campaigns launched or indicated by the Administrator using the edrone system,

1.b.

The Administrator informs that it uses the following technologies to track activities undertaken by the user/customer within the Store's website:

– edrone tracking codes – in order to analyze the statistics of the Store's website, as well as for marketing purposes only for the needs of e-mail, SMS and social media campaigns launched or indicated by the Administrator using the edrone system.

  1. Personal information we collect

This section contains information about personal data that we may collect from you when you use our Services and other personal data that we may receive from other sources.

When you register for our Services, you may provide us with: ·        Your personal data, including postal address, e-mail address, telephone number and date of birth;

·        Account login details, such as the username and password you have chosen;

When you buy from us online, browse our Websites or use our mobile applications, we may collect: ·        Information about your online purchases (for example, what you bought, when and where you bought it, and how you paid for it);

·        Information about how you browse our Websites and mobile applications and information about clicking on one of our advertisements (including on the websites of other organizations);

·        Information about any devices you use to access our Services (including brand, model and operating system, IP address, browser type and mobile device identifiers);

If you use coupons or vouchers we may collect: ·        Information on how and when you use coupons or vouchers;
By contacting us, or when we contact you or participate in promotions, competitions, surveys or surveys regarding our Services, we may collect: ·        Personal information that you provide about yourself whenever you contact us regarding our Services (for example, your name
and surname, username, contact details, login), including by telephone,
e-mail or post, or when chatting with us via social media;

·        Details of the emails and other digital messages we send to you, including any links you click on;

·        Your opinion and contribution to customer satisfaction surveys;

  1. Other sources of personal data

We may also use personal data from other sources such as specialist companies that provide information, our business partners and public registers. This type of personal data helps us, among others:

  • review and improve the accuracy of the data we hold;
  • improve and measure the effectiveness of our marketing communications, including online advertising.
  1. How and why we use personal data

The table below explains in detail how and why we use personal data:

We use personal data to: This means that the processing of your personal data allows us to: Why do we process your data in this way? Legal basis
Ensuring the accessibility of our services Managing the account you have created on our Website.

Processing your
orders and returns.

We need to process your personal data so that we can: manage your user account; provide you with goods and services that you wish to purchase; Assist with orders and returns you may request. Necessity to perform the contract

When we process:

·        data on purchases
and transactions;

·         contact details;

·        information from the user's profile;

·        delivery/collection details.

Without this information, we will not be able to provide you with our products or services.

Legitimate purpose

Data processed after the order is completed for after-sales service purposes.

Manage
and improve our daily business operations
Manage and improve our Websites and mobile applications. We use cookies and similar technologies on our Websites and mobile applications to improve the quality of customer service.

Some cookies are necessary, so you should not disable them to use all the functions of our Websites and mobile applications. You can disable other cookies, but this may affect your experience of using our websites. More information about cookies and how to disable them can be found in section Cookies and similar technologies .

Legitimate purpose
Develop and improve our range of products, services, know-how
and the way we communicate
with you.
We rely on the use of personal data to conduct market research, as well as to improve our IT systems (including security) and our product range and services. This allows us to serve you better as a customer.
Detecting and preventing fraud and other crimes. It is important that we monitor our Services in the context of detecting and preventing fraud, other crimes
and misuse of the Services. This will help us make sure you can use our Services safely.
Personalizing services to your expectations Analysing your browsing habits on our Websites and shopping habits, to better understand you as our user and customer and to provide you with personalized offers and services. Reviewing your behavior and purchases allows us to personalize our offers and services. This will help us meet your needs as a customer. Legitimate purpose
Sending appropriate marketing communications
(including by e-mail, postal mail or in the form of online advertising) regarding our products and services and the services of our suppliers and partners. Therefore
online advertising may be displayed on our websites and on third-party websites
and other online media channels. We may also measure the effectiveness of our marketing communications and those of our suppliers and business partners.
We want to ensure that we deliver marketing communications, including online advertising, that are relevant to your interests. To achieve this, we measure your responses to marketing communications related to the
products and services we offer, which means we can offer you products and services that better meet your needs as a customer.

You can change your marketing choices, both when you register with us
and at any time after.

You also have choices when it comes to online advertising. Further in the Policy, we present the options you can choose regarding cookies and how you can control your online behavioral preferences.

For most marketing communications, we rely on your consent , but there are situations where it is our legally justified purpose.
Contact
and interaction with you
Contact you about our Services, for example by telephone,
email or post, or by responding to social media posts you have made to us.
We want to serve you best as a customer, so we use personal information to provide clarification or help respond to your communications. Legitimate purpose
Management of
promotions and competitions,in which you participate, including those we conduct with our suppliers and business partners.
We need to process your personal data so that we can administer promotions
and competitions that you choose to participate in.
Inviting you to participate in customer satisfaction surveys and other market research conducted by us and other organizations acting on our behalf. We conduct market research to improve our Services. However, if we contact you about this, you do not have to participate in the study. If you tell us that you do not want us to contact you for market research purposes, we will respect that choice. This will not affect your ability to use our Services.
  1. Our legally justified purposes in using your personal data

Where we mentioned above that the use of personal data is based on our "legitimate purpose", these are:

  • servicing the needs of our customers, including the delivery of our products and services;
  • promoting and marketing our products and services;
  • account management (for example an online shopping account), managing complaints and resolving any disputes;
  • understanding our customers, including their patterns, behavior, as well as their likes and preferences;
  • protecting and supporting our business, colleagues, clients and co-owners;
  • testing and developing new products and services, as well as improving existing ones;
  • legal/regulatory requirements.
  1. How and why we share personal data with business partners and service providers

In this section we explain how and why we share personal data with business partners and service providers. When we share personal information with these companies, we require them to maintain security and are prohibited from using your personal information for their own marketing purposes.

Trading partners We work with a number of retail partners who sell products through our services.

In such situations, we only share personal data that allows our business partners to provide services. For example, when you make a purchase through our Service, we may share your name and contact information with our merchant partner so that they can deliver your selected products.

Service providers We work with carefully selected service providers who perform certain
functions on our behalf. These include, for example, companies that help us provide: customer services, technology services, storing and combining data, processing
payments and delivering orders. We only share personal information that enables our vendors to provide these services.

Some of the service providers we work with operate
online media channels in which they place appropriate advertising for our products and services, as well as for our suppliers and our trading partners. For example, you may see an announcement about our products and services when you use a particular social media site or watch online TV.

  1. How and why we share personal data with others

We may share personal information with other organizations in the following circumstances:

  • where the law or a public authority says we must share your personal data;
  • where we need to share personal data in order to establish, exercise or defend our legal rights (including transferring personal data to others for the purposes of preventing fraud and reducing credit risk);
  • to an organization to which we sell or transfer (or enter into negotiations to sell or transfer) any of our rights or obligations under any contract we may have with you. If the transfer or sale is successful, the entity receiving your personal data may use your personal data in the same way as we do;
  • to any legal successors related to our business.
  1. How we protect your personal data

We know how important it is to properly secure and manage personal data. This section highlights some
of the measures we have introduced.To ensure the security of your data, we use computer security measures such as:

  • limiting access only to employees who need it to perform their job duties;
  • we enforce physical, electronic and procedural safeguards relating to the collection, storage and disclosure of personal information;
  • physical access controls to our buildings and files;
  • Firewalls and data encryption in transit using the Secure Sockets Layer (SSL) protocol.

However, although we have taken appropriate technical and organizational measures to protect your personal data, we cannot guarantee the security of any personal data transmitted to us via the Internet.

The personal data we collect from you may be transferred to and stored at a destination outside the European Economic Area (“EEA”). It may also be processed by companies operating outside the EEA that work for us or one of our service providers. If we do so, we will ensure that we respect your privacy rights as set out in this Policy. The most common way we do this is by introducing a specific type of contract (more information on the topic can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en ) or through an approved program.

  1. How long do we process personal data

We will not keep your personal data longer than we need, which depends on several factors:

  1. (First and foremost) the reason we collected them;
  2. How long ago they were collected;
  3. Is there a legal/regulatory basis for us to keep them?
  4. Do we need them to protect yours or ours?
  1. Possibilitychoice regarding receiving marketing messages and participating in market research

We will send you relevant offers and information about our products and services in a number of ways, including by email, but only if you have previously agreed to receive this marketing information.
When you register on our Website, we will ask you whether you want to receive marketing communications. You will have the opportunity to change your selection of marketing preferences at any time via the
settings panel within your user account, by phone (+48 500102330)  or in writing ( info@colostrumpolska.pl ).

We would also like to hear your views to help us improve our Services, so we may contact you to conduct market research. You will always have the choice to participate
in our market research or to opt out.

  1. How we use cookies

Cookies are IT data - in particular text files - placed by our Website during each visit to the User's end device, which allows our websites to remember the User's computer or device and serves several purposes. The entity that places cookies on the Website User's end device and obtains access to them is the Foundation. The Website Server automatically records information sent by the User's browser when displaying the website. Server logs may include information such as the network request, IP address, browser type and language, and the date and time the request was submitted. This information allows us to improve the quality of our Services by identifying and storing User preferences and tracking trends, such as the ways in which our Services are searched.

The following types of cookies are used on our Websites:

OPERATION CHARACTERISTICS TYPE
Ensuring performance §  compatibility (e.g. browser type identification);

§  optimization (e.g. measuring the loading time of the Website content);

Session -> when you close the browser, cookies are deleted
Increased security §  checking whether the user's device is securely logged in throughout the duration of his visit to the Website; Session ->when you close the browser, cookies are deleted
Remembering preferences §  improving the operation of the Website, e.g. through personalized content, greeting or remembering the selected language; Session -> when you close the browser, cookies are deleted
Analysis of how
the Website is used
§  collecting statistics regarding, among others: the total number of visits, views and references to the Website; Fixed -> deleted after a long period of not visiting the Website
Feedback from Website Users §  not displaying one-time notifications after the User moves to the next subpage of the Website;

§  not displaying recurring notifications for a defined period;

Session -> when you close the browser, cookies are deleted

Constant -> deleted after a long period of not visiting the Website

Plugins / Widgets §  sharing the content of the Website on social media platforms;

§  recording user interactions on the Website (e.g. using a share counter);

Fixed -> deleted after a long period of not visiting the Website
Providing relevant marketing content
(especially online advertising)
§  delivering online advertising that we believe is most relevant to you on our Services and third-party websites; Fixed -> deleted after a long period of not visiting the Website
Measuring the effectiveness of our marketing communications
(including online advertising)
§  measuring the effectiveness of our online and email advertising campaigns;

§  controlling the number of ad impressions.

Fixed -> deleted after a long period of not visiting the Website

Cookies placed on the Website User's end device may also be used by third parties to offer users additional functionalities. Using the above tools or widgets may result in the collection of cookies on users' devices in order to facilitate the use of these websites and ensure that user interactions are displayed correctly on our Services.

  1. Your choices regarding cookies

Although most web browsers automatically allow cookies to be placed on your computer, the User can prohibit the receipt of cookies, thereby remaining anonymous. In such a case, please remember that if you do not consent to the placement of cookies, the user will not be able to fully use all functions of the Website. In order to configure the options of your device regarding consent to saving cookies and determining the scope of saved cookies, the User may change the settings of the web browser used (in most cases, this option is located in the Tools or the browser's Preferences menu).

Please be advised that if the User does not change the cookie settings, they will be stored
on the User's end device. In such a case, our Websites may store information on the User's end device and gain access to this information.

Information on managing cookies in specific browsers can be found on the pages dedicated to individual browsers:

Additional information about managing cookies can be found on websites such as http://allaboutcookies.org

  1. Right to access data

You have the right to access your personal data that we store.

  1. Other rights of persons whose data are processed

In relation to your personal data, you also have:

  • Right to correct data

If you believe we have inaccurate or missing information about you, please let us know and we will correct it.

  • Right to object

General objection – we will consider your objection to our use of your personal data. If your rights outweigh our interests in using your personal data, then at your request we will either restrict its processing (see section 14.3 below) or delete it (see section 14.4 below).

Objection to direct marketing – if you submit such an objection, we will stop using your personal data for direct marketing purposes. As a result of your objection to direct marketing and if we have no other legal basis for their use, the processing of your personal data will be suspended within 30 days.

  • Right to restrict data processing

There are several situations in which you can restrict the use of your personal data, including (but not limited to):

  • you have submitted a general objection (listed in section 14.2 above);
  • you dispute the accuracy of the personal data we hold about you;
  • We have used your personal data unlawfully, but you do not want us to delete it.
  • Right to delete data

There are several situations in which you can ask us to delete your personal data, including (but not limited to):

  • we no longer need to store your personal data;
  • you have successfully filed a general objection (listed in section 14.2 above);
  • you have withdrawn your consent to our use of your personal data (and we have no other reason to use it);
  • We have unlawfully processed your personal data.
  • Right to transfer data

If you would like to receive a copy of the personal data we hold about you, please contact us via the following address: info@colostrumpolska.pl

  • Right to lodge a complaint with the supervisory authority

We would like to be able to resolve any of your requests and comments, but you also have the right to lodge a complaint directly with your local supervisory authority if you believe that we are unlawfully processing your personal data.

  • More information about your data protection rights

The website of the President of the Office for Personal Data Protection (PUODO) regarding data protection contains more detailed information about your rights to the protection of personal data mentioned above. If you would like to discuss these rights with us in more detail, please use the section below on "how to contact us".

  1. How to contact us

If you have questions about how we collect, store and use your personal data, please contact us
:

Telephone: ( + 48 500102330)

E-mail:      info@colostrumpolska.pl

Post office:     Grunwaldzka 14a/34, 10-124 Olsztyn

The policy was last updated: 23/10/2024