Shisha Boutique
Privacy Policy
This document defines the Privacy Policy of the Shisha Boutique Online Store (hereinafter referred to as the “Online Store”). The Online Store is administered by Piotr Mołoniewicz, who conducts business activity under the name Cybuch Piotr Mołoniewicz, registered in the register of entrepreneurs of the Central Registration and Information on Business Activity conducted by the Minister of Development, with its registered seat at Dąbrowszczaków 6/24, 03-474 Warsaw, Poland NIP: 1132986837 REGON: 381707968. Capitalized words have the meaning given to them in the regulations of this Online Store. Personal data collected by the Administrator of the Online Store are processed in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27.04.2016 on the protection of individuals with regard to the processing of personal data and on the free flow of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (Official Journal of the EU L 119, p. 1), hereinafter referred to as: GDPR. The Administrator of the Online Store makes special efforts to protect privacy and information provided to him and concerning the Customers of the Online Store. The Administrator shall exercise due diligence in the selection and use of appropriate technical measures, including those of a programming and organizational nature, to ensure the protection of the processed data, in particular to protect the data against unauthorized access, disclosure, loss and destruction, unauthorized modification, as well as against their processing in violation of applicable laws. The addressee of the opportunity to use the Goods and Services available on the website is not children under the age of 16. The data controller does not provide for the purposeful collection of data on children under 16 years of age.
Personal data
Personal data administrator
The administrator of your personal data is:
Cybuch Piotr Mołoniewicz
Ul. Dąbrowszczaków 6/24, 03-474 Warsaw, Poland
You can contact the Data Administrator regarding your personal data via:
– e-mail: sklep@cybuchshisha.pl
– traditional mail: Cybuch Piotr Mołoniewicz, 6/24 Dąbrowszczaków St., 03-474 Warsaw
– contact form, which you can find at: https://shisha-boutique.com/contact/;
– phone: +48 730 010 250
Purposes and legal basis for processing personal data
The Personal Data Administrator processes your personal data for the following purposes and scope:
- to take action prior to the conclusion of a contract at your request (e.g. creation of an account), i.e. the data provided in the registration form in the Online Store, i.e. your e-mail address and the established password, gender; if you register an Account via an external authentication service (e.g. Google+, Facebook) we collect your name and surname, and if you register when you purchase Goods we collect your name and surname and data provided for the purpose of order processing such as shipping address; in order to provide Services that require the establishment of an Account such as maintaining order history, informing about the status of order processing, we process your data provided in the Account and when you purchase Goods;
- in order to provide Services that do not require the establishment of an Account and the purchase of Goods, i.e. browsing the web pages of the Online Store, searching for Goods, we process personal data regarding your activity in the Online Store, i.e. data regarding the Goods you browse, data regarding your device session, operating system, browser, location and unique ID, IP address;
- in order to perform the contract of sale of the Goods (e.g. delivery of the ordered Goods), as well as service prior to concluding such a contract, including through responses via chat, we process personal data provided by you when purchasing the Goods, such as your name, e-mail address, address data, payment data, and, if you purchase through an Account, additionally the established password;
- for the purpose of statistics on the use of the various functionalities available in the Online Store, to facilitate the use of the Online Store and to ensure the IT security of the Online Store, we process personal data concerning your activity in the Online Store and the amount of time spent on each sub-page in the Online Store, your search history, location, IP address, device ID, data concerning your web browser and operating system;
- for the purposes of establishing, investigating and enforcing claims and defending against claims in legal proceedings and other enforcement authorities, we may process your personal data provided when you purchase Goods or create an Account and other data necessary to prove the existence of a claim or which arises from a legal requirement, court order or other legal procedure;
- for the purpose of handling complaints, complaints and requests and responding to Customer inquiries, we process the personal data you provide in the contact form, complaints complaints and requests, or in order to respond to inquiries in another form, and certain personal data provided by you in your Account, as well as data relating to your order of Goods and other Services provided by us that are the cause of the complaint, complaint or request, and data contained in the documents attached to the complaints, complaints and requests;
- for the marketing of our Goods and Services and our customers and partners, including remarketing, including by sending newsletters; for this purpose, we process personal data provided by you when you create an Account and update it, data regarding your activity on the Online Store including orders, which are recorded and stored via cookies, in particular order history, search history, clicks on the Online Store, login and registration dates, history and your activity related to our communication with you. In the case of remarketing, we use your activity data to reach you with our marketing communications outside the Online Store and we use third-party providers for this purpose. These services involve displaying our messages on websites other than the Online Store. Please see the Cookie records for details;
- in order to organize contests and loyalty programs, i.e. notifications of accumulated points, notification of winning and advertising our offer, we use your personal data provided in your Account and when registering for a contest or loyalty program. Detailed information on this subject is provided each time in the terms and conditions of participation of a given contest or loyalty program;
- for market research and opinion research by us or our partners, i.e. order information, your data provided in the Account or when purchasing Goods, e-mail address. The data collected for market and opinion research is not used by us for advertising purposes. Exact instructions are given in the information about the respective survey or in the place where you enter your data.
Categories of relevant personal data
The controller processes the following categories of relevant personal data:
- contact data;
- data concerning activity in the Online Store;
- data concerning orders in the Online Store;
- data on complaints, complaints and requests;
- data on marketing services.
Voluntariness of providing personal data
The provision of the required personal data by you is voluntary and is a condition for the provision of services by the Personal Data Administrator through the Online Store.
Time of data processing
Personal data will be processed for the period necessary for the execution of orders, services, marketing activities and other services performed for the Customer. Personal data will be deleted in the following cases:
- when the data subject requests deletion or withdraws the consent given;
- when the data subject does not take action for more than 10 years (inactive contact);
- after being informed that the stored data is outdated or inaccurate.
Some data in the following areas: e-mail address, first and last name, may be stored for a further period of 3 years for evidential purposes, processing of complaints, claims and claims related to the services provided by the Online Store – these data will not be used for marketing purposes.
Data on orders of Goods and paid services, contests and loyalty programs will be stored for a period of 5 years from the date of delivery of the order.
We store data on non-logged-in Customers for a period of time corresponding to the life cycle of cookies stored on the devices or until they are deleted on the Customer’s device by the Customer.
Your personal data regarding your preferences, behaviors and choice of marketing content may be used as a basis for automated decisions to determine the sales opportunities of the Online Store.
Recipients of personal data
We provide your personal data to the following categories of recipients:
- state authorities, e.g. the Prosecutor’s Office, the Police, Inspector General for Personal Data Protection, the President of the OCCP, if they request us to do so.
Rights of the data subject
Under the GDPR, you have the right to:
- request access to your personal data;
- demand rectification of your personal data;
- request the erasure of your personal data;
- request the restriction of the processing of your personal data;
- to object to the processing of your personal data;
- request for the portability of personal data.
The Personal Data Administrator shall, without undue delay – and in any case within one month of receipt of the request – provide you with information on the actions taken with regard to your request. If necessary, the one-month period may be extended by another two months due to the complexity of the request or the number of requests.
In any case, the Data Administrator will inform you of such extension within one month of receipt of the request, stating the reasons for the delay.
Right of access to your personal data (Article 15 GDPR)
You have the right to obtain from the Data Administrator information on whether your personal data is being processed.
If the Administrator processes your personal data, you have the right to:
- access your personal data;
- obtain information about the purposes of the processing, the categories of personal data processed, the recipients or categories of recipients of that data, the intended period of storage of your data or the criteria for determining that period, your rights under the GDPR and the right to lodge a complaint with a supervisory authority, the source of that data, automated decision-making, including profiling, and the safeguards applied in connection with the transfer of that data outside the European Union;
- obtain a copy of your personal data.
If you wish to request access to your personal data, submit your request to: sklep@cybuchshisha.pl
Right to rectification of your personal data (Article 16 GDPR)
If your personal data is inaccurate, you have the right to request that the Administrator promptly rectify your personal data. You also have the right to request that the Administrator complete your personal data.
If you wish to request rectification of your personal data or supplementation of your personal data, please submit your request to: sklep@cybuchshisha.pl If you have registered with the Online Store your personal data can be rectified and supplemented by yourself after logging in to the Online Store.
The right to erasure of personal data, the so-called “right to be forgotten” (Article 17 GDPR)
You have the right to request the Data Administrator to erase your personal data when:
- your personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- you have withdrawn specific consent, to the extent that your personal data was processed based on your consent;
- your personal data was processed unlawfully;
- you have objected to the processing of your personal data for direct marketing purposes, including profiling, to the extent that the processing of your personal data is related to direct marketing;
- you have objected to the processing of your personal data in connection with processing necessary for the performance of a task carried out in the public interest or processing necessary for the purposes of legitimate interests pursued by the Personal Data Administrator or a third party. Despite your request for erasure, the Personal Data Administrator may continue to process your data for the purpose of establishing, asserting or defending claims of which you will be informed.
If you wish to request deletion of your personal data, please submit your request to: sklep@cybuchshisha.pl
Right to request restriction of processing of your personal data (Article 18 GDPR)
You have the right to request a restriction of the processing of your personal data when:
- you question the accuracy of your personal data – the Personal Data Administrator will restrict the processing of your personal data for a period of time that allows you to verify the accuracy of the data;
- when the processing of your data is unlawful, and instead of deleting your personal data, you request that the processing of your personal data be restricted;
- your personal data is no longer needed for the purposes of processing, but it is needed to establish, assert or defend your claims;
- when you have objected to the processing of your personal data – until it is determined whether the legitimate interests on the part of the Personal Data Administrator override the grounds stated in your objection. If you wish to request a restriction of the processing of your personal data, please submit your request to: sklep@cybuchshisha.pl
Right to object to the processing of your personal data (Article 21 GDPR)
You have the right, at any time, to object to the processing of your personal data, including profiling, in connection with:
- processing necessary for the performance of a task carried out in the public interest, or processing necessary for the purposes of legitimate interests pursued by the Personal Data Administrator or a third party;
- processing for direct marketing purposes. If you wish to object to the processing of your personal data, please submit your request to: sklep@cybuchshisha.pl
The right to request the portability of your personal data (Article 20 GDPR)
You have the right to receive your personal data from the Administrator in a structured, commonly used machine-readable format and send it to another controller. You may also request that it is the Personal Data Administrator who will send your personal data directly to another controller (if technically possible).
If you wish to request the transfer of your personal data, submit your request to: sklep@cybuchshisha.pl
Right to revoke consent
You may withdraw the consent you have given for the processing of your personal data at any time.
Withdrawal of consent to process your personal data does not affect the lawfulness of processing carried out on the basis of your consent before its withdrawal. If you wish to withdraw your consent to the processing of your personal data, submit your request to: sklep@cybuchshisha.pl
Complaint to the supervisory authority
If you believe that the processing of your personal data violates the GDPR you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, your place of work or the place where the alleged violation was committed. In Poland, the supervisory authority under the GDPR is the Office for Personal Data Protection (UODO).