PRIVACY POLICY DOCUMENT

§1 General provisions

  1. This document is an attachment to the Regulations. When you use our services, you trust us with your information. This Privacy Policy is only intended to help you understand what information and data is collected and for what purpose and what we use it for. This data is very important to us, so please read this document carefully as it defines the rules and methods of processing and protecting personal data. This document also defines the rules for the use of “Cookies”.
  2. We hereby declare that we comply with the principles of personal data protection and all legal regulations provided for in the Personal Data Protection Act and Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of individuals with regard to processing personal data and on the free movement of such data, and repealing Directive 95/46 / EC.
  3. The person whose personal data is processed has the right to contact us to obtain comprehensive information on how we use his personal data. We always try to inform clearly about the data we collect, how we use it, what purposes it is intended for and to whom we provide it, what we ensure the protection of this data when transferring it to other entities and provide information about institutions that should be contacted in case of doubt. 
  4. The seller uses technical measures such as: physical protection measures for personal data, hardware measures of IT and telecommunications infrastructure, protection measures as part of software tools and databases, and organizational measures ensuring adequate protection of personal data processed, in particular, securing personal data against disclosure to unauthorized third parties, obtaining by an unauthorized person and using them for an unknown purpose, as well as accidental or intentional change, loss, damage or destruction of such data.
  5. We have exclusive access to data on the terms set out in the Regulations and in this document. Access to personal data may also be entrusted to other entities with the help of which payments are made, which collect, process and store personal data in accordance with their Regulations, and entities that are responsible for the execution of the order. Access to personal data is granted to the above-mentioned entities to the extent necessary and only to those that will ensure the provision of services.
  6. Personal data is processed only for the purposes for which you have given your consent by clicking the appropriate fields of the form on the Website or in any other express way. The legal basis for the processing of your personal data is consent to the processing of data or the requirement to provide a service (e.g. ordering a Product) that you ordered from us (pursuant to Article 6 point 1 letter a and b of the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46 / EC (general regulation on data protection) – GDPR.

§2 Privacy policy

  1. We take privacy seriously. We are characterized by respect for privacy and the fullest possible and guaranteed comfort of using our services.
  2. We value the trust that Users place in us by entrusting us with their personal data to complete the order. We always use personal data fairly and in such a way as not to disappoint this trust, only to the extent necessary to perform the order, including its processing.
  3. You have the right to obtain clear and complete information on how we use your personal data and for what purposes it is needed. We always clearly inform about the data we collect, how we transfer it and to whom, and provide information about entities that should be contacted in case of doubts, questions or comments.
  4. In case of any doubts regarding the use of your personal data by us, we will immediately take steps to clarify and dispel such doubts, and we will fully and comprehensively answer all related questions.
  5. We will take all reasonable steps to protect Users’ data against improper and uncontrolled use and to secure them in a comprehensive manner.
  6. The administrator of your personal data is CITO Krzysztof Tomczak, ul. Chmurna 8, 61-680 Poznan (Country Poland), Tax Identification Number (NIP) PL7811604623, e-mail: contact @ cito-shop. com, 
  7. The basis for the processing of your personal data is Art. 6, section 1 (b) of GDPR. Providing data is not mandatory, but necessary to take appropriate steps prior to the conclusion of the contract and its implementation. We will transfer your personal data to other recipients entrusted with the processing of personal data on behalf of and for our benefit. Your data will be transferred based on art. 6, section 1(f) GDPR, where the legitimate interest is the proper performance of contracts / orders. In addition, we will share your personal data with other business partners. We store the collected personal data in the European Economic Area (“EEA”), but they may also be transferred to a country outside this area and processed there. Each operation of transmitting personal data is performed in accordance with applicable law. If data is transferred outside the EEA, we use standard contractual clauses and the privacy shield as safeguards in relation to countries where the European Commission has not found an adequate level of data protection.
  8. Your personal data related to the conclusion and implementation of the contract for the implementation of contracts will be processed for the period of their implementation, as well as for a period not longer than provided for by law, including the provisions of the Civil Code and the Accounting Act, i.e. not longer than 10 years, counting from the end of the calendar year in which the last contract was performed.
  9. Your personal data processed to conclude and perform future contracts will be processed until the objection is raised.
  10. You have the right to: access your personal data and receive a copy of the personal data being processed, rectify your incorrect data; request deletion of data (the right to be forgotten) in the event of circumstances provided for in art. 17 GDPR; requests to limit data processing in the cases specified in art. 18 GDPR, object to data processing in the cases specified in art. 21 GDPR, to transfer the provided data, processed in an automated manner.
  11. If you believe that your personal data is being processed unlawfully, you can lodge a complaint with the supervisory authority (Office for Personal Data Protection, ul. Stawki 2, Warsaw). If you need additional information related to the protection of personal data or want to exercise your rights, please contact us by letter to the correspondence address.
  12. We make every effort to protect against unauthorized access, unauthorized modification, disclosure, and destruction of information in our possession. In particular:
      • We review our information collection, storage and processing practices, including physical security measures, to guard against unauthorized access to systems.
      • We only grant access to personal data to employees, contractors and representatives who must have access to them. In addition, under the contract, they are obliged to maintain strict confidentiality, to enable us to control and check how they fulfill the entrusted obligations, and in the event of failure to fulfill these obligations, they may suffer consequences.

  1. We will comply with all applicable data protection laws and regulations and we will cooperate with data protection authorities and law enforcement agencies authorized to do so. In the absence of data protection regulations, we will act in accordance with generally accepted data protection principles, principles of social coexistence and established customs.
  2. The exact method of personal data protection is included in the personal data protection policy (GDPR: security policy, personal data protection regulations, IT system management manual). For security reasons, due to the procedures described in it, it is available only to state control authorities. 
  3. If you have any questions about how to handle personal data, please contact us via the page from which the user has been redirected to this Privacy Policy. The request for contact will be immediately forwarded to the appropriate person appointed for this.
  4. You always have the right to notify us if:
      • does not want to receive information or messages from us in any form;
      • would like to receive a copy of their personal data that we have;
      • correct, update or delete your personal data in our records;
      • would like to report violations, improper use, or processing of their personal data.
      • To help us answer or comment on the information provided, please provide your name and surname and further details.

§3 The scope and purpose of collecting personal data

  1. We process the necessary personal data for the purpose of providing services and for accounting purposes, and only for such purposes as:
  2. to place an order,
  3. to conclude a contract, complain and withdraw from the contract,
  4. issuing a VAT invoice or other receipt. 
  5. monitoring traffic on our websites;
  6. collecting anonymous statistics to determine how users use our website;
  7. determining the number of anonymous users of our websites
  8. controlling how often the selected content is shown to users and what content most often;
  9. controlling how often users choose a given service or the level of service from which the contact occurs most often;
  10. research on subscriptions to newsletters and contact options;
  11. use of the system of personalized recommendations for e-commerce;
  12. using the tool for communication both by e-mail and, consequently, by telephone;
  13. integration with the community portal;
  14. possible internet payments.

We collect, process, and store the following user data:

  • first name and surname,
  • residence address,
  • delivery address (if different from home address),
  • Tax Identification Number (NIP),
  • e-mail address,
  • telephone number (mobile, landline), 
  • information about web browser current in use, 
  • other personal data provided voluntarily to us.
  • Providing the above-mentioned data is completely voluntary but also necessary for the full implementation of services.

Purpose of collecting and processing or using data by us:

  1. direct marketing, archival purposes of advertising campaigns; 
  2. fulfillment of obligations imposed by law by collecting information about undesirable activities;
  3. We may transfer personal data to servers located outside your country of residence or to related entities, third parties based in other countries, including countries from the EEA (European Economic Area, EEA). European Economic Area, EEA – free trade zone and the Common Market, covering the countries of the European Union and the European Free Trade Association EFTA) for the processing of personal data by such entities on our behalf in accordance with the provisions of this Privacy Policy and applicable laws, customs and regulations regarding data protection. 
  4. We store your personal data for no longer than they are needed for the proper quality of service and, depending on the mode and purpose of obtaining them, we store them for the duration and after its completion for the purposes of:
  5. fulfillment of obligations resulting from legal regulations, tax, and accounting regulations;
  6. preventing abuse or crime;
  7. statistical and archiving purposes.
  8. Marketing activities – for the duration of the contract, granting a separate consent to the processing of such data – until the end of activities related to transaction processing, you object to such processing or withdraw your consent.
  9. Sales-related and promotional activities – e.g. contests, promotional campaigns – for the duration and settlement of such campaigns.
  10. Operational activities – until the obligations imposed by the GDPR Regulation and relevant national regulations are time-barred, to demonstrate reliability in the processing of personal data
  11. pursuing any claims related to the contract;
  12. Bearing in mind the fact that in many countries to which this personal data is transferred, the same level of legal protection of personal data does not apply as in the user’s country. The user’s personal data stored in another country can be accessed in accordance with the law in force there, for example: courts, authorities responsible for law enforcement and national security, in accordance with the laws in force in that country. Subject to lawful requests for disclosure of data, we undertake to require entities that process personal data outside the user’s country to take measures to protect data in an adequate manner to the regulation of their national law.

    TABLE:

    Categories of persons / data

    Purpose of processing

    Legal basis

    Data Retention

    BUSINESS ENTITY

    Natural or legal persons

    Conclusion and performance of contracts

    Art. 6, section 1(b) GDPR (performance of the contract)

    The data will be processed no longer than 6 months from the expiry of 6 years, after which the cooperation was terminated.

    Pursuing claims, undertaking debt collection actions

    Art. 6, section 1 (f) GDPR (legitimate interest – pursuing claims)

    Until the dispute is resolved, and in the case of settlement of the liability (repayment) for a period of 6 years from the end of the year in which the liability constituting the subject of the disputed contract expired.

    SERVICE ACTIVITY verification of needs

    Art. 6, section 1(a) and (f) GDPR (legitimate interest – analytical and statistical activities – possibly consent)

    If consent is granted until its withdrawal, restriction or other actions on your part limiting this consent,

    Data capacity and customer preferences

    MARKETING

    Potential customers, contact persons of potential customers

    Customer acquisition, including business customers, contact to present an offer

    Art. 6, section 1(f) GDPR (legitimate interest – direct marketing)

    Until the data subject submits an effective objection to the processing of his personal data.

    COMPLAINTS

    Persons submitting complaints about the services provided by the Administrator

    Receiving and considering complaints from Website Users and potential customers

    Art. 6, section 1(c) GDPR (legal obligation)
    art. 6, section 1(b) GDPR (performance of the contract)

    10 years from the receipt of the complaint and, in the event of a dispute, until it is resolved, considering the relevant limitation periods for claims.

    WEBSITE

    Website Users

    User Registration

    Art. 6, section 1(b) GDPR (performance of the contract)

    Until the end of cooperation or after 2 weeks from registration if registration was not accepted.

    Users subscribing to the newsletter

    Sending notifications about new offers

    Art. 6, section 1(a) GDPR (consent)

    Until the consent is withdrawn by the data subject or 2 weeks after subscription if the subscription has not been accepted.

    Users posting opinions on the portal and posts on the forum

    Possibility to express an opinion about the employer and add comments on the forum

    Art. 6, section 1(b) GDPR (performance of the contract)

    Until the end of cooperation.






§4 “Cookies” policy

  1. We automatically collect information contained in cookies to collect User data. A cookie file is a small piece of text that is sent to the User’s browser and which the browser sends back at the next visits to the website. They are mainly used to maintain a session, e.g. by generating and sending back a temporary identifier after logging in. We use “session” cookies stored on the User’s end device until logging out, turning off the website or turning off the web browser, and “permanent” cookies stored on the User’s end device for the time specified in the parameters of cookies or until their removal by the User.
  2. Cookies adapt and optimize the website and its offer for the needs of Users through such activities as creating page views statistics and ensuring security. Cookies are also necessary to maintain the session after leaving the website.
  3. The administrator processes the data contained in cookies each time the website is visited by visitors for the following purposes:
  4. optimizing the use of the website;
  5. identification of the Recipients as currently logged in;
  6. adaptation, graphics, selection options and any other content of the website to the individual preferences of the Customer;
  7. remembering automatically and manually completed data from Order Forms or login details provided by the visitor;
  8. collecting and analyzing anonymous statistics showing how to use the website in the administration panel and google analytics
  9. creating remarketing lists based on information about preferences, behavior, method of using the interests of the Website and collecting demographic data, and then sharing these lists in AdWords, AdSense, Facebook Ads.
  10. Google AdSense cookies are used to serve you with relevant advertisements. AdSense Cookies do not contain personal data. If you would like to learn more about the Google AdSense cookies program and how to control it, please go to http://www.google.co.uk/policies/privacy/ads/
  11. creating data segments based on demographic information, interests, preferences in the selection of viewed products / services.
  12. using demographic and interest data in Analytics reports.
  13. Due to the need to prevent the execution of certain functions on our trading platforms by internet robots, we use the Google ReCAPTCHA mechanism to sporadically test whether the behavior of users does not bear the characteristics of robotic behavior. In this case, we may disclose your IP address to Google LLC.
  14. The user at any time using his web browser can completely block and delete the collection of cookies.
  15. Blocking by the User the possibility of collecting cookies on his device may make it difficult or impossible to use some of the website functionalities to which the User is fully entitled, but in such a situation he must be aware of the functional limitations.

  1. RECAPTCHA V2

Cookies Name

Cookies Type

The purpose of saving Cookies

Cookie validity period

CONSENT

Permanent

For the sporadic testing if the users’ behavior does not indicate the behavior of robots.

2 years (since the last update)

NID

Permanent

For the sporadic testing if the users’ behavior does not indicate the behavior of robots.

2 years (since the last update)

  1. GOOGLE ADWORDS

Cookies Name

Cookies Type

The purpose of saving Cookies

Cookie validity period

PREF

Permanent

It helps you personalize ads in your services (e.g. in a search engine) – especially if you are not logged in to your Google account.

2 years (since the last update)

id

Permanent

Used for advertising outside of Google’s sites from the doubleclick.net domain

2 years (since the last update)

drt_, FLC, NID

Permanent

Ad server cookie .googleads.g.doubleclick.net. Collects information about user activities after clicking on the Google AdWords ad and returns information about conversions.

12 hours (since the last update)

  1. GOOGLE ANALYTICS

Cookies Name

Cookies Type

The purpose of saving Cookies

Cookie validity period

_UTMA

Permanent

Used to distinguish between users and sessions. The cookie is updated and each time the data is sent to Google Analytics.

2 years (since the last update)

_UTMB

Permanent

It is responsible for storing information about a particular visit

30 min (since last update)

_UMTC

Session

The _utmc cookie works with _utmb and its task is to determine whether a new visit should be tracked or whether the collected data should be included in the old one. It only contains information about the unique identifier of the site and expires when the browser window is closed.

Till the end of the session

_UMTZ

Permanent

It contains information about the sources of visits. Thanks to it, it is possible to count visits from search engines and data from marketing campaigns

6 months (since the last update)

_UMTV

Permanent

Stores the session ID. It is necessary to store information about the fact that you are logged in to the website.

2 years (since the last update)

 

  1. YOUTUBE

Cookies Name

Cookies Type

The purpose of saving Cookies

Cookie validity period

PREF

Permanent

This cookie is used by Google to user’s store preferences and information crucial to the running of Google Maps.

10 years (since the last update)

Visitor_info1_Live

Permanent

This cookie is used by YouTube to store user preferences on pages containing video content.

8 months (since the last update)

Use_Hitbox

Permanent

This cookie is used by YouTube to store user preferences on pages containing video content.

Till the end of the session

 

  1. GOOGLE MAPS

Cookies Name

Cookies Type

The purpose of saving Cookies

Cookie validity period

PREF

Permanent

This cookie is used by Google to user’s store preferences and information crucial to the running of Google Maps.

2 years (since the last update)

 

  1. FACEBOOK

Cookies Name

Cookies Type

The purpose of saving Cookies

Cookie validity period

datr

Permanent

This cookie is saved when the web browser gains access to facebook.com. The file allows recognizing suspicious login attempts, thus ensuring greater security for users. For example, it is used to signal unsuccessful login attempts or creating multiple accounts for sending spam.

2 years (since the last update)

  1. A user who does not want to use “cook

  2. A user who does not want to use “cookies” for the purpose described above may at any time delete them manually. To read the detailed instructions on how to proceed, visit the website of the manufacturer of the web browser currently used by the User.
  3. More information on Cookies is available in the help menu of each web browser. Examples of web browsers that support the aforementioned “Cookies”:
      • Internet Explorer cookie settings
      • Chrome cookie settings
      • Firefox cookie settings
      • Opera cookie settings
      • Safari cookie settings
      • Android cookies
      • Blackberry cookies
      • iOS (Safari) cookies
      • Windows Phone cookies

§5 Rights and obligations

  1. We have the right, and in cases specified by law, also the statutory obligation to provide selected or all information regarding personal data to public authorities or third parties who submit such a request for information on the basis of applicable provisions of Polish law.
  2. The User has the right to access the content of their personal data that they provide, the User may correct and supplement this data at any time, and also have the right to request that it be removed from their databases or ceased to be processed, without giving any reason. To exercise their rights, the User may at any time send a relevant message to the e-mail address or in another way that will deliver / transmit such a request.
  3. The processing of personal data of natural persons who are our clients is based on:
  4. legitimate interest as a data controller (e.g. in the field of database creation, analytical and profiling activities, including activities regarding the analysis of product use, direct marketing of own products, securing documentation for the purpose of defending against possible claims or for the purpose of pursuing claims)
  5. consent (including consent to e-mail marketing or telemarketing)
  6. performance of the concluded contract
  7. obligations under the law (e.g. tax law or accounting regulations).
  8. The processing of personal data of natural persons who are potential clients is based on:
  9. justified interests of the data controller (e.g. in the field of creating a database, direct marketing of own products)
  10. consent (including consent to e-mail marketing or telemarketing)
  11. The User’s request to delete personal data or to cease processing it may result in the complete impossibility of providing services by or severely restricting them. 
  12. We pay particular attention to profiling and indicate that:
  13. for profiling purposes, we usually process data that was previously encrypted by SSL;
  14. We use typical data for this: e-mail address and IP address or cookies
  15. we profile to analyze or forecast personal preferences and interests of people using our Websites or products or services and to adjust the content of our Websites or products to these preferences
  16. we profile for marketing purposes, i.e. matching the marketing offer to the above-mentioned preferences.
  17. We undertake to act in accordance with applicable law and the principles of social coexistence.
  18. Information on out-of-court settlement of consumer disputes. The entity authorized within the meaning of the Act on out-of-court settlement of consumer disputes is the Financial Ombudsman, whose website address is as follows: www.rf.gov.pl.

§6 Basic Safety Rules

  1. Each user should take care of their own data security and the security of their devices that access the Internet. Such a device should absolutely have an anti-virus program with an up-to-date, regularly updated database of virus definitions, types and types, a secure version of the web browser it uses, and a firewall enabled. The user should check that the operating system and the programs installed on it have the latest and compatible updates, because the attacks use the errors found in the installed software.
  2. Access data to services offered on the Internet are – e.g. logins, passwords, PINs, electronic certificates, etc. – should be secured in a place inaccessible to others and impossible to break in from the level of the Internet. They should not be disclosed or stored on the device in a form that allows unauthorized access and reading by unauthorized persons.
  3. Caution when opening strange attachments or clicking links in e-mail messages that we did not expect, e.g. from unknown senders or from the spam folder.
  4. It is recommended to run anti-phishing filters in the web browser, i.e. tools that check whether the displayed website is authentic and is not intended for phishing, e.g. by impersonating a person or institution.
  5. Files should be downloaded only from trusted places and websites. We do not recommend installing software from unverified sources, especially from unknown publishers with unverified opinion. This also applies to mobile devices, e.g. smartphones, tablets.
  6. When using a home Wi-Fi wireless network, set a password that is safe and hard to break, it should not be any pattern or string that is easy to guess (e.g. street name, host name, birthday, etc.). It is also recommended to use the highest possible standards of encryption of Wi-Fi wireless networks, which can be run on your equipment, e.g. WPA2. 

§7 Use of Social Media plugins

  1. Plug-ins of the social networks facebook.com, Twitter and others, can be found on our pages. The related services are provided respectively by the companies Facebook Inc. and Twitter Inc.
  2. Facebook is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA Facebook. To see Facebook plugins, go to: https://developers.facebook.com/docs/plugins
  3. Twitter is operated by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA. To view Twitter plugins, go to: https://dev.twitter.com/web/tweet-button
  4. The plug-in only informs its provider about which of our websites you have accessed and at what time. If, while viewing our website or visiting it, the user is logged in to his account, e.g. on Facebook or Twitter, the provider is able to combine your interests, information preferences, and other data obtained, for example, by clicking the Like button or leaving comment, or entering the profile name in the searched ones. Such information will also be transmitted directly to the provider via the browser.
  5. More detailed information on the collection and use of data by Facebook or Twitter and on the protection of privacy can be found on the following pages:
  6. Data protection / privacy advice from Facebook: http://www.facebook.com/policy.php
  7. Data protection / privacy advice issued by Twitter: https://twitter.com/privacy
  8. To avoid recording a visit to the selected user account via Facebook or Twitter on our website, you must log out of your account before browsing our websites.