Privacy Policy

This document sets out the rules for processing personal data at FLORA BIS Sp. z o.o. in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

I. GENERAL PROVISIONS

1. This document constitutes an information clause pursuant to Article 13(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: “GDPR”), for persons using the services of the data controller.

2. The controller of personal data (within the meaning of Article 4(7) GDPR) collected via the website www.flora-bis.pl is Flora Bis sp. z o.o., NIP 5742032630, registered office and correspondence address: ul. Rolnicza 3, 42-160 Krzepice, Poland, e-mail address: biuro@flora-bis.pl (hereinafter: the “Controller”).

3. Pursuant to Article 32(1) GDPR, the Controller observes the principles of personal data protection and applies appropriate technical and organisational measures to prevent accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data processed in connection with its business activity.

4. Providing personal data by the Service User is voluntary, but is a condition for concluding a contract for services provided by the Controller. The Service User is obliged to provide personal data, and failure to do so results in the inability to use the Controller’s offer.

5. Any words or expressions used in this Privacy Policy with a capital letter should be understood in accordance with their definition contained in the Terms and Conditions of the website www.flora-bis.pl.

II. PURPOSES AND LEGAL BASIS FOR PROCESSING PERSONAL DATA

1. The Controller processes personal data for the following purposes:

  1. conclusion and performance of a contract for services or products offered by the Controller in its Website;
  2. provision of electronic services available in the Controller’s Website, including enabling orders to be placed via forms available on the Website;
  3. sending marketing information regarding the Controller’s product or service offer;
  4. surveying opinions on the programmes, services and articles offered by the Controller;
  5. responding to questions addressed to the Controller via the contact form available on its website.

2. The legal basis for processing personal data is:

  1. taking action for the purpose of concluding and performing a contract (Article 6(1)(b) GDPR);
  2. the Controller’s legitimate interest, and additionally the consent of the data subject where required by applicable law (Article 6(1)(a) and (f) GDPR);
  3. the Controller’s legitimate interest (Article 6(1)(f) GDPR).

III. DATA RECIPIENTS. TRANSFER OF DATA TO THIRD COUNTRIES

  1. Recipients of personal data processed by the Controller may include:
    1. entities acting as intermediaries in deliveries or carrying out deliveries to persons purchasing the Controller’s products,
    2. electronic payment operators,
    3. providers of IT, hosting, accounting and legal services,
    4. providers of analytical tools (e.g. Google Analytics).
  2. The Controller may transfer personal data under a data processing agreement.
  3. When using analytical tools provided by entities established outside the EEA, data may be transferred to third countries, based on appropriate safeguards (e.g. standard contractual clauses).

IV. PERIOD OF STORAGE OF PERSONAL DATA

The Controller stores personal data for the period related to the term of the contract to which the processing relates, and, if the contract ends, for no longer than:

  1. for the duration of the contract concluded with the Service User and, after its termination, for purposes related to pursuing claims connected with the contract and performing obligations under applicable law, but for no longer than 10 years after its termination,
  2. for 5 years for personal data contained in billing documents (invoices), in accordance with the Accounting Act (accounting data),
  3. until consent to the processing of personal data is withdrawn,
  4. until consent is withdrawn in the case of marketing,
  5. for the period necessary to handle enquiries in the case of contact forms.

V. RIGHTS OF THE DATA SUBJECT

  1. Every person whose personal data is processed by the Controller has the right to access their data, to rectify it, to erase it (“the right to be forgotten”), to restrict processing, to data portability, to object, and to withdraw consent to the processing of data at any time.
  2. Every person who believes that their personal data is being processed by the Controller in breach of GDPR has the right to lodge a complaint with the President of the Personal Data Protection Office.

VI. PROFILING

  1. Personal data obtained by the Controller may be processed in an automated manner, including in the form of profiling, for marketing or analytical purposes. Profiling of personal data carried out by the Controller consists of assessing selected information about the data subject in order to analyse and predict personal preferences and interests, in particular to enable providing the data subject with a personalised offer.
  1. Automated processing of data carried out by the Controller does not give rise to any legal effects for the data subject.
  2. The data subject may object at any time to the automated processing of their data.

VII. “COOKIES”

  1. The Service Provider’s Website uses “cookies”.
  1. Cookies are used on the basis of the user’s consent expressed through a consent management mechanism (a “cookies” banner).
  2. The installation of “cookies” is necessary for the proper provision of services within the Website. “Cookies” contain information necessary for the proper functioning of the Website, in particular those requiring authorisation.
  3. The following types of files are used within the Website:
  1. persistent “cookies” are stored on the Service User’s end device for the period specified in the cookie parameters or until deleted by the Service User,
  2. analytical “cookies” make it possible to better understand how the Service User interacts with the Website’s content and to better organise its layout. They also collect information on how the Service User uses the Website, the type of page from which the Service User was redirected, and the number of visits and time spent on the Website. This information does not record specific personal data of the Service User, but is used to develop statistics on the use of the Website,
  3. marketing “cookies”, enabling advertising content to be tailored.
  4. The Service User has the right to decide on access to “cookies” by selecting the relevant option in their browser window. Detailed information on the possibilities and methods of handling “cookies” is available in the software (web browser) settings.

VIII. FINAL PROVISIONS

  1. The Controller applies technical and organisational measures ensuring protection of processed personal data appropriate to the risks and categories of data covered by such protection, in particular protecting the data against disclosure to unauthorised persons, removal by an unauthorised person, processing in breach of applicable law, and alteration, loss, damage or destruction.
  1. The Service Provider provides appropriate technical measures to prevent the acquisition and modification of personal data sent electronically by unauthorised persons.
  2. In matters not regulated by this Privacy Policy, the relevant provisions of the Terms and Conditions of the website www.flora-bis.pl and other applicable provisions of Polish law and GDPR shall apply accordingly.