Privacy Policy
This document sets out the terms and conditions for the processing of personal data (hereinafter also referred to as “data”) and cookies in the area of the online store sugarstore.pl, operated through the website, made available at the URL: sugarstore.pl, hereinafter referred to as the “Store”.
§1. HOW TO CONTACT THE DATA CONTROLLER
The administrator of the personal data processed within the Store is Sugar Sp. z o. o. based in Kryspinowo (32-060) at ul. Modrzewiowa 9, registered at the Rejestr Przedsiębiorców of the Krajowy Rejestr Sądowy under KRS: 0000941385, NIP: 9442274779 and REGON: 520783880.
The Data Controller can be contacted at telephone number: +48 536 730 941 and at the e-mail address: hello@sugarstore.pl.
§2. ON WHAT BASIS WE PROCESS YOUR DATA
When collecting personal data, we always inform about the legal basis for its processing. It stems from the provisions of RODO (Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016. on the protection of individuals with regard to the processing of personal data on the free movement of such data and the repeal of Directive 95/46/EC – the General Data Protection Regulation). When we report on:
- Art.6(1)(a) RODO – this means that we process personal data on the basis of consent received,
- Art.6(1)(b) RODO – this means that we process personal data because it is necessary for the performance of a contract or for taking action prior to entering into a contract, at your request,
- Art.6(1)(c) RODO – this means that we process personal data in order to fulfill a legal obligation,
- Art.6(1)(f) RODO – this means that we process personal data in order to pursue legitimate interests.
§3. INFORMATION ABOUT THE PROCESSING OF DATA FOR THE PURPOSE OF CONCLUDING AND PERFORMING CONTRACTS, POSSIBLE CLAIM AND DEFENSE AGAINST THEM
- We may process personal data necessary for the performance of the contract concluded with you. However, even before it is concluded, we may process personal data necessary to take action on your request. The processing of this data is based on Art. 6(1)(b) RODO.
- During and after the execution of the contract, we process the personal data of a party to the contract for the purpose of possible processing of claims, as well as their investigation. Our legitimate interest is, for example, the ability to respond to a possible complaint, which we are obliged to do under separate provisions of civil law. In this case, we will process personal data based on our legitimate interest in defending against or asserting potential claims. The processing of this data is based on Art. 6(1)(f) RODO.
- We will store this data for the period necessary for the fulfillment of the designated purposes, no later than the statute of limitations for claims under separate laws.
- You have the right to access, rectify, erase, restrict processing of your data, the right to data portability, as well as the right to lodge a complaint with the supervisory authority. In the situation of data processing for the purpose specified in point 2, you also have the right to object to the processing.
- Provision of this data is voluntary, but failure to provide this data will prevent the conclusion of the contract or its implementation.
- The recipients of this data are our web host, email service provider, IT service provider, shipping service provider, accounting service provider, electronic payment service provider, legal, consulting and collection service provider, and other service providers we use for the designated purpose.
§4. INFORMATION ON DATA PROCESSING FOR SENDING THE NEWSLETTER
- We allow you to sign up as a recipient of our newsletter. If you have used this functionality, we process your personal data just for the purpose of sending it. The newsletter may contain advertising, commercial or marketing content.
- The processing of this data is based on your consent and thus Art. 6(1)(a) RODO.
- You have the right to revoke the consent you have given at any time. However, withdrawal of consent does not affect the lawfulness of earlier data processing.
- We will keep your data until you withdraw the consent you have given. In case you never revoke it, we will process your data until we stop sending the newsletter.
- You have the right to access, rectify, erase, restrict processing of your data, the right to data portability, as well as the right to lodge a complaint with the supervisory authority.
- Providing this data is voluntary, but failure to provide this data will prevent the newsletter from being sent.
- The recipients of this data are our web host, IT service provider and email service provider.
§5. INFORMATION ON DATA PROCESSING FOR SENDING NOTIFICATIONS
- We allow you to subscribe to the list of recipients of our notifications, displayed via a web browser. If you have used this functionality, we process your personal data just for the purpose of sending it. Notifications may contain advertising, commercial or marketing content.
- The processing of this data is based on your consent and thus Art. 6(1)(a) RODO.
- You have the right to revoke the consent you have given at any time. However, withdrawal of consent does not affect the lawfulness of earlier data processing.
- We will keep your data until you withdraw the consent you have given. In case you never revoke it, we will process your data until we stop sending notifications.
- You can revoke your consent to data processing in your web browser.
- You have the right to access, rectify, erase, restrict processing of your data, the right to data portability, as well as the right to lodge a complaint with the supervisory authority.
- Provision of this data is voluntary, but failure to provide this data will prevent the sending of notifications.
- The recipients of this data are: our web host and advertising service provider.
§6. INFORMATION ABOUT DATA PROCESSING FOR DIRECT MARKETING AND PROFILING
- We may process your personal data for direct marketing purposes. This happens, for example, when we respond to your message with details of our offer.
- For direct marketing purposes, we may use profiling, which involves automated decision-making to display advertisements to you. This decision is made on the basis of the actions you take in the Store, and in particular on the basis of contracts concluded or pages viewed. In practice, profiling supports the usability of our Store by allowing us to present you with content that may potentially be of interest to you.
- The processing of this data is based on Art. 6(1)(f) RODO.
- We will keep your data until the time necessary for the purpose of fulfillment.
- You have the right to access, rectify, erase, restrict processing of your data, the right to data portability, the right to object to data processing, and the right to lodge a complaint with a supervisory authority.
- You have the right not to be subject to profiling unless you have consented to it. However, in that case, the basis for the processing of your data will be the consent you have given (Article 6(1)(a) RODO), which you can revoke at any time. Then, too, your data will be processed until you withdraw the consent you have given.
- Provision of this data is voluntary, and failure to provide this data will prevent the implementation of direct marketing activities.
- The recipients of this data are our web host, IT service provider, email service provider and advertising service provider.
§7. INFORMATION ON DATA PROCESSING FOR SECURITY PURPOSES
- From the moment you launch our website, we process data such as: – the public IP address of the device from which the request came,
- browser type and language,
- date and time of inquiry,
- The number of bytes sent by the server,
- The URL of the previously visited page, in case the visit occurred using this link,
- information about errors that occurred in the execution of the request.
- Our legitimate interest in this processing is to keep server event logs and protect the Store from potential hacking attacks and other abuse. Including, the ability to determine the IP address of a person performing an unauthorized activity in the Store area, such as attempting to break security, or publishing prohibited content, or attempting unauthorized activities using our servers.
- The processing of this data is based on Art. 6(1)(f) RODO.
- We will store this data for the period necessary for the fulfillment of the designated purposes, no later than the statute of limitations for claims under separate laws.
- You have the right to access, rectify, delete, restrict processing of your data, object to its processing, as well as the right to lodge a complaint with a supervisory authority.
- Providing this data is a condition for using the Store. Failure to provide this data will prevent the use of the Store.
- The recipient of this data is our web host and IT service provider.
§8. INFORMATION ON DATA PROCESSING FOR NOTIFICATION OF GOODS
- The store has the functionality of sending a notification of the selected goods to the e-mail address entered by the user.
- Our legitimate interest in this processing is to fulfill your request, and subsequently to safeguard the Store against potential abuse.
- The processing of this data is based on Art. 6(1)(f) RODO.
- We will store this data for the period necessary for the fulfillment of the designated purposes, no later than the statute of limitations for claims under separate laws.
- The data subject has the right to access, rectify, erase, restrict processing of his/her data, object to its processing, as well as the right to lodge a complaint with the supervisory authority.
- Providing this data is a condition for sending the notification. Failure to provide this data will prevent this activity.
- The recipient of this data is our web host and IT service provider.
- Shipping service provider / couriers: InPost S.A, ul. Wielicka 28, 30-552 Kraków; DHL Parcel Sp. z o.o., ul. Osmańska 2, 02-823 Warsaw; DPD Polska Sp. z o.o., ul. Mineralna 15, 02-274 Warsaw; FedEx Express International B.V., Attn: Legal Department, Taurusavenue 111, 2132 LS Hoofddorp (the Netherlands); Poczta Polska Spółka Akcyjna, ul. Rodziny Hiszpańskich 8, 00-940 Warsaw; Furgonetka sp. z o.o. sp. k. based in Warsaw, al. Prince Józef Poniatowski 1, 03-901 Warsaw.
- IT service provider: Owocni.pl – Mariusz Slowik ul. Miętowa 66, 81-589 Gdynia.
- Hosting provider: LH.pl Sp. z o.o., Fr. Jakub Wujka 7/26, 61-581 Poznań.
- Email service provider: LH.pl Sp. z o.o., Fr. Jakub Wujka 7/26, 61-581 Poznań.
- Advertising services provider: Owocni.pl – Mariusz Slowik ul. Miętowa 66, 81-589 Gdynia.
- Accounting service provider: inFakt Sp. z o.o., ul. Szlak 49, 31-153 Kraków.
- Provider of legal / consulting / collection services – these service providers are established on a case-by-case basis, as each need arises.
- Electronic payment service provider: mBank S.A., ul. Prosta 18, 00-850 Warsaw.
§9. INFORMATION ON DATA RECIPIENTS
When processing personal data, we use external services. Therefore, the recipients of your personal data may be third parties. When collecting personal data, we always inform about these recipients, but due to the primacy of the readability of the message, we do so briefly. Therefore, we hereby clarify that when we report on specific categories of recipients, they are the following:
§10. ABSOLUTE RIGHTS OF DATA SUBJECTS
When we write about rights related to the processing of your personal data, we refer to the rights described below. The possibility of exercising the following rights is independent of the legal basis for processing personal data.
Right of access to data
You have the right to obtain confirmation from us as to whether we are processing personal data concerning you. If this is the case, you have the right to access this data, as well as to receive additional information about:
- processing purposes,
- categories of relevant data,
- Recipients or categories of recipients to whom the data have been or will be disclosed, in particular recipients in third countries or international organizations,
- as far as possible, the planned period of data storage, and when this is not possible, about the criteria for determining this period,
- The right to request that we rectify, erase or restrict the processing of your data, to object to such processing, and the right to lodge a complaint with a supervisory authority,
- The source of the data, if your data was not collected from you,
- automated decision-making, including profiling, and the principles of such decision-making, as well as the meaning and expected consequences of such processing for you.
Upon receipt of such a request, we are required to provide a copy of the personal data being processed. If such a request is received electronically and unless we receive another objection, we will also provide information electronically.
Right to rectify data
You have the right to request that we promptly correct personal data concerning you that is inaccurate. Taking into account the purposes of processing, you have the right to request the completion of incomplete personal data, including by providing an additional statement.
The right to erasure (to be forgotten)
You have the right to request that we immediately delete personal data concerning you. We are then obliged to delete personal data without undue delay if one of the following circumstances applies:
- you have withdrawn your consent to process your personal data and we have no other basis for processing it,
- you have made an effective objection to the processing of data concerning you,
- Your personal data was processed illegally,
- Your personal data must be deleted in order to comply with a legal obligation,
- Your data was collected in connection with offering information society services.
Right to restrict processing
You have the right to request us to restrict processing in the following cases:
- when you question the accuracy of the data – for a period of time that allows us to check its accuracy,
- processing is unlawful, and you object to the deletion of the data, requesting instead a restriction on its use,
- we no longer need your personal data for the purposes of processing, but you need them to establish, assert or defend your claims,
- you have objected to the processing of your data – until we determine whether the legitimate grounds on our side override the grounds for your objection.
Automated decisions, including profiling
You have the right not to be subject to a decision that is based solely on automated processing, including profiling, and produces legal effects on you or similarly significantly affects you.
The law does not apply if this decision:
- is necessary for the conclusion or performance of the contract between you and us,
- is permitted by the law of the Union or the law of the Republic of Poland and which provides for appropriate measures to protect your rights, freedoms and legitimate interests, or
- Is based on your explicit consent.
The right to file a complaint
You have the right to lodge a complaint in connection with the processing of your personal data, to the supervisory authority: President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw, tel. 22 531 03 00, fax. 22 531 03 01, e-mail: kancelaria@uodo.gov.pl.
§11. RELATIVE RIGHTS OF DATA SUBJECTS
When we write about rights related to the processing of your personal data, we refer to the rights described below. The possibility of using them depends in each case on the legal basis for processing personal data.
Right to withdraw consent to processing
If we process your personal data on the basis of your consent to do so, you have the right to withdraw your consent at any time. Naturally, the revocation of the granted consent does not affect the legality of the earlier processing of personal data.
Right to data portability
You have the right to receive your personal data provided to us, in a structured and commonly used machine-readable format. You also have the right to send this personal data to another controller without hindrance from our side, if the processing takes place:
- On the basis of consent or by contract, and
- in an automated manner.
In exercising your right to data portability, you have the right to request that we send your personal data directly to another controller, if technically possible. This law must not adversely affect the rights and freedoms of others.
Right to object
In case we process your personal data on the basis of Art. 6(1)(f) RODO, you have the right to object to the processing of this data, on grounds related to your particular situation.
Then we are no longer allowed to process this personal data unless we can demonstrate the existence:
- valid, legitimate grounds for processing, and these grounds must be overridden by the interests, rights and freedoms of your person, or
- grounds for establishing, asserting or defending claims.
Also, if you object to the processing of your personal data for direct marketing purposes, then we will not be able to process it for such purposes.
§12. COOKIES – INTRODUCTION
The Store’s website uses cookies. These are commonly used, small files containing a string of characters that are sent to and stored on the end device (e.g. computer, laptop, tablet, smartphone) used when visiting the Store. This information is sent to the memory of the browser you are using, which sends it back the next time you visit the website. We can categorize cookies according to three methods of division.
In terms of the purposes of using cookies, we distinguish between three categories of them:
- Necessary files – these files enable the proper operation of the website and its functionality, such as authentication or security cookies. Without saving them on your device, it will be impossible to use the website.
- Analytical files – these files allow monitoring of opened web pages, traffic sources, time spent on the website. Without saving them, the use of the website’s functionality will not be restricted.
- Advertising files – these files allow you to display personalized advertisements within or outside the website area. Without saving them, the use of the website’s functionality will not be restricted.
- Social media files – these files allow you to display a fanpage in the website area, as well as to like it. Without saving them, the use of the website’s functionality will not be restricted.
In terms of their expiration time, we distinguish between two categories of cookies:
- session files – existing until the end of a given session,
- permanent files – those that exist after the session is completed.
In terms of distinguishing the entity that administers cookies, we distinguish:
- our cookies,
- third-party cookies.
§13. DATA CONTROLLER COOKIES
The cookies we administer allow:
- access authentication,
- maintaining a session after logging in,
- Securing the Store against hacking attacks,
- “remembering” by the browser the contents of the fields of completed forms (optional),
- “remembering” by the browser of items added to the shopping cart.
This makes it easier and more pleasant to use the functionality of the Store.
§14. THIRD-PARTY COOKIES
The use of third-party cookies is subject to the privacy and cookie policies of these entities.
We use cookies administered by Google Inc. 1600 Amphitheatre Pkwy, Mountain View, CA 94043, United States as part of the services:
- Google Ads – advertising files, used to conduct and evaluate the quality of advertising campaigns, implemented using the Google Ads service,
- Google Analytics – analytical files, used to study user behavior and traffic and compile traffic statistics,
Collected by Google Inc. are anonymous and aggregate in nature. In particular, they do not contain identifying characteristics (understood as personal data) of Store users. Using the aforementioned services, we collect such data as the sources of acquisition of users visiting the Store, as well as their behavior on the Store website, information on the devices and browsers they use, IP address, domain, demographic data (age, gender), interests and geographic data.
For more information in this regard, click here: https://policies.google.com/technologies/cookies?hl=pl
We use files administered by Facebook Inc. 1 Hacker Way, Menlo Park, CA 94025, United States:
- Functional cookies used by Facebook Inc. 1 Hacker Way, Menlo Park, CA 94025, United States. These cookies may be used to connect your account on the third-party social network Facebook with your account on the Store. These cookies may also be used to process on Facebook your activities performed with the “Share” or “Like” buttons. The processing of these activities may be public.
- Advertising pixel tags, used by Facebook Inc. 1 Hacker Way, Menlo Park, CA 94025, United States. These are elements published in the digital content and allow recording information, for example, about the activity carried out on the website, as well as evaluating the effectiveness of advertisements. Facebook Inc.’s pixel tag management. is possible through Facebook, in its user panel
For more information in this regard, click here: https://www.facebook.com/policies/cookies/
HOTJAR
We use cookies administered by Hotjar Limited, Level 2, St Julian’s Business Centre, 3, Elia Zammit Street, St Julian’s STJ 1000, Malta. With the Hotjar tool, we analyze your activities on our website, including: information about your device and browser and its language, location, and anonymized IP number. We perform this analysis to optimize our website for usability. If you wish to object to the processing of your data for these purposes, please use the link: https://www.hotjar.com/legal/compliance/opt-out.
The use of third-party cookies is subject to the privacy and cookie policies of these entities. Current third-party policies in this regard, can be found on the websites listed and here: https://www.e-regulaminy.pl/biuletyn/polityki-prywatnosci-i-plikow-cookies/.
§15. CONSENT TO THE USE AND MANAGEMENT OF COOKIES
Excluding the necessary cookies, their processing is based on the user’s consent.
Consent to the processing of cookies is voluntary and can be revoked at any time. Please note, however, that failure to consent to the use of certain cookies may result in restrictions on the use of the Store and its functionality, or even prevent such use.
Permission to process cookies can be granted:
- by means of the software settings installed in the telecommunications terminal device used by the user,
- by using the button containing a statement of consent to the processing of cookies or confirming that you have read its terms,
- using the settings available in the website area.
§16. CACHE
When you use the Store’s website, we may automatically use the cache installed on your device. Within the local memory, it is possible to store data inter-sessionally, i.e. Between consecutive visits to the Store’s website. The purpose of using the cache is to speed up the use of the Store by eliminating the situation where the same data would be repeatedly downloaded from the Store, thereby overloading the user’s Internet connection. The cache can also store data such as the login password.
§17. LINKS TO OTHER WEBSITES OR SOFTWARE
The store may contain links to other websites or software. We are not responsible for the privacy and cookie processing policies of these sites or this software. We recommend that you read the privacy and cookie policies of these sites or software after accessing them or before installing them.
§18. CHANGES TO PRIVACY AND COOKIES POLICY
- The privacy and cookies policy comes into effect on the date of publication on the Store’s website.
- The Privacy and Cookies Policy is amended by publishing its new content on the Store’s website.
- We publish information about the change of Privacy and Cookies Policy