PRIVACY AND COOKIES POLICY OF THE WEBSITE http://hempking.eu
§ 1. General Provisions
1. Privacy and Cookies Policy of the Website http://hempking.eu (hereafter: the “Policy”) has been developed and adopted by Biodio Sp. z o.o. Sp.k., ul. Choroszczańska 24, 15-732 Białystok, NIP: 542-339-33-34.
2. The terms used in the Policy shall mean:
Website: website available at http://hempking.eu;
User: entity using the publicly available Website;
Owner: Biodio Sp. z o.o. Sp.k., ul. Choroszczańska 24, 15-732 Białystok, NIP: 542-339-3334;
Cookies: text files sent by the Website and saved on the User’s end device that the User uses when browsing sites. Files contain information necessary for the proper functioning of the Website. Cookies most frequently contain the name of the website domain from which they originate, their storage time on the User’s end device as well as a unique number.
3. The Policy aims in particular at:
– ensuring that Users’ privacy is protected to the extent that it complies with the standards and requirements set out in the applicable laws.
4. The Owner limits the collection and use of information concerning the Users to the necessary minimum required for the provision of services to them and within the scope of the consent given by the User.
6. The following legal provisions, among others, apply:
– The Act of 16 July 2004 – Telecommunications Law (Journal of Laws of 2019, 2460, i.e. as amended);
– The Act of 18 July 2002 on the Provision of Electronic Services (Journal of Laws of 2019, 123, i.e. as amended);
– Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation, Official Journal L, 119 of 04.05.2016, as amended);
– Personal Data Protection Act of 10 May 2018 (i.e. Journal of Laws of 2019, item 1791, as amended).
§ 2. Protection of privacy and personal data
I. Information clause
Biodio Sp. z o.o. Sp.k., as a Personal Data Controller, in accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR,
Official Journal of the European Union L, No. 119, p. 1), provides information on the processing of personal data:
1. The Personal Data Controller is Biodio Sp. z o.o. Sp.k. The registered office of the Controller is located at ul. Choroszczańska 24, 15-732 Białystok. The Controller can be contacted via e-mail: [email protected], by traditional mail and by phone: +48 884 734 844.
2. Depending on the purpose of data processing and the form of contact with Biodio Sp. z o.o. Sp.k. you may be asked to provide more or less information necessary for the provision of services offered by Biodio Sp. z o.o. Sp.k., i.e.: first and last name, correspondence address, e-mail address, telephone number, data necessary for issuing an invoice, etc.
3. Personal data can be processed for the following purposes:
– to provide information on the products offered by Biodio (e-mail and text message marketing, analysing of the customer’s interests in order to offer them the most suitable purchase options),
– to handle contacts with customers and other interested persons, including handling of enquiries,
– to send a newsletter,
– to implement business cooperation,
– to administer the site, run a blog,
– to conclude and perform a contract as well as make settlements in connection with the services provided, in accordance with the standards, and fulfil the obligations of a controller set out in the provisions of generally applicable law,
– to pursue claims related to the contract concluded, for the purpose of debt enforcement and complaints.
4. Depending on the case, personal data may be processed on the basis of:
– consent in relation to being contacted, being recorded in the customer database, receiving a newsletter and commercial information by e-mail and text messages (Article 6(1)(a) of the GDPR: the data subject has consented to the processing of their personal data for one or more specified purposes), which can be withdrawn at any time; however the withdrawal of consent does not affect the lawfulness of the processing of personal data during the period when the consent was valid); Biodio Sp. z o.o. Sp.k. obtains consents on the basis of the provisions of the GDPR, the Telecommunications Law and the Act on the Provision of Electronic Services;
– conclusion and implementation of a contract (Article 6(1)(b): processing is necessary for the performance of a contract which the data subject is a party to or in order to take actions at the request of the data subject prior to entering into a contract);
– legal obligation of the controller (Article 6(1)(c) of the GDPR: processing is necessary to fulfil the legal obligation of the controller);
– legitimate interest of the controller (Article 6(1)(f) of the GDPR: processing is necessary for the purposes arising from legitimate interest of the controller or a third party, except where the interest or fundamental rights and freedoms of the data subject override that interest). We invoke the legitimate interest of Biodio Sp. z o.o. Sp.k. during the analysis, development, improvement and optimization of the site, products and services (primarily to ensure the security of the site, networks and systems), as well as the enforcement of claims related to the concluded contract, in order to enforce claims or complaints.
5. Personal data collected by Biodio Sp. z o.o. Sp.k. can be accessed only by authorized employees as well as authorized persons and entities to whom the Controller entrusts the processing of personal data by means of concluded data processing agreements, under Article 28 of the GDPR (e.g. entities providing accounting services, courier services, service providers, i.a. IT system providers). Personal data may be made available i.a. to state authorities under the law or to other entities authorized under the law, in order to perform the Controller’s obligations (e.g. post office, payment operators).
6. Personal data will be stored for the period necessary to achieve the purpose for which they have been collected and are processed (e.g. for the period of storage of contractual or accounting records under the law), until the end of the statute of limitations for claims related to the concluded contract, and personal data processed on the basis of consent will be stored until it is withdrawn. The period of processing may be extended in the case where processing is necessary to establish and assert possible claims or defence against them, and thereafter only if and to the extent required by law or your consent. At the end of the processing period, the data are irreversibly deleted or anonymised.
7. You have the following rights, provided that the conditions set out in Articles 15 to 22 of the GDPR are met and are not excluded by special provisions:
– the right to be informed about the processing of personal data,
– the right to obtain a copy of the data,
– the right to rectify the data,
– the right to data erasure,
– the right to restriction of processing (except for important reasons of public interest of the Republic of Poland or the European Union),
– the right to object to processing (including profiling),
– the right to data portability,
– the right to withdraw your consent by notifying Biodio Sp. z o.o. Sp.k. by e-mail,
– and the right to lodge a complaint – in case the processing of personal data is considered to violate the provisions of the GDPR or other regulations concerning personal data protection (the data subject may lodge a complaint with the President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw, phone: 22 531 03 00).
8. The provision of personal data is voluntary, but failure to provide data will make service provision impossible.
9. Biodio Sp. z o.o. Sp.k. does not transfer personal data outside the European Economic Area.
10. With the consent of the User of the website http://hempking.eu, the Controller can perform profiling by observing and analysing the products recently browsed on the site in order to offer purchase options that are most interesting to the customer. For example, the volume and frequency of purchases and the type of products selected may be analysed to better match the messages sent or information displayed on the site to the needs of the User. Consent to profiling may be withdrawn at any time. The Users also have the right to object to that. The right to object and withdraw your consent can be exercised by sending an e-mail to: [email protected] Your data are not and will not be subject to automated decision making.
1. The owner attaches importance to respecting the privacy of users visiting the site http://hempking.eu.
2. The data concerning the Users are processed by the Owner in accordance with generally applicable laws, guidelines of the President of the Office for the Protection of Personal Data and with the use of good practices in data processing.
3. The Owner shall exercise due diligence to protect the interests of data subjects and shall ensure in particular that these data are:
– processed lawfully, reliably and in a way transparent for the Customers and other data subjects;
– collected for specific, explicit and legitimate purposes and not further processed in a way incompatible with those purposes;
– adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
– correct and, if necessary, updated;
– kept in a form which enables identification of a data subject for no longer than is necessary for the purposes for which the data are processed;
– processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
4. The Owner shall take appropriate technical and organisational measures to ensure the protection of personal data processed, appropriate to the nature, scope, context and purpose of the processing, and the risk of infringement of the rights or freedoms of individuals.
5. The Owner strives for systematic modernization of the applied IT, technical and organizational measures for personal data protection, in particular the Owner ensures updates of IT protection measures enabling protection against viruses, unauthorized access and other threats resulting from the functioning of an IT system and telecommunication networks. The Owner has implemented and systematically updates the Information Security Management System in its organization.
6. The Owner shall ensure with respect to any User who has made their data available to the Owner that the rights of data subjects are respected in accordance with the applicable law.
7. With the consent of the User of the site http://hempking.eu, the Controller can perform profiling by observing and analysing the products recently browsed on the site in order to offer purchase options that are most interesting to the customer. For example, the volume and frequency of purchases and the type of products selected may be analysed to better match the messages sent or information displayed on the website to the needs of the User. Your data are not and will not be subject to automated decision making. Consent to profiling may be withdrawn at any time. The Users also have the right to object to that. The right to object and withdraw your consent can be exercised by sending an e-mail to: [email protected] Your data are not and will not be subject to automated decision making.
8. The person having access to personal data processes it exclusively on the basis of the Owner’s authorisation or under a personal data processing agreement.
9. If the User agrees to the processing of the data for other purposes, e.g. marketing and sending commercial information – the data will be used only for sending e-mails or information text messages from the site www.hempking.eu. These data are stored in the Mailchimp system. They can be accessed by the IT system provider. The User may at any time opt out of receiving this content by sending an e-mail to [email protected]
10. If a user adds a comment on the site www.hempking.eu, the data provided will not be used for marketing purposes. These data are stored in WordPress on a server at zenbox.com, for the purpose of managing and moderating them. They can be accessed by the IT system provider.
11. Personal data provided when placing an order in the Online Store will be used exclusively for the purpose of order processing and issuing relevant sales documents, i.e. VAT invoices, as well as to assert claims. Your personal data can be accessed only by those employees of Biodio Sp. z o.o. Sp.k. who have been trained in accordance with the personal data security policy and are subject to an obligation of confidentiality and protection, as well as employees of the provider of the website – WordPress, on which the store’s operation is based.
The data provided when placing an order are processed by Biodio Sp. z o.o. Sp.k. and the following entities to the extent specified below:
– first and last name, address, telephone number, e-mail address, indicated as the delivery address are provided to shipping companies:
a. Poczta Polska
b. DPD courier service
c. InPost courier service
and to the company that handles the issuance of sales documents, i.e. VAT invoices, for products purchased at the online store:
a. Subiekt GT www.insert.pl
12. If you use an external payment system for making a payment, all data provided after you have switched to the payment operator’s website are registered only in its database and are in no way accessible or stored by HempKing.eu.
We cooperate with the following payment operators and recommend that you familiarize yourself with their rules and regulations:
a. PayU, www.payu.pl
b. BLIK, www.blikmobile.com
§ 3. Cookies
2. Cookies are used for the following purposes:
– adjusting the content of the Website to the User’s preferences;
– optimizing the use of the Website, in particular by recognizing the User’s end device;
– creating statistics;
– maintaining User’s session;
– providing the User with advertising content.
3. Cookies may be saved on the end device of the Website User.
4. The data collected are used to monitor and check how Users use the Website, in order to improve the functioning of the Website for more efficient and seamless navigation.
5. Please note that in some cases, independent of the Owner, the software installed by the User on the end device used to browse sites (e.g. web browser) introduces a default storage of Cookies on the User’s end device. Users can change their Cookies settings at any time. These settings can be changed, among other things in such a way as to block the automatic Cookies settings or to ensure you are informed each time they are saved on your end device. The details of this are available in the settings and instructions for the software (web browser).
6. The User can disable or restore the option of storing cookies at any time by changing the settings of their web browser.
7. Changing the settings constitutes an objection, which in the future may cause difficulties in using the Website. The complete disabling of the Cookies option will not mean that the User will not be able to view the content of the Website, except for the content which can be accessed only upon logging in.
8. A failure to change the settings means that the data will be saved on the User’s end device (using the Website will result in automatic saving of Cookies on the User’s end device).
9. The stored data saved on the User’s end device does not cause any configuration changes in the User’s end device or the software installed on that device.
10. The information about Cookies also applies to other similar technologies used as part of the Website.
11. Google Analytics cookies enable the functionality of that tool. That software helps to obtain and analyse information about the type of browser used, the number of visitors to the website, the effectiveness of marketing campaigns and the duration of individual visits. That information is used to improve the site www.hempking.eu.
12. Facebook cookies enable the operation of the statistics function of that website. That software helps to obtain and analyse information about the effectiveness of marketing campaigns used. That information serves to improve the site www.hempking.eu and match ads on Facebook.
13. Google AdWords cookies enable the functionality of that tool. Google AdWords uses cookie technology in order to assess the correctness and effectiveness of the advertising activity conducted with the use of the AdWords network. That information is used to improve the site www.hempking.eu.
15. These files do not store any confidential information.
16. The IT system used by Hempking.eu automatically collects data related to the device you use when connecting to Hempking.eu, in its logs. These data are collected for statistical purposes only and cover: type of device, operating system, type of web browser, screen resolution, colour depth, IP address, internet service provider or address of a site from which you went to hempking.eu, and are used only in the process of optimising hempking.eu in order to ensure the maximum possible convenience of use.
§ 4. Final provisions
1. The Policy enters into force on 01.02.2020. The Policy may be amended by the Owner and is published on the site.
2. Any exceptions to this Policy shall be made in writing in order to be valid.
3. The law applicable to the Policy is the law of the Republic of Poland.
4. Any matters not covered by this Policy shall be governed by the relevant provisions of the generally applicable law.