PRIVACY POLICY OF THE ONLINE STORE
1 GENERAL PROVISIONS
- The administrator of personal data collected through the online store star-net.pl is Jacek Janusz Starzycki conducting business under the name Star-Net Jacek Starzycki registered in the Central Register and Information on Economic Activity of the Republic of Poland conducted by the minister competent for economy, place of business and address for correspondence: ul. Łukowska 46/61, 04-133 Warsaw, NIP: 6791282830, REGON: 141968413, email address:
This email address is being protected from spambots. You need JavaScript enabled to view it. , phone number: +48 533 711 411, hereinafter referred to as the "Administrator" and also the "Service Provider". - Personal data collected by the Administrator through the website are processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR.
- All words or expressions written in capital letters in the content of this Privacy Policy shall be understood in accordance with their definition contained in the Regulations of the online store www.star-net.pl.
2 TYPE OF PROCESSED PERSONAL DATA, PURPOSE AND SCOPE OF DATA COLLECTION
PROCESSING PURPOSE AND LEGAL BASIS. The Administrator processes the personal data of Service Recipients of the www.star-net.pl Store in the case of:
- registering an Account in the Store to create an individual account and manage this Account based on Article 6(1)(b) of the GDPR (performance of a contract for the provision of electronic services in accordance with the Store's Regulations),
- placing an Order in the Store to fulfill a Sales Agreement based on Article 6(1)(b) of the GDPR (performance of a sales contract).
- TYPE OF PROCESSED PERSONAL DATA. The Service Recipient provides, in the case of:
- 1. Account: first and last name, address, tax identification number (NIP), email address, phone number,
- Orders: first and last name, address, tax identification number (NIP), email address, phone number.
- DATA ARCHIVING PERIOD. The personal data of Service Recipients are stored by the Administrator:
3.1 in the case where the basis for data processing is the performance of a contract, for as long as necessary to perform the contract, and thereafter for a period corresponding to the limitation period for claims. If a specific provision does not provide otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activity - three years,
- in the case where the basis for data processing is consent, until the consent is revoked, and after revocation of consent for a period corresponding to the limitation period for claims that the Administrator may raise or may be raised against the Administrator. If a specific provision does not provide otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activity - three years.
- ADDITIONAL INFORMATION COLLECTION DURING STORE USE. Additional information may be collected during Store use, in particular: IP address assigned to the Service Recipient's computer or the external IP address of the Internet provider, domain name, browser type, access time, operating system type.
- After separate consent is given based on Article 6(1)(a) of the GDPR, data may also be processed for the purpose of sending commercial information electronically or making telephone calls for direct marketing purposes – respectively in connection with Article 10(2) of the Act of 18 July 2002 on the provision of electronic services or Article 172(1) of the Act of 16 July 2004 – Telecommunications Law, including those sent as a result of profiling, if the Service Recipient has given appropriate consent.
- Navigation data, including information about the links and references that they decide to click on or other actions taken in the Store, may also be collected from Service Recipients. The legal basis for such activities is the legitimate interest of the Administrator (Article 6(1)(f) of the GDPR) consisting of facilitating the use of services provided electronically and improving the functionality of these services.
- Providing personal data by the Service Recipient is voluntary.
- The Administrator takes special care to protect the interests of the data subjects and in particular ensures that the data collected by it are:
8.1. processed lawfully,
8.2. collected for specified, legitimate purposes and not further processed in a manner incompatible with those purposes,
8.3. factually correct and adequate in relation to the purposes for which they are processed and stored in a form that allows identification of the persons to whom they relate for no longer than is necessary for the purposes of processing.
3 DISCLOSURE OF PERSONAL DATA
- Personal data of Service Recipients are transferred to service providers used by the Administrator in running the Store, in particular to:
- entities carrying out the delivery of Products,
- payment system providers,
- accounting office,
- hosting provider,
- software providers enabling business operations,
- entities providing mailing systems,
- software providers necessary for running the online store.
- Service providers (referred to in point 1 of this paragraph) to whom personal data are transferred - depending on contractual arrangements and circumstances - either follow the instructions of the Administrator regarding the purposes and methods of processing such data (processors) or independently determine the purposes and methods of their processing (controllers).
- Personal data of Service Recipients are stored exclusively within the European Economic Area (EEA), with the exception of § 5 point 5 and § 6 of the Privacy Policy.
4 RIGHT TO CONTROL, ACCESS TO OWN DATA, AND THEIR CORRECTION
- The person whose data is concerned has the right to access their personal data and the right to rectify, erase, restrict processing, the right to data portability, the right to object, the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Legal bases for the Service Recipient's requests:
- Access to data – Article 15 of the GDPR,
- Rectification of data – Article 16 of the GDPR,
- Erasure of data (the right to be forgotten) – Article 17 of the GDPR,
- Restriction of processing – Article 18 of the GDPR,
- Data portability – Article 20 of the GDPR,
- Objection – Article 21 of the GDPR,
- Withdrawal of consent – Article 7(3) of the GDPR.
- To exercise the rights mentioned in point 2, a relevant email message can be sent to the address:
This email address is being protected from spambots. You need JavaScript enabled to view it. . - In the event of the Service Recipient exercising a right arising from the above rights, the Administrator shall comply with the request or refuse to comply with it immediately, but no later than one month after receiving it. However, if, due to the complexity of the request or the number of requests, the Administrator is unable to fulfill the request within one month, they shall do so within the next two months, informing the Service Recipient in advance within one month of receiving the request - about the intended extension of the deadline and its reasons.
- If it is found that the processing of personal data violates the provisions of the GDPR, the person whose data is concerned has the right to lodge a complaint with the President of the Personal Data Protection Office.
5 COOKIES
- The Administrator's website uses "cookies" files.
- The installation of "cookies" files is necessary for the proper provision of services on the Store's website. "Cookies" files contain information necessary for the proper functioning of the website and also allow for the development of general visit statistics to the website.
- Two types of "cookies" files are used on the website: "session" and "persistent."
- "Session" cookies are temporary files that are stored on the Service Recipient's end device until logging out (leaving the website).
- "Persistent" cookies files are stored on the Service Recipient's end device for the time specified in the parameters of the "cookies" files or until they are deleted by the Service Recipient.
- The Administrator uses their own cookies files to better understand the interaction of Service Recipients with the content of the website. The files collect information about the way the Service Recipient uses the website, the type of website from which the Service Recipient was redirected, and the number of visits and the time of the Service Recipient's visit to the website. This information does not record specific personal data of the Service Recipient but is used to compile statistics on the use of the website.
- The Administrator also uses external cookies files to collect general and anonymous statistical data through Google Analytics analytical tools (external cookies administrator: Google LLC. based in the USA).
- Cookies files may also be used by advertising networks (especially the Google network) to display advertisements tailored to the way the Service Recipient uses the Store. For this purpose, they may retain information about the Service Recipient's navigation path or the time spent on a particular page.
- The Service Recipient has the right to decide on the scope of access to "cookies" files on their computer by:
- Choosing the types of cookies files they consent to collect immediately after entering the Store's website and after the appearance of the cookies-related message,
- Changing settings in their browser window. Detailed information on the possibilities and methods of handling "cookies" files is also available in the software settings (internet browser).
6 ADDITIONAL SERVICES RELATED TO USER ACTIVITY IN THE STORE
- The Store uses so-called social plugins ("plugins") of social media services. By displaying the website www.star-net.pl containing such a plugin, the Service Recipient's browser establishes a direct connection to the servers of Facebook, Google, and LinkedIn.
- The content of the plugin is transmitted directly to the Service Recipient's browser by the respective service provider and integrated into the website. Thanks to this integration, service providers receive information that the Service Recipient's browser has displayed the www.star-net.pl website, even if the Service Recipient does not have a profile with the respective service provider or is not currently logged in. This information (along with the Service Recipient's IP address) is transmitted directly to the server of the respective service provider (some servers are located in the USA) and stored there.
- If the Service Recipient logs into one of the above-mentioned social media services, this service provider will be able to directly associate the visit to the www.star-net.pl website with the Service Recipient's profile on that social media platform.
- If the Service Recipient uses a particular plugin, e.g., by clicking the "Like" button or the "Share" button, the relevant information will also be transmitted directly to the server of the respective service provider and stored there.
- The purpose and scope of data collection and their further processing and use by service providers, as well as the possibility of contact and the rights of the Service Recipient in this regard, and the possibility of making settings to ensure the privacy protection of the Service Recipient, have been described in the privacy policies of the service providers:
- If the Service Recipient does not want social media services to directly associate data collected during visits to the www.star-net.pl website with their profile on that service, they must log out of that service before visiting the www.star-net.pl website. The Service Recipient can also completely prevent the loading of plugins on the website by using appropriate browser extensions, e.g., blocking scripts using "NoScript."
- The Administrator uses remarketing tools on their website, such as Google Ads. Their use involves the use of cookies from Google LLC. related to the Google Ads service. As part of the cookie settings management mechanism, the Service Recipient has the option to decide whether the Administrator will be able to use Google Ads (external cookies administrator: Google LLC. based in the USA) in relation to them.
7 FINAL PROVISIONS
- The Administrator implements technical and organizational measures to ensure the protection of processed personal data appropriate to the threats and categories of data covered by protection, in particular, securing data against unauthorized access, taking by an unauthorized person, processing in violation of applicable laws, as well as alteration, loss, damage, or destruction.
- The Administrator provides appropriate technical measures to prevent unauthorized acquisition and modification of personal data transmitted electronically.
- Matters not regulated by this Privacy Policy shall be governed by the provisions of the GDPR and other relevant Polish laws accordingly.