GDPR Disclosure Obligation
The information below provides a concise, understandable, and transparent summary of the information contained in the Privacy Policy regarding the Data Controller, the purpose and manner of processing personal data, and your rights in connection with such processing, in the form required to fulfill the GDPR’s information obligation. Details regarding the manner of processing and the entities involved in this process are available in the aforementioned policy.
Who is the data controller?
The Personal Data Controller (hereinafter referred to as the “Controller”) is the company “U BORÓWEK,” operating at the following address: 63-830 Pępowo, ul. Szkolna 26, with the following tax identification number (NIP): 618 138 79 38, which provides services electronically via the Website
How can I contact the data controller?
You can contact the data controller using one of the following methods
Mailing address – “U BORÓWEK”, 63-830 Pępowo, 26
Szkolna St. Email address – info@mushroomsborowczyk.com
Phone number – 605 247 315
Contact form – available in the CONTACT tab
Has the Controller appointed a Data Protection Officer?
Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
For matters related to data processing, including the processing of personal data, please contact the Data Controller directly.
What is the scope of the personal data we process?
The website processes basic personal data provided voluntarily by the individuals to whom it relates (e.g., first and last name, username, email address, phone number, IP address, etc.).
A detailed description of the data we process is available in our Privacy Policy.
What are the purposes of our data processing?
Personal data voluntarily provided by Users is processed for one of the following purposes:
Provision of electronic services:
Communication between the Administrator and Users regarding matters related to the Website and data protection.
The Website collects and processes Users’ data pursuant to:
Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
, Article 6(1)(a) – the data subject has given consent to the processing of his or her personal data for one or more specific purposes
; Article 6(1)(b) – processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract
, Article 6(1)(f) – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third
party; Act of May 10, 2018, on the Protection of Personal Data (Journal of Laws 2018, item 1000)
Act of July 16, 2004, Telecommunications Law (Journal of Laws 2004, No. 171, item 1800)
Act of February 4, 1994, on Copyright and Related Rights (Journal of Laws 1994, No. 24, item 83)
What is the legitimate interest pursued by the Controller?
For the purpose of potentially establishing, pursuing, or defending against claims—the legal basis for processing is our legitimate interest (Article 6(1)(f) of the GDPR), which consists of protecting our rights, including, among other things:
To assess the risk posed by potential customers
To evaluate planned marketing
campaigns To conduct direct marketing
How long do we process personal data?
As a general rule, the personal data in question is stored only for the duration of the service provided through the website operated by the Controller. It is deleted or anonymized within 30 days of the termination of service provision (e.g., deletion of a registered user account, unsubscribing from the newsletter, etc.).
In exceptional circumstances, in order to protect the Controller’s legitimate interests, this period may be extended. In such a case, the Administrator will retain the specified data, from the time the User requests its deletion, for no longer than 3 years in the event of a violation or suspected violation of the website’s terms of service by the data subject.
Who is the recipient of the data, including personal data?
As a general rule, the only recipient of the data is the Controller.
However, data processing may be entrusted to other entities that provide services to the Controller for the purpose of maintaining the Website’s operations.
Such entities include, among others:
1. Hosting companies that provide hosting or related services to the Administrator.
2. IT service and support companies that perform maintenance or are responsible for maintaining the IT infrastructure.
3. Companies acting as intermediaries in online payments for goods or services offered through the Website (when making a purchase on the Website).
4. Companies responsible for the Administrator’s accounting (in the event of a purchase transaction on the Website).
5. Companies responsible for delivering physical products to the User (postal/courier services in the event of a purchase transaction on the Website).
Will personal data be used for automated decision-making?
Personal data will not be used for automated decision-making (profiling).
What are your rights regarding the processing of personal data?
1. Users have the right to access their personal data, which is granted upon request submitted to the Controller
. 2. Users have the right to request that the Controller immediately correct any personal data that is inaccurate and/or complete any personal data that is incomplete, which is exercised by submitting a request to the Controller
. 3. Users have the right to request that the Controller promptly erase their personal data, which is exercised by submitting a request to the Controller.
For user accounts, data deletion involves anonymizing data that could identify the user.
Right to Restrict the Processing of Personal
Data 1. Users have the right to restrict the processing of personal data in the cases specified in Article 18 of the GDPR, including when disputing the accuracy of personal data, upon request submitted to the Controller
. 2. Users have the right to receive from the Controller their personal data in a structured, commonly used, machine-readable format, upon request submitted to the Controller
. 3. Users have the right to object to the processing of their personal data in the cases specified in Article 21 of the GDPR, exercisable upon request submitted to the Controller
4. Users have the right to lodge a complaint with a supervisory authority responsible for the protection of personal data.
o firmie | grzyby uprawne | grzyby leśne | owoce | warzywa | certyfikaty | kontakt
Zaufaj naszemu doświadczeniu i ciesz się najwyższej jakości produktami.