PRIVACY POLICY OF THE KOMINKOWE24H.PL ONLINE STORE
§ 1. GENERAL PROVISIONS
This Privacy Policy sets out the rules for the processing and protection of personal data provided by Users in connection with their use of the Online Store operating at www.kominkowe24h.pl (hereinafter referred to as the "Store").
The Administrator of personal data collected via the Store is:
THESEYOURWAY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office at ul. Tyniecka 39, 32-050 Skawina, Poland, entered into the Register of Entrepreneurs of the National Court Register (KRS) under number: 0001126504, NIP (Tax Identification Number): 9442290376, REGON (Statistical Number): 529620150, with a share capital of PLN 5,000.00 (hereinafter referred to as the "Administrator").
Contact details for personal data matters:
E-mail address: biuro@kominkowe24h.pl
Phone: +48 888 888 234
Postal address: THESEYOURWAY Sp. z o.o., ul. Tyniecka 39, 32-050 Skawina, Poland
Personal data are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR), as well as applicable national personal data protection regulations.
The Administrator takes special care to protect the interests of data subjects and, in particular, ensures that the data collected are:
processed lawfully, fairly, and in a transparent manner;
collected for specified, explicit, and legitimate purposes;
adequate, relevant, and limited to what is necessary for the purposes of processing;
accurate and kept up to date;
kept in a form which permits identification of data subjects for no longer than is necessary;
processed in a manner that ensures appropriate security of personal data.
This Privacy Policy sets out the rules for the processing and protection of personal data provided by Users in connection with their use of the Online Store operating at www.kominkowe24h.pl (hereinafter referred to as the "Store").
The Administrator of personal data collected via the Store is:
THESEYOURWAY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office at ul. Tyniecka 39, 32-050 Skawina, Poland, entered into the Register of Entrepreneurs of the National Court Register (KRS) under number: 0001126504, NIP (Tax Identification Number): 9442290376, REGON (Statistical Number): 529620150, with a share capital of PLN 5,000.00 (hereinafter referred to as the "Administrator").
Contact details for personal data matters:
E-mail address: biuro@kominkowe24h.pl
Phone: +48 888 888 234
Postal address: THESEYOURWAY Sp. z o.o., ul. Tyniecka 39, 32-050 Skawina, Poland
Personal data are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR), as well as applicable national personal data protection regulations.
The Administrator takes special care to protect the interests of data subjects and, in particular, ensures that the data collected are:
processed lawfully, fairly, and in a transparent manner;
collected for specified, explicit, and legitimate purposes;
adequate, relevant, and limited to what is necessary for the purposes of processing;
accurate and kept up to date;
kept in a form which permits identification of data subjects for no longer than is necessary;
processed in a manner that ensures appropriate security of personal data.
§ 2. PURPOSE, LEGAL BASIS, AND DURATION OF DATA PROCESSING
The Administrator processes Users' personal data for the following purposes, based on the specified legal grounds, and retains them for defined periods:
Performance of the Sales Contract and processing Orders:
Legal basis: Art. 6(1)(b) GDPR (necessity for the performance of a contract to which the data subject is party or in order to take steps prior to entering into a contract).
Scope of data: Name and surname, delivery address, e-mail address, phone number, tax identification number (NIP) and company name (in the case of businesses), order details.
Retention period: For the time necessary to process and fulfill the order, and thereafter until the expiry of statutory limitation periods for claims under the contract.
Compliance with accounting and legal tax obligations:
Legal basis: Art. 6(1)(c) GDPR (necessity for compliance with a legal obligation to which the Administrator is subject).
Scope of data: Name and surname/company name, address, NIP number, order history, financial transaction data.
Retention period: For the period required by law (e.g., 5 years from the end of the calendar year in which the tax obligation arose).
Handling complaints, legal claims, and returns:
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest of the Administrator – establishing, pursuing, or defending legal claims).
Scope of data: Name and surname, contact details, bank account number (for refunds), complaint/return details.
Retention period: For the period necessary to resolve the complaint/return and until the expiry of the statutory limitation period for mutual legal claims.
Electronic communication and customer inquiry handling:
Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Administrator – maintaining contact with customers and answering inquiries).
Scope of data: E-mail address, phone number, name, message content.
Retention period: For the duration of the communication necessary to answer the inquiry, and thereafter for up to 1 year for archiving purposes.
Direct marketing and Newsletter (if applicable):
Legal basis: Art. 6(1)(a) GDPR (consent of the data subject).
Scope of data: E-mail address, name.
Retention period: Until the User withdraws consent.
§ 3. CATEGORIES OF RECIPIENTS OF PERSONAL DATA
To ensure the proper functioning of the Store and fulfillment of placed Orders, the Administrator provides Users' personal data to external entities cooperating with the Administrator, strictly to the extent necessary.
Recipients of personal data may include:
Courier and transport companies: (e.g., InPost, DHL, DPD, JAS-FBG) – for the purpose of shipping and delivering orders (including pallet transport).
Payment system operators: (e.g., Stripe, PayU, Przelewy24, AutoPay, BLIK) – for processing electronic payments and card transactions.
Accounting and legal services: External accounting office and legal advisors operating on behalf of the Administrator.
IT and hosting service providers: Companies providing hosting services, database management, web software maintenance, and e-mail systems.
Authorized public authorities: Public authorities, courts, or state bodies entitled to receive data under applicable legal provisions.
All entities to which data are entrusted guarantee the application of appropriate technical and organizational measures to protect personal data in accordance with GDPR requirements.
To ensure the proper functioning of the Store and fulfillment of placed Orders, the Administrator provides Users' personal data to external entities cooperating with the Administrator, strictly to the extent necessary.
Recipients of personal data may include:
Courier and transport companies: (e.g., InPost, DHL, DPD, JAS-FBG) – for the purpose of shipping and delivering orders (including pallet transport).
Payment system operators: (e.g., Stripe, PayU, Przelewy24, AutoPay, BLIK) – for processing electronic payments and card transactions.
Accounting and legal services: External accounting office and legal advisors operating on behalf of the Administrator.
IT and hosting service providers: Companies providing hosting services, database management, web software maintenance, and e-mail systems.
Authorized public authorities: Public authorities, courts, or state bodies entitled to receive data under applicable legal provisions.
All entities to which data are entrusted guarantee the application of appropriate technical and organizational measures to protect personal data in accordance with GDPR requirements.
§ 4. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA (EEA)
Personal data are generally processed within the European Economic Area (EEA).
In connection with the use of tools and payment services provided by international vendors (e.g., Stripe Payments), personal data may be processed outside the EEA.
In such cases, any data transfer takes place in compliance with Chapter V of the GDPR, based on appropriate legal safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission or EU adequacy decisions.
Personal data are generally processed within the European Economic Area (EEA).
In connection with the use of tools and payment services provided by international vendors (e.g., Stripe Payments), personal data may be processed outside the EEA.
In such cases, any data transfer takes place in compliance with Chapter V of the GDPR, based on appropriate legal safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission or EU adequacy decisions.
§ 5. USER RIGHTS UNDER GDPR
Every User whose personal data are processed by the Administrator has the following rights:
Right of access to data: Right to obtain confirmation as to whether personal data are being processed, and to receive a copy of such data (Art. 15 GDPR).
Right to rectification: Right to request the correction or completion of inaccurate or incomplete personal data (Art. 16 GDPR).
Right to erasure ("right to be forgotten"): Right to request the deletion of personal data where legal grounds apply (Art. 17 GDPR).
Right to restriction of processing: Right to demand the restriction of data processing in cases specified in Art. 18 GDPR.
Right to data portability: Right to receive personal data in a structured, commonly used, and machine-readable format and transmit those data to another administrator (Art. 20 GDPR).
Right to object: Right to object at any time to the processing of personal data based on the legitimate interest of the Administrator (Art. 21 GDPR).
Right to withdraw consent: Where processing is based on consent, the User has the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of the rights mentioned above, the User may submit a request by e-mail to: biuro@kominkowe24h.pl or by mail to the Administrator's registered address.
Right to lodge a complaint with a supervisory authority:
If a User considers that the processing of their personal data violates the provisions of the GDPR, they have the right to lodge a complaint with the national supervisory authority:
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - PUODO), ul. Stawki 2, 00-193 Warsaw, Poland.
Every User whose personal data are processed by the Administrator has the following rights:
Right of access to data: Right to obtain confirmation as to whether personal data are being processed, and to receive a copy of such data (Art. 15 GDPR).
Right to rectification: Right to request the correction or completion of inaccurate or incomplete personal data (Art. 16 GDPR).
Right to erasure ("right to be forgotten"): Right to request the deletion of personal data where legal grounds apply (Art. 17 GDPR).
Right to restriction of processing: Right to demand the restriction of data processing in cases specified in Art. 18 GDPR.
Right to data portability: Right to receive personal data in a structured, commonly used, and machine-readable format and transmit those data to another administrator (Art. 20 GDPR).
Right to object: Right to object at any time to the processing of personal data based on the legitimate interest of the Administrator (Art. 21 GDPR).
Right to withdraw consent: Where processing is based on consent, the User has the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of the rights mentioned above, the User may submit a request by e-mail to: biuro@kominkowe24h.pl or by mail to the Administrator's registered address.
Right to lodge a complaint with a supervisory authority:
If a User considers that the processing of their personal data violates the provisions of the GDPR, they have the right to lodge a complaint with the national supervisory authority:
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - PUODO), ul. Stawki 2, 00-193 Warsaw, Poland.
§ 6. COOKIES AND PROFILING
The Store uses cookies (small text files stored on the User's terminal device) to ensure proper operation, improve usability, analyze web traffic, and implement security measures.
Types of cookies used in the Store:
Essential cookies: Necessary for the proper functioning of the Store website, maintaining sessions, cart operations, and security.
Analytical/Performance cookies: Used to collect anonymous statistics on how Users use the Store, helping to improve its structure and content.
Functional cookies: Allow the Store to remember user choices (e.g., language, currency, cart state).
Upon entering the Store website, the User is informed about the use of cookies and can manage their consent preferences via the cookie management banner.
The User may change cookie settings at any time in their web browser (e.g., block or delete cookies). Disabling essential cookies may, however, impair or prevent certain features of the Store from working properly.
Profiling: Users' personal data will not be used for automated decision-making that produces legal effects concerning the User or similarly significantly affects them (no automated profiling).
The Store uses cookies (small text files stored on the User's terminal device) to ensure proper operation, improve usability, analyze web traffic, and implement security measures.
Types of cookies used in the Store:
Essential cookies: Necessary for the proper functioning of the Store website, maintaining sessions, cart operations, and security.
Analytical/Performance cookies: Used to collect anonymous statistics on how Users use the Store, helping to improve its structure and content.
Functional cookies: Allow the Store to remember user choices (e.g., language, currency, cart state).
Upon entering the Store website, the User is informed about the use of cookies and can manage their consent preferences via the cookie management banner.
The User may change cookie settings at any time in their web browser (e.g., block or delete cookies). Disabling essential cookies may, however, impair or prevent certain features of the Store from working properly.
Profiling: Users' personal data will not be used for automated decision-making that produces legal effects concerning the User or similarly significantly affects them (no automated profiling).
§ 7. FINAL PROVISIONS
The Administrator applies appropriate technical and organizational security measures to protect personal data against unauthorized access, loss, alteration, or destruction.
The Store website may contain links to external third-party websites. The Administrator is not responsible for the privacy practices or content of those external websites. Users are encouraged to read the privacy policies of those third-party services.
The Administrator reserves the right to update or modify this Privacy Policy to reflect technical developments, changes in legal requirements, or updates in Store operations. Users will be informed of any significant changes via updates published on the Store's website.
This Privacy Policy enters into force on the day of its publication on the Store website.
The Administrator applies appropriate technical and organizational security measures to protect personal data against unauthorized access, loss, alteration, or destruction.
The Store website may contain links to external third-party websites. The Administrator is not responsible for the privacy practices or content of those external websites. Users are encouraged to read the privacy policies of those third-party services.
The Administrator reserves the right to update or modify this Privacy Policy to reflect technical developments, changes in legal requirements, or updates in Store operations. Users will be informed of any significant changes via updates published on the Store's website.
This Privacy Policy enters into force on the day of its publication on the Store website.
