Privacy Policy

Information on the Processing of Personal Data

This Privacy Policy explains how Patrycja Segedyn, trading as PAT SEGE, collects, uses,stores, discloses, and protects the personal data of users (referred to as "User" or "you"). It applies to the website WWW.PAT-SEGE.COM and all products and services offered through it.

 

DATA CONTROLLER

Administratorem danych osobowych jest Patrycja Segedyn prowadzącą działalność gospodarczą pod nazwą PAT SEGE, z siedzibą przy ul. Górniczej 1a, 59-800 Lubań, NIP: 8982303969, REGON: 527752611.

The legal basis for processing your data is the agreement between you and the data controller, which is formed upon acceptance of the Terms and Conditions and is necessary for the performance of that agreement. Data may also be processed on the basis of your consent for marketing purposes, or where there is a legitimate interest pursued by the data controller or a third party.

Providing data required for the issuance of an invoice is a statutory obligation under Polish VAT law.

 

PERSONAL DATA

Personal data — meaning any information relating to an identified or identifiable individual — submitted by customers through electronic forms on the website (including name, postal address, phone number, email address, and tax ID/NIP) is collected and used by the data controller solely for the purpose of fulfilling the agreement and taking necessary steps prior to entering into it. This includes creating and managing user accounts, carrying out marketing activities, and sending personalised and automated messages based on purchase history via email, SMS, or other channels — provided the customer has given their consent to receive commercial and marketing communications.

PAT SEGE may collect and process personal data in various ways, including when users visit the website or interact with its features and services. Users may be asked to provide their email address. Visiting the website anonymously is also possible. Personal data is only collected when users voluntarily submit it. Users may choose not to provide personal data; however, doing so may prevent them from placing orders, receiving support, or using certain features of the store.

 

NON-PERSONAL INFORMATION

PAT SEGE may collect non-personal information each time a user interacts with the website. This may include the browser name, device type, operating system, internet service provider, and other technical information about how users connect to the website.

COOKIES

The website www.pat-sege.com may use cookies to improve your browsing experience. Cookies are small files stored on your device by your browser, used for session management and sometimes to track usage information. You can set your browser to refuse cookies or to alert you when cookies are being sent. Please note that disabling cookies may affect the functionality of certain parts of the website.

PURPOSES OF DATA PROCESSING

PAT SEGE may process personal data for the following purposes:

  • Fulfilling sales agreements concluded through the online store at WWW.PAT-SEGE.COM
  • Communicating with users on matters related to the store and data protection
  • Pursuing the legitimate interests of the data controller

Anonymised data collected automatically may be processed for the following purposes:

  • Website analytics and statistics
  • Remarketing
  • Newsletter communications
  • Delivering personalised advertisements
  • Pursuing the legitimate interests of the data controller

DATA PROTECTION

Voluntarily provided personal data is stored only for as long as the service is being provided.

An exception applies where further retention is necessary to protect the data controller's legitimate legal interests

— in such cases, data may be retained for up to 3 years from the date of a deletion request, where there is a suspected or confirmed breach of the store's Terms and Conditions.

Anonymised data

Anonymised data collected automatically is retained indefinitely for statistical purposes, as it does not constitute personal data.

Third-party access to personal data:

As a general rule, the only recipient of personal data is the data controller.

Data collected through the store's services is not sold or transferred to third parties. However, access to data (typically under a data processing agreement) may be granted to the following service providers who support the operation of the store:

  • Hosting providers supplying infrastructure and related services to the data controller
  • Online payment processors facilitating transactions made through the store
  • Courier and postal service providers responsible for delivering physical orders to customers

Hosting services:

Administrator, w celu prowadzenia serwisu korzysta z usług zewnętrznego dostawcy hostingu, VPS lub Serwerów Dedykowanych – Wix.com Ltd.. Wszelkie dane gromadzone i przetwarzane w serwisie są przechowywane i przetwarzane w infrastrukturze usługodawcy zlokalizowanej poza obrębem granic Unii Europejskiej. Istnieje możliwość dostępu do danych wskutek prac serwisowych realizowanych przez personel usługodawcy. Dostęp do tych danych reguluje umowa zawarta pomiędzy Administratorem a Usługodawcą.

Online payments:

When processing online payments, all payment data is submitted directly by the user to the payment processor — Stripe Inc. Selected data required to complete the transaction is then passed by Stripe to the data controller. This transfer is governed by an agreement between the data controller and Stripe Inc.

Courier services:

When an order requires physical delivery, the relevant personal data of the customer is shared with the courier or parcel service selected by the user. This transfer is governed by an agreement between the data controller and the courier service provider.

SECURITY MEASURES

The data controller has implemented appropriate technical and organisational measures toensure the effective protection of customers' personal data. Key elements of the data protection system include:

SSL certificate — all data transmitted through the website is encrypted.

Personal data is protected in accordance with applicable data protection law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR). Access to personal data is restricted to authorised personnel of the data controller, who are bound by strict confidentiality obligations.

Personal data collected through the store is not shared with third parties, except for service providers acting under separate agreements or where the user has given their explicit consent. Where required by law, data may be disclosed to public authorities.

The store's IT systems meet the highest data protection standards. All technical and organisational measures comply with applicable data protection regulations and the guidelines of the relevant supervisory authority.

Zastosowano środki techniczne i organizacyjne zapewniające ochronę przetwarzanych danych zgodne z wymaganiami określonymi w przepisach o ochronie danych osobowych oraz wytycznymi organu ds. ochrony danych osobowych.

The data controller has fulfilled all legal obligations with regard to personal data protection.

YOUR RIGHTS

1. Użytkownik, którego dane osobowe są przetwarzane ma prawo do:

  1. Access, rectification, restriction, erasure, and portability — you have the right to request access to your personal data, to have it corrected, deleted ("right to be forgotten"), or its processing restricted. You also have the right to object to processing and to request data portability. These rights are set out in detail in Articles 15–21 of the GDPR.
  2. Withdrawal of consent — where your data is processed on the basis of your consent (under Article 6(1)(a) or Article 9(2)(a) of the GDPR), you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of any processing carried out before the withdrawal.
  3. Right to lodge a complaint — you have the right to lodge a complaint with the relevant supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO), Warsaw.
  4. Right to object — you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where it is based on Article 6(1) (e) (public interest) or Article 6(1)(f) (legitimate interests) of the GDPR, including profiling based on those provisions. In such cases, the data controller may no longer process your data unless it can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or that the processing is necessary for the establishment, exercise, or defence of legal claims.
  5. Right to object to direct marketing — where personal data is processed for direct marketing purposes (based on the data controller's legitimate interests, not on your consent), you have the right to object at any time to such processing, including profiling to the extent it relates to direct marketing.

To exercise any of the above rights, please send a request to contact@pat-sege.com, including your full name.

Users are responsible for ensuring that any data they submit through the website is accurate and up to date.

CHANGES TO THIS PRIVACY POLICY

The data controller reserves the right to update this Privacy Policy at any time without prior notice to users, in relation to the use of anonymised data or cookies.

The data controller also reserves the right to update this Privacy Policy in relation to the processing of personal data. Continued use of the store's services following any such update constitutes acceptance of the revised Privacy Policy.

Any changes to this Privacy Policy will be published on this page.

Changes take effect upon publication.

WEBSITE REQUIREMENTS

Restricting or disabling cookies on your device may cause certain features of the website to function incorrectly.

The data controller accepts no liability for any features of the website that do not function correctly as a result of the user restricting or disabling cookie storage and access.

CONTACT

For any questions or requests relating to your personal data, please contact us at: