Privacy Policy (GDPR)
This Privacy Policy sets out the rules for processing and protecting the personal data of Customers and Users of the online store operating at bromantan.pl (hereinafter: the "Store"). This document has been prepared on the basis of applicable law, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the "GDPR"). We care about the privacy of our Customers and the discretion of the orders we fulfil, which is why we attach particular importance to the security of the data entrusted to us.
1. Data Controller
The controller of personal data collected through the Store is the owner and operator of the bromantan.pl online store (hereinafter: the "Controller"). The Controller is a Polish chemical laboratory engaged in the sale of chemical reagents. The Controller independently determines the purposes and means of processing personal data and is responsible for its lawful processing.
In all matters relating to the protection of personal data, including the exercise of your rights, you may contact the Controller electronically at: sklep@bromantan.pl. Personal data is processed in accordance with the GDPR, the Polish Act of 10 May 2018 on the Protection of Personal Data, the Act of 18 July 2002 on the Provision of Services by Electronic Means, and the Act of 16 July 2004 – Telecommunications Law.
2. Legal Basis for Processing
Your personal data is processed only where there is a valid legal basis for doing so. In accordance with Article 6 of the GDPR, the Controller processes data on the following grounds:
- Article 6(1)(b) GDPR — processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract (fulfilment and handling of a placed order, including shipment of goods);
- Article 6(1)(c) GDPR — processing is necessary for compliance with a legal obligation to which the Controller is subject (tax, accounting and other statutory obligations, including those relating to the trade in chemical reagents);
- Article 6(1)(a) GDPR — processing is based on freely given consent, to the extent and for the purposes specified therein (e.g. marketing activities, newsletter);
- Article 6(1)(f) GDPR — processing is necessary for the purposes of the legitimate interests pursued by the Controller (handling enquiries, establishing or defending against claims, ensuring the security of the Store and preventing abuse).
3. What Data We Collect
The scope of data collected is limited to the minimum necessary for the proper fulfilment of an order and the provision of electronic services. The Controller collects the following categories of data:
- Order and contact data: first name and surname, delivery and correspondence address, telephone number, email address, and — in the case of businesses — the company name and tax identification number (NIP);
- Payment data: information required to settle a transaction made by bank transfer (account details, transfer title) or — for larger orders — data required to settle a payment in cryptocurrency (wallet address, transaction identifier). The Controller does not store full payment card details;
- Technical data and cookie data: IP address, information about the browser and device, date and time of the visit, information about activity within the Store, and identifiers stored in cookies and similar technologies.
Providing personal data is voluntary; however, failure to provide the data necessary to fulfil an order makes it impossible to accept and complete that order. Providing data required by law (e.g. data for an accounting document) is mandatory to the extent specified in those provisions.
4. Purposes of Processing
We process personal data only for specific, explicit and legitimate purposes, which are:
- accepting, fulfilling and handling an order, including preparing the parcel and shipping it to the Customer;
- contacting the Customer on matters related to the order, responding to enquiries, and handling complaints and returns;
- fulfilling the accounting, tax and reporting obligations incumbent on the Controller under applicable law;
- carrying out marketing activities, including sending a newsletter and commercial information — solely on the basis of prior, freely given consent;
- ensuring the security of the Store, preventing fraud, and establishing, pursuing or defending against potential claims.
5. Data Retention Period
Personal data is retained for the period necessary to achieve the purposes for which it was collected, and thereafter for the period required by law or for the limitation period of any potential claims:
- data related to the performance of a contract (order) — for the duration of the contract and until the limitation period for claims arising from it has expired;
- data contained in accounting and tax documents — for the period required by law, as a rule for 5 years counting from the end of the calendar year in which the tax obligation arose;
- data processed on the basis of consent (e.g. marketing) — until such consent is withdrawn;
- data processed on the basis of a legitimate interest — until an effective objection is raised or that interest ceases to exist.
6. Data Recipients
The Controller may share your personal data only with entities whose involvement is necessary for the proper fulfilment of an order and for compliance with legal obligations. The categories of data recipients include:
- postal operators and courier companies handling delivery (including Poczta Polska, the parcel locker operator, and entities handling international shipments) — to the extent necessary to deliver the parcel;
- entities handling payments — the bank maintaining the Controller's account and, in the case of cryptocurrency payments, the blockchain infrastructure necessary to settle the transaction;
- the hosting service provider and entities providing technical and IT support for the Store;
- the accounting office and legal and tax advisors — to the extent necessary to fulfil accounting and legal obligations;
- authorised state authorities — only where the obligation to disclose data arises from generally applicable law.
We do not sell or trade your data. The Controller never shares Customers' personal data with third parties for commercial or advertising purposes. Data is transferred solely to the extent and for the purpose described above, and each recipient is obliged to maintain confidentiality and to process the data in accordance with the GDPR.
7. Rights of the Data Subject
In connection with the processing of personal data, you have the following rights under the GDPR:
- the right of access to your data and to obtain a copy of it (Article 15 GDPR);
- the right to rectification of inaccurate data and completion of incomplete data (Article 16 GDPR);
- the right to erasure, the so-called "right to be forgotten" (Article 17 GDPR), subject to data whose retention arises from a legal obligation;
- the right to restrict processing of data (Article 18 GDPR);
- the right to data portability to another controller (Article 20 GDPR);
- the right to object to processing based on a legitimate interest (Article 21 GDPR);
- the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise your rights, simply send the relevant request to sklep@bromantan.pl. We will respond to your request without undue delay, no later than within one month of its receipt. Exercising these rights is free of charge, and the Controller makes every effort to ensure that the process is discreet and secure.
8. Right to Lodge a Complaint
If you consider that the processing of personal data infringes the provisions of the GDPR, you have the right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw. Exercising the right to lodge a complaint does not preclude the pursuit of claims before the courts or other remedies provided for by law.
9. Cookies
The Store uses cookies, i.e. small text files stored on the User's device. The use of cookies is carried out in accordance with the Act of 16 July 2004 – Telecommunications Law. We use the following types of cookies:
- strictly necessary — required for the proper operation of the Store, the handling of the shopping cart and the ordering process; disabling them makes it impossible to use the core functions;
- functional — allowing the User's chosen settings and preferences, such as language or cart contents, to be remembered;
- analytical — used to collect anonymous statistics on how the Store is used, enabling us to improve its operation.
The User may manage cookies at any time using their web browser settings, including completely blocking their storage or deleting files already stored. Restricting the use of cookies may affect some of the functionalities available in the Store.
10. Data Security
The Controller applies appropriate technical and organisational measures to protect the personal data processed, adapted to the risks involved and to the categories of data protected. Data transmitted within the Store is encrypted using the SSL/TLS protocol, and the server on which the Store operates is located within the territory of Poland. Access to personal data is granted only to authorised persons bound by an obligation of confidentiality.
In the interest of honesty towards our Customers, we inform you that, despite the use of advanced safeguards, no IT system can provide a one hundred per cent guarantee of the security of transmitted data. The Controller nevertheless makes every effort to reduce the risk of a data security breach to a minimum and continuously monitors and updates the safeguards in place.
11. Changes to the Privacy Policy
The Controller reserves the right to make changes to this Privacy Policy, in particular in connection with changes in the law, technological developments or changes in the way the Store operates. The current version of the Privacy Policy is published on the Store's website each time and applies from the moment of its publication. We encourage you to review the content of this document regularly.
12. Contact Regarding Personal Data
For all matters concerning the processing of personal data and the exercise of your rights, please contact the Controller by email at: sklep@bromantan.pl. We respond to all enquiries with due diligence and with respect for the privacy and discretion of our Customers.