1. This Privacy Policy sets out the rules for the processing of personal data obtained through the online store www.shop-mbpexpress.eu (hereinafter referred to as the "Online Store").
2. The owner of the Online Store and at the same time the data administrator is MBP Express Nowak Przemysław with its registered office in Gostyn (63-800),
Jana Pawła II 28 Street, NIP: 6961679941, REGON: 411555688, hereinafter referred to as MBP Express.
3. Personal data collected by MBP Express through the Online Store are processed in accordance with the Regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016 on the protection of natural persons in relation to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), also referred to as RODO.
4. MBP Express shall take special care to respect the privacy of Customers visiting the Online Store.
§ 1 Type of data processed, purposes and legal basis
1. MBP Express collects information concerning natural persons performing a legal action not directly related to their activity, natural persons conducting business or professional activity on their own behalf, and natural persons representing legal persons or organizational units which are not legal persons legal persons to whom the Act grants legal capacity, hereinafter collectively referred to as Clients.
2. Personal data of the Customers are collected in case of:
2.1. registration of an account in the Online Store, in order to create and manage an individual account. Legal basis: the necessity to perform the contract for the provision of the Account service (Article 6.1.b RODO);
2.2. placing an order on the Online Store, for the purpose of executing the sales contract. Legal basis: necessary to execute the sales contract (Article 6(1)(b) of the DPA);
2.3. subscribing to a newsletter (Newsletter), for the purpose of executing a contract the subject of which is a service provided electronically. Legal basis - consent of the data subject to perform the contract for the Newsletter service (Article 6(1)(a) RODO).
3. When registering an account with the Online Store, the Customer shall provide:
3.1. e-mail address;
3.2. address data:
3.3. postal code and city;
3.4. country (state);
3.5. street along with house/apartment number..
3.6. name and surname;
3.7. phone number.
4. When registering an account with the Online Store, the Customer shall independently set an individual password to access his/her account. The Customer may change the password, at a later time, according to the rules described in §6.
5. When placing an order in the Online Store, the Customer shall provide the following data:
5.1. e-mail address;
5.2. address data:
5.3. postal code and city;
5.4. country (state);
5.5. street along with house/apartment number.
5.6. name and surname;
5.7. phone number.
6. In the case of Entrepreneurs, the above scope of data shall be further expanded to include:
6.1. company name of the Entrepreneur
6.2. taxpayer identification number
7. When using the Newsletter service, the Customer shall provide only his/her e-mail address.
8. When using the Store's Website, additional information may be collected, in particular: the IP address assigned to the Customer's computer or the external IP address of the Internet provider, domain name, browser type, access time, type of operating system..
9. Navigation data may also be collected from Customers, including information about the links and references they choose to click on or other actions taken on the Online Store. Legal basis - legitimate interest (Article 6(1)(f) RODO), consisting of facilitating the use of services provided electronically and improving the functionality of these services.
10. For the purpose of establishing, investigating and enforcing claims, certain personal data provided by the Customer as part of the use of functionality on the Online Store may be processed, such as name, surname, data on the use of services, if the claims arise from the manner in which the Customer uses the services, other data necessary to prove the existence of the claim, including the extent of the damage suffered. Legal basis - legitimate interest (Article 6(1)(f) of the RODO), consisting in the establishment, investigation and enforcement of claims and defense against claims in proceedings before courts and other state authorities.
11. Submission of personal data to MBP Express is voluntary, in connection with contracts of sale or provision of services through the Store's Website, with the proviso, however, that failure to provide the data specified in the forms in the Registration process prevents the Registration and establishment of a Customer Account, and in the case of placing an order without the Registration of a Customer Account will prevent the placement and processing of the Customer's order.
§ 2 To whom is the data shared or entrusted and how long is it kept?
1. The Customer's personal data is transferred to the service providers used by MBP Express in the operation of the Online Store. The service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, are either subject to MBP Express' instructions as to the purposes and means of processing such data (processors) or determine the purposes and means of processing themselves (controllers).
1.1. Processors. MBP Express uses vendors who process personal data only at the direction of MBP Express. These include, but are not limited to, suppliers providing hosting services, suppliers of marketing systems, systems for analyzing traffic on the Online Store, systems for analyzing the effectiveness of marketing campaigns;
1.2. Administrators. MBP Express uses suppliers who do not act solely on instructions and determine themselves the purposes and uses of Customers' personal data. They provide electronic payment and banking services.
2. Location. The service providers are located in Poland and in other countries of the European Economic Area (EEA).
3. Personal data of Customers shall be stored:
3.1. If the basis for the processing of personal data is consent, then the Customer's personal data is processed by MBP Express as long as the consent is not revoked, and after revoking the consent for a period of time corresponding to the period of limitation of claims that MBP Express may raise. and which may be raised against it. Unless a special provision provides otherwise, the statute of limitations is six years, and for claims for periodic benefits and claims related to the conduct of business - three years.
3.2. If the basis for data processing is the performance of a contract, then the Customer's personal data shall be processed by MBP Express as long as it is necessary for the performance of the contract, and thereafter for a period corresponding to the period of limitation of claims. Unless a special provision provides otherwise, the statute of limitations is six years, and for claims for periodic benefits and claims related to the conduct of business - three years.
4. If a purchase is made in the Online Store, personal data may be transferred, depending on the choice of the Customer, to the following entities for the purpose of delivering the ordered goods:
4.1. courier company;
4.2. the company InPost Paczkomaty Sp. z o.o. with its registered office in Cracow, providing delivery services and operating a system of post office boxes (Paczkomaty);
5. If the Customer chooses to pay via the przelewy24.pl system, his/her personal data are transferred to the extent necessary for the execution of the payment to PayPro S.A. with its registered seat in Poznan (60-327 Poznan, ul. Kanclerska 15), entered in the register of entrepreneurs kept by the District Court Poznan - Nowe Miasto and Wilda in Poznan, VIII Economic Department of the National Court Register under KRS number 0000347935, NIP 7792369887, Regon 301345068.
6. Navigational data may be used to provide better service to Customers, analyze statistical data and adapt the Online Store to Customers' preferences, as well as to administer the Online Store.
7. If a Customer subscribes to a newsletter (Newsletter), MBP Express will send electronic messages containing commercial information about promotions and new products available in the Online Store to his/her e-mail address.
8. If a request is made, MBP Express shall make personal data available to authorized state authorities, in particular organizational units of the Prosecutor's Office, the Police, the President of the Office of Personal Data Protection, the President of the Office of Competition and Consumer Protection or the President of the Office of Electronic Communications.
§ 3 Cookie mechanism
1. The Online Store uses small files, called cookies. These are stored by MBP Express on the end device of a visitor to the Online Store, if the web browser allows it. A cookie usually contains the name of the domain from which it originated, its "expiration time" and an individual, random number that identifies the cookie. The information collected through cookies of this type helps tailor the products offered by MBP Express to the individual preferences and actual needs of visitors to the Online Store. They also give the possibility to develop general statistics of visits to the presented products in the Online Store.
2. MBP Express uses two types of cookies:
2.1. Session cookies: when the session of a given browser ends or the computer is turned off, the stored information is deleted from the device's memory. The mechanism of session cookies does not allow any personal data or any confidential information to be collected from Customers' computers.
2.2. Persistent cookies: they are stored in the memory of the Customer's terminal device and remain there until they are deleted or expire. The mechanism of permanent cookies does not allow any personal data or any confidential information to be collected from the Clients' computer.
3. MBP Express uses proprietary cookies for:
3.1. authenticating the Customer in the Internet Shop and providing the Customer's session in the Internet Shop (after logging in), thanks to which the Customer does not have to re-enter his/her login and password on each sub-page of the Internet Shop;
3.2. analysis and research, as well as audience audit, and in particular to create anonymous statistics that help to understand how the Customers use the Internet Shop's Website, which allows to improve its structure and content.
4. MBP Express uses external cookies for:
4.1. collect general and anonymous statistical data via Google Analytics analytical tools (administrator of external cookies: Google Inc. based in the USA);
4.2. presentation of the Certificate of Reliable Regulations through the website rzetelnyregulamin.pl (administrator of external cookies:Rzetelna Grupa sp. z o.o. based in Warsaw).
5. The mechanism of cookies is safe for the computers of the Customers of the Internet Shop. In particular, it is not possible to get viruses or other unwanted software or malware into the Customers' computers via this route. However, in their browsers, Customers have the option to limit or disable the access of cookies to their computers. If this option is used, the use of the Online Store will be possible, except for functions that by their nature require cookies.
§ 4 Rights of data subjects
1. Right to revoke consent - legal basis: article 7(3) RODO.
1.1. The customer has the right to withdraw any consent that he/she has given to MBP Express
1.2. Withdrawal of consent shall have effect from the moment of withdrawal of consent.
1.3. Withdrawal of consent shall not affect the processing performed by MBP Express lawfully before its withdrawal.
1.4. Withdrawal of consent shall not entail any negative consequences for the Customer, but may prevent further use of services or functionalities that MBP Express may lawfully provide only with consent.
2. The right to object to the processing of data - legal basis: Article 21 RODO.
2.1. The Customer has the right at any time to object - for reasons related to his/her particular situation - to the processing of his/her personal data, including profiling, if MBP Express processes his/her data based on a legitimate interest, such as marketing MBP Express products and services conducting statistics on the use of particular functionalities of the Online Store and facilitating the use of the Online Store, as well as satisfaction surveys.
2.2. Resignation in the form of an e-mail from receiving marketing communications regarding products or services shall imply the Customer's objection to the processing of his/her personal data, including profiling for these purposes.
2.3. If the Customer's objection proves to be valid and MBP Express has no other legal basis for processing personal data, the Customer's personal data will be deleted, against the processing of which, the Customer has objected.
3. Right to erasure of data ("right to be forgotten") - legal basis: article 17 of the RODO.
3.1. The Customer has the right to request deletion of all or some of his/her personal data.
3.2. The Customer has the right to request deletion of personal data if:
3.2.1. the personal data are no longer necessary for the purposes for which they were collected or for which they were processed;
3.2.2. he/she has withdrawn a specific consent, to the extent that the personal data was processed based on his/her consent;
3.2.3. objected to the use of his/her data for marketing purposes;
3.2.4. personal data is processed illegally;
3.2.5. the personal data must be erased in order to comply with a legal obligation under Union law or the law of a Member State to which MBP Express is subject;
3.2.6. the personal data was collected in connection with the offering of information society services.
3.3. Despite a request for deletion of personal data, due to the filing of an objection or withdrawal of consent, MBP Express may retain certain personal data to the extent that the processing is necessary to establish, assert or defend claims, as well as to comply with a legal obligation requiring processing under Union law or the law of a Member State to which MBP Express is subject. This applies in particular to personal data including: first name, last name, e-mail address, which data are retained for the purpose of processing complaints and claims related to the use of MBP Express services or, in addition, home address / mailing address, order number, which data are retained for the purpose of processing complaints and claims related to the concluded sales contracts or provision of services.
4. The right to restrict data processing - legal basis: article 18 of RODO.
4.1. The customer has the right to request restriction of processing of his personal data. Submitting a request, until it is considered, prevents the use of certain functionalities or services, the use of which will involve the processing of data covered by the request. MBP Express will also not send any communications, including marketing.
4.2. The customer has the right to request restriction of the use of personal data in the following cases:
4.2.1. when he or she questions the correctness of his or her personal data, in which case MBP Express shall limit the use of the data for the time needed to verify the correctness of the data, but no longer than for 7 days;
4.2.2. when the processing of the data is unlawful, and instead of deleting the data, the Customer requests the restriction of its use;
4.2.3. when the personal data are no longer necessary for the purposes for which they were collected or used but are needed by the Customer to establish, assert or defend claims;
4.2.4. when he or she has objected to the use of his or her data, in which case the restriction shall be for the time necessary to consider whether, due to the particular situation, the protection of the Client's interests, rights and freedoms outweighs the interests pursued by the Administrator in processing the Client's personal data.
5. Right of access to data - legal basis: article 15 RODO.
5.1. The Customer has the right to obtain confirmation from the Administrator as to whether it is processing personal data, and if so, the Customer has the right to:
5.1.1. gain access to his/her personal data;
5.1.2. obtain information about the purposes of processing, the categories of personal data processed, the recipients or categories of recipients of such data, the planned period of storage of the Customer's data or the criteria for determining this period (when it is not possible to determine the planned period of data processing), the Customer's rights under the RODO and the right to lodge a complaint with a supervisory authority, the source of such data, automated decision-making, including profiling, and the safeguards applied in connection with the transfer of such data outside the European Union;
5.1.3. obtain a copy of your personal data.
6. Right to rectification of data - legal basis: article 16 of the RODO.
6.1. The Customer shall have the right to request from the Administrator the immediate rectification of personal data pertaining to him/her that is inaccurate. Taking into account the purposes of the processing, the Customer to whom the data pertains has the right to request the completion of incomplete personal data, including by providing an additional statement, by addressing the request to the e-mail address in accordance with §7 of the Privacy Policy.
7. Right to data portability - legal basis: article 20 of the RODO.
7.1. The Customer has the right to receive his/her personal data, which he/she has provided to the Administrator, and then send it to another personal data controller of his/her choice. The Customer also has the right to request that the personal data be sent by the Administrator directly to such administrator, if technically possible. In such a case, the Administrator will send the Customer's personal data in the form of a file in csv format, which is a commonly used, machine-readable format that allows sending the received data to another personal data controller.
8. In a situation where the Customer claims an entitlement under the above rights, MBP Express shall either comply with the request or refuse to comply with it immediately, but no later than within one month after receiving it. However, if - due to the complex nature of the request or the number of requests - MBP Express will not be able to fulfill the request within one month, it will fulfill it within another two months informing the Customer in advance - within one month of receiving the request - of the intended extension of the deadline and the reasons for it.
9. The Customer may submit complaints, inquiries and requests to the Administrator regarding the processing of his personal data and the exercise of his rights.
10. The Customer shall have the right to request MBP Express to provide a copy of the standard contractual clauses by directing the request in the manner indicated in §7 of the Privacy Policy.
11. The Customer shall have the right to lodge a complaint with the President of the Office for Personal Data Protection regarding violation of his/her rights to personal data protection or other rights granted under the RODO.
§ 5 Services tailored to preferences and interests (profiling)
1. Profiling means any form of automated Processing of Personal Data, which involves the use of Personal Data to evaluate certain personal factors of an Individual, in particular to analyze or forecast aspects of that Individual's performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movement.
2. Personal data of Customers may be processed in an automated manner (profiling), however, this will not have any legal effect on them or similarly significantly affect the situation of Customers.
3. Profiling of personal data by MBP Express consists in the processing of Customers' data in an automated and manual manner, by using them to evaluate certain information about the Customer, in particular to analyze or forecast his personal preferences and interests.
4. In order to reach the Customer with marketing messages via the Online Store Site, MBP Express uses its own cookie mechanisms to retrieve information about the Customer's activity on the Online Store Site. For details on the cookies used, please refer to §3. Legal basis - legitimate interest (Article 6(1)(f) of the RODO), consisting of matching marketing messages to preferences and interests.