- The owner of the Store and at the same time the Administrator of Personal Data is Cosmo Group Sp. z o.o. Sp. K. with its registered office in Poznań (60-476), ul. Jasielska 10 A, entered into the Register of Entrepreneurs of the National Court Register kept by the District Court Poznań - Nowe Miasto and Wilda in Poznań, VIII Commercial Department of the National Court Register under the number KRS 0000437232, NIP: 9721241158, Regon: 302250849, hereinafter referred to as NEONAIL.pl, represented by the general partner: COSMO GROUP Sp. z o.o. with its registered office in Poznań (60-476), ul. Jasielska 10A, entered into the Register of Entrepreneurs kept by the District Court Poznań - Nowe Miasto and Wilda in Poznań, VIII Commercial Department of the National Court Register under the number KRS 0000436535 with share capital in the amount of PLN 5,000, having the Tax Identification Number: 9721241141, Regon number: 302249059.
- Personal data collected by NEONAIL.pl via the Online Store are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on free movement such data and repealing Directive 95/46 / EC (General Data Protection Regulation), also called the GDPR.
4. NEONAIL.pl makes particular diligence to respect the privacy of customers visiting the online store.
§ 1 The type of data processed, purposes and legal basis
1. NEONAIL.pl collects information about natural persons carrying out legal actions not directly related to their activities, natural persons conducting business or professional activities on their own behalf, and natural persons representing legal persons or organizational units which are not legal persons, to whom the law confers legal capacity, hereinafter referred to as including customers.
2. Customers' personal data is collected in the case of:
a) registering an account in the Online Store in order to create an individual account and manage this account. Legal basis: necessity to perform the contract for the provision of the Account service (Article 6 paragraph 1 point b of the GDPR);
b) placing an order in the Online Store in order to perform a sales contract. Legal basis: necessity to perform the sales contract (art.6 par.1 lit.b RODO);
c) subscription to the newsletter (Newsletter), in order to perform a contract the subject of which is an electronic service. Legal basis - consent of the data subject to perform the contract for the provision of the Newsletter service (Article 6 (1) (a) of the GDPR);
d) use the contact form service in the Online Store to perform the contract provided by electronic means. Legal basis: the necessity to perform the contract for the provision of the contact form service (Article 6 paragraph 1 point b of the GDPR);
e) use the service of notification of the availability of the Goods to perform the contract provided by electronic means. Legal basis - the necessity to perform the contract for the provision of a service notification of the availability of the Good (art.6 par.1 lit.b RODO).
f) use the service, provide an opinion in order to perform the contract, the subject of which is the service provided electronically. Legal basis - necessity to perform the contract for the provision of services, post an opinion (art.6 par.1 lit.b RODO).
3. When registering an account in the Online Store, the Customer provides:
a) email address.
4. When registering an account in the Online Store, the Customer sets an individual password to access his account. The customer may change the password at a later time, on the terms described in §6.
5. When placing an order in the Online Store, the Customer provides the following data:
a) email address;
b) address details:
a. zip code and city;
b. country (state);
c. street with house / flat number.
c) name and surname;
d) telephone number.
6. In the case of Entrepreneurs, the above range of data is further extended by:
a) the Entrepreneur's company;
b) tax identification number.
7. When using the Newsletter service, the Customer shall only provide his email address.
8. In the event of using the contact form service, the Customer shall provide the following data:
a) email address;
b) telephone number.
9. If you use the service, inform about availability, the Customer will only provide his e-mail address.
10. If you use the service, provide your opinion, the Customer provides the following data:
a) email address;
11. When using the Online Store Website, additional information may be downloaded, in particular: the IP address assigned to the Customer's computer or the external IP address of the Internet provider, domain name, type of browser, access time, type of operating system.
12. Navigational data may also be collected from customers, including information about links and links in which they decide to click or other activities undertaken in our Online Store. Legal basis - a legitimate interest (Article 6 paragraph 1 letter f of the GDPR), consisting in facilitating the use of electronic services and improving the functionality of these services.
13. In order to determine, pursue and enforce claims, certain personal data provided by the Customer may be processed as part of using the functionality in the Online Store, such as: name, surname, data regarding the use of services, if the claims result from the manner in which the Customer uses services, other data necessary to prove the existence of the claim, including the extent of the damage suffered. Legal basis - a legitimate interest (Article 6 paragraph 1 letter f of the GDPR), consisting in establishing, pursuing and enforcing claims, as well as defending against claims in proceedings before courts and other state authorities.
14. The transfer of personal data to NEONAIL.pl is voluntary in connection with concluded sales contracts or the provision of services via the Online Store Website, with the proviso that failure to provide the data specified in the forms in the Registration process prevents Registration and creating a Customer Account, and if you place an order without registering a customer account, you will not be able to place and process a customer order.
§ 2 Who is the data shared or entrusted to and how long is it stored?
1. The Customer's personal data is provided to service providers that NEONAIL.pl uses when running the Online Store. Service providers to whom personal data are transferred, depending on contractual arrangements and circumstances, or are subject to NEONAIL.pl's instructions as to the purposes and methods of processing this data (processing entities) or define the purposes and methods of their processing (administrators).
a) Processing entities. NEONAIL.pl uses suppliers who process personal data only at the request of NEONAIL.pl. These include providers of hosting services, accounting services, providing marketing systems, systems for analyzing traffic in the Online Store, systems for analyzing the effectiveness of marketing campaigns;
b) administrators. NEONAIL.pl uses suppliers who do not act only on instructions and set the purposes and ways of using the clients' personal data themselves. They provide electronic and banking payment services.
2. Location. Service providers are based mainly in Poland and other countries of the European Economic Area (EEA).
3. Customers' personal data are stored:
a) If the basis for the processing of personal data is consent, then the Customer's personal data is processed by NEONAIL.pl until the consent is revoked, and after the withdrawal of consent for a period of time corresponding to the limitation period of claims that NEONAIL.pl may raise and which may be raised against him. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activity - three years.
b) If the basis for data processing is the performance of the contract, then the Customer's personal data is processed by NEONAIL.pl as long as it is necessary to perform the contract, and after that time for a period corresponding to the period of limitation of claims. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activity - three years.
4. If you make a purchase in the Online Store, personal data may be transferred, depending on the customer's choice, to the following entities in order to deliver the ordered goods:
a) a courier company;
b) InPost Paczkomaty Sp. z o.o. with its registered office in Kraków, providing services in the delivery and operation of post office boxes (Paczkomaty);
c) Poczta Polska S.A. based in Warsaw.
5. If the customer chooses to pay via the dotpay.pl system, his personal data is transferred to the extent necessary for the payment to be made to Dotpay S.A. with its registered office in Kraków (30-552), ul. Wielicka 72, entered into the Register of Entrepreneurs kept by the District Court Kraków-Śródmieście in Kraków, 11th Commercial Division of the National Court Register under KRS number 0000296790.
6. If the Customer chooses the form of payment for Goods - the electronic deferred payment system "buy now - pay later", his personal data is transferred to the extent necessary for the payment to PayPo sp.z o.o. with its registered office in Warsaw (02-672), ul. Domaniewska 37, entered into the Register of Entrepreneurs kept by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register under KRS number: 0000575158.
7. Navigation data can be used to provide customers with better service, statistical data analysis and adapt the Online Store to customer preferences, as well as to administer the Online Store.
8. In the event that the Customer subscribes to the newsletter (Newsletter) to his email address NEONAIL.pl will send electronic messages containing commercial information about promotions and new products available in the Online Store.
9. In the event of a request being made, NEONAIL.pl provides personal data to authorized state bodies, in particular organizational units of the Prosecutor's Office, the Police, the President of the Office for Personal Data Protection, the President of the Office for Competition and Consumer Protection or the President of the Office of Electronic Communications.
§ 3 Cookies mechanism, IP address
1. The Online Store uses small files called cookies. They are saved by NEONAIL.pl on the terminal device of the person visiting the Online Store, if the web browser allows it. A cookie usually contains the name of the domain from which it comes, its "expiration time" and an individual, randomly selected number identifying this file. Information collected using files of this type helps to tailor the products offered by NEONAIL.pl to the individual preferences and real needs of people visiting the Store They also give the opportunity to compile general statistics of visits to presented products in the Online Store.
2. NEONAIL.pl uses two types of cookies:
a) Session cookies: after the browser session ends or the computer is turned off, the saved information is deleted from the device's memory. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from clients' computers.
b) Persistent cookies: they are stored in the memory of the Customer's terminal device and remain there until they are deleted or expire. The mechanism of persistent cookies does not allow you to download any personal data or any confidential information from your customers' computer.
3. NEONAIL.pl uses its own cookies to:
a) authenticating the Customer in the Online Store and ensuring the Customer session in the Online Store (after logging in), thanks to which the Customer does not have to re-enter the login and password on each subpage of the Online Store;
b) analysis and research and audience audit, and in particular to create anonymous statistics that help understand how customers use the Store Website, which allows improving its structure and content.
4. NEONAIL.pl uses external cookies to:
a) popularizing the Online Store using the social network facebook.com (administrator of external cookies: Facebook Inc. based in the USA or Facebook Ireland based in Ireland);
b) facilitating communication via the Store Website via chat (external cookie administrator: LiveChat Inc. with its registered office in the USA);
c) collecting general and anonymous static data via analytical tools Google Analytics (administrator of external cookies: Google Inc. based in the USA);
d) presenting advertisements tailored to the customer's preferences using the Google AdSense online advertising tool (external cookie administrator: Google Inc. based in the USA);
e) presentation of the Reliable Certificate Regulations via the rzetelnyregulamin.pl website (administrator of external cookies: Rzetelna Grupa sp.z o.o.with headquarters in Warsaw);
f) researching the behavior of visitors to the Online Store Website through the Hotjar tool (external cookie administrator: Hotjar Ltd. with its registered office in Malta);
g) presenting ads tailored to the customer's preferences using the go.pl online advertising tool (external cookie administrator: (GO.PL Sp.z o.o.with headquarters in Warsaw).
5. The cookie mechanism is safe for computers of Online Store Customers. In particular, it is not possible for viruses or other unwanted software or malware to enter your clients' computers in this way. Nevertheless, in their browsers, Customers have the option of limiting or disabling cookies' access to computers. If you use this option, you will be able to use the Online Store, in addition to functions that by their nature require cookies.
a) Internet Explorer browser;
b) Microsoft EDGE browser;
c) Mozilla Firefox browser;
d) Chrome browser;
e) Safari browser;
f) Opera browser.
7. NEONAIL.pl may collect Customers' IP addresses. The IP address is the number assigned to the computer of the person visiting the Online Store by the internet service provider. The IP number allows access to the Internet. In most cases, it is assigned to the computer dynamically, i.e. it changes every time you connect to the Internet. The IP address is used by NEONAIL.pl in diagnosing technical problems with the server, creating statistical analyzes (e.g. determining from which regions we record the most visits), as information useful in administering and improving the Online Store, as well as for security purposes and possible identification of incriminating server, unwanted automatic programs to view the content of the Online Store.
8. The Online Store contains links and references to other websites. NEONAIL.pl is not responsible for the privacy policies applicable to them.
§ 4 Rights of data subjects
1. Right to withdraw consent - legal basis: art. 7 item 3 GDPR.
a) The customer has the right to withdraw any consent given by NEONAIL.pl.
b) Withdrawal of consent has effect from the moment of withdrawal of consent.
c) Withdrawal of consent does not affect the processing carried out by NEONAIL.pl in accordance with the law before its withdrawal.
d) Withdrawal of consent does not entail any negative consequences for the Customer, however, it may prevent further use of services or functionalities which, according to the law of NEONAIL.pl, it can only provide with consent.
2. Right to object to data processing - legal basis: art. 21 GDPR.
a) The customer has the right to object at any time - for reasons related to his particular situation - to the processing of his personal data, including profiling, if NEONAIL.pl processes his data based on a legitimate interest, e.g. marketing of NEONAIL products and services .pl, keeping statistics on the use of individual functionalities of the Online Store and facilitating the use of the Online Store, as well as surveying satisfaction.
b) Resignation in the form of an e-mail message from receiving marketing messages regarding products or services will mean the Customer's objection to the processing of his personal data, including profiling for these purposes.
c) If the Customer's objection turns out to be well founded and NEONAIL.pl will not have another legal basis for processing personal data, the Customer's personal data will be deleted, for the processing of which the Customer has objected.
3. The right to delete data ("the right to be forgotten") - legal basis: art. 17 GDPR.
a) The customer has the right to request the erasure of all or some personal data.
b) The customer has the right to request the removal of personal data if:
a. personal data are no longer necessary for the purposes for which they were collected or for which they were processed;
b. withdrew specific consent to the extent to which personal data were processed based on his consent;
c. he objected to the use of his data for marketing purposes;
d. personal data is processed unlawfully;
e. personal data must be deleted in order to fulfill the legal obligation provided for in Union law or the law of the Member State to which NEONAIL.pl is subject;
f. personal data was collected in connection with offering information society services.
c) Despite the request to delete personal data, in connection with raising an objection or withdrawing consent, NEONAIL.pl may keep certain personal data to the extent that the processing is necessary to establish, assert or defend claims, as well as to fulfill a legal obligation requiring processing pursuant to Union or Member State law to which NEONAIL.pl is subject. This applies in particular to personal data including: name, surname, e-mail address, which are stored for the purpose of examining complaints and claims related to the use of NEONAIL.pl services, or additionally the address of residence / correspondence address, order number, which this data is kept for the purposes of examining complaints and claims related to concluded sales contracts or provision of services.
4. The right to limit data processing - legal basis: art. 18 GDPR.
a) The customer has the right to request a restriction of the processing of his personal data. Submission of a request, until it is considered, prevents the use of certain functionalities or services, the use of which will involve the processing of the data covered by the request. NEONAIL.pl will also not send any messages, including marketing messages.
b) The customer has the right to request the restriction of the use of personal data in the following cases:
a. when he questions the correctness of his personal data - then NEONAIL.pl limits its use for the time needed to check the correctness of the data, but no longer than for 7 days;
b. when the processing of data is unlawful, and instead of deleting the data, the Customer will request to limit their use;
c. when personal data cease to be necessary for the purposes for which they were collected or used but they are needed by the Customer to establish, assert or defend claims;
d. when he objected to the use of his data - then the restriction occurs for the time needed to consider whether - due to a special situation - the protection of the interests, rights and freedoms of the Customer outweighs the interests that the Administrator carries out by processing the Customer's personal data.
5. Right of access to data - legal basis: art. 15 GDPR.
a) The customer has the right to obtain confirmation from the Administrator whether he processes personal data, and if this is the case, the customer has the right to:
a. obtain access to your personal data;
b. obtain information about the purposes of processing, categories of personal data processed, about recipients or categories of recipients of such data, the planned period of storing the Customer's data or about the criteria for determining this period (when determining the planned period of data processing is not possible), about the rights of the Customer under GDPR and the right to lodge a complaint to the supervisory body, about the source of this data, about automated decision making, including profiling and about the safeguards used in connection with the transfer of these data outside the European Union;
c. obtain a copy of your personal data.
6. Right to rectify data - legal basis: art. 16 GDPR.
7. Right to data portability - legal basis: art. 20 GDPR.
a) The Customer has the right to receive his personal data, which he provided to the Administrator, and then send it to another personal data administrator of his choice. The customer also has the right to request that personal data be sent by the Administrator directly to such an administrator, if it is technically possible. In this case, the Administrator will post Customer's personal data in the form of a csv file, which is a commonly used, machine-readable format that allows the received data to be sent to another personal data administrator.
8. In the situation where the Customer has the right resulting from the above rights, NEONAIL.pl fulfills the request or refuses to comply with it immediately, but not later than within one month after receiving it. However, if - due to the complexity of the request or the number of requests - NEONAIL.pl will not be able to comply with the request within a month, it will meet them within the next two months informing the Customer within one month of receipt of the request - about the intended extension of the deadline and its reasons.
9. The Customer may submit to the Administrator complaints, queries and requests regarding the processing of his personal data and the exercise of his rights.
11. The customer has the right to lodge a complaint to the President of the Office for Personal Data Protection regarding the violation of his rights to the protection of personal data or other rights granted under the GDPR.
§ 5 Services tailored to preferences and interests (profiling)
1. Profiling means any form of automated Processing of Personal Data that involves the use of Personal Data to assess certain personal factors of a Physical Person, in particular to analyze or forecast aspects of the physical person's work effects, his economic situation, health, personal preferences, interests, credibility, behavior, location or movement.
2. Customers' personal data may be processed in an automated way (profiling), however, this will not have any legal effect on them or similarly significantly affect the situation of customers.
3. Profiling of personal data by NEONAIL.pl involves the processing of customer data in an automated and manual manner, by using it to evaluate certain information about the Customer, in particular to analyze or forecast his personal preferences and interests.
4. In order to reach the Customer with marketing messages outside the Online Store Website, NEONAIL.pl uses the services of external suppliers. These services consist of displaying marketing messages on pages other than the Online Store Website. For this purpose, external suppliers install e.g. the appropriate code or pixel to download information about the Customer's activity on the Online Store Website. Details regarding cookies used can be found in §3. Legal basis - a legitimate interest (art.6 par.1 lit.f RODO), consisting in matching marketing messages to preferences and interests.
5. In order to reach the Customer with marketing messages via the Online Store Website, NEONAIL.pl uses the services of external suppliers. These services consist in displaying marketing messages on the Online Store Pages. For this purpose, external suppliers install e.g. the appropriate code or pixel to download information about the Customer's activity on the Online Store Website. Details regarding cookies used can be found in §3. Legal basis - a legitimate interest (art.6 par.1 lit.f RODO), consisting in matching marketing messages to preferences and interests.
6. In order to reach the Customer with marketing messages via the Online Store Website, NEONAIL.pl uses its own cookie mechanisms to download information about the Customer's activity on the Online Store Website. Details regarding cookies used can be found in §3. Legal basis - a legitimate interest (art.6 par.1 lit.f RODO), consisting in matching marketing messages to preferences and interests.
§ 6 Security management - password
1. NEONAIL.pl provides customers with a secure and encrypted connection when sending personal data and when logging into the Customer's Account on the Website. NEONAIL.pl uses an SSL certificate issued by one of the world's leading companies in the field of security and encryption of data transmitted via the Internet.
2. In the event that the Customer who has an account in the Online Store has lost the access password in any way, the Online Store will generate a new password. NEONAIL.pl does not send password reminders. The password is stored in an encrypted form so that it cannot be read. In order to generate a new password, enter the e-mail address in the form available under the "Recover password" link provided at the login form to the account in the Online Store. The Customer will receive an e-mail containing a redirection to the dedicated form provided on the Shop Website, where the Customer will be able to set a new password to the e-mail address provided during registration or saved in the last change of account profile.
3. NEONAIL.pl never sends any correspondence, including electronic correspondence, asking for login details, in particular the password to access the Customer's account.
3. Date of last modification: 19.07.2019.