SATIS Privacy Policy
This Privacy Policy explains what personal data we process in connection with the use of our online store, purchases, enquiries, complaints, the Newsletter and cookies, as well as the rights available to individuals whose personal data is processed.
SATIS INTERNATIONAL S.C.
ul. Przeskok 53
63-400 Ostrów Wielkopolski
Poland
Data Controller and contact details
- The controller of personal data of users of the online store is SATIS INTERNATIONAL S.C., ul. Przeskok 53, 63-400 Ostrów Wielkopolski, Poland, NIP 6222754286, REGON 301625431.
- For matters concerning privacy, personal data processing or the exercise of your rights, you may contact us by e-mail at biuro@satispolska.pl, by telephone at +48 62 592 42 77, or in writing at the Controller's postal address.
- This Privacy Policy applies to personal data processed in connection with the use of the online store, placing and fulfilling orders, maintaining a Customer Account, enquiries, complaints, returns, the Newsletter, website security, cookies and similar technologies.
Personal data we collect
- Depending on how you use our online store, we may process in particular: your name and surname, company name, tax identification number, billing and delivery address, e-mail address, telephone number, Customer Account information, order history, payment and delivery details, correspondence and information provided in connection with a complaint or return.
- If you represent a business customer, we may process your identification details, business contact information, job title or function and information necessary to manage our business relationship.
- When you use our website, certain technical information may be recorded automatically, including your IP address, device and browser type, operating system, cookie identifiers, date and time of your visit, pages visited, referral source and information relating to technical and security events.
- We do not require special categories of personal data, such as information concerning health, racial or ethnic origin, political opinions, religious beliefs or similar sensitive information. Please do not provide such data unless it is necessary for handling a specific matter.
- Providing personal data is voluntary; however, certain information is necessary to enter into and perform a contract, issue accounting documents, arrange delivery, maintain a Customer Account, process a complaint or respond to your enquiry.
Purposes and legal bases
Article 6(1)(b) GDPR, including taking steps at the customer's request prior to entering into a contract.
Article 6(1)(c) GDPR, i.e. compliance with a legal obligation applicable to the Controller.
Article 6(1)(b) GDPR, i.e. performance of a contract for the provision of electronic services.
Article 6(1)(b) GDPR where communication concerns entering into or performing a contract, or Article 6(1)(f) GDPR, i.e. our legitimate interest in communicating with customers and handling enquiries.
Article 6(1)(b) and (c) GDPR and Article 6(1)(f) GDPR, including establishing, pursuing or defending legal claims.
Article 6(1)(a) GDPR, i.e. consent, as well as any consent required under applicable electronic communications legislation.
Article 6(1)(f) GDPR, i.e. our legitimate interest in protecting the website, users, transactions and records of relevant events.
Article 6(1)(a) GDPR where consent is required and provided through the cookie consent panel.
Orders and Customer Account
- Personal data provided during the purchase process is used to prepare and fulfil the order, communicate with you regarding the purchase, process payment, issue documents, arrange delivery, provide after-sales support and comply with applicable legal obligations.
- Customer Account data is processed for as long as the Account remains active. Customers may be able to purchase without registration where this option is available in the store.
- After deletion of the Customer Account, we may continue to retain information relating to completed transactions, accounting documents, complaints and claims where required by law or justified by the Controller's legitimate interests.
- Where an order is placed on behalf of a company, the contact person's information may be provided directly by that person, their employer or colleague, or obtained from public business registers and sources related to business activity.
Contact, complaints and returns
- Personal data provided by e-mail, telephone, contact form or other communication channels is used to respond to your enquiry, prepare an offer, handle your request or take steps prior to entering into a contract.
- When handling a complaint, return, warranty claim or service request, we may process contact details, purchase information, a description of the issue, photographs, serial numbers, technical information and correspondence relating to the matter.
- Correspondence may also be retained after the matter has been closed where necessary to document its handling, protect the Controller's rights or comply with legal obligations.
Payments and delivery
- For the purpose of processing payments, information necessary to complete the transaction may be transferred to the payment provider selected by the customer. The payment provider may act as an independent data controller in accordance with its own privacy policy.
- For payments processed via Przelewy24, personal data is transferred to the extent necessary to initiate, authorise and settle the payment.
- For delivery purposes, the recipient's name, address, telephone number, e-mail address and shipment information may be provided to the courier, carrier, freight forwarder or logistics provider.
- The scope of transferred personal data is limited to the information necessary to provide the selected service, handle transport-related complaints and settle the transaction.
Recipients of personal data
- Personal data may be disclosed to service providers supporting the Controller with hosting, IT services, PrestaShop maintenance, e-mail services, cybersecurity, backups and technical support.
- Recipients may also include payment operators, banks, courier companies, carriers, freight forwarders, logistics providers, accounting system providers, accounting firms, legal advisers, insurers and providers involved in complaints and service support.
- Where the appropriate consent has been given, recipients may also include providers of analytics, advertising, marketing tools, Newsletter services and social media platforms.
- Personal data may be disclosed to public authorities, courts or other authorised entities where required by applicable law.
- The Controller does not sell personal data.
How long we keep your data
- Personal data relating to a contract is retained for the duration of the contract and afterwards for periods required under accounting and tax legislation and until the expiry of applicable limitation periods for potential claims.
- Customer Account data is processed until the Account is deleted and afterwards to the extent necessary to comply with legal obligations, complete settlements and protect against claims.
- Data relating to complaints, warranties, returns and servicing is retained for the period necessary to handle the matter and until the expiry of relevant liability and claim periods.
- Data processed on the basis of consent is retained until consent is withdrawn, the purpose becomes obsolete or the data is deleted earlier, unless information concerning the consent must be retained for evidential purposes.
- Data processed on the basis of legitimate interests is retained until the relevant purpose ceases to apply, an effective objection is made or an overriding obligation to delete the data arises, taking into account periods necessary to protect against claims.
- Security logs may be retained for a period appropriate for detecting incidents, ensuring business continuity and pursuing or defending claims.
Your data protection rights
You may request information about the processing of your personal data and obtain a copy of it.
You may request correction of inaccurate personal data or completion of incomplete data.
You may request deletion of your personal data in the circumstances provided for under the GDPR.
You may request temporary restriction of the way your personal data is processed.
You may receive your personal data and transmit it to another controller where the conditions set out in the GDPR are met.
You may object to processing based on legitimate interests.
You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
You may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) or, where applicable, with the competent supervisory authority in your country.
Please contact us at biuro@satispolska.pl. We may request additional information necessary to verify your identity and ensure that personal data is not disclosed to an unauthorised person.
Transfers outside the European Economic Area
- Some technology, analytics, marketing, e-mail or infrastructure providers may process personal data outside the European Economic Area (EEA).
- Where this occurs, personal data is transferred only using a mechanism permitted under the GDPR, in particular an adequacy decision or Standard Contractual Clauses, together with additional safeguards where necessary.
- Information about specific providers activated on the basis of consent should be available in the cookie settings panel or in the privacy policies of those providers.
Profiling and automated decision-making
- If a user consents to analytics or marketing, information about their activity may be used to create audience groups, measure campaign effectiveness and tailor displayed content or advertising.
- Marketing profiling based on consent does not produce legal effects concerning the user or similarly significantly affect them.
- The Controller does not make decisions concerning customers based solely on automated processing where such decisions would produce legal effects or similarly significantly affect the individual, unless information about such processing is provided separately.
Data security
- The Controller implements appropriate technical and organisational measures taking into account the nature, scope and risks associated with the processing of personal data.
- Protection measures may include, in particular, encrypted transmission, access controls, backups, software updates, system protection, event logging, access authorisation procedures and confidentiality obligations applicable to persons processing personal data.
- No method of transmitting or storing information can guarantee complete elimination of risk. In the event of a personal data breach, we follow the procedures required under the GDPR.
- Users should protect their Customer Account passwords, use up-to-date software and never disclose login credentials to third parties.
Changes to this Privacy Policy
- This Privacy Policy may be updated where there are changes to applicable law, online store functionality, technologies used, processing activities, recipients of personal data or the Controller's details.
- The current version of the Privacy Policy is published on the online store website together with its effective date.
- If a change materially affects the processing of personal data relating to persons who maintain a Customer Account or use ongoing services, information about the change may also be provided by e-mail or through the Customer Account.