Privacy Policy

PRIVACY POLICY

1. This Privacy Policy defines the rules for processing personal data obtained through the online store https://www.molehillgoods.com (hereinafter referred to as the “Online Store”).

2. The owner of the Online Store and also the Data Controller is Good Goods Company Łukasz Król, ul. Ks. J. Popiełuszki 13/21, 01-595 Warszawa, NIP: 9521990151, REGON: 142279101, registered in the CEIDG (Central Registration and Information on Business).

3. Personal data collected by Good Goods Company Łukasz Król via the Online Store are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as **GDPR**.

4. Good Goods Company Łukasz Król takes special care to respect the privacy of Clients visiting the Online Store.

§ 1 Type of Processed Data, Purposes, and Legal Basis

1. Good Goods Company Łukasz Król collects information regarding natural persons performing a legal act not directly related to their business activity, natural persons conducting business or professional activity on their own behalf, and natural persons representing legal persons or organizational units without legal personality, to whom the law grants legal capacity, conducting business or professional activity on their own behalf, hereinafter collectively referred to as **Clients**.

2. Clients’ personal data are collected in the event of:
a) **Account registration** in the Online Store, for the purpose of creating and managing an individual user account. Legal basis: necessity for the performance of the Account service agreement (Art. 6(1)(b) GDPR);
b) **Placing an order** in the Online Store, for the purpose of performing the sales agreement. Legal basis: necessity for the performance of the sales agreement (Art. 6(1)(b) GDPR);
c) **Newsletter subscription** for the purpose of performing an agreement whose subject is an electronically supplied service. Legal basis – consent of the data subject for the performance of the Newsletter service agreement (Art. 6(1)(a) GDPR).

3. In the case of **User Account registration** in the Online Store, the Client provides:
a) email address;
b) address details:
– postcode and city;
– country;
– street with house/apartment number.
– first name and last name;
– phone number.

4. During User Account registration in the Online Store, the Client independently sets an individual access password to their Account. The Client can change the password later, according to the rules described in §6.

5. When **placing an order** in the Online Store, the Client provides the following data:
a) email address;
b) address details:
– postcode and city;
– country;
– street with house/apartment number.
– first name and last name;
– phone number.

6. In the case of **Entrepreneurs**, the above scope of data is additionally extended by:
a) Entrepreneur’s company name;
b) NIP number (Tax Identification Number).

7. When using the **Newsletter service**, the Client only provides their email address.

8. When using the store’s website, additional information may be collected, in particular: the IP address assigned to the Client’s computer or the external IP address of the internet provider, domain name, browser type, access time, operating system type.

9. Navigation data may also be collected from Clients, including information about links they choose to click or other actions taken in our Online Store. Legal basis – legitimate interest (Art. 6(1)(f) GDPR), consisting of facilitating the use of electronically supplied services and improving the functionality of these services.

10. For the purpose of establishing, exercising, and defending claims, some personal data provided by the Client when using functionalities in the Online Store may be processed, such as: first name, last name, data regarding the use of services, if the claims arise from the way the Client uses the services, other data necessary to prove the existence of a claim, including the extent of damages incurred. Legal basis – legitimate interest (Art. 6(1)(f) GDPR), consisting of establishing, exercising, and defending claims, and defending against claims in proceedings before courts and other state authorities.

11. Personal data provided to Good Goods Company Łukasz Król are given voluntarily, in connection with concluded sales agreements or the provision of services via the store’s website, with the proviso that failure to provide certain data in the forms during the registration process prevents registration and creation of a user account, while in the case of placing an order without user account registration, it does not prevent the submission and fulfillment of the Client’s order.

§ 2 To Whom Data is Disclosed or Entrusted and How Long It is Stored

1. Client’s personal data are transferred to service providers used by Good Goods Company Łukasz Król in running the Online Store. Service providers to whom personal data are transferred, depending on contractual agreements and circumstances, either follow Good Goods Company Łukasz Król’s instructions regarding the purposes and methods of processing such data (processors) or independently determine the purposes and methods of their processing (controllers).

a) **Processors.** Good Goods Company Łukasz Król uses providers who process personal data solely on the instructions of Good Goods Company Łukasz Król. These include, among others, hosting service providers, marketing system providers, systems for analyzing traffic in the Online Store, and systems for analyzing the effectiveness of marketing campaigns;
b) **Controllers.** Good Goods Company Łukasz Król uses providers who do not act exclusively on instructions and themselves determine the purposes and methods of using Clients’ personal data. They provide electronic payment and banking services.

2. **Location.** Service providers are mainly based in Poland and other countries of the European Economic Area (EEA).

3. Clients’ personal data are stored:
a) If the legal basis for processing personal data is **consent**, then the Client’s personal data are processed by Good Goods Company Łukasz Król until the consent is revoked, and after the consent is revoked, for a period corresponding to the statute of limitations for claims that Good Goods Company Łukasz Król may raise and that may be raised against it. Unless a specific provision states otherwise, the statute of limitations is ten years, and for claims for periodic benefits and claims related to conducting business activity – three years.
b) If the legal basis for processing data is the **performance of a contract**, then the Client’s personal data are processed by Good Goods Company Łukasz Król as long as it is necessary for the performance of the contract, and thereafter for a period corresponding to the statute of limitations for claims. Unless a specific provision states otherwise, the statute of limitations is ten years, and for claims for periodic benefits and claims related to conducting business activity – three years.

4. In the event of a purchase in the Online Store, personal data may be transferred, depending on the Client’s choice, to the following entities for the purpose of delivering ordered goods:
a) courier company;
b) InPost Paczkomaty Sp. z o.o. with its registered office in Krakow, providing delivery and parcel locker system services;
c) Alsendo spółka z ograniczoną odpowiedzialnością (ul. Klimczaka 1 02-797 Warszawa), responsible for shipping processes.

5. If the Client chooses payment via the tPay system, their personal data are transferred to Krajowy Integrator Płatności S.A. with its registered office in Poznań (ul. Sw. Marcin 73/6, 61-808 Poznań), NIP: 7773061579, to the extent necessary for payment processing.

6. If the Client chooses payment via the PayPal system, their personal data are transferred to PayPal Sp. zo.o. with its registered office in Warszawa (ul. Emilii Plater 53, 00-113 Warszawa), REGON: 141108225, to the extent necessary for payment processing.

7. Navigation data may be used to provide Clients with better service, analyze statistical data, adapt the Online Store to Client preferences, and administer the Online Store.

8. If the Client subscribes to the Newsletter, Good Goods Company Łukasz Król will send electronic messages containing commercial information about promotions and new products available in the Online Store to their email address.

9. Good Goods Company Łukasz Król, if requested, provides personal data to authorized state authorities, in particular organizational units of the Prosecutor’s Office, Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.

§ 3 Cookies Mechanism, IP Address

1. The Online Store uses small files called **cookies**. They are saved by Good Goods Company Łukasz Król on the end device of the person visiting the Online Store, if the web browser allows it. A cookie file usually contains the name of the domain it comes from, its “expiration time”, and an individual, randomly selected number identifying this file. Information collected using this type of files helps Good Goods Company Łukasz Król adapt the products offered to the individual preferences and actual needs of people visiting the online store. They also make it possible to compile general statistics of visits to the presented products in the Online Store.

2. Data collected in log files are used solely for the purpose of administering the Online Store.

3. In accordance with the practice of most websites, we store HTTP queries directed to our server (server logs). Therefore, we store:
– IP addresses from which users view the informational content of our website;
– time of arrival of the request,
– time of sending the response,
– Client’s workstation name – identification performed by the HTTP protocol,
– information about errors that occurred during the HTTP transaction,
– URL of the previously visited page by the user (referer link);
– information about the user’s browser.

4. Collected logs are stored indefinitely as auxiliary material for administering the Online Store. The information contained therein is not disclosed to anyone other than persons authorized to administer the Online Store. Based on log files, statistics can be generated to assist in administration. Aggregate summaries in the form of such statistics do not contain any features identifying visitors to the site.

5. The Cookies mechanism is not used to obtain any information about website users or track their navigation. Cookies used in the Online Store do not store any personal data or other information collected from users.

6. In the Online Store, we use the following Cookies:
– google-analytics.com cookies – statistics for the molehillgoods.com website
– session cookies (expire after the session ends)
– cookies used to handle user authorization
– cookies related to displaying messages related to form handling
– cookie related to the “AddThis Social Bookmarking Widget” plugin, which is used for easy content sharing via social networks. The privacy policy of the Addthis service is described here: [http://www.addthis.com/privacy/privacy-policy#publisher-visitors](http://www.addthis.com/privacy/privacy-policy#publisher-visitors)

7. Third-party services whose materials we present may also use cookies that enable logging in and are used to deliver advertisements corresponding to the user’s preferences and behavior.

8. In your web browser, you can change your cookie settings. Failure to change these settings means acceptance of the cookies used here.

§ 4 Rights of Data Subjects

1. **Right to withdraw consent** – legal basis: Art. 7(3) GDPR.

a) The Client has the right to withdraw any consent they have given to Good Goods Company Łukasz Król.
b) Withdrawal of consent is effective from the moment of its withdrawal.
c) Withdrawal of consent does not affect the processing carried out by Good Goods Company Łukasz Król lawfully before its withdrawal.
d) Withdrawal of consent does not entail any negative consequences for the Client, but it may prevent further use of services or functionalities that Good Goods Company Łukasz Król can lawfully provide only with consent.

2. **Right to object to data processing** – legal basis: Art. 21 GDPR.

a) The Client has the right to object at any time – on grounds relating to their particular situation – to the processing of their personal data, including profiling, if Good Goods Company Łukasz Król processes their data based on a legitimate interest, e.g., marketing of Good Goods Company Łukasz Król products and services, conducting statistics on the use of individual functionalities of the Online Store and facilitating the use of the Online Store, as well as satisfaction surveys.
b) Opting out of receiving marketing communications regarding products or services via email will mean the Client’s objection to the processing of their personal data, including profiling for these purposes.
c) If the Client’s objection proves justified and Good Goods Company Łukasz Król has no other legal basis for processing personal data, the Client’s personal data against whose processing the Client objected will be deleted.

3. **Right to erasure (“right to be forgotten”)** – legal basis: Art. 17 GDPR.

a) The Client has the right to request the erasure of all or some personal data.
b) The Client has the right to request the erasure of personal data if:

– the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
– they have withdrawn consent on which the processing is based, and there is no other legal ground for the processing;
– they have objected to the use of their data for marketing purposes;
– the personal data have been unlawfully processed;
– the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which Good Goods Company Łukasz Król is subject;
– the personal data have been collected in relation to the offer of information society services.

c) Despite the request for erasure of personal data, due to an objection or withdrawal of consent, Good Goods Company Łukasz Król may retain certain personal data to the extent that processing is necessary for the establishment, exercise, or defense of legal claims, as well as for compliance with a legal obligation requiring processing by Union or Member State law to which Good Goods Company Łukasz Król is subject. This applies in particular to personal data including: first name, last name, email address, which are retained for the purpose of handling complaints and claims related to the use of Good Goods Company Łukasz Król’s services, or additionally, residential/correspondence address, order number, which are retained for the purpose of handling complaints and claims related to concluded sales agreements or service provision.

4. **Right to restriction of processing** – legal basis: Art. 18 GDPR.
a) The Client has the right to request the restriction of processing of their personal data. Submitting such a request, until it is considered, prevents the use of certain functionalities or services whose use would involve the processing of the data covered by the request. Good Goods Company Łukasz Król will also not send any communications, including marketing ones.
b) The Client has the right to request the restriction of the use of personal data in the following cases:

– when they contest the accuracy of their personal data – in which case Good Goods Company Łukasz Król restricts their use for a period necessary to verify the accuracy of the data, but no longer than 7 days;
– when the processing of data is unlawful, and instead of erasure, the Client requests the restriction of their use;
– when the personal data are no longer needed for the purposes for which they were collected or used but are required by the Client for the establishment, exercise, or defense of legal claims;
– when they have objected to the use of their data – in which case the restriction applies for a period necessary to ascertain whether – due to the particular situation – the protection of the Client’s interests, rights, and freedoms overrides the interests pursued by the Controller when processing the Client’s personal data.

5. **Right of access to data** – legal basis: Art. 15 GDPR.
a) The Client has the right to obtain from the Controller confirmation as to whether or not personal data concerning them are being processed, and where that is the case, the Client has the right to:
– obtain access to their personal data;
– obtain information about the purposes of processing, the categories of personal data processed, the recipients or categories of recipients of such data, the envisaged period for which the Client’s data will be stored, or the criteria used to determine that period (when it is not possible to specify the planned period of data processing), the rights available to the Client under the GDPR and the right to lodge a complaint with a supervisory authority, the source of such data, automated decision-making, including profiling, and the safeguards applied in connection with the transfer of such data outside the European Union;
– obtain a copy of their personal data.

6. **Right to rectification of data** – legal basis: Art. 16 GDPR.
a) The Client has the right to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement, by sending a request to the email address in accordance with §7 of the Privacy Policy.

7. **Right to data portability** – legal basis: Art. 20 GDPR.
a) The Client has the right to receive their personal data, which they have provided to the Controller, and then transmit those data to another, chosen by them, personal data controller. The Client also has the right to have the personal data transmitted directly from the Controller to another controller, where technically feasible. In such a case, the Controller will send the Client’s personal data in a csv file format, which is a commonly used, machine-readable format allowing for the transfer of the received data to another personal data controller.

8. In the event of a Client exercising any of the above rights, Good Goods Company Łukasz Król shall comply with the request or refuse to comply with it without undue delay, but no later than within one month of receipt. However, if – due to the complex nature of the request or the number of requests – Good Goods Company Łukasz Król is unable to meet the request within one month, it will do so within the next two months, informing the Client within one month of receiving the request – of the intended extension of the deadline and the reasons for it.

9. The Client may submit complaints, inquiries, and requests to the Controller regarding the processing of their personal data and the exercise of their rights.

10. The Client has the right to request Good Goods Company Łukasz Król to provide a copy of the standard contractual clauses by sending an inquiry in the manner indicated in §7 of the Privacy Policy.

11. The Client has the right to lodge a complaint with the President of the Personal Data Protection Office regarding the violation of their personal data protection rights or other rights granted under the GDPR.

§ 5 Services Tailored to Preferences and Interests (Profiling)

1. **Profiling** means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

2. Clients’ personal data may be processed in an automated manner (profiling), however, this will not produce any legal effects concerning them or similarly significantly affect Clients’ situation.

3. Profiling of personal data by Good Goods Company Łukasz Król involves the automated and manual processing of Client data by using it to evaluate certain information about the Client, in particular to analyze or predict their personal preferences and interests.

4. In order to reach the Client with marketing communications via the Online Store website, Good Goods Company Łukasz Król uses its own cookie mechanisms to collect information about the Client’s activity on the Online Store website. Details regarding the cookies used can be found in §3. Legal basis – legitimate interest (Art. 6(1)(f) GDPR), consisting of tailoring marketing communications to preferences and interests.

§ 6 Security Management – Password

1. Good Goods Company Łukasz Król ensures Clients a secure and encrypted connection when transmitting personal data and when logging into the user account on https://www.molehillgoods.com, using an SSL certificate issued by one of the companies specializing in security and encryption of data transmitted over the Internet.

2. f a Client with a user account in the store has lost their access password in any way, the Online Store allows for the generation of a new password. Good Goods Company Łukasz Król does not send password reminders. The password is stored in the database in encrypted form, making it impossible to read. To generate a new password, you must enter your email address in the form available under the “Forgot your password” link, provided next to the user account login form in the Online Store. A new password will be automatically sent to the email address provided during registration or saved in the last account profile change.

3. Good Goods Company Łukasz Król never sends any correspondence, including electronic correspondence, requesting login details, and in particular the access password to the user account.

§ 7 Changes to the Privacy Policy

1. The Privacy Policy may be subject to change, of which Good Goods Company Łukasz Król will inform Clients 7 days in advance.

2. Questions related to the Privacy Policy should be directed to: hello@molehillgoods.com

3. Last modified: May 25, 2018.