PRIVACY POLICY OF THE BUNKIER ONLINE SHOP
1. General information
This Privacy Policy explains how the Bunkier online shop processes the personal data of people who visit the website, contact the shop, create a customer account, subscribe to the newsletter, use notifications or place orders.
This Policy is provided for information and to meet obligations under personal data protection law, in particular the General Data Protection Regulation (GDPR).
2. Personal data controller
The personal data controller is:
VIPER TEAM SP脫艁KA Z OGRANICZON膭 ODPOWIEDZIALNO艢CI膭
KRS 0001205307
NIP 9121953092
REGON 543250305
Wincentego Witosa 39, 55-220 Jelcz-Laskowice, Poland
[email protected]
For matters relating to personal data protection, you can contact the Controller at the e-mail address above or by post at the registered office address.
3. Scope of data processed
The Controller processes data to the extent needed to operate the shop and manage the relationship with the user. Depending on how the shop is used, this may include in particular:
- first name and surname,
- delivery address and billing address,
- e-mail address,
- telephone number,
- company details, including tax identification number, if the customer requests an invoice,
- customer account data,
- data relating to an order, payment, delivery, complaint, return or claim,
- the content of correspondence sent by form, e-mail or telephone,
- data relating to the newsletter, product availability notification or product review,
- technical data relating to use of the website, such as cookie identifiers, session data, IP address, device information and server logs.
The Controller processes data only to the extent appropriate for the purpose for which it was collected.
4. Purposes and legal bases of processing
a) placing and fulfilling an order
Data is processed to accept an order, conclude and perform a sales contract, handle payment, prepare delivery, contact the customer about the order and provide after-sales support. The legal basis is Article 6(1)(b) GDPR.
b) the Controller's legal obligations
Data is processed to issue and store sales documents, keep accounts, meet tax and accounting obligations and comply with other obligations under law. The legal basis is Article 6(1)(c) GDPR.
c) complaints, returns and claims
Data is processed to handle complaints, contract withdrawals, returns, pursue claims or defend against claims. The legal basis may be Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR, depending on the nature of the matter.
d) contacting the Controller
Data provided through the contact form, by e-mail or by telephone is processed to respond and manage correspondence. The legal basis is Article 6(1)(b) GDPR where the contact relates to a contract or pre-contractual steps, or Article 6(1)(f) GDPR, namely the Controller's legitimate interest in handling correspondence.
e) customer account
If a user creates a customer account, data is processed to create and maintain the account and provide the functions assigned to it. The legal basis is Article 6(1)(b) GDPR.
f) newsletter, notifications and marketing consents
Data is processed to send the newsletter, commercial information, marketing information or product availability notifications where the user has given the relevant consent. The legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
g) product reviews
If a user adds a product review, data may be processed to handle, verify and publish the review. The legal basis is Article 6(1)(f) GDPR, namely the Controller's legitimate interest in handling reviews and presenting product information, and, where consent has been given, Article 6(1)(a) GDPR.
h) shop security and operation
Technical data, necessary cookies, session data, logs and information about website use are processed to ensure proper shop operation, shopping basket functionality, session maintenance, diagnostics, security and protection against abuse. The legal basis is Article 6(1)(f) GDPR.
5. Is providing data required?
Providing data is voluntary, but may be necessary to conclude or perform a contract, handle an order, issue a sales document, deliver a parcel, create an account, respond to a message, subscribe to the newsletter or use a selected shop function. Failure to provide data required for a given action may prevent that action from being completed.
6. Data recipients
Personal data may be disclosed to entities cooperating with the Controller only to the extent needed to achieve the stated purposes. These may include in particular:
- providers of hosting, IT services, website maintenance and shop software,
- Cloudflare as the provider of public edge infrastructure, proxy and security services, which may process technical request and security data, including IP addresses and request and log information,
- entities handling e-mail, SMTP, contact forms, newsletters, notifications and customer communication,
- Przelewy24 as the main online payment operator and institutions supporting the selected payment method,
- banks supporting bank transfer payment,
- Apaczka/Alsendo and selected delivery, courier and pickup-point operators presented during checkout, including entities supporting pickup-point selection where the delivery method provides it,
- entities supporting accounting, tax, legal, complaint-handling or debt-recovery matters,
- authorised public authorities where disclosure is required by law.
Processors acting on the Controller's behalf process data under appropriate agreements and may process data only in accordance with the Controller's instructions.
7. Transfers outside the European Economic Area
Some infrastructure or service providers, including Cloudflare and their subprocessors, may process data outside the European Economic Area. Such transfers take place only using mechanisms allowed by applicable data-protection law, including an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses or another lawful safeguard. Further information about applicable safeguards may be obtained by contacting the Controller.
8. Data retention period
Data is stored for the period necessary to achieve the purpose for which it was collected, and then for the period required by law or needed to secure claims. In particular:
- data relating to order fulfilment and accounting documentation is stored for the period required by tax and accounting law,
- customer account data is stored for the duration of the account, unless longer storage is required by law or needed to protect claims,
- data relating to complaints, returns and claims is stored for the period needed to handle the matter and for the limitation period for claims,
- data confirming the giving, scope and withdrawal of consent is stored for the period needed to demonstrate the correctness of processing based on consent,
- data relating to newsletters and notifications is stored until consent is withdrawn, the service is cancelled or the purpose of processing ceases, subject to the need to demonstrate that consent was previously given,
- data relating to product reviews is stored for the period of publication or review handling, unless longer storage is needed to protect claims or is required by law,
- correspondence and contact-form data is stored for the period needed to handle the matter and demonstrate its course,
- technical and security logs are stored for the period needed to ensure operation, diagnostics, security and protection against abuse, and then for the period needed to secure claims or comply with legal obligations.
9. Rights of the data subject
The data subject has the following rights, in the cases provided for by law:
- the right of access to data,
- the right to obtain a copy of data,
- the right to rectification,
- the right to erasure,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing,
- the right to withdraw consent at any time where processing is based on consent.
A rights request may be submitted by contacting the Controller. The Controller may ask for information needed to confirm the identity of the person making the request.
10. Right to lodge a complaint
If the data subject considers that the processing of their personal data breaches GDPR, they have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urz臋du Ochrony Danych Osobowych).
11. Automated decision-making and profiling
The Controller does not currently use personal data for automated decision-making producing legal effects or similarly significantly affecting the user. The shop does not currently perform marketing profiling.
12. Cookies and similar technologies
The shop currently uses cookies and similar technologies necessary for website operation, session maintenance, shopping basket functionality, security and interface preferences. Analytics and marketing tracking are not currently enabled. Details are provided in the Cookie Policy.
13. Data security
The Controller applies appropriate technical and organisational measures intended to protect personal data against loss, destruction, disclosure to unauthorised persons, unauthorised modification or unauthorised access.
14. Changes to this Privacy Policy
This Privacy Policy may be updated if the law changes, technology changes, shop functions change or data processing methods change. The current version of the Privacy Policy is published on the shop website.
15. Privacy contact
For matters relating to personal data protection, you can contact the Controller:
Viper Team Sp. z o.o.
ul. Wincentego Witosa 39
55-220 Jelcz-Laskowice
Poland
[email protected]