PRIVACY POLICY OF THE ENESMAGNETS.PL ONLINE STORE
1. General information
- This Privacy Policy, hereinafter referred to as the “Policy”, explains how personal data is processed in connection with the use of the ENESMAGNETS.PL online store operating at https://enesmagnets.pl, hereinafter referred to as the “Store”.
- This Policy applies in particular to persons who:
a) visit the Store;
b) create or use a Customer Account;
c) place orders as registered customers or as guests;
d) contact the Store by e-mail, telephone or through an online form;
e) submit complaints, return products or exercise other rights relating to a sales agreement;
f) use functions involving cookies or similar technologies.
- The Store sells physical products only.
- Capitalised terms not defined in this Policy have the meanings assigned to them in the Store’s Terms and Conditions.
2. Personal data Controller
- The Controller of personal data is:
ENES Magnesy Paweł Zientek sp.k.
ul. gen. Tadeusza Kutrzeby 15
05-082 Stare Babice
Poland
National Court Register number – KRS: 0000373568
Tax Identification Number – NIP: 1182054337
Statistical Number – REGON: 142735326
hereinafter referred to as the “Controller”.
- The Controller may be contacted:
a) by e-mail at: shop@enesmagnets.pl;
b) by telephone at: +48 22 733 14 65;
c) by post at the registered office address stated above.
- The Controller has not appointed a Data Protection Officer. All matters concerning the processing of personal data should be addressed directly to the Controller.
3. Personal data processing principles
- The Controller processes personal data in accordance with applicable law, in particular:
a) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, hereinafter referred to as the “GDPR”;
b) the Polish Act of 10 May 2018 on the Protection of Personal Data;
c) applicable rules concerning privacy and data protection in electronic communications.
- The Controller applies appropriate technical and organisational measures taking into account the nature of the data, the purposes of processing and the risks related to such processing.
- Personal data is processed:
a) lawfully, fairly and transparently;
b) for specified, explicit and legitimate purposes;
c) only to the extent necessary for those purposes;
d) for no longer than necessary;
e) with an appropriate level of security.
4. Sources and categories of personal data
- The Controller usually obtains personal data directly from the person using the Store, in particular when that person:
a) creates a Customer Account;
b) places an order;
c) provides billing or delivery details;
d) contacts the Store;
e) submits a complaint, withdrawal notice, return request or another claim.
- Depending on how the Store is used, the Controller may process:
a) first name and surname;
b) company name;
c) tax identification number or EU VAT number;
d) billing, business and delivery addresses;
e) country;
f) e-mail address;
g) telephone number;
h) login details and Customer Account information;
i) order history;
j) information concerning ordered products, payments, invoices, shipping and delivery;
k) correspondence, complaints and other requests;
l) information voluntarily included in an order comment or message;
m) IP address, date and time of access, device, operating system and browser information, and technical logs;
n) information concerning activity in the Store, visited pages, viewed products and interactions with advertisements, where the user has given the appropriate consent.
- The Controller may also receive information from payment providers, couriers, technical service providers and other entities involved in processing an order. Such information may include payment confirmation, shipment status, transaction identifiers or details of an issue affecting the service.
5. Customer Account
- Creating a Customer Account is voluntary. A customer may also purchase products without registration by using guest checkout.
- Data submitted during registration is processed to:
a) create and maintain the Customer Account;
b) enable the customer to sign in;
c) store customer details and order history;
d) provide Customer Account functions;
e) handle requests relating to the Customer Account.
- The legal basis is Article 6(1)(b) of the GDPR, as processing is necessary to enter into and perform the agreement for the provision of the Customer Account service.
- Providing the required information is voluntary but necessary to create a Customer Account.
- Customer Account data is processed until the Account is deleted or the Account service is terminated. Certain information may subsequently be retained for the period required to establish, exercise or defend legal claims.
- Where the Store offers a sign-in option provided by an external service, the Controller may receive information necessary to authenticate the user, within the scope approved by that user.
6. Orders and sales agreements
- Customer data is processed to:
a) receive and confirm an order;
b) enter into and perform a sales agreement;
c) prepare products for shipment;
d) communicate with the customer about the order;
e) provide shipment information to the selected courier;
f) process payment;
g) issue and provide sales documents;
h) handle a return, complaint or another request relating to the order.
- The legal basis for processing data necessary to accept and perform an order is Article 6(1)(b) of the GDPR.
- Providing the information marked as required is voluntary but necessary to enter into and perform the agreement. Failure to provide it may make it impossible to place an order, process payment, issue a sales document or deliver the products.
- Order information is retained for the duration of the agreement and subsequently for the periods required under tax and accounting law and the applicable limitation periods.
7. Payments
- Depending on the payment method selected by the customer, information necessary to process payment may be shared with:
a) Stripe;
b) PayPal;
c) banks involved in processing bank transfers or SEPA payments;
d) card schemes and payment service providers;
e) Apple Pay and Google Pay providers;
f) providers of local payment methods made available through Stripe or PayPal, including Klarna, Revolut, Bancontact, EPS, Link, MobilePay, Multibanco or TWINT, where available to a particular customer.
- Payment providers may process customer data as independent controllers in accordance with their own privacy policies and the laws applicable to them.
- The Controller processes payment status and information required to link a payment with an order on the basis of Article 6(1)(b) of the GDPR.
- Where the processing of particular information is required by tax, accounting, fraud-prevention or other applicable legislation, the legal basis is also Article 6(1)(c) of the GDPR.
- As a rule, the Controller does not receive the customer’s complete payment card details where those details are entered directly into the payment provider’s system.
8. Delivery
- Information necessary to deliver an order may be shared with the courier or logistics provider selected for the shipment.
- The Store uses in particular:
a) FedEx;
b) DHL.
- A courier or logistics provider may receive:
a) the recipient’s name;
b) company name;
c) delivery address;
d) e-mail address;
e) telephone number;
f) other information necessary to process and deliver the shipment.
- The legal basis for processing and sharing this data is Article 6(1)(b) of the GDPR, as delivery is necessary to perform the sales agreement.
- Where an order is delivered outside the European Economic Area, information necessary for delivery and customs clearance may be provided to couriers, logistics providers, customs representatives, public authorities or other entities located in or serving the destination country.
9. Invoices, accounting and KSeF
- The Controller processes personal data to:
a) issue and store invoices and other accounting documents;
b) maintain tax and accounting records;
c) comply with reporting obligations;
d) transmit documents and data through the Polish National e-Invoicing System, known as KSeF;
e) comply with other tax and accounting obligations.
- The legal basis is Article 6(1)(c) of the GDPR, as processing is necessary to comply with legal obligations imposed on the Controller.
- Data may be processed by an external accounting and tax services provider working within the Controller’s systems and by providers of financial and accounting systems.
- Data may be disclosed to the Polish National Revenue Administration and other competent public authorities where required by applicable law.
- Accounting and tax records are retained for the periods required by applicable legislation.
10. Complaints, returns and legal claims
- Personal data included in a complaint, withdrawal notice, return request or another customer claim is processed to:
a) identify the customer and the relevant order;
b) examine and handle the request;
c) provide a response;
d) comply with consumer protection obligations;
e) issue a refund or receive returned products;
f) establish, exercise or defend legal claims.
- Depending on the nature of the matter, the legal basis may be:
a) Article 6(1)(b) of the GDPR – performance of the agreement;
b) Article 6(1)(c) of the GDPR – compliance with a legal obligation;
c) Article 6(1)(f) of the GDPR – the Controller’s legitimate interest in protecting its rights and handling claims.
- Data is retained until the matter is closed and subsequently for the applicable limitation period or for any longer period required by law.
11. Contact with the Store
- When a person contacts the Store by e-mail, telephone or through an online form, the Controller may process:
a) first name and surname;
b) e-mail address;
c) telephone number;
d) the content of the message;
e) other information voluntarily provided by the person contacting the Store.
- Where the message relates to a planned or existing order, the legal basis is Article 6(1)(b) of the GDPR.
- In other cases, the legal basis is Article 6(1)(f) of the GDPR, meaning the Controller’s legitimate interest in communicating with customers, responding to requests and providing customer service.
- Providing information is voluntary, although contact details may be necessary for the Controller to respond.
- Correspondence is retained until the matter has been completed and subsequently for a period justified by the nature of the matter and the possibility of related legal claims.
12. IT systems, security and technical logs
- Customer and order data may be processed in particular in:
a) the e-commerce platform;
b) the ERP system;
c) the WMS warehouse management system;
d) financial and accounting systems;
e) payment, delivery and communication systems;
f) backup and security systems.
- The Controller may process technical information including:
a) IP address;
b) browser information;
c) device and operating system information;
d) date and time of connection;
e) system events and errors;
f) session identifiers.
- Technical information is processed to:
a) ensure that the Store operates correctly;
b) maintain user sessions and shopping baskets;
c) protect the Store and its users;
d) detect errors, misuse and unauthorised access attempts;
e) create and restore backups;
f) investigate security incidents.
- The legal basis is Article 6(1)(f) of the GDPR, meaning the Controller’s legitimate interest in maintaining the security, availability and reliability of the Store.
- Technical logs are retained for the period necessary for those purposes, taking into account backup cycles and the time reasonably required to investigate incidents.
- Store forms may be protected using Google reCAPTCHA. The service is used to distinguish genuine human activity from automated attempts to misuse online forms.
- Processing necessary to protect the Store may be based on Article 6(1)(f) of the GDPR. Where the service requires non-essential cookies or similar technologies, they are activated in accordance with the user’s choices in the consent panel.
13. Analytics, advertising and remarketing
- After obtaining the appropriate consent, the Controller may:
a) analyse how the Store is used;
b) produce visitor statistics;
c) measure advertising performance;
d) display advertisements to persons who have previously visited the Store;
e) create advertising audiences;
f) analyse the customer journey leading to an order.
- For these purposes, the Store may use in particular:
a) Google Analytics 4;
b) Google Tag Manager;
c) Google Ads and conversion measurement tools;
d) Google remarketing functions;
e) Meta Pixel;
f) Meta remarketing functions;
g) Google Maps;
h) other services identified in the current Cookie Declaration.
- Depending on the consent given, the following information may be processed:
a) IP address;
b) cookie and device identifiers;
c) browser and operating system information;
d) approximate location;
e) the source from which the user accessed the Store;
f) visited pages and viewed products;
g) information about adding a product to the shopping basket;
h) information about starting checkout or completing a transaction;
i) information about interactions with advertisements.
- Processing for statistical, advertising and remarketing purposes is based on the user’s consent under Article 6(1)(a) of the GDPR and, where required, consent to store or access information on the user’s device.
- Consent is voluntary. Refusing consent does not prevent a customer from purchasing products, but it may prevent the Controller from producing complete statistics, measuring advertising performance or tailoring advertisements to the user’s interests.
- The user may change or withdraw consent at any time through the cookie settings panel.
- Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
- The Controller does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect a person.
- Advertising services may, however, create audience groups or interest profiles for the purpose of selecting advertisements.
14. Cookies and similar technologies
- The Store uses cookies and similar technologies, including:
a) online identifiers;
b) local browser storage;
c) tags;
d) pixels;
e) device identifiers.
- Cookies may be divided into the following categories:
a) necessary cookies – required for the proper operation of the Store, session management, shopping basket functions, login, security and storage of consent choices;
b) preference cookies – remember selected settings and help customise Store functions;
c) statistics cookies – allow the Controller to analyse how the Store is used;
d) marketing cookies – support campaign measurement, remarketing and personalised advertising.
- The Store uses Cookiebot to:
a) display information about cookies;
b) collect and record users’ choices;
c) block non-essential scripts until appropriate consent has been obtained;
d) allow consent to be changed or withdrawn;
e) display the current Cookie Declaration.
- A user may:
a) accept all cookies;
b) reject cookies other than necessary cookies;
c) select individual categories;
d) change or withdraw consent at a later time.
- The user’s consent choice is generally stored for 12 months, unless:
a) the user changes or withdraws consent earlier;
b) there is a material change to the cookie configuration;
c) consent must be obtained again;
d) the user deletes cookies from the device.
- Individual cookies may remain active for a shorter or longer period than the record of consent.
- Current information concerning cookie names, providers, purposes and retention periods is contained in the Cookie Declaration displayed by Cookiebot.
- The Store uses Google Consent Mode. This mechanism communicates the user’s consent choices to Google services and adjusts the operation of analytics and advertising tags accordingly.
- Users may also manage cookies through their browser settings. Blocking necessary cookies may, however, cause some Store functions to operate incorrectly.
15. Recipients of personal data
- Personal data may be disclosed to entities supporting the Controller in operating the Store, including:
a) e-commerce platform, hosting and technical infrastructure providers;
b) IT support, maintenance and security service providers;
c) ERP, WMS, financial and accounting system providers;
d) the external accounting and tax services provider;
e) payment providers, banks and card schemes;
f) couriers, logistics providers and customs representatives;
g) e-mail and communication service providers;
h) analytics, advertising, mapping, form-security and consent-management providers;
i) legal and tax advisers, auditors and insurers, where necessary;
j) public authorities, courts, tax authorities and law enforcement bodies, where disclosure is required by law.
- Processors acting on behalf of the Controller may use personal data only within the scope of their contracts and the Controller’s documented instructions.
- Certain recipients, particularly payment providers, couriers, Google and Meta services, may process personal data as independent controllers.
16. Transfers outside the European Economic Area
- The use of global service providers, including Google, Meta, payment services, security tools and infrastructure providers, may involve transferring personal data outside the European Economic Area or allowing access to data from such countries.
- Data may be transferred:
a) to a country for which the European Commission has adopted an adequacy decision;
b) to a US organisation participating in the EU–US Data Privacy Framework;
c) on the basis of standard contractual clauses approved by the European Commission;
d) under another mechanism permitted by Chapter V of the GDPR.
- Where required, additional technical, organisational or contractual safeguards are applied.
- A data subject may contact the Controller to obtain further information concerning the safeguards applied or a copy of the relevant transfer mechanism, subject to the protection of trade secrets and other confidential information.
17. Data retention
- The retention period depends on the purpose for which the data is processed:
a) Customer Account data – until the Account is deleted or the service is terminated, followed by the period necessary to protect against legal claims;
b) order data – for the duration of the agreement and subsequently for tax, accounting and limitation periods;
c) complaint and return information – until the matter is closed and subsequently for the applicable claims period;
d) accounting and tax records – for the period required by law;
e) correspondence – until the matter is completed and subsequently for a period justified by possible legal claims;
f) technical logs and security data – for the period necessary to protect the Store, detect errors and investigate incidents;
g) data processed on the basis of consent – until consent is withdrawn, the purpose is achieved or the relevant service’s retention period expires;
h) evidence of consent or withdrawal – for the period necessary to demonstrate compliance and defend potential claims.
- After the applicable period, personal data is deleted, anonymised or retained only to the extent required by law or necessary to protect legal claims.
18. Data subject rights
- Subject to the conditions set out in the GDPR, a data subject has the right to:
a) obtain access to personal data and receive a copy;
b) rectify inaccurate data;
c) complete incomplete data;
d) request erasure;
e) request restriction of processing;
f) receive and transmit data where processing is based on consent or a contract and is carried out by automated means;
g) object to processing based on the Controller’s legitimate interests;
h) withdraw consent at any time;
i) lodge a complaint with the President of the Polish Personal Data Protection Office or, where applicable, another competent supervisory authority in the European Union.
- An objection to processing for direct marketing purposes may be made at any time and does not require justification.
- Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- To exercise these rights, the data subject should contact the Controller:
a) by e-mail at: shop@enesmagnets.pl;
b) by post at the Controller’s registered office.
- Where necessary to protect personal data against unauthorised access, the Controller may request additional information to confirm the identity of the person making the request.
- Certain rights may be restricted where continued processing is required by law or necessary to establish, exercise or defend legal claims.
19. Changes to this Policy
- This Policy may be updated, in particular where:
a) applicable law changes;
b) the operation of the Store changes;
c) new providers or tools are introduced;
d) the purposes or methods of processing change.
- The current version of the Policy is published in the Store.
- This Policy takes effect on the date on which it is published in the Store.