2. Personal data collected by Assam Aromas via the Online Store are processed in accordance with the Regulations
3. Assam Aromas makes special care to respect the privacy of customers visiting the Online Store.
§ 1 Type of data to be processed, objectives and legal basis
1. Assam Aromas collects information on natural persons conducting legal transactions not directly related to their business, natural persons conducting business or professional activity on their own behalf and natural persons representing legal persons or organizational units that are not legal entities, which the Act grants legal capacity, conducting business or professional activity on their own behalf, hereinafter referred to jointly as Clients.
2. Customers' personal data is collected in the case of:
a) account registration in the Online Store, in order to create an individual account and manage this account. Legal basis: indispensability to perform the contract for the provision of the Account service (Article 6 (1) (b) of the GDPR);
b) place an order in the Online Store in order to perform a sales contract. Legal basis: indispensability to perform a sales contract (Article 6 (1) (b) of the GDPR);
c) subscribing to the newsletter (Newsletter), in order to perform the contract, the subject of which is the service provided electronically. Legal basis - consent of the data subject to perform the contract for the provision of the Newsletter service.
3. In the case of registering an account in the Online Store, the Customer provides:
a) e-mail address;
b) name and surname.
4. When registering an account in the Online Store, the Customer sets the individual password for access to his account. The customer can change the password at a later time, on the terms described in §5.
5. In the case of placing an order in the Online Store, the Customer provides the following data:
a) e-mail address;
b) address data:
a. zip code and town;
b. street with the house / flat number;
c) name and surname;
d) telephone number.
6. In the case of Entrepreneurs, the above data scope is additionally extended by:
a) the Entrepreneur's company;
b) Passport or national ID number
7. If you use the Newsletter service, the customer only provides his e-mail address.
8. When using the Online Store Website, additional information may be downloaded, in particular: the IP address assigned to the Client's computer or the external IP address of the Internet provider, domain name, browser type, access time, type of operating system.
9. Navigational data may also be collected from customers, including information about links and links in which they decide to click or other activities undertaken in our Online Store. Legal basis - a legitimate interest, consisting in facilitating the use of services provided electronically and improving the functionality of these services.
10. In order to determine, investigate and enforce claims, some personal data provided by the Customer may be processed as part of using the functionality in the Online Store, such as: name, surname, data on the use of services, if claims result from the manner in which the customer uses from services, other data necessary to prove the existence of the claim, including the extent of the damage suffered. Legal basis - a legitimate interest, consisting in determining, pursuing and enforcing claims and defending against claims in proceedings before courts and other state authorities.
11. The transfer of personal data to Assam Aromas is voluntary, in connection with concluded sales contracts or provision of services via the Shop Website, with the reservation that failure to specify in the data forms in the Registration process prevents registration and establishment of the Customer Account, and in If you place an order without registering your customer account, you will not be able to place and process your order.
§ 2 To whom data is shared or entrusted, and for how long it is stored
. 1. The client's personal data is provided to service providers used by Assam Aroma while running the Online Store. Service providers to whom personal data are transferred, depending on contractual arrangements and circumstances, or are subject to Assam Aroma’s instructions as to the purposes and methods of data processing (processors) or independently determine the purposes and means of processing them (administrators).
a) Processors. Assam Aroma uses suppliers who process personal data only at Assam Aroma's request. These include providers providing hosting services, accounting services, providing marketing systems, systems for analyzing traffic in the Online Store, systems for analyzing the effectiveness of marketing campaigns;
b) Administrators. Assam Aroma uses suppliers who do not act solely on the instructions and set the goals and methods of using personal data of clients. They provide electronic and bank payment services.
2. Location. Service providers are based mainly in Indian and Poland and most of international shipping will be done via Poland.
3. Customers' personal data are stored:
a) If the basis for the processing of personal data is consent then the personal data of the customer are processed by Assam Aroma until the consent is canceled, and after the cancellation of the consent for a period of time corresponding to the period of limitation claims Assam Aroma can raise that can be raised against him . Unless a special provision provides otherwise, the period of limitation is six years, and for claims for periodic benefits and claims related to running a business - three years.
4. In the event of purchase in the Online Store, personal data may be transferred, depending on the choice of the Customer, to the following entities to deliver the ordered goods:
a) courier company;
b) Poczta Polska SA with its registered office in Warsaw.
5. In the event that the Customer chooses to pay via PayPal, his personal data is transferred to the extent necessary for the payment to PayPal (Europe) S.à rl & Cie, SCA based in Luxembourg.
6. The navigation data can be used to provide customers with better service, analysis of statistical data and adaptation of the Online Store to the preferences of customers, as well as the administration of the Online Store.
7. If the Customer subscribes to the newsletter (Newsletter) at his e-mail address, Assam Aroma will send electronic messages containing commercial information about promotions and new products available in the Online Store.
9. In the case of a request, Assam Aroma provides personal data to authorized state bodies, in particular to the organizational units of the Prosecutor's Office, the Police, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
§ 3 Cookie mechanism, IP address
1. The Online Store uses small files called cookies. They are saved by Assam Aroma on the end device of the person visiting the Online Store, if the web browser allows it. A cookie file usually contains the name of the domain it originates from, its "expiration time" and an individual, randomly selected number identifying this file. The information collected by means of such files help to adapt products offered by Assam Aroma to individual preferences and real needs of people visiting the Online Store. They also provide the opportunity to develop general statistics of visits to the presented products in the Online Store.
2. Assam Aroma uses two types of cookies:
a) Session cookies: after completing a session of a given browser or turning off the computer, stored information is removed from the device's memory. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from the Clients' computers.
b) Persistent cookies: they are stored in the memory of the Customer's end device and remain there until they are deleted or expired. The mechanism of persistent cookies does not allow the collection of any personal data or any confidential information from the client's computer.
3. Assam Aroma uses own cookies in order to:
a) authentication of the Customer in the Online Store and ensuring Customer's session in the Online Store (after logging in), thanks to which the Customer does not have to enter the login and password on each subpage of the Online Store;
b) analysis and research and audience audits, and in particular to create anonymous statistics that help to understand how customers use the Store Website, which allows improving its structure and content.
4. Assam Aroma uses external cookies to:
a) popularize the Online Store using the social network service pinterest.com (administrator of external cookies: Pinterest, Inc. with its registered office in the USA);
b) popularizing the Store by means of the social website twitter.com (administrator of external cookies: Twitter Inc. based in the USA);
c) collecting general and anonymous static data via analytical tools of Google Analytics (administrator of external cookies: Google Inc with its registered office in the USA);
5. The cookie mechanism is safe for the Customers of the Online Store. In particular, this way it is not possible to get viruses or other unwanted software or malicious software onto your computer. However, in their browsers, Customers have the option of limiting or disabling access to cookies on their computers. If you use this option, the use of the Online Store will be possible, in addition to the functions which, by their nature, require cookies.
a) Internet Explorer;
b) Microsoft EDGE browser;
c) Mozilla Firefox browser;
d) Chrome browser;
e) Safari browser;
f) Opera browser.
7. Assam Aroma can collect customer IP addresses. An IP address is a number assigned to the computer of the visitor of the Online Store by the ISP. The IP number allows access to the Internet. In most cases, it is assigned to the computer dynamically, i.e. it changes every time you connect to the Internet. The IP address is used by Assam Aroma in diagnosing technical problems with the server, creating statistical analyzes (eg determining in which regions we note the most visits), as information useful in the administration and improvement of the Online Store, as well as for security purposes and possible identification of those charging the server, unwanted automated programs to browse the contents of the Online Store.
8. The Online Store contains links and links to other websites. Assam Aroma is not responsible for the privacy practices applicable to them.
§ 4 Rights of data subjects
1. Right to withdraw consent - legal basis: art. 7 par. 3 RHODE.
a) The customer has the right to withdraw any consent given by Assam Aroma.
b) Withdrawal of consent has effect since the withdrawal of consent.
c) Withdrawal of consent does not affect the processing carried out by Assam Aroma in accordance with the law before its withdrawal.
d) Withdrawal of consent does not entail any negative consequences for the customer, but it may prevent further use of services or functionality which, according to the Assam Aroma law, can only be provided with consent.
2. Right to object to data processing - legal basis: art. 21 THE RHODE.
a) The customer has the right to object at any time - for reasons related to his specific situation - to the processing of his personal data, including profiling, if Assam Aroma processes his data based on a legitimate interest, e.g. marketing of Assam Aroma products and services, statistics on the use of individual functionalities of the Online Store and facilitating the use of the Online Store, as well as a satisfaction survey.
b) Opting out in the form of an e-mail from receiving marketing messages concerning products or services will mean the Customer's objection to the processing of his personal data, including profiling for these purposes.
c) If the customer's objection proves to be justified and Assam Aroma has no other legal basis for the processing of personal data, the client's personal data will be deleted, the client has objected to the processing.
3. The right to delete data ("the right to be forgotten") - the legal basis: art. 17 THE RHODE.
a) The customer has the right to request the removal of all or some personal data.
b) The customer has the right to request the deletion of personal data if:
a. the personal data are no longer necessary for the purposes for which they were collected or processed;
b. withdrew a specific consent to the extent to which personal data were processed based on his consent;
C. he objected to the use of his data for marketing purposes;
D. personal data are processed unlawfully;
E. personal data must be removed in order to comply with a legal obligation under Union law or the law of the Member State to which Assam Aroma is subject;
F. personal data have been collected in connection with the offering of information society services.
c) Despite the request to delete personal data, in connection with opposition or withdrawal of consent, Assam Aroma may retain certain personal data to the extent that processing is necessary to establish, assert or defend claims, as well as to fulfill a legal obligation requiring processing Union law or the law of the Member State to which Assam Aroma is subject. This applies in particular to personal data including: name, surname, email address, which data is preserved for the purpose of handling complaints and claims related to the use of Assam Aroma services, or additionally the address of residence / mailing address, order number, which data they are kept for the purpose of handling complaints and claims related to concluded sales agreements or provision of services.
4. The right to limit data processing - legal basis
a) The customer has the right to demand the restriction of the processing of his personal data. Submission of a request, until its consideration prevents the use of certain functionalities or services, the use of which will involve the processing of data covered by the request. Assam Aroma will also not send any messages, including marketing messages.
b) The customer has the right to demand limitation of the use of personal data in the following cases:
a. when he challenges the accuracy of his personal data - then Assam Aroma limits their use for the time needed to verify the correctness of data, but no longer than for 7 days;
b. when data processing is unlawful, and instead of deleting data, the Customer will demand restriction of their use;
c. where personal information is no longer necessary for the purposes for which it was collected or used but is needed by the Customer to establish, assert or defend claims;
d. when he objected to the use of his data - then the restriction occurs for the time needed to consider whether - due to the special situation - protection of the client's interests, rights and freedoms outweighs the interests that the Administrator performs while processing the client's personal data.
§ 5 Security Management - Password (Incase it adds account management)
1. Assam Aroma provides Clients with a secure and encrypted connection when transferring personal data and when logging in to the Customer Account on the Website. Assam Aroma uses an SSL certificate issued by one of the world's leading companies in the field of security and encryption of data transmitted via the Internet.
2. In the event that the Customer who has an account in the Online Store has lost any access password in any way, the Online Store allows you to generate a new password. Assam Aroma does not send a password reminder. The password is stored in an encrypted form in a way that prevents its reading. To generate a new password, please enter your e-mail address in the form available under the link "Forgot your password" provided at the login form for the account in the Online Store. The customer to the e-mail address provided during registration or saved in the last change of the account profile will receive an e-mail containing a redirection to a dedicated form provided on the Shop Website, where the customer will be able to set a new password.
3. Assam Aroma never sends any correspondence, including electronic correspondence, with a request to provide login details, in particular an access password to the Customer's account.
a) The Customer has the right to obtain from the Administrator confirmation whether he processes personal data, and if this is the case, the Customer has the right to:
a. gain access to his personal data;
b. obtain information about the purposes of processing, categories of personal data being processed, the recipients or categories of recipients of such data, planned
3. Date of last modification: 01/07/2019 .