1. General information
This policy applies to the website operating at the url address: https://lashesmania.com
The website operator and personal data administrator is: Mariusz Nowak Ogrodowa 167 33-300 Nowy Sącz
The operator's e-mail address is: [email protected]
The Operator is the Administrator of your personal data in relation to data provided voluntarily on the Website.
The website uses personal data for the following purposes:
Maintaining a newsletter
Preparation, packing and shipping of goods
Implementation of ordered services
The website performs the functions of obtaining information about users and their behavior in the following way:
By voluntarily entering data in forms that are entered into the Operator's systems.
By saving cookies on end devices (so-called "cookies").
2. Selected data protection methods used by the Operator
The places of logging in and entering personal data are protected in the transmission layer (SSL certificate). Thanks to this, personal data and login details entered on the website are encrypted on the user's computer and can only be read on the target server.
Personal data stored in the database are encrypted in such a way that only the Operator who has the key can read them. Thanks to this, the data is protected in case the database is stolen from the server.
User passwords are stored in hashed form. The hash function works in one direction - it is impossible to reverse its operation, which is currently the modern standard for storing user passwords.
The operator periodically changes its administrative passwords.
In order to protect data, the Operator regularly makes backup copies.
An important element of data protection is the regular updating of all software used by the Operator to process personal data, which in particular means regular updates of programming components.
The website is hosted (technically maintained) on the operator's servers: OVH.pl
4. Your rights and additional information about how your data is used
In some situations, the Administrator has the right to transfer your personal data to other recipients if it is necessary to perform the contract concluded with you or to fulfill the obligations imposed on the Administrator. This applies to the following target groups:
authorized employees and collaborators who use data to achieve the purpose of the website
Your personal data processed by the Administrator no longer than is necessary to perform related activities specified in separate regulations (e.g. accounting). With respect to marketing data, data will not be processed for longer than 3 years.
You have the right to request from the Administrator:
access to personal data relating to you,
and data transfer.
You have the right to object to the processing indicated in point 3.3 c) to the processing of personal data for the purpose of pursuing legally justified interests pursued by the Administrator, including profiling, but the right to object will not be possible if there are valid legally justified grounds for processing, interests, rights and freedoms that override you, in particular the establishment, exercise or defense of claims.
You may lodge a complaint against the Administrator's actions to the President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw.
Providing personal data is voluntary, but necessary to operate the Website.
Activities involving automated decision-making may be undertaken in relation to you, including profiling, in order to provide services under the concluded contract and for the purpose of conducting direct marketing by the Administrator.
Personal data is not transferred from third countries within the meaning of personal data protection regulations. This means that we do not send them outside the European Union.
5. Information in forms
The website collects information provided voluntarily by the user, including personal data, if provided.
The website may save information about connection parameters (time stamp, IP address).
In some cases, the website may save information that makes it easier to link the data in the form with the e-mail address of the user completing the form. In this case, the user's e-mail address appears inside the URL of the page containing the form.
The data provided in the form is processed for the purpose resulting from the function of a specific form, e.g. to process a service request or commercial contact, register services, etc. Each time, the context and description of the form in a clear way