Polityka prywatności
1. Data controller and definitions
1. The data controller of the data of Customers/Users of the Online Shop, also referred to as the Seller, is: POLSKI INSTYTUT SPRAW MIĘDZYNARODOWYCH, telephone No.: 532475492, NIP [tax identification number]: 5252167765, REGON [statistical identification number]: 016274699.
2. The Data Controller can be contacted at:
1. the mailing address: WARECKA 1A, 00-950 WARSZAWA;
2. the e-mail address: iodo@pism.pl.
3. User – a natural person accessing the website(s) of the Online Shop or using the services or functionalities described in this Privacy Policy and Cookie Policy.
4. Customer – a natural person having full legal capacity to perform acts in law, a natural person who is a Consumer, a legal person or an organizational unit without legal personality, to which the Act grants legal capacity, which concludes a Distance Selling Agreement with the Seller.
5. Online Shop – a website operated by the Seller, available at electronic addresses (websites): https://eksiegarnia.pism.pl through which the Customer/User may obtain information about the Goods and availability of the Goods and buy the Goods or order the service.
6. Newsletter – information, including commercial communications within the meaning of the Act of 18 July 2002 on the provision of services by electronic means (Journal of Laws [Dz. U.] of 2020, item 344) from the Seller, sent to the Customer/User by electronic means; receipt of the newsletter is voluntary and requires the consent of the Customer/Use.
7. Account - a set of data stored in the Online Shop and in the Seller's ICT system, concerning the Customer/User and orders placed by the Customer/User and agreements concluded, which enables the Customer/User to place orders and conclude agreements.
8. GDRP – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the General Data Protection Regulation).
2. . Purposes, legal basis and duration of the processing
1. In order to perform the Distance Selling Agreement, the Seller processes:
1. information concerning the User's device in order to ensure the correct functioning of the services: IP address of the computer, information contained in cookies or other similar technologies, session data, web browser data, device data, data concerning activity on the Website, including on individual subpages;
2. geolocation data, if the User has consented to the service provider's access to geolocation. The geolocation data are used to provide more tailored offers of products and services;
3. Users’ personal data: name, surname, registered office address, correspondence address, e-mail address, telephone number, Tax Identification Number (NIP), bank account number, or other personal data required by the Controller in the purchasing process.
2. This information does not contain identity data of the Users, but in combination with other information may constitute personal data, and therefore the Data Controller extends full GDPR protection to such information.
3. Such data are processed in accordance with Article 6.1(b) of the GDPR, for the purpose of providing a service, i.e. an agreement for the provision of services by electronic means in accordance with the Regulation, and in accordance with Article 6.1(a) of the GDPR, in accordance with consenting to the use of certain cookies or other similar technologies, as expressed by the appropriate settings of the Internet browser, in accordance with the Electronic Communication Law or in accordance with consenting to geolocation. The data are processed until the end of the Customer’s/User's use of the Online Shop.
4. The Controller undertakes to take all measures required under Article 32 of the GDPR, i.e., taking into account the state of the art, the costs of implementation and the nature, scope, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Controller shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
3. Marketing activities of the data controller
1. The Data Controller may place marking information about its products or services on the website of the Online Shop. Such content shall be displayed by the Data Controller in accordance with Article 6.1(f) of the GDPR, in accordance with the legitimate interest pursued by the Data Controller, consisting in publishing the content related to the services provided and the promotional content of the campaigns in which the Data Controller is involved. At the same time, such action does not infringe the rights and freedoms of the Customers/Users, the Customers/Users expect to receive similar content, or event look forward to it, or it is their direct purpose of visiting the website(s) of the Online Shop.
4. Recipients of Users’ data
1. The Data Controller discloses the Users' personal data only to the processors under the concluded contracts for the processing of personal data, for the purpose of providing services to the Data Controller, e.g. hosting and maintenance of the website, IT services, marketing and PR services.
5. Transfer of personal data to third countries
1. Personal data will not be processed in third countries.
6. Rights for the data subjects
1. Every data subject has the right:
1. of access (Article 15 of the GDPR) – to obtain from the Data Controller confirmation as to whether or not personal data concerning him or her are being processed. Where the data concerning the person are processed, he or she is entitled to access to the personal data and to obtain the following information: about the purposes of the processing, the categories of personal data, the recipients or categories of recipients to whom the personal data have been or will be disclosed, about the period of data storage or about the criteria used to determine that period, about the right to request rectification, erasure or restriction of processing of personal data and to object to such processing;
2. to obtain a copy of the data (Article 15.3 of the GDPR) – to obtain a copy of the data to be processed; the first copy being free of charge, and for further copies the Data Controller may charge a reasonable fee based on administrative costs;
3. to rectification (Article 16 of the GDPR) - to request the rectification of inaccurate or to supplement incomplete data concerning him or her;
4. to erase the data (Article 17 of the GDPR) – to request the erasure of his/her personal data if the Data Controller has no longer a legal basis for the processing or the data are no longer necessary for the purposes of processing;
5. to restriction of processing (Article 18 of the GDPR) – to request restriction of processing of personal data where:
1. the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data,
2. the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead,
3. the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims,
4. the data subject has objected to processing pursuant to Article 21.1 pending the verification whether the legitimate grounds of the controller override those of the data subject;
6. to data portability (Article 20 GDPR) – to receive the personal data concerning him or her, which he or she has provided to a data controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the data controller to which the personal data have been provided, where data are processed on the basis of the data subject's consent or on a contract with him/her and where data are processed by automated means;
7. to object (Article 21 of the GDPR) - to object to the processing of his/her personal data for the legitimate purposes of the controller, on grounds related to his/her specific situation, including profiling. In such case, the Data Controller shall assess the existence of important legitimate grounds for processing overriding the interests, rights and freedoms of data subjects or grounds for establishing, pursuing or defending claims. If according to the assessment the interests of the data subject take precedence over the interests of the controller, the Data Controller shall be obliged to stop processing the data for those purposes;
8. to withdraw consent at any time and without giving any reason, but the processing of personal data carried out before withdrawal of consent will still remain lawful. Withdrawal of consent shall result in the Data Controller ceasing to process personal data for the purpose for which the consent was given.
2. In order to exercise the aforementioned rights, the data subject should contact the Data Controller, using the contact details provided and inform the Data Controller which right and to what extent he/she wants to exercise.
7. President of the Personal Data Protection Office
1. The data subject has the right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office [Prezes Urzędu Ochrony Danych Osobowych], with its registered office in Warsaw, ul. Stawki 2, who can be contacted as follows:
2. by letter at: ul. Stawki 2, 00-193 Warszawa;
3. via the electronic mailbox available at: https://www.uodo.gov.pl/pl/p/kontakt;
4. Helpline: 606-950-000.
8. Data Protection Officer
1. In each case, the data subject may also contact the data protection officer of the Data Controller directly by e-mail or in writing to the address of the Data Controller stated in section 1 paragraph 2 of this Privacy Policy and Cookie Policy.
9. Amendments to the Privacy Policy
1. The Privacy Policy and Cookie Policy may be supplemented or updated according to the Data Controller’s current needs in order to provide up-to-date and reliable information to Customers/Users.
10. Cookies
1. The Online Shop performs the functions of obtaining information about Customers, Users and their behaviour in the following way:
1. by information voluntarily entered on the forms, for purposes arising from the function of the form;
2. by saving cookies in terminal devices;
3. by collecting web server logs by the Online Shop’s hosting operator (necessary for proper operation of the Online Shop).
2. Cookies are IT data, in particular text files, which are stored in the Customer's/ User's terminal device and are designed to use the Online Shop’ s website. Cookies usually contain the name of the website from which they come, the duration of storing them on the terminal device, and a unique number.
3. The Online Shop uses cookies only after the Customer/User has given his/her prior consent in this regard. Consent to the use of all cookies by the Online Shop is given by clicking the button: "Close" when the notice about the use of cookies by the Online Shop is displayed or by closing that notice.
4. If the Customer/User does not agree to the use of cookies by the Online Shop, he/she may use the option: "I do not agree", which is also available in the notice about the use of cookies by the Online Shop or make changes to the settings of the Internet browser, which is currently used by the Customer/User (however, this may cause incorrect operation of the Online Shop).
5. In order to manage the cookie settings, the Customer/User should select web browser/system from the list and follow the instructions: Internet Explorer, Chrome, Safari, Firefox, Opera, Android, Safari (iOS), Windows Phone.
6. The legal basis for the processing of personal data from cookies is the legitimate interests pursued by the Data Controller, consisting in providing high quality services, ensuring the safety of services.
7. The Online Shop uses two basic types of cookies: session cookies and persistent cookies. Session cookies are temporary files, which are stored in the User's terminal device until logging out, leaving the Online Shop or switching off the software (web browser). Persistent cookies are stored in a User's device for the time specified in the parameters of cookies or until their removal by the Customer/User.
Functional cookies (required)
eksiegarnia.pism.pl
monit_token: 365 days, cookie
Identifies the shop’s customer.
shop_monit_token: 30 minutes, cookie
Identifies the shop’s customer.
client: 1 day, cookie
Identifies a logged-in customer / shopping cart of a non-logged-in customer.
affiliate: 90 days, cookie
It stores information about the referral partner ID.
ordersDocuments: cookie
Stores information about the document print status.
__idsui: 1095 days, cookie
A file necessary for the so-called lightweight login function on the website.
__idsual: 1095 days, cookie
A file necessary for the so-called lightweight login function on the website.
__IAI_SRC: 90 days, cookie
It only stores the source from which the page was accessed.
login: cookie
Stores information about whether the user has logged in to the site.
CPA: 28 days, cookie
Contains information about the variables for the CPA / CPS programmes in which the site participates.
__IAIRSABTVARIANT__: 30 days, cookie
Variant identifier for the A/B test and IdoSell RS engine configurator.
basket_id: 365 days, cookie
The site user’s shopping cart identifier, assigned for the duration of the ongoing session.
page_counter: 1 days, cookie
Counter of pages visited.
LANGID: 180 days, cookie
Stores information about the language selected by the site user.
REGID: 180 days, cookie
Stores information about the site user’s region.
CURRID: 180 days, cookie
Stores information about the currency selected by the site user.
__IAIABT__: 30 days, cookie
Stores the A/B test identifier, for the purpose of testing and improving the shop functionalities.
__IAIABTSHOP__: 30 days, cookie
Stores the identifier of the shop participating in the A/B test.
__IAIABTVARIANT__: 30 days, cookie
Stores the identifier of the variant drawn as part of the ongoing A/B test.
toplayerwidgetcounter[]: cookie
Stores the number of times a pop up message has been displayed.
samedayZipcode: 90 days, cookie
Stores information about the site user’s postcode which is necessary to offer courier delivery in the SameDay service.
applePayAvailability: 30 days, cookie
Stores information about whether the ApplePay payment method is available for the user.
paypalMerchant: 1 days, cookie
PayPal account ID.
toplayerNextShowTime_: cookie
Stores information about the time when the next pop up message is to be displayed.
rabateCode_clicked: 1 days, cookie
Stores information about closing the active discount bar.
freeeshipping_clicked: 1 days, cookie
Stores information about closing the free delivery bar.
redirection: cookie
Stores information about closing the pop-up message informing about the suggested language for the shop.
filterHidden: 365 days, cookie
After the option to collapse the filter for goods is clicked, it saves which filter is to be collapsed when the goods list is refreshed.
toplayerwidgetcounterclosedX_: cookie
Stores information about closing a pop-up message.
cpa_currency: 60 minutes, cookie
Contains currency information for CPA / CPS programmes in which the site participates.
basket_products_count: cookie
Stores information about the number of goods in the shopping cart.
wishes_products_count: cookie
Stores information about the number of goods in the favourites list.
remembered_mfa: 365 days, cookie
Stores remembered user information for multi-factor authentication (MFA)
HOMELANDID: 180 days, cookie
Stores information about the visitor’s country.
IAI S.A.
iai_accounts_toplayer: 30 days, cookie
Ensures the correct display of the pop up message informing about the IdoAccounts login service (https://www.idosell.com/pl/tysiace-gotowych-do-uzycia-funkcji/logowanie-do-sklepu-z-konta-w-innym-serwisie/).
IdoSell
platform_id: cookie
Stores information about whether the page is displayed in a mobile application.
paypalAvailability_: 1 days, cookie
Stores information about whether a PayPal method is available for the user.
ck_cook: 3 days, cookie
Stores information about whether the user has agreed to cookies.
IdoAccounts
accounts_terms: 365 days, cookie
Stores information about whether the user has accepted consent to use the IdoAccounts service.
express_checkout_login: 365 days, cookie
CookieNameExpressCheckoutLogin
Google
NID: 180 days, cookie
Those cookie (NID, ENID) are used to remember the user’s preferences and other information, such as the user’s preferred language, the number of results displayed on the search results page (for example 10 or 20) and whether the user wants to have the Google SafeSearch filter turned on. This cookie is also necessary to offer the Google Pay payment service.
Google reCAPTCHA
_GRECAPTCHA: 1095 days, cookie
This cookie is set by Google reCAPTCHA, which protects our site against spam enquiries on contact forms.
PayPal
ts: cookie
This cookie is generally provided by PayPal and supports payment services on the website.
ts_c: 1095 days, cookie
This cookie is generally provided by PayPal and is used to prevent fraud.
x-pp-s: cookie
This cookie is generally provided by PayPal and supports payment services on the website.
enforce_policy: 365 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
tsrce: 3 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
l7_az: 60 minutes, cookie
Ten cookie is necessary for the PayPal login function on the website.
LANG: 1 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
nsid: cookie
Used in the context of transactions on the Website. The cookie is required for secure transactions.
Analytics cookies
IAI S.A.
__IAI_AC2: 45 days, cookie
Activity Tracking identifier used to collect the history of pre-order sources, as well as the source through which the order was placed according to the last click attribution model.
Google Maps
SID: 3650 days, cookie
Contain digitally signed and encrypted records of a user’s Google account ID and the most recent sign-in time. The combination of those cookies (SID, HSID) allows Google to block many types of attacks, such as attempts to steal the content of forms submitted in Google services.
Advertising cookie
eksiegarnia.pism.pl
RSSID: 180 days, cookie
IdoSell RS user ID, used for the purpose of displaying tailored product recommendations on the website.
__IAIRSUSER__: 60 minutes, cookie
IdoSell RS user ID, used for the purpose of displaying tailored product recommendations on the website.
8. The cookies are used for the following purpose:
1. to create statistics that help to understand how Customers/Users of the Online Shop use the websites, which allows to improve their structure and content;
2. to maintain the Customer’s/User’s session (after logging in), thanks to which the Customer/User does not have to re-enter the login and password on each subpage of the Online Shop;
3. to define the Customer's/User’s profile in order to display product recommendations and matching materials in advertising networks, in particular the Google network.
9. Software for web browsing (web browser) usually by default allows for storing cookies in the Customer’s/User's terminal device. Customers/Users may change their settings in this regard. A web browser allows to remove cookies. It is also possible to automatically block cookies.
10. Restrictions on the use of cookies may affect some of the functionalities available on the Online Shop's websites.
11. Cookies placed in the Customer’s/User's terminal device and may also be used by Online Shop’s advertisers and partners, cooperating with the Online Shop.
12. Cookies may be used by the Google network to display advertisements tailored to the way the Customer/User uses the Online Shop. For this purpose, they can store information about the user's navigation path or time spent on a given page: https://policies.google.com/technologies/partner-sites.
13. We recommend that the Customer/User should read these companies' privacy policies in order to understand the cookies’ usage in the statistics: Privacy Policy - Google Analytic.
14. In terms of information about the Customer’s/ User's preferences collected by the Google's advertising network, the Customer/User can view and edit the information resulting from cookies using the tool: https://www.google.com/ads/preferences/.
15. On the website of the OnlineShop there are plug-ins, which can transfer the data of Customers/Users to the data controllers, such as e.g.: Google Maps, PayPal, Google reCAPTCHA, IdoAccounts, IdoSell, IAI S.A., Google.
16. In order to perform the Distance Selling Agreement properly, the Data Controller may make the Customer/User data available to courier entities. The delivery methods currently available in the Online Shop are available at: https://eksiegarnia.pism.pl/pl/delivery.html.
17. In order to perform the Distance Selling Agreement properly, the Data Controller may make the Customer/User data available to online payment systems. The methods of payment in the form of prepayment currently available in the Online Shop are available at: https://eksiegarnia.pism.pl/pl/payments.html.
18. More information on terms and conditions and privacy can also be found on the Google’s Privacy and Terms page.
11. Newsletter
1. The Customer may give his/her consent to receive commercial communications electronically by ticking the appropriate option in the registration form or at a later date in the appropriate tab. In the case of such consent, the Customer/User will receive communications (Newsletter) of the Online Shop as well as other commercial communications sent by the Seller to the Customer’s/User’s email address.
2. The Customer may unsubscribe from the Newsletter any time by unchecking the appropriate box on his/her Account page or by going to the https://eksiegarnia.pism.pl/pl/newsletter.html form, clicking the appropriate link in the content of each Newsletter, or thought the Customer Service Office.
12. Account
1. The Client/User must not place in the Online Shop or provide the Seller with content, including opinions and other data, of an illegal nature.
2. The Customer/User gets access to the Account after registration.
3. When registering, the Customer/User provides the account type or gender, name, surname, company name, NIP number, data for issuing a sales document, shipping data, e-mail address, and chooses a password. The Customer/User assures that the data provided by him/her in the registration form are correct. Registration requires that Customer/User read the Regulations carefully and mark on the registration form that he/she has read the Regulations and fully accepts all provisions thereof.
4. At the moment of granting the Customer/User access to the Account, an agreement for the provision of services by electronic means is concluded between the Seller and the Customer/User for an indefinite period of time. The Consumer may rescind this agreement on the terms specified in the Regulations.
5. Registration of an Account on one of the sites of the Online Shop means at the same time registration allowing access to other sites where the Online Shop is available.
6. The Customer/User may terminate the agreement for the provision of services by electronic means any time with immediate effect, informing the Seller about it by e-mail or in writing to the address of the Data Controller given in section 1 paragraph 2 of this Privacy Policy and Cookie Policy.
7. The Seller has the right to terminate the agreement for the provision of services concerning the Account in the event of: cessation or transfer of the Online Shop service to a third party, violation by the Customer/User of the law or provisions of the Regulations, as well as in the event of inactivity of the Customer/User for a period of 6 months. The agreement is terminated with seven-day notice. The Seller may stipulate that re-registration of the Account shall require the Seller's permission.