Privacy Policy of the Lionelo Website
The controller of your personal data placed on the Lionelo website (hereinafter also referred to as: the Website) is BrandLine Group sp. z o.o., with its registered office in Poznań, ul. Adama Kręglewskiego 1, 61-248 Poznań, entered in the National Court Register under KRS number: 0000552768, NIP: 7822579840, REGON: 361233546, BDO: 000008493, with a share capital of PLN 24,800.00 (hereinafter also referred to as: BrandLine or the Controller).
The purpose of this Privacy Policy is to define the actions taken by BrandLine Group sp. z o.o. regarding the protection of personal data and the scope and legal basis for their processing. All activities of BrandLine are subject to the GDPR and the Act of 10 May 2018 on the protection of personal data.
For all matters related to the protection of personal data, you may contact the Controller:
- by post to: ul. Adama Kręglewskiego 1, 61-248 Poznań
- electronically to: daneosobowe@brandlinegroup.com
- by phone: +48 612 222 980
1. Controller of Personal Data
- processed lawfully, fairly and in a transparent manner,
- collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes,
- adequate, relevant and limited to what is necessary for the purposes for which they are processed – the principle of data minimisation applies,
- accurate and, where necessary, kept up to date,
- stored in a form which permits identification of the data subject for no longer than is necessary for the purposes for which the personal data are processed,
- processed in a manner that ensures appropriate security of personal data: the Controller provides protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures. The Controller ensures a secure and encrypted connection when transmitting personal data on the Website. The Website pages are secured with an SSL certificate.
The Controller takes all necessary steps to ensure that its subcontractors and other cooperating entities guarantee the application of appropriate security measures in every case where they process Personal Data on behalf of the Controller.
2. Processing of Data in Connection with the Use of the Website
- Users (all persons using the Website);
- Customers (persons making purchases on the Website, whether registered or not holding an account on the Website);
- Persons contacting the Controller via tools made available on the Website, i.e.:
- using internet communicators such as Messenger and WhatsApp,
- using the contact form,
- by phone,
- using the live chat function,
- Newsletter recipients.
3. Purposes, Legal Basis and Period of Data Processing
- pursuant to Article 6(1)(b) GDPR, where processing is necessary for the performance of the sales contract in accordance with the Store's Terms and Conditions;
- pursuant to Article 6(1)(c) GDPR, where processing is necessary to fulfil the legal obligation incumbent on the Controller, in connection with the Act of 30 May 2014 on consumer rights, the Act of 18 July 2002 on the provision of electronic services, the Act of 29 September 1994 on accounting, and other accounting and tax regulations;
Personal Data will be processed for the period necessary for the performance of the sales contract, extended by the warranty period and the statute of limitations for potential claims. Providing the data indicated as mandatory is required in order to accept and process the order.
- pursuant to Article 6(1)(b) GDPR;
- pursuant to Article 6(1)(c) GDPR, in connection with the Act of 30 May 2014 on consumer rights, the Act of 23 April 1964 Civil Code;
- pursuant to Article 6(1)(f) GDPR;
Personal Data will be processed for the period necessary for the performance of the sales contract, extended by the warranty period and the statute of limitations.
- pursuant to Article 6(1)(b) GDPR;
- pursuant to Article 6(1)(c) GDPR, in connection with the Act of 30 May 2014 on consumer rights, the Act of 23 April 1964 Civil Code, the Act of 29 September 1994 on accounting, and other accounting and tax regulations;
- pursuant to Article 6(1)(f) GDPR;
Personal Data will be processed for the duration of the service provided under the Lionelo Protect Programme. Providing the data indicated as mandatory is required in order to participate in the Programme.
4. Recipients of Data
4.1. Your Personal Data may be transferred to third parties whose services the Controller uses in connection with the operation of the Website, the provision of electronic services, and the sale of goods, including in particular:
- entities providing IT services and IT system suppliers,
- postal operators,
- carriers,
- logistics companies,
- entities handling payment transactions,
- entities providing warehousing services,
- entities providing marketing services,
- entities providing goods distribution services,
- entities providing server colocation services,
- law firms,
- entities providing advisory and audit services,
- companies providing maintenance services (in connection with complaint reports),
- authorised entities upon a documented request,
4.2. Additionally, for the purpose of using Google and YouTube tools, Personal Data may be transferred outside the EEA, including to Google LLC. For the purpose of using Facebook tools, Personal Data may be transferred to the United States (Meta Platforms Inc.). The transfer takes place pursuant to Article 46 GDPR. For the purpose of using the Czater.pl tool, Personal Data may be transferred outside the EEA. Czater.pl uses standard contractual clauses approved by the European Commission.
4.3. The Website also features social media plug-ins and chats. The purposes and scope of data collection and their further processing and use by service providers are described in the privacy policies listed below:
Facebook – Meta Privacy Policy
YouTube – YouTube Privacy Guidelines
Instagram – Meta Privacy Policy
LinkedIn – LinkedIn Privacy Policy
WhatsApp – Privacy Policy – EEA
Czater.pl – Polityka Prywatności (czater.pl)
5. Your Rights
Providing Personal Data is always voluntary; however, failure to provide data indicated as mandatory will make it impossible to use the services provided via the Website. Each of you whose Personal Data is processed by the Controller has the right to:
- 5.1. Right of access to data – this means that you may request BrandLine to provide information on whether and what data we process as the Controller. Pursuant to Article 15 GDPR, a registered Customer has unlimited access at any time to all their Personal Data, order history, complaint history, list of favourite products, and their own reviews.
- 5.2. Right to rectification of data – this means that you may request BrandLine to correct inaccurate data or complete incomplete data.
- 5.3. Right to erasure of data – this means that you may request the erasure of your data processed by the Controller.
- 5.4. Right to restriction of processing – this means that you may request BrandLine to restrict the processing of data.
- 5.5. Right to data portability – this means that, subject to certain conditions, you may request that your data be transferred directly to another designated controller.
- 5.6. Right to object – this means that you may object to the processing of Personal Data by the Controller.
- 5.7. Right to object to automated decision-making, including profiling – this means that you may object to Personal Data being used in automated decision-making processes, including profiling.
- 5.8. Right to withdraw consent – this means that you may withdraw your previously given consent at any time.
- 5.9. Right to lodge a complaint with a supervisory authority regarding a personal data breach – if you consider that our processing of data violates the law (right to lodge a complaint with the President of the Personal Data Protection Office, www.uodo.gov.pl).
6. Cookies and Similar Technologies
The Controller uses cookies or similar technologies (hereinafter also referred to as “Cookies”). Cookies are information stored in text form on the User's terminal device when the User accepts them or configures their browser accordingly. The Cookies used by BrandLine are safe for your devices.
There are three basic types of Cookies:
- Session Cookies: temporary files, specific to a particular visit, deleted when the browser is closed;
- Persistent Cookies: files that save information about the User's preferences, stored in the browser's cache;
- Third-party Cookies: placed by trusted partners of BrandLine, used to collect data from a variety of websites or sessions.
What types of Cookies do we use?
- Essential (system): necessary for the proper functioning of the Website, including maintaining the session after logging in.
- Performance (analytical-statistical): necessary for conducting research on traffic on the Website and learning about the preferences of our Users.
- Functional (reference): allow the Website settings to be remembered.
- Marketing and advertising (targeting): allow the advertisements displayed to be tailored to the preferences of our Users.
- Other: all those other than the above.
The Website uses both first-party cookies and third-party cookies.
Cookie storage duration
The duration of cookie storage depends on the type of cookie. Detailed information can be checked when visiting the Website. On the first visit, the information is displayed in a pop-up window.
Managing Cookies and consent to their use
By default, most internet browsers available on the market accept the storage of Cookies. The User has the ability to define the conditions for the use of Cookies via the settings of their own internet browser.
Consent is given when accepting the cookie configuration, usually during the first visit to the Website. This consent is voluntary and may be withdrawn at any time. However, consent does not apply to essential (system) Cookies.
Detailed information on changing cookie settings and deleting them independently in the most popular internet browsers is also available in the browser's help section.
7. Automated Decision-Making, Including Profiling
8. System Logs
While browsing the Website, information is automatically collected regarding the use of the Website by Users and their IP addresses, based on the analysis of access logs, e.g. browser type, operating system type, date and time of visits. Automatically collected data are not associated with specific individuals browsing the pages and are used exclusively for internal analytical and statistical purposes.
Third-party Cookies – Purposes
- Website configuration;
- contact with BrandLine using the Czater.pl chat tool;
- creating statistics via the Google Analytics analytical tools (Google Ireland Ltd.); https://policies.google.com/privacy?fg=1;
- determining the Customer's profile using the Google Ads online advertising tool (Google Ireland Ltd.); https://policies.google.com/privacy?fg=1;
- collecting information about User behaviour using the Facebook Pixel tool (Meta Platforms Ireland Limited); https://www.facebook.com/help/cookies;
- promoting the online store via the YouTube.com service (Google Ireland Ltd.); https://policies.google.com/privacy?hl=pl&gl=pl;
- using Google Signals (Google Ireland Ltd.); https://policies.google.com/privacy?fg=1;
- creating statistics via the MS Clarity analytical tools (Microsoft Corporation); https://privacy.microsoft.com/pl-pl/privacystatement;
- analysing user activity via the SALESmanago platform (Benhauer sp. z o.o.); http://pomoc.salesmanago.pl/ochrona-danych-osobowych/;
- presenting and submitting reviews on the web pages of the external Ceneo.pl internet service (Ceneo.pl sp. z o.o.); http://info.ceneo.pl/polityka_plikow_cookies;
- presenting reviews retrieved from the external Opineo.pl internet service (Opineo.pl sp. z o.o.); http://www.opineo.pl/i/informacje-o-ciastkach.
List of service providers used in operating the Website
| Entity | Purpose |
|---|---|
| ING Bank Śląski S.A. | Ensuring payment processing |
| PayU S.A., with its registered office in Poznań | Ensuring payment processing |
| PayPo Sp. z o.o., with its registered office in Warsaw | Ensuring payment processing |
| Operator DPD sp. z o.o., with its registered office in Warsaw | Order fulfilment (shipments) |
| FedEx Express Polska sp. z o.o., with its registered office in Warsaw | Order fulfilment (shipments) |
| Operator InPost S.A., with its registered office in Kraków | Order fulfilment (shipments) |
| Ceneo sp. z o.o., with its registered office in Poznań | Measuring customer satisfaction with purchases or inclusion of purchases in the Buyer Protection Programme |
| Opineo sp. z o.o., with its registered office in Wrocław | Presenting and submitting reviews on external internet service web pages |
| TrustMate S.A., with its registered office in Wrocław | Presenting and submitting reviews on external internet service web pages |
| BaseLinker Sp. z o.o., with its registered office in Wrocław | Order fulfilment |
| Google Ireland Ltd. (Google Cloud, Google Analytics, Google Analytics 360, Fabric Software), with its registered office in Ireland | Measuring website traffic, reporting errors on the Website, creating statistics |
| Google Ireland Ltd., with its registered office in Ireland | Analysing Customer activity |
| Google Ireland Ltd. (Google Adwords, Double Click Manager, Double Click Search, Remarketing Service, Firebase), with its registered office in Ireland | Measuring the effectiveness of advertising campaigns, managing advertising campaigns |
| Meta Platforms Ireland Limited | Promoting the Website via the Facebook.com social network |
| LinkedIn Ireland Ltd., with its registered office in Ireland | Promoting the Website via the LinkedIn.com social network |
| Microsoft Corporation, with its registered office in the USA | Analysing Customer activity |