VETSUPREME
I. General Information
This Privacy Policy applies to all users (“Users”) of our website (“Site”) available at: https://vetsupreme.shop. Definitions used in this Policy are clarified in point XIII below.
The Data Administrator is:
Natalia Gorzna
VetSupreme veterinary equipment
Zdrój 31C
62-065 Zdrój
NIP PL9950207105
For any questions, concerns, or comments regarding the information contained in this Policy or other matters related to the processing of Users’ Personal Data by the Administrator, including the exercise of rights referred to in point IX of this Policy, please contact: info@vetsupreme.shop
II. Collection of Personal Data
The Administrator may process Users’ Personal Data such as:
-
First name, last name
-
Address and contact details, including e-mail address, phone number
-
Payment data, including bank account number and account holder’s name
The Administrator takes all appropriate measures to ensure that the scope of Users’ Personal Data processed is limited to data essential for the purposes specified in this Policy.
Personal Data is collected particularly in situations such as:
-
When Users provide Personal Data to obtain information about products available on the Site, for marketing activities conducted by the Data Administrator, or to receive newsletters (e.g., by e-mail, phone, contact form, Facebook, consent to receive newsletters, or in any other way);
-
When Personal Data is collected from Users during purchases made on the Site (order completion process);
-
When Personal Data published by Users on social media is collected (e.g., information from Users’ profiles to the extent public information is available);
-
When Users visit Administrator’s pages or use any features or resources available on or through the Site. When Users visit the Site, their devices and browsers may automatically provide certain information (device type, operating system, browser type, browser settings, IP address, language settings, dates, times of Site access, and other technical communication data), some of which may constitute Personal Data.
No User Personal Data will be stored by the Administrator during the Site visit without the User’s prior, explicit consent. However, temporary storage of log files and cookies facilitates use of the Site, and Users are asked for consent. Granting such consent is voluntary and does not affect Site usability. In some cases, however, not providing consent may limit certain functionalities.
Legal Bases for Processing Personal Data
Depending on circumstances, the Administrator may rely on one or more of these legal bases for processing:
-
Processing is based on the User’s prior, voluntary, specific, informed, and unequivocal consent (Art. 6(1)(a) GDPR);
-
Processing is necessary for the performance of a contract the User has entered into or intends to enter into with the Administrator (Art. 6(1)(b) GDPR);
-
Processing is necessary for compliance with a legal obligation to which the Administrator is subject (Art. 6(1)(c) GDPR);
-
Processing is necessary to protect the vital interests of any natural person (Art. 6(1)(d) GDPR);
-
Processing is necessary for the purposes of the legitimate interests pursued by the Administrator, including defending and pursuing claims (Art. 6(1)(f) GDPR).
Purposes of Personal Data Processing
Personal Data may be processed for the following purposes:
-
Site Management: operation and management of our Site, presenting content; publishing advertisements and promotional/marketing information; communicating with clients, suppliers, or potential employees/collaborators through the Site.
-
Offering Products and Services: presenting products/services; providing promotional materials at the Users’ request; communications relating to the Administrator’s services.
-
Marketing Communication: sharing messages or information in any manner (including e-mail, phone, text, social media, mail, face-to-face) that may interest Users. This includes distribution of newsletters and commercial information, after receiving prior consent, in accordance with applicable law.
-
IT Communication & Operations: managing communication systems, acting for IT security, and performing IT security audits.
-
Finance Management: sales, finance, audit, sales management.
-
Research: gathering information on Users’ opinions about the Administrator’s products/services.
-
Product/Service Improvement: identifying issues with existing products/services, planning improvements, and developing new products/services.
III. Sharing Personal Data with Third Parties
The Administrator may only share Users’ Personal Data with:
-
Administrative or court authorities at their request, to report actual or suspected legal violations.
-
Auditors, lawyers, PR agencies, provided confidentiality obligations (contractual or legal) are observed.
-
Third parties processing data on behalf of the Administrator, regardless of location, as specified below.
-
Any entity involved in prevention, investigation, detection, or prosecution of prohibited acts, public safety, or enforcement of criminal penalties.
-
Any acquiring entity if the Administrator (or any organized part or shares thereof) is sold or transferred (including in case of reorganization, dissolution, or liquidation).
The Site may use plugins or content from third parties. If Users utilize them, their Personal Data may be shared with third parties or social platforms. The Administrator recommends reading the respective privacy policies before using such plugins or content.
Social Media Redirects Used:
Data Processors:
If a third party is engaged to process User Personal Data, the processing entity must:
-
Only process Personal Data as specified in the Administrator’s written instructions.
-
Apply all measures to protect data confidentiality and security and comply with all legal obligations.
Processors may include:
-
Shoplo Sp. z o.o. (website developer and technical support)
-
PayPro S.A. (online payment processing via Przelewy24.pl)
-
Courier and logistics operators
Processors ensure full security of Personal Data using up-to-date technical and organizational measures, and are prohibited from using data for purposes other than those entrusted by the Administrator.
IV. International Transfer of Personal Data
The Administrator does not transfer Users’ Personal Data outside the European Economic Area.
V. Data Protection Measures
The Administrator has implemented appropriate technical and organizational security measures to protect Personal Data, especially against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access and other unlawful or unauthorized processing, in accordance with applicable law.
The Administrator is not responsible for Users’ actions/inactions. Users are responsible for ensuring their Personal Data is sent to the Administrator securely.
VI. Data Storage
The criteria for determining how long Personal Data is stored are as follows:
The Administrator keeps copies of Users’ Personal Data in an identifiable form only as long as necessary for the purposes stated in this Policy, unless applicable law requires a longer storage period.
When processing is based on User consent (Art. 6(1)(a) GDPR), data is processed until consent is withdrawn.
The Administrator may, in particular, keep Personal Data for the period necessary to establish, exercise, or defend claims.
VII. User Rights
According to GDPR, regarding their Personal Data processed by the Administrator, Users have rights to:
-
Access their Personal Data
-
Request rectification
-
Request erasure
-
Request restriction of processing
-
Data portability
-
Object to processing
-
Not be subject to solely automated decision-making
If processing is based on consent, Users may withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal.
In case of improper processing of Personal Data, Users have the right to lodge a complaint with the national data protection supervisory authority (the President of the Personal Data Protection Office in Poland).
These rights do not affect other rights Users have under law.
To exercise any rights or inquire further, contact details are provided in point XII of the full policy.
VIII. Cookies
A cookie is a small file placed on a User’s device when visiting the website (including our Site). It records information about the device, browser, and sometimes preferences or typical user actions online. The Administrator may process Personal Data using cookies, in accordance with the Cookie Policy.
https://vetsupreme.shop uses cookies for:
-
Personalizing the displayed content
-
Targeted advertising
-
Analyzing site traffic
Cookies contain the domain name, expiration (“lifetime”), a unique random identifier, and the public IP address of the device.
Cookies are mainly used for statistical purposes and do not contain identifiable characteristics of site visitors. This data is not combined with data of specific individuals.
Cookies are kept for up to 24 months, depending on type.
Types of cookies used:
-
Session cookies: Deleted when the browser session ends or the device is turned off; they do not collect personal or sensitive information.
-
Persistent cookies: Stored on the user’s device; improve functionality, remember interface settings, and allow generation of site statistics.
Cookies used do not harm devices or change device/browser configuration.
Users can limit or disable cookies at any time; however, some site functionalities may be diminished.
IX. Newsletter
If Users voluntarily, specifically, knowingly, and clearly consent to receiving the Administrator’s newsletter, the Administrator may send an electronic newsletter containing commercial information for promotional and informational purposes. Personal Data provided for newsletter subscription will be used solely for this purpose. Users can unsubscribe at any time via the opt-out link in the email footer or by contacting the Administrator.
Personal Data obtained for the newsletter will be stored solely for as long as Users subscribe and until their consent is withdrawn.
Providing Personal Data for this purpose is not a legal or contractual requirement and is not mandatory for any agreement. The only legal basis for receiving the newsletter is User consent (Art. 6(1)(a) GDPR). Without it, the newsletter will not be sent.
X. Definitions
-
Administrator: The entity deciding how and for what purposes Personal Data is processed. Responsible for compliance with data protection laws.
-
Personal Data: Any information about an identified or identifiable natural person. Examples are listed in point II.
-
Processing: Any activity involving Personal Data, automated or not, such as collecting, recording, organizing, structuring, storage, adaptation, alteration, retrieval, consultation, use, transfer, dissemination, ordering, combining, restriction, erasure, or destruction.
-
Processor: Any person or entity processing Personal Data on behalf of the Administrator (other than the Administrator’s employees).
