Privacy & Cookies Policy
Baby Tim Store (“Store”)
Dear User!
Our goal is to make you feel safe on our website, which is why your privacy and the protection of your personal rights are important to us. For this reason, please read the following summary carefully about how our website works.
You can be assured that your data will be processed transparently and fairly, and that we will make every effort to ensure that your data is treated carefully and responsibly.
The following Privacy Policy aims to inform you about how we use your personal data, for which we meet all the requirements of the Polish Data Protection Act and the requirements of the General Data Protection Regulation (GDPR).
We have moved the provisions of the Privacy Policy from the Regulations here to keep access to information in one place:
§ PERSONAL DATA PROTECTION AND PRIVACY POLICY
1. The administrator of Users' personal data (hereinafter: "Administrator") within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as GDPR) is the Administrator - Vitalii Losiev, 00-100 Warszawa.
2. The administrator of the Buyer's personal data (hereinafter referred to as the "Seller Administrator") within the meaning of the GDPR is the Seller.
3. Contact with the Administrator is possible via the e-mail address hello@baby-tim.pl
4. Buyers' personal data (name and surname, delivery address, e-mail address, telephone number) are processed in order to complete the order and execute the sales contract concluded with them, including preparation and delivery of the order, issuing an invoice, as well as for the purpose of implementing the right to withdraw from the contract and to exercise the right to submit a complaint under the terms set out in the Regulations.
5. Personal data of Users who have created an account in the Online Store (name and surname, delivery address, e-mail address, telephone number) are processed only to the extent necessary to register and operate the account of a given User on the Store's website.
6. The User or the Buyer may give prior consent by accepting the appropriate Clause to sending him commercial information within the meaning of the Act of July 18, 2002 on the provision of electronic services (Journal of Laws of 2002, No. 144, item 1204, as amended). changes). The consent referred to in the preceding sentence is voluntary and does not condition the execution of the placed order.
7. The Administrator may process the User's personal data (e-mail address) for marketing purposes only with the User's prior consent expressed in the appropriate Clause. The Administrator may disclose such User's personal data to third parties only with the User's prior consent expressed in the appropriate Clause.
8. Providing personal data is voluntary, but necessary to achieve the above-mentioned purposes, including servicing the User's account, delivering the order, issuing an invoice, handling complaints and the right to withdraw from the contract. This information is strictly confidential and used only by the Administrator or the Seller, who is subject to the same obligations as the Administrator, in accordance with the Privacy Policy and Cookies Privacy Policy.
9. Personal data processed by the Administrator will not be made available to other entities without the prior consent of the User or the Buyer. Personal data may be made available to entities authorized under the law.
10. The Administrator may, by means of a written agreement, entrust the processing of personal data to third parties only for the purpose specified by him and to the extent necessary to register and operate the User's account or to complete a given order and perform the contract concluded with the Buyer, in accordance with Art. 28 GDPR.
11. Personal data will not be transferred to a third country or international organization.
12. Personal data will be stored for the period necessary to achieve the purposes, including:
- in terms of personal data necessary to register and operate the account of a given User - for the period necessary to provide the service;
- in terms of personal data necessary to complete the order - until the Product is delivered to the Buyer;
- scope of personal data necessary to exercise the right to withdraw from the contract and the right to submit a complaint - up to two years from the date of delivery of the Product to the Buyer;
- in the scope of personal data necessary to achieve marketing purposes provided electronically, referred to in the point above - until the consent given by the User is withdrawn;
13. The User or Buyer has the right to access their data and the right to rectify, delete, limit processing, transfer, object, and withdraw consent to the processing of personal data at any time. Exercising the right to withdraw consent does not affect the lawfulness of the processing of personal data that took place before the withdrawal of consent.
14. The User or Buyer has the right to lodge a complaint with the Personal Data Protection Office if they consider that the processing of personal data concerning the User or Buyer violates the provisions of the GDPR.
15. In order to exercise the rights referred to in points 13 and 14, please contact the Administrator via e-mail address hello@baby-tim.pl
16. The website uses cookies. By using the Store Website, the User or Buyer accepts that cookies will be installed on the end device, which enable the Administrator to provide services. More information about the use of cookies by the Administrator on the Store's Website can be found below.
Check in detail how we process your data:
- Data of the personal data administrator
The controller for the purposes of the GDPR, other legal acts in force in EU Member States and other provisions relating to data protection is:
Vitalii Losiev is available at: hello@baby-tim.pl
- Scope of personal data processing
We collect and process your personal data only to the extent necessary to ensure the functioning of the website, the content and services we present, for example when you register on our website, log in to an existing customer account or order products. Your personal data is collected and used only with your consent. The exception to this rule are situations in which prior consent is not possible due to given circumstances and data processing is permitted by law.
The security of your personal data is a high priority for us. Therefore, we take technical and organizational measures to ensure the protection of your data stored and processed by us, in order to effectively prevent their loss and misuse by third parties. Our employees processing personal data are particularly bound by confidentiality obligations and must comply with them. Your personal data is protected by ensuring that it is transmitted in encrypted form; for example, we use SSL (Secure Sockets Layer) to communicate with your web browser. Your browser will display a padlock symbol so you can see when an SSL connection has been established. To ensure that your data is protected at all times, technical security measures are regularly reviewed and, where necessary, adapted to new technological standards. These principles also apply to companies to which we commission the processing and use of data in accordance with our instructions.
- Purposes of processing and legal principles governing the processing of your personal data
We collect, process and use your personal data for the following purposes:
- Conclusion and performance of contracts
- Marketing activities
- Customer service and customer assistance
- Providing broadcast media services, e.g. to process orders for goods and services we offer online
Your personal data may be processed based on the following legal principles:
- Art. 6, par. 1 letter and GDPR is the legal basis for processing activities for which we obtain your consent for a given processing purpose.
- Art. 6, par. 1 letter b GDPR states that personal data may be processed for the purpose of performing a contract, e.g. when purchasing a product. The same applies to all processing activities necessary to carry out pre-contractual activities, such as handling inquiries regarding products or services.
- Art. 6, par. 1 letter c GDPR applies in cases where we have a legal obligation requiring the processing of personal data, for example to fulfill tax obligations.
- Art. 6, par. 1 letter f GDPR applies in relation to our legitimate interests, for example when employing service providers to fulfill orders (e.g. delivery services), when completing surveys for statistical purposes and conducting statistical analyses, when attempting to log in or ensure security on the website. Our interest is in providing a user-friendly, attractive and secure website and in optimizing it to meet both our business goals and your expectations.
- Storage period and course of deletion of personal data
We process and store your personal data only for as long as necessary to fulfill the purpose of storage or as long as we are required to do so by law or regulation. As soon as the purpose no longer applies or is fulfilled, your personal data will be deleted or their processing will be restricted. In the event of restriction of data processing, such data will be deleted as soon as the data retention periods imposed by law, the company's articles of association or contract provisions no longer prevent such deletion, unless there is reason to assume that such deletion would jeopardize legitimate interests and under provided that such removal would not require disproportionate effort due to the particular nature of the storage.
- Collection of data and general information (log records)
Our website collects a number of data and general information each time you access it, which is stored temporarily in server logs. The log record is created as part of automatic logging performed by the processing computer system. The following data may be collected:
- Website access (date, time and frequency)
- How you arrived at the page (referrer, hyperlink, etc.)
- Volume of transferred data
- The browser you use and its version
- The operating system you are using
- The Internet service provider you use
- The IP address assigned to your computer by your Internet Service Provider when you connect to the Internet
The collection and storage of this data is required for the operation of the website in order to ensure the functionality of the website and to properly display the content of our website. We also use this data to optimize our website and to ensure the security of our IT systems. Therefore, for technical prudential reasons, these data are stored for a period of seven days.
We also use this data for marketing purposes, to research and define the market and to structure our services to meet demand by creating and analyzing usage profiles under pseudonyms, but only if you have not exercised your right to refuse or to withdraw consent to the use of your data. data in this way (see notes regarding your right to object in the "Your rights" section).
- Cookies, analytical services (web analysis) and social media
We use cookies, web analysis services and social media plug-ins on our website.
We want your experience of using our website to be as good as possible, which is why we use cookies, web analysis services and social media plug-ins in accordance with Art. 6 pairs 1 GDPR.
For this purpose, we use various cookies and services that guarantee the full functionality of our website, so that it contains as much information as possible and is as user-friendly as possible for the user, i.e. you. It is important to us that you can surf our website with ease and that is why we attach great importance to making continuous improvements to it. These actions include saving your settings and pre-filled forms so that you don't have to re-enter the same data. It is also important to us that you see only the content that really interests you and that your contact with the online world is easier.
Nevertheless, we will remember to handle your personal data carefully. In the document following this introduction you will find detailed information on the use of cookies and services available on this website. Of course, you can deactivate all cookies and services as you wish. You can do this by blocking or deleting cookies from the web browser you use. You can also deactivate them separately by installing an opt-out cookie (opt-out cookie). You can also perform operations available after selecting a hyperlink (commonly called a link). Please note that deactivation is necessary for all browsers you use. If you delete all cookies in your browser, this also affects the opt-out cookie.
- Functional cookies
Cookies are small files that are placed on your computer by websites you visit. They allow you to reconstruct any settings or other changes you have made on your next visit to this website.
These functional cookies ensure that our website functions properly. These cookies are stored for a maximum of two years - after this time they are automatically deleted. The following functions are possible using these cookies:
- saving products that you have placed in your electronic basket or saved on your wish list,
- saving the data you entered when leaving the electronic checkout or when placing an order, so that you do not have to re-enter them,
- saving settings such as language, location, number of search results, etc.,
- saving settings for optimal display on your device's screen, e.g. desired buffer size and data on your screen's resolution,
- saving your browser settings to allow our website to display it optimally,
- recording misuse of our websites and services, such as recording multiple consecutive or failed registration attempts,
- fully loading the website so that it remains accessible or
- saving your login details so that you do not have to re-enter them every time.
You can prevent the storage of these cookies or delete those that are already stored. You can obtain more detailed information from the manufacturer of your web browser or in its help section. We must remind you that some of the functions of our website will no longer be available or will only be available to a limited extent if you do not allow the use of these functional cookies.
- Analytical services for statistical purposes
To determine what content of our website is most attractive to you, we constantly monitor the number of people visiting it and the most frequently viewed content. We use the data we collect for statistical purposes, such as:
- recording the number of people visiting our websites,
- recording the time that visitors spend on our website,
- recording the order of visits to various websites,
- determining which parts of our website require changes or
- to optimize the website.
We use the following services for statistical purposes; they can be deactivated by installing an opt-out cookie or by clicking on the hyperlink:
- Google Analytics
Google Analytics is a web analytics service offered by Google Inc., 1600 Amphitheater Parkway Mountain View, CA 94043, USA. Google Analytics uses cookies to enable the website operator to analyze how users use the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. Google will first shorten your IP address located in Member States of the European Union or in other countries that are party to the European Economic Area Agreement. Only in exceptional cases will the full IP address be sent to a Google server in the USA and shortened there. The IP address transmitted by your browser in the context of Google Analytics is not merged with other Google data. Stored Google Analytics cookies are automatically deleted after 14 months.
You can find more information about terms of use and data protection on the following website https://www.google.com/analytics/terms/gb.html and https://policies.google.com/?hl=en
To deactivate Google Analytics, click on the hyperlink below to download and install the browser plug-in: https://tools.google.com/dlpage/gaoptout?hl=en
- Google Maps
Google Maps API is a map service offered by Google Inc., 1600 Amphitheater Parkway Mountain View, CA 94043, USA. We use Google Maps API to display an interactive driving map and create driving directions or to help you find a stationary store. When using Google Maps, information about your use of this website (including your IP address) may be transferred to Google servers in the United States and stored there by Google.
To find more information about Google Maps' privacy policy and terms of use, please visit the following website https://www.google.com/intl/eng_eng/help/terms_maps.html and https://policies.google. com/privacy?hl=eng
- Marketing services
We use marketing services to present you attractive offers. The above will include our displaying advertisements through advertising partners or using advertising networks that use cookies from third parties. They are activated when you visit our website and are only read by the relevant advertising partner. In addition, we want to show you ads that you find really interesting. For this purpose, we use the so-called retargeting to ensure that ads match your interests. Cookies stored temporarily for this operation allow our retargeting partners to recognize visitors to our website under a pseudonym and only show products that would be of interest to our visitors.
Our retargeting partners' cookies do not store any ordinary or special category personal data. In addition, the collected data will not be merged with data that allows us to identify our visitors.
These services enable us, for example:
- guaranteeing advertising success and fees between advertising partners and us,
- Track which ads you've already seen to avoid seeing the same ads again
- determining the number of views of our website,
- tracking internal search commands
- spotting products whose websites are called or
- recognizing your login status.
However, we would like to inform you that even if you deactivate these services for marketing purposes, advertisements will still be shown to you. These advertisements could be adapted, for example, to the content of the website. You could compare this type of content, which is dependent Internet advertising, to television advertising: if you watch a television program about cooking, then during the commercial break during such a program, you will often be shown advertisements for cooking-related products.
We use the following services for marketing purposes; you can deactivate them by installing the opt-out cookie or by clicking on the hyperlink:
- Facebook “visitor action pixel”
Visitor action pixel {“visitor action pixel”} is a tool of Facebook Inc., 1601 Willow Road, Menlo Park, CA 94025, USA. Based on visits to the website and surfing behavior, this tool allows us to determine target groups for Facebook advertising, the so-called “Facebook-Ads”. We also use this tool to measure the effectiveness of marketing activities in the online world. So we can track what users do after they see and/or click on a Facebook ad and then place an order.
Once you have entered the website, this pixel is integrated directly by Facebook and may store a cookie on your device. If you then log in to Facebook, or if you are already logged in there, your visit to the website will be recorded in your profile. The collected data remains anonymous, which means that we cannot see the personal data of individual users; similarly, we cannot associate them with other information about the user. However, this data is stored and processed by Facebook, so that conclusions can be drawn about the profile of the respective user. Data processing by Facebook takes place in accordance with the Data Use Policy of Facebook. If you are not a Facebook member, this data processing does not affect you.
Social media – plugins
Our website provides you with plugins for social media sites so that you can connect to your social media channels. These plug-ins are marked with a logo or the words "social plug-in".
The following social media plug-ins are integrated into our website:
- Facebook like/share button. Provider: Facebook Inc., 1601 Willow Road, Menlo Park, CA 94025, USA
- Google+ button Provider: Google Inc., 1600 Amphitheater Parkway Mountain View, CA 94043, USA
- Instagram social plugin. Provider: Instagram LLC, 1601 Willow Road, Menlo Park, CA 94025, USA
- Pin-it button. Provider: Pinterest Inc., 651 Brannan Street, San Francisco, CA 94103, USA
- YouTube social plugin. Provider: YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA
- Sharing information about our products and services, special offers and other news.
We use your data to send information you request regarding our products, services and other special offers to the e-mail address and/or telephone number you provide. The above will only take place with your prior consent, or if permitted by law. Consent to such transmission is regulated by Art. 6 pairs 1 letter a and art. 7 GDPR.
- Registration in the store
If you register on our website to receive information by email and/or telephone, we will store your email address and telephone number so that we can provide you with information about our products and services.
- Deliveries related to the sale of products and services
If you purchase products or services on our website, we may send you information about our own, similar products and services to the e-mail address and/or telephone number provided by you, even without your consent.
- Postal items
We may also use your information to send you information about our products, services, special offers and partner offers by post.
We want you to enjoy reading our offers, so we try to include only information that you are likely to find interesting. Therefore, we measure and store the frequency of visits and clicks on your user profile, as part of the Administrator's justified purpose (Article 6(1)(f) of the GDPR). This information includes whether and when you open our communications, what content you click on and when, and whether and why you may not receive our offers. We also use this data for statistical purposes.
Of course, you can also unsubscribe to stop receiving such offers, i.e. withdraw your consent with future effect, for which purpose a corresponding unsubscribe link is included in each offer and newsletter. You will then be asked to confirm your cancellation on our website. You can also contact us to withdraw your consent at any time:
- by e-mail: hello@baby-tim.pl
It is not possible to unsubscribe from receiving certain information messages required for the performance of contracts and for the operation of our website, including service-related e-mails (e.g. registration confirmations, customer service information) or information about purchases (e.g. order confirmations, contract-related documents regarding payment processing). You will receive these notifications according to the contact information you provide.
- Processing of personal data when establishing contact, after registration and when placing orders without registration
a) Making contact
The information you provide to us when contacting us by e-mail, telephone or via the contact form will be stored by us pursuant to Art. 6, par. 1, letter f GDPR, in order to answer your questions. The contact will be recorded in a register so that we can prove that the contact took place in accordance with legal requirements.
b) Registration
On our website, we provide you with the option to register by providing your personal data. This data is entered into a data form and transmitted to us and stored by us. Registration is made for the purpose of performing a contract or carrying out activities aimed at concluding a contract, and therefore the basis for them is Art. 6, par. 1, letter b GDPR.
In order to conclude and perform contracts, we require contact details depending on the specific case, for example name and surname, delivery address, invoice address, e-mail address, telephone number and information about the selected payment method. We also use your data to maintain our customer records, where only the most relevant data is stored. In order to prevent typographical errors (so-called "typos") and to ensure that the ordered products are actually delivered to you, we check the completeness and correctness of your address when entering it.
c) Orders placed without registration
You can place an order as a visitor, i.e. without registration. If you choose this method of ordering, you do not need to register before placing an order. Please note that you will then have to re-enter your details when placing orders in the future.
When ordering without registration, we collect, process and use the data provided by you in order to perform the contract, in accordance with Art. 6, par. 1, letter b GDPR. We store the information you provide for the duration of the processing and fulfillment of your order. Your data will then be deleted unless you decide to activate your customer account within 14 days of placing your order. The processing of data that we are obliged to store in accordance with statutory, corporate or contractual requirements will be limited to prevent it from being used for other purposes, but will not be deleted.
d) Miscellaneous provisions
Based on Article. 6, par. 1, letter c and f GDPR, we use and store your personal data and, where necessary, technical information, in order to prevent misuse of data or other unlawful behavior on our website, or to conduct investigations in such cases, e.g. to ensure data security in the event of attacks on our IT systems. This may be carried out on the basis of orders of public authorities or common courts, if required by law, as well as to protect our rights and interests and to enable us to defend ourselves in court.
- Transfer of personal data to third parties
When transferring your personal data, we ensure that the level of security is always as high as possible, which is why your data is transferred only to carefully selected service and partner companies that are bound by contractual obligations. We only transfer your data to entities located within the European Economic Area and therefore subject to strict EU data protection regulations or bound by an appropriate security standard. Transferring data to third countries is not currently practiced or planned.
a) Transfer of data to service partners in accordance with Art. 6, par. 1, letters b and f of the GDPR
In order to operate and optimize our website and to fulfill contracts, we commission various service companies to act on our behalf, e.g. to provide central IT services, to host our website, to process payments and ship products, to install equipment or to deliver information bulletins. We provide service partners with the information required for a given purpose (e.g. name, address).
Some of these companies act on our behalf in connection with the processing and fulfillment of orders and are therefore only permitted to use the data provided in accordance with our instructions. In this case, the service partner is legally responsible for ensuring that appropriate measures are taken to ensure data security. For our part, we agree on specific data security measures with these entities and regularly monitor these solutions.
If the goods to be shipped are large and heavy, your order will be sent via a service provider such as a courier company or your own transport. The service provider will receive information from us, such as the e-mail address and/or telephone number provided by you in the order, in order to enable them to make arrangements with you regarding a specific delivery time.
Contrary to the requirements for external processing, we transfer data to third parties in order to perform the contract in the following cases, which makes these entities themselves responsible for the use of this data:
- When forwarding goods, data is transferred to logistics companies or postal service providers specified in the order.
- Regarding payment for the ordered goods, data is transferred to the payment processor or financing bank specified in the order. When providing a credit card as a payment method, in order to avoid credit card fraud, a security check will be carried out for the given transaction with the help of the payment processor Pay Pro SA.
Regarding payments, we do not collect or store payment information such as credit card numbers or account details. They are exclusively and directly sent to the relevant payment processor. In the case of credit card payments, an exception is the "pseudo-card number". So that you do not have to re-enter your credit card number every time you make a payment, a pseudo-card number is stored in your customer account. This pseudo-card number allows you to purchase products and services only on our website, ordered from your customer account and is not identical to the number.
b) Transfer to other third parties in accordance with Art. 6, par. 1, letters c and f of the GDPR
Finally, we may transfer your data to third parties or public administration bodies in accordance with current data protection regulations, if we are required to do so by law (e.g. based on an order issued by a public administration body or a court), or if we are entitled to do so (e.g. because it is necessary for the investigation of criminal activities or to report and assert our rights and interests).
- Your rights
Of course, you have rights regarding the collection of your data, which we are pleased to inform you about here. If you would like to exercise any of these rights free of charge, simply send us a message. You can use the following contact details without incurring any costs other than those charged by your telecommunications service provider for transmitting the message:
- by e-mail: hello@baby-tim.pl
For your protection, we reserve the right to obtain further information when responding to an existing inquiry in order to confirm your identity. If identification proves impossible, we also reserve the right to refuse to respond to your inquiry.
- The right to access data
You have the right to request information from us regarding the personal data we store about you.
- Right to rectification
You have the right to request immediate rectification and/or completion of personal data stored about you
- The right to restrict processing
You have the right to request that the processing of your personal data be restricted if you question the accuracy of the data stored about you, if the processing is carried out unlawfully and we no longer need the data, but you do not wish for the data to be deleted , and you require them in order to declare, exercise or defend rights arising from legal provisions, or if you have expressed your objection to their processing.
- Right to erasure
You have the right to request the deletion of your personal data stored by us, unless maintaining the data is necessary to ensure freedom of speech, freedom of access to information, fulfillment of an obligation arising from legal provisions, for reasons of public interest, to submit or defend against claims or in to assert rights under the law.
- The right to information
If you have expressed the right to rectify, delete or limit the processing of your data, we will notify all recipients of your personal data about the method of rectifying, deleting or imposing restrictions on the processing of this data, unless it is impossible to carry out or involves a disproportionate effort.
- The right to transfer data
You have the right to obtain a copy of the data you have provided to us, which will be sent to you or a third party in a structured, standard, machine-readable format. If you request that your data be sent to another data controller, this will be done if it is technically possible.
- Right to object
If your personal data is processed for the legitimate interest of Art. 6, par. 1, letter f GDPR, you have the right to object to processing at any time, in accordance with Art. 21 GDPR.
- The right to withdraw consent
You have the right to withdraw your consent to the collection of data at any time, with future effect. This will not affect the data collected so far. We hope you understand that for technical reasons it may take some time to process your withdrawal of consent and that you may continue to receive communications from us during this period.
- The right not to be subject to a decision based on automated processing, including Profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, if such a decision produces legal effects for you or similarly significantly affects you.
- The right to lodge a complaint with a regulatory authority
If the processing of your personal data violates data protection regulations or if your data protection rights have been violated in any other way, you may submit a complaint to the President of the Personal Data Protection Office.
Please note that once you delete your data, you will no longer have access to services related to our products via our website. The above may also include Internet re-download services. Therefore, we encourage you to make a backup copy of your data before exercising your right to deletion. The processing of data that we are obliged to store in accordance with statutory, corporate or contractual requirements will be limited to prevent it from being used for other purposes, but will not be deleted.
- Changes to the Privacy Policy
In order to ensure that our Privacy Policy meets current statutory requirements at all times, we reserve the right to make changes to it at any time. The above also applies in cases where the Privacy Policy requires changes to cover new or changed products or services.
The privacy policy enters into force in March 2023.