PRIVACY POLICY
1. This Privacy Policy sets out the rules for processing personal data obtained through the skinlabgabinet.com online store (hereinafter referred to as the “Online Store”).
2. The owner of the Store and at the same time the data administrator is Joanna Małek-Baranowska running a business under the name SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska with its registered office in Gdańsk (80-280), ul. Mariana Hemara 2, entered in the Central Register and Information on Economic Activity kept by the Minister of Development, Labour and Technology, NIP: 7921975527, REGON: 221190222, hereinafter referred to as SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska.
3. Personal data collected by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska via the Online Store are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as GDPR.
4. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska takes special care to respect the privacy of customers visiting the Online Store.
§1 Type of data processed, purposes and legal basis
1. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska collects information on natural persons performing legal acts not directly related to their activities, natural persons conducting business or professional activities on their own behalf and natural persons representing legal persons or organisational units that are not legal persons to which the Act grants legal capacity, hereinafter referred to as Customers.
2. Customers’ personal data is collected in the case of:
A) registering an account in the Online Store, in order to create an individual account and manage this account. Legal basis: necessity to fulfil the contract for the provision of the Account service (Article 6(1)(b) of the GDPR);
B) placing an order in the Online Store, in order to fulfil the sales contract. Legal basis: necessity for the fulfilment of the sales contract (Article 6(1)(b) of the GDPR);
C) subscription to the newsletter (Newsletter) in order to perform the contract, the subject of which is a service provided electronically. Legal basis – consent of the data subject to the performance of the contract for the provision of the Newsletter service (Article 6(1)(a) of the GDPR).
3. In the case of registering an account in the Online Store, the Customer provides:
A) e-mail address.
4. When registering an account in the Online Store, the Customer independently sets an individual password to access his account. The customer may change the password, at a later time, according to the rules described in §5.
5. In the case of placing an order in the Online Store, the Customer provides the following data:
A) E-mail address;
(B) Address data:
A. Postal code and city;
B. Country (state).
C) Name and surname;
D) Phone number.
6. In the case of Entrepreneurs, the above range of data is further expanded by:
A) The Entrepreneur’s company;
(B) NIP number.
7. In the case of using the Newsletter service, the Customer provides only his e-mail address.
8. When using the Store’s Website, additional information may be collected, in particular: IP address assigned to the Customer’s computer or external IP address of the Internet provider, domain name, browser type, access time, type of operating system.
9. Navigation data may also be collected from Customers, including information about the links and references they decide to click on or other activities undertaken in the Online Store. Legal basis – a legitimate interest (Article 6(1)(f) of the GDPR), consisting in facilitating the use of services provided electronically and improving the functionality of these services.
10. In order to determine, investigate and enforce claims, some personal data provided by the Customer as part of the use of the functionality in the Online Store may be processed, such as: name, surname, data on the use of services, if the claims result from the way in which the Customer uses the services, other data necessary to prove the existence of the claim, including the extent of the damage suffered. Legal basis – legitimate interest (Article 6(1)(f) of the GDPR), consisting in the establishment, pursuit and enforcement of claims and the Defence against claims in proceedings before courts and other state authorities.
11. The transfer of personal data to SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska is voluntary, in connection with the concluded sales contracts or the provision of services via the Store’s Website, with the proviso, however, that failure to provide the data specified in the forms in the Registration process prevents Registration and setting up a Customer Account, and in the case of placing an order without Customer Account Registration, it will prevent the placement and execution of the Customer’s order.
§2 To whom is the data shared or entrusted and how long is it stored?
1. The Customer’s personal data is transferred to the service providers used by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska when running the Online Store. Service providers to whom personal data are transferred, depending on contractual agreements and circumstances, are either subject to SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska recommendations for the purposes and methods of processing this data (processors) or independently determine the purposes and methods of their processing (administrators).
A) SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska uses suppliers who process personal data only on the instructions of SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska. These include, among others, providers providing hosting services, accounting services, providing marketing systems, systems for analysing traffic in the Online Store, systems for analysing the effectiveness of marketing campaigns;
(B) Administrators. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska uses suppliers who do not act only on the recommendation and determine the goals and methods of using Customers’ personal data. They provide electronic payment and banking services.
2. Localisation. Service providers are based in Poland and other European Economic Area (EEA) countries.
3. Customers’ personal data is stored:
A) In the event that the basis for the processing of personal data is consent, then the Customer’s personal data is processed by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska until the consent is revoked, and after the withdrawal of consent for a period of time corresponding to the limitation period of claims that SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska may raise and which may be raised against him. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to conducting business activity – three years.
(B) In the event that the basis for data processing is the performance of the contract, then the Customer’s personal data is processed by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska for as long as it is necessary to perform the contract, and after that time for a period corresponding to the limitation period of limitation of claims. Unless a special provision provides otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to conducting business activity – three years.
4. In the case of a purchase in the Online Store, personal data may be transferred, depending on the Customer’s choice, to the following entities in order to deliver the ordered goods:
A) Courier company;
(B) InPost Paczkomaty Sp. z o.o. based in Krakow, providing delivery and operation services for the mailbox system (Paczkomaty).
5. In the event that the Customer chooses to pay through the PayU system, his personal data is transferred to the extent necessary for the payment to PayU S.A. with its registered office in Poznań (60-166), at ul. Grunwaldzka 182, entered in the register of entrepreneurs kept by the District Court Poznań – Nowe Miasto and Wilda in Poznań, VIII Commercial Division of the National Court Register under KRS number 0000274399.
6. Navigation data may be used to provide customers with better service, analyse statistical data and adapt the Online Store to Customers’ preferences, as well as to administer the Online Store.
7. In the event that the Customer subscribes to the newsletter (Newsletter) to his e-mail address, SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska will send electronic messages containing commercial information about promotions and new products available in the Online Store.
8. In the event of a request, SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska provides personal data with authorised state bodies, in particular organisational units of the Prosecutor’s Office, the Police, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection or the President of the Office of Electronic Communications.
§3 Cookie mechanism, IP address
1. The Online Store uses small files called cookies. They are saved by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska on the end device of the person visiting the Online Store, if the web browser allows it. A cookie usually contains the domain name from which it comes, its “expiration time” and an individual, randomly selected number identifying the file. The information collected using files of this type helps to adapt the products offered by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska to the individual preferences and real needs of visitors to the Online Store. They also give you the opportunity to develop general statistics on visits to the presented products in the Online Store.
2. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska uses two types of cookies:
A) Session cookies: after the end of the browser session or the computer is turned off, the stored information is deleted from the device’s memory. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from Customers’ computers.
(B) Persistent cookies: they are stored in the memory of the Customer’s end device and remain there until they are deleted or expire. The mechanism of persistent cookies does not allow the collection of any personal data or any confidential information from the customers’ computer.
3. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska uses its own cookies in order to:
A) Authenticating the Customer in the Online Store and ensuring the Customer’s session in the Online Store (after logging in), thanks to which the Customer does not have to re-enter the login and password on each subpage of the Online Store;
(B) Analysis and research and audience audit, and in particular to create anonymous statistics that help to understand how Customers use the Store’s Website, which makes it possible to improve its structure and content.
4. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska uses external cookies to:
A) Popularisation of the Online Store using Instagram (external cookie administrator: Instagram LLC.based in the USA);
(B) Popularisation of the Online Store using the social network facebook.com (external cookie administrator: Facebook Inc based in the USA or Facebook Ireland based in Ireland);
C) Presenting multimedia content on the Store’s websites, which are downloaded from an external website www.youtube.com (external cookie administrator: Google Inc based in the USA);
D) Presentation of the Certificate of Reliable Regulations via the website rzetelnyregulamin.pl (external cookie administrator: Rzetelna Grupa sp. z o.o. with its registered office in Warsaw).
5. The cookie mechanism is safe for the computers of the Online Store Customers. In particular, it is not possible for viruses or other unwanted software or malicious software to enter Customers’ computers in this way. However, in their browsers, Customers have the option to limit or disable the access of cookies to computers. If you use this option, the use of the Online Store will be possible, apart from functions that by their nature require cookies.
6. Below we present how you can change the settings of popular web browsers regarding the use of cookies:
A) Chrome and Chrome Mobile browser;
(B) Facebook in-app browser;
C) Internet Explorer browser;
D) Microsoft EDGE browser;
E) Mozilla Firefox browser;
F) Opera browser;
G) Safari browser and Safari Mobile;
H) Samsung Browser.
7. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska can collect customers’ IP addresses. An IP address is a number assigned to the computer of the person visiting the Online Store by the Internet service provider. The IP number allows you to access the Internet. In most cases, it is assigned to the computer dynamically, i.e. it changes every time you connect to the Internet. The IP address is used by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska when diagnosing technical problems with the server, creating statistical analyses (e.g. determining which regions we record the most visits from), as information useful in administering and improving the Online Store, as well as for security purposes and possible identification of unwanted automated programs for viewing the content of the Online Store that burden the server.
8. The Online Store contains links and references to other websites. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska is not responsible for the privacy policy in force on them.
§4 Rights of data subjects
1. Right to withdraw consent – legal basis: art. 7 para. 3 GDPR.
A) The customer has the right to withdraw any consent given by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska
(B) The withdrawal of consent is effective from the moment of withdrawal of consent.
C) Withdrawal of consent does not affect the processing carried out by SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska in accordance with the law before its withdrawal.
D) Withdrawal of consent does not entail any negative consequences for the Customer, but it may prevent further use of services or functionality, which according to the law of SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska can only provide with consent.
2. Right to object to data processing – legal basis: art. 21 GDPR.
A) The customer has the right at any time to object – for reasons related to his particular situation – to the processing of his personal data, including profiling, if SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska processes his data based on a legitimate interest, e.g. marketing of products and services SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska, keeping statistics on the use of individual functionalities of the Online Store and facilitating the use of the Online Store, as well as satisfaction survey.
(B) Resignation in the form of an e-mail from receiving marketing messages regarding products or services will mean the Customer’s objection to the processing of his personal data, including profiling for these purposes.
C) If the Customer’s objection proves to be justified and Fluo Works Grochowalski Patryk has no other legal basis for processing personal data, the Customer’s personal data will be deleted, to the processing of which the Customer has objected.
3. Right to erasure (“right to be forgotten”) – legal basis: art. 17 GDPR.
A) The customer has the right to request the deletion of all or some personal data.
(B) The Customer has the right to request the deletion of personal data if:
A. Personal data are no longer necessary for the purposes for which they were collected or processed;
B. Withdraws a specific consent, to the extent that personal data were processed based on his consent;
C. Objected to the use of his data for marketing purposes;
D. Personal data is processed unlawfully;
E. Personal data must be deleted in order to comply with a legal obligation provided for in the law of the Union or the law of a Member State to which SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska is subject;
F. Personal data was collected in connection with the offer of information society services.
C) Despite the request to delete personal data, in connection with the objection or withdrawal of consent, SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska may retain certain personal data to the extent that the processing is necessary to establish, pursue or defend claims, as well as to fulfil a legal obligation requiring processing under EU law or the law of the Member State to which SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska is subject. This applies in particular to personal data including: name, surname, e-mail address, which are stored for the purposes of considering complaints and claims related to the use of the services of SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska, or additionally the address of residence / correspondence address, order number, which data are stored for the purposes of considering complaints and claims related to concluded sales contracts or the provision of services.
4. Right to restrict data processing – legal basis: art. 18 GDPR.
A) The customer has the right to request the restriction of the processing of his personal data. Submitting a request, until it is considered, prevents the use of certain functionalities or services, the use of which will be associated with the processing of the data covered by the request. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska will also not send any messages, including marketing ones.
(B) The customer has the right to request the restriction of the use of personal data in the following cases:
A. When he questions the accuracy of his personal data – then SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska limits their use for the time needed to check the correctness of the data, but not longer than 7 days;
B. When the processing of data is unlawful, and instead of deleting the data, the Customer will request the restriction of their use;
C. When personal data is no longer necessary for the purposes for which it was collected or used but it is necessary for the Customer to establish, pursue or defend claims;
D. When he objected to the use of his data – then the restriction takes place for the time needed to consider whether – due to the special situation – the protection of the interests, rights and freedoms of the Client prevails over the interests that the Administrator pursues by processing the Customer’s personal data.
5. Right of access to data – legal basis: art. 15 GDPR.
A) The Customer has the right to obtain from the Administrator confirmation whether he processes personal data, and if this is the case, the Customer has the right to:
A. Access your personal data;
B. Obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of this data, the planned period of storage of the Customer’s data or the criteria for determining this period (when it is not possible to determine the planned period of data processing), the Customer’s rights under the GDPR and the right to lodge a complaint with the supervisory authority, the source of this data, automated decision-making, including profiling and safeguards applied in connection with the transfer of this data outside the European Union;
C. Obtain a copy of your personal data.
6. Right to rectification of data – legal basis: art. 16 GDPR.
A) The Customer has the right to request from the Administrator an immediate rectification of his personal data, which are incorrect. Taking into account the purposes of processing, the Customer of the data subject has the right to request the completion of incomplete personal data, including by submitting an additional statement, sending a request to the e-mail address in accordance with §6 of the Privacy Policy.
7. Right to data portability – legal basis: art. 20 GDPR.
A) The Customer has the right to receive his personal data, which he has provided to the Administrator, and then send it to another personal data administrator of his choice. The Customer also has the right to request that personal data be sent by the Administrator directly to such administrator, if it is technically possible. In this case, the Administrator will send the Customer’s personal data in the form of a file in csv format, which is a commonly used format, machine-readable and allowing the received data to be sent to another personal data administrator.
8. In the event that the Customer has an authorisation resulting from the above rights, SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska fulfils the request or refuses to fulfil it immediately, but no later than within a month after receiving it. However, if – due to the complicated nature of the request or the number of requests – SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska is unable to fulfil the request within a month, it will fulfil it within the next two months by informing the Customer in advance within a month from receiving the request – about the intended extension of the deadline and its reasons.
9. The Customer may submit to the Administrator complaints, inquiries and requests regarding the processing of his personal data and the exercise of his rights.
10. The customer has the right to request from SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska to provide copies of the standard contractual clauses by sending an inquiry in the manner indicated in §6 of the Privacy Policy.
11. The customer has the right to lodge a complaint with the President of the Office for Personal Data Protection regarding the violation of his rights to the protection of personal data or other rights granted under the GDPR.
§5 Security management – password
1. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska provides customers with a secure and encrypted connection when sending personal data and logging in to the Customer Account on the Website. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska uses an SSL certificate issued by one of the world’s leading companies in the field of security and encryption of data transmitted via the Internet.
2. In the event that the Customer with an account in the Online Store has lost the access password in any way, the Online Store allows you to generate a new password. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska does not send a password reminder. The password is stored in encrypted form, in a way that makes it impossible to read it. In order to generate a new password, you must enter your e-mail address in the form available under the “Forgot your password” link provided next to the online store account login form. The Customer will receive an e-mail message to the e-mail address provided during registration or saved in the last change of the account profile containing a redirection to a dedicated form made available on the Store’s Website, where the Customer will be able to set a new password.
3. SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska never sends any correspondence, including electronic correspondence with a request for login data, and in particular the access password to the Customer’s account.
§6 Changes to the Privacy Policy
1. The Privacy Policy may change, about which SKINLAB Gabinet Kosmetologii Joanna Małek-Baranowska will inform customers 7 days in advance.
2. Questions related to the Privacy Policy should be directed to: sklep@skinlabgabinet.com
3. Date of last modification: 31.01.2025