Privacy Policy
Privacy Policy and Personal Data Protection.
Introductory Provisions
- This Privacy Policy constitutes an annex to the Terms and Conditions of the online store operating at petigio.com and has been in effect since 25 May 2018. Its provisions have been adapted to the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Acceptance of the Store’s Terms and Conditions (https://petigio.com/terms-and-conditions/) constitutes acceptance of this Privacy Policy.
Glossary
- For the purposes of this document:
- “Data Controller” means PetiGIO Sp. z o.o., with its registered office at ul. Ostródzka 74H, 03‑289 Warsaw, entered in the National Court Register (KRS 0001126528; NIP 5243017121; REGON 52963185700000; share capital PLN 5,400), operating the online store petigio.com (hereinafter also “Store”);
- “Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity;
- “Password” means a sequence of letters, numbers or other characters known only to the person authorized to use the IT system;
- “User identifier (login)” means a sequence of letters, numbers or other characters uniquely identifying the person authorized to process personal data in the IT system;
- “User account” means the space in the online store petigio.com available to the User for making purchases; registering requires providing a login and password;
- “Newsletter” means an electronic bulletin used to inform Store Users about promotional campaigns and news in the petigio.com Store;
- “Data breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data transmitted, stored or otherwise processed;
- “Recipient” means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not. Public authorities receiving data under Union or Member State law are not considered recipients;
- “Restriction of processing” means marking stored personal data with the aim of limiting their future processing;
- “Supervisory authority” means the independent public authority established by a Member State under Article 51 of the Regulation, namely the President of the Personal Data Protection Office, ul. Stawki 2, 00‑193 Warsaw;
- “Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller;
- “Confidentiality of data” means the property ensuring that personal data are not disclosed to unauthorized entities;
- “Processing” means any operation or set of operations performed on personal data or sets of personal data, whether by automated or non‑automated means, such as collection, recording, organization, structuring, storage, adaptation, modification, retrieval, consultation, use, disclosure, dissemination, alignment, restriction, erasure or destruction;
- “Regulation” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
- “Erasure” (also: “anonymization”) means deletion of personal data or such modification that prevents identification of the data subject;
- “Authentication” means the process of verifying the declared identity of a data subject;
- “User” means a natural person with full or limited capacity to act, a legal person or organizational unit without legal personality but with legal capacity, holding a User account on petigio.com, logging in with an individual login and password;
- “Consent of the data subject” means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
Data Controller: Purposes, Scope and Legal Basis of Processing
- The Data Controller of Users’ personal data is PetiGIO Sp. z o.o., with its registered office as above.
- Contact regarding personal data protection matters may be made by mail to ul. Ostródzka 74H, 03‑289 Warsaw; by email to petigio@petigio.com (subject: “Personal Data”); or by phone at +48 508 311 775.
- Users’ personal data are processed exclusively for the following purposes:
- setting up and managing the User account;
- fulfilling sales contracts concluded with the Controller;
- handling complaints submitted to the Controller;
- providing warranty services;
- sending commercial and marketing information;
- accounting and tax purposes arising from legal obligations;
- establishing, pursuing or defending the Controller’s claims, including debt collection and court proceedings.
- The User provides personal data voluntarily by consenting at account registration. The legal basis for processing data for a purchase is Article 6 (1)(b) of the Regulation. Providing personal data is necessary to conclude and perform the contract; failure to provide data prevents order processing.
- The legal basis for processing Users’ personal data for marketing and promotional purposes is the User’s voluntary consent, obtained in accordance with the Act of 18 July 2002 on electronic services and the Telecommunication Law.
- The Controller processes the following personal data of the User:
- first and last name;
- address;
- email address;
- contact telephone number.
Information Clauses
- The User’s consent to personal data processing is voluntary and may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal. Withdrawal is equivalent to deleting the User’s email from the Store’s mailing list.
- The User has the right to request access to their data, obtain confirmation of processing, and receive information on: processing purposes; categories of processed data; recipients or categories of recipients; planned retention periods; and rights regarding their data.
- At the User’s request, the Store will provide a copy of their personal data being processed. The request form is Appendix No. 1 at the end of this Policy.
- The User has the right to request rectification of inaccurate data and completion of incomplete data, including by submitting an additional statement.
- The User has the right to have their personal data erased (“right to be forgotten”), and the Controller must erase such data without undue delay when one of the following applies:
- data are no longer necessary for the purposes collected;
- consent is withdrawn and no other legal basis applies;
- User objects to processing;
- data have been processed unlawfully;
- erasure is required to comply with a legal obligation under EU or national law.
— The above does not apply if processing is necessary for the establishment, exercise or defence of legal claims or compliance with legal obligations.
- The Controller may refuse erasure if the User has unsettled liabilities, breached Store terms or legal obligations, and the data are necessary to clarify circumstances and determine liability.
- The User has the right to restrict processing when they contest accuracy, when processing is unlawful and they oppose erasure, when data are no longer needed by the Controller but required by the User for legal claims, or when the User objects.
- The User has the right to object to processing at any time; the Controller must cease processing unless it demonstrates compelling legitimate grounds overriding the User’s interests, rights and freedoms, or for legal claims.
- The User has the right to data portability; the Controller shall provide data in a structured, commonly used, machine‑readable format for transmission to another Controller.
- Personal data will be processed for:
- the duration of the User’s account and 30 days thereafter upon deletion request;
- complaints for the period necessary to resolve them, but no longer than 2 years from purchase;
- warranty services for the duration of the warranty;
- accounting purposes for 5 years from the end of the calendar year of purchase.
— In each case, only data necessary for these purposes are processed. Exceptions are described above.
- The User has the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office, ul. Stawki 2, 00‑193 Warsaw, if they believe processing infringes the Regulation.
- The Controller ensures that processing is carried out with the utmost respect for privacy and security, implementing all legally required physical, IT and organizational measures as detailed in its Data Protection Policy and IT System Management Instruction.
Disclosure of Users’ Personal Data
- The Controller may disclose personal data without consent only to entities authorized under specific provisions (e.g., courts, law enforcement agencies).
- The Store does not share Users’ personal data with other entities except those providing postal, delivery or other necessary services for order fulfillment, to the extent required.
- If the User pays via tpay.com according to tpay.com’s terms, the petigio.com Store is not the Data Controller of data provided to tpay.com, and such data are used by the payment provider without involvement of the Store.
User Comments and Opinions
Comments and opinions left by the User on the Store’s website may be published on petigio.com and disseminated only with the User’s consent expressed by checking the consent clause below the form.
Newsletter
- Receiving the Newsletter is possible only by submitting an email address in the newsletter form and consenting to personal data processing for marketing purposes in accordance with the Act of 16 July 2004 – Telecommunications Law, and to receive commercial information by electronic means under the Act of 18 July 2002 on the provision of electronic services.
- Opting out of marketing and commercial information via the newsletter is possible by clicking the unsubscribe link in the footer of each email.
Deletion of a Registered User Account
- The User has the right at any time to request deletion of their account registered in the petigio.com online store.
- Requests should be sent by email to petigio@petigio.com from the address used for account registration.
- The Controller will delete the account within 30 days of receiving the request, unless specific laws require further processing; the User will be informed by the email from which the request was sent.
- The Controller will not delete the account within the above period if processing is necessary for establishing, pursuing or defending legal claims or fulfilling legal obligations.
- The Controller may refuse deletion if the User has unsettled dues or breached Store terms or legal obligations, and the data are necessary to clarify circumstances and determine liability.
User’s Responsibility
- The User is responsible for the accuracy of the personal data provided.
- To ensure data protection, the User must safeguard their login and password used for the Store. Users are liable for disclosing login credentials to third parties.
Cookies Policy
- The Service does not automatically collect any information except that contained in cookies.
- Cookies are information stored in text files on the User’s device, intended for use with the Store’s web pages. They typically contain the website name, storage duration, and a unique number.
- The entity placing cookies on the User’s device and accessing them is petigio.com and PetiGIO Sp. z o.o., ul. Ostródzka 74H, 03‑289 Warsaw.
- Cookies are used to:
- adapt the Store’s content to User preferences and optimize browsing; in particular, cookies allow the Store to recognize the User’s device and display a tailored website;
- create statistics to understand how Users use the Store’s pages, enabling improvement of their structure and content;
- maintain the User’s session (after login) so the User does not have to re-enter credentials on each subpage;
- Two main types of cookies are used: session cookies (temporary, deleted upon logout, leaving the site or closing the browser) and persistent cookies (stored for a specified time or until deleted by the User).
- Types of cookies used:
- “necessary” cookies enabling use of Store services, e.g., authentication cookies;
- security cookies, e.g., to detect authentication abuse;
- “performance” cookies, collecting information on how Users use the Store;
- “functional” cookies, remembering User settings and personalizing the interface, e.g., language, region, font size, website appearance;
- “advertising” cookies, delivering tailored ads based on User interests.
- By default, browsers allow cookie storage. Users can change cookie settings at any time to block automatic handling or be notified of each placement. Detailed instructions are in browser settings.
- Restricting cookies may affect some Store functionalities.
- Cookies on the User’s device may also be used by cooperating advertisers and partners.