PRIVACY POLICY
This Privacy Policy (hereinafter referred to as the “Policy”) applies to the website operating under the domain www.candleboxfactory.com (hereinafter referred to as the “Website”) and is intended to inform Users about the principles of processing their personal data and their rights.
I. DEFINITIONS
Personal Data – any information relating to an identified or identifiable natural person.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
User – any natural person visiting the Website or using one or more services or functionalities described in this Policy.
Profiling – any form of automated processing of personal data consisting in the use of personal data to evaluate certain personal aspects of a natural person.
II. STORAGE AND PROTECTION OF PERSONAL DATA
Personal data are processed in a manner ensuring appropriate security, including protection against unauthorized or unlawful processing and accidental loss, destruction or damage, using appropriate technical and organizational measures.
III. DATA CONTROLLER
The controller of personal data processed via the Website is:
Fidelio – Gift Factory Sp. z o.o.
ul. Parkowa 1B, 05-110 Jabłonna
NIP: 5253014549
Representative of the Controller: Paulina Przygoda
Contact with the Controller is possible via the contact form on the Website or by e-mail:
contact@candleboxfactory.com
IV. PURPOSES AND LEGAL BASES FOR DATA PROCESSING
1. Contact form / e-mail inquiries
For the purpose of responding to inquiries sent via the contact form or e-mail, the following data are processed:
e-mail address
first and last name
Providing data is voluntary but necessary to handle the inquiry.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: until the inquiry is resolved or objection is raised.
2. Marketing and profiling
For the purpose of providing personalized advertising, the Controller may process:
browser type and settings,
operating system,
cookie data,
IP address,
activity on the Website,
approximate location data.
These data may be subject to automated decision-making, including profiling. Profiling does not produce legal effects or significantly affect the User.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: up to 3 years.
3. Newsletter
For the purpose of providing the newsletter, the following data are processed:
e-mail address.
Users may unsubscribe at any time.
Legal basis: User’s consent (Art. 6(1)(a) GDPR).
Retention period: until consent is withdrawn, no longer than 3 years.
4. Claims and complaints
For establishing, pursuing or defending claims, the following data may be processed:
name and surname,
e-mail address,
IP address,
company name and tax number (if provided).
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: according to limitation periods.
5. Analytics and statistics
For analytical and statistical purposes:
operating system,
IP address,
Website activity data.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Retention period: up to 3 years.
V. USER RIGHTS
Users have the right to:
access their data,
receive a copy,
rectify data,
erase data,
restrict processing,
data portability,
object to processing,
withdraw consent,
lodge a complaint with a supervisory authority.
Requests may be sent to: contact@candleboxfactory.com
VI. DATA SHARING
The Controller uses trusted third parties who provide sufficient guarantees of GDPR compliance. Data are shared only to the extent necessary to provide services.
VII. FINAL PROVISIONS
Any changes to this Policy will be communicated to Users by e-mail at least 7 days before publication.
The updated version will be available at:
www.candleboxfactory.com/privacy-policy