1. General Information and Data Controller
This Privacy Policy sets out the rules for processing and protecting the personal data of users of the online store available at a1mate.com.
The Data Controller is:
Vacgear Sp. z o.o.
ul. Ostrobramska 101/301
04-041 Warsaw, Poland
Tax ID (NIP): 1133061099
E-mail: support@a1mate.com
Phone: +48 726 398 525
The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and other applicable data protection laws.
We take appropriate technical and organisational measures to protect users' privacy and the security of processed personal data.
2. Personal Data We Collect
The scope of personal data collected depends on how the user interacts with the store and may include:
A. Data provided directly by the user:
- first and last name;
- company name;
- Tax ID or other tax identification number where required for invoicing;
- delivery address;
- billing address;
- e-mail address;
- phone number;
- data provided when creating a customer account;
- information provided when contacting the Controller, including correspondence content.
B. Data collected automatically:
When using the store, certain technical information may be collected automatically, including:
- IP address;
- browser type;
- operating system;
- device information;
- pages visited;
- date and time of visits;
- information stored using cookies and similar technologies.
The use of cookies also depends on the user's settings and consent where such consent is required.
C. Payment information:
The Controller does not store full payment card details.
Electronic payments are processed by external payment service providers according to the payment method selected by the customer. The Controller receives only the information necessary to identify, confirm and settle the payment.
3. Purposes of Personal Data Processing
Personal data may be processed for the following purposes:
- entering into and performing a sales contract;
- accepting and processing orders;
- processing payments;
- organising delivery of ordered products;
- issuing invoices and other accounting documents;
- maintaining customer accounts;
- communicating with customers regarding orders;
- handling enquiries and customer service requests;
- handling complaints, returns and other customer rights;
- complying with tax, accounting and other legal obligations;
- ensuring store security and preventing fraud and abuse;
- establishing, pursuing or defending legal claims;
- conducting analyses and statistics concerning store operation;
- carrying out marketing activities where an appropriate legal basis exists, including consent where required.
4. Legal Basis for Processing Personal Data
Personal data is processed only where an appropriate legal basis exists.
Depending on the purpose of processing, the legal basis may be:
a) Article 6(1)(b) GDPR – performance of a contract or steps taken prior to entering into a contract
This legal basis applies in particular to data processing necessary for:
- entering into and performing a sales contract;
- processing orders;
- processing payments;
- delivery of products;
- maintaining a customer account;
- communication related to performance of the contract.
b) Article 6(1)(c) GDPR – compliance with a legal obligation
This legal basis applies in particular to data processing necessary for:
- tax and accounting obligations;
- retention of documentation required by law;
- compliance with consumer protection obligations.
c) Article 6(1)(f) GDPR – legitimate interests pursued by the Controller
The Controller's legitimate interests may include:
- ensuring store security;
- preventing fraud and abuse;
- responding to enquiries;
- conducting basic analyses and statistics;
- establishing, pursuing or defending legal claims.
d) Article 6(1)(a) GDPR – consent
Where processing requires consent, personal data is processed on the basis of the user's freely given consent, particularly in relation to certain marketing activities or optional tracking technologies.
Where processing is based on consent, the user may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
5. Recipients of Personal Data
The Controller does not sell or rent users' personal data.
Personal data may be disclosed to service providers cooperating with the Controller only to the extent necessary to operate the store and provide services.
Recipients may include:
- courier, postal and logistics companies;
- payment service providers;
- hosting and IT service providers;
- software providers used for operating the store;
- accounting service providers;
- e-mail service providers;
- marketing and analytics service providers where an appropriate legal basis exists;
- public authorities, courts or other authorised entities where disclosure is required by law.
Entities processing data on behalf of the Controller receive access only to data necessary to perform the services entrusted to them.
6. Data Retention Period
Personal data is retained for as long as necessary to fulfil the purpose for which it was collected.
In particular:
- data related to order fulfilment is retained for the period necessary to perform the contract and for the period during which legal claims may be pursued;
- accounting and tax documentation is retained for the period required by applicable law;
- customer account data is retained for the duration of the account and subsequently for the period necessary to protect against potential claims;
- data processed on the basis of consent is retained until consent is withdrawn, unless another legal basis for further processing exists;
- data processed on the basis of legitimate interests is retained until those interests cease to exist or a valid objection is raised where applicable under the GDPR.
7. Data Security
The Controller applies appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, destruction, alteration, unauthorised disclosure or access.
Connections to the store are secured using SSL/TLS encryption.
However, no method of transmitting or storing data over the Internet can guarantee complete elimination of all risks.
8. Rights of Data Subjects
Subject to the conditions provided by the GDPR, individuals may have the following rights:
- the right of access to personal data;
- the right to obtain a copy of personal data;
- the right to rectification of inaccurate data;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing;
- the right to withdraw consent at any time where processing is based on consent.
To exercise these rights, please contact the Controller at:
Data subjects also have the right to lodge a complaint with the competent data protection supervisory authority.
In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO).
9. Cookies
The store uses cookies and similar technologies to ensure correct operation of the website, maintain user sessions, operate the shopping cart and order process, ensure security and, depending on user settings and consent, conduct analytics or marketing activities.
Certain cookies are necessary for the proper functioning of the store and may be used without consent where permitted by applicable law.
Non-essential cookies are used on the basis of the user's consent where such consent is required.
Users may manage cookie settings using the tools available in the store and their browser settings.
Restricting certain cookies may affect the functionality of some parts of the store.
10. Marketing
Personal data may be used for marketing purposes only where an appropriate legal basis exists.
Where consent is required for a particular type of marketing communication, such communication will only be sent after the relevant consent has been obtained.
Users may withdraw consent or opt out of marketing communications at any time.
11. Transfers of Personal Data Outside the European Economic Area
Because the Controller may use external technology service providers, certain personal data may be processed outside the European Economic Area (EEA).
Where such transfers take place, the Controller applies appropriate safeguards provided for under the GDPR, including an adequacy decision of the European Commission or Standard Contractual Clauses where applicable.
12. Children's Data
The store is not directed at children.
The Controller does not knowingly collect children's personal data for purposes requiring the child's independent consent. If the Controller becomes aware that data has been provided in breach of applicable law, appropriate action will be taken.
13. Changes to this Privacy Policy
The Controller may update this Privacy Policy, in particular due to changes in applicable law, store operations, technologies used or external services.
The current version of the Privacy Policy is published on the store website.
14. Contact
For questions regarding this Privacy Policy or the processing of personal data, please contact the Controller:
Vacgear Sp. z o.o.
ul. Ostrobramska 101/301
04-041 Warsaw, Poland
Tax ID (NIP): 1133061099
E-mail: support@a1mate.com
Phone: +48 726 398 525