Privacy policy and cookies

1. This Privacy Policy sets out the rules for the processing of personal data obtained via the online shop www.bestsport24.com (hereinafter: "Online Shop").

2. The owner of the Online Shop and at the same time the data administrator is BEST SPORT Sp. z o.o. with its registered office in Warsaw (02-495), ul.Dzieci Warszawy 31 lok.74, entered into the Register of Entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register under the KRS No. 0000239657, with the share capital of PLN 600,000, NIP No.: 5222784186, REGON No.: 140224107, hereinafter referred to as BEST SPORT.

3. Personal data collected by BEST SPORT via the Online Shop is processed in accordance with Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) also called GDPR.

4. BEST SPORT takes special care to respect the privacy of customers visiting the Online Shop.

§ 1 Type of data processed, objectives and legal basis

1. BEST SPORT collects information on natural persons conducting legal transactions not directly related to their activities, natural persons conducting business or professional activity on their own behalf, and natural persons representing legal persons or organizational units that are not legal entities to which the act grants legal capacity, conducting economic or professional business activity on their own behalf, hereinafter referred to collectively as Customers.

2. Customers' personal data is collected in the case of:

a) registering an account in the Online Shop, in order to create an individual account and manage this account. Legal basis: indispensability to execute an agreement for the provision of the Account service (Art. 6 para. 1 letter b of GDPR);

b) placing an order in the Online Shop in order to execute a sale agreement. Legal basis: indispensability to execute a sale agreement (Art. 6 para. 1 letter b of GDPR);

c) subscribing to the newsletter (Newsletter), in order to execute an agreement, the subject of which is the service provided electronically. Legal basis - consent of the data subject to execute an agreement for the provision of the Newsletter service (Art. 6 para. 1 letter a of GDPR);

d) using the contact form service to execute an agreement provided electronically. Legal basis: indispensability to execute an agreement for the provision of the contact form service (Art. 6 para. 1 letter b of GDPR);

3. In the case of an account registration in the Online Shop, the Customer provides:

a) email address;

b) address details:

- zip code and city;

- street with house/flat number.

c) name and surname;

d) telephone number.

4. When registering an account in the Online Shop, the Customer sets an individual password to access his account. The customer can change the password at a later time, on the terms described in §5.

5. In the case of placing an order in the Online Shop, the Customer provides the following data:

a) email address;

b) address details:

- zip code and city;

- street with house/flat number.

c) name and surname;

d) telephone number.

6. In the case of Entrepreneurs, the above data scope is additionally extended by:

a) Entrepreneur's company;

b) NIP number.

7. In the case of using the contact form service, the Customer provides the following data:

a) email address;

b) name and surname;

8. When using the Online Shop Website, additional information may be downloaded, in particular: the IP address assigned to the Customer's computer or the external IP address of the Internet provider, domain name, browser type, access time, type of operating system.

9. The Online Shop may also collect navigation data, including information about links in which the Customers decide to click or other activities undertaken in our Online Shop. Legal basis - a legitimate interest (Art. 6 para. 1 letter f of GDPR), consisting in facilitating the use of electronic services and improving the functionality of these services.

10. In order to determine, investigate and enforce claims, certain personal data provided by the Customer may be processed as part of using the functionality in the Online Shop, such as: name, surname, data on the use of services, if claims result from the manner in which the Customer uses the services, other data necessary to prove the existence of the claim, including the extent of the damage suffered. Legal basis - a legitimate interest (Art. 6 para. 1 letter f of GDPR), consisting in determining, pursuing and enforcing claims and defending against claims in proceedings before courts and other state authorities.

11. The transfer of personal data to BEST SPORT is voluntary, in connection with concluded sale agreements or provision of services via the Shop Website, however, with the reservation that failure to provide data specified in the data forms in the Registration process makes it impossible to register and set up a Customer Account, and in the case of placing an order without registering a Customer Account will prevent the submission and execution of the Customer's order.

§ 2 Who do we entrust or share your personal information with and how long is it stored?

1. The Customer's personal data is provided to service providers used by BEST SPORT while running the Online Shop. Service providers to whom personal data are transferred to, depending on contractual arrangements and circumstances, are either subject to BEST SPORT recommendations as to the purposes and methods of data processing (processors) or independently define the purposes and methods of their processing (administrators).

a) Processors. BEST SPORT uses suppliers who process personal data only at the request of BEST SPORT. These include providers providing hosting services, accounting services, marketing systems, systems for analysing traffic in the Online Shop, systems for analysing the effectiveness of marketing campaigns;

b) Administrators. BEST SPORT uses suppliers who do not act solely on command and set the goals and methods of using personal data of Customers. They provide electronic and bank payment services.

2. Location. Service providers are based mainly in Poland and other countries of the European Economic Area (EEA).

3. Customers' personal data is stored:

a) If the basis for the processing of personal data is a consent, then, the Customer's personal data is processed by BEST SPORT until the consent is withdrawn, and after the consent has been withdrawn for a period corresponding to the period of limitation of claims that may raise BEST SPORT and what may be raised to it. Unless a special rule provides otherwise, the period of limitation is ten years, and for claims for periodic benefits and claims related to running a business - three years.

b) If the basis for data processing is the performance of the agreement, then the Customer's personal data are processed by BEST SPORT as long as it is necessary to execute the agreement, and after that time for the period corresponding to the period of limitation of claims. Unless a special rule provides otherwise, the period of limitation is ten years, and for claims for periodic benefits and claims related to running a business - three years.

4. In the event of purchase in the Online Shop, personal data may be transferred, depending on the choice of the Customer, to the following entities to deliver the ordered goods:

a) a courier company;

b) If the Customer chooses a payment through the PayPro system (credit card or other payment methods operated by PayPro), his personal data will be transferred to the extent necessary for the payment to PayPro S.A. with its registered office in Poznań (60-327 Poznań, ul. Kanclerska 15), entered into the Register of Entrepreneurs kept by the District Court for Poznań - Nowe Miasto and Wilda in Poznań, 8th Commercial Department of the National Court Register under the KRS No. 0000347935; NIP No.: 7792369887, REGON No.: 301345068.

c) If the Customer chooses a payment through the PayPal system, his personal data will be transferred to the extent necessary for the payment to PayPal (Europe) S.à r.l. et Cie, S.C.A. L-1150 Luxembourg.

6. The navigation data can be used to provide Customers with better service, statistical data analysis and adaptation of the Online Shop to Customer preferences, as well as the administration of the Online Shop.

7. If the Customer subscribes to the newsletter (Newsletter) at his e-mail address, BEST SPORT will send electronic messages containing commercial information about promotions and new products available in the Online Shop.

8. In the event of a request, BEST SPORT provides personal data to authorized state authorities, in particular to the organizational units of the Prosecutor's Office, the Police, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.

§ 3 The mechanism of cookies, IP address

1. The Online Shop uses small files called cookies. They are saved by BEST SPORT on the end device of the person visiting the Online Shop, if the web browser allows it. A cookie file usually contains the name of the domain it comes from, its "expiration time" and an individual, random number identifying this file. The information collected by means of such files help to adapt products offered by BEST SPORT to individual preferences and real needs of people visiting the Online Shop. They also provide the opportunity to develop general statistics of visits to the presented products in the Online Shop.

2. BEST SPORT uses two types of cookies:

a) Session cookies: after completing a session of a given browser or turning off the computer, stored information is removed from the device's memory. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from the Customers' computers.

b) Persistent cookies: they are stored in the memory of the Customer's end device and remain there until they are deleted or expired. The mechanism of persistent cookies does not allow the collection of any personal data or any confidential information from the Customer's computer.

3. BEST SPORT uses own cookies for the purpose of:

a) Customer authentication in the Online Shop and ensuring Customer's session in the Online Shop (after logging in), thanks to which the Customer does not have to enter the login and password on each subpage of the Online Shop;

b) analysis, research and audience audits, in particular to create anonymous statistics that help to understand how Customers use the Shop Website, which allows improving its structure and content.

4. BEST SPORT uses external cookies for the purpose of:

a) popularizing the Online Shop using the social network facebook.com (administrator of external cookies: Facebook Inc with its registered office in the USA or Facebook Ireland based in Ireland);

b) collecting general and anonymous static data via analytical tools of Google Analytics (external cookie administrator: Google Inc. with its registered office in the USA);

5. The cookie mechanism is safe for the Customers of the Online Shop. In particular, this way it is not possible to get viruses or other unwanted software or malicious software onto Customers’ computers. However, in their browsers, Customers have the option of limiting or disabling access of cookies to computers. If you use this option, the use of the Online Shop will be possible, apart from the functions which, by their nature, require cookies.

6. Below we present how you can change the settings of popular web browsers in the use of cookies:

a. Internet Explorer

b. Microsoft EDGE

c. Mozilla Firefox

d. Chrome

e. Safari

f. Opera

7. BEST SPORT can collect IP addresses of Customers. An IP address is a number assigned to the computer of the visitor of the Online Shop by the ISP. The IP number allows access to the Internet. In most cases, it is assigned to the computer dynamically, i.e. it changes every time you connect to the Internet and is therefore commonly regarded as non-person identifying information. The IP address is used by BEST SPORT, when diagnosing technical problems with the server, creating statistical analyses (e.g. determining the regions from which we receive the most visits), as information useful in administering and improving the Online Shop, as well as for security purposes and possible identification of the server , unwanted automated programs to browse the contents of the Online Shop.

8. The Online Shop contains links to other websites. BEST SPORT is not responsible for the privacy practices applicable to them.

§ 4 Rights of data subjects

1. The right to withdraw the consent - legal basis: art. 7 par. 3 of GDPR.

a) The Customer has the right to withdraw any consent granted to BEST SPORT.

b) Withdrawal of consent has effect since the withdrawal of consent.

c) Withdrawal of consent does not affect the processing carried out by BEST SPORT in accordance with the law before its withdrawal.

d) Withdrawal of consent does not entail any negative consequences for the Customer, however, it may prevent further use of services or functionality that, according to BEST SPORT law, may be provided only with consent.

2. The right to object to data processing - legal basis: art. 21 of GDPR.

a) The Customer has the right to object at any time - for reasons related to his special situation - to the processing of his personal data, including profiling, if BEST SPORT processes his data based on a legitimate interest, e.g. marketing of BEST SPORT products and services , statistics on the use of individual functionalities of the Online Shop and facilitating the use of the Online Shop, as well as a satisfaction survey.

b) Resignation in the form of an e-mail from receiving marketing messages regarding products or services will mean the Customer's objection to the processing of his personal data, including profiling for these purposes.

c) If the Customer's objection turns out to be justified and BEST SPORT has no other legal basis to process personal data, the Customer's personal data will be deleted from the processing of which the Customer has lodged an objection.

3. The right to delete data ("the right to be forgotten") - legal basis: art. 17 of GDPR.

a) The Customer has the right to request the removal of all or some personal data.

b) The Customer has the right to request the deletion of personal data if:

a. personal data are no longer necessary for the purposes for which they were collected or processed;

b. he withdrew his specific consent to the extent to which personal data were processed based on this consent;

c. he objected to the use of his data for marketing purposes;

d. personal data are processed unlawfully;

e. personal data must be removed in order to comply with the legal obligation provided for by Union law or the law of the Member State to which BEST SPORT is subject;

f. personal data has been collected in connection with the offering of information society services.

c) Despite the request to delete personal data, in connection with objection or withdrawal of consent, BEST SPORT may retain certain personal data to the extent that processing is necessary to establish, assert or defend claims, as well as to fulfil a legal obligation requiring processing under the EU law or the law of the Member State to which BEST SPORT is subject. This applies in particular to personal data including: name, surname, e-mail address, which data are kept for the purpose of handling complaints and claims related to the use of BEST SPORT services, or additionally, residential address/address for letters, order number, which data are retained for the purpose of handling complaints and claims related to concluded sale agreements or provision of services.

4. The right to limit data processing - legal basis: art. 18 of GDPR.

a) The Customer has the right to demand the restriction of the processing of his personal data. Submission of a request, pending its consideration, prevents the use of certain functionalities or services, the use of which will involve the processing of data covered by the request. BEST SPORT will also not send any messages, including marketing ones.

b) The Customer has the right to request a limitation of the use of personal data in the following cases:

a. when he questions the correctness of his personal data - then BEST SPORT limits its use for the time needed to verify the correctness of data, but no longer than for 7 days;

b. when the data processing is unlawful, and instead of deleting the data, the Customer will demand limitation of its use;

c. where personal information is no longer necessary for the purposes for which it was collected or used, but is needed by the Customer to establish, assert or defend claims;

d. when he objected to the use of his data - then the limitation takes place for the time needed to consider whether - due to the special situation - protection of the Customer's interests, rights and freedoms outweighs the interests that the Administrator performs while processing the Customer's personal data.

5. The right of access to data - legal basis: art. 15 of GDPR.

a) The Customer has the right to obtain from the Administrator confirmation whether he processes personal data, and if so, the Customer has the right to:

a. get access to his personal data;

b. obtain information about the purposes of processing, categories of personal data being processed, recipients or categories of recipients of this data, the planned period of customer data storage or criteria for determining this period (when it is not possible to determine the planned data processing period), about the rights of the Customer under GDPR and the right to lodge a complaint with the supervisory body, the source of this data, about automated decision-making, including profiling and about safeguards applied in connection with the transfer of this data outside the European Union;

c. obtain a copy of his personal data.

6. The right to rectify data - legal basis: art. 16 of GDPR.

a) The Customer has the right to demand from the Administrator that he corrects his personal data, which is incorrect. Taking into account the purposes of processing, the data subject has the right to request supplementing of incomplete personal data, including by submitting an additional statement, directing the request to the e-mail address in accordance with § 6 of the Privacy Policy.

7. The right to transfer data - legal basis: art. 20 of GDPR.

a) The Customer has the right to receive his personal data, which he provided to the Administrator, and then send it to another personal data administrator of his choice. The Customer also has the right to demand that personal data is sent by the Administrator directly to another administrator, if it is technically possible. In this case, the Administrator will send the Customer's personal data in the form of a file in csv format, which is a widely used, machine-readable format that allows sending the received data to another personal data administrator.

8. In the situation, when the Customer comes with the right resulting from the above rights, BEST SPORT meets the request or refuses to meet it immediately, but not later than within one month after receiving it. However, if - due to the complexity of the request or the number of requests - BEST SPORT will not be able to meet the request within a month, it will meet it within the next two months by informing the Customer within one month of receiving the request - about the intended extension and its reasons.

9. The Customer may submit complaints, inquiries and requests to the Administrator regarding the processing of his personal data and the exercise of his rights.

10. The Customer has the right to request from BEST SPORT a copy of standard contractual clauses by directing the inquiry in the manner specified in § 6 of the Privacy Policy.

11. The Customer has the right to lodge a complaint to the President of the Office for Personal Data Protection in the scope of violation of his rights to the protection of personal data or other rights granted under GDPR.

§ 5 Security management - password

1. BEST SPORT provides Customers with a secure and encrypted connection when sending personal data and when logging in to the Customer Account on the Website. BEST SPORT uses an SSL certificate issued by one of the world's leading companies in the field of security and encryption of data transmitted via the Internet.

2. In the event that the Customer who has an account in the Online Shop has lost any access password in any way, the Online Shop allows you to generate a new password. BEST SPORT does not send a password reminder. The password is stored in an encrypted form in a way that prevents its reading. To generate a new password, please enter your e-mail address in the form available under the link "Forgot my password" provided at the login form for the account in the Online Shop. The Customer to the e-mail address provided during registration or saved in the last change of the account profile will receive an e-mail containing a redirection to a dedicated form provided on the Shop Website, where he will be able to set a new password.

3. BEST SPORT never sends any correspondence, including electronic correspondence, with a request to provide login details, in particular an access password to the Customer's account.

§ 6 Changes to the Privacy Policy

1. Privacy Policy may be subject to change, and BEST SPORT will inform Customers about it 7 days in advance.

2. Questions related to the Privacy Policy should be addressed to: bestsport@bestsport.com.pl

3. Date of last modification: 1 Jan 2019