Privacy Policy

Privacy policy and use of cookies on the website www.maybella.fr

General information

This document sets out the rules of the privacy policy on the website (hereinafter referred to as the "Website"). The administrator of the Website is XYZ

Capitalized words have the meanings given to them in the rules of this website.

The personal data collected by the site administrator are processed in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46/EC (General Data Protection Regulation) (Journal of Laws EU L 119, p. 1), hereinafter referred to as: GDPR.

The website administrator makes special efforts to protect the confidentiality of information provided by website customers. The administrator, with due diligence, selects and implements appropriate technical measures, including programming and organizational measures, thus ensuring the protection of processed data. This includes protection against unauthorized disclosure, loss, destruction, unauthorized modification, as well as any processing in violation of applicable laws.

The recipients of the Services available on the site (including the possibility of placing an Order) are not persons under the age of 16. The personal data administrator does not intend to deliberately collect data on persons under the age of 16.

Personal data

Responsible for processing personal data

The administrator of your personal data is:

XYZ Limited Liability Company Limited Partnership

  1. XYZ

Regarding your personal data, you can contact the personal data administrator via:

Purposes and legal bases for the processing of personal data

The personal data administrator processes your personal data for the following purposes and within the following scope:

  • In order to take steps prior to concluding the contract at your request (e.g. creating an account), i.e. the data provided in the registration form on the website, i.e. email address and established password, gender; if the account is registered via an external authentication service (e.g. Google+, Facebook), we collect your first and last name, and if you register when ordering the goods, we collect your first and last name and the data provided for the purpose of processing the order, such as the delivery address; in order to provide services that require an account, such as: keeping an order history, informing about the order status, we process your data provided in the account and when ordering the goods;

  • In order to provide services that do not require creating an account and purchasing goods, i.e. browsing the website, searching for goods, we process personal data about your activity on the website, i.e. data about the goods you browse, data about your device session, operating system, browser, location and unique identifier, IP address;

  • In order to execute the brokerage agreement (e.g. delivery of the ordered goods), we process the personal data you provided when ordering the goods, such as first and last name, email address, contact details, payment details;

  • In order to generate statistics on the use of individual features available on the Website, to facilitate the use of the Website and to ensure the IT security of the Website, we process personal data about your activity on the Website and the time spent on each of the sub-pages of the Website, your search history, your location, your IP address, your device ID, your data about your web browser and your operating system;

  • In order to establish, pursue and enforce claims and to defend against claims in court proceedings and other enforcement authorities, we may process your personal data provided when ordering the goods or creating an account and other data necessary to prove the existence of a claim or which arise from a legal obligation, court order or other legal procedure;

  • In order to process complaints or requests and answer customer questions, we process the personal data you provided in the contact form, complaints and requests, or answers to questions contained in a different form and certain personal data you provided in the Account, as well as data on the order of the Goods and other Services we provide that are the basis of the complaint or request, as well as the data contained in the documents attached to the complaint, complaint and request;

  • For the purpose of marketing our products and services to our customers and partners, including remarketing, for this purpose we process the personal data you provided when creating and updating your account, data about your activity on the website, including orders recorded and stored via cookies, including order history, search history, clicks on the Site, login and registration dates, history and your activity related to our communication with you. In the case of remarketing, we use data about your activity in order to reach you with our marketing messages outside the website and for this purpose we use the services of external providers. These services consist of displaying our messages on websites other than the website.

  • In order to organize competitions and loyalty programs, i.e. notifications about accumulated points, notifications about winnings and advertising our offer, we use your personal data provided in the account and when registering for a competition or loyalty program. Detailed information on this is provided each time in the conditions of participation in a given competition or loyalty program;

  • In order to study the market and opinions about us or our partners, i.e. order information, your data provided in the account or when purchasing goods, email address. Data collected as part of market research and opinion polls are not used for advertising purposes. Detailed instructions are provided in the survey information or at the point where you enter your data.

Relevant categories of personal data

The controller of personal data processes the following categories of relevant personal data:

  • Contact details;

  • Website activity data;

  • Data relating to orders on the website;

  • Complaints and requests data;

  • Marketing Services Data.

Voluntary provision of personal data

The provision of the required personal data is voluntary and is a condition for the provision of services by the Personal Data Administrator through the Website.

Data processing time

Personal data will be processed for the period necessary to fulfill orders, services, marketing activities and other services provided to the customer. Personal data will be deleted in the following cases:

  • When the data subject requests their deletion or withdraws the consent granted;

  • When the person concerned does not act for more than 10 years (inactive contact);

  • After obtaining information that the stored data is outdated or inaccurate.

Some data such as: email address, first and last name, may be stored for the next 3 years for the purpose of evidence, handling complaints and claims related to the services provided by the website - these data will not be used for marketing purposes.

Data on orders for paid goods and services, competitions and loyalty programs will be kept for a period of 5 years from the date of delivery of the order.

We store data about customers who are not logged in for a period corresponding to the lifetime of the cookies stored on the devices or until they are deleted on the customer's device by the customer.

Your personal data regarding preferences, behaviors and selection of marketing content may be used as a basis for automated decisions to determine sales opportunities on the website.

Recipients of personal data

We provide your personal data to the following categories of recipients:

  • state authorities, for example the prosecutor's office, the police, the PUODO, the president of the UOKiK, if they ask us,

  • service providers we use to operate the website, for example to fulfill an order.

Rights of the data subject

Under the GDPR (General Data Protection Regulation), you have the right to:

  • Request access to your personal data;

  • Request the rectification of your personal data;

  • Request the deletion of your personal data;

  • Request the limitation of the processing of personal data;

  • Object to the processing of personal data;

  • Request the transfer of personal data.

The personal data controller, without undue delay - and in any case within one month of receiving the request - will inform you of the actions taken in relation to the request you have made. If necessary, the monthly period may be extended by two additional months due to the complexity of the request or the number of requests.

In any case, the personal data administrator will inform you of this extension within one month of receipt of the request, indicating the reasons for the delay.

The right of access to personal data (Article 15 of the GDPR)

You have the right to obtain information from the personal data controller whether your personal data is being processed.

If the administrator processes your personal data, you have the right to:

  • Access personal data;

  • Obtain information on the purposes of the processing, the categories of personal data processed, the recipients or categories of recipients of this data, the planned storage period of your data or the criteria for determining this period, your rights under the GDPR and the right to lodge a complaint with the supervisory authority, the source of this data, automated decision-making, including profiling, and the security measures used in connection with the transfer of this data outside the European Union;

  • Obtain a copy of your personal data.

If you wish to request access to your personal data, please submit your request to: contact@maybella.fr.

The right to rectify personal data (Article 16 of the GDPR)

If your personal data is incorrect, you have the right to request the administrator to immediately correct your personal data.

You also have the right to ask the administrator to complete your personal data.

If you would like your personal data to be corrected or completed, please submit your request to: contact@maybella.fr.

If you have registered on the Website, you can correct and complete your personal data yourself after logging in to the Website.

The right to delete personal data, the "Right to be forgotten" (Article 17 of the GDPR)

You have the right to request the personal data administrator to delete your personal data when:

  • Your personal data are no longer necessary for the purposes for which they were collected or otherwise processed;

  • You have withdrawn your specific consent to the extent that personal data was processed on the basis of your consent;

  • Your personal data has been unlawfully processed;

  • You have objected to the processing of your personal data for direct marketing purposes, including profiling, to the extent that the processing of personal data is related to direct marketing;

  • You have objected to the processing of your personal data as necessary for the performance of a task carried out in the public interest or as necessary for purposes arising from the legitimate interests pursued by the personal data controller or a third party.

Despite the submission of a request for deletion of personal data, the personal data administrator may continue to process your data in order to establish, assert or defend claims against you.

If you wish to delete your personal data, please send your request to: contact@maybella.fr.

The right to submit a request to restrict the processing of personal data (Article 18 of the GDPR)

You have the right to request the limitation of the processing of your personal data when:

  • You question the accuracy of your personal data - the personal data administrator will limit the processing of your personal data for a period allowing verification of the accuracy of such data;

  • Where the processing of your data is unlawful, and instead of deleting personal data, you request the restriction of the processing of your personal data;

  • Your personal data are no longer necessary for the purposes of processing, but are necessary to establish, assert or defend your claims;

  • When you have objected to the processing of your personal data - until it is determined whether the legitimate interests of the personal data controller outweigh the grounds stated in your objection.

If you wish to restrict the processing of your personal data, please submit your request to: contact@maybella.fr.

The right to object to the processing of personal data (Article 21 of the GDPR)

You have the right to object at any time to the processing of your personal data, including profiling, in relation to:

  • Processing necessary for the performance of a task carried out in the public interest or processing necessary for purposes arising from the legitimate interests pursued by the personal data controller or a third party;

  • Processing for direct marketing purposes.

If you wish to object to the processing of your personal data, please submit your request to: contact@maybella.fr.

The right to request the transfer of personal data (Article 20 of the GDPR)

You have the right to receive your personal data via the personal data administrator in a structured and machine-readable format commonly used (computer, mobile phone) and to send them to another personal data administrator.

You can also ask the personal data administrator to send your personal data directly to another administrator (if technically possible).

If you wish to request the transfer of your personal data, please submit your request to the following address: contact@maybella.fr.

The right to withdraw consent

You can withdraw your consent to the processing of your personal data at any time.

Withdrawal of consent to the processing of personal data does not affect the lawfulness of processing carried out on the basis of your consent before its withdrawal.

If you wish to withdraw your consent to the processing of your personal data, please submit your request to: contact@maybella.fr or use the appropriate features in the account.

Complaint to the supervisory authority

If you consider that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.

In Poland, the supervisory body within the meaning of the GDPR is the President of the Personal Data Protection Office (PUODO).

Cookies

General information

When browsing the website, "cookies" are used, hereinafter referred to as cookies, i.e. small text information stored on your terminal device in the context of using the website. Their use is aimed at ensuring the proper functioning of the website pages.

These files allow you to identify the software you are using and customize the website individually according to your needs.

Cookies typically contain the name of the domain they come from, the length of time they are stored on the device, and the assigned value.

Security

The cookies we use are safe for your devices. In particular, it is not possible for viruses or other unwanted software or malware to enter your devices via cookies.

Types of cookies

We use two types of cookies:

  • Session cookies: These are stored on your device and remain there until the end of the browser session. The stored information is then permanently deleted from your device's memory. The session cookie mechanism does not allow the collection of personal data or confidential information on your device.

  • Persistent cookies: These are stored on your device and remain there until deleted. Ending a browser session or turning off your device does not delete them from your device. The persistent cookie mechanism does not allow the collection of personal data or confidential information on your device.

Goals

We also use third-party cookies for the following purposes:

  • Website configuration;

  • Create statistics that help understand how website customers use the website, which allows improving its structure and content through the analytical tools of Google Analytics, whose administrator is Google Inc based in the United States, Google's privacy policy is available under the following links: http://www.google.com/intl/pl/policies/privacy/, http://www.google.com/intl/pl/policies/privacy/partners/;

  • To determine the Client's profile in order to display the corresponding content in advertising networks, using the online advertising tool Google AdSense, whose administrator is Google Inc. based in the United States, Google's privacy policy is available at the following links: http://www.google.com/intl/pl/policies/privacy/, http://www.google.com/intl/pl/policies/privacy/partners/.

  • Determine the Client's profile in order to display the corresponding elements in advertising networks, using the online advertising tool Google Adwords, whose administrator is Google Inc. based in the United States, Google's privacy policy is available at the following links: http://www.google.com/intl/pl/policies/privacy/, http://www.google.com/intl/pl/policies/privacy/partners/.

  • Popularize the website using the social network Facebook.com, whose administrator is Facebook Inc. Based in the United States or Facebook Ireland based in Ireland, Facebook's privacy policy is available at the following link: https://www.facebook.com/help/cookies/.

To learn more about the rules for using cookies, we recommend that you read the privacy policies of the above-mentioned companies.

Cookies may be used by advertising networks, including the Google network, to display advertisements tailored to your preferences. For this purpose, information may be stored about how you browse the web or the time you use the website.

To view and modify information about your preferences collected by the Google advertising network, you can use the tool available at https://www.google.com/ads/preferences/.

By using your web browser settings or by configuring the service, you can change your cookie settings at any time, specifying the conditions for their storage and access to your device. You can adjust these settings to block the automatic management of cookies in your web browser settings or to accept/reject these cookies each time you visit your device. Detailed information on the possibilities and methods for managing cookies is available in your software (web browser) settings.