PRIVACY POLICY

MARION LIMITED LIABILITY COMPANY

§ 1 GENERAL PROVISIONS

  1. We respect and protect the privacy and security of users of our website („Users”). This Privacy Policy („Privacy Policy”) concerns data provided to us via the website https://cosmeticsmarion.com/ („Service”). In this Privacy Policy, we describe what information we collect in connection with the provision of electronic services („Services” or „Service”), the purpose of collecting such information, and how it is used.
  2. The administrator of personal data collected via the Service is Marion Sp. z o.o. with its registered office in Gdynia, ul. Chwaszczyńska 131A, 81-571 Gdynia, KRS 0000064030, email address: naruszenia.rodo@marionkosmetyki.pl – hereinafter referred to as the „Administrator” and also the Service provider.
  3. The term „data processing” used in this Privacy Policy refers to information voluntarily provided by Users, as well as information automatically collected (via „cookies”), and includes all operations performed on personal data, particularly: collecting, recording, storing, processing, modifying, sharing, and deleting, performed in connection with the availability of the Service and the provision of Services. The primary goal of data processing is to optimize the functionality of the Service and the Services so that Users can use them in the simplest and most efficient way.
  4. „Personal data” refers to any information identifying or allowing the identification of a natural person, such as name, surname, email address, phone number, IP address, or other internet identifiers collected via cookies or other similar technologies.

§ 2 DATA PROCESSING

  1. In connection with the use of the Service, the Administrator collects Users’ personal data to the extent necessary to provide the Services offered through the Service, as well as collects information about User activity on the Service. Personal data in the Service is processed by the Administrator in accordance with applicable law, particularly in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as „GDPR”.
  2. Data is processed for the following purposes:
    1. to provide electronic services, including sharing content collected on the Service with Users – the legal basis for processing is the necessity of processing for the performance of a contract (Article 6(1)(b) GDPR). The Administrator also provides a contact form to Users for asking questions, which requires providing personal data necessary for the Administrator to contact the User and respond to the inquiry;
    2. for analytical and statistical purposes – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR), related to the analysis of User activity and preferences to improve the functionalities and Services offered;
    3. to determine, pursue, or defend against claims – the legal basis for processing is the legitimate interest of the Administrator (Article 6(1)(f) GDPR) to protect their rights;
    4. to send marketing communications – the legal basis for processing is the legitimate interest of the Administrator in connection with the User’s consent to receive such content via a specified channel (via phone or email).
  3. Using the Service, including entering into contracts for the provision of Services, is voluntary. Similarly, providing personal data by the User is voluntary. However, if entering into a contract for the provision of Services with the Administrator, failure to provide personal data necessary for entering into and performing the contract will result in the inability to conclude such a contract.
  4. Considering the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of individuals, the Administrator implements appropriate technical and organizational measures to ensure that processing is performed in accordance with the law and can demonstrate this. These measures are reviewed and updated as necessary. The Administrator uses technical measures to prevent unauthorized access to and modification of personal data transmitted electronically.
  5. The Administrator informs that it processes the personal data of Users visiting the Administrator’s profiles on social media (e.g., Facebook, Instagram, YouTube, TikTok). Data provided by Users on the Administrator’s profile is processed for the purpose of informing the User about the Administrator’s activity on the profile (the legal basis is the performance of a contract, Article 6(1)(b) GDPR) and for promoting the Administrator’s services and products (the legal basis is the legitimate interest of the Administrator, Article 6(1)(f) GDPR).

§ 3 COOKIES ON THE SERVICE

  1. The Service uses cookies and similar technologies. Cookies are small text files sent by the server and stored on the User’s device (e.g., computer, laptop, tablet, phone – depending on the device the User is using).
  2. The Administrator may process data contained in cookies when visitors use the Service for the following purposes: a. to display content and improve the quality of Services, b. for analytical and statistical purposes.
  3. By default, the User’s internet browser settings consent to the installation of cookies on their devices. Consent to install cookies can be withdrawn at any time by changing the browser settings.

§ 4 PERIOD OF PERSONAL DATA PROCESSING

  1. In principle, personal data is stored no longer than necessary to achieve the purposes for which it was collected. However, legal provisions may require the Administrator to store it for a longer period. Personal data is processed for the following periods:
    1. during the validity of the contract with the Administrator;
    2. until the User withdraws their consent (if personal data is processed based on the User’s consent);
    3. while addressing a User’s issue directed to the Administrator;
    4. until a valid objection is raised (if personal data is processed based on legitimate interest);
    5. as indicated in legal provisions if such provisions require data retention.
  2. The Administrator also informs that the data retention period may be extended by the period of limitation of claims if the processing of personal data is necessary for the establishment, pursuit, or defense of claims. After this period, personal data will be processed only to the extent and for the time required by law. After the processing period, personal data will be irreversibly deleted or anonymized.

§ 5 DATA RECIPIENTS IN THE SERVICE

  1. The Administrator ensures that personal data is not shared with unauthorized entities. As a rule, the Administrator does not share personal data without the User’s consent. However, as the Administrator uses subcontractors to provide services within the Service, personal data may be entrusted to subcontractors when such entrustment is part of the service provided to the User. Data may also be shared with third parties if required by law (e.g., law enforcement authorities).
  2. The Administrator uses only data processors who provide sufficient guarantees to implement appropriate technical and organizational measures to ensure that processing complies with GDPR and protects the rights of the individuals concerned.
  3. Data is not always transferred to all recipients or categories of recipients listed in this Privacy Policy – the Administrator only shares data when necessary to achieve the specified processing purpose and only to the extent necessary.
  4. Personal data of Service Users may be transferred to the following recipients or categories of recipients:
    1. service providers supplying the Administrator with technical, IT, and organizational solutions enabling the Administrator to conduct business, including the Service and Services provided through it (e.g., software providers, email, and hosting providers);
    2. providers of accounting and advisory services.
  5. With the User’s consent, their personal data may also be shared with other entities for their own purposes, including marketing purposes.

§ 6 TECHNOLOGIES USED ON THE SITE

The Administrator collects information regarding system logs, including data about the device and login, which includes the date, time of visit, and IP address of the device used to connect, as well as data on website traffic and page views. The Administrator and its partners use the following tools and solutions for analytical and marketing purposes:

  1. Google Analytics cookies are used by Google to analyze how Users interact with the Service and create statistics and reports on the Service’s performance.
  2. Google AdWords allows the display of sponsored links in Google search results and on cooperating websites within the Google AdSense program.
  3. Facebook Pixels help measure the effectiveness of advertising campaigns on Facebook.
  4. Social media plugins (Facebook, Instagram) allow Users to share activities from the Service with their friends on social networks.

§ 7 DATA TRANSFER OUTSIDE THE EEA

  1. In principle, the Administrator processes personal data within the European Economic Area (EEA). The Administrator may transfer personal data outside the EEA only when necessary, ensuring appropriate protection in compliance with the law. The Administrator will always inform Users when personal data is to be transferred outside the EEA.
  2. Personal data is not transferred to international organizations.

§ 8 RIGHTS OF USERS WHOSE DATA IS PROCESSED

  1. Users have the right to access their data, rectify it, erase it, restrict processing, and the right to data portability.
  2. Users also have the right to object to the processing of their data based on the Administrator’s legitimate interest or the performance of a task carried out in the public interest.
  3. Users have the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office – if they believe that the processing of their personal data by the Administrator violates GDPR.

§ 9 FINAL PROVISIONS

The current version of the Privacy Policy is effective as of 6th of February 2025.

Contact with the Administrator is possible using the data provided in the first section of this Privacy Policy.

The Privacy Policy is regularly reviewed and updated as needed.