Privacy Policy
1. Data Controller and Contact Details
The controller of your personal data is:
Tijara Essence s.r.o.
Company ID / VAT ID: CZ23592087
Registered office: Soukenická 877/9, Moravská Ostrava, 702 00 Ostrava
Czech Republic
For matters relating to data protection, please contact us at: biuro@aromaflav.com
2. Categories of Personal Data and Sources
We process the following categories of personal data:
- identification, contact and address details,
- user account data,
- order-related data, including payment identifiers,
- logistics data, including shipment numbers and delivery statuses,
- statements and consents, including acceptance of terms and conditions,
- technical logs, including IP addresses, device identifiers and timestamps,
- data collected through cookies and SDKs.
Personal data is obtained directly from the Customer, from payment systems, from carriers and from the Customer's device through cookies and SDKs.
3. Purposes and Legal Bases for Processing
- Performance of a contract, including registration, processing purchases, payments, deliveries, returns and complaints – Article 6(1)(b) GDPR.
- Compliance with legal obligations, including accounting, tax settlements, the OSS procedure, archiving, product safety and cooperation with public authorities – Article 6(1)(c) GDPR.
- Age verification, fraud prevention and the establishment, exercise or defence of legal claims – Article 6(1)(c) and (f) GDPR.
- Communication relating to public-law obligations, for example reminders concerning formal requirements, as part of order processing – Article 6(1)(b) and (c) GDPR.
- Analytics and personalisation – based on consent pursuant to Article 6(1)(a) GDPR or on the legitimate interests of the Controller pursuant to Article 6(1)(f) GDPR, with due regard to applicable privacy laws.
- Maintenance and security of the Service, including logging, fraud prevention and testing – Article 6(1)(f) GDPR.
4. Recipients of Personal Data
Personal data may be disclosed to:
- payment service providers,
- logistics operators and carriers,
- hosting and IT service providers,
- CRM and customer service system providers,
- accounting firms,
- law firms,
- analytics tool providers,
- competent public authorities where required by law, including tax and customs authorities.
5. Transfers of Personal Data Outside the European Economic Area (EEA)
If our service providers are established outside the European Economic Area, we ensure that appropriate legal safeguards are in place for the transfer of personal data, including the European Commission's Standard Contractual Clauses, and we apply appropriate security measures.
A copy of the safeguards applied may be obtained by contacting us.
6. Data Retention Periods
- Account data and purchase history – for the duration of the use of the account and thereafter for the period required by accounting regulations and applicable limitation periods for legal claims.
- Tax data and records retained for the purposes of the OSS procedure – in accordance with applicable regulations, generally for 10 years from the end of the relevant tax year.
7. Rights of Data Subjects
You have the following rights:
- the right of access to your personal data,
- the right to rectification,
- the right to erasure,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing,
- the right to withdraw consent at any time.
The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
You may lodge a complaint with the Polish Personal Data Protection Office (UODO) or with the supervisory authority competent for your place of residence.
8. Automated Decision-Making and Profiling
We do not make decisions that produce legal effects solely on the basis of automated processing of personal data.
We may use profiling for analytics purposes and to personalise our offer. You have the right to object to such processing at any time.
9. Cookies and Similar Technologies
The Service uses cookies and similar technologies, such as local storage, to ensure the proper functioning of the Service and to analyse website traffic.
We use a consent management mechanism in the form of a cookie banner, which allows users to choose between the following categories:
- Necessary,
- Analytics.
Cookie settings can be changed in the footer of the website.
Data collected through cookies may be linked to a user's account after login only on the basis of the consents provided.
10. Security and Data Breach Notification
We apply appropriate technical and organisational measures, including encryption, access controls, pseudonymisation and security testing.
In the event of a personal data breach, we act in accordance with the requirements of the GDPR. Where there is a high risk to the rights and freedoms of individuals, we inform the affected data subjects.
11. Changes to this Privacy Policy and Contact
We reserve the right to update this Privacy Policy. We will notify users of material changes through the Service and, where possible, by email.
For matters relating to the protection of personal data, please contact us at:
biuro@aromaflav.com