INFORMATION ON THE PROCESSING OF PERSONAL DATA
The protection of your personal data is important to us, which is why we process them in accordance with applicable legislation. Below we provide information on which personal data we obtain, for what purpose it is used and other useful information regarding its processing.
- General information
- Identity and contact details of the Operator The person is responsible for the protection of personal data
- Samir Osmanovič – POSTERMA
8. mája 909/19, 927 01 Šaľa
IČO: 47786418
DIČ: 1086842482
Registered in ŽRSR: District Office Šaľa,Trade register number: 450-12701
(hereinafter referred to as the “Operator”), which is the operator of the online store www.posterma.sk Contact details of the responsible person of the Operator
E-mail: info@posterma.sk
Adress: 8. mája 909/19, 927 01 Šaľa.
- For what purpose, what personal data do we process and on what legal basis and for how long?
As the Operator, we process your personal data for different purposes, on the basis of different legal bases and for different periods of time. The provision of common personal data is a requirement that in some cases is necessary to conclude a contract, e.g. if you do not provide us with your name, billing address, delivery address and contact information, we will not be able to deliver the shipment to you. You, as the person concerned, are obliged to provide the personal data necessary to achieve the stated purpose. Failure to provide this personal data would result in the impossibility of entering into a contractual relationship with us – the Operator.
WE PROCESS DATA OF BUSINESS PARTNERS AS FOLLOWS:
Purpose: business cooperation with the business partners of the Operator, we need your data to conclude and fulfill the contract, implement business cooperation, process payment, answer your questions, or perform other related activities. Data: ordinary personal data, i.e. name, surname, phone number, e-mail and payment details. Legal basis: pre-contractual and contractual relationship, we process the personal data of our business partners in accordance with Art. 6 par. 1 letter b) GDPR and in accordance with sec. § 13 par. 1 letter b) of the Act. The legal basis is therefore the processing of personal data necessary for the performance of a contract to which the affected person (You as a business partner) is a party, or to take measures before concluding a contract based on the request of the affected person (You as a business partner), a pre-contractual relationship. Processing period: 10 years after termination of the contractual relationship.
ÚDAJE ZÁKAZNÍKOV SPRACOVÁVAME NASLEDOVNE:
Purpose: providing services to customers through www.posterma.com, we need your data to conclude and fulfill a purchase contract, process payment, deliver the product, answer your questions, or perform other related activities (e.g. complaints procedure). Data: ordinary personal data, i.e. first name, last name, billing address, delivery address, telephone number, e-mail and payment information. Legal basis: pre-contractual and contractual relationship, we process your personal data in accordance with Art. 6 par. 1 letter b) GDPR and in accordance with sec. § 13 par. 1 letter b) of the Act. The legal basis is therefore the processing of personal data necessary for the performance of a contract to which the affected person (You as the buyer) is a party, or to take measures before concluding the contract based on the request of the affected person (You as the buyer), a pre-contractual relationship. Processing period: 10 years after termination of the contractual relationship.
Purpose: direct marketing, data necessary for the purposes of legitimate interests pursued by the Operator – promotion of the e-shop and website www.posterma.sk and implementation of direct marketing, i.e. marketing that goes from us (the Operator) directly to you (our clients). Data: ordinary personal data, i.e. name, surname, address, telephone number, e-mail. Legal basis: legitimate interest, we process your personal data in accordance with Art. 6 par. 1 letter f) GDPR and in accordance with sec. § 13 par. 1 letter f) of the Act. The legal basis is therefore our legitimate interest as a seller due to the promotion of our goods to our customers. Processing period: 10 years after termination of the contractual relationship. Lesson learned: Every customer can object to direct marketing, as a result no services or goods will be offered to them. Purpose: tracking satisfaction with the purchase in the form of a satisfaction questionnaire (Heureka), data necessary for the purposes of legitimate interests monitored by the Operator – customer satisfaction and promotion of the e-shop and the website www.posterma.com. Data: ordinary personal data, i.e. information about purchased goods, e-mail. Legal basis: legitimate interest, we process your personal data in accordance with Art. 6 par. 1 letter f) GDPR and in accordance with sec. § 13 par. 1 letter f) of the Act. The legal basis is therefore our legitimate interest in the position of the seller due to monitoring satisfaction with the purchase in the form of a satisfaction questionnaire (Heureka). Processing time: 4 years after filling out the satisfaction questionnaire. Instruction: You can withdraw your consent to the publication of your purchase evaluation on the Heureka.sk portal at any time at the address gdpr@heureka.cz or info@posterma.com.
In the event that the affected person (buyer or our customer) has given the given consent: Purpose: account registration and use of the loyalty program via www.posterma.sk, i.e. if you have given the Operator consent to the processing of your personal data for this purpose/by clicking opt-in. As part of the loyalty program, after registration, your completed orders will be added up and based on them, a discount will be deducted from the purchase that is the subject of the current order in accordance with the current conditions of the loyalty program. Data: ordinary personal data, i.e. first name, last name, billing address, delivery address, phone number, e-mail, payment information, login name, order information. Legal basis: express consent, we process your personal data in accordance with Art. 6 par. 1 letter a) GDPR and in accordance with sec. § 13 par. 1 letter a) of the Act. The legal basis is therefore the processing of personal data only on the basis of your consent and on the basis of your interest in registration and the loyalty program. Of course, you can also shop in our online store without registration.
Processing time: 1 year after canceling the registration of your account within our e-shop, or after withdrawing consent. Advantages of registration: Registration is not required for your purchase, if you decide to purchase through registration, we will process your personal data as follows: Through your account, you can get information about your orders, you can manage your personal data. You protect your account with a password. The Operator is not responsible for its misuse. Personal data from your account will be evaluated and collected for the purpose of using the services. If you create an account, we will use access to the account if you ask us to reset your password. By accepting cookies, you give us your consent to evaluate your shopping behavior (that is, which products you bought, which products you viewed), your user behavior on the website www.posterma.sk will be assigned to your customer account, so that we can provide you with a personalized content (eg special events and information). If, however, you have changed your mind and do not want to continue to be registered, you can cancel the registration in your account, or delete account. You can shop at www.posterma.sk at any time even as an unregistered buyer, i.e. a guest.
Purpose: monitoring and evaluating the behavior of visitors to our e-shop www.posterma.com,
Data: cookie files, i.e. small text files containing the name of the page visited, validity and a predefined value. They are saved in the folder of your browser. When you revisit the website that created the file, the browser may resend it. The cookies we use do not damage your computer or other devices used for internet browsing. Legal basis: consent, we process your personal data in accordance with Art. 6 par. 1 letter a) GDPR and in accordance with sec. § 13 par. 1 letter a) of the Act. The legal basis is therefore the processing of personal data only on the basis of your consent and on the basis of your setting of your web browser. Processing time: 1 year after canceling the registration of your account within our e-shop. Purpose: registration of the rights of the affected persons, we need your data in order to be able to register your suggestions in accordance with the GDPR and the Personal Data Protection Act. Data: ordinary personal data, i.e. name, surname, address, telephone number, e-mail and payment details, subject of the service provided, scope of exercise of rights. Legal basis: legitimate interest, we process your personal data in accordance with Art. 6 par. 1 letter f) GDPR and in accordance with sec. § 13 par. 1 letter f) of the Act. The legal basis is therefore the legitimate interest of us, in the position of the seller, due to the exercise of your rights. Processing time: 5 years from the date of resolution of the request of the person concerned. Instruction: Every customer can object to the data processed as part of the complaint procedure.
Unstructured data Of course, we also process ordinary data in the form of unstructured data located in e-mail boxes and in technical devices that are processed for the purpose of carrying out business activities (legal basis is the legitimate interest of the Operator). The operator, that is, we process them for 1 year. Then we delete unnecessary things and get things in order.
- More information about the use of your cookies by our company What are cookies? Cookies are small text files that can be sent to the Internet browser when visiting websites and stored on your device (computer or other device with Internet access, such as a smartphone or tablet). Cookies are stored in the file folder of your browser. Cookies usually contain the name of the website from which they originate, their validity and value. The next time you visit the page, the web browser reloads the cookie files and sends this information back to the website that originally created the cookies. The cookies we use do not damage your computer.
Why do we use cookies? Cookies allow us to remember your preferences and actions (for example, login data, data about your order in the shopping cart). We use them in order to optimally create and constantly improve the quality of our services, adapt them to your interests and needs and improve their structure and content. Temporary and permanent cookies can be used on the website www.posterma.com.
CoCookies are used on the website www.posterma.com for the purpose of:
- the functioning of websites, measuring website traffic and creating statistics regarding traffic and visitor behavior on websites,
- advertising customization and targeting, if you have given your consent; it is the so-called automated profiling, in which we analyze your usual personal data and activities in the online environment, on the basis of which we can provide you with information that is interesting and relevant to you,
- re-targeting if you have consented to it.
Collection of cookies for the purposes specified in letter a) cannot be considered as the processing of personal data, as these cookies are considered in the form of a collective whole and thus in an anonymous form that does not allow the identification of an individual. Collection of cookies for purposes according to letter b) and letter c) can be considered as processing of personal data, as they are processed for the purposes of customization and targeting of advertising and for retargeting. These personal data are processed on the basis of your consent, or based on your web browser settings. You grant consent for the period indicated in the table below. Consent to the collection of cookie data for marketing purposes can be withdrawn at any time by changing the settings of the relevant internet browser.
DruTypes of cookies we use:
- Basic allows the use of basic functions such as logging in as a registered user or pre-filling forms. If you disable these cookies, we cannot guarantee the full functionality of our website.
- Operational cookies are used to analyze visitor behavior on the website and subsequently to improve its functionality and appearance. If you disable these cookies, we cannot guarantee the full functionality of our website.
- Advertising fees are used to optimize the displayed advertisement in view of the visitor’s habits and the effectiveness of the marketing communication of the submitters. Thanks to them, for example, you will not be shown unnecessarily often advertising from an area you are not interested in. You can block or delete this type of cookies at any time by adjusting the settings of the cookie files in your browser (Instructions for blocking them can be found below).
- Third-party cookies are created and used by service providers such as Google Analytics, Google Ads (formerly Google AdWords), or Facebook. These services are integrated into our site because we consider them useful and completely safe. In the case of such linking and integration of content from other websites, cookies may be created during the use of our website, which are not subject to our control as the Operator. If you want to know how these third parties use cookies, read the privacy policy and cookie policy of these services.
On our website, we process the following cookies with the stated purposes and processing time:
Basic, operational cookies Title Purpose Maximum processing time Google Analytics Obtaining statistical information for routine analysis of web traffic and its improvement according to the setting, or the way of using the internet browser
Advertising cookies Title Purpose Maximum processing time Google Analytics Identification within the Google advertising network (profiling) according to the setting, or the way of using the internet browser Google Ads Identification within the Google advertising network, retargeting of advertising (retargeting) 540 days Facebook pixel Identification within the Facebook advertising network, retargeting of advertising 180 days Instagram Identification within Instagram’s advertising network, retargeting 180 days
Setting cookies: Web browsers (Internet Explorer, Mozilla Firefox, Google Chrome, etc.) support cookie management. Within the web browser settings, you can manually delete individual cookies, block or completely prohibit their use, or block or enable them only for individual websites. However, in such a case, we cannot guarantee that all areas of our sites will retain their intended function. Instructions for blocking and deleting cookies from the most commonly used browsers: Most internet browsers are initially set to automatically accept cookies. If you do not want to use cookies, you can change this setting by blocking cookies or by notifying you if cookies are to be sent to your device. If you use different devices to access the pages (e.g. computer, smartphone, tablet), we recommend that each browser on each device be adapted to your cookie preferences. You can delete cookies in the browser individually or all at once, either directly (if you know where they are stored) or using the browser.
individual instructions can be found at:
- Mozilla: https://support.mozilla.org/sk/kb/povolenie-zakazanie-cookies
- Chrome: https://support.google.com/chrome/answer/95647?hl=sk
- Explorer: https://support.microsoft.com/en-us/help/17442
- Opera: help.opera.com
- Safari: support.apple.com
- Who else processes your personal data? If it is necessary for the proper performance of the contract or if you have given express consent, during the processing of the order and the performance of the purchase contract, your personal data is also provided to third parties:
- To companies providing the transport of ordered goods directly to our customers,
- An expert external consultant in the areas of IT, marketing and personal data protection,
- To the companies ensuring the realization of the payment,
- To the companies we use for profiling and setting up marketing actions,
- Heureka.sk company when determining your satisfaction with the purchase.
- What if you are under 16? Our company, as the Operator, in connection with the offer of information society services, processes personal data based on the consent of the person concerned, legally, if the person concerned has reached the age of 16. However, our e-shop is not directly intended for persons under the age of 18. Our company does not process personal data of persons under the age of 16. At each registration/login, the Operator requests a sworn statement from the buyer that he is over 16 years of age.
- We do not transfer personal data to third countries Our company does not intend to transfer personal data to a third country or international organization, including the identification of the country or international organization.
- How do we work with your IP address? An IP address is a set of numbers that uniquely identifies a device in a computer network. From the point of view of personal data protection, it can be characterized as data relating to an identifiable person. The IP address is transmitted when you enter your every request to the server, thanks to which the server has information about where the response to your request should be sent. For this purpose, the IP address is assigned to you by the Internet connection provider at the moment you connect to the Internet. The Internet service provider can trace which customer was assigned a selected IP address at a certain moment. IP addresses are not permanently stored by us or by our statistical service providers, but are used in anonymized form exclusively for the purpose of determining the place where the server’s response to your request should be sent, as well as for the purpose of preventing possible hacker attacks.
- We guarantee secure data transfer Your personal data is transmitted securely thanks to encryption. We use the SSL (Secure Socket Layer) coding system, which is most often used for secure communication with web servers. Personal data in our systems as well as the website are secured by appropriate technical and organizational measures against loss, destruction, alteration and further dissemination of data by unauthorized persons. If you are registered on our website www.posterma.com, only you have access to your account, so make sure that you handle this data confidentially. The operator is not responsible for unauthorized loading or misuse of the password.
- What are your rights in connection with the protection of personal data? As a buyer, you have the following rights in terms of GDPR: and, the right to rectification, b, the right to erasure, c, the right to data portability, d, the right to object, e, the right to withdraw consent, f, the right to access information, g, the right to file a motion to initiate proceedings.
a) Right to rectification You have the right for the Operator to correct incorrect personal data relating to you without undue delay and, if they are incomplete, for the Operator to supplement them.
b) Right to erasure Your personal data will be deleted without undue delay if any of the following reasons are met:
- personal data are no longer necessary for the purpose for which they were obtained or processed,
- the person concerned revokes consent to the processing of personal data for at least one specific purpose (see paragraph 13 letter e) Right to revoke consent),
- the consent of the person concerned is invalid if its provision is excluded by a special regulation,
- the data subject objects to the processing of personal data and there are no valid reasons for the processing of personal data or the data subject objects to the processing of personal data and it concerns direct marketing, including profiling,
- personal data is processed illegally,
- the reason for erasure is the fulfillment of an obligation according to the Act, a special regulation or an international treaty to which the Slovak Republic is bound, or
- personal data was obtained in connection with the offer of information company services (the person concerned is under 16 years old). If the Operator has published personal data and is obliged to delete it, it is also obliged to take adequate security measures, including technical measures, taking into account the available technology and the costs of their implementation, in order to inform other operators (or intermediaries) who process the personal data of the person concerned about her request that these operators (or intermediaries) delete links to her personal data and their copies or write-offs.
c) Right to data portability You have the right to receive personal data concerning you that you have provided to the Operator in a structured, commonly used and machine-readable format, and you have the right to transfer this personal data to another operator – a seller, if it is technically possible and if:
- personal data is processed on the basis of your consent, on the basis of a contract and on the basis of your consent, which is invalid if its provision is excluded by a special regulation,
- the processing of your personal data is carried out by automated means.
d) The right to object You have the right to object at any time to the processing of your personal data for the purpose of direct marketing, including profiling. If we process your personal data to secure our legitimate interests, you can also object (reject) to this processing. In such a case, we can process your personal data only if we prove the existence of necessary legitimate reasons that outweigh your interests, rights and freedoms, or if these data are necessary for proving, exercising or defending legal claims.
e) Withdrawal of consent If the processing of personal data is based on your consent, you have the right to withdraw your consent to their processing at any time. The withdrawal of consent is effective until the future. Withdrawal of consent does not affect the lawfulness of personal data processing based on consent prior to its withdrawal. You can revoke your consent in the same way you gave your consent, e.g. by e-mail sent to the address: info@posterma.sk or by post to the address: Samir Osmanovič – POSTERMA 8.Mája 909/19, 927 01 Šaľa
If you are registered on the website www.posterma.com, you can delete your account at any time. You can unsubscribe from the newsletter via the unsubscribe link located in the footer of the newsletter or by setting the unsubscribe in your account.
f) Right of access to information You have the right to obtain confirmation from the Operator as to whether it is processing your personal data. If the Operator processes such personal data, you have the right to access this personal data and information about:
- the purpose of processing personal data,
- category of processed personal data (the Operator only processes ordinary personal data),
- the identification of the recipient or the category of recipient to whom the personal data have been or are to be provided, in particular the recipient in a third country or an international organization, if possible,
- period of storage of personal data; if this is not possible, information on the criteria for its determination,
- the right to request from the Operator the correction of personal data concerning you, their deletion or restriction of their processing, or the right to object to the processing of personal data,
- just file a motion to initiate proceedings,
- sources of personal data, if the personal data were not obtained from you,
- the existence of automated individual decision-making, including profiling, in these cases the Operator will provide you with information in particular about the procedure used, as well as about the meaning and expected consequences of such processing of your personal data. Based on your request, the operator is obliged to provide information within 30 days of receiving the request. The Operator can extend this deadline by another 60 days, we will inform you about the postponement.
g) The right to file a motion to initiate proceedings If you are directly affected by your rights, you have the right to file a motion to initiate proceedings pursuant to § 100 of the Act. The proposal must contain: who submits it, against whom the proposal is directed, the subject of the proposal with an indication of the rights that should have been violated during the processing of personal data, evidence. The proposal must be sent to the Office for the Protection of Personal Data, with headquarters at Hraničná 12, 820 02 Bratislava. The Office assesses the initiative within 30 days, makes a decision within 90 days, or may extend the deadline accordingly.
- Did you not find all the information you are interested in? Contact us: info@posterma.sk. Your posterma.com team Version valid and effective from: 11/11/2022