Privacy Policy
This Privacy Policy and Cookie Policy (hereinafter referred to as the "Privacy Policy") applies to all information that the "ampm-store" online store may obtain about the user while using the online store website, programs and products of the company's online store.
Pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data, repealing Directive 95/46/EC (hereinafter referred to as the "GDPR"), Act No. 18/2018 Coll. on the protection of personal data and on amendments and supplements to certain acts, as amended (hereinafter referred to as the "Act on the Protection of Personal Data") and Act No. 452/2021 Coll., on electronic communications, as amended (hereinafter referred to as the "EC Act"), we would like to inform you about the processing of your personal data and cookies.
1. DEFINITION OF TERMS
1.1. The following terms are used in this Privacy Policy:
1.1.1. Data subject: A data subject is an identified or identifiable natural person. An identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or by reference to one or more elements specific to the physical identity of that natural person. The data subject in relation to the website "ampm-store.com" is any natural person who purchases or otherwise uses the website. Data subjects may be customers who purchase goods, registered users who create an account on the website "ampm-store.com", or visitors to the website who browse its content (hereinafter also referred to as "you", "user" or "customer").
1.1.2. Personal data: Any information relating to the data subject (hereinafter also referred to as "data" or "information").
1.1.3. Controller: The entity that alone or jointly with others determines the purposes and means of processing personal data and cookies. The controller of personal data and cookies in relation to the website www.ampm-store.com is Indoor Environment Expert, s. r. o., (from: 10/06/2023); Registered seat: Jarná 1148/6; Košice - Staré Mesto 040 01; (IČO): 55 780 105 (hereinafter referred to as the “controller”).
1.1.4. Purpose of processing personal data, e.g. performance of the contract, management of user accounts, handling of suggestions and complaints, sending commercial communications (so-called “newsletters”), displaying advertisements based on the interests and preferences of customers, etc.
1.1.5. Cookies: Cookies are short text files that a website sends to your internet browser, which then stores them. Most cookies contain a unique identifier, the so-called cookie ID. It is a string of characters that websites and servers assign to the browser that saved the cookie. This allows websites and servers to distinguish and identify individual browsers. Cookies are used to improve the functioning of websites, to evaluate their traffic and to better target marketing activities, they allow the website to record information about your visit, such as the chosen language, etc., so that future visits to the website are easier and more enjoyable for you. Cookies are important because without them, browsing the Internet would be much more difficult. Cookies allow you to better use our website "ampm-store.com" and adapt its content to your needs; they are used by almost all websites in the world. Cookies are useful because they increase the user-friendliness of a repeatedly visited website. Cookies do not cause damage to your terminal device and do not contain viruses, Trojan horses or other malicious software.
1.1.6. Third countries: countries outside the European Economic Area.
1.1.7. IP address: a unique network address of a node in a computer network built using the IP protocol.
2. GENERAL PROVISIONS
2.1. By using the online store website, the user agrees to this Privacy Policy and the terms of processing the user's personal data.
2.2. If the user does not agree to the terms of the Privacy Policy, he must stop using the online store website.
2.3. This Privacy Policy applies only to the website of the online store "ampm-store.com". The online store does not control third-party websites and is not responsible for third-party websites to which the user has access through links available on the website of the online store "ampm-store.com".
2.4. The site administration does not control the authenticity of personal data provided by users of the website of the online store "ampm-store.com".
2.5. The use of our website may also involve other data controllers who process data about you. The privacy policies for these other controllers can be found here:
2.5.1. Google - https://policies.google.com/privacy
2.5.2. Facebook - https://www.facebook.com/privacy/policy
2.5.3. Microsoft - https://www.microsoft.com/sk-SK/privacy/privacystatement
2.5.4. Stripe - https://stripe.com/en-en/privacy
3. Personal data processed
3.1. The controller processes the following personal data:
3.1.1. Customer's name and surname;
3.1.2. Customer's contact telephone number;
3.1.3. Customer's email address;
3.1.4. Customer's billing address (permanent residence address);
3.1.5. Company ID, VAT number or other identification data, if available (for billing purposes);
3.1.6. Payment card or bank account identification data (for payment purposes);
3.1.7. Order data (e.g. date, amount, payment method, delivery address);
3.1.8. Data on returned or complained about goods;
3.1.9. Communication with customers (e.g. emails regarding orders, complaints, questions, suggestions, etc.).
3.2. The online store "ampm-store.com" protects data that is automatically transmitted when viewing advertising blocks and when visiting pages on which the statistical script of the system ("pixel") is installed:
• IP address;
• information from cookies;
• information about the browser (or about another program that provides access to displaying advertising);
• access time;
• the address of the page on which the advertising unit is located;
• the intermediary (address of the previous page).
3.2.1. Disabling cookies may result in the inability to access parts of the website of the online store "ampm-store.com" that require authorization.
3.2.2. The online store collects statistics on the IP addresses of its visitors. This information is used to identify and solve technical problems, to check the legality of financial payments.
3.3. Any other personal data not listed (purchase history, browsers and operating systems used, etc.) are subject to secure storage and non-dissemination, except for the cases specified in paragraphs 5.2. and 5.3. of this Privacy Policy.
4. Legal basis and purposes of processing personal data
Your personal data is processed on the basis of the following legal grounds:
4.1. Processing based on the performance and conclusion of a contract pursuant to Article 6(1)(b) of the GDPR. In order to conclude a contract, we process personal data in the following way:
4.1.1. Account management and order processing - processing is necessary for the performance of a contract to which the customer is a party, or to take steps at the request of the data subject prior to concluding a contract;
4.1.2. Contact details (telephone number, email address) for communication within the framework of the contract performance – sending order confirmation, information about the order status and for communication with the customer;
4.1.3. Information about the payment method, payment card, bank account or payment gateway details;
4.1.4. Processing of personal data for the purposes of processing orders and delivering goods;
4.1.5. Improving customer service – processing of personal data may be justified for the purpose of improving customer service, for example, to provide customer support and resolve complaints;
4.1.6. Operation of a chatbot – data processing is necessary to answer a customer question;
4.1.7. Processing of the contact form – data processing is necessary to answer a customer question;
4.1.8. Processing of withdrawal from the contract - processing is necessary for the purpose of processing the notification of withdrawal from the contract;
4.1.9. Handling complaints - processing of personal data is necessary for handling the complaint;
4.1.10. Processing of data on social networks - processing of data is necessary for answering questions and for customer support.
4.2. Processing based on the legitimate interests of the controller pursuant to Article 6(1)(f) of the GDPR. For the purposes of the legitimate interests of the controller, we process personal data as follows:
4.2.1. Processing of personal data for statistical purposes, such as collecting and analyzing data on e-shop traffic and customer behavior;
4.2.2. Sending commercial communications (newsletter) – data processing for sending marketing information via a communication channel designated by the customer is carried out in accordance with Section 116 of the EC Act;
4.2.3. Data processing on social networks – data processing is necessary for the operator's promotion.
4.3. Processing based on the fulfillment of legal obligations the operator's responsibilities under Article 6(1)(c) of the GDPR. We process personal data based on the fulfillment of the operator's legal obligations, for example:
4.3.1. issuing a tax document (invoice) in accordance with tax regulations;
4.3.2. archiving data on orders and payment transactions for a certain period of time set by law (e.g. up to 10 years in accordance with tax regulations);
4.3.3. compliance with obligations in the field of consumer protection and business conditions;
4.3.4. compliance with obligations related to complaints, returns of goods, etc.
5. Methods and conditions of processing personal data
5.1. The processing of the user's personal data is carried out without time limitation by any lawful means and also in personal data information systems with the use of automation tools or without the use of such tools:
5.1.1. during the period necessary to fulfill a legal obligation under the relevant tax regulations;
5.1.2. to protect the rights and legitimate interests of the operator, in particular to assert or defend claims against them at least for the duration of the relevant limitation periods;
5.1.3. during the period until the consent to the processing of personal data for marketing purposes is withdrawn, if the personal data is processed on the basis of consent.
5.2. The user agrees that the administration of the website "ampm-store.com" has the right to transfer personal data to third parties, in particular suppliers, courier services, transport companies, postal organizations, telecommunications operators solely for the purpose of fulfilling the user's order placed on the website of the online store "ampm-store.com", including the delivery of goods. We may provide your personal data to affiliated persons.
5.3. The user's personal data may be transferred to authorized state authorities of the state only for the reasons and in the manner established by the legislation of the given state.
5.4. The operator collects service records, but does not link them with personal data in any way. Log files can be used to create statistics that help in managing the website. Summary reports in the form of these statistics do not contain identification features of website visitors.
5.5. In providing our services, we use technical solutions offered by entities that may process personal data outside the European Economic Area (EEA), such as Google, Facebook, YouTube, Instagram, Pinterest and others.
5.6. Any transfer of personal data to countries outside the European Economic Area, including onward transfers of personal data from the third country in question or from the international organisation in question to another third country or another international organisation, shall only take place in strict compliance with the protection of personal data within the meaning of Art. 6(1) GDPR and Art. 44 to 50 GDPR. This includes ensuring an adequate level of data protection by means of approved safeguards, adequacy decisions of the Commission or specific exceptions in cases where the data subject gives explicit consent, it concerns the performance of a contract, important public interests, the defence of legal claims or the protection of vital interests. The supervisory authorities monitor and approve these transfers to ensure compliance with the standards of personal data protection.
5.7. In the event of loss or disclosure of personal data, the site administration shall inform the user of the loss or disclosure of personal data.
5.8. The site administration shall take the necessary organizational and technical measures to protect the user's personal data from unauthorized or accidental access, destruction, modification, blocking, copying, dissemination, as well as from other unlawful actions of third parties.
5.9. The site administration, together with the user, shall take all necessary measures to prevent losses or other negative consequences caused by the loss or disclosure of the user's personal data.
6. Information on the obligation to provide data and the consequences of failure to provide personal data
6.1. The provision of personal data is voluntary, but if the provider does not provide it, it will not be able to perform the requested actions, conclude a contract with you, provide you with relevant services, send you the requested business information or otherwise communicate with you in this regard based on your request. The provision of data necessary for issuing an invoice is a legal obligation, resulting from Section 74 of Act No. 222/2004 Coll. on Value Added Tax, as amended.
6.2. If you are an intermediary, agent or contact person acting on behalf of or in the interest of the data subject with whom the operator concludes a contract, the provision of your personal data is also voluntary, but at the same time necessary for the conclusion and performance of the contract between the operator and the data subject whom you represent or in whose interest you otherwise act.
6.3. Provision of personal data ov based on consent to the processing of personal data is always voluntary. Failure to provide (failure to grant consent or withdrawal of consent) does not have any sanctioning consequences.
7. Rights of data subjects
In connection with the processing of your data, you have the right to:
7.1. access to your personal data (further information in Article 15 GDPR);
7.2. rectification of personal data (further information in Article 16 GDPR);
7.3. erasure of personal data (further information in Article 17 GDPR);
7.4. restriction of processing of personal data (further information in Article 18 GDPR);
7.5. portability of personal data (further information in Article 20 GDPR);
7.6. to object to the processing of personal data (further information in Article 21 GDPR);
7.7. withdraw consent to the processing of personal data at any time without affecting the lawfulness of the processing carried out before its withdrawal - if the processing is based on the consent granted to the controller, in the cases and under the conditions set out in the GDPR. The data subject may exercise the rights referred to in points a) to g) by contacting the controller using the contact details provided in the header of this information (further information in Article 7(3) GDPR).
8. Right to lodge a complaint with a supervisory authority
8.1. In connection with the processing of your personal data, you have the right to file a complaint with the Personal Data Protection Office, located at Hraničná 4826/12, 820 07 Bratislava 27, Slovak Republic, tel.: 02/323 132 14, website: https://dataprotection.gov.sk/uoou/, if you believe that your right to personal data protection has been violated.
9. Automated individual decision-making with legal or similar effects, including profiling
9.1. Profiling means any form of automated processing of personal data which uses personal data to evaluate certain personal aspects of a natural person, in particular for statistical purposes, to analyze or predict aspects relating to the performance of a natural person. You agree and acknowledge that our E-shop may carry out automated individual decision-making, including profiling, based on your personal data, in accordance with Art. 22 GDPR. This profiling is done exclusively to collect statistical information and analyses aimed at improving and customizing our services and offer (more information in Art. 22 GDPR).
10. Cookies
10.1. Types of cookies:
10.1.1. Temporary cookies allow us to link your individual activities while browsing this website. These cookies are activated when you open a browser window and deactivated when you close the browser window. In the case of temporary cookies, all these files are deleted when you close the browser.
10.1.2. Persistent cookies help to identify your computer when you visit our website again. Another advantage of persistent cookies is that they allow us to tailor our website to your specific needs.
10.2. In accordance with Section 111 of the EC Act, we hereby inform you that our website uses cookies for its operation. This means that cookies are stored in accordance with the conditions set out in the EC Act and your cookies, including persistent cookies, and the personal data they collect are processed by us in accordance with the conditions set out in the GDPR and the Personal Data Protection Act.
10.3. The processing of cookies serves the following purposes:
10.3.1. Technically necessary cookies are a basic type of cookies that are necessary for the proper functioning of the website and enable basic functions such as navigating between pages, logging into your account, saving items in the shopping cart, displaying website content, etc. These cookies do not require your consent and are always allowed;
10.3.2. Preference cookies are another type of cookie that collects information about the user's preferences on a website, such as language preferences or display settings. These cookies allow websites to provide users with personalized content and improve the overall user experience. Preference cookies do not require your consent if they are used solely to store your choices, such as language preferences on a website;
10.3.3. Statistical cookies collect information about how users use websites, such as how much time they spend on the site, which pages they visit most often, etc. This information helps to optimize the performance and functionality of the website. These cookies do not require your consent;
10.3.4. Marketing cookies are used to display personalized advertising on the website. These cookies can be used to track your browsing of the website and collect information about your interests in order to make advertising as relevant as possible. These cookies require your consent;
10.3.5. Social cookies allow you to share content from the website on social networks and allow you to interact with content from different social networks. These cookies require your consent.
10.4. The legal basis for the use of marketing cookies is your consent pursuant to Article 6(1)(a) of the GDPR. The legal basis for the use of technically necessary cookies, preference cookies and statistical cookies is Article 6(1)(f) of the GDPR, i.e. we process your data based on the legitimate interests of the controller and pursuant to Article 6(1)(b) of the GDPR, i.e. to conclude a contract.
10.5. You can withdraw/change your consent at any time with future effect without affecting the lawfulness of the processing carried out before the withdrawal of consent.