Privacy Policy
PRIVACY AND PERSONAL DATA PROCESSING POLICY
Becker Polska Piotr Namedyński - dangbei.pl online store
1. Data Controller
The Controller of personal data is Becker Polska Piotr Namedyński, VAT ID (NIP): 1250994953, National Business Registry No. (REGON): 142181939, registered address: Wierna 24/U10, 03-890 Warsaw, Poland, contact address and principal place of business: Bukowiecka 92/305, 03-893 Warsaw, Poland, hereinafter referred to as the “Controller”.
Contact details for matters concerning the processing of personal data:
- e-mail: info@dangbei.pl
- telephone: +48 608 333 880
- contact address: Bukowiecka 92/305, 03-893 Warsaw, Poland
2. Scope of this Policy
This Policy applies to personal data processed in connection with:
- using the dangbei.pl online store and its functionalities,
- creating and managing a customer account,
- placing and fulfilling orders, payments and deliveries,
- contacting the store, submitting enquiries and receiving offers,
- handling returns, withdrawals from contracts, complaints, warranties and service requests,
- subscribing to the newsletter or consenting to other forms of electronic marketing,
- publishing reviews and using product recommendation features,
- relationships with business partners, their employees, representatives and contact persons.
3. Categories and sources of data
Depending on how the store is used, the Controller may process in particular:
- identification and contact data, including first name, surname, company name, VAT ID (NIP), address, e-mail address and telephone number,
- data concerning the account, orders, payments, deliveries, returns, complaints and contact history,
- data required to issue and retain accounting and tax documents,
- technical data, such as the IP address, session identifiers, information about the device, browser, operating system, logs and activity on the website,
- data provided in messages, forms, service requests, photographs, videos and attachments,
- data concerning consents, their scope, the date on which they were given and withdrawn.
Data is obtained directly from the data subject or from the person placing an order, a business partner, a sales platform, a payment operator, a carrier, an IT system provider or publicly available registers where this is necessary to manage a B2B relationship. In such cases, the scope of the data is limited to what is necessary for the relevant purpose.
4. Purposes, legal bases and retention periods
| Purpose of processing | Scope of data | Legal basis | Retention period |
|---|---|---|---|
| Use of the website, ensuring its operation and security, and diagnosing errors | technical data, logs, IP address, device and session information | Article 6(1)(f) GDPR - the legitimate interest of ensuring the operation and security of the website; for the necessary storage of or access to information on a device, also Article 399(3) of the Polish Electronic Communications Law (PKE) | for the period necessary to ensure security, carry out diagnostics and protect against abuse, and subsequently until the applicable limitation period for claims expires |
| Creating and managing a customer account and providing electronic services | registration data, login data, account history and order history | Article 6(1)(b) GDPR - performance of a contract for the provision of electronic services | until the account is deleted or the service ends, and subsequently for the period necessary to establish, pursue or defend claims |
| Accepting and fulfilling an order, payment and delivery | identification, contact, address, transaction and settlement data | Article 6(1)(b) GDPR - entering into and performing a contract; Article 6(1)(c) GDPR - compliance with legal obligations | for the duration of the contract and subsequently for the period required by tax and accounting regulations and until the limitation period for claims expires |
| Handling enquiries, negotiations and offers | contact data and the content of correspondence | Article 6(1)(b) GDPR - steps taken prior to entering into a contract, or Article 6(1)(f) GDPR - handling communications and maintaining business relationships | until the matter is concluded and subsequently for the period necessary to document the course of the contact and defend claims |
| Returns, withdrawals, complaints, warranties and servicing | customer data, order and device data, serial number, fault description, photographic or video documentation and settlement data | Article 6(1)(b) GDPR - performance of a contract; Article 6(1)(c) GDPR - compliance with statutory obligations; Article 6(1)(f) GDPR - establishing and defending claims | until the matter is concluded, and subsequently for the period required by law and until the applicable limitation period for claims expires |
| Accounting, taxation and settlement documentation | data contained in invoices and other accounting documents | Article 6(1)(c) GDPR - compliance with legal obligations | for the period required by tax and accounting regulations |
| Pursuing, establishing and defending claims and preventing abuse | data relating to the transaction, contact, payment and course of the matter | Article 6(1)(f) GDPR - the Controller's legitimate interest | until the matter is finally concluded or the applicable limitation period for claims expires |
| Newsletter and marketing conducted by e-mail, SMS or other electronic channels | e-mail address, telephone number, information about consent and interactions with messages | Article 6(1)(a) GDPR - consent; Article 398 PKE - prior consent to use the relevant communication channel | until consent is withdrawn or the relevant marketing activity ends; information about consent and its withdrawal may be retained for the period necessary to demonstrate compliance and defend claims |
| Analytics, personalisation, recommendations and advertising based on cookies or similar technologies | online identifiers and information about activity and preferences | Article 6(1)(a) GDPR and Articles 399(1) and 400 PKE - consent, unless the technology is necessary to provide a service explicitly requested by the user | until consent is withdrawn or for the lifetime of the relevant identifier specified in the cookie settings panel |
| Managing relationships with business partners and their representatives | business data, job title, contact data and the content of contracts and correspondence | Article 6(1)(b) GDPR - where the person is a party to the contract; Article 6(1)(f) GDPR - entering into and performing contracts and maintaining business contacts | for the duration of the cooperation, and subsequently for the period required by law and until the limitation period for claims expires |
5. Voluntary and mandatory provision of data
Providing data is generally voluntary. However, certain data is necessary to enter into and perform a contract, process a payment, arrange delivery, handle a complaint, issue an accounting document or provide a response. Failure to provide required data may make these activities impossible. Consent to marketing and to analytical or advertising tracking technologies is voluntary and is not a condition of making a purchase.
6. Recipients of data
Data may be disclosed, only to the extent necessary for the relevant purpose, to the following categories of recipients:
- IAI S.A., operating under the IdoSell brand, and other providers of hosting, infrastructure, software, IT services, backups and technical support,
- payment operators, banks and entities offering instalment payments, deferred payments or leasing,
- carriers, logistics operators, collection points and entities handling shipments,
- the accounting office, providers of accounting systems and entities supporting tax settlements,
- providers of customer service, communication, newsletter, SMS, review and survey systems,
- providers of analytical and advertising tools - solely to the extent resulting from the service configuration and the user’s consents,
- the manufacturer, importer, authorised service centre, insurer or protection-plan operator where necessary to handle a warranty, repair, complaint or device protection,
- law firms, advisers, auditors, debt collection agencies and insurers,
- public authorities and other entities authorised under applicable law.
Recipients may act as processors on behalf of the Controller or as independent controllers, in particular where they independently determine the purposes and means of processing required to provide their own services or comply with legal obligations.
7. Transfers of data outside the European Economic Area
Because the Controller uses global providers of IT, payment, analytical, advertising or service-related services, data may in certain cases be transferred outside the European Economic Area. Any transfer takes place only after the requirements of the GDPR have been met, in particular on the basis of a European Commission adequacy decision, the recipient’s participation in the EU-US Data Privacy Framework, standard contractual clauses or another legally permitted mechanism. Information about the mechanism used in a specific case may be obtained by contacting the Controller.
8. Profiling and automated decision-making
The Controller may use information about user activity to create product recommendations, measure advertising effectiveness and tailor communications where the user has given the required consent. The Controller does not make decisions concerning customers based solely on automated processing that produce legal effects or similarly significantly affect the individual. Independent payment or financing providers may carry out their own risk assessments under the terms set out in their privacy notices.
9. Rights of data subjects
Within the limits laid down in the GDPR, the data subject has the following rights:
- to access the data and receive a copy of it,
- to rectify the data,
- to erase the data,
- to restrict processing,
- to data portability where processing is based on consent or a contract and is carried out by automated means,
- to object to processing based on Article 6(1)(f) GDPR,
- to object at any time to direct marketing, including related profiling,
- to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
Requests may be sent to info@dangbei.pl or in writing to the Controller’s contact address: Bukowiecka 92/305, 03-893 Warsaw, Poland. The Controller may request information necessary to verify the identity of the person making the request.
10. Complaint to the supervisory authority
A person who believes that their data is being processed unlawfully has the right to lodge a complaint with the President of the Personal Data Protection Office. The current address of the Office is: ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.
11. Data security
The Controller applies technical and organisational measures appropriate to the nature, scope, context and purposes of processing and to the risk of infringement of the rights or freedoms of individuals. These measures include, in particular, access controls, transmission encryption, backups, system updates, authorisations and cooperation with providers required to maintain the confidentiality and security of data.
12. Cookies and similar technologies
The website uses cookies, browser local storage, pixels and similar technologies. They may fall into the following categories:
- essential and functional - required to transmit a communication, operate the basket, enable login, ensure security, remember settings or provide a service explicitly requested by the user; consent is not required for these purposes,
- analytical - used to measure traffic, traffic sources, conversions and how the store is used,
- advertising and personalisation - used for profiling, remarketing, advertising measurement and tailoring content or recommendations.
Technologies other than those that are essential may be used only after obtaining the user’s prior consent, in accordance with Articles 399(1) and 400 of the Act of 12 July 2024 - Electronic Communications Law and Article 6(1)(a) GDPR. The user should be able to accept all non-essential technologies, reject them or select individual categories and providers. Consent may subsequently be changed or withdrawn using the cookie settings available on the website.
The current list of technologies, their providers, purposes and lifetimes is presented in the cookie settings or in information made available on the website. This list may change as the website develops and the configuration of services changes. Restricting essential technologies may cause some website functions to operate incorrectly.
13. Newsletter and electronic marketing
The newsletter and other commercial communications are sent only through a channel for which the recipient has given prior consent. Consent may be withdrawn at any time, including by using the unsubscribe link in the message, changing account settings or contacting the Controller. Withdrawal of consent does not affect the ability to use the account or make a purchase.
14. Data stored on devices submitted for servicing
Before submitting a projector or another device for servicing, the user should - where technically possible - back up any data they need, sign out of user accounts and streaming service accounts, delete saved passwords, Wi-Fi network data, usage history and other private content, and remove memory cards and other storage media that do not need to be submitted. The Controller and the service centre may access data stored on the device only to the extent necessary to carry out diagnostics or repairs. The scope of data transferred to the manufacturer, importer or service centre is limited to the information necessary to handle the request.
15. Changes to this Policy
This Policy may be updated if the law, the operation of the store, the scope of services, providers or technologies used change. The current version of the document is made available on the website together with its effective date. Changes requiring renewed consent will be implemented after such consent has been obtained.
