Privacy policy
LIONELO WEBSITE PRIVACY POLICY
The controller of your personal data provided through the Lionelo website (hereinafter also referred to as the “Website”) is BrandLine Group sp. z o.o., with its registered office in Poznań at ul. Adama Kręglewskiego 1, 61-248 Poznań, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court Poznań – Nowe Miasto and Wilda in Poznań, 8th Commercial Division of the National Court Register, under KRS No. 0000552768, NIP (Tax Identification Number): 7822579840, REGON: 361233546, BDO: 000008493, with a share capital of PLN 24,800.00 (hereinafter also referred to as “BrandLine” or the “Controller”).
The purpose of this Privacy Policy is to define the measures undertaken by BrandLine Group sp. z o.o. with regard to the protection of personal data and to specify the scope and legal grounds for processing such data when using the Website. All activities undertaken by BrandLine are subject to the applicable personal data protection laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: “GDPR”), as well as the Polish Act of 10 May 2018 on the Protection of Personal Data.
For all matters related to the protection of personal data, you may contact the Controller:
a. by post at: ul. Adama Kręglewskiego 1, 61-248 Poznań, Poland;
b. by e-mail at: daneosobowe@brandlinegroup.com;
c. by telephone at: +48 612 222 980.
1. PERSONAL DATA CONTROLLER
With a view to ensuring security and respecting and safeguarding your rights, Personal Data at BrandLine are:
• processed lawfully, fairly and in a transparent manner;
• collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes;
• adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed, in accordance with the principle of data minimisation;
• accurate and, where necessary, kept up to date;
• kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the Personal Data are processed;
• processed in a manner that ensures appropriate security of Personal Data. The Controller ensures protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures. The Controller ensures a secure and encrypted connection when Personal Data are transmitted through the Website. The Website pages are secured with an SSL certificate.
The Controller takes all necessary measures to ensure that its subcontractors and other cooperating entities provide sufficient guarantees that appropriate security measures are implemented whenever they process Personal Data on behalf of the Controller.
2. DATA PROCESSING IN CONNECTION WITH THE USE OF THE WEBSITE
In connection with the use of the Website, the Controller processes the personal data (hereinafter also referred to as “Personal Data”) of:
• Users (all persons visiting and using the Website);
• Customers (persons making purchases through the Website, both registered users and persons without an account on the Website);
• persons contacting the Controller using tools available on the Website, i.e.:
a. via online messaging services such as Messenger and WhatsApp;
b. via contact forms;
c. by telephone;
d. via the live chat function;
• newsletter recipients.
3. PURPOSES, LEGAL BASIS AND PERIOD OF DATA PROCESSING
3.1.
Users’ Personal Data may be collected through cookies and other similar technologies and processed for the purposes of ensuring the proper functioning of the Website, analysing traffic and the manner in which the Website is used, adapting content to the User’s preferences, and conducting measurement and marketing activities, including displaying personalised advertisements, on the basis of consent given when configuring cookies (Article 6(1)(a) GDPR).
The data are processed until consent is withdrawn or until the relevant cookie expires, whichever occurs first. The use of cookies necessary for the proper functioning of the Website does not require the User’s consent.
3.2.
The data of persons contacting the Controller using tools available on the Website will be processed for the same purposes as Users’ data and, additionally:
3.2.1.
for the purpose of responding to questions submitted by such persons (handling enquiries), pursuant to Article 6(1)(f) GDPR, where processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in responding to enquiries, ensuring efficient communication, sending marketing content where relevant to the enquiry, and defending against potential claims.
The data will be processed for the period necessary to respond to submitted enquiries, extended by the limitation period applicable to potential claims.
3.2.2.
in connection with the monitoring of telephone calls for the purpose of ensuring high-quality customer service and protecting the legal interests of persons making contact, pursuant to Article 6(1)(a) GDPR, i.e. on the basis of consent expressed by continuing the telephone call.
The data will be processed for a period of 3 months from the date on which they are obtained. If you decide to enter into an agreement with us, the data will subsequently be processed for the period appropriate for the performance of that agreement, in accordance with the provisions set out in Section 3.3 of this Website Privacy Policy.
Providing data indicated as mandatory is required in order to receive and handle an enquiry. Failure to provide such data will make it impossible to handle the enquiry. Providing any other data is voluntary.
3.3.
Customers’ Personal Data are processed for the same purposes as the Personal Data of Users and persons contacting the Controller using tools available on the Website (where the Customer uses such tools), and additionally:
3.3.1.
for the purpose of handling concluded sales agreements, i.e. operational processing of orders, issuing sales documents, dispatching or delivering ordered goods, handling returns and complaints, and fulfilling obligations arising from guarantees and statutory warranties:
a. pursuant to Article 6(1)(b) GDPR, where processing is necessary for the performance of a sales agreement in accordance with the Terms and Conditions of the store;
b. pursuant to Article 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation to which the Controller is subject, in connection with the provisions of the Act of 30 May 2014 on Consumer Rights, the Act of 18 July 2002 on Providing Services by Electronic Means, the Accounting Act of 29 September 1994 and other accounting and tax regulations.
Personal Data will be processed for the period necessary for the performance of the sales agreement, extended by the applicable guarantee/warranty period and the limitation period for potential claims or, where required by law, for the period prescribed by applicable legislation.
Providing data indicated as mandatory is required in order to accept and process an order. Failure to provide such data will result in the order not being processed. Providing any other data is optional.
3.3.2.
for the purpose of enabling participation in and exercising the rights arising from the Customer’s participation in the Lionelo Protect Additional Programme, including the use of the services specified therein, i.e. an extended product warranty, ordering a replacement product, repair services and replacement of an accident-damaged product with a new one, pursuant to Article 6(1)(b) GDPR, where processing is necessary to provide the service selected by the Customer under the Lionelo Protect Programme in accordance with the accepted Terms and Conditions of the Lionelo Protect Programme.
Personal Data will be processed for the duration of the service provided under the Lionelo Protect Programme, extended by the limitation period for potential claims or, where required by law, for the period prescribed by applicable legislation.
Providing data indicated as mandatory is required in order to use the services covered by the Lionelo Protect Programme. Failure to provide such data will make it impossible to use the relevant service. Providing any other data is optional.
3.3.3.
for the purpose of registering a Customer account and ensuring the operation of the Customer’s profile – provision of an electronic service (including enabling the Customer to view orders, check order fulfilment status, use additional functions offered by the Controller and resolve technical problems) – pursuant to Article 6(1)(b) GDPR, where processing is necessary for the performance of a contract to which the data subject is party, in accordance with the Terms and Conditions of the store.
Personal Data will be processed for the duration of the service, i.e. for as long as the person remains a registered Customer of the online store, and after deletion of the account for the period necessary to comply with legal obligations and to establish, pursue or defend against potential claims.
3.3.4.
for the purpose of measuring Customer satisfaction by sending the Customer a request to provide a product review, on the basis of the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR, until an objection to the processing is raised.
3.3.5.
for the purpose of conducting research and analyses aimed at improving the operation of available services, including evaluating the Website, on the basis of the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR, until an objection to the processing is raised.
3.3.6.
for the purpose of sending reminders concerning abandoned shopping carts and incomplete purchases, on the basis of the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR, until an objection to the processing is raised.
3.3.7.
for the purpose of handling incoming and outgoing correspondence of the Controller pursuant to Article 6(1)(f) GDPR, where processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in the proper and efficient conduct of its business activities and responding to enquiries sent to the Controller by post.
The data are stored until they cease to be useful, depending on the content of the correspondence, generally in accordance with the applicable limitation periods for claims.
3.3.8.
for the purpose of providing the Customer with commercial information concerning services provided by the Controller (marketing of the Controller’s own services), pursuant to Article 6(1)(f) GDPR, where processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in marketing its own services, until an objection to the processing is raised.
3.3.9.
for the purpose of collecting waste electrical or electronic equipment (where the Customer chooses to return such waste equipment), in accordance with the information concerning waste equipment provided on the Website, pursuant to Article 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation to which the Controller is subject under the Act of 11 September 2015 on Waste Electrical and Electronic Equipment.
The data will be processed only for the period necessary to provide the service, i.e. to collect the waste equipment.
3.3.10.
for the purpose of preventing infringements in communications and taking measures to review reports concerning illegal and/or non-compliant content in connection with the Website services, pursuant to Article 6(1)(c) GDPR, where processing is necessary for compliance with a legal obligation to which the Controller is subject under Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services and amending Directive 2000/31/EC (Digital Services Act).
Your data will also be processed after the report has been reviewed. The legal basis for such processing is the Controller’s legitimate interest in archiving the report in order to document the course of the proceedings in the future and to defend against potential claims (Article 6(1)(f) GDPR).
The data will be processed for the period necessary to review the report and subsequently for the period corresponding to the limitation period applicable to claims arising from the report.
3.4.
The Controller provides an electronic service consisting in sending newsletters to persons who have provided their e-mail address for this purpose.
3.4.1.
The Personal Data of newsletter recipients are processed for the same purposes for which the Controller processes Users’ Personal Data and, additionally, for the purpose of providing the electronic newsletter service.
Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract, in accordance with the Terms and Conditions for the provision of the newsletter service accepted by the recipient, pursuant to Article 6(1)(b) GDPR.
Where marketing content is sent to a User as part of the newsletter service, the legal basis for processing is the Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR in conjunction with the consent given to receive marketing communications.
The data will be processed for the duration of the service (until the newsletter service is cancelled) or until an objection is raised. Providing the data is required in order to provide the newsletter service, and failure to provide such data will make it impossible to send the newsletter.
3.5.
The data of all the above-mentioned persons are also processed for the purpose of securing potential claims until the expiry of the applicable limitation periods under the law.
4. RECIPIENTS OF DATA
4.1.
Personal Data may be transferred to entities whose services are used by the Controller in connection with operating the Website, providing electronic services and selling goods, including in particular:
• IT service providers and IT system providers;
• postal operators;
• carriers;
• logistics companies;
• payment transaction service providers;
• warehousing service providers;
• marketing service providers;
• goods distribution service providers;
• server colocation service providers;
• law firms;
• advisory and auditing service providers;
• companies providing servicing and repair services (in connection with complaints and warranty claims);
• authorised entities upon a documented request.
4.2.
The Website may use tools and plug-ins provided by third parties, in particular Meta Platforms Ireland Limited (Facebook, Instagram, WhatsApp), Google Ireland Limited (YouTube) and LinkedIn Ireland Unlimited Company (LinkedIn).
Use of these functionalities may result in certain information being transferred to the providers of these services, including in particular IP addresses, online identifiers, device information and data concerning the User’s activity on the Website.
Detailed rules governing the processing of data by individual providers are available in their current privacy policies published on their respective websites.
5. YOUR RIGHTS
Providing Personal Data is always voluntary; however, failure to provide data designated as necessary will make it impossible to use the services provided through the Website.
To the extent provided for by the GDPR and subject to the limitations specified therein, every person whose Personal Data are processed by the Controller has the following rights:
5.1. Right of access
This means the right to contact BrandLine to obtain information as to whether and what data we process as the Controller.
Pursuant to Article 15 GDPR, a registered Customer of the Website has unrestricted access at any time to all Personal Data provided to the Controller, their order history, history of complaints concerning orders, list of favourite products and submitted reviews.
5.2. Right to rectification
This means the right to request that BrandLine rectify inaccurate data or complete incomplete data. A registered Customer of the Website may at any time independently rectify their Personal Data in their Profile within their Customer account.
5.3. Right to erasure
This means the right to request the deletion of data processed by the Controller.
5.4. Right to restriction of processing
This means the right to request that BrandLine restrict the processing of data.
5.5. Right to data portability
This means that, subject to certain conditions, you may request that your data be transmitted directly to another controller designated by you.
5.6. Right to object
This means the right to object to the processing of Personal Data by the Controller.
5.7. Right concerning automated decision-making, including profiling
This means the right to object to Personal Data being used in automated decision-making processes, including profiling.
5.8. Right to withdraw consent
This means that consent previously given may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of that consent before its withdrawal.
5.9. Right to lodge a complaint with a supervisory authority
If you believe that our processing of your data infringes applicable law, you have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych): www.uodo.gov.pl.
6. TRANSFER OF DATA OUTSIDE THE EEA
Given that Personal Data are processed using tools such as Google Analytics, Google Tag Manager, Microsoft Clarity, Klavyio, Meta and Shopify Plus, they may be transferred outside the European Economic Area.
Google LLC (Google Analytics and Google Tag Manager), Microsoft Corporation (Microsoft Clarity), Klavyio Inc. (Klavyio), Meta Platforms, Inc. (Meta) and Shopify Inc. (Shopify Plus) carry out transfers outside the EEA using, pursuant to Article 45 GDPR, the transfer mechanism based on an adequacy decision applicable to entities included on the EU-U.S. Data Privacy Framework list, i.e. the framework governing data protection between the European Union and the United States, implemented by the European Commission decision of 10 July 2023 and administered by the U.S. Department of Commerce (EU-U.S. DPF).
7. AUTOMATED DECISION-MAKING, INCLUDING PROFILING
7.1.
The Controller uses systems for automated decision-making, including profiling; however, such processing will not produce legal effects concerning Users or similarly significantly affect them.
7.2.
The profiling of Personal Data by the Controller consists in processing data (including by automated means) by using such data to evaluate certain information, in particular to analyse or predict the personal preferences of our Users.
7.3.
Information obtained as a result of automated decision-making, including profiling, will be used solely for the purpose of adapting our marketing activities to Users’ needs and preferences.
8. COOKIES AND SIMILAR TECHNOLOGIES
The Controller uses cookies and similar technologies (hereinafter also referred to as “Cookies”).
What are Cookies?
The Website uses Cookies and similar technologies, such as browser local storage (Local Storage), tracking pixels, device identifiers and web beacons. These are pieces of information stored on or read from the User’s device while using the Website.
These technologies may store, among other things, a session or device identifier, information concerning Website settings, pages visited, products viewed, the source of the visit, browser and device type, approximate location and information about how the Website is used.
To the extent that such information makes it possible to identify a User directly or indirectly, it constitutes Personal Data.
Three basic types of Cookies can be distinguished:
• Session Cookies: temporary files specific to a particular visit, limited to sending a so-called session identifier (a random string of digits generated by the server) so that the User does not have to re-enter the same information after navigating to another page of the Website or after leaving it completely. Session Cookies are not permanently stored on the User’s device and are deleted when the browser is closed;
• Persistent Cookies: files that store information concerning the User’s preferences and are retained in the browser cache or on a mobile device. Ending a browser session or switching off the device does not remove them from the device;
• Third-party Cookies: Cookies placed by BrandLine’s trusted partners for the purpose of collecting data from multiple websites or sessions.
What types of Cookies do we use?
The following Cookies are used on the Website:
1. Necessary (system) technologies
Necessary technologies ensure security, maintain sessions, enable the shopping cart to function, support forms, save consent settings, and ensure the proper display and operation of the Website. Without some of these technologies, it would not be possible to provide a service explicitly requested by the User.
Necessary technologies are used without separate consent from the User only to the extent that the conditions laid down in Article 399(3) of the Polish Electronic Communications Law are met.
Where information associated with these technologies constitutes Personal Data, the legal basis for its further processing is, depending on the relevant function, the necessity to perform a contract or take steps at the User’s request, or the Controller’s legitimate interest in ensuring the security and proper functioning of the Website.
2. Performance (analytics and statistics) technologies
Statistical and analytical technologies make it possible to measure the number of visits, analyse traffic sources, how Users navigate the Website and use its functions, and assess the effectiveness of changes introduced to the Website.
Analytical data should not be treated as anonymous solely because they do not contain the User’s first and last name. They may include online identifiers, device identifiers and activity information and may therefore constitute Personal Data.
Statistical and analytical technologies are optional and are activated only after consent has been given.
3. Functional (preference) technologies
Preference technologies make it possible to remember the User’s choices, such as language, region, interface settings or other settings affecting how the Website operates and appears.
These technologies are optional and are activated only after consent has been given.
4. Marketing and advertising (targeting) technologies
Marketing technologies are used to measure advertising effectiveness, create audiences, limit the number of times an advertisement is displayed, personalise advertising content and conduct marketing activities both on and outside the Website.
Marketing technologies are optional and are activated only after consent has been given.
5. Unclassified technologies
Technologies whose purpose, provider or operating principles have not yet been determined are not activated until they have been classified and their purpose, storage period, provider, legal basis and any potential transfers of data outside the European Economic Area have been established.
Cookie retention period
The retention period for Cookies depends on the type of Cookie. Detailed information on how long the Controller stores Cookies can be checked when visiting the Website.
During the first visit, this information is displayed in a pop-up window. During subsequent visits, it can be accessed by clicking the “Cookie Settings” banner.
Data stored by providers of individual tools may be retained for a period different from the lifetime of the relevant Cookie. These periods depend on the configuration of individual services and should be specified in the information provided by the relevant provider.
Managing Cookies and consent to their use
During the first visit, the User may:
• reject all optional technologies;
• accept all optional technologies;
• make a separate choice for each individual category.
Taking no action, continuing to browse the Website or closing the banner does not constitute consent.
The User may change or withdraw their consent at any time using the “Cookie Settings” link available in the footer of the Website. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
Restricting the use of necessary technologies may result in certain Website functions, in particular the shopping cart, login, forms or the purchasing process, not operating correctly. Refusal to consent to optional technologies must not prevent the User from using the basic functions of the Website.
Detailed information on changing Cookie settings and manually deleting Cookies in the most popular web browsers is also available in the help section of the relevant web browser.