This Privacy policy sets out the rules for storing and accessing data on the Devices of Users using the Shop for the purpose of providing services by electronic means by the Controller, and the rules for collecting and processing Users’ personal data provided by them personally and voluntarily through the tools available in the Shop.
The Privacy policy is an integral part of the Terms and conditions, which set out the rules, rights and obligations of Users using the Shop. A concise summary of the information required by the GDPR is in the GDPR notice.
§1 Definitions
- Shop – the “SONTO” online shop operating at https://sonto.eu
- Shop / Data Controller – the Controller of the Shop and Controller of Data (hereinafter the Controller) is “SONTO Sp. z o.o.”, operating at ul. Bagienna 36c, 70-772 Szczecin, Poland, tax identification number (NIP): 9552564863, providing services by electronic means through the Shop
- User – a natural person for whom the Controller provides services by electronic means through the Shop
- Device – an electronic device together with its software, through which the User accesses the Shop
- Cookies – text data collected in the form of files placed on the User’s Device
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
- Personal data – information relating to an identified or identifiable natural person
- Processing – an operation or set of operations performed on personal data, whether or not by automated means
- Consent – a freely given, specific, informed and unambiguous indication of will by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to them
- Anonymisation – an irreversible process of operations on data which makes it impossible to identify a given record or link it to a specific natural person
§2 Data Protection Officer
The Controller is not obliged to appoint a Data Protection Officer within the meaning of Article 37 GDPR and has not appointed one. In matters concerning data processing, including personal data, please contact the Controller directly in the manner set out in §12.
§3 Types of Cookies
- Necessary cookies – files necessary for the Shop to function correctly; disabling them makes proper use of the Shop impossible. They do not require the User’s consent.
- Functional cookies – files that make it possible to remember the User’s preferences and to personalise the Shop. They require the User’s consent.
- Analytics cookies – files used to collect information on how the Shop is used, to compile statistics and to analyse User behaviour. They require the User’s consent.
- Marketing cookies – files used to display advertising matched to the User’s interests, including remarketing. They require the User’s consent.
Cookies are further divided into first-party (stored by the Shop’s system) and third-party (stored by the systems of the partners listed in §6), and into session cookies (deleted when the browser session ends) and persistent cookies (stored until the stated period expires or until they are deleted manually).
§3a Cookies used in the Shop and their retention periods
| Category | Use in the Shop | Retention period |
|---|---|---|
| Necessary | Keeping the contents of the basket and the shopping session (WooCommerce), remembering the chosen language version (WPML), form security, the session of a signed-in User | Until the browser session ends; the session of a signed-in User up to 14 days |
| Necessary – consent handling | Remembering the decision made in the cookie consent banner | Up to 12 months |
| Functional | Remembering the User’s preferences and interface settings | Up to 12 months |
| Analytics | Google Analytics 4 (GA4) – analysis of traffic and User behaviour; Google Tag Manager (GTM) – management of measurement tags and scripts | GA4: up to 14 months from the last visit |
| Marketing | Remarketing and advertising files | Up to 13 months |
The User may at any time delete stored Cookies through their web browser settings or change their preferences through the cookie consent banner available in the Shop.
§4 Consent to Cookies
- On the first visit to the Shop the User is shown a cookie consent banner allowing consent to the storing of cookies other than necessary ones to be given or refused.
- Necessary cookies are run automatically, because they are required for the Shop to work correctly.
- Functional, analytics and marketing cookies are run only after the User has given express consent. Until it is given, the corresponding scripts are not executed and no data is sent to their providers.
- Giving consent is voluntary. The User may at any time change or withdraw consent through the consent settings icon visible in the Shop, the “Cookie settings” link in the footer or their web browser settings.
- Withdrawing consent is as easy as giving it and does not affect the lawfulness of processing carried out on the basis of consent before it was withdrawn.
§5 Purposes of processing personal data
Personal data provided voluntarily by Users is processed for the following purposes:
- Performance of the order and of the sales contract, including preparation of the offer and the transport quote, contact concerning the order and its delivery (Article 6(1)(b) GDPR).
- Handling enquiries sent through the contact form (Article 6(1)(b) and (f) GDPR).
- Issuing and keeping accounting documents, including invoices (Article 6(1)(c) GDPR).
- Handling complaints, returns and the exercise of rights under the statutory warranty or a guarantee (Article 6(1)(b) and (c) GDPR).
- Analytics and statistics on the use of the Shop – on the basis of consent given through the cookie consent banner (Article 6(1)(a) GDPR).
- Marketing activities, including remarketing – on the basis of consent given through the cookie consent banner (Article 6(1)(a) GDPR).
- Establishing, exercising or defending legal claims – on the basis of the legitimate interest of the Controller (Article 6(1)(f) GDPR).
§6 Third-party Cookies
The Controller uses scripts and components of partners in the Shop which may place their own cookies on the User’s Device. List of partners:
- Google Analytics 4 (GA4) – a service provided by Google LLC, used to analyse traffic in the Shop and User behaviour.
- Google Tag Manager (GTM) – a service provided by Google LLC, used to manage the measurement tags and scripts used in the Shop. The GTM container is run only after consent to analytics cookies has been given; until then it is neither downloaded nor executed.
Analytics and marketing cookies are run only after the User has given consent through the cookie consent banner shown on the first visit. The User may change or withdraw the consent given at any time. Services provided by third parties remain outside the Controller’s control — those entities may change their terms of service, privacy policies and the way they use cookies.
§7 Types of data collected
Data collected automatically (some of it may constitute personal data within the meaning of the GDPR, in particular the IP address): IP address, browser type, screen resolution, approximate location, subpages opened, time spent on a subpage, type of operating system, referring page address, browser language, Internet service provider.
Data given in the contact form: e-mail address, telephone number, message content.
Data given when placing an order: first name and surname or company name, delivery address and invoice address, tax identification number (for companies), e-mail address, telephone number, content of notes to the order.
Voluntary nature of providing data. Providing personal data is voluntary, but failing to provide certain data will make it impossible to use selected services — in particular, failing to provide data in the contact form will make it impossible to answer the enquiry, and failing to provide address and contact data will make it impossible to carry out the order. Providing data to the extent required by law (e.g. data for issuing an invoice) is mandatory and follows from tax and accounting law.
§8 Access to personal data by third parties
As a rule, the only recipient of the personal data provided by Users is the Controller. Data collected in the course of the services provided is neither transferred nor resold to third parties.
Access to the data — usually under a data processing agreement — may be held by entities responsible for maintaining the infrastructure and services necessary to run the Shop:
- Contabo GmbH – provider of the VPS server on which the Shop runs. The infrastructure is located within the European Union (Germany). Access to the data may occur as a result of maintenance work carried out by the provider’s personnel; that access is governed by the agreement concluded between the Controller and the provider.
- Laravel LLC (Laravel Forge) – provider of the server management platform used for deployments and administration. The platform has technical access to the Shop’s server.
- Service and IT support companies carrying out maintenance or responsible for keeping the IT infrastructure running.
- Google LLC – as regards the Google Analytics 4 and Google Tag Manager services.
- Carriers, courier and freight companies – as regards the data necessary to deliver the order (first name and surname or company name, delivery address, telephone number, e-mail address). The data is passed only to the carrier performing the given delivery.
- Entities providing accounting services – as regards the data contained in accounting documents, where accounting is handled by an external entity.
§9 Manner of processing personal data
As a rule, personal data will not be transferred outside the European Economic Area (EEA). An exception is where data is processed by the provider of analytics tools (Google LLC — Google Analytics 4, Google Tag Manager) established in the United States. In that case the transfer takes place on the basis of Standard Contractual Clauses (SCC) approved by the European Commission or under the Data Privacy Framework (DPF), which provide an adequate level of personal data protection. The User has the right to obtain information about the transfer safeguards applied and a copy of them by contacting the Controller in the manner set out in §12.
Personal data will not be used for automated decision-making producing legal effects concerning the User or similarly significantly affecting them within the meaning of Article 22 GDPR. The Controller does, however, apply profiling for analytical and marketing purposes, consisting in the analysis of User behaviour in the Shop using Google Analytics 4 and Google Tag Manager. That profiling takes place on the basis of the User’s consent (Article 6(1)(a) GDPR) given through the cookie consent banner and may be withdrawn at any time.
Personal data will not be resold to third parties.
§10 Personal data retention periods
- Data given in the contact form is kept for the period necessary to answer and handle the matter, and is then deleted or anonymised within 30 days of the end of the correspondence.
- Data relating to the performance of an order is kept for the period necessary to carry it out and for the limitation period for claims arising from the contract.
- Data contained in accounting documents (e.g. invoices) is kept for the period required by law — as a rule for 5 years, counting from the end of the calendar year in which the tax payment deadline fell, in accordance with Article 86 §1 of the Tax Ordinance and Article 74(2) of the Accounting Act.
- In the event of a breach or suspected breach of the Terms and conditions the Controller may keep the data for no longer than 3 years from the request for its deletion, in order to safeguard a legitimate interest.
- Anonymous statistical data which does not constitute personal data is kept indefinitely.
§11 Users’ rights
In connection with the processing of personal data Users have the following rights, exercised on request made to the Controller:
- Right of access to personal data – to obtain information about the data processed and a copy of it.
- Right to rectification – to request that incorrect data be rectified without delay or that incomplete data be completed.
- Right to erasure – to request that the data be erased without delay. The Controller reserves the right to withhold performance of the request in order to protect a legitimate interest, and to the extent that keeping the data is required by tax and accounting law.
- Right to restriction of processing – in the cases set out in Article 18 GDPR.
- Right to data portability – to receive the data in a structured, commonly used, machine-readable format.
- Right to object – to the processing of data in the cases set out in Article 21 GDPR.
- Right to withdraw consent – where processing is based on consent (Article 6(1)(a) GDPR), consent may be withdrawn at any time, in the same way as it was given — in the case of cookie consent through the consent settings icon or the “Cookie settings” link in the footer. Withdrawing consent does not affect the lawfulness of processing carried out before it was withdrawn.
- Right to lodge a complaint – with a supervisory authority. The competent authority in the Republic of Poland is the President of the Personal Data Protection Office — Prezes Urzędu Ochrony Danych Osobowych (PUODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.
§12 Contacting the Controller
- Postal address – SONTO Sp. z o.o., ul. Bagienna 36c, 70-772 Szczecin, Poland
- E-mail address – kontakt@sonto.pl
- Telephone – +48 509 810 910
- Contact form – available on the Contact page
This page is a translation of a document drawn up in Polish. In the event of any discrepancy between this translation and the Polish version, the Polish version prevails.