By using the service, you confirm that you have read and accept the guidelines presented in the terms of use and the privacy policy.
Privacy Policy
Privacy policy of the Japa Druk website
§ In accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as GDPR), as well as other generally applicable laws regarding the protection of personal data, we undertake to maintain the security and confidentiality of the personal data obtained. All service employees have been appropriately trained in the processing and protection of personal data.
§ Every User of the service has the option to choose whether and to what extent they want to use our services and share information about themselves. Every User of the Service has the right to delete their data or not to use our service.
§ The administrator of personal data of service Users is JAPA DRUK Sp. z o.o.
§ When processing Users' personal data, we apply the following principles:
lawfulness, fairness, and transparency: we process personal data in accordance with the law. We inform the data subjects (Users) comprehensively about all related matters,
data minimization and adequacy: we process only those data (adequate) that are actually needed to achieve a given purpose,
data accuracy: we take the utmost care to ensure that the data we process is current and truthful,
purpose limitation and secure storage of processed data: we collect personal data only for a specific and legally justified purpose. We store data in a form that allows identification of the data subject. We process them only as long as it is necessary to achieve the purpose for which we obtained them (unless we are obliged to further process them by legal provisions),
data integrity and confidentiality: we provide technical and organizational solutions that ensure the security of processed personal data,
accountability: we are able to demonstrate that when processing personal data, we act in accordance with applicable law.
§
In our service, we collect the following personal data from Users:
name and surname - when placing an order, necessary for placing orders and contact;
home address or company address - for shipping ordered goods;
phone number - data used for contact regarding order fulfillment;
email address - order confirmation and potential contact are sent via email;
addresses - information resulting from general rules of connections made on the Internet such as IP address (and other information contained in system logs);
cookies - the service uses cookie technology to adapt the service to individual needs and enable placing orders.
Providing the above data is necessary in the following cases:
when making a purchase in the Store, data for identifying the Buyer must be provided;
registration in the Customer database is voluntary, data is stored in the database to enable and facilitate purchases in the Store.
Owners of other websites will not have access to this data.
If the User does not agree to the personalization of the service, they should disable cookie support in the options of their web browser.
§ The legal bases for processing personal data for individual purposes and the duration of their processing are as follows:
Purpose - performance of the contract between the Company and the Service User - legal basis - art. 6 sec. 1 lit b) GDPR - necessity for the performance of a contract to which the User is a party;
Purpose - marketing of the administrator's products and services (including analyzing and profiling data for marketing purposes in an automated manner), statistical measurements - legal basis - art. 6 sec. 1 lit a) - consent of the data subject (User);
Purpose - processing data for technical reasons to ensure continuity of operation and functionality of the service - legal basis - art. 6 sec. 1 lit f) - legitimate interest of the administrator.The personal data of the Service User, within our services, will be processed only if we have one of the legal bases allowed by the GDPR for their processing and only for the purpose adapted to a given basis, as described above.
Data will be processed until there is a basis for their processing:
in case of consent, until its withdrawal, limitation, or other actions on your part limiting this consent,
in case the data is necessary for the performance of the contract - for the duration of its performance and for the period necessary to pursue claims, as well as due to obligations provided by law, e.g., tax regulations,
in cases where the basis for data processing is the legitimate interest of the administrator - until this legitimate interest exists.
§
We do not share personal data obtained from the User with third parties, with the exception of entities cooperating with the service, e.g., payment system operators and courier, forwarding companies that process payments for goods purchased in the service and deliver purchased goods to Buyers, hosting companies. In such cases, the amount of data transferred to companies cooperating with the service is limited to the required minimum.
All companies cooperating with the service that gain access to personal data provided by Users have committed to protecting them in a manner consistent with applicable law and to training their employees in the processing and protection of obtained personal data.
The personal data of Users held by us may be made available to appropriate public authorities if required by applicable law.
We do not store confidential data, such as credit card numbers or bank account access data.
§
Users have the following rights in connection with our processing of their personal data:
right to access their data, including obtaining a copy of the data,
right to request rectification of data,
right to erasure of data (in specific situations),
right to lodge a complaint with the supervisory authority dealing with personal data protection,
right to restriction of data processing,
right to object (in specific situations).
If the User's data is processed based on consent or as part of a provided service (data is necessary for providing the service), they may exercise the right to data portability, i.e., to receive their personal data from the administrator, in a structured, commonly used and machine-readable format. They may be sent to another data administrator.To exercise the above rights, please contact the administrator or the Personal Data Protection Inspector (IODO) (data in § 3 above).