PRIVACY POLICY AND COOKIE POLICY
This Privacy Policy and Cookie Policy contains information regarding the processing of personal data that you may provide to the Administrator while using the Store and the use of Cookies.
The Administrator reserves the right to introduce changes to the privacy policy. The reasons for introducing changes may include changes in legal regulations, the development of Internet technology, the use of new tools by the Administrator, and other objective reasons. At the top of the page there is the publication date of the current Privacy Policy and Cookie Policy.
DEFINITIONS
Administrator – The data controller is the entity that carries out specific purposes of data processing. I always inform about the details of data processing when collecting the data, for example in agreements concluded with you or in announcements. The Personal Data Controller implementing this Personal Data Security Policy is: Maja Tworska, Tax Identification Number (NIF): 300141173
Personal Data – information concerning an identified or identifiable natural person through one or more specific factors determining physical, physiological, genetic, mental, economic, cultural or social identity, including the device IP address, location data, internet identifier, and information collected through cookies and other similar technologies.
Policy – this Privacy Policy, containing information on the processing of Personal Data and the use of cookies and similar tracking technologies within the Service.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC.
Personal Data Protection Act – the Act of 10 May 2018 on the protection of personal data (Journal of Laws 2018, item 1000, as amended).
Service – the website operated by the Administrator at the address www.tworskapilatesconcept.com through web browsers and all its subpages, including any services provided within the domain, e.g., a contact form.
User – a natural person visiting the Service or using one or more services or functionalities described in the Policy.
Device – an electronic device through which the User gains access to the Website.
WHO IS THE PERSONAL DATA CONTROLLER?
The personal data controller is: Maja Tworska, Tax Identification Number (NIF): 300141173
Contact with the Administrator is possible at the above-mentioned address and via e-mail: majatworska@gmail.com and by telephone number: +351 912 582 098.
By contacting the Administrator through an e-mail address, contact form, social media, or by subscribing to the newsletter, you provide your personal data, for example your name and e-mail address.
The Administrator attaches great importance to the issues of security and compliance with the law in the process of processing Users’ personal data.
The User’s personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC, hereinafter referred to as the “GDPR”, as well as other currently applicable personal data protection laws.
WHAT PERSONAL DATA IS PROCESSED BY THE ADMINISTRATOR IN CONNECTION WITH THE USE OF THE SERVICE?
The Service enables the User to contact the Administrator and provide identification data, contact data, as well as information related to the content of messages.
The Administrator collects data related to User activity, such as the time spent on the website, searched phrases, the number of viewed subpages, the date and source of visits.
If the User contacts the Administrator, the data has been provided directly by the User.
If the User’s data has been provided in connection with a matter handled by another person who referred that matter to the Administrator, then the source of the data is that person. In such a case, the Administrator receives identification data, address data, and information related to the matter, such as a description of the matter.
In connection with the User’s use of the Service, the Administrator collects data to the extent necessary to provide the offered services, such as name, surname, residential address, and e-mail address.
Below are detailed rules and purposes of processing personal data collected while using the Service.
PURPOSE AND LEGAL BASIS OF THE DATA PROCESSED BY THE ADMINISTRATOR
Purposes and Legal Bases for the Processing of Personal Data in the Service
The personal data of all persons using the Service are processed by the Administrator for the purpose of:
- Analyzing network traffic, ensuring security within the Service, and adapting content (Article 6(1)(f) GDPR);
- Responding to correspondence, providing the requested offer, and conducting correspondence (Article 6(1)(a) and (f) GDPR);
- Delivering and displaying content within the Service – for this purpose, the Administrator collects personal data in the form of: IP address and cookies; the data is processed on the basis of Article 6(1)(f) GDPR;
- Establishing, defending, and pursuing claims – the legal basis for processing is the Administrator’s legitimate interest (Article 6(1)(f) GDPR), consisting of the protection of its rights;
- Publishing reviews by the User regarding services provided by the Administrator and conducting opinion surveys through questionnaires (Article 6(1)(a) GDPR);
- Using cookies on the Website and its subpages (Article 6(1)(a) GDPR);
- Analytical and statistical purposes – consisting of conducting analyses of User activity within the Service in order to improve the functionalities used (Article 6(1)(f) GDPR);
- Operating the newsletter (Article 6(1)(a) GDPR and Article 6(1)(f) GDPR);
- Contacting the Administrator – the Administrator provides the possibility of contacting him through an electronic contact form. Use of the form requires providing personal data necessary to establish contact. The User may also provide additional data in order to facilitate contact or handling of the inquiry. Providing data marked as mandatory is required for accepting and handling the inquiry, and failure to provide such data results in the inability to handle the inquiry. Providing other data is voluntary.
Personal data is processed for the purpose of identifying the sender and handling the inquiry submitted via the provided form. The legal basis for processing is the necessity of processing for the performance of a contract for the provision of a service (Article 6(1)(b) GDPR); with regard to optionally provided data, the legal basis for processing is consent (Article 6(1)(a) GDPR).
HOW DOES THE ADMINISTRATOR OBTAIN PERSONAL DATA?
Personal data means any information that can be used to indirectly or directly identify a specific person. This definition includes personal data collected online through the Administrator’s Website and company pages on external platforms.
During contact with the Administrator, you may be asked to provide your personal data.
The data controllers may share your personal data with each other and with other companies related to the Administrator through capital or personal ties and use it in a manner consistent with this Privacy Notice. The Administrator may also combine such data with other information in order to improve its content.
The Administrator collects personal data from various sources. These are:
Personal Data Provided Directly
The Administrator collects information regarding how you use the website, for example information about the types of content you view or engage with, as well as the frequency and duration of your activities.
Personal Data Collected Automatically
The Administrator also receives and stores certain types of personal data whenever you contact the Administrator online.
For example, I use cookies and tracking technologies to obtain personal data when a web browser accesses my website and other content provided on other websites.
Personal data is also collected during searches and the publication of posts.
Examples of the types of personal data I collect include:
- IP address;
- Device identifier;
- Location data;
- Information about the computer and connection, such as:
- browser type and version,
- time zone settings,
- browser plug-in types and versions,
- operating system.
USER RIGHTS RELATED TO THE PROCESSING OF THEIR PERSONAL DATA
The GDPR grants the following rights related to the processing of personal data:
- The right of access to personal data and to obtain a copy thereof;
- The right to rectify or correct personal data;
- The right to erase personal data (the right to be forgotten);
- The right to restrict the processing of personal data;
- The right to object to the processing of personal data;
- The right to withdraw consent;
- The right to object to the processing of personal data;
- The right to data portability;
- The right to lodge a complaint with the President of the Personal Data Protection Office.
Not all of these rights will always apply to the User in every case. This is related to the nature of legal regulations.
PERIOD OF PROCESSING PERSONAL DATA
The period of processing the User’s personal data by the Administrator depends on the type of service provided and the purpose of processing.
The User’s personal data will be stored until consent is withdrawn or until the matter has been resolved.
Data related to network traffic analysis collected through cookies and similar technologies may be stored until the cookie expires.
Some cookies never expire; therefore, the data retention period will be equivalent to the period necessary for the Administrator to achieve the purposes related to data collection, such as ensuring security and analyzing historical data concerning website traffic.
The data processing period may be extended if processing is necessary to establish and pursue possible claims or defend against claims, and after that period only if and to the extent required by law.
After the processing period expires, the data is irreversibly deleted or anonymized.
DATA SECURITY
The User’s personal data is stored and protected with due care, in accordance with the Administrator’s implemented internal procedures.
The Administrator processes information about the User using appropriate technical and organizational measures that meet the requirements of generally applicable legal provisions, in particular regulations concerning personal data protection.
These measures are intended primarily to protect Users’ personal data against access by unauthorized persons.
In particular, only authorized persons who are obliged to maintain confidentiality have access to Users’ personal data.
At the same time, the User should exercise due diligence in protecting personal data transmitted via the Internet, in particular by:
- not disclosing login credentials to third parties,
- using antivirus protection,
- updating software.
TRANSFER OF DATA TO THIRD PARTIES
The User’s personal data may be transferred to third parties whose services the Administrator uses in connection with operating the Service.
Due to the use of services such as Google or Facebook, Users’ personal data may be transferred to the United States of America (USA), Canada, and other countries. These entities guarantee an appropriate level of protection of personal data as required by European regulations.
Entities Processing Shared Data Within the European Economic Area (EEA)
- Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02X525, Ireland (formerly Facebook Ireland Limited).
- MailerLite Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland – an entity providing the newsletter distribution system.
- Facebook or Instagram, particularly with regard to advertising tools.
- Facebook Ireland Ltd. – with regard to the use of Meta Platforms (Facebook) advertising tools and the entrustment of data within custom audience groups.
- Other contractors or subcontractors engaged in technical support, administration, or the provision of legal assistance for the Administrator and its clients, e.g.:
- accounting services,
- IT services,
- graphic design services,
- copywriting services,
- debt collection companies,
- lawyers,
- public authorities, such as tax offices,
for the purpose of fulfilling legal and tax obligations related to settlements and accounting.
Entities Processing Shared Data Outside the European Economic Area (EEA)
Google Analytics by Google LLC
An entity providing:
- a tool securing the Service,
- a tool for statistical analysis (Google Analytics).
MANYCHAT, INC.
535 Mission St, San Francisco, CA 94105, USA
MANYCHAT is a tool facilitating communication between the Administrator and Recipients.
I use this tool within the Service as part of my marketing activities.
MANYCHAT enables the sending of automated messages with content specified by me to recipients interested in my content and materials.
MANYCHAT performs two roles depending on the purpose for which it is used. In some cases it acts as a data controller (usually in relation to my data), while in other cases it acts as a processor (usually in relation to your data).
An integral part of my agreement with MANYCHAT (Terms of Use: https://manychat.com/legal/tos) is a data processing addendum that defines the rules for data processing by MANYCHAT.
You can read more here:
MANYCHAT AS A DATA CONTROLLER
MANYCHAT is my data controller for the purpose of:
- entering into an agreement with me,
- managing my account,
- complying with generally applicable legal regulations.
For these purposes, MANYCHAT processes my data as well as the data of End Users, i.e. mine and others whose data is processed and who have lawful access to the service on my behalf or with our authorization.
The categories of data processed include:
- identification data,
- linked pages and accounts,
- products used,
- telecommunications data (IP addresses, location data),
- financial information (credit card details, account details, payment information),
to the extent that such data is visible in the Service or has been voluntarily provided.
MANYCHAT AS A DATA PROCESSOR
MANYCHAT also acts as a processor, meaning an entity processing data on behalf of the Administrator for the purpose of providing automation services under the agreement concluded with me.
This includes:
- providing support,
- communication regarding the Service through the tool,
- sending technical notifications,
- announcements,
- updates,
- security alerts,
- responding to requests, questions, and feedback related to the service,
- recording activities,
- tracking errors and incidents,
- correcting errors,
- ensuring availability,
- ensuring security,
- ensuring usability of the service in my legitimate interest.
MANYCHAT processes data on my behalf until the termination or expiration of the agreement concluded with me, in accordance with its terms.
Data Processed by MANYCHAT as a Processor
The data that MANYCHAT may process as a processor includes:
- identification data (name and surname, email address),
- publicly available information on social media profiles,
- linked pages and accounts,
- telecommunications data:
- IP addresses,
- geographic location,
- usage data,
- cookie data,
- browser data,
- other information.
Subscribers
In the case of subscribers, i.e. persons with whom we communicate using MANYCHAT and/or whose data is transmitted to the service by us, the processed data may include:
- identification data,
- publicly available social media profile information,
- chat history and chat content,
- chatbot usage information,
- other electronic data transmitted, stored, sent, or received by end users,
- other personal data whose scope is determined and controlled by me according to the functions available within MANYCHAT.
Source of Data
The source of the above-mentioned data is:
- my registration and use of the service,
- registration and use of the service by the end user,
- communication with subscribers,
- integrations and third-party applications connected by me,
- other applications specified at:
http://www.aps.manychat.com
Consent for Messages
In order for MANYCHAT to send messages and materials to you, it requires your consent to receive messages.
The consent referred to above is granted by:
- sending a message, or
- publishing a comment with content specified in a particular publication made available within the Service or on the Administrator’s social media channels.
After sending a message or posting a comment within the Service or on the Administrator’s social media channels, you will receive automated messages from me sent through MANYCHAT.
Retention Period
MANYCHAT, as a processor, processes data until the agreement with us is terminated.
We, as the Administrator, also process the data until:
- you resign from receiving marketing communications,
- the legally required retention period expires,
- including the limitation period for claims.
International Transfers
In connection with the use of MANYCHAT, personal data may be transferred outside the European Economic Area on the basis of Standard Contractual Clauses (SCCs).
MANYCHAT also applies appropriate security measures for data processing.
More information about data processing by MANYCHAT and the security measures applied can be found at:
I also inform you that I may use the assistance of third parties who provide technical support in operating MANYCHAT.
Please note that I use the services of entities for whom the protection of your personal data is important, and I conclude data processing agreements with them.
COOKIES AND TRACKING TECHNOLOGIES
The website you are currently visiting uses cookies.
During the first visit to the website, information regarding the use of cookies is displayed. Failure to change the browser settings is equivalent to consenting to their use.
The Service allows the collection of information about the User through cookies and similar technologies, the use of which is most often associated with installing a tool on the User’s device.
This information is used to:
- remember the User’s decisions (font selection, contrast settings, acceptance of the policy),
- maintain the User’s session (e.g. after logging in),
- remember passwords (with the User’s consent),
- collect information about the User’s device and visit in order to ensure security,
- analyze visits,
- customize content.
Information obtained through cookies and similar technologies is not combined with other data of Service Users and is not used by the Administrator to identify them.
Cookies are short text files stored on the device you use when browsing websites.
They may be read by:
- the Administrator („own cookies”), which are used to ensure the proper functioning of the website,
- systems belonging to other entities whose services the Administrator uses („third-party cookies”).
The User has the right to:
- change cookie settings through their browser,
- delete cookies.
The User may also use the website in so-called incognito mode, which blocks the collection of data regarding their visit.
This website uses the following tracking technologies:
- social media plugins, such as:
- Facebook,
- Instagram;
- analytical and marketing tools, such as:
- Google Analytics,
- Facebook Pixel.
NEWSLETTER
By subscribing to the newsletter, the User provides the Administrator with:
- first name,
- email address.
Providing this data is voluntary, but necessary to subscribe to the newsletter.
The User may unsubscribe from the newsletter at any time by:
- clicking the link included in every newsletter message,
- contacting the Administrator using the contact details provided above.
Subscription to the newsletter means that the User consents to receiving marketing and commercial information by electronic means of communication within the meaning of the Act on Providing Services by Electronic Means.
By confirming the newsletter subscription, the User consents to the Administrator’s use of telecommunications terminal equipment for the direct marketing of the Administrator’s products and services, as well as for sending commercial information.
The mailing system used by the Administrator to send newsletters records all activity and actions undertaken by the User in connection with emails sent to them, including:
- the date and time the message was opened,
- clicks on links contained in the message,
- the moment of unsubscribing,
- and other related activities.
SERVER LOGS
Use of the website involves sending requests to the server on which the website is hosted.
Every request directed to the server is recorded in server logs, which include, for example:
- IP address,
- server date and time,
- information about the web browser,
- information about the operating system used.
Data stored in server logs is not associated with specific persons using the Service and is used as auxiliary material for administrative purposes.
The content of server logs is not disclosed to anyone except persons authorized to administer the server.
SOCIAL MEDIA
The Administrator maintains profiles on the social media platforms Facebook and Instagram (referred to as „fan pages”).
Content, offers, and product recommendations are regularly published and shared on these fan pages.
Administrators of social networking services record users’ behavior through cookies and other similar technologies during every interaction with our fan pages and other Facebook and Instagram websites.
The administrators of social networking services have access to general statistics regarding the interests and demographic data of users visiting fan pages, such as:
- age,
- gender,
- place of residence.
Within the use of social media services, the scope and purposes of data processing on social media platforms are determined by the administrators of those platforms.
CHANGES TO THE PRIVACY POLICY
The Policy is regularly reviewed and updated when necessary.
I will update this Privacy Notice whenever necessary.
When I publish changes to this statement, I will also change the date of the last update.
I will also keep previous versions of this Privacy Notice in an archive.
I will not limit your rights under this Privacy Notice without your consent.