top of page

 

 

PRIVACY POLICY

 

  1. This Privacy Policy shall determine the principles of processing personal data obtained via the online shop www.rugseu.com (hereinafter referred to as the 'Online Shop').

  2. The Online Shop owner and data administrator at the same time is RUGS EU Sp. z o.o. with the registered office in Białystok (15-281), ul. Legionowa 9/1 lok.123, entered into the National Court Register under KRS No. 0000910100 , NIP: 5423437416, REGON: 389391329, hereinafter referred to as RUGS EU.

  3. Personal data collected by RUGS EU through the Online Shop shall be processed in accordance with the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), also referred to as RODO.

  4. RUGS EU takes special care to respect the privacy of Customers visiting the Online Shop.

 

§ 1 Type of data processing, purposes and legal basis

 

  1. RUGS EU collects information concerning natural persons performing a legal action not directly related to their activity, natural persons conducting a business or professional activity on their own behalf and natural persons representing legal persons or organisational units which are not legal persons and to which the law grants legal capacity, conducting a business or professional activity on their own behalf, hereinafter collectively referred to as ‘Customer(s)’.

  2. Customers' personal data are collected in the case of:

a) registration of an account in the Online Shop, in order to create and manage an individual account. Legal basis: necessity to perform the agreement on providing the Account service (Article 6(1)(b) of the RODO);

b) placing an order in the Online Shop, in order to perform the sales agreement. Legal basis: necessity for the performance of the sales agreement (Article 6(1)(b) of the RODO).

3. When registering an account with the Online Shop, the Customer provides an e-mail address.

4. When registering an account with the Online Shop, the Customer independently sets an individual password to access his/her account. The               Customer may change the password, at a later time, according to the rules described in § 5.

5. When placing an order in the Online Store, the Customer provides the following data:

a) e-mail address;

b) address data:

  • postal code and town;

  • country (state);

  • street with the house/flat number;

  • province.

  • first and last name;

  • telephone number.

 6.  In the case of Entrepreneurs, the above data shall be additionally extended by:

a) the business name of the Entrepreneur;

b) Tax Identification Number.

 7.  When using the Shop website, additional information may be collected, in particular: the IP address assigned to the Customer's computer or an           external IP address of the Internet provider, domain name, browser type, access time, operating system type. 

 8.  We may also collect navigational data from customers, including information about links and references they choose to click on or other actions           taken in our Online Shop. Legal basis - legitimate interest (Article 6(1)(f) RODO), consisting in facilitating the use of services provided                         electronically and improving the functionality of these services.

 9.  In order to conduct an investigation and enforcement of claims, some personal data provided by the Customer as part of the use of functionalities       in the Online Store may be processed, such as: name, surname, data on the use of services, if the claims arise from the manner in which the               Customer uses the services, other data necessary to prove the existence of the claim, including the extent of damage suffered. Legal basis - legally       justified interest (Article 6(1)(f) RODO), consisting in the establishment, assertion and enforcement of claims and the defence against claims in             proceedings before courts and other state authorities.

 10.Personal data provided to RUGS EU are given to it voluntarily in connection with concluded sales agreements or the provision of services via the         Shop's Website, with the proviso, however, that failing to provide the data specified in the forms in the Registration process prevents the                     Registration and creation of a Customer Account, whereas in the case of placing an order without the Registration of a Customer Account prevents       the submission and fulfilment of the Customer's order.

​

§ 2 With whom is the data shared or entrusted and how long is it stored?

​

  1. The Customer's personal data shall be transferred to the service providers used by RUGS EU to operate the Online Shop. The service providers to whom the personal data are transferred, depending on the contractual arrangements and circumstances, are either subject to the instructions of RUGS EU as to the purposes and means of processing the data (processors) or determine themselves the purposes and means of processing the data (controllers).

a) Processers: RUGS EU uses suppliers who process personal data exclusively on the instructions of RUGS EU. These include, but are not limited to, providers of hosting services, accounting services, providers of marketing systems, systems for analysing traffic on the Online Shop, systems for analysing the effectiveness of marketing campaigns;

b) Administrators: RUGS EU uses providers who do not act solely on instruction and determine themselves the purposes and uses of Customers' personal data. They provide electronic payment and banking services.

 2.  Location. The service providers are mainly based in Poland and in other countries of the European Economic Area (EEA). 3.

 3.  The Customers' personal data is stored:

a) If the basis for the processing of personal data is consent then the Customer's personal data shall be processed by RUGS EU as long as the consent is not revoked, and after revocation of the consent for a period of time corresponding to the period of limitation of claims that RUGS EU may raise and that may be raised against it. Unless otherwise provided by specific law, the period of limitation shall be ten years, and for claims for periodic performance and claims relating to the conduct of a business, three years.

b) If the basis for data processing is the performance of a contract, then the Customer's personal data shall be processed by RUGS EU as long as it is necessary for the performance of the contract, and thereafter for a period corresponding to the period of limitation of claims. If a special provision does not state otherwise, the period of limitation shall be ten years, and for periodical performance claims and claims related to conducting business activity - three years.

 4.   If you make a purchase in the Shop Online, your personal data may be transferred to a courier company, in order to deliver the ordered goods.

 5.   If the Customer chooses to pay via PayPal, his/her personal data shall be transferred to the extent necessary for payment to PayPal (Europe) S.à          r.l with headquarters 22-24 Boulevard Royal in Luxembourg, R.C.S. B 118 349. 

 6.   Navigation data may be used to provide better service to Customers, to analyse statistical data and to adapt the Internet Shop to Customers'              preferences, as well as to administer the Internet Shop.

 7.   RUGS EU, in the case of a request addressed to it, shall make personal data available to authorised state authorities, in particular to                          organisational units of the Prosecutor's Office, Police, the President of the Office for Personal Data Protection, the President of the Office for                  Competition and Consumer Protection or the President of the Office of Electronic Communications.

​

§ 3 Cookie mechanism, IP address

 

  1. The Internet Shop uses small files called cookies. They are saved by RUGS EU on the final device of the person visiting the Webshop, if the Internet browser allows it. A cookie file usually contains the name of the domain it came from, its "expiry time" and an individual random number identifying the file. Information collected by cookies of this type helps to customise products offered by RUGS EU to the individual preferences and real needs of visitors to the Online Shop. They also make it possible to compile general statistics of visits to the presented products in the Internet Shop.

  2. RUGS EU uses two types of cookies:

a) Session cookies: after ending the session of a given browser or switching off the computer, the stored information is deleted from the device memory. The mechanism of session cookies does not allow collecting any personal data or any confidential information from Clients' computers.

b) Permanent cookies: are stored in the memory of the Customer's terminal equipment and remain there until they are deleted or expire. The mechanism of persistent cookies does not allow collecting any personal data or any confidential information from the Clients' computer.

 3.   RUGS EU uses its own cookies in order to:

a) authenticate the Customer in the Internet Shop and ensure a Customer session in the Internet Shop (after logging in), thanks to which the Customer does not have to enter his/her login and password again on each subpage of the Internet Shop;

b) analyses and research as well as audience audit, and in particular for creating anonymous statistics which help to understand how the Customers use the Internet Shop's website, which enables improving its structure and content.

 4.    RUGS EU uses external cookies in order to:

a) popularising the Internet Shop by means of the facebook.com social network (administrator of external cookies: Facebook Inc based in the USA or Facebook Ireland based in Ireland);

b) to present on the Store's information pages a map showing the location of the RugsEU office by means of the maps.google.com website (administrator of external cookies: Google Inc. based in the USA);

c) collection of general and anonymous statistical data by means of Google Analytics analytical tools (administrator of external cookies: Google Inc. based in the USA);

 5.    The cookie mechanism is safe for the Customers' computers of the Internet Shop. In particular, it is not possible for viruses or other unwanted               software or malware to get into Customers' computers via this route. Nevertheless, Customers have the possibility to limit or disable access of             cookies to their computers in their browsers. In the case of using this option, use of the Online Store will be possible, except for functions that by         their nature require cookies

 6.    Below we present how to change the settings of popular web browsers regarding the use of cookies:

a) Internet Explorer browser;

b) Microsoft EDGE browser;

c) Mozilla Firefox browser;

d) Chrome browser;

e) Safari browser;

f) Opera browser.

 7.    RUGS EU may collect Customers' IP addresses. IP address is a number assigned to the computer of the person visiting the Internet Shop by the             Internet Service Provider. The IP number enables access to the Internet. In most cases, it is assigned to the computer dynamically, i.e. it changes           each time the computer is connected to the Internet and for this reason it is commonly treated as non-personal identification information. The IP             address is used by RUGS EU to diagnose technical problems with the server, to create statistical analyses (e.g. to determine from which regions           we record the highest number of visits), as information useful for administration and improvement of the Internet Shop, as well as for security               purposes and possible identification of server-loading, unwanted automatic programmes for browsing the contents of the Internet Shop.

 8.    The Internet Shop contains links and references to other websites. RUGS EU shall not be liable for the privacy protection rules applicable therein.

​

§ 4 Data subjects' rights

 

  1. Right to withdraw consent - legal basis: article 7(3) RODO.

a) The customer shall have the right to withdraw any consent given by RUGS EU.

b) The withdrawal of consent shall have effect from the moment of withdrawal.

c) The withdrawal of consent shall not affect the processing carried out by RUGS EU in accordance with the law prior to the withdrawal of consent.

d) The withdrawal of consent does not entail any negative consequences for the Customer, but it may prevent the Customer from continuing to use services or functionalities that RUGS EU can legally provide only with consent.

 2.   Right to object to the processing of data - legal basis: Article 21 RODO.

a) The Customer has the right to object at any time - for reasons related to his/her particular situation - to the processing of his/her personal data, including profiling, if RUGS EU processes his/her data on the basis of legally justified interests, e.g. marketing of RUGS EU products and services, conducting statistics on the use of particular functionalities of the Online Shop and facilitating the use of the Online Shop, as well as satisfaction surveys.

b) Resignation in the form of an e-mail message from receiving marketing messages concerning products or services will mean that the Customer objects to the processing of his/her personal data, including profiling for these purposes.

c) If the Customer's objection proves to be valid and RUGS EU has no other legal basis for processing the personal data, the Customer's personal data will be erased, the processing of which the Customer has objected to.

 3.    The right to erasure ("right to be forgotten") - legal basis: article 17 of the RODO.

I) The Customer has the right to request the erasure of all or some personal data.

II) The Customer has the right to request erasure of personal data if:

a) the personal data are no longer necessary for the purposes for which they were collected or processed;

b) he/she has withdrawn specific consent, to the extent that the personal data were processed on the basis of his/her consent;

c) he/she has objected to the use of his/her data for marketing purposes;

d) the personal data are unlawfully processed;

e) the personal data must be erased in order to comply with a legal obligation under Union law or the law of a Member State to which RUGS EU is subject;

f) the personal data were collected in connection with the offering of information society services.

III) Despite a request to erasure of the personal data, due to an objection or withdrawal of consent, the RUGS EU may retain certain personal data to the extent that the processing is necessary for the establishment, assertion or defence of claims, as well as to comply with a legal obligation requiring processing under Union Law or the law of a Member State to which the RUGS EU is subject. This applies in particular to personal data such as your name, surname, e-mail address, which will be stored for the purpose of handling complaints and claims relating to the use of RUGS EU services, or additionally your address/correspondence address, order number, which will be stored for the purpose of handling complaints and claims relating to concluded sales contracts or the provision of services.

 4.    The right to restrict data processing - legal basis: article 18 of the RODO.

I) The Customer has the right to request the restriction of the processing of his/her personal data. The submission of a request, until it is considered, prevents the use of certain functionalities or services, the use of which will involve the processing of data covered by the request. RUGS EU will also not send any messages, including marketing messages.

II) The Customer has the right to request the restriction of the use of personal data in the following cases:

a) when he/she questions the correctness of his/her personal data, in which case RUGS EU shall restrict the use of the data for the time needed to verify the correctness of the data, but for no longer than 7 days;

b) when the processing of the data is unlawful and instead of deleting the data the Client requests the restriction of its use;

c) when the personal data are no longer necessary for the purposes for which they were collected or used, but are needed by the Client to establish, assert or defend a claim;

d) when he/she has objected to the use of his/her data - then the restriction shall take place for the time necessary to consider whether, due to the particular situation, the protection of the interests, rights and freedoms of the Client outweighs the interests pursued by the Administrator by processing the Client's personal data.

 5.    Right of access to data - legal basis: Article 15 RODO. The Customer has the right to obtain confirmation from the Administrator as to whether it         is processing personal data, and if this is the case, the Customer has the right to:

a) gain access to his/her personal data;

b) obtain information about the purposes of processing, the categories of personal data processed, the recipients or categories of recipients of such data, the intended period of storage of the Customer's data or the criteria for determining this period (where it is not possible to determine the intended period of data processing), the Customer's rights under the RODO and the right to lodge a complaint to the supervisory authority, the source of such data, automated decision-making, including profiling, and the safeguards applied in connection with the transfer of such data outside the European Union;

c) obtain a copy of your personal data.

 6.   Right to rectification - legal basis: article 16 of the RODO - The Customer has the right to request the Administrator to immediately rectify personal        data concerning him/her that are incorrect. Taking into account the purposes of the processing, the Customer to whom the data pertains has the          right to request the completion of incomplete personal data, including by providing an additional statement, by directing the request to the e-mail        address in accordance with §6 of the Privacy Policy.

 7.   The Customer may lodge complaints, enquiries and requests to the Administrator regarding the processing of his/her personal data and the                exercise of his/her rights.

 8.   The Customer has the right to request RUGS EU to provide a copy of the standard contractual clauses by submitting an enquiry in the manner              indicated in §6 of the Privacy Policy.

 9.  The Customer shall have the right to lodge a complaint with the President of the Office for Personal Data Protection regarding infringement of its           rights to personal data protection or other rights granted under the RODO.

 

§ 5 Security management - password

 

  1. RUGS EU shall provide Customers with a secure and encrypted connection when transferring personal data and when logging into the Customer Account on the Website. RUGS EU uses an SSL certificate issued by one of the world's leading companies for the security and encryption of data transmitted over the Internet.

  2. In the event that the Customer holding an account with the Online Shop has lost his/her password in any way, the Online Shop shall enable the generation of a new password. RUGS EU shall not send a password reminder. The password shall be stored in an encrypted form in such a manner that it cannot be read. In order to generate a new password, the e-mail address shall be provided in the form available under the link "You have forgotten your password", provided when logging in to the Online Shop account. The Customer shall receive an e-mail message to the e-mail address provided during registration or saved in the last change of the account profile, containing a redirection to a dedicated form made available on the Shop's Website, where the Customer shall have the opportunity to set a new password.

  3. RUGS EU shall never send any correspondence, including electronic correspondence, asking for login data and in particular the password to access the Customer's account.

 

§ 6 Changes in the Privacy Policy

 

  1. The Privacy Policy may be subject to change, of which RUGS EU shall inform the Clients 7 days in advance.

  2. Questions related to the Privacy Policy shall be sent to the following address: info@rugseu.com.

.

bottom of page