1 GENERAL PROVISIONS

1. The Controller of personal data collected via the online store www.peptofit.pl is S. K. entered into the Central Registration and Information on Business, registered office address and place of business: ul. Wronia 45 -37 00-870 Warsaw, NIP: 7010666313, REGON: 540383968, e-mail address: info@peptofit.pl, hereinafter referred to as the "Controller" and being at the same time the "Service Provider".

2. Personal data collected by the Controller via the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the GDPR.

3. Any words or expressions written in capital letters in the content of this Privacy Policy should be understood in accordance with their definitions contained in the Regulations of the online store www.peptofit.pl.

2. TYPE OF PERSONAL DATA PROCESSED, PURPOSE AND SCOPE OF DATA COLLECTION

1. PURPOSE OF PROCESSING AND LEGAL BASIS. The Administrator processes the personal data of Service Users of the www.peptofit.pl Store in the event of:

2. TYPE OF PERSONAL DATA PROCESSED. The Service Recipient provides, in the case of:

3. PERSONAL DATA ARCHIVING PERIOD. The personal data of Service Users are stored by the Administrator:

4. When using the Store, additional information may be downloaded, in particular: the IP address assigned to the Service User's computer or the external IP address of the Internet provider, domain name, browser type, access time, type of operating system.

5. After expressing separate consent, pursuant to Article 6 paragraph 1 letter a) of the GDPR, data may also be processed for the purpose of sending commercial information by electronic means – in connection with Article 10 paragraph 2 of the Act of 18 July 2002 on the provision of services by electronic means, including those directed as a result of profiling, provided that the Service User has given appropriate consent.

6. Navigational data may also be collected from Service Users, including information about links and hyperlinks they choose to click or other actions they take on the Store. The legal basis for this type of activity is the Controller's legitimate interest (Article 6, Section 1, Letter f of the GDPR), which consists in facilitating the use of services provided electronically and improving the functionality of these services.

7. Providing personal data by the Service User is voluntary, however, refusal to provide data marked as mandatory will prevent the execution of the order or the provision of the service.

8. The Administrator takes special care to protect the interests of data subjects, and in particular ensures that the data collected by him are:

3. SHARING PERSONAL DATA

1. Personal data of Service Users may be transferred to external entities only to the extent necessary to fulfill the order, process payments and provide services related to running the Store.

2. Entities to which personal data are transferred process them in accordance with the requirements of the GDPR and secure them in a manner appropriate to the risks.

3. The personal data of Service Users are stored within the European Economic Area (EEA).

4. THE RIGHT TO CONTROL, ACCESS AND CORRECT YOUR OWN DATA

1. The data subject has the right to access the content of his or her personal data and the right to rectify, delete, limit processing, the right to data transfer, the right to object, the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

2. Legal basis for the Service Recipient's request:

3. In order to exercise the rights referred to in point 2, you can send an appropriate e-mail to the following address: info@peptofit.pl.

4. If the Service User exercises the above rights, the Administrator will either comply with the request or refuse to comply with it immediately, but no later than one month after receiving it. However, if – due to the complex nature of the request or the number of requests – the Administrator is unable to comply with the request within one month, the Administrator will comply with it within the next two months, informing the Service User within one month of receiving the request of the intended extension and the reasons therefor.

5. If it is found that the processing of personal data violates the provisions of the GDPR, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office.

§ 5 COOKIES„

1. The Administrator's website uses cookies.

2. The installation of cookies is necessary for the proper provision of services on the Store's website. Cookies contain information necessary for the proper functioning of the website and also enable the compilation of general website visitor statistics.

3. The website uses two types of cookies: "session" and "persistent".

4. The Administrator uses its own cookies to better understand how Service Users interact with the website's content. These cookies collect information about how the Service User uses the website, the type of website from which the Service User was redirected, and the number and duration of the Service User's visits to the website. This information does not record specific personal data about the Service User, but is used to compile website usage statistics.

5. The Service User has the right to decide on the access of cookies to his/her computer by:

§ 6 ANALYTICAL AND MARKETING TOOLS

1. The Administrator may use analytical and marketing tools to improve the functionality of the website and adapt the offer to the needs of Service Users.

2. In the future, the Administrator may use the following tools:

3. Using the above tools involves the use of third-party cookies. The Service User can manage consent to these cookies using the cookie settings management mechanism available on the website.

4. If the Service User does not want the data collected during a visit to the website www.peptofit.pl to be used by analytical or marketing tools, he or she may configure cookie settings accordingly or log out of the relevant services before visiting the website.

§ 7 FINAL PROVISIONS

1. The Administrator applies technical and organizational measures to ensure the protection of processed personal data appropriate to the threats and categories of data subject to protection, and in particular protects data against disclosure to unauthorized persons, removal by an unauthorized person, processing in violation of applicable regulations, and alteration, loss, damage or destruction.

2. The Administrator provides appropriate technical measures to prevent unauthorized persons from obtaining and modifying personal data sent electronically.

3. In matters not covered by this Privacy Policy, the provisions of the GDPR and other relevant provisions of Polish law shall apply accordingly.

4. The Administrator reserves the right to make changes to the Privacy Policy, about which Service Users will be informed via a message on the Store's website.