The following Privacy Policy
outlines the principles of processing personal data obtained through the website xnauti.com (hereinafter referred to as the “website”). Ksenia Nauti takes special care to respect the privacy of customers visiting the website.
TYPES OF PROCESSED DATA, PURPOSES, AND LEGAL BASIS
Ksenia Nauti collects information about individuals performing legal actions not directly related to their business activities, individuals conducting business or professional activities on their own behalf, and individuals representing legal entities or organizational units not being legal persons, to whom the law grants legal capacity, conducting business or professional activities on their own behalf, hereinafter collectively referred to as “Customers.”
Personal data of Customers is collected in case of: a) registering an account on the website to create an individual account and manage it; b) placing an order on the website to fulfill the sales contract; c) subscribing to the newsletter (Newsletter) to perform a service provided electronically.
In case of registering an account on the website, the Customer provides: a) email address.
During the registration of an account on the website, the Customer independently sets an individual password to access their account. The Customer can change the password later.
In case of placing an order on the website, the Customer provides the following data: a) email address; b) address details: c) postal code and city; d) country; e) street with house/apartment number. f) first and last name; g) phone number.
In the case of Entrepreneurs, the above scope of data is additionally expanded to: a) Entrepreneur’s company; b) tax identification number (NIP).
In case of using the Newsletter service, the Customer provides the following data: a) email address; b) phone number.
While using the website, additional information may be collected, including: IP address assigned to the Customer’s computer or external IP address of the Internet provider, domain name, browser type, access time, operating system type.
From Customers, navigational data may also be collected, including information about links and references they decide to click or other actions taken on the website. Legal basis – legitimate interest, consisting of facilitating the use of services provided electronically and improving the functionality of these services.
For the purpose of establishing, investigating, and enforcing claims, certain personal data provided by the Customer in using the website functionalities, such as: name, surname, data concerning the use of services, if the claims arise from the way the Customer uses the services, other data necessary to prove the existence of the claim, including the size of the damage suffered.
The provision of personal data to Ksenia Nauti is voluntary; however, failure to provide certain data in the forms during the Registration process makes it impossible to Register and create a Customer Account. In the case of placing an order without registering a Customer Account, it prevents the submission and execution of the Customer’s order.
TO WHOM ARE THE DATA MADE AVAILABLE OR ENTRUSTED, AND HOW LONG ARE THEY STORED?
Customer’s personal data is transferred to service providers used by Ksenia Nauti in operating the website. Service providers to whom personal data is transferred, depending on contractual agreements and circumstances, either follow Ksenia Nauti’s instructions regarding the purposes and methods of processing this data (processing entities) or independently determine the purposes and methods of processing (administrators).
a) Processing entities. Ksenia Nauti uses suppliers who process personal data only on Ksenia Nauti’s instruction. These include hosting service providers, accounting services, providers of marketing systems, systems for analyzing website traffic, systems for analyzing the effectiveness of marketing campaigns. b) Administrators. Ksenia Nauti uses suppliers who do not act solely on Ksenia Nauti’s instructions and independently determine the purposes and methods of using Customer’s personal data. They provide electronic payment and banking services.
Location. Service providers are mainly located in Poland and other countries of the European Economic Area (EEA).
Customer’s personal data is stored:
a) In the case when the legal basis for data processing is consent, the personal data of the Customer is processed by Ksenia Nauti until the consent is withdrawn, and after withdrawing the consent, for a period corresponding to the limitation period for claims that Ksenia Nauti can raise and that can be raised against it. If a specific provision does not state otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activities – three years. b) In the case when the legal basis for data processing is the performance of the contract, the personal data of the Customer is processed by Ksenia Nauti for as long as it is necessary to perform the contract, and after that time for a period corresponding to the limitation period for claims. If a specific provision does not state otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activities – three years.
In the case of Customers using the website without registering an account, personal data is processed for the time necessary to perform the order, and after that time, for a period corresponding to the limitation period for claims. If a specific provision does not state otherwise, the limitation period is six years, and for claims for periodic benefits and claims related to business activities – three years.
Customer’s personal data processed for the purpose of performing the contract is transferred to the administrator of the payment system and stored by this administrator for the time necessary to perform the contract. The payment administrator is an entity authorized to perform payment services (e.g., a bank).
Customer’s personal data processed for the purpose of sending marketing content by electronic means, including the Newsletter, is processed until the Customer withdraws the consent.
Customer’s personal data processed for the purpose of handling complaints, submitting claims, and for purposes resulting from generally applicable laws are processed for the time necessary to achieve these purposes, not longer than for the period of limitation of claims.
CUSTOMER’S RIGHTS
Customers have the right to:
- Access to the content of their data and the right to rectify it;
- Delete data;
- The right to limit processing;
- The right to data transfer;
- The right to object;
- The right to withdraw consent at any time without affecting the legality of processing (if the processing is based on consent before its withdrawal);
- The right to lodge a complaint with the supervisory body in relation to the processing of personal data by Ksenia Nauti.
To exercise the rights referred to in point 1-5 and point 7, contact the Administrator by selecting the appropriate option in the Contact section.
INFORMATION ABOUT THE REQUIREMENT/VOLUNTARY NATURE OF PROVIDING DATA
The provision of data by the Customer is voluntary but necessary to create a Customer Account, place an order, and use the Newsletter service.
INFORMATION ON AUTOMATED DECISION MAKING, INCLUDING PROFILING
Customer’s personal data will be processed in an automated way (including in the form of profiling), however, it will not cause legal effects for the Customer or have a significant impact on their situation.
COOKIES AND SIMILAR TECHNOLOGIES
The website uses cookies. Cookies are small text files sent by a website visited by a user to the user’s device. Cookies are used for the proper functioning of the website.
Ksenia Nauti uses its cookies for the following purposes: a) the proper functioning of the website, including the possibility of creating an account and logging in to it, and remembering the cart contents; b) maintaining the user’s session (after logging in), thanks to which the user does not have to re-enter the login and password on every subpage of the website; c) adaptation of the content of the website to the user’s preferences and optimizing the use of websites; in particular, these files allow to recognize the device of the website user and properly display the website, tailored to their individual needs; d) creating statistics that help to understand how users use websites, which allows improving their structure and content.
As part of the website, third-party cookies are used (e.g., Google Analytics, Facebook, Instagram, Pinterest). These cookies are subject to the privacy policy of the respective service providers: Google, Facebook, Instagram, Pinterest.
The website also uses web beacons (pixels). These are small graphic files that allow you to log into a computer or other device information such as the IP address, URL address of the website, the browser used, and the like.
The website may also contain links to other websites. Ksenia Nauti recommends that after going to other websites, read the privacy policy there.
CONTACT WITH CUSTOMERS
The Administrator may contact the Customer in matters related to the services provided electronically, also for direct marketing of their own products or services. The Administrator may send messages related to the services provided electronically and other messages, in particular related to changes in these services or the Administrator’s offer.
FINAL PROVISIONS
The website may contain links to other websites. Ksenia Nauti recommends that after going to other websites, read the privacy policy there.
Ksenia Nauti uses technical and organizational measures to ensure the protection of personal data being processed, appropriate to the threats and categories of data protected, and in particular, protects data against unauthorized disclosure, unauthorized removal, processing with violation of applicable laws, and change, loss, damage, or destruction.
Ksenia Nauti provides the following technical measures to prevent the unauthorized access and modification of personal data transmitted electronically: a) securing the data set against unauthorized access.
The customer logs in by entering an email address and password. When registering, the Customer sets an individual password. The password is confidential and known only to the Customer. The Customer may change the password after logging in.
Ksenia Nauti applies organizational measures to ensure the protection of personal data processed appropriate to the threats and categories of data being protected, and in particular, it ensures that:
a) Data sets are processed in accordance with the law; b) Data is protected against unauthorized access; c) Data is protected against being processed in violation of the law; d) Data is subject to change, loss, damage, or destruction.
The information about the threat and the security measures applied is secret and confidential. The Customer is obliged to keep secret and confidential any information about the threat and the security measures applied.
CHANGES TO PRIVACY POLICY
Ksenia Nauti reserves the right to change this Privacy Policy for important reasons, i.e., changes in legislation, changes in the range and provision of services through the Website, changes in technical and organizational protection measures. The Customer will be informed about the change by information about the change of the Privacy Policy placed on the Website. The change of the Privacy Policy comes into effect on the date indicated by the Administrator, not shorter than 7 days from the date of placing the information about the change on the Website. The Customer has the right to object to the change in the Privacy Policy within 14 days from the date of notification. In the event of such an objection, the Service cannot be continued.
REMARKS
Ksenia Nauti reserves the right to process personal data, provided that it is necessary to establish, investigate, or defend against any claims that may be raised, as well as if the law requires processing.
The privacy policy may be subject to changes and updates, so it is recommended to periodically review this policy to stay informed about how personal data is protected. The current version of the privacy policy is always available on the website.
This Privacy Policy is valid from [insert effective date] and was last updated on 29 Feb 2024.