Maritime Hair Center
Privacy Policy
Definitions
Data Controller – Maritime Hair Center
Personal Data – means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Policy – this document
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Scope of Collected Data
In connection with the User's use of the Website, the Data Controller collects personal data to the extent necessary to provide the specific services offered, as well as information about the User's activity.
Personal data of all individuals using the Website (including IP address, identifiers, and information collected via cookies) are processed by the Data Controller for the following purposes:
Purposes of Processing
Provision of electronic services – making content stored on the Website available, as well as providing contact forms.
Legal basis: Art. 6(1)(b) GDPR
Analytical and statistical purposes – conducting analyses of Users' activity and their preferences to improve functionality and the services provided.
Legal basis: Art. 6(1)(f) GDPR
Establishment and enforcement of claims – protecting the Data Controller's rights and eventual defense against claims.
Legal basis: Art. 6(1)(f) GDPR
System Logs
The User's activity on the Website, including personal data, is recorded in system logs (a special computer program used to store a chronological record containing information about events and activities concerning the IT system used to provide services by the Data Controller). The information collected in the logs is processed in connection with the provision of services. The Data Controller also processes it for technical purposes – to ensure the security and proper functioning of IT systems, e.g., in connection with creating backups, testing changes in IT systems, detecting irregularities, or protecting against abuse and attacks.
Contact Form
The Data Controller enables contact via an electronic contact form. Using the form requires providing personal data necessary to establish contact and respond to the inquiry. The User may also provide other data to facilitate contact or request handling. Providing data marked as mandatory is required to accept and handle the inquiry – failure to provide it results in the inability to handle the request. Providing other data is entirely voluntary.
Personal data provided via the contact form are processed to identify the sender and handle their inquiry submitted via the provided form – the legal basis for processing is the necessity of processing for the performance of a service contract (Art. 6(1)(b) GDPR).
Cookies
Cookies are small text files installed on the device of the User browsing the Website. Cookies collect information that facilitates the use of the website – e.g., by remembering visits and actions taken.
The Data Controller uses the so-called service cookies primarily to provide the User with electronically supplied services and to improve the quality of these services. In connection with this, the Data Controller and other entities providing analytical and statistical services to it use cookies, storing information or gaining access to information already stored on the User's telecommunications terminal equipment (computer, phone, tablet, etc.).
Necessary
Enable the use of services available within the website, e.g., authentication cookies used for services that require authentication
Security
Used to detect authentication fraud or abuse within the website
Performance
Enable the collection of information on how the website's pages are being used
Retention Period
The period of data processing depends on the type of service provided and the purpose of processing. As a general rule, data are processed for the duration of the provision of the service, until the withdrawal of consent, or until a successful objection to data processing is raised in cases where the legal basis for data processing is the Data Controller's legitimate interest. The data processing period may be extended if processing is necessary to establish and pursue potential claims or defend against them, and after that time only if and to the extent required by law. After the processing period expires, the data are irreversibly deleted or anonymized.
User Rights
Access to your personal data
Right to rectification of data
Right to erasure or restriction of processing
Right to object to processing
Right to data portability
Right to lodge a complaint with PUODO
If you believe that the processing of personal data violates the provisions of the GDPR or other regulations regarding personal data protection, the data subject may lodge a complaint with the President of the Personal Data Protection Office (PUODO).
Data Security
The Data Controller continuously conducts risk analyses to ensure that personal data are processed securely – ensuring, above all, that only authorized persons have access to the data and only to the extent necessary for their tasks. The Data Controller ensures that all operations on personal data are recorded and carried out only by authorized employees and associates.
The Data Controller does not use profiling. The Data Controller has not appointed a Data Protection Officer.