Privacy and Cookies Policy


§1. WHO IS THE PERSONAL DATA CONTROLLER?

      1. The personal data controller is Telimena Stachnik, running a business under the name TS Telimena Stachnik, at the following address: Ropczyce, 39-100 Ropczyce, 3-Maja 247, NIP: 8181737032, in accordance with the document generated from the Central Registration and Information on Business system.
      2. Contact with the Administrator is possible at the above-mentioned address and e-mail address: telismanofficial@gmail.com and by telephone: +48 608 230 283
      3. When contacting the Administrator via e-mail, contact form, social media and other communication channels, you provide your personal data, for example your name and e-mail address.
      4. The Administrator places great importance on the security and lawfulness of the processing of Users' personal data. Users' personal data are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as "GDPR"), and other currently applicable data protection laws.

§2. DEFINITIONS

ADMINISTRATOR

Telimena Stachnik, conducting business activity under the name TS Telimena Stachnik, at the following address: Ropczyce, 39-100 Ropczyce, 3-Maja 247, NIP: 8181737032, in accordance with the document generated from the Central Registration and Information on Business. __

PERSONAL DATA

Information that identifies or allows for the identification of a specific person, e.g. name and surname, address, telephone number, e-mail address, PESEL number, sensitive data such as health information.

POLICY

This Privacy Policy.

GDPR

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

SERVICE/SHOP

The website at www.telisman.com and all its subpages, through which Users can place orders, browse its content, contact the Administrator, and order commercial and marketing information via the Newsletter service.

USER

Any natural person visiting the Website, social media operated by the Administrator or using one or more services or functionalities described in the Privacy Policy.

§3. WHAT PERSONAL DATA ARE PROCESSED BY THE ADMINISTRATOR IN CONNECTION WITH THE USE OF THE SERVICE?

 

      1. The Website enables the User to contact the Administrator and provide him with identification and contact details, as well as data related to the content of messages.
      2. The Administrator collects data related to User activity, such as time spent on the website, search phrases, number of subpages viewed, date and source of visits.
      3. The Personal Data Administrator comes into possession of the User's data in most cases due to the User's actions, i.e. if the User contacts the Administrator, places an order, submits a complaint, withdraws from the contract, or subscribes to the Newsletter.
      4. In connection with the User's use of the Website, the Administrator collects data to the extent necessary to provide individual services offered or to conclude the Agreement, including name, surname and e-mail address.
      5. In order to subscribe to the Administrator's Newsletter, the Administrator collects the following data: e-mail address.
      6. Detailed rules and purposes of processing personal data collected when using the Website are described below.

§4. FOR WHAT PURPOSES AND ON WHAT LEGAL BASIS ARE THEY PROCESSED BY THE CONTROLLER?

The personal data of all persons using the Website are processed by the Administrator for the purpose of:

      1. Preparation and execution of the Sales Agreement – ​​as well as the exercise of rights arising therefrom. Data are processed on the basis of Article 6(1)(b) of the GDPR;
      2. Analyzing network traffic, ensuring security within the Website, and customizing content. Data is processed on the basis of Article 6(1)(f) of the GDPR;
      3. Responding to correspondence , forwarding the requested offer and conducting correspondence. Data are processed on the basis of Article 6 paragraph 1 letter a) and f) of the GDPR;
      4. Providing and displaying content on the Website – for this purpose, the Administrator collects personal data in the form of: IP address, cookies. Data is processed on the basis of Article 6(1)(f) of the GDPR;
      5. Establishing, defending, and pursuing claims – the legal basis for processing is the Controller's legitimate interest in protecting its rights. Data are processed on the basis of Article 6(1)(f) of the GDPR;
      6. User posting opinions about the services provided by the Controller or Goods, Digital Content, and opinion research through surveys . Data are processed on the basis of Article 6(1)(a) of the GDPR, i.e. the consent of the data subject;
      7. The use of cookies on the Website and its subpages pursuant to Article 6(1)(a) of the GDPR, i.e. the consent of the data subject;
      8. Registration and creation of an Account in the Store . Data are processed on the basis of Article 6(1)(a) of the GDPR, i.e. the consent of the data subject;
      9. Sending a request for an opinion on the Controller's services and goods via external satisfaction survey services . Data are processed on the basis of Article 6(1)(a) of the GDPR, i.e. the consent of the data subject;
      10. For analytical and statistical purposes – consisting in conducting analyses of User activity on the Website in order to improve the functionalities used. Data are processed on the basis of Article 6(1)(f) of the GDPR;
      11. Sending requested marketing information electronically (Newsletter). Data is processed on the basis of Article 6(1)(a) of the GDPR);
      12. Registration and creation of an Account in the Store. Data are processed on the basis of Article 6(1)(a) of the GDPR;
      13. To contact the Administrator, you can use an electronic contact form. Using the form requires the provision of personal data necessary to establish contact. You may also provide other data to facilitate contact or process your inquiry. Providing data marked as mandatory is required to accept and process your inquiry, and failure to provide it will result in the inability to process it. Providing the remaining data is voluntary. Personal data is processed to identify the sender and process their inquiry submitted via the form provided. Data is processed pursuant to Article 6(1)(b) of the GDPR; for data provided optionally, the legal basis for processing is consent (Article 6(1)(a) of the GDPR).

§5. USER RIGHTS RELATED TO THE PROCESSING OF THEIR PERSONAL DATA

The GDPR grants the following rights related to the processing of personal data:

      1. The right to be informed about the processing of personal data and to receive a copy thereof (Article 12 of the GDPR);
      2. The right to access your personal data (15 GDPR);
      3. The right to correct, supplement, update and rectify personal data (16 GDPR);
      4. The right to erasure (the right to be forgotten) (Article 17 GDPR);
      5. The right to restrict processing referred to in (Article 18 of the GDPR);
      6. The right to object to the processing of personal data (Article 21 of the GDPR);
      7. The right to lodge a complaint with the supervisory authority (i.e. the President of the Personal Data Protection Office) (Article 77 of the GDPR);

Not all of these rights will apply to the User at all times and in every case. This is due to the nature of legal provisions. Failure to provide the required data will prevent the performance of a distance contract, the issuance of a bill or invoice, or contact at the request of the data subject.

§6. WHAT IS THE PERIOD OF PROCESSING PERSONAL DATA?

      1. The period of processing of the User's personal data by the Administrator depends on the type of service provided and the purpose of processing.
      2. The User's personal data will be stored until the consent is withdrawn or until the matter is resolved or the Agreement is completed.
      3. Conclusion and performance of the Sales Agreement, including distance selling - for the period necessary to document the performed contract, including issuing a bill or invoice - 5 years, counting from the end of the calendar year in which the tax payment deadline expired.
      4. Data related to web traffic analysis collected via cookies and similar technologies may be stored until the cookie expires. Some cookies never expire, therefore, the data retention period will be equivalent to the time necessary for the Administrator to achieve the data collection purposes, such as ensuring security and analyzing historical data related to website traffic.
      5. The data processing period may be extended if processing is necessary to establish, pursue, or defend against potential claims, and after that period only if and to the extent required by law. After the processing period, the data is irreversibly deleted or anonymized.

§7. DATA SECURITY

Users' personal data are stored and protected with due diligence, in accordance with the Administrator's implemented internal procedures. The Administrator processes User information using appropriate technical and organizational measures that meet the requirements of generally applicable law, in particular personal data protection regulations. These measures are primarily intended to protect Users' personal data from unauthorized access. In particular, only authorized individuals have access to Users' personal data, and they are obligated to keep this data confidential.

At the same time, the User should exercise due diligence in securing his/her personal data transmitted via the Internet, in particular not to disclose his/her login details to third parties, use anti-virus protection and update the software.

§8. TRANSFER OF DATA TO THIRD PARTIES

      1. The User's personal data may be transferred to third parties whose services the Administrator uses in connection with running the Website, for example:
        • Website hosting;
        • Providing legal services;
        • Providing accounting services;
        • Providing office services;
        • Courier services broker
        • Maintaining and sending the newsletter;
        • Operating the payment system and electronic transactions;
        • Servicing and maintaining IT systems in which data is processed, including for the purpose of automating the Newsletter, issuing invoices, processing orders, etc.;
        • Dropshipping and/or order logistics.
      2. Personal data may be processed outside the European Economic Area in a so-called third country, in particular in the United States of America, in connection with the Controller's use of IT solutions whose servers are located outside the European Economic Area. The basis for data processing in third countries will be European Commission Decision 2021/914 on standard contractual clauses for the transfer of personal data to third countries. The Controller and service provider will ensure the highest level of data protection. Data processing will not violate the privacy of individuals.
      3. Entities processing data in the European Economic Area:
      4. "Abacus" in the field of accounting services;
      5. ________ in the scope of office services
      6. "Shopify" for technical and administrative support in running a website, including an online store;
      7. Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02X525, Ireland (formerly Facebook Ireland Limited ) for the operation of social media;
      8. Facebook Ireland Ltd. – in relation to the use of Meta Platforms (Facebook) advertising tools and the transfer of data within a custom audience;
      9. - Fakturownia sp. z o. o. with its registered office in Warsaw at ul. Juliana Smulikowskiego 6/8, 00-389 Warsaw, KRS: 0000572426, NIP: 5213704420

- FIRMA SA with its registered office in Wrocław, ul. Grabiszyńska 241b, 53-234 Wrocław, KRS 0000281947, NIP: 8981647572

in the scope of issuing accounting documents;

      1. - Przelewy 24 – PayPro SA with its registered office in Poznań, at ul. Pastelowa 8, 60-198 Poznań, KRS 0000347935, NIP number 7792369887, REGON: 301345068.

- Tpay - National Payment Integrator SA with its registered office in Poznań, plac Andersa 3, 17th floor 61-894 Poznań, KRS: 0000412357, NIP 7773061579.

      1. - Blue Media SA with its registered office in Sopot, ul. Powstańców Warszawy 6, 81-718 Sopot, KRS: 0000320590, NIP 5851351185.

- For foreign payments - PayPal (Europe) S.à rl et Cie, SCA with its registered office in Luxembourg, L-2449, duly authorized in Luxembourg to operate as a credit institution within the meaning of Article 2 of the Financial Sector Act of 5 April 1993 (as amended), subject to the supervision of the Luxembourg Financial Supervisory Commission (Commission de Surveillance du Secteur Financier, CSSF), registered with RCS Luxembourg under number B 118 349;

- in the scope of handling the payment system and electronic transactions ;

      1. - MailerLite Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland

- FreshMail sp. z o. o. in Kraków, KRS: 0000497051;

- GetResponse SA, with its registered office in Gdańsk, al. Grunwaldzka 413, 80-309 Gdańsk, KRS 0000942075, NIP 9581468984.

– regarding the sending of the newsletter

      1. Other contractors or subcontractors engaged in technical or administrative support or to provide legal assistance to the Controller and its clients, e.g. accounting, IT, graphic design, copywriting assistance, debt collection agencies, lawyers, etc.
      2. Offices, e.g. the tax office – in order to fulfill legal and tax obligations related to settlements and accounting.
      3. Entities processing data outside the European Economic Area:
      4. Google Analytics by Google LLC – in the scope of using the Website security tools and statistical analysis tools (Google Analytics).
      5. YouTube by Google LLC – for embedding audiovisual materials on my pages;
      6. Vimeo, Inc. – in the scope of embedding audiovisual materials on the website;
      7. Google Analytics by Google LLC – for marketing tools;
      8. Disqus – for embedding comments under articles on the website;
      9. Manychat, 535 Mission St., San Francisco, CA 94105 for sending automatic messages on the Administrator’s social networking sites.
      10. As part of the Administrator's activities, social media plugins have also been embedded on the website. The purpose and scope of data collection and its further processing and use by service providers are described in the privacy policies indicated below:
      11. Facebook – https://www.facebook.com/privacy/explanation
      12. Instagram- https://help.instagram.com/519522125107875?helpref=page_content
      13. Tik-Tok - https://www.tiktok.com/legal/page/eea/privacy-policy/pl
      14. LinkedIn – https://www.linkedin.com/legal/privacy-policy
      15. Pinterest – https://policy.pinterest.com/pl/privacy-policy
      16. Vimeo, Inc. – https://vimeo.com/features/video-privacy
      17. YouTube – https://support.google.com/youtube/answer/7671399

 

§9. COOKIES AND TRACKING TECHNOLOGIES

 

      1. This website uses cookies.
      2. When you first visit the Website, you will be informed about the use of cookies. Failure to change your browser settings constitutes consent to their use.
      3. The website enables the collection of user information via cookies and similar technologies, the use of which typically involves installing this tool on the user's device (computer, smartphone). This information is used to remember user decisions (font selection, contrast, policy acceptance), maintain user sessions (e.g., after logging in), remember passwords (with consent), collect information about the user's device and visit for security purposes, as well as to analyze visits and customize content.
      4. Information obtained via cookies and similar technologies is not combined with other data of website users, nor is it used to identify them by the Administrator.
      5. Cookies are short text files stored on the device the User uses to browse websites.
      6. They can be read by the Administrator ("own cookies" which the Administrator uses to ensure the proper functioning of this website), as well as by systems belonging to other entities whose services the Administrator uses ("external cookies").
      7. The user has the right to change cookie settings in their browser or to delete them.
      8. The user also has the option of using the website in so-called incognito mode, which blocks the collection of data about their visit.
      9. This website uses the following tracking technologies:

social plugins such as: Facebook, Instagram, Tik-Tok;

analytical and marketing tools such as: Google Analytics, Facebook Pixel.

§10. SERVER LOGS

      1. Using the website involves sending queries to the server on which the website is hosted. Each query sent to the server is saved in server logs, which include: the IP address of the computer sending the query; language; time of receipt; browser information; access times and the address of the page from which the User was redirected; and information about the web browser or information system the User is using.
      2. The data stored in the server logs is not associated with specific people using the website and is used as auxiliary material for administrative purposes.
      3. Logs are saved and stored on the server
      4. The Administrator does not use server logs in any way to identify the User.

§11. SOCIAL MEDIA

 

      1. The Administrator has profiles on Facebook and Instagram (hereinafter referred to as "fan pages"). Content, offers, and product recommendations are regularly published and shared on these fan pages.
      2. Social media administrators record user behavior using cookies and other similar technologies whenever you interact with our fan pages and other Facebook and Instagram websites.
      3. Social media administrators have access to general statistics regarding the interests and demographic data (such as age, gender, and place of residence) of users visiting fan pages. When using social media, the scope and purposes of data processing on social media are determined by the administrators of those sites.