1. General information
- This policy applies to the website operating at the following url: winoland.com
- The website operator and the personal data administrator is: WINOLAND Hubert Sochacki ul. Łubinowa 4
- Operator’s e-mail address: firstname.lastname@example.org
- The operator is the Administrator of your personal data in relation to the data provided voluntarily on the Website.
- Website uses personal data for the following purposes:
- Operating a newsletter
- Operating a comments system
- Handling inquiries via the form
- Preparing, packing, shipping goods
- Provision of ordered services
- Presentation of an offer or information
- The website performs the functions of obtaining information about users and their behavior in the following way:
- By voluntarily entering data in forms, which are entered into the Operator’s systems.
- By saving cookie files (so-called “cookies”) in end devices.
2. Selected data protection methods used by the Operator
- Login areas and entering personal data are protected in the transmission layer (SSL certificate). Thanks to this, personal data and login data entered on the website are encrypted on the user’s computer and can only be read on the target server.
- Personal data stored in the database is encrypted in such a way that only the Operator key can read them. Thanks to this, data is protected in the event of the database being stolen from the server.
- User passwords are stored in hashed form. The hashing function works in one direction – it is not possible to reverse its operation, which is currently a modern standard for storing user passwords.
- Operator periodically changes its administrative passwords.
- In order to protect data, the Operator regularly makes backup copies.
- An important element of data protection is regular updating of all software used by the Operator to process personal data, which in particular means regular updates of programming components.
- The website is hosted (technically maintained) on the operator’s server: linuxpl.com
- Registration data of the hosting company: H88 S.A. with its registered office in Poznań, Franklina Roosevelta 22, 60-829 Poznań, entered into the National Court Register by the District Court Poznań – Nowe Miasto and Wilda in Poznań, VIII Commercial Division of the National Court Register under KRS number 0000612359, REGON number 364261632, NIP number 7822622168, share capital PLN 210,000.00 fully paid.
- The hosting company:
- uses data loss protection measures (e.g. disk arrays, regular backups),
- applies adequate security measures processing sites in the event of fire (e.g. special fire extinguishing systems),
- uses adequate measures to protect processing systems in the event of a sudden power failure (e.g. dual power lines, generators, UPS voltage support systems),
- applies physical measures to protect access to data processing sites (e.g. access control, monitoring),
- uses measures to ensure appropriate environmental conditions for servers as elements of the data processing system (e.g. control of environmental conditions, specialized air conditioning systems),
- applies organizational solutions to ensure the highest possible level of protection and confidentiality (training, internal regulations, password policies, etc.),
- appointed a Data Protection Officer.
- Hosting company in order to ensure technical reliability maintains logs at the server level.The following may be recorded:
- resources specified by the URL identifier (addresses of the requested resources – pages, files),
- time of request arrival,
- time of sending the response,
- name of the client station – identification carried out by the HTTP protocol,
- information about errors that occurred during the implementation of the HTTP transaction,
- URL address of the page previously visited by the user (referrer link) – in if the Website was accessed via a link,
- information about the user’s browser,
- IP address information,
- diagnostic information related to the process of self-ordering services through recorders on the website,
- information related to the handling of e-mail addressed to the Operator and sent by the Operator.
4. Your rights and additional information on how the data is used
- In some situations, the Administrator has the right to transfer your personal data to other recipients, if it is necessary to perform the contract concluded with you or to fulfill your obligations incumbent on the Administrator. This applies to the following groups of recipients:
- authorized employees and associates who use data to achieve the purpose of the website
- companies providing marketing services to the Administrator
- Your personal data processed by the Administrator for no longer than it is necessary to perform related activities specified in separate regulations (e.g. on keeping accounts). With regard to marketing data, the data will not be processed for longer than 3 years.
- You have the right to request from the Administrator:
- access to your personal data,
- their rectification,
- restrictions on processing,
- and data transfer.
- You have the right to object to the processing indicated in point 3.3 c) to the processing of personal data in order to perform legally justified interests pursued by the Administrator, including profiling, however, the right to object will not be exercised if there are valid legitimate grounds for processing, overriding interests, rights and freedoms towards you, in particular the determination, investigation or defense of claims.
- You may lodge a complaint against the Administrator’s actions to the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warszawa.
- Providing personal data is voluntary, but necessary to operate the Website.
- You may be subject to automated decision-making, including profiling in order to provide services under the concluded contract and for the Administrator to conduct direct marketing.
- Personal data is not transferred from third countries within the meaning of the provisions on the protection of personal data. This means that we do not send them outside the European Union.
5. Information in forms
- The website collects information provided voluntarily by the user, including personal data, if provided.
- The website may save information about connection parameters (time stamp, IP address).
- In some cases, the website may save information facilitating the linking of data in the form with the e-mail address of the user completing the form. In this case, the user’s e-mail address appears inside the url of the page containing the form.
- The data provided in the form is processed for the purpose resulting from the function of a specific form, e.g. in order to process a service request or commercial contact service registration, etc. Each time, the context and description of the form clearly informs what it is for.
6. Administrator Logs
- Information about the behavior of users on the website may be subject to logging. These data are used to administer the website.
7. Significant marketing techniques
- The operator uses remarketing techniques , allowing to match advertising messages to the user’s behavior on the website, which may give the illusion that the user’s personal data is used to track him, but in practice no personal data is transferred from the Operator to advertising operators. The technological condition for such activities is the enabled cookie support.
- The operator uses a solution that examines the behavior of users by creating heat maps and recording behavior on the website. This information is anonymized before it is sent to the service operator so that he does not know which natural person it concerns. In particular, entered passwords and other personal data are not subject to recording.
- The operator uses a solution that automates the operation of the Website in relation to users, e.g. from the Operator.
8. Information about cookies
- Cookies are IT data, in particular text files, which are stored in the Website User’s end device and are intended for using the Website’s websites. Cookies usually contain the name of the website they come from, the time of their storage on the end device and a unique number.
- The entity placing cookies on the Website User’s end device and accessing them is the Website operator.
- Cookies are used for the following purposes:
- maintaining the Website user’s session (after logging in), thanks to which the user does not have to re-enter the login and password on each subpage of the Website;
- implementation of goals set out above in the “Important Marketing Techniques” section;
- The Website uses two basic types of cookies: “session” (session cookies) and “permanent” (persistent cookies). Session cookies are temporary files that are stored on the User’s end device until logging out, leaving the website or turning off the software (web browser). “Permanent” cookies are stored on the User’s end device for the time specified in the cookie file parameters or until they are deleted by the User.
- Software for browsing websites (web browser) usually allows cookies to be stored on the device by default. End User. Website users can change the settings in this regard. The web browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this subject can be found in the help or documentation of the web browser.
- Cookies placed on the Website User’s end device may also be used by entities cooperating with the Website operator, in particular the following companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA), Twitter (Twitter Inc. based in the USA).
9. Managing cookies – how to give and withdraw consent in practice?
- If the user does not want to receive cookies, he can change the browser settings. We reserve that disabling cookies necessary for authentication processes, security, maintaining user preferences may make it difficult, and in extreme cases may prevent the use of websites
- To manage cookie settings, select the web browser you use from the list below and follow the instructions: