Privacy policy
Who is the Administrator of my personal data?
The Administrator of your personal data is:
ALBA THYMENT limited liability company, ul. Szkolna 98, 62-002 Suchy Las, Tax Identification Number (NIP): 7820026054, National Business Registry Number (REGON): 63251406600000, National Court Register (KRS): 0000152323
The Administrator is responsible for the safe and legal use of personal data in accordance with applicable law.
Who can I contact regarding the processing of my personal data?
For all matters related to the processing of your personal data by the Administrator, you can contact:
The Administrator has not appointed a Data Protection Officer or a representative.
What is the source of my data - where is it obtained from?
We obtain personal data directly from you when you contact us regarding the purchase of products offered by ALBA THYMENT sp. z o.o. Your data is acquired for various purposes, and we process it in different scopes and on different legal bases provided for in the GDPR. The Processing Time of Personal Data varies. To provide you with the most transparent information, we have grouped this information by referring to the purpose of processing your personal data, and we present it below.
What is the scope of personal data processed by the Administrator and the purpose of processing?
- Customer account registration via the website
Description.
- Personal data is processed to enable customers to register via the website.
Data scope.
- Name, Surname, phone number, optionally other data that the customer decides to provide,
Legal basis.
- Legal basis: Art. 6(1)(b) of the GDPR, i.e., the necessity of providing personal data for the registration of a customer account via the websites https://www.albathyment.com.pl/, https://www.alba1913.pl, http://www.alba1913.com, https://www.balsamique.pl/, and https://apothia.pl/
Processing time of personal data.
- Personal data is processed for the period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Goods purchase via the website
Description.
- Personal data is processed to enable customers to purchase goods via the website.
Data scope.
- To enable the purchase of goods via the website, the following personal data of the customer is processed: Name, Surname, email address, phone number,
Legal basis.
- Processing of personal data is necessary for the performance of actions at the request of the data subject before entering into a contract (Art. 6(1)(b) of the GDPR)
Processing time of personal data.
- Personal data is processed for the period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Payment for an order
Description.
- Personal data is processed to enable customers to pay for an order.
Data scope.
- When making a payment for an order, the following personal data is processed: Name, Surname, bank account number, address,
Legal basis.
- Processing of personal data is necessary for the performance of actions at the request of the data subject before entering into a contract (Art. 6(1)(b) of the GDPR)
Processing time of personal data.
- Data is processed for the period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Purchase of goods in a stationary store
Description.
- Personal data is processed when purchasing in a stationary store when the customer provides their personal data to the Seller.
Data scope.
- In the case of purchasing products offered by Alba Thyment sp. z o.o. in a stationary store, the following personal data is processed: Name, Surname, email address, phone number,
Legal basis.
- Processing of personal data is necessary for the performance of actions at the request of the data subject before entering into a contract (Art. 6(1)(b) of the GDPR)
Processing time of personal data.
- Data is processed for the period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Remote purchase of goods or services, inquiry for an offer
Description.
- Personal data is processed to enable customers to remotely purchase goods and to respond to an inquiry for an offer.
Data scope.
- In connection with remote purchase of goods or services and submitting inquiries for offers, the following personal data is processed: name, surname, email address, phone number,
Legal basis.
- Processing of personal data is necessary for the performance of actions at the request of the data subject before entering into a contract and for the performance of a contract or provision of services (Art. 6(1)(b) of the GDPR)
Processing time of personal data.
- Data is processed for the period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Product return
Description.
- Personal data is processed to enable customers to return a product.
Data scope.
- To enable customers to return a product, the following personal data is processed: name and surname, email, phone number,
Legal basis.
- Processing of personal data is necessary for the performance of actions at the request of the data subject for the performance of a contract or provision of services (Art. 6(1)(b) of the GDPR)
Processing time of personal data.
- Data is processed for the period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Telephone contact with customers
Description.
- Personal data is processed to enable customers to contact the Administrator by phone.
Data scope.
- For this purpose, the following personal data is processed: name, surname, phone number.
Legal basis.
- Processing of personal data is necessary for the performance of actions at the request of the data subject for the performance of a contract or provision of services (Art. 6(1)(b) of the GDPR)
Processing time of personal data.
- Data is processed for the period resulting from the primary purpose for which it was collected, but not longer than 5 years
- Email contact with customers
Description.
- Personal data is processed to enable customers to contact the Administrator by email.
Data scope.
- For this purpose, the following personal data is processed: name, surname, email address.
Legal basis.
- Processing of personal data is necessary for the performance of actions at the request of the data subject for the performance of a contract or provision of services (Art. 6(1)(b) of the GDPR)
Processing time of personal data.
- The data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Contact with Customers via Facebook FANPAGE
Description.
- Personal data is processed to enable customers to contact Alba Thyment via Facebook FANPAGE.
Data scope.
- For this purpose, the following personal data is processed: name, surname, email address, phone number, image.
Legal basis.
- Processing of personal data is necessary to take actions at the request of the person to whom the data relates, for the performance of a contract, or for the provision of services (Art. 6(1)(b) GDPR).
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Contact with Customers via Messenger
Description.
- Personal data is processed to enable customers to contact via Messenger.
Data scope.
- For this purpose, the following personal data is processed: name, surname, email address, phone number.
Legal basis.
- Processing of personal data is necessary to take actions at the request of the person to whom the data relates, before entering into a contract (Art. 6(1)(b) GDPR).
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Contact with Customers via WhatsApp
Description.
- Personal data is processed to enable customers to contact via WhatsApp.
Data scope.
- For this purpose, the following personal data is processed: name, surname, email address, phone number.
Legal basis.
- Processing of personal data is necessary to take actions at the request of the person to whom the data relates, before entering into a contract (Art. 6(1)(b) GDPR).
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Contact with Contractors via Slack application
Description.
- Personal data is processed to enable contractors to contact via the Slack application.
Data scope.
- To enable contractors to contact via the Slack application, the following personal data is processed: name, surname, address, email address, phone number, image.
Legal basis.
- Processing of personal data is necessary to take actions at the request of the person to whom the data relates, before entering into a contract (Art. 6(1)(b) GDPR).
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Shipment of ordered goods
Description.
- Personal data is processed for the purpose of delivering ordered goods to the customer.
Data scope.
- To provide the service of shipping ordered goods, the administrator processes the following personal data: name, surname, address, phone number.
Legal basis.
- Processing of personal data is necessary for the performance of a sales contract or service provision (Art. 6(1)(b) GDPR).
Processing time of personal data.
- Personal data is processed for the time needed to manage the purchase of acquired products or services, including any returns, complaints, or claims related to a specific product or service. Data is processed at the latest until the expiration of claims under the concluded sales contract or service provision.
- Complaint of a product purchased through the online store
Description.
- Personal data is processed to enable customers to make complaints about purchased products.
Data scope.
- To enable customers to make complaints about products, the following personal data is processed: name, surname, residential address, email address, phone number.
Legal basis.
- Processing of personal data is necessary to fulfill a legal obligation incumbent on the Administrator (legal basis: Art. 6(1)(c) GDPR).
Processing time of personal data.
- The data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Exercising rights under warranty
Description.
- Personal data is processed to enable customers to exercise warranty rights.
Data scope.
- To enable customers to exercise warranty rights, the following personal data is processed: name, surname, residential address, email address, phone number.
Legal basis.
- Processing of personal data is necessary to fulfill a legal obligation incumbent on the Administrator.
Processing time of personal data.
- The data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- IT support
Description.
- Personal data is processed to enable the provision of IT services tailored to the needs of the customer.
Data scope.
- In connection with IT support, the Personal Data Administrator processes personal data such as: name, surname, email address, phone number.
Legal basis.
- The legal basis for processing personal data is the legitimate interest of the Administrator in ensuring proper IT support (Art. 6(1)(f) GDPR).
Processing time of personal data.
- Personal data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Statistics of using specific functionalities of the Online Store and facilitating the use of the website containing the online store, ensuring the IT security of the service
Description.
- The data is processed for the purpose of:
- - ensuring better service for customers and contractors using the Administrator's services,
- - analyzing statistical data and adjusting websites to the preferences of visitors,
- - administration of websites, including the online store.
Data scope.
- The Administrator processes the following personal data regarding the Customer's activity on the Administrator's websites, including the online store: visited pages and subpages, time spent on each of them, as well as data related to search history, IP address, location, device ID, browser, and operating system data.
Legal basis.
- Processing of personal data is necessary for the performance of a contract or the provision of services (legal basis: Article 6(1)(b) GDPR).
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Accounting, bookkeeping
Description.
- Personal data is processed for the purpose of:
- - accounting (income or expenditure book, any accounting books),
- - VAT records,
- - preparation of monthly and annual tax returns,
- - preparation of reports for the tax and statistical office,
- - preparation of financial statements.
Data scope.
- For this purpose, the Administrator processes: name, surname, address, name of the business conducted, Tax Identification Number (NIP), address of the business, and bank account number.
Legal basis.
- The legal basis for processing personal data is the necessity to fulfill legal obligations incumbent on the Administrator (legal basis: Article 6(1)(c) GDPR).
Processing time of personal data.
- Personal data is processed by the Administrator for the period of storing accounting, tax, and personnel-payroll documentation. Personalized receipts and VAT invoices are kept until the expiry of tax obligations, i.e., for 5 years from the end of the calendar year in which the tax payment deadline expired.
- Establishment, investigation, and enforcement of claims
Description.
- Establishing claims related to business activities, conducting accounting, fulfilling tax obligations, enforcing payment for services provided.
Data scope.
- In connection with the establishment, investigation, and enforcement of claims, the following personal data is processed: name, surname, residential address, phone number.
Legal basis.
- Legitimate interest - assertion of claims and defense of rights (Article 6(1)(c) GDPR in conjunction with Article 74(2) of the Accounting Act as a legitimate interest of the data controller).
Processing time of personal data.
- Data is processed for the limitation period for claims according to the Civil Code. All data processed for accounting and tax purposes is processed for 5 years, counted from the end of the calendar year in which the tax obligation arose. After the expiration of these periods, the data is deleted or anonymized.
- Contact with the Customer - handling complaints, requests, inquiries
Description.
- Personal data is processed to handle complaints, requests, inquiries.
Data scope.
- For this purpose, the Administrator processes: name, surname, address, email, phone.
Legal basis.
- The legal basis for processing personal data is Article 6(1)(f) GDPR, justified legal interest of the Administrator in improving and raising the quality of provided products and services.
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
- Analysis of adverse effects of cosmetics and pharmaceutical products
Description.
- Personal data is processed for the purpose of analyzing and then eliminating adverse effects.
Data scope.
- The Personal Data Administrator processes personal data such as: name, surname, address, phone email, and optionally sensitive health data.
Legal basis.
- The legal basis for processing personal data is Article 6(1)(f), justified legal interest of the Administrator in eliminating adverse effects of applied products.
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 5 years.
Processing time of personal data.
- Personal data is processed for the time a natural person uses the websites provided by the Administrator through Facebook.
- Use of services from third parties or purchase of goods from third parties for the purposes of running the current business by ALBA THYMENT sp. z o.o.
Description.
- In connection with the conducted business activity, we use the supply of goods and services from third parties.
Data scope.
- For this purpose, we process personal data:
- Representative of the Contractor – name, surname, position/title, business email address, business phone number, name of the company represented by the Representative,
- Contractor (individual conducting business activity) – name, surname, name of the business conducted, NIP, address of the business, bank account number.
Legal basis.
- Personal data is processed based on Article 6(1)(b) GDPR, i.e., in connection with negotiations, conclusion, and performance of a service provision contract concluded between ALBA THYMENT sp. z o.o. and the Contractor. Additionally, the legal basis for processing personal data is Article 6(1)(f) GDPR, i.e., the legitimate interest of the Personal Data Administrator, arising from the necessity of processing personal data for the implementation of the Administrator's business activities (assertion and defense against claims, fraud prevention, ensuring the security of the teleinformation environment).
Processing time of personal data.
- Personal data is processed for the duration of conducting business cooperation, up to a maximum of 3 years from the last contact between the Administrator and the Contractor's Representative (or longer only until the expiration of claims arising from the contract between the parties). Personal data resulting from invoices is processed for the period of storing VAT invoices, required by law, i.e., for 5 years, counting from the end of the calendar year in which the VAT payment deadline for the VAT invoice expired.
- Complaints about purchased goods by the Contractor
Description.
- Personal data of Contractor's Representatives is processed to enable the submission of complaints about purchased goods.
Data scope.
- The Administrator of personal data processes the personal data of contractors such as: name and surname, job position (and information about the company in which the person is employed), business correspondence address, business email address, and business phone number.
Legal basis.
- The legal basis is the legal basis: Article 6(1)(f) GDPR and Article 6(1)(b) GDPR.
Processing time of personal data.
- Personal data of Contractor's Representatives will be stored for the duration of conducting business cooperation and after its termination, as long as there are reasonable grounds to believe that this cooperation will be resumed, or until the limitation of claims.
- Monitoring the company's premises only from the outside. Processing the image of employees, buyers, including individuals, personally picking up purchased goods, and contractors
Description.
- Personal data is processed to ensure the safety of individuals and property on the premises of the Data Administrator.
Data scope.
- The Administrator of personal data processes the image.
Legal basis.
- The legal basis is the legal basis: Article 6(1)(f) GDPR.
Processing time of personal data.
- Data is processed for a period resulting from the primary purpose for which it was collected, but not longer than 6 months.
Who are my personal data shared with?
Personal Data Administrator takes utmost care to ensure the confidentiality of your personal data. Due to the necessity of fulfilling contractual obligations and ensuring the proper provision of services to our customers, personal data is disclosed to the individuals specified below.
Service Providers
We also disclose your personal data to service providers we use in the course of our business operations. These providers equip the Administrator with technical and organizational solutions, enabling the provision of services to customers and organizational management. We disclose data to entities providing IT services to the Administrator and handling IT systems, such as software suppliers, including server providers where personal data is stored.
Government Authorities
We disclose your personal data if authorized government authorities, especially organizational units of the prosecutor's office, the Police, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications, request it.
The Administrator transfers personal data outside the European Union and the European Economic Area.
Is Providing Data Mandatory?
Providing some data is a condition for using specific services offered by the Administrator (mandatory data). Our system automatically designates mandatory data. The consequence of not providing this data is the inability to provide certain services on your behalf. Apart from data marked as mandatory, providing other personal data is voluntary. Your personal data will not be processed for automated decision-making.
What Are My Rights?
In connection with the processing of your personal data, the Administrator ensures the realization of your rights related to the processing of personal data, as described below. You can exercise your rights by submitting a request to:
With regard to the processing of your personal data, you have the right to:
How Quickly Do We Fulfill Your Request?
If, in the exercise of the above rights, you make a request to us, we fulfill that request or refuse to fulfill it immediately, but no later than one month after receiving it. However, if, due to the complex nature of the request or the number of requests, we are unable to fulfill your request within a month, we will fulfill it within the next two months, informing you in advance of the intended extension of the deadline.
Right to Lodge a Complaint
If the processing of personal data violates legal regulations, you can lodge a complaint with the supervisory authority for the processing of personal data by the Personal Data Administrator. A complaint can be submitted to the President of the Office for Personal Data Protection.
COOKIE POLICY
By using the website available at https://www.albathyment.com.pl/, https://www.alba1913.pl, https://www.balsamique.pl, and https://apothia.pl consent is given to the installation of cookies on the end device of the person using the Site and the use of cookies by ALBA THYMENT limited liability company based in Suchy Las, in accordance with this Policy. Consent is expressed through the settings of the web browser. If the User does not agree to the use of cookies, they should change their browser settings accordingly or refrain from using the Site (more information below).
- What is a Cookie?
"Cookies" are individual, small text files sent by visited websites and downloaded to the user's computer. The information contained in these files allows only the website that created them to read the information. Thus, the website cannot access other files on the user's computer.
- For What Purpose do Websites https://www.albathyment.com.pl/, https://www.alba1913.pl, https://www.balsamique.pl, and https://apothia.pl Use Cookies?
Cookies used on the websites https://www.albathyment.com.pl/, https://www.alba1913.pl, https://www.balsamique.pl, and https://apothia.pl allow measuring user activity on the site. We use cookies to customize and improve the operation of the website. Cookies will also allow examining user preferences and thus continuously improving the quality of services provided by us. We do not use cookies to contact users by phone, email, or traditional mail. We do not use behavioral cookies on our sites.
- What Types of Cookies Do We Use?
Two types of cookies may be used on the sites https://www.albathyment.com.pl/, https://www.alba1913.pl, https://www.balsamique.pl, and https://apothia.pl.
We may use both analytical and advertising cookies on our site.
Analytical cookies collect information about how you use our site, including IP address, device type, operating system, URLs, country information, date and time of site visits, and which pages you visit most frequently. This helps us create reports and statistics about site performance and present you with content more relevant to your interests. By analyzing this information, we can understand the size of our audience, general usage patterns, identify and resolve issues you may encounter on the site, and assess the effectiveness of our advertising.
Advertising cookies are used to display ads that we consider relevant and related to your interests. For example, we use Google advertising cookies to customize ads and content you see on our site, conduct behavioral advertising, limit the number of times the same ad is displayed on our site, measure the effectiveness of our advertising campaigns, and conduct market research. We may also share information about your use of our site with our advertising and analytics partners, who may combine it with other information you have provided to them or that they have collected while using their services. By using advertising cookies, we can customize ads you see to your interests and show you ads that are more interesting to you.
Please note that if you need more information about cookies and the technologies we use on our website, additional details can be found on our partner's website - Google. We encourage you to review their privacy policy and terms of service for a more comprehensive understanding of the data they collect and how it is used.
https://policies.google.com/technologies/partner-sites
- Can I Decline to Accept Cookies?
Actions related to storing and sending cookies are handled by web browsers and are invisible to users. Most commonly used browsers accept them by default. However, users can set their browser to reject requests to store cookies altogether or select ones. This can be done through browser settings. Before making such a decision, it is worth remembering that many cookies help in using the website.
- How to Disable Cookie Support?
Detailed information on managing cookies is available in the settings and documentation of the selected web browser.