1. Personal data administrator
This Privacy Policy sets out the rules for the collection, processing, and use of personal data obtained from you by the Mennica Skarbowa online store, operated under the domain http://www.mennicaskarbowa.pl/ (hereinafter referred to as the Website, Store) by the Personal Data Administrator (hereinafter referred to as "PDA") Mennica Skarbowa S.A. with its registered office in Warsaw, 00-013, ul. Jasna 1. Mennica Skarbowa makes every effort to ensure that your privacy is respected and that the personal information you provide is protected when using the Website and making purchases in the Store, and takes all necessary measures to this end.
Contact ADO: biuro@mennicaskarbowa.pl
2. Definitions
- Administrator – Mennica Skarbowa S.A. with its registered office in Warsaw [00-013], ul. Jasna 1, entered in the Register of Entrepreneurs of the National Court Register by the District Court for the Capital City of Warsaw in Warsaw, 12th Commercial Division of the National Court Register, under number: 0000391546, REGON: 142951136, NIP: 7010307347, share capital: PLN 208,020.00 [paid in full].
- Personal data – information about a natural person who is identified or identifiable by one or more specific factors determining physical, physiological, genetic, mental, economic, cultural, or social identity, including device IP, Internet identifier, and information collected through cookies and other similar technologies.
- Politics – this Privacy Policy.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
- Website - website mennicaskarbowa.pl
- Online Store or Website – the Mennica Skarbowa online store, operated by the Administrator as part of the http://www.mennicaskarbowa.pl/ website.
- User – any natural person visiting the Online Store website.
- Contact form - a form posted on the Online Store website for the User to contact the Administrator.
3. Processing of personal data
When processing your personal data, we take due care to ensure that it is processed in a lawful, fair, transparent, and secure manner.
Below are the most important principles we follow when processing personal data:
- we collect personal data for clearly defined purposes and do not process data in a manner inconsistent with those purposes;
- we collect personal data only to the minimum extent necessary to achieve the purposes for which it is collected, i.e. we do not collect it "in reserve";
- we process personal data solely on the basis specified in the provisions of law;
- we ensure that your personal data is up to date and accurate, and we respond immediately to requests to correct or update your data;
- we limit the storage of personal data to the period necessary to achieve the purposes for which it is collected, unless there are circumstances that may extend the storage period;
- we implement your right to access your personal data, correct it, as well as to delete personal data, withdraw consent, restrict processing, transfer data, object to data processing, not be subject to a decision based solely on automated data processing, including profiling;
- we protect your personal data from unauthorized access, as well as from accidental or unlawful loss, damage, or alteration of personal data;
- if personal data is made available to other entities, this is done in a secure manner, protected by an appropriate personal data processing agreement, in accordance with applicable law;
- we use technical and organizational measures to protect personal data against unlawful or unauthorized access or use, as well as against accidental destruction, loss, or breach of integrity;
- As part of ensuring the security of processed personal data, we undertake to take into account:
- confidentiality rules – we ensure that your personal data is not accidentally disclosed to unauthorized persons;
- integrity principles – we protect data against unauthorized modification;
- access rules – we ensure that authorized persons have access to data when necessary. Each of our employees who has access to your personal data has the appropriate authorization and is obliged to maintain the confidentiality of the personal data being processed.
The Online Store makes every effort to secure your data and protect it from third parties. We use all necessary security measures for our servers, connections, and Website to protect your data. Communication between your computer and our server when we collect personal data is encrypted using SSL (Secure Socket Layer) protocol. In addition, our databases are protected against access by third parties. Only authorized employees and persons involved in the operation of the Mennica Skarbowa store have direct access to your personal data.
All connections related to your electronic payments, if you choose this option, will be made via a secure encrypted connection.
However, the measures we take may prove insufficient if you do not follow the security rules yourself. In particular, you must keep your login and password for the Website confidential and not disclose them to third parties. Please note that the Online Store will not ask you to provide them, except when logging in to the Website. In order to prevent unauthorized persons from using your account, please log out after using the Website.
4. Basis and purpose of personal data processing
|
L.P. |
Purpose of processing/type of service |
Personal data |
Legal basis |
|
1 |
User account registration, identity verification |
First and last name |
Article 6(1)(b) of the GDPR – based on acceptance of the Terms and Conditions |
|
Email address |
|||
|
Home address |
|||
|
Phone number |
|||
|
Personal data will be processed for the period of remaining a registered user in the Store, and then for the time necessary to pursue claims or comply with legal regulations. |
|||
|
2 |
Online purchase – to fulfill orders, provide customer service, process payments, provide order status updates, and respond to inquiries. |
First and last name |
Article 6(1)(b) of the GDPR – based on acceptance of the Terms and Conditions |
|
Email address |
|||
|
Personal Identification Number |
|||
|
Home/shipping address |
|||
|
Tax Identification Number |
|||
|
Phone number |
|||
|
Bank account number |
|||
|
Personal data will be processed for a period of 5 years from the end of the calendar year in which the User made their last purchase. |
|||
|
3 |
Determination, investigation, or defense against claims |
First and last name |
Article 6(1)(f) of the GDPR |
|
Email address |
|||
|
Address of residence/registered office |
|||
|
PESEL/KRS number |
|||
|
Tax Identification Number |
|||
|
Personal data will be processed until the time of defense or the expiration of the statute of limitations for claims. |
|||
|
4 |
Compliance with legal obligations, in particular those related to anti-money laundering and counter-terrorist financing |
First and last name |
Article 6(1)(c) of the GDPR |
|
Email address |
|||
|
Personal Identification Number |
|||
|
ID card number, Passport number |
|||
|
Home/shipping address |
|||
|
Tax Identification Number |
|||
|
KRS number |
|||
|
Phone number |
|||
|
Bank account number |
|||
|
Payment ID number |
|||
|
Personal data will be processed for 5 years from the first day of the year following the year in which transactions or business relations with the User ceased. |
|||
|
5 |
Analysis of activity in the Store |
Date and time of visit |
Article 6(1)(f) of the GDPR |
|
Amount of data sent in bytes |
|||
|
Source/link through which the user arrived at the website |
|||
|
Web browser used |
|||
|
Operating system used |
|||
|
Device IP address |
|||
|
Personal data will be processed until an effective objection is lodged or the purpose of processing is achieved. |
|||
|
6 |
Sending marketing content |
Email address |
Article 6(1)(b) or (f) of the GDPR |
|
Phone number |
|||
|
Personal data will be processed until an effective objection is lodged, the purpose of processing is achieved, or claims related to the Newsletter delivery agreement become time-barred. |
|||
|
7 |
Communication via the contact form with the user in order to establish contact with the User and respond to the question asked. |
Email address |
Article 6(1)(b) of the GDPR if it is necessary for the performance of a contract for the provision of services |
|
Article 6(1)(f) of the GDPR |
|||
|
Personal data will be processed until an effective objection is lodged or the purpose of processing is achieved. |
|||
|
8 |
Communication via online chat |
Information provided by the User |
Article 6(1)(f) of the GDPR |
|
Web browser used |
|||
|
Personal data will be processed until an effective objection is lodged or the purpose of processing is achieved. |
|||
|
9 |
Recording calls with Users |
Information provided by the User |
Article 6(1)(a) of the GDPR |
|
The data will be processed for the purpose of improving security and customer service quality for no longer than 1 year from the date of recording. If the data constitutes evidence in proceedings conducted under the law or may constitute evidence in proceedings, this period shall be extended until the proceedings are legally concluded. |
|||
|
10 |
Managing profiles on Facebook, Twitter, and Instagram |
User profile name |
Article 6(1)(f) of the GDPR |
|
User data marked as "public" |
|||
|
Personal data will be processed until an effective objection is lodged or the purpose of processing is achieved. |
|||
|
11 |
Adding reviews about products and services |
First and last name |
Article 6(1)(a) of the GDPR |
|
Email address |
|||
|
IP number |
|||
|
Personal data will be processed until consent is withdrawn (review is deleted). |
|||
|
12 |
Recruitment |
First and last name |
Article 6(1)(c) of the GDPR when data processing is carried out on the basis of Article 22(1)(1) of the Labor Code |
|
Date of birth |
Article 6(1)(a) of the GDPR – processing based on consent |
||
|
Contact details (phone number, email address) |
|||
|
Education |
|||
|
Professional qualifications |
|||
|
Employment history |
|||
|
Personal data will be processed until the recruitment process is completed or the candidate withdraws their application, unless the candidate consents to the processing of their personal data for future recruitment purposes or until the consent is withdrawn (in the case of data provided on the basis of consent). |
|||
|
13 |
Video surveillance |
Image |
Article 6(1)(a) of the GDPR |
|
Personal data will be processed for 3 months from the date of the last image recording. If it constitutes evidence in proceedings conducted on the basis of law or may constitute evidence in proceedings, this period shall be extended until the proceedings are legally concluded. The data processed relates only to vision. |
|||
When processing your personal data, we take due care to ensure that it is processed in a lawful, fair, transparent, and secure manner. Providing personal data is voluntary, but failure to do so may prevent or hinder the proper performance of a service, completion of a sale, or provision of after-sales service.
You have the right to access your personal data and correct it, as well as the right to request its removal. To exercise this right, please use the options available in your account or contact us at: biuro@mennicaskarbowa.pl.
Some data is collected when you provide it to us. This may include, for example, data provided to us in email correspondence or in a contract concluded with us.
Other data is collected automatically by our IT systems when you visit our Website, e.g., cookies.
When you visit our Website, your browser sends data to our server. This data enables us to optimize our services and provides you with more options for using our Website and applications. The data is automatically collected and stored by us or by third parties on our behalf.
We may collect information about your computer for system administration purposes and use aggregated data for internal marketing analysis. This is statistical data about our users' browsing activities and patterns.
Providing data when using the newsletter is required in order to accept and process your inquiry, and failure to provide such data will result in the inability to process your inquiry.
We process personal data for the purpose of identifying the user and handling inquiries submitted via the form provided.
During the recruitment process, the Company expects you to provide only the personal data required by the Labor Code. Any additional data you provide will be processed on the basis of the candidate's consent pursuant to Article 6(1)(a) of the GDPR.
5. How can you exercise your rights?
You can view and edit your data at any time on the Website after logging in with your username and password. If you forget your password or encounter other problems with logging in, please contact us at: biuro@mennicaskarbowa.pl.
You have the following rights regarding your personal data:
- access to data,
- correction of data,
- supplements,
- deletion of data ("right to be forgotten"),
- restrictions on data processing,
- object to processing and to data portability,
This applies to processing carried out on the basis of our legitimate interest and automated processing involving decision-making in individual cases, including profiling and processing for direct marketing purposes, as well as in connection with the pursuit of statistical and analytical objectives due to your unique situation.
- data transfer,
Exercising this right does not exempt us from the obligation to exercise other rights to which you are entitled. If you store the data provided in your own IT system or other system, you are responsible for finding appropriate measures to secure this data. This applies to data concerning you that you have provided to us and that we process in an automated manner on the basis of your consent or a contract.
- lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office, regarding the processing of Users' and Customers' personal data by the Website, both in Poland (to the President of the Personal Data Protection Office) and in the EU Member State of their habitual residence, place of work, or alleged infringement
- object to the processing of data for marketing purposes, if the processing of data is based on the legitimate interest of the Administrator, as well as in connection with the implementation of statistical and analytical purposes due to your unique situation;
- not to be subject to automated decision-making in individual cases, including profiling,
You may object to such processing at any time.
- withdrawal of consent
Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
Requests may be submitted:
- by traditional mail to the following address: Mennica Skarbowa S.A. with its registered office in Warsaw, ul. Jasna 1, 00-013 Warsaw;
- by email to the following address: biuro@mennicaskarbowa.pl,
- in person at our headquarters, i.e. at ul. Jasna 1, 00-013 Warsaw;
We consider requests from data subjects with due care, taking into account the provisions of the law and the rights and freedoms of other persons whose data may be concerned.
When submitting your request, you should provide information that allows you to be clearly identified.
We do not refuse to take action at the request of a data subject who wishes to exercise their rights, unless we are unable to clearly identify the data subject.
We will provide information about the actions taken in response to the request without undue delay, and in any case within one month of receiving the request. If necessary, we may extend this period by a further two months due to the complexity of the request or the number of requests. Within one month of receiving the request, we will inform you of such an extension, stating the reasons for the delay.
If we receive your request electronically, we will also provide feedback electronically wherever possible, unless you request a different form.
If we do not take action in response to your request, we will inform you immediately—within one month of receiving the request at the latest—of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking legal protection before a court.
If we cannot clearly identify you or have reasonable doubts about your identity, we may request additional information necessary to confirm your identity. If, within 30 days of receiving a request for additional information, you fail to provide it and your unambiguous identification is impossible, your request will be denied. You will be informed of the deadline for providing additional data and the consequences of not providing it.
We will inform each recipient to whom we have disclosed your personal data about any rectification, supplementation, erasure, or restriction of processing of your personal data, unless this proves impossible or involves a disproportionate effort.
6. Who has access to your personal data?
Access to Customer data is granted to: Store employees responsible for operating and servicing the Store, as well as entities cooperating with the Store, including those providing IT systems, IT support, and shipping services, such as:
- Courier companies, postal service deliveries;
- IAI S.A.;
- Comarch S.A.;
- PayU S.A., for the purposes of processing online payments;
- Meta Platforms, Inc.;
- Internet domain providers
- Newsletter service providers
- Companies providing tools for analyzing activity on the Website and directing direct marketing to its users (including Google Analytics).
- IT services company
Personal data may be transferred to other private or public entities when required by generally applicable laws or a final decision.
7. Transfer of personal data to a third country
We use tools such as Google Analytics and Facebook Pixel, which means that your personal data may be transferred to the following third countries: the United Kingdom, Canada, the United States, Chile, Brazil, Israel, Saudi Arabia, Qatar, India, China, South Korea, Japan, Singapore, Taiwan (Republic of China), Indonesia, and Australia. According to decisions of the European Commission, the United Kingdom, Canada, Israel, and Japan ensure an adequate level of personal data protection. With regard to the United States, Chile, Brazil, Saudi Arabia, Qatar, India, China, South Korea, Singapore, Taiwan (Republic of China), Indonesia, and Australia, contractual clauses ensuring an adequate level of protection, in accordance with the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries under Regulation (EU) 2016/679 of the European Parliament and of the Council.
8. Other websites
Links to other websites may appear periodically on the Website. Such websites operate independently of the Website and are not supervised by the Online Store in any way. These websites may have their own privacy policies, which we recommend you read. The Online Store is not responsible for the data handling policies of these websites.
Our website or fan pages may use third-party social media plugins, e.g., Facebook (plugins or so-called "buttons," e.g., "Like," "Share"), marked with the well-known icons of these networks. For this purpose, a code referring to the above networks is placed on the relevant pages. The content of our Website may be sent to this page or service. Depending on your privacy settings, it may be visible publicly or privately (e.g., only to friends, followers, or anyone who visits your profile). As a logged-in user of these services, you can use these plugins to share the page you are currently on within these services. However, the plugin will only be loaded if you install the corresponding plugin using the activation icon. The content of the plugin will then be transmitted by the respective social network directly to your end device and displayed there. If you select the appropriate option, this activation will remain in effect for the duration of your visit to our website. You can deactivate the buttons at any time by clicking on "Cancel." Without the appropriate activation, the plugins will remain inactive and no connection to the social networks will be established. If you have activated the use of the plugin, we process the following data and transmit it to the plugin provider: (date and time of access, part of our website visited, IP address, domain name).
Our Website also contains external links, e.g. to our Facebook page. When you use these links, you leave our website. It may also be possible to communicate with us via the Messenger chat window (after logging into Facebook), which is located directly on our pages and uses cookies.
We have no control over what data the plug-in provider or social media sites collect and how they process it. For information on the purpose and scope of data collection, including cookies used there, their further processing and use by third-party providers, and your rights and privacy settings options for these providers, please refer to the data protection information of the respective provider.
9. Trusted Shops
Our website features an integrated Trusted Shops Trustbadge, which is used to display our Trusted Shops quality mark and the reviews collected about purchases in our store, as well as to present the Trusted Shops product range available to buyers after placing an order in our store.
The above serves to protect our overriding legitimate interest in the optimal functioning of our market offering. Trustbadge and the services advertised with it are an offering of Trusted Shops GmbH, Subbelrather Str. 15C, 50823 Cologne.
When the Trustbadge is called up, the server automatically stores so-called server logs, which contain, for example, your IP address, the date and time of the call, the amount of data transferred, and the requesting service provider (access data), and documents the call. The above access data is not analyzed and is automatically overwritten within seven days of closing the page.
Other personal data is only transferred to Trusted Shops if, after completing your order, you voluntarily decide to use Trusted Shops products or have already registered to use them. In such cases, the agreement you have concluded with Trusted Shops applies.
10. Cookies
The Online Store does not automatically collect any data, except for data contained in cookies during the use of the Website. Cookies are small text files sent by the Online Store and stored on your end device (e.g., computer, laptop, tablet, or smartphone) containing certain information related to your use of the Website and the Online Store. They can also be read by other systems belonging to entities whose services are used by the Administrator (Google, Meta).
We distinguish between the following types of cookies
- Essential: they provide the Website's functionality and services to Users who wish to use them.
Legal basis for data processing: Article 6(1)(b) of the GDPR. They remain on your end device for a period of 1 year.
- Functional: they remember and adapt the Website to the User's settings.
Legal basis for data processing: Article 6(1)(b) of the GDPR. They remain on your end device for a period of 1 year.
- Analytical: enable the collection of information about the number of visits and the source of traffic on the Website. They allow us to determine which pages and subpages are visited more frequently by the User, the search engine used, and the location, which allows us to compile statistics on traffic on the Website. Their purpose is not to determine your identity. They remain on your end device for a period of 2 years.
- Marketing: they enable the content displayed to be tailored to the interests of Users and to target advertisements tailored to their preferences. They remain on your end device for a period of 3 months.
Cookies used by the Online Store may be temporary or permanent. Temporary cookies are deleted when you close your browser, while permanent cookies are stored even after you have finished using the Website and are used to store information such as your password or login, which speeds up and facilitates the use of the Website. Some permanent cookies allow us or our partners to recognize your browser on subsequent visits. In any case, you can block the installation of cookies or delete permanent cookies using the appropriate options in your web browser. If you encounter any problems, we recommend that you consult your browser's help file or contact the manufacturer of the browser you are using. You can make changes to your web browser settings by following these links:
- Internet Explorer: https://support.microsoft.com/pl-pl/help/278835/how-to-delete-cookie-files-in-internet-explorer
- Microsoft Edge: https://support.microsoft.com/pl-pl/help/10607/microsoft-edge-view-delete-browser-history
- Firefox: https://support.mozilla.org/pl/kb/usuwanie-ciasteczek
- Google Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=pl
- Safari: https://support.apple.com/pl-pl/guide/safari/sfri11471/mac
- Opera: https://help.opera.com/pl/latest/web-preferences/#cookies
Information on how to configure cookie settings on mobile devices can be found on the websites of the manufacturers of the most popular mobile systems (iOS, Android, Windows Phone, and BlackBerry devices).
The data collected by cookies does not enable your identification. We use cookies placed on your devices by external companies: Google LLC, Google Ads, IAI S.A., Meta Platforms, Inc., Facebook Pixel in order to compile statistics and tailor our offer to the User's expectations.
Certain information stored in cookies (e.g., preferences), especially when combined with other information about the website user, may be considered personal data. Personal data collected using cookies may only be processed for the purpose of performing specific functions for the user, as described above. Such data is encrypted in a way that prevents unauthorized persons from accessing it.
As a result of changing the settings in your browser, a so-called opt-out cookie will be placed on your device. It is used solely to identify your objection – lack of consent. Please note that the opt-out cookie only works in the browser in which it was saved. If you delete all cookies or use a different browser or device, you will need to set up the opt-out again.
Due to the possibility of sharing data collected using cookies with our external providers, we would like to inform you that some data may be transferred outside the European Economic Area. Due to the fact that Google LLC is based in the US and uses technical infrastructure located in the US, the adequate level of personal data protection required by European regulations is ensured on the basis of standard data protection clauses adopted by the European Commission, referred to in Article 46(2)(c) of the GDPR. Please be advised that restrictions on the use of cookies may affect some of the functionalities available on the website.
