Privacy & Cookie Policy
1. General Provisions
1.1. The purpose of the following Privacy Policy is to inform you about the way we use your personal data, in respect of which we meet all the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC of 27 April 2016 (hereinafter referred to as "GDPR").
1.2. The terms written in the Policy with a capital letter, unless otherwise stated in the content of the Policy, have the meaning specified in the Store Terms and conditions.
1.3. The term:
a) "User" means, depending on the context, the Customer or a person wishing to become a Customer or an Internet user visiting the Store's pages.
b) “Store” or “Online Store” means the website operated by the Seller, available at the following electronic address (website): petsona.eu
1.4. By clicking on the links on the website of the store, the User may be redirected to websites or services that are administered or constitute a service provided by entities independent of Kontri sp. z o.o. In such a case, the personal data processing process is carried out in accordance with the principles specified by these entities - e.g. in the privacy policy appropriate for services or applications available on external websites or services. In such a case, the User should familiarize themselves with the privacy policy of these entities (e.g. Facebook, Instagram, etc.).
2. Data controller
Data controller is Kontri sp. z o.o. with its registered office in Białystok, Jacka Kuronia 3, 15-569 Białystok, registered in the register of companies of the National Court Register under KRS number 0000258273, whose registration files are maintained by the District Court in Białystok, 12th Commercial Division of the National Court Register, share capital: PLN 350,000, NIP 9661848306, REGON 200084060, e-mail: contact@petsona.eu, Phone: (+ 48 85 740 40 76) hereinafter referred to as "Kontri sp. z o.o."
3. Scope of processed personal data
3.1. In order to use the services offered by Kontri sp. z o.o. via the Store (e.g. Customer Account, newsletter subscription), the User must complete the appropriate form and provide the required personal data.
3.2. Providing personal data is voluntary, but necessary to complete the order or provide services to the User via the Store.
3.3. The basis for verification of a registered Customer in the Kontri sp. z o.o. store is the e-mail address provided during registration and the Customer's individual password. Kontri sp. z o.o. recommends proper protection of the password against access by unauthorized persons. During the registration process, the customer selects a password that cannot be shorter than 10 characters and not longer than 30 characters; the password must contain letters and numbers or special characters.
3.4. Kontri sp. z o.o. hereby informs that it never requests the provision of an e-mail address and password in the content of the e-mail or in any other place than the registration / login form on the website.
3.5. It is forbidden to provide personal data of an unlawful nature.
3.6 Kontri sp. z o.o. also processes data collected during the User's/Service Recipient's activity on the online store website, including visited pages and locations, time of visit, clicks, method of using services (e.g. shopping history, product search). Processing by Kontri sp. z o.o. of the above-described data saved in cookies on the User's device and its cache (including data shared in the browsing history and data collected during activity in services) and location data generated by the device is necessary due to the nature of the services provided by Kontri sp. z o.o. electronically, including sharing content within our websites. Kontri sp. z o.o. informs that it does not sell or transfer the collected data to third parties for purposes other than the legitimate interest of Kontri sp. z o.o.
4. Purposes and legal basis of data processing
Personal data are processed for the following purposes:
-
marketing, including contact via e-mail to send, among others, promotional offers and discounts, reminders about an unfinished order and providing the Service User with personalized offers on third-party websites - based on consent (Article 6 paragraph 1 letter a of the GDPR)
-
assessing and improving the effectiveness of our marketing campaigns, monitoring the performance of our website and constantly looking for opportunities to improve the petsona.eu website - based on consent (Article 6 paragraph 1 letter a of the GDPR)
-
registering an account in the store and User logging, taking actions at the User's request before concluding a contract (e.g. answering questions about products), implementing the concluded purchase-sale contract, handling payments, delivering the order, informing about the status of the order (in the form of an SMS and/or e-mail), handling the complaint process - in connection with the conclusion and performance of the contract (Article 6 paragraph 1 letter b of the GDPR),
-
related to: counteracting money laundering and terrorism financing based on the AML Act, with accounting and taxes, for archival purposes - in connection with fulfilling the legal obligations incumbent on the Administrator (Article 6 paragraph 1 letter c GDPR);
-
conducting marketing; profiling; analytical and statistical purposes, consisting in conducting analyses of Users' activities, as well as their preferences in order to improve the functionalities used (including the website, its structure and content) and the services provided- maintaining the integrity of our IT systems; business planning, reporting and forecasting and optimisation of operations - based on the legitimate interest of the Administrator (art. 6 sec. 1 letter f GDPR);
-
using contact forms made available by the Administrator on the Store's website, in order to take care of the Store's Users and to provide answers to questions, as well as to defend against possible claims - based on the legitimate interest of the Administrator (art. 6 sec. 1 letter f GDPR).
5. Transfer of personal data.
5.1. Kontri sp. z o.o. may entrust the processing of collected User data to entities with which it has concluded a cooperation agreement ("Data Processors") in order to implement the agreement between us, fulfill the obligations of Kontri sp. z o.o. provided by law, protect the rights of Kontri sp. z o.o. in accordance with the provisions of law, and fulfill the legitimate interest of Kontri sp. z o.o. within the meaning of the provisions on the protection of personal data. In particular, Kontri sp. z o.o. may transfer your Personal Data to entities with which we cooperate in order to provide marketing services. Such entities will be obliged under the agreements concluded with Kontri sp. z o.o. to apply appropriate security, technical and organizational measures to protect personal data and process them only in accordance with the instructions provided by Kontri sp. z o.o.
5.2. Kontri sp. z o.o. may transfer data to supervisory authorities, courts, authorities and other third parties; in the event that it is necessary to achieve the purposes indicated above and to fulfill the obligations imposed by law. Personal data may be transferred, for example, to tax authorities and law enforcement agencies, independent external advisors (e.g. auditors).
5.3. The User's personal data will be entrusted by Kontri sp. z o.o., in particular, to entities providing postal or courier services, debt collection companies, accounting companies, law firms, IT companies, software services, companies providing the following services: server rental, online chat, SMS gateway.
6. Transfer to recipients outside the EEA
We may also transfer personal data to recipients based outside the EEA in so-called third countries. In this case, before transferring the data, we ensure that the recipient has an adequate level of data protection (e.g. based on a decision of the EU Commission stating an adequate level of protection for the relevant country or agreement with the recipient on so-called standard contractual clauses of the European Union).
7. Technical measures used by Kontri sp. z o.o. and the period of storage of personal data
7.1. Kontri sp. z o.o. undertakes to apply appropriate security measures, both technical and organizational, to protect your personal data.
7.2 Personal data will be stored by Kontri sp. z o.o. and/or Data Processors only for the time necessary to achieve the purposes for which the data is collected, to perform obligations arising from legal regulations, at the maximum for the period of securing materials necessary for applicable tax regulations. If the processing of personal data is dependent only on the granting of consent, then the data is processed until its withdrawal, restriction or other actions by the User limiting this consent.
8. Newsletter sent electronically
If the User agrees to receive e-mail messages about promotions, sales and new products, their data are used, among other things, for the purpose of implementing the newsletter service (sending ordered messages of an advertising nature to the provided e-mail addresses). Each User of the service has the possibility at any time to change or delete the provided e-mail address by changing the settings of the Customer Account, by clicking the "unsubscribe" link on the petsona.eu website, by clicking the appropriate link, available in the newsletter sent to the e-mail address or by sending a message to Kontri sp. z o.o. to the address contact@petsona.eu.
The sending of such newsletters by e-mail or text message takes place on the basis of the express consent granted by the User, separately in accordance with art. 6 sec. 1 sentence 1 letter a of the GDPR. For security reasons, Kontri sp. z o.o. uses the double opt-in procedure: We send the newsletter to Users by e-mail only after the User has previously confirmed that he/she has given his/her consent to receive marketing messages and commercial information.
In some cases, marketing messages and commercial information may be sent via an external service provider to whom we provide the User's e-mail address and/or telephone number for this purpose. In such cases, the data is processed on behalf of Kontri sp. z o.o. The User may object to the above use of your e-mail address at any time by sending a message to the contact address provided below.
The mailing service provider may use the recipients' data in pseudonymised form, i.e. without assigning it to the User, in order to optimise or improve the services, e.g. for the technical optimisation of the mailing and the presentation of the newsletter, or for statistical purposes. However, the mailing service provider does not use the data of the newsletter recipients to contact them directly, nor does it pass this data on to third parties.
9. Automatic collection and use of data
a) Cookies
The petsona.eu website may use cookies.
A cookie is a small piece of data (text file) that a website - when visited by the User - asks the User's browser to save on their device in order to remember information about the User, such as preferred language or login details. These cookies are set by us and are called first-party cookies (first-party cookies). For advertising and marketing purposes, we also use third-party cookies - which come from a domain other than the domain of the website being visited. The list of cookies currently used is available under this Privacy Policy.
Blocking cookies
In any case, the User may block the installation of cookies using the appropriate options of the web browser. Additionally, a link to the tool: "Manage Cookie files" has been placed in the footer, which allows Users/Service Recipients to adjust cookies to their own preferences. Kontri sp. z o.o. also indicates that cookies may be deleted by the User after they have been saved by Kontri sp. z o.o. through: appropriate functions of the web browser, programs for this purpose or using appropriate tools available within the operating system used by the User.
However, Kontri sp. z o.o. informs Users that changing the configuration of the web browser, which prevents or limits the storage of cookies on the User's end device may result in limitations of the functionality of the services provided. Deleting cookies during the provision of the service may lead to similar effects. This may result interrupting the session after logging in.
b) Other tools for collecting, analyzing and using data:
Kontri sp. z o.o. may collect User data using the following tools:
-
marketing automation (e-mail, text messages, push notifications);
-
software for testing websites;
-
marketing tools analyzing the behavior of Users on the website and the effects of internet marketing;
-
marketing tools for automating product recommendations;
-
product search engines;
-
online messengers;
-
customer relationship management system;
-
maps (location) e.g. OpenStreetMap;
-
payment services e.g. Payu;
for the purposes of performing the contract, analytical, statistical and marketing.
The above-mentioned services help the Administrator, among others, to keep statistics and analyze traffic in the Online Store. By using the above services in the Online Store, the Administrator collects such data as the sources and medium of acquiring visitors to the Online Store and the way they behave on the Online Store website, information on the devices and browsers from which they visit the website, IP and domain, geographic data and demographic data (age, gender) and interests.
10. Profiling in the online store
10.1. The Administrator may use profiling in the Online Store for direct marketing purposes, but decisions made on its basis by the Administrator do not concern the conclusion or refusal to conclude a Sales Agreement or the possibility of using the Services in the Online Store. The effect of using profiling in the Online Store may be, for example, granting a given person a discount, sending them a discount code, sending a product proposal that may meet the interests or preferences of a given person or proposing better conditions compared to the standard offer of the Online Store. Despite profiling, a given person freely decides whether they will want to use the discount received in this way or better conditions and make a purchase in the Online Store.
10.2. Profiling in the Online Store includes automatic analysis or forecasting of a given person's behavior on the Online Store website, e.g. by adding a specific product to the basket, browsing the page of a specific product in the Online Store, or by analyzing the history of purchases made in the Online Store to date.
11. User Rights
11.1. The User has rights in the scope of personal data protection. In accordance with applicable data protection law, Users are entitled to lodge a complaint with the appropriate supervisory authority (i.e. the President of the Office for Personal Data Protection).
11.2. In addition, the User has the right to:
-
Request access to personal data - the data subject is entitled to obtain confirmation as to whether personal data concerning them are being processed, and if so, is entitled to obtain access to them. Kontri sp. z o.o. will provide Users with a copy of their personal data subject to processing upon request. For any subsequent copies that the User requests from the Administrator, Kontri sp. z o.o. may charge a reasonable fee resulting from administrative costs;
-
Rectification of personal data - the User has the right to rectify personal data concerning them that are incorrect. Taking into account the purposes of processing, the User has the right to request supplementation of incomplete personal data, including by submitting an additional declaration; Removal of personal data ("right to be forgotten") - the User has the right to request, if there are circumstances provided for by law, immediate removal of personal data concerning him/her, and Kontri sp. z o.o is obliged to remove such personal data without undue delay;
-
Restrictions on the processing of personal data - in such a case, Kontri sp. z o.o may, at the User's request, limit the processing of personal data only and exclusively for specific purposes;
-
Transfer of personal data - under certain conditions, the User has the right to receive in a structured, commonly used, machine-readable format, personal data concerning him/her, processed by Kontri sp. z o.o., he/she also has the right to request that such personal data be sent to another entity;
-
Objection - in certain circumstances, the User has the right to object at any time - for reasons related to his/her special situation - to the processing of his/her personal data.
11.3. In the case of voluntary consent to the processing of data, each person whose data is processed has the right to withdraw consent to the processing of data.
11.4. Requests regarding the exercise of data subject rights may be submitted in writing to the Controller’s address provided in this Policy.
12. Other
12.1. The User may not use the services provided via the Store anonymously or under a pseudonym. The above reservation does not apply to the service of sending marketing messages and commercial information.
12.2. In case of any questions regarding Personal Data or exercising privacy rights, please contact: Kontri sp. z o.o., at the address: ul. Jacka Kuronia 3 15-569 Białystok or at the e-mail address: contact@petsona.eu.
12.3. We inform you about the possibility of periodic updates of this Information in accordance with applicable law (e.g. if we implement new systems or processes that involve the use of personal data).
12.4. After each transaction, Kontri sp. z o.o. will process personal data, in the form of an e-mail address, in order to examine opinions on the level of satisfaction with the purchase. In order to examine opinions on the level of satisfaction with the purchase, Kontri sp. z o.o. uses an external service provider.
12.5. The policy can be found at: https://petsona.eu/pl/privacy-and-cookie-notice.html
LIST OF COOKIES:
Functional cookies (required)
petsona.eu
monit_token: 365 days, cookie
Identifies the shop's customer.
shop_monit_token: 30 minutes, cookie
Identifies the shop's customer.
client: 1 days, cookie
Identifies the logged-in customer / basket of the non-logged-in customer.
affiliate: 90 days, cookie
It stores information about the partner ID from which the shop was entered.
ordersDocuments: cookie
Stores information about the print status of a document.
__idsui: 1095 days, cookie
File required for the so-called lightweight login function on the website.
__idsual: 1095 days, cookie
File required for the so-called lightweight login function on the website.
__IAI_SRC: 90 days, cookie
It only stores the source from which the page was accessed.
login: cookie
Stores information about whether the user has logged in to the site.
CPA: 28 days, cookie
Includes information on the variables for the CPA / CPS programmes in which the site participates.
__IAIRSABTVARIANT__: 30 days, cookie
Variant identifier for the A/B test and IdoSell RS engine configuration.
basket_id: 365 days, cookie
The site user's shopping cart identifier, assigned for the duration of the ongoing session.
page_counter: 1 days, cookie
Counter of pages visited.
LANGID: 180 days, cookie
Stores information about the language selected by the site user.
REGID: 180 days, cookie
Stores information about the site user's region.
CURRID: 180 days, cookie
Stores information about the currency of the site selected by the user.
__IAIABT__: 30 days, cookie
It stores the A/B test identifier, for the purpose of testing and improving shop functionality.
__IAIABTSHOP__: 30 days, cookie
It stores the identifier of the shop participating in the A/B test.
__IAIABTVARIANT__: 30 days, cookie
Stores the identifier of the variant drawn as part of the ongoing A/B test.
toplayerwidgetcounter[]: cookie
Stores the number of times a pop up message has been displayed.
samedayZipcode: 90 days, cookie
Stores information about the site user's postcode, which is required to offer courier delivery on the SameDay service.
applePayAvailability: 30 days, cookie
Stores information about whether an ApplePay payment method is available for the user.
paypalMerchant: 1 days, cookie
PayPal account ID.
toplayerNextShowTime_: cookie
Stores information about the time at which the next pop up message is to be displayed.
rabateCode_clicked: 1 days, cookie
Stores information about the closure of the active discount bar.
freeeshipping_clicked: 1 days, cookie
Stores information about the closing of the free delivery bar.
redirection: cookie
Stores information on the closure of the pop-up message indicating the suggested language for the shop.
filterHidden: 365 days, cookie
When the option to collapse the filter for goods is clicked, it saves which filter is to be collapsed when the goods list is refreshed.
toplayerwidgetcounterclosedX_: cookie
It stores information about closing the pop-up message.
cpa_currency: 60 minutes, cookie
Includes currency information for CPA / CPS programmes in which the site participates.
basket_products_count: cookie
Stores information on the number of products in the basket.
wishes_products_count: cookie
Stores information on the number of products in the favorites list.
remembered_mfa: 365 days, cookie
Stores remembered user information for multi-factor authentication (MFA)
HOMELANDID: 180 days, cookie
Stores information about the visitor's country.
IAI S.A.
iai_accounts_toplayer: 30 days, cookie
Ensures the correct display of the pop up message informing about the IdoAccounts login service (https://www.idosell.com/en/idoaccounts-is-a-system-that-facilitates-the-process-of-logging-in-to-many-stores-with-one-account-and-placing-orders-in-online-stores/).
IdoSell
platform_id: cookie
Stores information about whether the page is displayed in the mobile app.
paypalAvailability_: 1 days, cookie
Stores information on whether a PayPal payment method is available for the user.
ck_cook: 3 days, cookie
Stores information about whether the user of the website has consented to cookies.
IdoAccounts
accounts_terms: 365 days, cookie
Stores information on whether the user has accepted consent to use the IdoAccounts service.
express_checkout_login: 365 days, cookie
CookieNameExpressCheckoutLogin
NID: 180 days, cookie
These cookies (NID, ENID) are used to remember your preferences and other information, such as your preferred language, how many results you prefer to have shown on a search results page (for example, 10 or 20), and whether you want to have Google’s SafeSearch filter turned on. This cookie is also required to offer the Google Pay payment service.
Google reCAPTCHA
_GRECAPTCHA: 1095 days, cookie
This cookie is set by Google reCAPTCHA, which protects our site against spam enquiries on contact forms.
PayPal
ts: cookie
This cookie is generally provided by PayPal and supports payment services on the website.
ts_c: 1095 days, cookie
This cookie is generally provided by PayPal and is used to prevent fraud.
x-pp-s: cookie
This cookie is generally provided by PayPal and supports payment services on the website.
enforce_policy: 365 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
tsrce: 3 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
l7_az: 60 minutes, cookie
This cookie is necessary for the PayPal login-function on the website.
LANG: 1 days, cookie
This cookie is generally provided by PayPal and supports payment services on the website.
nsid: cookie
Used in the context of transactions on the Website. The cookie is required for secure transactions.
Analytics cookies
IAI S.A.
__IAI_AC2: 45 days, cookie
Activity Tracking identifier to collect the history of pre-order sources as well as the source through which the order was placed according to the last click attribution model.
Google Ads
*-*: 14 days, cookie
It stores information about whether a 'Google Consumer Reviews' popup has already been displayed, asking for consent to send a survey about the order.
Google Maps
SID: 3650 days, cookie
Contain digitally signed and encrypted records of a user’s Google Account ID and most recent sign-in time. The combination of these cookies (SID, HSID) allows Google to block many types of attack, such as attempts to steal the content of forms submitted in Google services.
Advertising cookies
Meta (Facebook)
fbsr_: cookie
Contains the signed request for the Facebook App user.
fbss_: 365 days, cookie
Shared session Facebook.
fbs_: 30 minutes, cookie
Facebook session.
Meta Pixel: 999 days, tracking pixel
The Meta Pixel is a piece of code that allows you to measure the effectiveness of your advertising by understanding the actions taken by users of the site and allows you to make sure that your shop ads are shown to the right people.
_fbp: 90 days, cookie
Cookie used for user profiling and to match advertising to user profile as accurately as possible.
fr: 90 days, cookie
Cookie used for user profiling and to match advertising to user profile as accurately as possible.
_fbc: 730 days, cookie
Store last visit.
tr: cookie
Cookie used for user profiling and to match advertising to user profile as accurately as possible.
sb: 402 days, cookie
This cookie helps identify and apply additional security measures in case someone tries to access your Facebook account without authorization, for example by entering random passwords. It is also used to record information that will allow Facebook to recover a user's account if they forget their password, or to provide additional authentication if it suspects someone has hacked into their account. This includes, for example, \"sb\" and \"dbln\" cookies, which can securely identify a user's browser.
usida: cookie
Collects a combination of the user’s browser and unique identifier, used to tailor advertising to users.
wd: 9 days, cookie
This cookie helps direct traffic between servers and analyze how fast Meta Products load on different users. Thanks to cookies, Meta can also record the aspect ratio and dimensions of a user's screen and windows, and know whether the user has high contrast mode enabled, so it can present its sites and applications correctly. It can, for example, use \"dpr\" and \"wd\" cookies, among others, to provide the user with optimal device screen parameters.
locale: 9 days, cookie
This cookie contains the display locale of the last logged in user on this browser.
datr: 7 days, cookie
The purpose of the datr cookie is to identify the web browser being used to connect to Facebook independent of the logged in user. This cookie plays a key role in Facebook's security and site integrity features.
petsona.eu
RSSID: 180 days, cookie
IdoSell RS user ID, used for the purpose of displaying tailored product recommendations on the website.
__IAIRSUSER__: 60 minutes, cookie
IdoSell RS user ID, used for the purpose of displaying tailored product recommendations on the website.
Google Ads
_gcl_au : 90 days, cookie
Used by Google AdSense for experimenting with advertisement efficiency across websites using their services.
FPAU: 90 days, cookie
A cookie that collects information about users and their activity on the site through embedded elements for analytical and reporting purposes.
FPGCLAW: 90 days, cookie
Contains campaign related information on the user.
FPGCLGB: 90 days, cookie
Contains campaign related information on the user.
_gcl_gb: 90 days, cookie
Contains campaign related information on the user.
_gac_gb_<>: 90 days, cookie
Contains campaign related information on the user.
_gcl_aw: 90 days, cookie
Contains campaign related information on the user.
IDE: 730 days, cookie
This cookie are used to show Google ads on non-Google sites.
1P_JAR: 30 days, cookie
This cookie file is used to collect website statistics and track conversion rates. Sets a unique ID to remember your preferences and other information such as website statistics and track conversion rates.
test_cookie: 1 days, cookie
It is used for testing whether the permissions to set cookies in the user's browser are enabled
AEC: 138 days, cookie
These cookies prevent malicious sites from acting on behalf of a user without that user’s knowledge.
APISID: 193 days, cookie
This cookie file is stored on your computer to remain connected to your Google account, while visiting their services again. While you remain with this active session and use add-ons on other websites, such as ours, Google will use these cookies to improve your user experience.
CONSENT: 559 days, cookie
This cookie file is stored on your computer to remain connected to your Google account, while visiting their services again. While you remain with this active session and use add-ons on other websites, such as ours, Google will use these cookies to improve your user experience.
DSID: 10 days, cookie
‘DSID’ cookie is used to identify a signed-in user on non-Google sites and to remember whether the user has agreed to ad personalization.
OTZ: 23 days, cookie
This cookie is used to remember your preferences and other information, such as your preferred language, the number of results displayed on a search results page (for example, 10 or 20), and whether you want to have Google SafeSearch turned on.
SAPISID: 28 days, cookie
This cookie file is stored on your computer to remain connected to your Google account, while visiting their services again. While you remain with this active session and use add-ons on other websites, such as ours, Google will use these cookies to improve your user experience.
SEARCH_SAMESITE: 176 days, cookie
Allow servers to mitigate the risk of CSRF and information leakage attacks by asserting that a particular cookie should only be sent with requests initiated from the same registrable domain.
SIDCC: 393 days, cookie
Download certain tools from Google and save certain preferences, for example the number of search results per sheet or activation of the SafeSearch filter. Adjust the ads appearing in google search.
SSID: 393 days, cookie
This cookie file is stored on your computer to remain connected to your Google account, while visiting their services again. While you remain with this active session and use add-ons on other websites, such as ours, Google will use these cookies to improve your user experience.
__Secure-*: 730 days, cookie
These cookies are used to deliver ads more relevant to you and your interests.