Privacy Policy

1. Data Controller and Definitions

  1. The administrator of personal data of Customers / Users of the Online Store, also referred to as the Seller, is: Bellamy Rita Suchocka, phone: +48733666144, NIP: 687-164-95-92, REGON: 180055760.
  2. The Data Controller can be contacted:
    1. at the correspondence address: ul. Składowa 6, 38-540 Zagórz;
    2. at the e-mail address: biuro@bellamy.pl.
  3. User - a natural person entering the online store page(s) or using the services or functionalities described in this Privacy and Cookies Policy.
  4. Customer - a natural person with full legal capacity, a natural person who is a Consumer, a legal person or an organizational unit without legal personality, to whom the law grants legal capacity, who enters into a Distance Sales Agreement with the Seller.
  5. Online Store - an internet service run by the Seller, available at the electronic addresses (pages): https://bellamy.pl through which the Customer/User can obtain information about the Goods and their availability, and purchase Goods or commission a service.
  6. Newsletter - information, including commercial information within the meaning of the Act of July 18, 2002, on the provision of electronic services (Journal of Laws of 2020, item 344) from the Seller, sent to the Customer/User electronically; receiving it is voluntary and requires the Customer/User's consent.
  7. Account - a collection of data stored in the Online Store and in the Seller's ICT system concerning a given Customer/User, their placed orders, and concluded contracts, through which the Customer/User can place orders and conclude contracts.
  8. GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

2. Purposes, legal bases, and duration of data processing

  1. For the purpose of performing the Distance Sales Agreement, the Seller processes:
    1. information regarding the User's device to ensure the correct functioning of services: computer IP address, information contained in cookies or other similar technologies, session data, web browser data, device data, activity data on the Website, including on individual subpages;
    2. geolocation information, if the User has consented to the service provider accessing geolocation. Geolocation information is used to provide more tailored product and service offers;
    3. Users' personal data: name, surname, registered office address, correspondence address, e-mail address, telephone number, NIP (tax identification number), bank account number, or other personal data whose provision is necessary to complete the purchase and whose provision in the purchasing process is required by the Administrator.
  2. This information does not contain data relating to the identity of Users, but in combination with other information, it may constitute personal data and, therefore, the Administrator grants it full protection under the GDPR.
  3. This data is processed in accordance with Article 6(1)(b) of the GDPR, for the purpose of service provision, i.e., the contract for the provision of electronic services in accordance with the Regulations, and in accordance with Article 6(1)(a) of the GDPR, in connection with expressing consent to the use of specific cookies or other similar technologies, expressed through appropriate web browser settings in accordance with telecommunications law or in connection with expressing consent to geolocation. Data is processed until the Customer/User ceases to use the Online Store.
  4. The Administrator undertakes to take all measures required under Article 32 of the GDPR, i.e., taking into account the state of technical knowledge, implementation costs, and the nature, scope, and purposes of processing, as well as the risk of violating the rights or freedoms of natural persons with varying likelihood and severity, the Administrator implements appropriate technical and organizational measures to ensure a level of security commensurate with this risk.

3. Administrator's marketing activities

  1. On the Online Store's website, the Data Administrator may post marketing information about its products or services. The display of this content is carried out by the Data Administrator in accordance with Article 6(1)(f) of the GDPR, i.e., in accordance with the Data Administrator's legitimate interest in publishing content related to the services provided and promotional content for campaigns in which the Data Administrator is involved. At the same time, this action does not infringe the rights and freedoms of Customers/Users; Customers/Users expect to receive content of similar nature and even anticipate it, or it is their direct purpose for visiting the Online Store's website(s).

4. Recipients of user data

  1. The Data Controller discloses users' personal data only to processors under data processing agreements for the purpose of providing services to the Data Controller, e.g., hosting and website support, IT services, marketing and PR services.

5. Collection, acquisition, scope, and purpose of personal data collection

  1. The Administrator informs Users that it entrusts the processing of personal data to the following entities:
    - Edrone Sp. z o.o., ul. Lekarska 1, 31-203 Kraków, NIP: 676-248-20-64, KRS: 0000537197 – for the purpose of using the edrone.me mailing system, used for sending newsletters,
    - Edrone Sp. z o.o., ul. Lekarska 1, 31-203 Kraków, NIP: 676-248-20-64, KRS: 0000537197: – for marketing purposes solely for the needs of email, SMS, social media campaigns launched or indicated by the Administrator using the edrone system.
  2. The Administrator informs that it uses the following technologies to track actions taken by the user/Customer on the Store's website:
    - Edrone tracking codes – for the purpose of analyzing the Store's website statistics, as well as for marketing purposes solely for the needs of email, SMS, social media campaigns launched or indicated by the Administrator using the edrone system.

6. Transfer of personal data to third countries

  1. Personal data will not be processed in third countries.

7. Rights of data subjects

  1. Every data subject has the right to:
    1. access (Article 15 GDPR) - obtain from the Data Controller confirmation as to whether or not personal data concerning him or her are being processed. If data concerning the person is being processed, he or she is entitled to access them and obtain the following information: about the purposes of processing, categories of personal data, recipients or categories of recipients to whom the data have been or will be disclosed, the period of data storage or the criteria for determining it, the right to request rectification, erasure or restriction of processing of personal data concerning the data subject, and to object to such processing;
    2. receive a copy of the data (Article 15(3) GDPR) - obtain a copy of the data undergoing processing, whereby the first copy is free of charge, and for subsequent copies, the Data Controller may impose a reasonable fee, resulting from administrative costs;
    3. rectification (Article 16 GDPR) - request the rectification of personal data concerning him or her that is inaccurate, or to have incomplete data completed;
    4. erasure of data (Article 17 GDPR) - request the erasure of his or her personal data if the Data Controller no longer has a legal basis for processing them or the data are no longer necessary for the purposes of processing;
    5. restriction of processing (Article 18 GDPR) - request the restriction of personal data processing when:
      1. the accuracy of the personal data is contested by the data subject, for a period enabling the Data Controller to verify the accuracy of the personal data,
      2. the processing is unlawful and the data subject opposes the erasure of the personal data and requests instead the restriction of their use,
      3. the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims,
      4. the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject;
    6. data portability (Article 20 GDPR) - receive the personal data concerning him or her, which he or she has provided to the Data Controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller, where the processing is based on consent or on a contract and the processing is carried out by automated means;
    7. object (Article 21 GDPR) - object to the processing of his or her personal data for the controller's legitimate purposes, on grounds relating to his or her particular situation, including profiling. In such a case, the Data Controller assesses the existence of compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims. If, according to the assessment, the data subject's interests are more important than the controller's interests, the Data Controller will be obliged to cease processing the data for these purposes;
    8. withdraw consent at any time and without giving any reason, but the processing of personal data carried out before the withdrawal of consent will still remain lawful. Withdrawal of consent will result in the Data Controller ceasing to process personal data for the purpose for which the consent was given.
  2. To exercise the aforementioned rights, the data subject should contact the Data Controller using the provided contact details and inform them which right they wish to exercise and to what extent.

8. President of the Personal Data Protection Office

  1. The data subject has the right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) with its seat in Warsaw, ul. Stawki 2, who can be contacted as follows:
  2. by mail: ul. Stawki 2, 00-193 Warsaw;
  3. via the electronic inbox available on the website: https://www.uodo.gov.pl/pl/p/kontakt;
  4. Helpline: 606-950-000.

9. Data Protection Officer

  1. In any case, the data subject may also contact the Administrator's data protection officer directly by email or in writing to the Administrator's address, as specified in section 1, point 2 of this Privacy and Cookies Policy.

10. Changes to the Privacy Policy

  1. The privacy and cookies policy may be supplemented or updated in accordance with the Administrator's current needs to provide up-to-date and reliable information to Customers/Users.

11. Cookies

  1. The online store acquires information about Customers, Users, and their behavior in the following ways:
    1. through information voluntarily entered into forms for purposes resulting from the function of a specific form;
    2. by saving cookies (so-called "cookies") on end devices;
    3. by collecting web server logs by the online store's hosting provider (necessary for the proper functioning of the service).
  2. Cookies are IT data, in particular text files, which are stored on the Customer's / User's end device and are intended for using the Online Store's website. Cookies usually contain the name of the website they come from, the time of their storage on the end device, and a unique number.
  3. The Online Store uses cookies only after the Customer/User of the Store has given prior consent in this regard. Consent to the use of all cookies by the Online Store is given by clicking the "Close" button when the message about the Online Store's use of cookies is displayed, or by closing this message.
  4. If the Customer/User of the Online Store does not agree to the Online Store's use of cookies, they can use the "I do not agree" option, also available in the message about the Online Store's use of cookies, or change the settings of the web browser they are currently using (however, this may cause the Online Store's website to function incorrectly).
  5. To manage cookie settings, select the internet browser/system from the list and follow the instructions: Internet Explorer, Chrome, Safari, Firefox, Opera, Android, Safari (iOS), Windows Phone.
  6. The legal basis for processing personal data originating from cookies is the legitimate interests of the Data Controller, consisting of ensuring high-quality services and ensuring the security of services.
  7. The Online Store uses two main types of cookies: "session" cookies and "persistent" cookies. "Session" cookies are temporary files that are stored on the User's end device until logging out, leaving the Online Store, or turning off the software (web browser). "Persistent" cookies are stored on the Customer's/User's end device for a time specified in the cookie parameters or until they are deleted by the Customer/User.

 

Functional cookies (required)

bellamy.pl

monit_token: 365 days, cookie
Identifies the store customer.

shop_monit_token: 30 minutes, cookie
Identifies the store customer.

client: 1 day, cookie
Identifies a logged-in customer / shopping cart of a non-logged-in customer.

affiliate: 90 days, cookie
Stores information about the affiliate ID from which the entry to the store occurred.

ordersDocuments: cookie
Stores information about the document printing status.

__idsui: 1095 days, cookie
File necessary for the functioning of so-called light login on the website.

__idsual: 1095 days, cookie
File necessary for the functioning of so-called light login on the website.

__IAI_SRC: 90 days, cookie
Stores only the source from which the website was accessed.

login: cookie
Stores information about whether the user has logged in to the website.

CPA: 28 days, cookie
Contains information about variables for CPA / CPS programs in which the site participates.

__IAIRSABTVARIANT__: 30 days, cookie
Variant identifier for A/B testing and IdoSell RS engine configuration.

basket_id: 365 days, cookie
Identifier of the user's shopping cart, assigned for the duration of the current session.

page_counter: 1 day, cookie
Page visit counter.

LANGID: 180 days, cookie
Stores information about the language selected by the website user.

REGID: 180 days, cookie
Stores information about the website user's region.

CURRID: 180 days, cookie
Stores information about the currency selected by the website user.

__IAIABT__: 30 days, cookie
Stores the A/B test identifier for the purpose of testing and improving store functionality.

__IAIABTSHOP__: 30 days, cookie
Stores the identifier of the store participating in the A/B test.

__IAIABTVARIANT__: 30 days, cookie
Stores the identifier of the variant drawn within the ongoing A/B test.

toplayerwidgetcounter[]: cookie
Stores the number of pop-up message displays.

samedayZipcode: 90 days, cookie
Stores information about the website user's zip code, which is necessary to offer courier delivery in the SameDay service.

applePayAvailability: 30 days, cookie
Stores information about whether the ApplePay payment method is available to the user.

paypalMerchant: 1 day, cookie
PayPal account identifier.

toplayerNextShowTime_: cookie
Stores information about the time when the next pop-up message should be displayed. 

rabateCode_clicked: 1 day, cookie
Stores information about closing the bar informing about an active discount.

freeeshipping_clicked: 1 day, cookie
Stores information about closing the bar informing about free shipping.

redirection: cookie
Stores information about closing the pop-up message informing about the suggested language for the store.

filterHidden: 365 days, cookie
After clicking the option to collapse the product filter, it saves information about which filter should be collapsed after refreshing the product list.

toplayerwidgetcounterclosedX_: cookie
Stores information about closing a pop-up message.

cpa_currency: 60 minutes, cookie
Contains information about the currency for CPA / CPS programs in which the site participates.

basket_products_count: cookie
Stores information about the number of items in the shopping cart.

wishes_products_count: cookie
Stores information about the number of items on the wish list.

remembered_mfa: 365 days, cookie
Stores information about a remembered user for multi-factor authentication (MFA) purposes.

HOMELANDID: 180 days, cookie
Stores information about the visitor's country.

IAI S.A.

iai_accounts_toplayer: 30 days, cookie
Ensures the correct display of the pop-up message informing about the IdoAccounts login service (https://www.idosell.com/pl/tysiace-gotowych-do-uzycia-funkcji/logowanie-do-sklepu-z-konta-w-innym-serwisie/).

IdoSell

platform_id: cookie
Stores information about whether the page is displayed in a mobile application.

paypalAvailability_: 1 day, cookie
Stores information about whether the PayPal payment method is available to the user.

ck_cook: 3 days, cookie
Stores information about whether the website user has consented to cookies.

IdoAccounts

accounts_terms: 365 days, cookie
Stores information about whether the user has accepted the consent to use the IdoAccounts service.

express_checkout_login: 365 days, cookie
CookieNameExpressCheckoutLogin

Google

NID: 180 days, cookie
These cookies (NID, ENID) are used to remember user preferences and other information, such as preferred language, the number of results displayed on a search results page (e.g., 10 or 20), and whether the user wants Google SafeSearch enabled. This file is also necessary to offer the Google Pay payment service.

Google reCAPTCHA

_GRECAPTCHA: 1095 days, cookie
This cookie is set by Google reCAPTCHA, which protects our site from spam queries in contact forms.

PayPal

ts: cookie
This cookie is typically provided by PayPal and supports payment services on the website.

ts_c: 1095 days, cookie
This cookie is typically provided by PayPal and is used to prevent fraud.

x-pp-s: cookie
This cookie is typically provided by PayPal and supports payment services on the website.

enforce_policy: 365 days, cookie
This cookie is typically provided by PayPal and supports payment services on the website.

tsrce: 3 days, cookie
This cookie is typically provided by PayPal and supports payment services on the website.

l7_az: 60 minutes, cookie
This cookie is essential for the PayPal login function on the website.

LANG: 1 day, cookie
This cookie is typically provided by PayPal and supports payment services on the website.

nsid: cookie
Used in the context of transactions on the website. The cookie is required for secure transactions.


Analytical cookies

IAI S.A.

__IAI_AC2: 45 days, cookie
Conversion tracking identifier (Activity Tracking) for the purpose of collecting the history of sources preceding an order placement, as well as the source through which an order was placed according to the last-click attribution model.

Google Maps

SID: 3650 days, cookie
Contains digitally signed and encrypted records of the user's Google account ID and last login time. The combination of these cookies (SID, HSID) allows Google to block many types of attacks, such as attempts to steal the content of forms submitted in Google services.


Advertising cookies

Meta (Facebook)

fbsr_: cookie
Contains a signed request for the Facebook App user.

fbss_: 365 days, cookie
Facebook shared session.

fbs_: 30 minutes, cookie
Facebook session.

Meta Pixel: 999 days, tracking pixel
Meta Pixel is a piece of code that allows you to measure the effectiveness of advertising by understanding the actions taken by website users and ensures that store ads are displayed to the right people.

_fbp: 90 days, cookie
Cookie used for user profiling and to match ads as accurately as possible to the user's profile.

fr: 90 days, cookie
Cookie used for user profiling and to match ads as accurately as possible to the user's profile.

_fbc: 730 days, cookie
Last visit to the store.

tr: cookie
Cookie used for user profiling and to match ads as accurately as possible to the user's profile.

sb: 402 days, cookie
This cookie helps identify and apply additional security measures if someone tries to access a Facebook account without authorization, for example, by entering randomly selected passwords. It is also used to save information that will allow Facebook to recover the user's account if they forget their password, or for additional authentication when they suspect someone has hacked their account. This includes, for example, the "sb" and "dbln" cookies, which allow Facebook to securely identify the user's browser.

usida: cookie
Collects a combination of the user's browser and a unique identifier, used to match ads to users.

wd: 9 days, cookie
This cookie helps route traffic between servers and analyze the loading speed of Meta's Products for different users. Thanks to cookies, Meta can also record the aspect ratios and dimensions of the user's screen and windows and knows if they have high contrast mode enabled, so it can correctly present its websites and applications. For example, it can use "dpr" and "wd" files, among others, to provide the user with optimal device screen parameters.

locale: 9 days, cookie
This cookie contains the location of the last logged-in user in this browser.

datr: 7 days, cookie
The purpose of the datr cookie is to identify the web browser used to connect to Facebook regardless of the logged-in user. This cookie plays a key role in the security and integrity features of the Facebook site.

bellamy.pl

RSSID: 180 days, cookie
IdoSell RS user identifier, used to display tailored product recommendations on the website.

__IAIRSUSER__: 60 minutes, cookie
IdoSell RS user identifier, used to display tailored product recommendations on the website.

Photoslurp

ps_analytics: 29 days, cookie
Tracks which photos or galleries a given user has viewed. This information is used for marketing purposes.


 

  1. Cookies are used for the following purposes:
    1. creating statistics that help understand how Customers/Users of the Online Store use websites, which allows for improving their structure and content;
    2. maintaining the Customer's/User's session (after logging in), thanks to which the Customer/User does not have to re-enter their login and password on every subpage of the Online Store;
    3. determining the Customer's/User's profile in order to display product recommendations and tailored materials in advertising networks, especially the Google network.
  2. Web browsing software (internet browser) usually by default allows storing cookies on the Customer's/User's end device. Customers/Users can change these settings. The internet browser allows for the deletion of cookies. It is also possible to automatically block cookies.
  3. Restrictions on the use of cookies may affect some functionalities available on the Online Store's websites.
  4. Cookies placed on the Customer's/User's end device and used may also be used by advertisers and partners of the Online Store cooperating with it.
  5. Cookies may be used by the Google network to display advertisements tailored to how the Customer/User uses the Online Store. For this purpose, they may store information about the user's navigation path or time spent on a given page: https://policies.google.com/technologies/partner-sites.
  6. We recommend that the Customer/User read the privacy policy of these companies to learn the rules of using cookies used in statistics: Google Analytics Privacy Policy.
  7. Regarding information about Customer/User preferences collected by the Google advertising network, the Customer/User can view and edit information resulting from cookies using the tool: https://www.google.com/ads/preferences/.
  8. The Online Store's website contains plugins that may transfer Customer/User data to Administrators such as, for example: Google Maps, Meta (Facebook), PayPal, Photoslurp, Google reCAPTCHA, IdoAccounts, IdoSell, IAI S.A., Google.
  9. In order to properly execute the Distance Sales Agreement, the Data Controller may share Customer/User data with courier entities. Currently available delivery methods in the Online Store are available at: https://bellamy.pl/pl/delivery.html.
  10. In order to properly implement the Distance Sales Agreement, the Administrator may share Customer/User data with online payment systems. Currently available prepayment methods in the Online Store are available at: https://bellamy.pl/pl/payments.html.

12. Newsletter

  1. The Customer may consent to receive commercial information electronically by checking the appropriate option in the registration form or at a later date in the relevant tab. If such consent is given, the Customer/User will receive information (Newsletter) from the Online Store, as well as other commercial information sent by the Seller, to the email address provided.
  2. The Customer may unsubscribe from the Newsletter at any time independently, by unchecking the appropriate box on their Account page, or by visiting the form https://bellamy.pl/pl/newsletter.html, clicking the appropriate link included in each Newsletter, or through Customer Service.

13. Account

  1. The Customer/User may not post or provide to the Seller any unlawful content, including opinions and other data, on the Online Store.
  2. The Customer/User gains access to the Account after registration.
  3. During registration, the Customer/User provides the account type or gender, first name, last name, company name, NIP (tax ID), data for issuing sales documents, shipping data, email address, and chooses a password. The Customer/User assures that the data provided in the registration form is truthful. Registration requires careful reading of the Regulations and checking the box on the registration form confirming that the Customer/User has read the Regulations and fully accepts all its provisions.
  4. Upon granting the Customer/User access to the Account, an agreement for the provision of services by electronic means concerning the Account is concluded between the Seller and the Customer for an indefinite period. A consumer may withdraw from this agreement under the terms specified in the Regulations.
  5. Registering an Account on one of the Online Store's websites also means registration enabling access to other websites where the Online Store is available.
  6. The Customer/User may terminate the agreement for the provision of electronic services at any time with immediate effect, by informing the Seller via email or in writing to the Data Controller's address, as specified in section 1, point 2 of this Privacy and Cookies Policy.
  7. The Seller has the right to terminate the agreement for the provision of services concerning the Account in the event of discontinuing the provision or transferring the Online Store service to a third party, a breach of law or the provisions of the Regulations by the Customer/User, as well as in the event of the Customer's/User's inactivity for a period of 6 months. The termination of the agreement occurs with a seven-day notice period. The Seller may stipulate that re-registration of the Account will require the Seller's permission.