• Privacy & Cookie Policy – Data Protection

Privacy and Cookie Policy of the AEON – Watch Corner Online Store

§1. Data controller and contact details

  1. The controller of the personal data of users and Customers of the aeonzegarki.com online store is Jarosław Napierała, conducting business under the name AEON – Kącik Zegarkowy, ul. Polska 15a/1, 67-200 Głogów, Poland, Tax Identification Number (NIP): 693-102-48-79, Business Registry Number (REGON): 390372966, hereinafter referred to as the “Controller”.

  2. For matters concerning personal data, the Controller may be contacted by e-mail at info@aeonzegarki.com, by telephone at +48 514 761 004 or in writing at the address stated above.

  3. The Controller has not appointed a data protection officer. All privacy-related enquiries should be addressed directly to the Controller.

§2. Categories and sources of data

  1. The Controller may process information provided by a user or Customer, including: full name, business name, tax identification number, billing and delivery address, e-mail address, telephone number, Customer account information, correspondence, order number, purchase, return, complaint and guarantee information, and information required to issue a bill or another sales document required by law.

  2. The Controller does not retain full payment-card details. Payments are handled by external payment providers according to the method selected by the Customer.

  3. Technical information may be recorded automatically when the Store is used, including the IP address, date and time of connection, device and browser type, operating-system information, referring address, cookie identifiers and information about activity in the Store.

  4. Data is obtained primarily from the user. The Controller may also receive payment and delivery status information from payment providers, banks, carriers and providers of the Store’s technical infrastructure.

§3. Purposes, legal bases and retention periods

  1. Personal data is processed only to the extent required for specified purposes and on an appropriate legal basis.

Purpose Legal basis Retention period
Creating and maintaining a Customer account Performance of an electronic-services contract or steps taken before entering into it Until the account is deleted and subsequently for any period required to comply with legal obligations or protect legal claims
Accepting, receiving payment for and fulfilling an order; order-related contact; delivery and after-sales support Performance of a contract or steps taken at the Customer’s request before entering into a contract For the duration of the contract and subsequently until the expiry of applicable limitation periods and statutory retention periods
Issuing and retaining bills and other sales or accounting documents required by law Compliance with legal obligations imposed on the Controller For the period required by tax, accounting and other applicable laws
Handling returns, complaints, lack of conformity and guarantee claims Performance of the Controller’s contractual and legal obligations For the duration of the matter and subsequently until the expiry of the relevant limitation period
Answering enquiries and conducting correspondence Steps before entering into a contract or the legitimate interest in handling correspondence and protecting legal claims Until correspondence is completed and subsequently for the period necessary to protect claims or demonstrate the course of communication
Preventing fraud, abuse, fictitious unpaid orders, attacks and security incidents The Controller’s legitimate interest in protecting the Store, Customers, property and legal claims For the period required to analyse the event and protect claims; ordinary technical logs are retained for a period justified by system operation and security
Establishing, pursuing or defending legal claims The Controller’s legitimate interest Until expiry of the relevant limitation period or final completion of proceedings
Newsletter and electronic commercial communications The user’s voluntary consent Until consent is withdrawn or an effective objection is made; records demonstrating consent may be retained for the period required to defend against claims
Analysis of use of the Store and measurement of promotional activity using optional cookies Voluntary consent provided through cookie settings Until consent is withdrawn, identifiers are deleted or the relevant cookie expires
Personalised marketing, creation of audiences and advertising measurement using optional cookies Voluntary consent provided through cookie settings Until consent is withdrawn, identifiers are deleted or the relevant cookie expires

§4. Recipients of personal data

  1. Personal data may be disclosed only to the extent required to perform a particular task:

    • providers of the Sky-Shop e-commerce platform, hosting, e-mail, information technology, security and technical-support services;
    • payment providers and banks, including Sky-Pay, PayU and PayPal, depending on the method selected by the Customer;
    • carriers and collection-point operators, including InPost and DHL;
    • providers of accounting, legal, debt-recovery, audit or insurance services where required;
    • manufacturers, distributors and service centres solely to the extent required to confirm availability, fulfil an order or handle a guarantee claim or complaint;
    • providers of analytics, advertising and external-content tools, including Google and Meta, solely to the extent resulting from the user’s settings and consent;
    • public authorities, courts and other authorised entities where disclosure is required by law.
  2. Processors acting on the Controller’s behalf operate under appropriate agreements or other legally required arrangements and may process personal data only within the scope of the tasks entrusted to them.

  3. The Controller does not sell users’ personal data.

§5. Transfers outside the European Economic Area

  1. Some providers of technology, payment, analytics, advertising or external-content services may process personal data outside the European Economic Area.

  2. In such cases, data is transferred only under a mechanism permitted by data-protection law, including a European Commission adequacy decision, standard contractual clauses or another appropriate basis provided for in Chapter V of the GDPR.

  3. Information about the safeguards used may be obtained by contacting the Controller.

§6. Rights of data subjects

  1. Subject to the conditions laid down in the GDPR, a data subject may request:

    • access to personal data and a copy of it;
    • rectification of inaccurate data and completion of incomplete data;
    • erasure of personal data;
    • restriction of processing;
    • data portability where processing is based on consent or a contract and is carried out by automated means;
    • the right to object to processing based on the Controller’s legitimate interests;
    • withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  2. The right to erasure is not absolute. The Controller may retain personal data where further processing is required to comply with a legal obligation, establish, pursue or defend legal claims, or on another basis permitted by law.

  3. Requests may be sent to info@aeonzegarki.com. The Controller may request additional information necessary to verify the identity of the person making the request.

  4. A data subject has the right to lodge a complaint with the President of the Polish Personal Data Protection Office.

§7. Whether providing data is voluntary

  1. Browsing the publicly available part of the Store generally does not require the user to provide identifying information, except for technical data and essential cookies processed during the connection.

  2. Providing information marked as required during the ordering process is necessary to conclude and perform the contract. Failure to provide it may prevent the order, payment or delivery from being completed.

  3. Creating an account is voluntary unless a particular Store function requires login. Consent to a newsletter, analytics cookies and marketing cookies is voluntary and is not a condition of making a purchase.

  4. The Customer should provide accurate, current and complete information. Incorrect or incomplete information may prevent fulfilment or delay delivery.

§8. Automated decision-making and profiling

  1. The Controller does not make decisions concerning users based solely on automated processing that produce legal effects or similarly significantly affect them.

  2. After consent to analytics or marketing cookies is given, tool providers may create profiles relating to a user’s activity, interests and the likely effectiveness of advertising. Such profiling is used for statistical analysis, campaign measurement, creation of audiences and advertising personalisation, but does not by itself result in the Store entering into or refusing a contract.

§9. Data security

  1. The Controller applies appropriate technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration, disclosure or destruction, taking account of the nature of the data, the scope of processing and the level of risk.

  2. Access is granted only to persons and entities that require it to perform their assigned tasks.

  3. No method of transmitting or storing information provides absolute security. The Controller responds to detected incidents in accordance with applicable law.

§10. Cookies and similar technologies

  1. Cookies are small files or pieces of information stored on or read from a user’s device while the Store is used. Similar technologies may include pixels, device identifiers, local storage and tags used for website operation, analytics or advertising.

  2. The Store may use the following categories:

    • Essential – required for website operation, shopping-cart functions, login, security, session handling, privacy-setting storage and functions expressly requested by the user. They are active without additional consent because the requested service could not be provided without them.
    • Preference or functional – remember selected settings that are not required for the Store’s basic operation. They are enabled after consent unless they are necessary for a function expressly requested by the user.
    • Analytics – help determine how the Store is used, measure traffic and identify problems. They may include Google Analytics. They are enabled only after consent.
    • Marketing – used for advertising measurement, creation of audiences and personalisation of advertising. They may include Meta tools, including Meta Pixel, and Google advertising tools. They are enabled only after consent.
    • External content – enable embedded content such as YouTube videos. The external provider may store its own identifiers after the material or relevant consent category is activated.
  3. On the first visit, the user may accept all optional cookies, reject them or manage individual categories. Refusal of optional cookies must not block basic access to the Store but may disable some features, statistics, personalised content or external materials.

  4. Consent may be changed or withdrawn at any time through the cookie settings available in the Store. Withdrawal does not affect the lawfulness of earlier processing.

  5. Cookies may be session cookies, deleted when the browser is closed, or persistent cookies, retained until a specified expiry date or earlier deletion. The current list of providers, purposes and durations should be displayed in the cookie-settings panel used by the Store.

  6. The user may also delete or block cookies through browser settings. Blocking essential cookies may prevent the shopping cart, login, payment or other basic functions from operating correctly.

§11. Server logs

  1. Use of the Store involves sending requests to the server. Technical information, including the IP address, date and time, requested resource, browser type and error information, may be recorded in logs.

  2. Logs are used to ensure Store operation and security, diagnose errors, prevent abuse, prepare aggregated technical statistics and establish, pursue or defend legal claims.

§12. Third-party services and websites

  1. The Store may contain links to or embedded content from external services, including Google, YouTube, Facebook, Instagram and X. After visiting such a service or activating its content, personal data is also processed under that provider’s rules.

  2. The Controller is not responsible for the content or privacy practices of independent third-party services. Users should review their current privacy policies.

§13. Changes to this Policy

  1. This Policy may be amended, in particular, following changes in law, the scope of the Store’s activities, providers or technologies used.

  2. The current version is published in the Store together with its effective date. Changes to the Policy do not restrict rights already acquired by data subjects.