2. The owner of the Website and at the same time the data administrator is Heads Yachting d.o.o. with its registered office in Split (21,000), Put Trścenice 6, entered into the Register of Entrepreneurs of the National Court Register kept by the Commercial Court for the city of Split, under the business entity identification number 5222729, with share capital of 20,000 HRK, VAT ID 31602332600, hereinafter referred to as HY.
3. Personal data collected by HY via the Website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repeal Directive 95/46 / EC (General Data Protection Regulation), also called GDPR.
4. HY makes special efforts to respect the privacy of Users visiting the Website.
§ 1 The type of data processed, purposes and legal basis
1. HY collects information about natural persons conducting business or professional activity on their own behalf, as well as natural persons representing legal persons or organizational units that are not legal persons, to whom the Act grants legal capacity, hereinafter collectively referred to as Users.
2. Users' personal data is collected in the case of:
3. When registering an account on the Website, the User provides:
4. In the case of Entrepreneurs, the above range of data is further extended by:
5. When registering an account on the Website, the User sets an individual password to access his account. The user may change the password at a later time, on the terms described in §5.
6. When placing an order on the Website, the User provides the following data:
7. In the case of Entrepreneurs, the above data range is further extended by:
8. When using the Newsletter service, the User provides only his e-mail address, optionally a contact telephone number.
9. When using the contact form service, the User provides the following data:
b) name and surname;
c) telephone number.
10. When using the Website, additional information may be downloaded, in particular: the IP address assigned to the User's computer or the external IP address of the Internet provider, domain name, type of browser, access time, type of operating system.
11. Navigation data may also be collected from Users, including information about links and links in which they decide to click or other activities undertaken on the Website. Legal basis - a legitimate interest (Article 6 paragraph 1 letter f of the GDPR), consisting in facilitating the use of electronic services and improving the functionality of these services.
12. In order to determine, assert and enforce claims, certain personal data provided by the User may be processed as part of using the Website's functionalities, such as: name, surname, data on the use of services, if the claims result from the manner in which the User uses the services , other data necessary to prove the existence of the claim, including the extent of the damage suffered. Legal basis - a legitimate interest (art.6 par.1 lit.f RODO), consisting in the determination, investigation and enforcement of claims as well as defense against claims in proceedings before courts and other state authorities.
13. Providing personal data to HY is voluntary, in connection with concluded sales contracts or providing services via the Website, with the proviso that failure to provide the data specified in the forms in the Registration process prevents Registration and creating a User Account, and in the case of placing an order without registering a User Account will prevent the submission and implementation of the User's order.
§ 2 Who is the data shared or entrusted to and how long is it stored ?
1. The User's personal data is transferred to service providers that HY uses when running the Website. Service providers to whom personal data are transferred, depending on contractual arrangements and circumstances, or are subject to HY's instructions as to the purposes and methods of processing such data (processors) or independently determine the purposes and methods of their processing (administrators).
2. Location. Service providers are based in Poland and other countries of the European Economic Area (EEA).
3. Users' personal data is stored:
4. Navigation data can be used to provide Users with better service, statistical data analysis and adapt the Website to Users' preferences, as well as to administer the Website.
5. In the event that the User subscribes to the newsletter (Newsletter) to his email address HY will send electronic messages containing commercial information about promotions and new offers available on the Website.
6. In the event of a request, HY discloses personal data to authorized state authorities, in particular organizational units of the Prosecutor's Office, the Police, the President of the Office for Personal Data Protection, the President of the Office for Competition and Consumer Protection or the President of the Office of Electronic Communications.
§ 3 Cookies mechanism, IP address
1. The website uses small files called cookies. They are saved by HY on the terminal equipment of the person visiting the Website, if the web browser allows it. A cookie usually contains the name of the domain from which it comes, its "expiration time" and an individual, randomly selected number identifying this file. Information collected using this type of files helps tailoring products offered by HY to the individual preferences and real needs of visitors to the Website. They also give the opportunity to compile general statistics of visits to the products presented on the Website.
2. HY uses two types of cookies:
3. HY uses its own cookies to:
4. HY uses external cookies to:
4. The cookies mechanism is safe for computers of Website Users. In particular, it is not possible for viruses or other unwanted software or malware to enter Users' computers in this way. However, in their browsers, Users have the option of limiting or disabling cookies' access to computers. If you use this option, you will be able to use the Website, in addition to functions that, by their nature, require cookies.
7. HY may collect Users' IP addresses. The IP address is the number assigned to the computer of the person visiting the Website by the internet service provider. The IP number allows access to the Internet. In most cases, it is assigned to your computer dynamically, i.e. it changes every time you connect to the Internet. The IP address is used by HY in diagnosing technical problems with the server, creating statistical analyzes (e.g. determining from which regions we record the most visits), as information useful in administering and improving the Website, as well as for security purposes and possible identification incriminating server, unwanted automatic programs for viewing the content of the Website.
8. The Website contains links and references to other websites. HY is not responsible for the privacy policies applicable to them.
§ 4 Rights of data subjects
1.The right to withdraw consent - legal basis: art. 7 item 3 GDPR.
2. The right to object to data processing - legal basis: art. 21 GDPR.
3. The right to delete data ("the right to be forgotten") - legal basis: art. 17 GDPR.
4. The right to limit data processing - legal basis: art. 18 GDPR.
5. Right of access to data - legal basis: art. 15 GDPR.
6. The right to rectify data - legal basis: art. 16 GDPR.
7. Right to data portability - legal basis: art. 20 GDPR.
8. In the event of the User having the right resulting from the above rights, HY fulfills the request or refuses to comply with it immediately, but not later than within a month after receiving it. However, if - due to the complex nature of the request or the number of requests - HY will not be able to fulfill the request within a month, it will meet them within the next two months informing the User within one month of receipt of the request - about the intended extension of the deadline and its reasons.
9. The User may submit to the Administrator complaints, queries and requests regarding the processing of his personal data and the exercise of his rights.
11. The User has the right to lodge a complaint to the President of the Office for Personal Data Protection regarding the violation of his rights to the protection of personal data or other rights granted under the GDPR.
§ 5 Security management – password
1. HY provides Users with a secure and encrypted connection when sending personal data and when logging into the User Account on the Website. HY uses an SSL certificate issued by one of the world's leading companies in the field of security and encryption of data transmitted via the Internet.
2. In the event that a User who has an account on the Website has lost the access password in any way, the Website shall generate a new password. HY does not send password reminders. The password is stored in an encrypted form in a way that makes it impossible to read. In order to generate a new password, enter the e-mail address in the form available under the "Forgot your password" link provided at the account login form on the Website. The User will receive an electronic message containing a redirection to the dedicated form provided on the Website to the e-mail address provided during registration or saved in the last change of account profile, where the User will be able to set a new password.
3. HY never sends any correspondence, including electronic correspondence, asking for login details, and in particular the password to access the User's account.
3. Date of last modification: 25.03.2020.