Privacy Policy – Rules for Processing Personal Data on biossom.bio
Dear User,
Below, we provide information on how, for what purposes, and to what extent we process your personal data in connection with your use of the biossom.bio website.
WHO IS THE ADMINISTRATOR OF YOUR PERSONAL DATA? HOW CAN YOU CONTACT US?
The administrator of your personal data is ECO MINDSET sp. z o.o., headquartered at Podbiałowa 11/8, 61-680 Poznań.
If you wish to contact the data administrator, you can do so by writing to hi@biossom.bio.
FOR WHAT PURPOSE DO WE PROCESS YOUR PERSONAL DATA?
Your personal data as a user of the biossom.bio website is processed for the purpose of operating this website and ensuring its functionality, such as:
- creating a user account and subsequent login,
- placing an order,
- submitting inquiries via the contact form.
Your personal data may also be processed for marketing purposes of ECO MINDSET sp. z o.o., particularly to promote its products or services. As part of such marketing, the data administrator aims to present you with offers and promotions tailored to your interests. To this end, profiling activities may be carried out; however, these will not affect your rights or freedoms in any way.
If you give your consent, your personal data may also be processed for the purpose of sending marketing communications (e.g., offers, discount vouchers, current promotions) related to the biossom.bio store.
WHAT PERSONAL DATA DO WE PROCESS? HOW DO WE COLLECT IT?
We collect and process information about how you use the biossom.bio website, how you arrived at our site, your IP address, and the device you use to access our website, including its settings (e.g., browser, screen resolution) via cookies, if you agree to their use. More information about cookies can be found [here].
We also collect your personal data when you provide it to us during account creation. By sharing additional personal data, such as your home address, you enable us to fulfill your orders.
Your personal data is also obtained when you send a message to us via the contact form available on the biossom.bio website.
WHY (ON WHAT BASIS) DO WE PROCESS YOUR PERSONAL DATA?
The processing of your data is based on the legitimate interest of the data administrator (Article 6(1)(f) of the GDPR). This includes:
- ensuring a high-quality user experience and maintaining website functionality,
- managing the contact inbox, responding to inquiries, and providing positive customer interactions,
- promoting our product and service offerings as a legally justified interest (as explicitly stated in Recital 47 of the GDPR).
Personal data provided during account registration is processed to fulfill our electronic service agreement (Article 6(1)(b) of the GDPR).
Personal data provided during purchases is processed to fulfill our sales contract, including delivery and post-purchase support (warranty, complaints) (Article 6(1)(b) of the GDPR).
Additionally, if you have given explicit consent, we may send you marketing communications related to biossom.bio (Article 6(1)(a) of the GDPR).
We may also be required to process personal data to comply with legal obligations, such as tax regulations (Article 6(1)(c) of the GDPR).
HOW LONG DO WE STORE YOUR PERSONAL DATA?
- If you create a customer account, your data will be processed until you delete the account.
- Data related to purchases will be processed for the duration of the contract execution.
- If you send us an inquiry and are not a registered user, your data will be stored only as long as necessary to provide a response.
After these periods, we may still store your data if required by law (e.g., tax regulations) or until the statute of limitations for claims expires.
WHO DO WE DISCLOSE YOUR PERSONAL DATA TO?
Your data is disclosed to third parties only when necessary, specifically to:
- IT and technical service providers managing the biossom.bio website,
- courier companies delivering orders,
- law firms and accounting offices supporting our business operations,
- marketing agencies assisting us in offering personalized promotions and offers.
Whenever we share your data with external service providers, we ensure compliance with legal regulations. When service providers process your data on our behalf, they are obligated to implement security measures that comply with GDPR requirements.
WILL YOUR DATA BE TRANSFERRED OUTSIDE THE EUROPEAN ECONOMIC AREA (EEA)?
In operating the biossom.bio website, we use tools provided by companies outside the EEA, and some of our service providers may store your data outside this territory (e.g., Google).
If personal data is transferred outside the EEA, it will only occur in accordance with data protection laws, ensuring:
- The destination country is deemed to provide adequate protection (as per an EU Commission decision), OR
- In the absence of such a decision, appropriate safeguards are implemented, such as Standard Contractual Clauses (SCCs) with additional security measures, ensuring your rights and legal protections.
WHAT ARE YOUR RIGHTS?
Under data protection laws, you have several rights, which you can exercise at any time, provided your identity can be verified. These include:
- The right to access your personal data,
- The right to correct (rectify) data,
- The right to restrict processing,
- The right to request data deletion,
- The right to transfer your data to another data administrator.
To exercise these rights, contact us at hi@biossom.bio.
If you believe we have violated data protection rules, you have the right to file a complaint with the supervisory authority (President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw).
Additionally, in certain cases, you have the right to object to the processing of your data, particularly for marketing purposes. If you file an objection, we will no longer process your data for that specific purpose but may continue processing it for other legitimate needs.
To submit an objection, please contact us at hi@biossom.bio.