Rikkinail Privacy Policy
1. General information
This privacy policy describes how the rikkinail.com online store processes users’ personal data. It explains the purposes and legal bases of processing, retention rules, the use of cookies and users’ rights.
We aim to process personal data transparently and protect it in accordance with data protection legislation, including the General Data Protection Regulation (GDPR).
Document version: 1.0, dated 10 June 2023.
2. Data controller and contact details
The controller of your personal data is:
Firma Taras Tokaryk Rikki nail shop
ul. Rymarska 45/11, 53-206
Warsaw, Poland
Contact the data protection officer at [email protected].
3. Scope of processing and data security
We process data necessary to operate the website, provide content and deliver services, including registration, login and order processing. Processing relies on consent or another applicable legal basis.
We use technical and organisational safeguards against loss and unauthorised access. Employees handling personal data are subject to confidentiality obligations. Browser communications are encrypted using SSL, and we regularly review and update our safeguards.
Companies processing data on our behalf must follow appropriate data protection rules and our instructions.
4. Purposes and legal bases
We use data to enter into and perform contracts, process orders, provide customer support and online services, send newsletters and conduct marketing activities such as prize draws.
Processing may rely on:
- Article 6(1)(a) GDPR: consent for a specific purpose.
- Article 6(1)(b) GDPR: performance of a contract or steps before entering into one, including product and service enquiries.
- Article 6(1)(c) GDPR: legal obligations, including tax obligations.
- Article 6(1)(d) GDPR: protection of your or another person’s vital interests.
- Article 6(1)(f) GDPR: legitimate interests, including working with service providers, statistical analysis, security, login monitoring and website optimisation.
5. Data retention
We retain data for as long as necessary for its purpose or as required by applicable rules. When the purpose ends, we erase the data or restrict its processing.
Restricted data is erased when legal, contractual or retention requirements no longer prevent deletion. The original policy also provides for continued retention in special circumstances involving legitimate interests and disproportionate effort required for deletion.
6. Technical data and server logs
During a visit, the website automatically collects technical data under Article 6(1)(f) GDPR:
- the date, time and frequency of access;
- the source of the visit;
- the amount of data transferred;
- browser type and version and operating system;
- internet service provider and IP address.
This information supports website operation, display, optimisation and security. Logs are retained for 7 days.
Data may also support marketing, market research and service personalisation through pseudonymous user profiles, unless you have objected or withdrawn consent for that use.
7. Cookies, analytics and social media
We use cookies, analytics services and social media plugins to support website functions, remember preferences and make the website easier to use. The source document identifies Article 6(1)(f) GDPR as the legal basis.
You can block or delete cookies through your browser. Some services also provide an opt-out cookie or link. Deleting all cookies also removes stored opt-out cookies.
Functional cookies are retained for up to 2 years. They may support:
- shopping baskets, wish lists and checkout form data;
- language, location and search preferences;
- display settings for your device, screen resolution and browser;
- recording misuse, including unsuccessful registration attempts;
- faster loading and remembering login details.
Blocking functional cookies may limit some website features.
For cookies, analytics and social media, the source document names:
- Meta LLC — cookie policy.
- Mega LLC — no privacy policy address is provided in the source document.
- Alphabet Inc — the source document links to this cookie information page.
8. Newsletters and marketing communications
We send product, service and special offer information with consent or where permitted by law. Consent-based processing relies on Articles 6(1)(a) and 7 GDPR.
When you subscribe to the free newsletter, we collect the form data, including at least your email address. We also retain your email address when you sign up for product information through the store.
The source policy provides for sending information about our own similar products after a purchase without separate consent, and for sending offers by post.
To personalise messages and compile statistics, we record email opens, clicks, dates and times, and delivery failures. This information may be linked to your user profile; the stated basis is Article 6(1)(f) GDPR.
You can unsubscribe through the link in a message and the confirmation page, or by contacting [email protected]. You can also write to the controller’s postal address.
Unsubscribing from marketing does not stop messages necessary for contracts or account administration, such as registration, order and payment confirmations.
9. Contact, customer accounts and guest orders
We retain information supplied by phone, email or a contact form to respond and document the communication under Article 6(1)(f) GDPR.
Account registration and contract administration rely on Article 6(1)(b) GDPR. We may need your name, delivery address, billing address, email and selected payment method. We check address completeness and accuracy and maintain a customer database containing necessary information.
Guest checkout does not require an account, but details must be entered again for future orders. We process the data to perform the contract and erase it after fulfilment unless you activate an account within 14 days of placing the order.
Data subject to legal or contractual retention requirements is not erased; its processing is restricted.
10. Security and legal claims
Under Articles 6(1)(c) and 6(1)(f) GDPR, personal and technical data may be used to prevent misuse, investigate attacks, comply with lawful official requests and establish, exercise or defend legal claims.
11. Data recipients and partners
Under Article 6(1)(b) GDPR, suppliers of ordered products may receive registration and additional account data necessary to enter into and perform the contract, particularly email, delivery and billing addresses. The relevant supplier is identified on the product page and in the legal notice and may apply its own privacy policy.
We also work with IT, hosting, payment, transport, equipment installation and newsletter providers. We share only information needed for their tasks. Processors acting on our behalf follow our instructions; we agree safeguards with them and monitor their effectiveness.
For heavy or oversized shipments, the document names DTS Transport Sp. z o.o., Rohlig Suus Logistics S.A. and DPD Polska Sp. z o.o. Contact details, including email, may be shared to arrange delivery.
Logistics companies, postal operators, payment providers and financing banks may be independently responsible for processing the data they receive. Card fraud checks are carried out by the payment provider, with eCard S.A. and PayPal Polska Sp. z o.o. given as examples.
We do not collect or store card numbers or bank account details used for payments; these are sent directly to the payment provider. The document provides for storing a card pseudonumber in the customer account for subsequent purchases solely through our store. It is not the actual card number.
12. Your rights
You may exercise your rights without charge by contacting [email protected] or writing to the controller. Your provider’s normal communication charges may apply.
We may request information to verify your identity. If verification is not possible, we may decline to disclose information.
- Access: obtain information about your stored personal data.
- Rectification: correct or complete data without undue delay.
- Restriction: request restricted processing in circumstances including disputed accuracy, unlawful processing, retention for claims or an objection.
- Erasure: request deletion, subject to exceptions including legal duties, freedom of expression and information, public interest and legal claims.
- Notification: recipients are informed of rectification, erasure or restriction unless impossible or disproportionately difficult.
- Portability: receive supplied data in a structured, commonly used, machine-readable format and, where technically possible, have it transferred to another controller.
- Objection: object to legitimate-interest processing under Article 21 GDPR.
- Withdrawal of consent: withdraw consent for the future without affecting the lawfulness of previous processing. Technical implementation may take time.
- Automated decisions: not be subject to solely automated decisions, including profiling, that produce legal or similarly significant effects.
- Complaint: lodge a complaint with the competent supervisory authority.
Deletion may prevent access to related services, including repeat downloads. Back up any necessary data beforehand. Data that must be retained remains subject to restricted processing.
13. External websites and policy changes
Our website may link to third-party websites. We are not responsible for their data safeguards and recommend reading their privacy policies.
This policy may change in response to changes in legislation, products or services.
