Privacy Policy
1. BASIC INFORMATION
1.1.
This document sets out the rules for the processing of personal data of users of the services offered by Planet Fun SRL, having its registered office at 15 Șipotul Fântânilor Street, Floor S, Room 2, 010156 Bucharest, Sector 1, Romania, registered under number J40/12345/2014, CUI: RO32833467, EU VAT: PL526378787 (hereinafter the “Controller”), by means of the websites www.mindblower.pl, www.mindblowershop.de, and www.mindblowershop.com (hereinafter the “Services”).
1.2.
In processing users’ personal data, the Controller complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”), as well as with the applicable Romanian legislation on data protection and other related legal acts.
1.3.
“Personal data” within the meaning of the GDPR means any information relating to an identified or identifiable natural person — in particular by means of a name, identification number, location data, an online identifier or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
A “data subject” is any natural person whose personal data are processed — this includes any user of the Controller’s Services, including you.
The Controller within the meaning of the GDPR is Planet Fun SRL, which determines the purposes and means of the processing of personal data and processes them on its own behalf.
1.4.
This Privacy Policy has been in force since 25 May 2018 and constitutes the Controller’s fulfilment of the information obligation under Article 13 of the GDPR.
2. LEGAL BASIS AND PURPOSE OF PERSONAL DATA PROCESSING
2.1.
By actively confirming your acceptance of the terms of use of the website (by checking the appropriate box) and submitting an order or other service request you:
a) consent to the processing of your personal data for the purposes set out in this document, in accordance with applicable law;
b) confirm that the personal data you provide are correct and up to date.
2.2.
I. Performance of a contract or actions prior to entering into a contract
The purpose of processing personal data is to supply the goods or services offered by the Controller and to enter into and perform the contract of sale, which constitutes the legal basis for using the ordered service.
The Controller’s services include the online shop at the websites www.mindblower.pl, www.mindblowershop.de, www.mindblowershop.com, through which users make purchases.
2.3.
The Controller recommends carefully reading the terms and conditions available on the websites www.mindblower.pl, www.mindblowershop.de, www.mindblowershop.com, in particular the document “Terms & Conditions”.
2.4.
Providing and processing personal data is necessary in order to dispatch the ordered goods or provide the services, as well as to enter into and perform the contract which constitutes the legal basis for providing the services.
The Controller has the right to process personal data for this purpose for a period of up to 10 years after the conclusion of the last contract.
2.5.
Purposes directly related to the use of the Services include sending short email notifications regarding delivery, product availability, invoicing or other important information related to the order.
These notifications may be sent to the email address provided by the user. The subscription to these messages may be managed in the customer account on the websites www.mindblower.pl, www.mindblowershop.de, www.mindblowershop.com.
2.6.
II. Legitimate interest
The Controller may process personal data for analytical and statistical purposes related to the use of the Services, which allows the improvement and optimisation of the websites and the quality of customer service.
2.7.
Personal data may also be processed for the purposes of direct marketing, including profiling to a limited extent, which constitutes the Controller’s legitimate interest under recital 47 of the GDPR.
This means the Controller may send marketing communications containing commercial content for up to three years from the last order, unless you unsubscribe earlier. You may unsubscribe at any time (for example by sending an email to kontakt@mindblower.pl or by clicking the unsubscribe link in the marketing communication).
2.8.
Data processing may also be necessary for the Controller’s legitimate interests, including:
a) investigating and defending claims,
b) preventing abuse and fraud,
c) cooperating with law enforcement bodies,
d) ensuring IT and data security,
e) other legitimate interests compatible with the GDPR and applicable law.
2.9.
III. Compliance with legal obligations
The Controller may also process personal data in order to fulfil obligations under law (e.g., accounting, tax, consumer protection).
In such cases, data may be retained for a period of 10 years from the conclusion of the last contract.
2.10.
IV. Consent to processing personal data
By giving consent to the processing of personal data, the user also agrees to the establishment of a customer account and effective marketing communications, including profiling, in connection with use of the websites www.mindblower.pl, www.mindblowershop.de, www.mindblowershop.com.
The Controller may process data for other purposes only with your explicit consent or if the processing is compatible with the original purpose of collection.
3. SCOPE OF PERSONAL DATA PROCESSING
3.1.
The Controller processes personal data exclusively to the extent necessary for the purposes set out in this document, including:
-
email address,
-
first name and last name,
-
postal address (street, number, city, postal code, country),
-
telephone number (if provided),
-
history of orders and communications,
-
login data (if applicable),
-
IP address,
-
cookie data,
-
browsing history.
4. COOKIES
The Controller uses cookies on the websites www.mindblower.pl, www.mindblowershop.de, www.mindblowershop.com.
By visiting the websites you give consent to their use.
Cookies are small text files stored on your device that enable the website to recognise the browser and improve the user experience. They may store language preferences, browsing history or the contents of the shopping cart.
You may disable or delete cookies in your browser settings. However, disabling cookies may affect some functionalities of the websites.
You may object to the processing of cookies by contacting kontakt@mindblower.pl.
5. ACCESS TO DATA
5.1.
Personal data are processed mainly by Planet Fun SRL and authorised personnel. All persons who have access to the data are obliged to maintain confidentiality.
5.2.
The Controller may engage external entities (processors) to process data for ancillary services, such as customer service, hosting, marketing, analytics or logistics.
Processors used by Planet Fun SRL include, among others:
-
Google Ireland Ltd. – analytical and marketing tools (Google Ads, Google Analytics),
-
Meta Platforms, Inc. – marketing tools (Facebook Ads, Instagram Ads),
-
Shopify Inc. – e-commerce platform,
-
DPD and other courier companies – delivery of goods,
-
Email marketing and automation service providers – sending newsletters.
Each processor processes personal data only to the extent necessary and on the basis of a written contract ensuring GDPR compliance.
6. RIGHTS OF DATA SUBJECTS
6.1.
You have the following rights under the GDPR and applicable law:
a) the right of access to your data (Art. 15 GDPR),
b) the right to rectification of data (Art. 16 GDPR),
c) the right to erasure of data (“right to be forgotten”) (Art. 17 GDPR),
d) the right to restriction of processing (Art. 18 GDPR),
e) the right to data portability (Art. 20 GDPR),
f) the right to object to processing (Art. 21 GDPR),
g) the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP),
h) the right to withdraw consent at any time,
i) the obligation to provide data – necessary for the conclusion of a contract; the lack of data will prevent its fulfilment.
6.2.
You have the right to object to:
a) processing based on legitimate interest (including profiling),
b) processing for direct marketing purposes.
6.3.
Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. If no other legal basis applies, data will be deleted or anonymised without undue delay.
7. EXERCISING RIGHTS AND CONTACT DETAILS
7.1.
To exercise your rights or to obtain information about the processing of personal data you may contact the Controller or the Data Protection Officer at the following details:
Controller:
Planet Fun SRL
15 Șipotul Fântânilor Street, Floor S, Room 2, 010156 Bucharest, Sector 1, Romania
Email: kontakt@mindblower.pl
Data Protection Officer: Angela Stan
7.2.
If your request is obviously unfounded, excessive or repetitive, the Controller may impose a reasonable administrative fee or refuse to act.
7.3.
Before responding, the Controller may verify your identity to prevent unauthorised access to data.
7.4.
If you are not satisfied with the processing of your data, you may contact the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), based at 28–30 G-ral Gheorghe Magheru Street, Bucharest, Romania, or file a complaint via https://www.dataprotection.ro.