The administrator of http://nudermasupply.com is Medicle MD Ltd, 27 Old Gloucester Street, London, WC1N 3AX. You can contact us by email at contact@nudermasupply.com.
I. For what purpose do we obtain data from you and how we process it?
1. Newsletter. By subscribing to the newsletter you receive news, valuable content and industry information from us. When you sign up, you provide us with your name and email address in the form. Providing this data is voluntary, but necessary to receive valuable content from us through the newsletter. The legal basis for processing this data is your consent (Article 6(1)(a) of the DPA) given when you sign up. Additional your data, together with the IP number from which you signed up for the newsletter, will be stored on the server of the mailing service provider with whom the Administrator has signed a data processing entrustment agreement. Your data is processed for the purpose of sending you the ordered content and will be stored in the database for the duration of the newsletter service, unless you opt out earlier, which will result in the deletion of your data from the database.
2. Contact form. You have the opportunity to contact us by submitting an inquiry via the contact form located on our website. In this case, you provide us with your name, e-mail address and other information in the body of the message, which may contain personal data. Providing this data is voluntary, but necessary to contact us via the form. We process the data you provide for the purposes of:
- answering the question you have asked, i.e. taking action at the request of the data subject (Article 6(1)(b) of the RODO).
- archiving which is our legitimate interest of the Administrator (Article 6(1)(f) RODO)
- possible claim or defense against claims which is our legitimate interest of the Administrator (Article 6(1)(f) RODO) to protect our rights;
You have the right to access the history of your correspondence (if it was subject to archiving) and you have the right to request the deletion of your correspondence, unless the archiving is justified by the Administrator’s overriding interests, such as defense against potential claims on your part.
3. Registering an account on the site. If you choose to register on our site by creating a user account you will be asked to provide data necessary for its creation and operation. Provision of mandatory data such as name, address, e-mail, telephone number is required to create and operate an account. If you do not provide them, we will not be able to set up your user account.
We process the data you provide in order to:
- to maintain and operate your user account on the site which is necessary for the performance of the contract (Article 6(1)(b) RODO);
- for statistical and analytical purposes, which is our legitimate interest of the Administrator (Article 6(1)(f) RODO), which consists in conducting analyses of behavior and activity of Users as well as their preferences aimed at improving the quality and adequacy of applied functionalities and provided services;
- the possible assertion of claims or defense against them, which is our legitimate interest of the Administrator (Article 6(1)(f) RODO), consisting of protecting our rights;
- marketing of products and services, which is our legitimate interest (Article 6(1)(f) RODO), which is to present an offer to our customers;
Personal data will be processed until the purpose for which it was collected ceases to exist, or in the case of data whose processing requires your consent until it is withdrawn.
4. Order form. When making a purchase of a product or service on our site, you are required to complete an order form and provide in it the data necessary to finalize the sales process. You will be asked to provide: your name, shipping address, email address and phone number. If, in addition, you ask for an invoice you will be required to provide data that will enable the invoice to be issued. Data that are mandatory for placing an order on our site have been marked with an asterisk. Providing this data is voluntary, but necessary to make an order. We process the data you provide in order to:
- to complete your order which is necessary for the performance of the contract (Article 6(1)(b) of the RODO);
- for statistical and analytical purposes, which is our legitimate interest of the Administrator (Article 6(1)(f) RODO), which consists in conducting analyses of Users’ behavior and activity as well as their preferences aimed at improving the quality and relevance of the functionalities used and services provided;
- possible assertion of claims or defense against them, which is our legitimate interest of the Administrator (Article 6(1)(f) RODO), which consists in protecting our rights;
- marketing of the Administrator what is our legitimate interest (Article 6(1)(f) RODO), which consists in presenting our offer to customers;
Personal data will be processed until the purpose for which it was collected ceases to exist, or in the case of data whose processing requires your consent until it is withdrawn.
5. Withdrawal form. We have provided a withdrawal form on our website, which will streamline the process related to the return of a product or service purchased on our site related to the withdrawal from the sales contract. Withdrawing from the contract, you are required to fill out the form and provide in it the data necessary to process the return and finalize it.
You will be asked to provide: your name, company details (if applicable), home address, e-mail address and phone number, account number. Providing the data is voluntary, but necessary to complete the withdrawal from the sales contract and make the return.
We process the data you provide in order to:
- to exercise the right of withdrawal from the contract which is necessary for the execution of the contract (Article 6(1)(b) RODO);
- for statistical and analytical purposes, which is our legitimate interest of the Administrator (Article 6(1)(f) RODO), which consists in conducting analyses of Users’ behavior and activity as well as their preferences aimed at improving the quality and adequacy of the functionalities used and services provided;
- possible claim or defense against claims, which is our legitimate interest of the Administrator (Article 6.1.f RODO), consisting of protecting our rights;
Personal data will be processed until the purpose for which it was collected ceases to exist or, in the case of data whose processing requires your consent, until it is withdrawn.
6. Complaint form. We have provided a complaint form on our website, which will streamline the process related to reporting a defective product or service purchased from our site. When making a complaint, you are required to fill out the form and provide in it the data necessary to process the complaint.
You will be asked to provide: name and surname, company details (if applicable), residential address, e-mail address and telephone number, account number. Providing the data is voluntary, but necessary to process the complaint.
We process the data you provide in order to:
- To process the complaint which is necessary for the performance of the contract (Article 6(1)(b) of the RODO);
- For statistical and analytical purposes, which is our legitimate interest of the Administrator (Article 6(1)(f) RODO), which consists in conducting analyses of Users’ behavior and activity as well as their preferences aimed at improving the quality and adequacy of the functionalities used and services provided;
- possible claim or defense against claims, which is our legitimate interest of the Administrator (Article 6.1.f RODO), consisting of protecting our rights;
Personal data will be processed until the purpose for which it was collected ceases to exist or, in the case of data whose processing requires your consent, until it is withdrawn.
7. Comments. In order to post a comment on an entry on our site, you must fill out a form in which you provide us with your name and email address. Providing data is voluntary, but necessary to add a comment. The legal basis for processing this data is the performance of a contract or to take action at the request of the data subject (Article 6(1)(b) of the DPA).
Your data is processed for the purpose of publishing a comment and will be processed for the period of operation of comments on the site, unless you request us to delete it beforehand, which will remove your data from the database.
8. Payment Gateway. When you purchase a product or service, you make a payment through an online payment system provider in the payment gateway. This is a functioning application that is linked to authorization centers, banks and other financial institutions, and which allows you to transfer data to the information systems of these institutions in order to complete online payment transactions. When making a payment, you will be asked to provide the data necessary to initiate the payment process. Providing this data is voluntary, but necessary to make payment for a product or service. The legal basis for processing this data is the performance of a contract or to take action at the request of the data subject (Article 6(1)(b) of the DPA). Your data is stored on the server of the service provider until memento, when it is no longer needed to achieve the purpose for which it was collected. The Administrator has entered into an entrustment agreement with the service provider for the processing of personal data.
II. Your rights as a data subject
In connection with our processing of your personal data, you have the following rights:
- the right to request access to your personal data, rectification, erasure or restriction of processing,
- the right to object to the processing,
- the right to data portability,
- the right to withdraw consent to the processing of personal data for a specific purpose, if you have previously given such consent,
- the right to lodge a complaint with a supervisory authority in connection with our processing of your personal data.
III. Recipients of your personal data
In specific situations where applicable law requires us to share the collected data with state authorities, we will be required to share such data. In addition, the Administrator will share your personal data with accounting service providers, postal service providers, courier service providers, legal service providers, providers of IT services and software to support website management, providers of email and website hosting services, banks and other financial institutions for payment processing, owners of a social networking site (e.g. facebook). If you want to know the list of entities to which we share or entrust your personal data, please contact us.
IV. Do we transfer your data to countries outside the European Economic Area?
Your personal data may be transferred outside of the European Economic Area especially if the providers of the services used on the site are based or have servers outside of the OEG. If such a transfer takes place it will always be based on the appropriate legal safeguards, which include the standard contractual clauses for the transfer of personal data to processors located in third countries approved by the European Commission.
V. Final provisions
The Administrator reserves the right to change the privacy policy if required by applicable law, the technological conditions of the website’s operation change, or the change introduces a standard higher than the minimum required by law.