This Privacy Policy sets out the rules for storing and accessing data on the Devices of Users who use the Service for the purpose of the electronic services provided by the Controller, and the rules for collecting and processing Users' personal data, which they provided personally and voluntarily through the tools available in the Service.
This Privacy Policy is an integral part of the Terms of Service, which set out the rules, rights and obligations of Users of the Service.
Service - the "drinkify.pl" website operating at https://drinkify.pl
External service - websites of partners, service providers or service recipients cooperating with the Controller
Service / Data Controller - the Controller of the Service and the Data Controller (hereinafter the Controller) is a natural person providing electronic services through the Service
User - a natural person for whom the Controller provides electronic services through the Service.
Device - an electronic device with software through which the User accesses the Service
Cookies - text data collected in the form of files placed on the User's Device
GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
Personal data - any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
Processing - any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
Restriction of processing - the marking of stored personal data with the aim of limiting their processing in the future
Profiling - any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
Consent - consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them
Personal data breach - a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed
Pseudonymisation - the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person
Anonymisation - the irreversible processing of data that destroys / overwrites "personal data", making it impossible to identify or link a given record to a specific user or natural person.
Pursuant to Art. 37 GDPR, the Controller has not appointed a Data Protection Officer.
In matters concerning the processing of data, including personal data, please contact the Controller directly.
Internal cookies - files placed on and read from the User's Device by the Service's ICT system
External cookies - files placed on and read from the User's Device by the ICT systems of External services. Scripts of External services that may place cookies on Users' Devices have been knowingly placed in the Service through scripts and services made available and installed in the Service
Session cookies - files placed on and read from the User's Device by the Service during a single session of that Device. When the session ends, the files are deleted from the User's Device.
Persistent cookies - files placed on and read from the User's Device by the Service until they are deleted manually. The files are not deleted automatically when the Device session ends, unless the User's Device is configured to delete cookies at the end of the Device session.
Cookie storage and reading mechanisms - The mechanisms for storing, reading and exchanging data between the Cookies saved on the User's Device and the Service are implemented through the built-in mechanisms of web browsers and do not allow other data to be collected from the User's Device or data of other websites the User has visited, including personal data or confidential information. Transferring viruses, trojans or other worms to the User's Device is also practically impossible.
Internal cookies - the cookies used by the Controller are safe for Users' Devices and do not contain scripts, content or information that could threaten the security of personal data or the security of the Device the User uses.
External cookies - the Controller takes all possible steps to verify and select the Service's partners with Users' security in mind. The Controller selects well-known, large partners with global public trust. However, the Controller does not have full control over the content of cookies originating from external partners. To the extent permitted by law, the Controller is not responsible for the security of cookies, their content and their licence-compliant use by Scripts installed in the Service that originate from External services. The list of partners is provided further in this Privacy Policy.
Cookie control
The User may at any time change the settings for saving, deleting and accessing the data of saved Cookies by any website on their own
Information on how to disable cookies in the most popular desktop browsers is available at: how to disable cookies or from one of the listed providers:
The User may at any time delete all Cookies saved so far using the tools of the User's Device through which the User uses the Service.
Risks on the User's side - The Controller applies all possible technical measures to ensure the security of the data placed in Cookies. Note, however, that ensuring the security of this data depends on both parties, including the User's conduct. The Controller is not responsible for the interception of this data, impersonation of the User's session or its deletion as a result of the User's conscious or unconscious actions, viruses, trojans or other spyware with which the User's Device is or was infected. To protect themselves against these risks, Users should follow the principles of safe internet use.
Storage of personal data - The Controller declares that every effort is made to ensure that the personal data voluntarily entered by Users is secure, that access to it is restricted and carried out in accordance with its intended use and the purposes of processing. The Controller also declares that every effort is made to protect the data held against loss through appropriate physical and organisational safeguards.
Storage of passwords - The Controller declares that passwords are stored in encrypted form, using the latest standards and guidelines in this area. Decrypting account passwords provided in the Service is practically impossible.
Personal data voluntarily provided by Users is processed for one of the following purposes:
Data about Users collected anonymously and automatically is processed for one of the following purposes:
In the Service the Controller uses JavaScript scripts and web components of partners that may place their own cookies on the User's Device. Remember that in your browser settings you can decide for yourself which cookies may be used by individual websites. Below is a list of partners or their services implemented in the Service that may place cookies:
Services provided by third parties are beyond the Controller's control. These entities may at any time change their terms of service, privacy policies, purpose of data processing and the way they use cookies.
The Service collects data about Users. Some of the data is collected automatically and anonymously, and some is personal data provided voluntarily by Users when signing up for individual services offered by the Service.
Anonymous data collected automatically:
Data collected during registration:
Data collected when subscribing to the Newsletter
Some data (without identifying data) may be stored in cookies. Some data (without identifying data) may be transferred to the statistics service provider.
As a rule, the only recipient of personal data provided by Users is the Controller. Data collected as part of the services provided is not transferred or sold to third parties.
Access to the data (usually under a data processing agreement) may be held by entities responsible for maintaining the infrastructure and services necessary to run the Service, i.e.:
Entrusting the processing of personal data - Hosting, VPS or Dedicated Server services
To run the Service, the Controller uses the services of an external hosting, VPS or dedicated server provider - OVH sp. z o.o.. All data collected and processed in the Service is stored and processed in the provider's infrastructure located outside the European Union. Access to the data is possible as a result of maintenance work carried out by the provider's staff. Access to this data is governed by the agreement between the Controller and the Provider.
Data processing for online payments
When an online payment is made, all payment data is provided by the User directly to the entity processing the payment - Stripe. Selected data necessary to complete the transaction is then passed on by that entity to the Controller. The transfer of data is governed by the agreement between the Controller and the Provider.
Personal data voluntarily provided by Users:
Anonymous data (without personal data) collected automatically:
The Service collects and processes Users' data on the basis of:
Personal data voluntarily provided by Users:
As a rule, the indicated personal data is stored only for the period during which the Controller provides the Service. It is deleted or anonymised within 30 days of the end of service provision (e.g. deletion of a registered user account, unsubscribing from the Newsletter list, etc.)
An exception is a situation that requires securing the legally justified purposes of further processing of this data by the Controller. In such a situation the Controller will retain the indicated data, from the time the User requests its deletion, for no longer than 3 years in the event of a breach or suspected breach of the Service's terms by the User
Anonymous data (without personal data) collected automatically:
Anonymous statistical data that does not constitute personal data is stored by the Controller for the purpose of keeping Service statistics for an indefinite period
Users have the following rights:
Right of access to personal data Users have the right to obtain access to their personal data, exercised upon a request submitted to the Controller
Right to rectification of personal data Users have the right to request that the Controller promptly rectify inaccurate personal data and/or complete incomplete personal data, exercised upon a request submitted to the Controller
Right to erasure of personal data Users have the right to request that the Controller promptly erase their personal data, exercised upon a request submitted to the Controller. For user accounts, erasure consists of anonymising the data that makes it possible to identify the User. The Controller reserves the right to suspend the execution of an erasure request in order to protect the Controller's legitimate interest (e.g. when the User has breached the Terms or the data was obtained through correspondence). For the Newsletter service, the User can delete their personal data on their own using the link included in every email sent.
Right to restriction of processing of personal data Users have the right to restrict the processing of personal data in the cases indicated in Art. 18 GDPR, including contesting the accuracy of the personal data, exercised upon a request submitted to the Controller
Right to data portability Users have the right to receive from the Controller the personal data concerning the User in a structured, commonly used and machine-readable format, exercised upon a request submitted to the Controller
Right to object to the processing of personal data Users have the right to object to the processing of their personal data in the cases specified in Art. 21 GDPR, exercised upon a request submitted to the Controller
Right to lodge a complaint Users have the right to lodge a complaint with the supervisory authority responsible for personal data protection.
The Controller can be contacted in one of the following ways
Email address - [email protected]
Restricting the saving of and access to Cookies on the User's Device may cause some functions of the Service to work incorrectly.
The Controller accepts no responsibility for Service functions that work incorrectly when the User restricts in any way the ability to save and read Cookies.
The Service - in articles, posts, entries or Users' comments - may contain links to external websites with which the Service Owner does not cooperate. These links and the pages or files they point to may be dangerous for your Device or pose a threat to the security of your data. The Controller is not responsible for content located outside the Service.
The Controller reserves the right to change this Privacy Policy at any time without having to inform Users, with regard to the use of anonymous data or the use of Cookies.
The Controller reserves the right to change this Privacy Policy at any time with regard to the processing of Personal Data, of which Users holding user accounts or subscribed to the newsletter service will be informed by email within 7 days of the change. Continued use of the services means that the User has read and accepted the changes to the Privacy Policy. If the User does not agree with the changes, they must delete their account from the Service or unsubscribe from the Newsletter service.
Changes to the Privacy Policy will be published on this page of the Service.
Changes take effect upon publication.