Privacy Policy
§1 [GENERAL PROVISIONS]
1. This document defines the Privacy Policy of the Grand Fitness store, which specifically includes regulations regarding the protection of personal data and the security of other data entered into the Service by the User.
2. The Privacy Policy constitutes an integral appendix to the Terms and Conditions.
§2 [DEFINITIONS]
The terms used in this document mean:
1. Administrator – Grand Piotr Brot, ul. Okrężna 39, 63-024 Krzykosy, NIP: 7861668944,
2. Service – the website available at grand-fitness.pl and all its subpages,
3. Parties – the Administrator and the User,
4. User – a natural person who uses the Service and provides their personal data within it.
§3 [PERSONAL DATA PROTECTION]
1. The Administrator is the controller of personal data within the meaning of the General Data Protection Regulation (GDPR) of April 27, 2016.
2. The Administrator processes data within the scope, duration, and purposes specified in the content provided under the forms used to collect personal data from the User.
3. Personal data will be shared only with trusted subcontractors of the Administrator, such as IT service providers, accounting firms, and administrative services.
§4 [USER RIGHTS]
1. In case of changes to personal data, the User should update them by sending an appropriate message to the Administrator.
2. The User has the right to request access to their personal data, rectify them, delete them, and restrict their processing. Additionally, the User has the right to withdraw consent at any time without affecting the legality of processing based on consent before its withdrawal, the right to data portability, and the right to object to the processing of personal data.
3. The User has the right to file a complaint with the President of the Office for Personal Data Protection.
4. Providing personal data is voluntary; however, failure to consent to data processing prevents the use of the Service.
5. The Administrator may refuse to delete the User's personal data if retaining the data is necessary due to a legal obligation imposed on the Administrator.
§5 [TECHNICAL DATA PROTECTION]
1. The Administrator uses all technical and organizational measures to ensure the security of the User's personal data and protect them from accidental or intentional destruction, accidental loss, modification, unauthorized disclosure, or access. Information is stored and processed on highly secure servers with appropriate security measures, in compliance with Polish law requirements.
2. The Administrator commits to storing backup copies containing the User’s personal data.
3. The entrusted data is stored on top-class equipment and servers in well-secured data storage centers, accessible only to authorized persons.
4. The Administrator performs personal data processing activities in compliance with all legal and technical requirements imposed by personal data protection regulations.
§6 [COOKIES POLICY]
1. For the convenience of Users, the Service uses cookies, among other things, to adjust the Service to Users’ needs and for statistical purposes. Cookies are small text files sent by a website visited by an internet user to their device.
2. The Service uses two types of cookies: “session” (session cookies) and “persistent” (persistent cookies). "Session" cookies are temporary files stored on the User’s device until they log out, leave the website, or turn off the web browser. "Persistent" cookies are stored on the User’s device for the period specified in the cookie parameters or until they are deleted by the User.
3. The Service uses the following types of cookies:
a. "Necessary" – enable the use of services available within the Service, e.g., used for user authentication,
b. "Security" – used to ensure security, e.g., detecting abuse in the use of the Service,
c. "Performance" – allow collecting information on how the Service is used,
d. "Functional" – allow remembering User-selected settings and personalizing the User’s interface, such as the selected language, region, font size, appearance of the Service, etc.
§7 [LOGS]
1. In accordance with standard practices of most websites, we store HTTP requests directed to our server (server logs). Therefore, we store:
a. IP addresses from which users access our Service’s informational content;
b. Time of request arrival,
c. Time of response sending,
d. Client station name – identified through the HTTP protocol,
e. Information about errors that occurred during the HTTP transaction,
f. URL address of the previously visited page by the User (referer link),
g. Information about the User’s browser.
2. Data collected in log files is used exclusively for Service administration purposes.
3. Collected logs are stored indefinitely as auxiliary material for Service administration. The information contained in them is not disclosed to anyone except authorized persons responsible for Service administration. Statistical reports may be generated based on log files to aid administration. Such reports do not contain any identifying characteristics of people visiting the Service.
§8 [CONTACT]
1. The User may contact the Administrator at any time to obtain information on whether and how the Administrator processes their personal data.
2. The User may also request the Administrator to delete their personal data, either in full or in part.
3. The Administrator can be contacted by sending an email to:
piotrgrandfitness@gmail.com