-Privacy Policy-
Privacy Policy – Natural Person
This Privacy Policy sets out the principles for storing and accessing data on Users’ devices who use the Service for the purpose of providing electronic services by the Administrator, as well as the rules for collecting and processing personal data voluntarily provided by Users through the tools available on the Service.
This Privacy Policy is an integral part of the Service Terms and Conditions, which define the rules, rights, and obligations of Users using the Service.
§1 Definitions
Service – the online service aromax.online operating at https://aromax.online
External Service – online services of partners, service providers, or Users cooperating with the Administrator
Service / Data Administrator – The Administrator of the Service and Data (hereinafter: Administrator) is a natural person, Dawid Krzyżewski, residing at Sochaczewska 12, 05-840 Brwinów, providing electronic services via the Service
User – a natural person for whom the Administrator provides electronic services via the Service
Device – an electronic device and software through which the User accesses the Service
Cookies – text data collected in files stored on the User’s Device
GDPR – Regulation (EU) 2016/679 of the European Parliament and Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data
Personal Data – information about an identified or identifiable natural person (“data subject”); an identifiable natural person is someone who can be identified directly or indirectly, in particular via an identifier such as name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person
Processing – any operation or set of operations performed on personal data, whether automated or not, such as collecting, storing, organizing, adapting, using, disclosing, or deleting data
Restriction of Processing – marking stored personal data to limit its future processing
Profiling – any form of automated processing of personal data to evaluate certain personal aspects of a natural person, including analyzing or predicting aspects of work performance, economic situation, health, preferences, interests, reliability, behavior, location, or movement
Consent – any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by statement or clear affirmative action, allowing the processing of personal data
Data Breach – a breach of security leading to accidental or unlawful destruction, loss, modification, unauthorized disclosure, or access to personal data
Pseudonymization – processing personal data so that it cannot be attributed to a specific data subject without additional information, provided such information is stored separately and secured
Anonymization – the irreversible process of modifying data so that it cannot be linked to a specific individual
§2 Data Protection Officer
Under Article 37 GDPR, the Administrator has not appointed a Data Protection Officer.
For any matters regarding personal data processing, please contact the Administrator directly.
§3 Types of Cookies
- First-party Cookies – stored and read on the User’s Device by the Service system
- Third-party Cookies – stored and read on the User’s Device by external services; scripts from third-party services may place Cookies via the Service
- Session Cookies – temporary Cookies deleted at the end of the session
- Persistent Cookies – stored until manually deleted by the User
§4 Data Storage Security
- Internal Cookies are safe and contain no harmful scripts
- External Cookies are chosen from trusted partners, but the Administrator cannot fully control them
- Users may manage or delete Cookies at any time via browser/device settings
- Administrator uses appropriate physical and organizational measures to protect personal data
§5 Purposes of Cookies
- Improving Service usability
- Personalizing the Service
- Enabling login
- Marketing/Remarketing on external services
- Advertising services
- Affiliate services
- Service statistics
§6 Purposes of Personal Data Processing
User-provided data is used for:
- User account registration and maintenance
- Communication regarding the Service and data protection
- Ensuring the Administrator’s legitimate interest
Automatically collected data is used for:
- Statistics and analytics
- Remarketing and targeted ads
- Affiliate programs
- Ensuring the Administrator’s legitimate interest
§7 Third-party Service Cookies
The Service uses external scripts and web components that may place their own Cookies. Users can manage allowed Cookies in browser settings. Examples of third-party services:
- Advertising & Affiliate Networks: Google Adsense
- Analytics: Google Analytics, WordPress Stats, Facebook Analytics for Apps
- Other Services: Google Maps
§8 Types of Collected Data
Automatically collected (anonymous) data: IP, browser type, screen resolution, approximate location, visited pages, time spent, OS type, referrer, language, connection speed, ISP
Data collected during registration: name, surname, nickname, login, email, IP
Newsletter subscription: email
Comments: name/nickname, email, website, IP
§9 Third-party Access to Personal Data
Personal data is shared only with:
- Hosting providers (LH.pl)
- Payment providers (Stripe, PayPal)
- Courier/postal services for delivery
All third-party processing is governed by contracts and GDPR compliance.
§10 Data Processing Rules
- Personal data is not transferred outside the EU, except if publicly posted by the User
- Data is not used for profiling or resold
- Anonymous data may be transferred outside the EU, but not for profiling or resale
§11 Legal Basis
- GDPR Art. 6(1)(a) – consent
- GDPR Art. 6(1)(b) – contract performance
- GDPR Art. 6(1)(f) – legitimate interest
- Polish Data Protection Act, Telecommunication Law, Copyright Act
§12 Data Retention
- User-provided data: stored for the duration of Service provision, then deleted/anonimized within 30 days
- Exceptions for legal reasons: retained up to 3 years
- Anonymous statistical data: retained indefinitely
§13 Users’ Rights
- Access, correction, deletion, restriction, portability, objection to processing
- Complaint to the supervisory authority
Newsletter users can unsubscribe via each email’s link.
§14 Administrator Contact
- Email: digihub135@gmail.com
- Phone: +48 791 763 348
§15 Service Requirements
Limiting Cookies may affect Service functionality. The Administrator is not responsible for malfunctioning features if Cookies are restricted.
§16 External Links
External links may lead to unsafe websites. The Administrator is not responsible for content outside the Service.
§17 Privacy Policy Updates
- Changes may occur without prior notice regarding anonymous data and Cookies
- Changes regarding personal data will be notified within 7 days to registered Users or Newsletter subscribers
- Continued use of the Service constitutes acceptance of updates