Skip to content

Zamówienia złożone do niedzieli zostaną nadane w poniedziałek.

Darmowa dostawa do automatów i punktów DPD Pickup do końca roku!
Free delivery for purchases over 100 PLN

Privacy Policy

Privacy Policy of the Yamann online store

1. General information

  • This policy applies to the website operating at the following url address: yamann.com
  • The website operator and personal data controller is: Yamann Spółka z ograniczoną odpowiedzialnością with its registered office in Wrocław (54-530) at 1 Skrzypowa Street, entered into the register of entrepreneurs maintained by the District Court for Wrocław-Fabryczna in Wrocław, 9th Commercial Division of the National Court Register, under the KRS number: 0000444280, using the REGON number 022037032 and NIP number 8992740275, share capital: PLN 140,000.00,
  • Contact with the Operator is possible via:
  1. post office: ul. Skrzypowa 1, 54-530 Wroclaw
  2. Operator's e-mail address: hello@yamann.com
  3. contact form on the Website
  • The Operator is the Administrator of your personal data in relation to the data provided voluntarily on the Website.
  • Your data are processed in accordance with the currently applicable provisions and legal standards, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (OJ EU L. of 2016, No. 119, p. 1, as amended, hereinafter referred to as GDPR), the Act of 10 May 2018 on the protection of personal data (Journal of Laws 2019, item 1781) and the Act of 18 July 2002 on the provision of electronic services (Journal of Laws 2024, item 1513).
  • The Operator processes your data provided through various communication channels, including in writing, by email, by telephone, via the Website, and on social media (Facebook). Data may have been provided to the Operator in various situations, for example, as part of cooperation in the execution of sales contracts or contracts for the provision of electronic services.
  • Personal data may be provided to the Operator directly by you or may come from publicly available sources (CEiDG, KRS).
  • Your personal data will be processed on the basis of Article 6 paragraph 1 letters a) - c) and f) of the GDPR for the purpose of establishing cooperation, concluding and performing a sales contract (including delivery) or relating to the provision of services electronically, responding to any questions or requests addressed to the Operator and conducting further correspondence in this respect, direct marketing, including in the form of a newsletter (in the case of consent) and conducting online chat conversations, contacting regarding other information, offers and services (in the case of consent), as well as fulfilling the legal obligations incumbent on the Operator, establishing, defending and pursuing any claims, handling complaints, financial settlements, including issuing accounting documents.
  • The website performs the functions of obtaining information about users and their behavior in the following way:
  1. Through data entered voluntarily in forms, which are entered into the Operator's systems.
  2. By saving cookie files (so-called "cookies") in end devices.
  • In connection with the implementation of sales and service contracts and related legal obligations, the Operator may process the following data:
  1. identification data, including name and surname, Tax Identification Number, National Business Registry Number,
  2. contact details, including home address, telephone number, e-mail address, payment account number, payment card number,
  3. other personal data provided in connection with cooperation, a request for contact or the provision of information.

2. Selected data protection methods used by the Operator

  • The internal procedures implemented by the Operator guarantee that the collected data are:
  • processed lawfully, fairly and transparently for the data subject;
  • collected for specific, explicit and legitimate purposes and not further processed in a way that is incompatible with those purposes;
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed;
  • correct and updated as necessary;
  • kept in a form which permits identification of the data subject for no longer than is necessary for the purposes for which the data are processed;
  • processed in a way that ensures appropriate data security, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage, using appropriate technical or organisational measures.
  • The areas where you log in and enter personal data are protected at the transmission layer (SSL certificate). This means that personal data and login information entered on the website are encrypted on the user's computer and can only be read by the target server.
  • User passwords are stored in a hashed format. The hash function is one-way and cannot be reversed, which is currently the modern standard for storing user passwords.
  • The website uses two-factor authentication, which provides an additional form of protection when logging in to the website.

3. Hosting

  • The website is hosted (technically maintained) on the operator's servers: cyberFolks.pl
  • To ensure technical reliability, the hosting company maintains server-level logs. The following may be recorded:
  1. resources specified by the URL identifier (addresses of requested resources – pages, files),
  2. time of arrival of the request,
  3. time of sending the response,
  4. name of the client station – identification performed via the HTTP protocol,
  5. information about errors that occurred during the execution of the HTTP transaction,
  6. URL address of the page previously visited by the user (referrer link) – if the Website was accessed via a link,
  7. information about the user's browser,
  8. IP address information,
  9. diagnostic information related to the process of self-ordering services via the website's registers,
  10. information related to the handling of e-mail addressed to the Operator and sent by the Operator.

4. Your rights and additional information on how your data is used

  • In certain situations, the Controller has the right to transfer your personal data to entities cooperating with it, if this is necessary to perform the sales contract concluded with you, including related additional services or the contract for the provision of electronic services, or to fulfill the Controller's obligations. Your data may be transferred to entities cooperating with the Operator under a personal data processing agreement. This applies to the following groups of recipients:
  1. hosting company,
  2. couriers and postal operator,
  3. payment operators,
  4. entities providing the Operator with advisory services, legal, tax and accounting assistance,
  5. companies providing marketing services to the Administrator (in the event of consent to the processing of personal data for marketing purposes)

Personal data may be disclosed to authorized employees of the Operator and associates who use the data to achieve the purpose of the Website.

  • Your personal data will be processed by the Controller no longer than necessary to achieve the processing purposes specified above or until consent is withdrawn. After the contract expires, the Controller will process your personal data for no longer than necessary to settle any claims (particularly those arising from the limitation periods specified in the Tax Ordinance and the Civil Code) or to fulfill obligations arising from legal provisions, particularly tax and accounting law. With respect to marketing data, data will be processed until consent is withdrawn, but no longer than for three years.
  • You have the right to request from the Administrator:
  1. access to personal data concerning you,
  2. their corrections,
  3. removal,
  4. processing restrictions,
  5. and data transfer.
  • You have the right to object to the processing indicated above to the processing of personal data for the purpose of pursuing legitimate interests pursued by the Controller, including profiling, however, the right to object cannot be exercised if there are valid legitimate grounds for processing, overriding interests, rights and freedoms towards you, in particular the establishment, exercise or defense of claims.
  • If your data is processed based on your consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal. However, withdrawing consent may prevent the performance of a contract on your behalf.
  • If personal data are processed by the Operator for direct marketing purposes, you may object to the processing of personal data for such marketing purposes at any time.
  • If you wish to exercise any of the above rights, please send a request indicating the scope of data that is the subject of the request to the e-mail address or by post to the contact addresses provided.
  • You may lodge a complaint against the Administrator's actions with the President of the Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw.
  • Providing personal data is voluntary, but some data are required as necessary for the performance of the Agreement by the Operator and the operation of the Website.
  • Personal data is not transferred to third countries within the meaning of data protection regulations. This means that we do not transfer it outside the European Union. This data may be transferred outside the aforementioned area in connection with Meta's social media activities or in connection with the use of tools and plug-ins by Google LLC. In such a case, the transfer is based on data protection clauses adopted by the European Commission or on the basis of a relevant decision of the European Commission. Google LLC is responsible for the transfer of data outside the EEA under the terms set out at: https://policies.google.com/privacy/frameworks?hl=pl, and Meta under the terms set out at: https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0

5. Information in forms

  • The website collects information provided voluntarily by the user, including personal data, if provided.
  • The website may save information about connection parameters (time stamp, IP address).
  • In some cases, the website may store information to facilitate linking the data in a form with the email address of the user completing the form. In such cases, the user's email address appears within the URL of the page containing the form.
  • The data provided in the form is processed for the purpose resulting from the function of a specific form, e.g. to process a service request or sales contact, register services, etc. In each case, the context and description of the form clearly indicate its purpose.

6. Administrator Logs

  • Information about user behavior on the website may be subject to logging. This data is used for website administration purposes.

7. Important Marketing Techniques

  • The operator uses statistical analysis of website traffic through Google Analytics (Google Inc., based in the USA). The operator does not provide personal data to the operator of this service, only anonymized information. The service relies on the use of cookies on the user's end device. In terms of information about user preferences collected by the Google advertising network, the user can view and edit information derived from cookies using the tool: https://www.google.com/ads/preferences/
  • The Operator uses remarketing techniques to tailor advertising messages to user behavior on the website. This may create the illusion that user personal data is being used to track them. However, in practice, no personal data is transferred from the Operator to advertising providers. The technological requirement for such activities is the enabled use of cookies.
  • The operator uses the Facebook pixel. This technology allows Facebook (Facebook Inc., based in the USA) to know that a given registered user is using the Service. In this case, it relies on activity data and personal data, which it itself administers. The operator does not share any additional personal data with Facebook. The service relies on the use of cookies on the user's end device. More information: https://privacycenter.instagram.com/policy
  • The Operator uses a solution that automates the operation of the Website in relation to users, e.g. it may send an e-mail to the user after visiting a specific subpage, provided that the user has agreed to receive commercial correspondence from the Operator.
  • The operator uses Google Ads and Facebook Ads tools for marketing purposes, enabling the customization of displayed ads based on the websites you visit and cookies. Google Ads and Facebook Ads collect data in the form of IP addresses, in particular to determine your location and tailor ads to your needs. To learn more about the data used by Google Ads, visit: https://policies.google.com/technologies/partner-sites . To learn more about the data used by Facebook Ads, visit: https://www.facebook.com/privacy/policy/?locale=pl_PL

8. NEWSLETTER and product availability notification

  1. To subscribe to the Newsletter, you must provide your email address and provide your consent. By subscribing to the Newsletter, you are entering into a contract for the provision of digital content.
  2. The newsletter allows you to receive periodic emails containing information about, among other things, current offers, promotions, and events.
  3. You can unsubscribe from the Newsletter at any time by unchecking your consent to the Newsletter via the "Unsubscribe" link in the delivered Newsletter or by sending a request to the following e-mail address: hello@yamann.com
  4. By using the "Notify me when a product is available" function, you voluntarily consent to receiving a one-time email notification informing you of the availability of the indicated product. The legal basis for processing is your consent (Article 6, Section 1, Letter a of the GDPR). We store your data until the notification is sent or you withdraw your consent. This function is independent of the Newsletter and does not result in your subscription to the Newsletter. You can withdraw your consent at any time via the link in the message or by writing to: hello@yamann.com. Data recipients may include hosting providers and marketing automation systems acting on our behalf.

9. Changes to the Privacy Policy

The Operator reserves the right to make changes to the Privacy Policy, of which you will be informed accordingly.