Data controller:
The controller of your personal data is P.P.H.U. HELLUX-HAIN Sp. J., Kuniów 17B, 46-200 Kluczbork, Poland, VAT ID PL7511497146, e-mail: sklep@hellux.pl, phone +48 691 197 611. You can contact us at this e-mail address in all matters concerning your personal data.
Data collected automatically:
During your visit to the website, data about your visit is automatically collected, i.e. your address IP, domain name, browser type, operating system type, etc. - these data do not allow for unambiguous Identifying you.
Where did we get yours? Data?
We got them from you when we started. the account on our website, as well as when placing and executing orders. We store your data personal for the duration of the contract concluded with you and after it has been concluded for a maximum of 10 years.
Data collected when you contact us:
When you contact us for the purpose of carrying out the actions (e.g. submitting a complaint) via the website Internet, phone or e-mail, we will again require you to provide us with your personal data to confirm your identity and feedback. This applies to the same personal data, which were previously given. Again, this data is not mandatory, but is necessary to perform activities or obtain information that you are interested in.
Data usage:
The personal data you provided and on which you agreed to the processing will only be processed to the extent and purpose of the consent or for the purpose of the allowed law.
Automatically collected data can be used to analyze user behaviour on services or to collecting demographic data about our users.
Data collected during correspondence between you and P.P.H.U. Hellux Hain Sp.J. will only be used in to answer your question as correctly, fully and efficiently as possible.
Your personal data we process according to the provisions of the Data Protection Regulation (GDPR)
Approval processing of personal data, you can withdraw at any time, with a request for suspension processing of personal data in accordance with Article 32(1)(6) of the Personal Data Protection Act.
How will we contact you?
If by filling out the contact form you sent us a message, we can contact you by telephone, email or fax to send an answer to your question.
Cookies and consent:
The shop uses cookies (small files stored in your browser) and similar technologies. Necessary cookies are required for the shop to work: they remember your cart, your login, the selected language and currency and your choice in the cookie banner (cookie "hlx_consent", 12 months). The cookies of the payment provider Stripe and the spam protection of the forms by Cloudflare Turnstile (described below) are also necessary. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in a working and secure shop (Art. 6(1)(f) GDPR); under the Polish Electronic Communications Law no consent is required for these cookies.
Marketing (Meta pixel) and the Trusted Shops trustbadge are only activated after you have given your consent in the cookie banner shown on your first visit (Art. 6(1)(a) GDPR). You can change or withdraw your consent at any time via the "Cookie settings" link at the bottom of every page; the withdrawal does not affect the lawfulness of processing before it. You can also block or delete cookies in your browser settings – some functions of the shop (e.g. cart, login) may then not work.
Payments – Stripe and bank transfer:
Online payments (e.g. by card) are processed by the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland ("Stripe"). If you choose such a payment method, we transfer the data required for the payment to Stripe (e.g. name, e-mail address, billing address, order amount); you enter your card details directly with Stripe – they are not stored on our server. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
To prevent fraud and to process payments securely, our website loads a script from Stripe, which sets the necessary cookies "__stripe_mid" (1 year) and "__stripe_sid" (30 minutes) and processes device and usage data (e.g. IP address, browser information). The legal basis is our legitimate interest in secure payment processing and fraud prevention (Art. 6(1)(f) GDPR). Stripe may also process data in the USA on the basis of the EU-US Data Privacy Framework or the standard contractual clauses of the European Commission. More information: https://stripe.com/privacy
If you pay by bank transfer, we receive the transfer data (e.g. name, account number, amount, reference) from our bank and use it only to settle your order (Art. 6(1)(b) and (c) GDPR).
Spam protection – Cloudflare Turnstile:
To protect our forms (e.g. contact form, registration, login and password reset) against automated submissions and abuse, we use Cloudflare Turnstile of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA ("Cloudflare"). Turnstile is only loaded when you start filling in a form. Technical information such as your IP address and browser and device data is then transferred to Cloudflare and analysed to check whether the form is filled in by a human; according to Cloudflare, this data is not used for advertising or tracking. The legal basis is our legitimate interest in protecting our forms against abuse (Art. 6(1)(f) GDPR). Data may be transferred to the USA; Cloudflare, Inc. is certified under the EU-US Data Privacy Framework. More information: https://www.cloudflare.com/privacypolicy/ and https://www.cloudflare.com/turnstile-privacy-policy/
Meta pixel (Facebook):
With your consent (Art. 6(1)(a) GDPR) we use the Meta pixel, a tool of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland ("Meta"). The pixel allows us to measure the success of our ads on Facebook and Instagram (e.g. which visits and purchases come from an ad) and to show ads to people who have visited our shop or to similar audiences. For this purpose, the pixel sets cookies (e.g. "_fbp", up to 3 months) and transfers to Meta information about the pages you visit and your actions (e.g. an order with its value and product numbers), your IP address and browser and device data. If you have a Facebook or Instagram account, Meta may link this information to your account.
We are jointly responsible with Meta for collecting this data and transferring it to Meta (Art. 26 GDPR, Controller Addendum); Meta is responsible for the further processing. Data may be transferred to Meta Platforms, Inc. in the USA; Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework. The pixel is only loaded after you consent to the category "Marketing" in the cookie banner; you can withdraw your consent at any time via the "Cookie settings" link at the bottom of every page. More information: https://www.facebook.com/privacy/policy/
Integration of the Trusted Shops Trustbadge / other widgets:
If you have given your consent pursuant to Art. 6(1)(a) GDPR, Trusted Shops widgets are integrated on this website to display the Trusted Shops services (e.g. trustmark, collected reviews) and to offer Trusted Shops products to buyers after an order.
When you interact with the Trustbadge AI+, session cookies are set to store the login status and to display the so-called welcome layer, which shows the details of the online shop (company information, reviews, information on the existence of buyer protection) and the #trstd secret. To recognise logged-in users, a cookie is set and stored for a maximum of 400 days after login. In addition, session cookies are set to send push notifications when the app is used, if the user has allowed this. This is necessary so that Trusted Shops can provide the digital service you requested. Trusted Shops is responsible for the data processing when you interact with the Trustbadge AI+.
The Trustbadge and the services advertised with it are offered by Trusted Shops SE, Subbelrather Str. 15C, 50823 Cologne, Germany ("Trusted Shops"), with whom we are joint controllers pursuant to Art. 26 GDPR. Below we inform you about the essential contents of the agreement pursuant to Art. 26(2) GDPR.
Within the joint controllership between us and Trusted Shops, please preferably contact Trusted Shops for data protection questions and to exercise your rights, using the contact options given in their privacy information. Irrespective of this, you can always contact the controller of your choice. If necessary, your request will then be forwarded to the other controller for a response.
1. Data processing when integrating the Trustbadge / other widgets
The Trustbadge is provided by a US content delivery network (CDN) provider. An adequate level of data protection is ensured by an adequacy decision of the EU Commission, available for the USA here. Service providers from the USA are generally certified under the EU-U.S. Data Privacy Framework (DPF); more information here. Where service providers are not certified under the DPF, standard contractual clauses have been concluded as appropriate safeguards.
When the Trustbadge is called up, the web server automatically saves a so-called server log file, which also contains your IP address, the date and time of the call-up, the amount of data transferred and the requesting provider (access data) and documents the call-up. The IP address is anonymised immediately after collection so that the stored data cannot be attributed to you. The anonymised data is used in particular for statistical purposes and for error analysis.
2. Data processing after completion of the order
If you have given your consent, the Trustbadge accesses order information stored on your terminal device (order total, order number, purchased product if applicable) and your e-mail address after completion of the order, and your e-mail address is hashed using a cryptographic one-way function. The hash value is then transferred to Trusted Shops together with the order information pursuant to Art. 6(1)(a) GDPR. This serves to check whether you are already registered for Trusted Shops services. If this is the case, further processing takes place in accordance with the contractual agreement between you and Trusted Shops. If you are not yet registered for the services or do not give your consent to automatic recognition via the Trustbadge, you will then have the opportunity to register manually for the services or to take out the protection under your existing user agreement, if any.
For this purpose, after completion of your order, the Trustbadge accesses the following information stored on your terminal device: order total, order number and e-mail address. This is necessary so that we can offer you buyer protection. The data is only transferred to Trusted Shops when you actively decide to take out buyer protection by clicking the corresponding button in the so-called Trustcard. If you decide to use the services, further processing is governed by the contractual agreement with Trusted Shops pursuant to Art. 6(1)(b) GDPR, in order to complete your registration for buyer protection, to protect the order and, if applicable, to send you review invitations by e-mail afterwards.
Trusted Shops uses service providers in the areas of hosting, monitoring and logging. The legal basis is Art. 6(1)(f) GDPR for the purpose of ensuring trouble-free operation. Processing may take place in third countries (USA and Israel). An adequate level of data protection is ensured by adequacy decisions of the EU Commission, available for the USA here and for Israel here. Service providers from the USA are generally certified under the EU-U.S. Data Privacy Framework; more information here. Where service providers are not certified under the DPF, standard contractual clauses have been concluded as appropriate safeguards.
P.P.H.U Hellux is not responsible for the content of cookies sent by other websites, to whose links are placed on the online store.