Privacy Policy
EONLIFE BIOTECH sp. z o.o. pays particular attention to respecting the privacy of Customers visiting the Online Store.
This Privacy Policy sets out the rules for the processing of personal data collected via the online store eonlife.pl (hereinafter referred to as the “Online Store”).
The owner of the Online Store and the Data Controller is EONLIFE BIOTECH sp. z o.o., ul. Inowrocławska 19a, 61-044 Poznań, NIP: 7773436973, KRS 0001138229, REGON 540177230.
Personal data collected by EONLIFE BIOTECH sp. z o.o. via the Online Store are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR).
§ 1 Type of data processed, purposes and legal basis
- EONLIFE BIOTECH sp. z o.o. collects information regarding natural persons who are consumers.
- Customers’ personal data are collected in the following cases:
a) Registration of an account in the Online Store, in order to create an individual account and manage it. Legal basis: necessity for the performance of the account service contract (Art. 6(1)(b) GDPR);
b) Placing an order in the Online Store, in order to perform the sales contract. Legal basis: necessity for the performance of the sales contract (Art. 6(1)(b) GDPR);
c) Subscription to the newsletter, in order to perform the contract for the electronic provision of the newsletter service. Legal basis: consent of the data subject to perform the newsletter service contract (Art. 6(1)(a) GDPR);
d) Use of the “post a review” service, in order to perform the contract for the electronic provision of this service. Legal basis: necessity for the performance of the review service contract (Art. 6(1)(b) GDPR);
e) Use of the supplementation selection service, in order to perform the contract for the electronic provision of this service. Legal basis: necessity for the performance of the supplementation selection service contract (Art. 6(1)(b) GDPR and Art. 9(2)(a) GDPR);
f) Conducting analytical, marketing, or online remarketing activities. Legal basis: consent of the data subject, expressed by checking a relevant box or consenting to the installation of cookies used for marketing or analytical purposes;
g) Customer satisfaction surveys. Legal basis: necessity for processing for the legitimate interest of EONLIFE BIOTECH sp. z o.o., consisting in ensuring and maintaining a high quality of service and customer satisfaction with products and services (Art. 6(1)(f) GDPR). - When registering an account in the Online Store, the Customer provides:
a) an email address. - During account registration, the Customer sets an individual password for their account. The Customer may change the password later, as described in §6.
- When placing an order, the Customer provides the following data:
a) email address;
b) address details:
i. postal code and city;
ii. country (state);
iii. street with house/flat number.
c) first and last name;
d) telephone number. - When using the Newsletter service, the Customer provides only their email address.
- When using the “post a review” service, the Customer provides only their pseudonym, nickname, or first name.
- When using the supplementation selection service, the Customer provides:
a) email address;
b) weight;
c) height;
d) age;
e) information on previously used dietary supplements. - For customer satisfaction surveys, EONLIFE BIOTECH sp. z o.o. processes the following data:
a) email address;
b) order number. - When using the Online Store website, additional information may be collected, in particular: the IP address assigned to the Customer’s computer or the external IP address of the Internet provider, domain name, browser type, access time, and operating system type.
- Navigational data may also be collected from Customers, including information about links and references they choose to click on or other actions taken within the Online Store. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), consisting in facilitating the use of electronic services and improving the functionality of these services.
- For the purpose of establishing, pursuing, and enforcing claims, certain personal data provided by the Customer as part of using the functionalities in the Online Store, such as name, surname, information on the use of services, and other data necessary to prove the existence of a claim, including the extent of damages suffered, may be processed. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), consisting in establishing, pursuing, and enforcing claims as well as defending against claims in proceedings before courts and other state authorities.
- EONLIFE BIOTECH sp. z o.o. processes personal data including: name, surname, email address, as well as responses to prepared questions in satisfaction surveys and forms used for satisfaction research. Participation in such actions is voluntary. If the Customer does not agree to participate, they may inform EONLIFE BIOTECH sp. z o.o. at any time as per §7, in which case EONLIFE BIOTECH sp. z o.o. will block the relevant data. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), consisting in improving the functionality of electronically provided services and assessing satisfaction with our services.
- Providing personal data to EONLIFE BIOTECH sp. z o.o. is voluntary in connection with concluded sales contracts or the provision of services via the Online Store website; however, failure to provide the data specified in the registration forms will prevent registration and the creation of a Customer Account, and in the case of orders placed without registration, will prevent the submission and execution of the order.
§ 2 To Whom Data Are Disclosed or Entrusted and How Long Are They Stored?
- The Customer’s personal data are transferred to service providers used by EONLIFE BIOTECH sp. z o.o. in operating the Online Store. Depending on contractual arrangements and circumstances, service providers either act on the instructions of EONLIFE BIOTECH sp. z o.o. with regard to the purposes and methods of processing these data (processors) or independently determine the purposes and methods of their processing (controllers).
a) Processors. EONLIFE BIOTECH sp. z o.o. uses providers who process personal data exclusively on its instructions. These include, among others, providers of hosting services, accounting services, marketing systems, customer satisfaction survey systems, traffic analysis systems for the Online Store, and systems for analyzing the effectiveness of marketing campaigns.
b) Controllers. EONLIFE BIOTECH sp. z o.o. uses providers who do not act exclusively on its instructions and independently determine the purposes and methods of using Customers’ personal data. They provide electronic payment, banking, and postal services.
- Location. Service providers are primarily based in Poland and other countries of the European Economic Area (EEA). Some of them may be based outside the EEA. In such cases, the Controller ensures that the providers guarantee a high level of personal data protection, in particular through the use of standard contractual clauses approved by the European Commission or participation in the Data Privacy Framework Program.
- Data Retention:
a) Where the basis for data processing is consent, the Customer’s personal data are processed by EONLIFE BIOTECH sp. z o.o. until the consent is withdrawn, and after withdrawal for a period corresponding to the statute of limitations for claims that may be raised by or against EONLIFE BIOTECH sp. z o.o. Unless otherwise provided by specific provisions, the limitation period is six years, and for claims for periodic benefits or related to business activity – three years.
b) Where the basis for processing is the performance of a contract, the Customer’s personal data are processed by EONLIFE BIOTECH sp. z o.o. as long as it is necessary for contract performance, and after that for a period corresponding to the statute of limitations for claims. Unless otherwise provided by specific provisions, the limitation period is six years, and for claims for periodic benefits or related to business activity – three years.
- In the case of purchases in the Online Store, personal data may be transferred, depending on the Customer’s choice, to the following entities for the purpose of delivering the ordered goods:
a) a courier company;
b) InPost Paczkomaty Sp. z o.o., based in Kraków, providing delivery and parcel locker services. - If the Customer chooses to pay via the Tpay system, their personal data are transferred to Tpay S.A., based in Poznań, to the extent necessary for the execution of the payment.
- With the express and voluntary consent of the Customer, EONLIFE BIOTECH sp. z o.o. may transfer the Customer’s personal data to Opineo Sp. z o.o., based in Wrocław (50-381 Wrocław, ul. Marii Curie-Skłodowskiej 12, entered in the register of entrepreneurs kept by the District Court for Wrocław Fabryczna, VI Economic Department of the National Court Register, KRS: 0000357466), for the purpose of sending, by Opineo Sp. z o.o., a satisfaction survey to the Customer’s email address regarding a transaction made in the Online Store.
- With the express and voluntary consent of the Customer, EONLIFE BIOTECH sp. z o.o. may transfer the Customer’s personal data to Ceneo Sp. z o.o., based in Poznań (60-166 Poznań, ul. Grunwaldzka 182, entered in the register of entrepreneurs kept by the District Court Poznań – Nowe Miasto i Wilda, VIII Economic Department of the National Court Register, KRS: 0000493884), for the purpose of sending, by Ceneo Sp. z o.o., a satisfaction survey to the Customer’s email address regarding a transaction made in the Online Store.
- Navigational data may be used to provide better service, analyze statistical data, and adjust the Online Store to Customer preferences, as well as for the administration of the Online Store.
- If the Customer subscribes to the newsletter, EONLIFE BIOTECH sp. z o.o. will send commercial information about promotions and new products available in the Online Store to the Customer’s email address.
- If requested, EONLIFE BIOTECH sp. z o.o. provides personal data to authorized state authorities, in particular organizational units of the Prosecutor’s Office, the Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
- EONLIFE BIOTECH sp. z o.o. provides a “Like” plugin for the social networking site facebook.com (administered by Facebook Ireland, based in Ireland) on the Online Store website. Through the “Like” plugin, Facebook collects information about the Customer’s device, such as the operating system, hardware and software versions, battery level, signal strength, available memory, browser type, names and types of applications and files, and installed plugins. Additionally, Facebook collects information about actions and behaviors related to the devices, e.g., whether a window is open in the foreground or background, or information about mouse movements, unique identifiers, device identifiers, and other identifiers. Facebook also collects signals from the device, including Bluetooth signals, Wi-Fi access points, beacons and cell towers in the vicinity, device settings, and, with Customer consent, GPS location, camera, or photos. With regard to networks and connections, Facebook collects the name of the mobile operator or Internet provider used by the Customer, language, time zone, mobile phone number, IP address, connection speed, and, in some cases, information about other devices nearby or on the Customer’s network.
If the Customer is logged into their Facebook account while browsing the EONLIFE BIOTECH sp. z o.o. website, the “Like” plugin sends Facebook information about visiting the EONLIFE BIOTECH sp. z o.o. website. The data obtained by Facebook include the user’s Facebook ID (known only to Facebook), the visited website, date and time, and the above-mentioned data. Facebook collects this data to personalize content displayed on Facebook and to improve the services provided by Facebook. If the Customer additionally uses the “Like” function, this will be recorded by Facebook as content that the Customer prefers.
If the Customer is not logged into their Facebook account or does not have a Facebook account, the “Like” plugin still sends Facebook information about the visited site, date and time of visit, and the data listed above. The purpose of data collection by Facebook is to improve the services provided by Facebook.
§ 3 Cookies Mechanism, IP Address
· The Online Store uses small files called cookies. These are saved by EONLIFE BIOTECH sp. z o.o. on the end device of the person visiting the Online Store, provided that the web browser allows it. A cookie file usually contains the name of the domain it comes from, its “expiry time,” and an individual, randomly selected number identifying this file. Information collected through this type of files helps to tailor the products offered by EONLIFE BIOTECH sp. z o.o. to the individual preferences and actual needs of visitors to the Online Store. They also enable the preparation of general statistics on the presentation of products in the Online Store.
· EONLIFE BIOTECH sp. z o.o. uses two types of cookies:
a) Session cookies: after the session of a given browser ends or the computer is turned off, the stored information is deleted from the device memory. The session cookies mechanism does not allow any personal data or confidential information to be retrieved from the Customers’ computers.
b) Persistent cookies: these are stored in the Customer’s device and remain there until deleted or expired. The persistent cookies mechanism does not allow any personal data or confidential information to be retrieved from the Customer’s computer.
· EONLIFE BIOTECH sp. z o.o. uses its own cookies for:
a) authenticating the Customer in the Online Store and ensuring the Customer’s session in the Online Store (after logging in), so that the Customer does not have to enter their login and password on every subpage of the Online Store;
b) analyses and research and audience audit, especially for creating anonymous statistics that help understand how Customers use the Online Store website, which makes it possible to improve its structure and content.
· EONLIFE BIOTECH sp. z o.o. uses external cookies for:
a) promoting the Online Store via the social networking site facebook.com (external cookie administrator: Meta Platforms Ireland Limited, Ireland);
b) presenting advertisements tailored to the Customer’s preferences using the facebook.com online advertising tool (external cookie administrator: Meta Platforms Ireland Limited, Ireland);
c) presenting the overall store score from the external service opineo.pl (external cookie administrator: Opineo Sp. z o.o., Wrocław);
d) presenting advertisements tailored to the Customer’s preferences using Google Ads (external cookie administrator: Google Ireland Limited, Ireland);
e) presenting multimedia content on the Online Store website from www.youtube.com (external cookie administrator: Google Ireland Limited, Ireland);
f) collecting general and anonymous statistical data using Google Analytics (external cookie administrator: Google LLC, USA);
g) presenting the “Rzetelny Regulamin” certificate via rzetelnyregulamin.pl (external cookie administrator: Rzetelna Grupa sp. z o.o., Warsaw);
h) analyzing the behavior of Online Store visitors using Hotjar (external cookie administrator: Hotjar Ltd., Malta);
i) aggregating and analyzing data on preferences and purchase choices to carry out statistics and optimize marketing activities (external cookie administrator: BloomReach, Inc., USA);
j) presenting advertisements as part of targeted marketing campaigns for specific audiences using RTB House tools (external cookie administrator: RTB House Poland Sp. z o.o., Warsaw); detailed information here: https://www.rtbhouse.com/cn/centrum-prywatnosci/polityka-prywatnosci-uslug/;
k) presenting advertisements tailored to the Customer’s preferences using Criteo (external cookie administrator: Criteo SA, France);
l) presenting advertisements tailored to the Customer’s preferences using Microsoft Advertising (external cookie administrator: Microsoft Ireland Operations Limited, Ireland); details – https://privacy.microsoft.com/de-de/privacystatement;
m) analyzing visitor behavior using Microsoft activity map tools (external cookie administrator: Microsoft Ireland Operations Limited, Ireland); details – https://privacy.microsoft.com/de-de/privacystatement;
n) presenting advertisements via Microsoft Advertising remarketing (external cookie administrator: Microsoft Ireland Operations Limited, Ireland); details – https://privacy.microsoft.com/de-de/privacystatement;
o) presenting advertisements using X Advertising (external cookie administrator: Twitter Inc., Ireland); details – https://help.x.com/en/rules-and-policies/x-cookies;
p) presenting advertisements via X Advertising remarketing (external cookie administrator: Twitter Inc., Ireland); details – https://help.x.com/en/rules-and-policies/x-cookies;
q) presenting advertisements using Pinterest Ads (external cookie administrator: Pinterest Inc., Ireland); details – https://policy.pinterest.com/pl/privacy-policy#section-scope-of-the-privacy-policy;
r) presenting advertisements via Pinterest Ads remarketing (external cookie administrator: Pinterest Inc., Ireland); details – https://policy.pinterest.com/pl/privacy-policy#section-scope-of-the-privacy-policy.
· The cookies mechanism is safe for Customers’ computers. In particular, it is not possible for viruses or unwanted software or malware to enter Customers’ computers via this route. However, Customers can limit or disable cookies in their browsers. In such case, the use of the Online Store will be possible except for functions that by their nature require cookies.
· Below are links on how to change cookie settings in popular web browsers:
a) Internet Explorer;
b) Microsoft EDGE;
c) Mozilla Firefox;
d) Chrome and Chrome Mobile;
e) Safari and Safari Mobile;
f) Opera.
EONLIFE BIOTECH sp. z o.o. may collect Customers’ IP addresses. The IP address is a number assigned to the visitor’s computer by the Internet service provider. In most cases, it changes each time you connect to the Internet. The IP address is used by EONLIFE BIOTECH sp. z o.o. for diagnosing technical problems with the server, creating statistical analyses (e.g., to determine from which regions the most visits are recorded), as useful information for administering and improving the Online Store, and for security and possible identification of unwanted automated programs that burden the server.
· The Online Store contains links to other websites. EONLIFE BIOTECH sp. z o.o. is not responsible for the privacy policies of those sites.
§ 4 Rights of Data Subjects
· Right to Withdraw Consent – Legal basis: Article 7(3) GDPR.
a) The Customer has the right to withdraw any consent given to EONLIFE BIOTECH sp. z o.o.
b) The withdrawal of consent is effective from the moment it is withdrawn.
c) Withdrawal of consent does not affect the lawfulness of processing carried out by EONLIFE BIOTECH sp. z o.o. before the consent was withdrawn.
d) Withdrawal of consent does not have any negative consequences for the Customer, but it may prevent further use of services or functionalities which, by law, EONLIFE BIOTECH sp. z o.o. can only provide with consent.
· Right to Object to Data Processing – Legal basis: Article 21 GDPR.
a) The Customer has the right to object at any time – on grounds relating to their particular situation – to the processing of their personal data, including profiling, if EONLIFE BIOTECH sp. z o.o. processes their data based on a legitimate interest, e.g., marketing of EONLIFE BIOTECH sp. z o.o. products and services, compiling usage statistics for specific functionalities of the Online Store, facilitating use of the Online Store, or customer satisfaction surveys.
b) Unsubscribing via email from receiving marketing communications regarding products or services will constitute the Customer’s objection to the processing of their personal data, including profiling, for such purposes.
c) If the Customer’s objection is valid and EONLIFE BIOTECH sp. z o.o. has no other legal basis for processing the personal data, the Customer’s personal data, with respect to which the objection was raised, will be deleted.
· Right to Erasure (“Right to be Forgotten”) – Legal basis: Article 17 GDPR.
a) The Customer has the right to request the erasure of all or part of their personal data.
b) The Customer has the right to request erasure of personal data if:
a. the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
b. they have withdrawn a specific consent, to the extent that the personal data were processed based on their consent;
c. they have objected to the use of their data for marketing purposes;
d. the personal data are processed unlawfully;
e. the personal data must be erased to comply with a legal obligation under European Union law or the law of a Member State to which EONLIFE BIOTECH sp. z o.o. is subject;
f. the personal data were collected in connection with the offer of information society services.
c) Despite a request for the erasure of personal data, in connection with an objection or withdrawal of consent, EONLIFE BIOTECH sp. z o.o. may retain certain personal data to the extent that processing is necessary for establishing, asserting, or defending claims, as well as for compliance with a legal obligation requiring processing under European Union or Member State law to which EONLIFE BIOTECH sp. z o.o. is subject. This applies in particular to personal data such as: first name, last name, email address, which are retained for handling complaints and claims related to the use of EONLIFE BIOTECH sp. z o.o. services, as well as (if applicable) home address/correspondence address, order number, which are retained for handling complaints and claims related to concluded sales or service agreements.
The data retention period for accounting purposes is 5 years, counted from the end of the calendar year in which the tax payment deadline for the relevant agreement expired, in accordance with the statute of limitations for tax liabilities in the Republic of Poland.
· Right to Restrict Processing – Legal basis: Article 18 GDPR.
a) The Customer has the right to request the restriction of processing of their personal data. Submitting such a request, until it is reviewed, makes it impossible to use specific functionalities or services that require processing of the data covered by the request. EONLIFE BIOTECH sp. z o.o. will also not send any communications, including marketing communications.
b) The Customer has the right to request restriction of personal data processing in the following cases:
a. when they contest the accuracy of their personal data – in which case EONLIFE BIOTECH sp. z o.o. will restrict their use for the time necessary to verify the accuracy of the data, but no longer than 30 days;
b. when processing is unlawful, but instead of erasure the Customer requests restriction of their use;
c. when the personal data are no longer necessary for the purposes for which they were collected or used, but are required by the Customer for establishing, asserting, or defending claims;
d. when they have objected to the use of their data – in which case restriction occurs for the time needed to determine whether the protection of the Customer’s interests, rights, and freedoms outweighs the interests pursued by the Controller in processing the Customer’s personal data.
· Right of Access to Data – Legal basis: Article 15 GDPR.
a) The Customer has the right to obtain from the Controller confirmation as to whether or not their personal data are being processed, and if so, the Customer has the right to:
a. access their personal data;
b. obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of such data, the planned retention period or criteria for determining that period (where it is not possible to specify the planned retention period), rights under the GDPR and the right to lodge a complaint with a supervisory authority, the source of the data, automated decision-making including profiling, and safeguards applied in connection with the transfer of such data outside the European Union;
c. obtain a copy of their personal data.
· Right to Rectification – Legal basis: Article 16 GDPR.
a) The Customer has the right to request the Controller to promptly rectify any inaccurate personal data concerning them. Taking into account the purposes of the processing, the Customer also has the right to request the completion of incomplete personal data, including by providing a supplementary statement, by sending a request to the email address specified in §7 of the Privacy Policy.
· Right to Data Portability – Legal basis: Article 20 GDPR.
a) The Customer has the right to receive their personal data provided to the Controller and to transmit those data to another controller of their choice. The Customer also has the right to request that the personal data be transferred by the Controller directly to another controller, where technically feasible. In such a case, the Controller will provide the Customer’s personal data in a csv file format, which is a commonly used, machine-readable format that allows the transfer of the received data to another data controller.
· Where the Customer exercises any of the above rights, EONLIFE BIOTECH sp. z o.o. shall fulfill or refuse to fulfill the request without undue delay, but no later than within one month of receiving it. However, if – due to the complex nature of the request or the number of requests – EONLIFE BIOTECH sp. z o.o. is unable to fulfill the request within one month, it will fulfill it within the following two months, informing the Customer within one month of receiving the request about the intended extension of the deadline and its reasons.
· The Customer may submit complaints, inquiries, and requests to the Controller regarding the processing of their personal data and the exercise of their rights.
· The Customer has the right to request EONLIFE BIOTECH sp. z o.o. to provide a copy of the standard contractual clauses by submitting a request in the manner indicated in §7 of the Privacy Policy.
· The Customer has the right to lodge a complaint with the President of the Personal Data Protection Office regarding any infringement of their rights to personal data protection or other rights granted under the GDPR.
§ 5 Services Tailored to Preferences and Interests (Profiling)
1. Profiling means any form of automated processing of Personal Data, which consists of the use of Personal Data to assess certain personal factors relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
2. Customers’ personal data may be processed in an automated manner (profiling); however, this will not result in any legal effects concerning them or similarly significantly affect their situation.
3. Profiling of personal data by EONLIFE BIOTECH sp. z o.o. consists of processing Customers’ data both automatically and manually, by using such data to assess certain information about the Customer, in particular to analyze or predict their personal preferences and interests.
4. In order to reach the Customer with marketing communications outside of the Online Store, EONLIFE BIOTECH sp. z o.o. uses services of external providers. These services involve displaying marketing communications on websites other than the Online Store. For this purpose, external providers install, for example, appropriate code or a pixel to collect information about the Customer’s activity on the Online Store website. Details regarding the cookies used can be found in §3. Legal basis – legitimate interest (Article 6(1)(f) GDPR), consisting in tailoring marketing communications to preferences and interests.
5. In order to reach the Customer with marketing communications outside of the Online Store, EONLIFE BIOTECH sp. z o.o. uses services of external providers. These services involve displaying marketing communications on websites other than the Online Store. For this purpose, external providers install, for example, appropriate code or a pixel to collect information about the Customer’s activity on the Online Store website. Details regarding the cookies used can be found in §3. Legal basis – consent of the data subject (Article 6(1)(a) GDPR), consisting in tailoring marketing communications to preferences and interests.
§ 6 Security Management – Password
1. EONLIFE BIOTECH sp. z o.o. provides Customers with a secure and encrypted connection when transmitting personal data and when logging in to the Customer Account on the Service. EONLIFE BIOTECH sp. z o.o. uses an SSL certificate issued by one of the leading global companies in the field of security and data encryption transmitted over the Internet.
2. If a Customer with an account in the Online Store loses access to their password in any way, the Online Store enables the generation of a new password. EONLIFE BIOTECH sp. z o.o. does not send password reminders. The password is stored in the database in encrypted form, in a way that makes it impossible to read. To generate a new password, you must enter your email address in the form available via the “Forgot your password” link provided on the login form to the Online Store account. The new password will be automatically sent to the email address provided during registration or last saved in the account profile update.
3. EONLIFE BIOTECH sp. z o.o. never sends any correspondence, including electronic correspondence, requesting login data, especially the Customer’s account password.
§ 7 Changes to the Privacy Policy
1. The Privacy Policy may be amended, of which EONLIFE BIOTECH sp. z o.o. will inform Customers in advance, at least 7 days prior to the change.
2. Questions regarding the Privacy Policy should be addressed to our Data Protection Officer at: rodo@eonlife.
3. Date of last modification: 30.01.2025.