Refund policy

This document sets out the rules of the Privacy Policy of the Online Store (hereinafter referred to as the “Online Store”). The controller of your data is IMU MEDICAL S.A. company, with its registered office in Piaseczno at ul. Kościuszki 10/1, 05-500 Piaseczno, using the tax number NIP: 123-153-23-29, and the e-mail address: biuro@auronn.com. Capitalized terms have the meaning assigned to them in the regulations of this Online Store. Personal data collected by the Online Store Administrator are processed in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119, p. 1), hereinafter: GDPR. The Online Store Administrator makes every effort to protect the privacy and information provided to him, relating to the Customers of the Online Store. The Administrator diligently selects and applies appropriate technical, programming, and organizational measures to ensure the protection of processed data, in particular safeguarding the data against unauthorized access, disclosure, loss, destruction, unlawful modification, and processing in violation of applicable law. The goods and services available on the website are not intended for children under the age of 16. The Administrator does not intentionally collect data concerning children under the age of 16. Personal Data Data Controller The controller of your personal data is: IMU MEDICAL S.A. with its registered office in Piaseczno, ul. Kościuszki 10/1, 05-500 Piaseczno, using the tax number NIP: 123-153-23-29, and the e-mail address: biuro@auronn.com You can contact the Data Controller regarding your personal data via: • e-mail: biuro@auronn.com • traditional mail: ul. Kościuszki 10/1, 05-500 Piaseczno Purposes and Legal Basis for Processing The Data Controller processes your personal data for the following purposes and scope: • To take actions prior to concluding a contract at your request (e.g., creating an account), i.e., data provided in the registration form in the Online Store such as e-mail address, name, phone number, password, gender, and data necessary to fulfill an order such as shipping address; • To provide services that do not require an account or purchase of goods, i.e., browsing the Online Store pages and using the product search, we process data about your activity in the Online Store — e.g., viewed products, session, operating system, browser, location, unique ID, IP address; • To perform the sales contract for goods (e.g., delivery of ordered goods), we process personal data provided when purchasing goods such as name, e-mail address, address details, payment data, and if purchased through an account — additionally the password; • For statistical purposes, facilitating use of the site, ensuring IT security — data about your activity, time spent on pages, search history, location, IP address, device ID, browser and OS data; • To establish, pursue, and defend claims, we may process data provided at purchase or account creation and other necessary information arising from legal obligations or legal procedures; • To handle complaints, inquiries, and requests, we process data provided in forms, complaints, inquiries, and service/order-related data; • For marketing purposes, including remarketing, we process data provided at account creation and activity data in the Store (e.g., order history, searches, clicks, login dates, communication activity); • To organize contests and loyalty programs, we use data provided at registration in a contest or program; • For market and opinion research, we process information about the order, data from account creation or purchase, and e-mail address. Categories of Data We process the following categories of personal data: • contact details • activity data in the Online Store • order data • complaint, inquiry, and request data • marketing data Voluntariness of Providing Data Providing required personal data is voluntary but necessary to provide services through the Online Store. Data Retention Data will be processed for the period necessary to fulfill orders, services, marketing activities, and other services. Data will be deleted when: • the data subject requests deletion or withdraws consent • the data subject remains inactive for over 10 years • the data becomes outdated or inaccurate Certain data (e.g., e-mail, name) may be retained for 3 years for evidence purposes. Order data and loyalty/contest data are kept for 5 years from delivery. For non-logged-in customers, data is kept for the lifespan of cookies or until deleted. Data Recipients We may share your data with: • state authorities (e.g., prosecutor, police, data protection authority) if necessary • service providers (e.g., to fulfill orders), acting as processors or controllers Profiling Data may be processed automatically, including profiling, to tailor marketing messages to preferences. You have the right to object to profiling. Your Rights under GDPR You have the right to: • access your data (Art. 15) • rectify your data (Art. 16) • erase your data (“right to be forgotten”) (Art. 17) • restrict processing (Art. 18) • object to processing (Art. 21) • data portability (Art. 20) • withdraw consent at any time We will respond to your request without undue delay, no later than within one month. If you believe data processing violates GDPR, you may lodge a complaint with a supervisory authority (in Poland: President of the Personal Data Protection Office). Contact for exercising your rights: biuro@auronn.com Right of Access to Personal Data (Art. 15 GDPR) You have the right to obtain from the Controller information as to whether your personal data is being processed. If it is, you have the right to: • access your personal data; • obtain information about the purposes of processing, categories of data, recipients or categories of recipients, retention period or criteria for determining it, your rights under GDPR, the source of the data, automated decision-making (including profiling), and safeguards for data transferred outside the EU; • obtain a copy of your data. To request access to your data, please contact us at: biuro@auronn.com Right to Rectification of Personal Data (Art. 16 GDPR) If your data is incorrect, you have the right to request its prompt rectification or completion. To do so, please contact us at: biuro@auronn.com If you have an account in the Online Store, you can also rectify and complete your data yourself after logging in. Right to Erasure of Personal Data (“Right to be Forgotten”) (Art. 17 GDPR) You have the right to request the erasure of your data if: • the data is no longer necessary for the purposes for which it was collected or processed; • you withdraw your consent on which the processing is based; • the data was processed unlawfully; • you object to the processing of data for marketing purposes (including profiling); • you object to processing necessary for the performance of a task carried out in the public interest or for purposes arising from the legitimate interests of the Controller or a third party. Despite a request for erasure, the Controller may continue to process the data to establish, exercise, or defend legal claims — you will be informed of this. To request erasure of your data, please contact us at: biuro@auronn.com Right to Restrict Processing of Personal Data (Art. 18 GDPR) You have the right to request restriction of processing if: • you contest the accuracy of your data — processing will be restricted until accuracy is verified; • processing is unlawful but instead of erasure you request restriction of processing; • the data is no longer needed for processing purposes but is required to establish, exercise, or defend legal claims; • you have objected to processing — until it is determined whether the Controller’s legitimate grounds override yours. To request restriction of processing, please contact us at: biuro@auronn.com Right to Object to Processing of Personal Data (Art. 21 GDPR) You have the right at any time to object to the processing of your data, including profiling, in connection with: • processing necessary for the performance of a task carried out in the public interest or for purposes arising from the legitimate interests of the Controller; • processing for direct marketing purposes. To object, please contact us at: biuro@auronn.com Right to Data Portability (Art. 20 GDPR) You have the right to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller. You may also request that the Controller transfer your data directly to another controller, where technically feasible. To request data portability, please contact us at: biuro@auronn.com Right to Withdraw Consent You may withdraw your consent to the processing of your personal data at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. To withdraw your consent, please contact us at: biuro@auronn.com or use the appropriate functionalities in your Account. Complaint to Supervisory Authority If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged violation. In Poland, the supervisory authority is the President of the Personal Data Protection Office (PUODO).