effective from 1. April 2021
Personal data is various types of information about you. This includes information such as e.g. your first name and surname, e-mail address, postal address, telephone number. Personal data are collected during your use of the Hebe Beauty Supply Store Website  (e.g. when you complete the contact form, place orders or browse the website). The Data Controller may process the personal data of Customers (as defined in the Terms of Sale) of the Hebe Beauty Supply Store Website and of other persons visiting the Data Controller’s profiles relating to the Hebe Beauty Supply Store Website, e.g. on Facebook, Instagram, YouTube in relation to the maintenance of those profiles (“Users ”).
We respect your right to privacy; therefore, please be informed that the controller of your personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L No. 110, p. 1) (hereinafter: GDPR) is Jeronimo Martins Drogerie i Farmacja Sp. z o.o. with registered office in Kostrzyn (62-025) at ul. Żniwna 5 (hereinafter: Data Controller). See below for detailed information about the processing of your personal data:
1. How can I contact the Data Controller?
In all matters relating to the processing of personal data on the Hebe Beauty Supply Store Website, including the exercise of rights related to personal data, the Data Controller can be contacted by e-mail at firstname.lastname@example.org, by telephone at +48 22 206 54 00 or in writing to the following address: Jeronimo Martins Drogerie i Farmacja Sp. z o.o., ul. Żniwna 5, 62-025, Kostrzyn.
2. How can I contact the Data Protection Officer?
The Data Controller has appointed a Data Protection Officer who can be contacted by e-mail at email@example.com. The Data Protection Officer can be contacted in all matters concerning the processing of personal data.
3. What are the purposes and grounds of personal data processing?
Personal data may be processed for the purposes specified in the table below. Providing personal data is voluntary, but may be necessary to use certain functionalities of the Hebe Beauty Supply Store Website or the Data Controller's social media accounts, and failure to provide such data will result in inability to use the specific service.
Article 6 clause 1 letter “b” GDPR
Processing is necessary for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract
Article 6 clause 1 letter “c” GDPR
Legal obligation (e.g. tax, accounting, civil and consumer law)
· to carry out after-sales activities, e.g. to encourage customers to leave their opinions on the Hebe Beauty Supply Store Website, i.e. to increase the attractiveness of offered products and to support the decision making process regarding the purchase of a given product;
· to operate accounts of the Hebe Beauty Supply Store Website on social networking sites with the aim to promote the Controller's image, to inform about campaigns, competitions and events organized by the Controller, to promote products, services and other offers of the Hebe Beauty Supply Store Website, and to communicate via such profiles in social media, i.e. to promote the image, brand and the Hebe Online Beauty Supply Store and to keep a circle of followers of the social media profiles.
Article 6 clause 1 letter “f” GDPR
The Controller’s legitimate interests that follow from the processes and interests described in the right column
Article 6 clause 1 letter “a” GDPR
4. What personal data are required to create an Account and to place orders?
a) Creating an Account at Hebe Online Beauty Supply Store
To register and create your Account at Hebe Online Beauty Supply Store, you need to complete the account registration form. First name, surname, email address, mobile phone number and password are the personal data that must be provided to create and operate an Account at Hebe Online Beauty Supply Store (contractual obligation). Optional data – the birth date – can be provided on voluntary basis and involve additional benefits (for example, providing your birth date, you gain access to a birthday offer). Providing your date of birth, you thereby consent to its processing. Providing data is voluntary, but necessary to create an Account. Failing to provide the personal data indicated in this section, you will not be able create an Account at the Hebe Online Beauty Supply Store, and failing to provide the optional personal data will make it impossible to take advantage of additional benefits.
b) Order placement and processing at Hebe Online Beauty Supply Store
To place an order at Hebe Online Beauty Supply Store, a customer who is registered and logged in provides the required personal data, i.e. his/her first name, surname, mobile phone number and - depending on the choice of delivery method - the delivery address, while an unregistered customer (guest) additionally provides an e-mail address and mobile phone number, which data are necessary to process and complete the order at Hebe Online Beauty Supply Store and the customer’s failure to provide them invalidates the order.
5. Are my personal data being profiled?
Data obtained from the profiling of logged-in customers will also available for use in the Controller's other online store, i.e. the store located at hebe.pl ("Hebe.pl"). Customers will log in to that store using the same account as on Hebe.com. This integration of profiles will only apply to persons who use the same account on both websites.
6. What are my rights relating to the processing of my personal data?
(i) Under GDPR and to the extent provided therein, your rights related to the processing of personal data are as follows:
a) right of access to data;
b) right to obtain a copy of data;
c) right to rectification and completion of incomplete data;
d) right to erasure of data
e) right to restriction of data processing;
f) right to transfer data;
g) right to object to data processing for marketing and the Controller's other legitimate purposes;
h) right to withdraw consent – the data subject whose data are processed with his/her consent may withdraw such consent at any time. The withdrawal of consent does not affect the lawfulness of data processing performed on the basis of such consent before its withdrawal;
i) right to lodge a complaint with the supervisory authority for personal data protection.
(ii) The intention to exercise the rights indicated above may be notified:
- via the contact form available on the Hebe.com website, tab: Biuro Obsługi Klienta (kontakt) [Customer Service (contact)];
- via the contact form available on the Hebe.com websitep after logging in to Customer Account, tab: Moje Konto/Moje Prawa [My Account / My Rights];
- by e-mail to the address: firstname.lastname@example.org
- in writing, by sending a statement to the Controller’s address: Jeronimo Martins Drogerie i Farmacje Sp. z o.o., ul. Żniwna 5, 62-025, Kostrzyn
- by phone at: +48 22 206 54 00.
You can exercise your right to complain to the supervisory authority for personal data protection by filing a complaint directly with that authority. A list of European supervisory authorities for personal data protection is available at https://edpb.europa.eu/about-edpb/board/members_en.
(iii) The statement submitted to the Data Controller under (ii) above should, to the extent possible, specify the following:
- the right which the person filing the statement wishes to exercise;
- the service for which data are processed (e.g. placement of order at Hebe Online Beauty Supply Store);
- the purposes of processing concerned.
The Controller reserves the right to request additional information from the person making the statement if the the content of the statement cannot be detrermined or the person making the statement cannot be identified.
7. What are the sources of my personal data?
(i) We collect personal data directly from the data subject when he or she uses the Hebe Online Beauty Supply Store or interacts with the social networking site account.
(ii) The Controller may also collect third parties’ personal data provided by you. When providing the data of third parties on the Hebe Beauty Supply Store Website, you may do so under the condition that you do not violate the personal interests of those third parties and respect the applicable law.
8. How long are personal data stored?
(i) The Controller stores personal data adequately and for as long as necessary for the purposes for which they were collected or, if necessary, to comply with applicable law. The length of the period when the Controller processes data depends on the type of service provided and the purpose of the processing.
(ii) Personal data are stored as follows:
o for the duration of the service, which includes services provided electronically and creation of Account at the Hebe Beauty Supply Store (e.g. processing continues until the Account is deleted); except, the Controller stores information about the deleted Account for 30 days in order to enable its possible restoration;
o for the duration of order performance within the Hebe Online Beauty Supply Store. Due to tax and accounting obligations, the Controller will store some of such personal data for a period of 6 years from the date of completion of the respective contracts;
o personal data required for handling a complaint will be stored until expiration of entitlements on that account;
o personal data provided for the purpose of contacting the Controller will be stored for the duration of the contact, and then archived for 30 days after the end of contact, if necessary and justified by the need to reconstruct the content of such contact;
o until withdrawal of consent given (applies e.g. to data processed for the purpose of sending electronic newsletters, behavior data collected on the website through cookies, geolocation data); or
o until a successful objection to data processing is filed in cases where the legal basis of data processing is the Controller’s legitimate interest; this includes an objection to data processing for the purposes of direct marketing.
The data processing period may be longer if the processing is necessary for the establishment and assertion of or defense against claims, taking into account the limitation periods for the relevant claims (e.g. under a sales contract).
After the storage period, personal data are erased or irreversibly anonymized.
Besides, the Data Controller collects information about your behavior for the purpose of sending marketing messages, such as push notifications, text messages and the newsletter, as well as geolocation data, for no longer than the duration of your Account, unless you withdraw consent or successfully object to the processing of data.
9. Who are personal data shared with?
The Data Controller may share personal data with the following recipients or categories of recipients:
- the providers of services for the Controller or on behalf of the Controller (e.g. PR/marketing agencies, IT service providers, payment or deferred payment service providers, banks, courier companies in connection with order processing, telecommunications operators);
- business partners and other companies of the Controller's capital group;
- If such an obligation arises from applicable laws, the Controller may also make personal data available to third parties, in particular to authorized state agencies.
10. Are my personal data transferred outside the EEA?
(i) The Controller stores personal data within the EEA. Due to the location of some of our suppliers, the data of users of the Hebe Beauty Supply Store Website or of our services may be transferred by the Controller to countries outside the EEA where data protection laws differ from those in force in the EEA, including to countries, where the adequate protection assurance decision has not been issued.
(ii) In the case of personal data transfers to recipients located in third countries, including the United States, the Controller will use mechanisms compliant with applicable law, which include (1.) conclusion of an agreement in the form of the European Commission's "Standard Contractual Clauses", taking into account the circumstances of the transfer and complementary measures added after each analysis of the circumstances surrounding the transfer to ensure that the transfer does not adversely affect the adequate level of protection, (2.) transfer of data to a recipient located in a third country for which the European Commission has established by decision that such third country assures an adequate level of data protection, (3.) transfer with the data subject's explicit consent.
(iii) In the case of transfers to third countries, more information about the existing safeguards implemented by the Controller to ensure the processing of personal data in accordance with the regulations and about the possibilities of obtaining a copy of the data or about the place where the data are made available can be obtained by contacting the Controller at: email@example.com.
 The Hebe Beauty Supply Store Website or Hebe Online Beauty Supply Store is an Internet platform available at www.hebe.com for online retail sales of products and provision of electronic services offered by the Administrator, operated by the Administrator and governed by rules set forth in the Rules/Terms & Conditions available on the website.