Privacy & Cookies Policy

  1. Administrator of Personal Data
    The Administrator of personal data of the users of the online shop Canna-Sativa.pl is AN COMPANY LIMITED Sp. z o. o., registered address: Aleja Jana Pawła II 27, 00-867 Warszawa, tax ID (NIP)  PL5273141311.

  2. Scope and purpose of data processing
    The customers’ personal data is processed exclusively in the scope necessary to:
    • process orders and provide services related to online shopping,
    • contact the customer in matters related to an order,
    • implement marketing activities, including sending newsletters (exclusively for the users who gave their consent),
    • handle complaints and returns,
    • meet the accounting and tax requirements in accordance with the law.

  3. Types of processed data
    We process following personal data of our users:
    • name and surname,
    • delivery address and e-mail address,
    • phone number,
    • data regarding payment and purchase history (without storing sensitive data of payment cards),
    • data necessary to issue an invoice, if the user requests it.
  4. Basis of data processing
    The personal data is processed on following bases:
    • user’s consent (e.g. to receive a newsletter),
    • implement an agreement (product purchasing),
    • fulfil legal obligations resulting from accounting and tax rules,
    • administrator’s justified interest, such as carrying out statistical and marketing analyses.

  5. Sharing of personal data
    The customers’ personal data can be shared with:
    • parcel services and providers in order to deliver the ordered products,
    • payment operators, in order to support the transactions,
    • entities supporting the shop’s activity (e.g. IT companies), exclusively in the scope necessary to provide the services.

  6. Users’ rights
    Every user has a right to:
    • access their data and receive its copies,
    • rectify or complete the data if it is incorrect,
    • delete the data if it is not necessary anymore to process the orders,
    • limit the data processing in specific cases,
    • transfer the data to another administrator,
    • raise objection against the processing of personal data for marketing purposes,
    • withdraw the consent for data processing (without affecting the legality of the processing made before the withdrawal).
    To use these rights, please contact the administrator using the e-mail address given on the website.

  7. Data storage period
    The personal data will be stored for the period necessary to fulfil the purposes for which they have been collected:
    • in case of data related to order processing – for the time of order processing and additional time resulting from accounting obligations,
    • data for marketing purposes – until the user withdraws the consent.

  8. Data security
    We apply corresponding technical and organisational means to ensure the security of users’ personal data. The data is protected from being accessed by unauthorised persons, accidental loss, damage and unauthorised processing.

  9. Cookies
    The shop uses cookies in order to optimise the function of the website and statistical analysis. Cookies make it possible to adapt the offer to the user’s needs and improve the quality of our support. The user can manage cookies using the browser settings.

  10. Changes to the Privacy Policy
    The Administrator reserves a right to change this Privacy Policy if it will be required be the changes to the law or updates to the shop’s offer. The latest version of the Privacy Policy will be always published on the shop’s website.