CONTENTS:

1) GENERAL PROVISIONS

1. This Website’s privacy policy is for information purposes only, which means that it does not impose any obligations on the Website’s users. The privacy policy primarily sets out the rules governing the processing of personal data by the Controller on the Website, including the legal basis, purposes and duration of such processing, as well as the rights of data subjects, and information regarding the use of cookies on the Website and

analytical tools.

2. The controller of the personal data collected via the Website is Anna Parzychowska-Parol, trading as NOVOLABS – Anna Parzychowska-Parol, registered in the Central

Register of Business Activity of the Republic of Poland maintained by the Minister responsible for the economy; with the following business address and address for service: Kraśnicza Wola 56, 05-825 Kraśnicza Wola, Tax Identification Number (NIP): 5441512625, REGON: 524934010, email address: kontakt@novolabs.pl – hereinafter referred to as the “Controller” and acting simultaneously as the Service Provider on the Website.

3. Personal data on the Website is processed by the Controller in accordance with applicable law, in particular in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as the “GDPR” or “GDPR Regulation”. Official text of the GDPR: https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679.

4. Use of the Website, including making purchases, is voluntary. Similarly, the provision of personal data by the Service User using the Website is voluntary, subject to two exceptions: (1) entering into contracts with the Controller – failure to provide, in the cases and to the extent specified on the Website, in the Website Terms and Conditions and in this privacy policy, the personal data necessary for the conclusion and performance of the Contract or any other agreement with the Controller will result in the inability to enter into such an agreement.

In such cases, the provision of personal data is a contractual requirement, and if the person who

If the data subject wishes to enter into a contract with the Controller, they are required to provide the necessary data. In each case, the scope of data required to conclude the contract is specified in advance on the Website and in the Website Terms and Conditions; (2) the Controller’s statutory obligations – the provision of personal data is a statutory requirement arising from generally applicable legal provisions imposing an obligation on the Controller to process data

personal data (e.g. for accounting purposes) and failure to provide such data will prevent the Controller from fulfilling these obligations.

5. The controller shall exercise due care to protect the interests of the data subjects whose personal data it processes, and in particular shall be responsible for and ensure that the data it collects: (1) is processed lawfully; (2) collected for specified, legitimate purposes and not further processed in a manner incompatible with those purposes; (3) factually accurate and relevant to the purposes for which they are processed; (4) stored in a form that enables

identifiable for no longer than is necessary to achieve the purpose of the processing; and (5) processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

6. Taking into account the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity of harm to the rights and freedoms of natural persons, the Controller shall implement appropriate technical and organisational measures to ensure that the processing is carried out in accordance with the GDPR and to be able to demonstrate this. These measures shall be reviewed and updated as necessary. The Controller shall implement technical measures to prevent unauthorised persons from accessing or altering personal data transmitted electronically.

7. All words, phrases and acronyms appearing in this privacy policy and beginning with a capital letter (e.g. Service Provider, Website, Electronic Service) shall be understood in accordance with their definitions set out in the Website Terms and Conditions available on the Website.

2) LEGAL BASIS FOR DATA PROCESSING

1. The controller is authorised to process personal data where – and to the extent that – at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specific purposes; (2) processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract; (3) processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where

the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, take precedence over those interests, in particular where the data subject is a child.

2. The processing of personal data by the Controller requires, in each case, the existence of at least one of the grounds set out in section 2.1 of the privacy policy. The specific grounds for the Controller’s processing of the personal data of Website Users are set out in the following section of the privacy policy – in relation to the specific purpose of the Controller’s processing of personal data.

3) PURPOSE, LEGAL BASIS AND DURATION OF DATA PROCESSING ON THE WEBSITE

1. In each case, the purpose, legal basis, duration and recipients of the personal data processed by the Controller are determined by the actions taken by the relevant User on the Website.

2. The Controller may process personal data on the Website for the following purposes, on the following legal grounds and for the following period:

Purpose of data processingLegal basis for data processingData retention period
The performance of a contract or an agreement for the provision of an electronic service, or the taking of action at the request of the data subject prior to the conclusion of a contract.Article 6(1)(b) of the GDPR (contract) – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contractThe data is retained for the period necessary to perform, terminate or otherwise bring to an end the contract entered into.
Direct marketingArticle 6(1)(f) of the GDPR (the controller’s legitimate interests) – processing is necessary for the purposes of the controller’s legitimate interests – which consist of safeguarding the interests and good reputation of the controller and its website, and striving to provide electronic services and sell productsData is retained for as long as the legitimate interest pursued by the Controller exists, but for no longer than the limitation period for the Controller’s claims against the data subject arising from the Controller’s business activities. The limitation period is determined by law, in particular the Civil Code (the basic limitation period for claims relating to the conduct of business activities is three years). The Controller may not process data for direct marketing purposes if the data subject has effectively objected to such processing.
MarketingArticle 6(1)(a) of the GDPR (consent) – the data subject has given consent to the processing of their personal data for the purpose of receiving marketing communications from the Controller, e.g. by emailThe data is retained until the data subject withdraws their consent to the further processing of their data for this purpose.
Keeping tax recordsArticle 6(1)(c) of the GDPR in conjunction with Article 86(1) of the Tax Ordinance of 17 January 2017 (Journal of Laws of 2017, item 201, as amended) – processing is necessary for compliance with a legal obligation to which the Controller is subjectThe data is retained for the period required by the legislation obliging the Controller to keep tax records (until the expiry of the limitation period for tax liabilities, unless otherwise provided for in tax legislation).
The establishment, pursuit or defence of claims that may be brought by the Controller or against the ControllerArticle 6(1)(f) of the GDPR (the controller’s legitimate interests) – processing is necessary for the purposes of the controller’s legitimate interests – consisting in the establishment, exercise or defence of legal claims which the controller may bring or which may be brought against the controllerThe data is retained for as long as the legitimate interest pursued by the Controller persists, but for no longer than the limitation period for claims that may be brought against the Controller (the standard limitation period for claims against the Controller is six years).
Using the Website and ensuring it functions properlyArticle 6(1)(f) of the GDPR (the controller’s legitimate interests) – processing is necessary for the purposes of the controller’s legitimate interests, which consist in establishing and maintaining the WebsiteData is retained for as long as the legitimate interest pursued by the Controller persists, but for no longer than the limitation period for the Controller’s claims against the data subject arising from the Controller’s business activities. The limitation period is determined by law, in particular the Civil Code (the basic limitation period for claims relating to the conduct of business activities is three years).
Keeping statistics and analysing traffic on the websiteArticle 6(1)(f) of the GDPR (the controller’s legitimate interests) – processing is necessary for the purposes of the controller’s legitimate interests, which consist of compiling statistics and analysing traffic on the Website in order to improve the functioning of the WebsiteData is retained for as long as the legitimate interest pursued by the Controller persists, but for no longer than the limitation period for the Controller’s claims against the data subject arising from the Controller’s business activities. The limitation period is determined by law, in particular the Civil Code (the basic limitation period for claims relating to the conduct of business activities is three years).

4) RECIPIENTS OF DATA ON THE WEBSITE

1. For the Website to function properly, including the proper provision of Electronic Services and delivery of Products by the Controller, it is necessary for the Controller to use the services of third parties (such as software providers and payment processors). The Administrator uses only the services of such processors who provide sufficient guarantees that appropriate technical and organisational measures will be implemented so that the processing meets the requirements of the GDPR and protects the rights of individuals,

the data subjects concerned.

2. Personal data may be transferred by the Controller to a third country; however, the Controller ensures that, in such cases, the transfer will take place to a country providing an adequate level of protection – in accordance with the GDPR – and, in the case of other countries, that the transfer will be based on standard data protection clauses. The Controller ensures that the data subject has the opportunity to obtain a copy of their data. The Controller transfers the collected personal data only where and to the extent necessary to fulfil the specific purpose of data processing in accordance with this privacy policy.

3. The Controller does not disclose data in every instance, nor to all recipients or categories of recipients listed in the privacy policy – the Controller discloses data only where this is necessary to achieve the specific purpose of processing personal data, and only to the extent necessary to achieve that purpose.

4. The personal data of Customers/Users of the Website may be disclosed to the following recipients or categories of recipients:

a. carriers / freight forwarders / courier brokers / entities managing the warehouse and/or the dispatch process – in the case of a Customer who, on the Website, opts for delivery of the Product by courier, The Controller shall make the Service User’s personal data available to the selected carrier, freight forwarder or intermediary handling shipments on the Controller’s behalf, and if the shipment originates from an external warehouse – to the entity managing the warehouse and/or the dispatch process – to the extent necessary to deliver the Product to the Service User

b. entities processing electronic or card payments – in the case of a Service User who uses electronic or card payment methods on the Website, the Controller shall make the Service User’s personal data available to the selected entity handling such payments on the Website, acting on the Controller’s behalf, to the extent necessary to process the payment made by the Service User.

c. service providers supplying the Controller with technical, IT and organisational solutions enabling the Controller to conduct business activities, including the Website and the Electronic Services provided through it (in particular, suppliers of computer software for operating the Website, email and hosting providers, and suppliers of business management software and technical support to the Controller) – The Controller shall make the collected personal data available to a selected service provider acting on its behalf only where and to the extent necessary to achieve the specific purpose of data processing in accordance with this privacy policy.

d. providers of accounting, legal and advisory services who provide the Controller with accounting, legal or advisory support (in particular, an accounting firm, a law firm or a debt collection agency) – The Controller shall make the collected personal data available to a selected service provider acting on its behalf only where and to the extent necessary to achieve the specific purpose of data processing in accordance with this privacy policy.

5) PROFILING ON THE WEBSITE

1. The GDPR imposes an obligation on the Controller to provide information regarding automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR, and – at least in such cases – relevant information on the principles governing such decision-making, as well as the significance and anticipated consequences of such processing for the data subject. With this in mind, the Controller provides information in this section of the privacy policy regarding possible

profiling.

1. The Controller may use profiling on the Website for direct marketing purposes, but decisions made by the Controller on this basis do not relate to the conclusion or refusal to conclude a Contract, nor to the ability to use the Electronic Services on the Website. The use of profiling on the Website may result, for example, in a reminder about unfinished actions on the Website, the sending of a discount, or a proposal for a Product which may

to match a person’s interests or preferences, or to offer better terms than those of the Website’s standard offer. Despite profiling, it is the individual who freely decides whether to take advantage of, for example, an offer or discount received in this way.

2. Profiling on the Website involves the automatic analysis or prediction of a person’s behaviour on the Website, or through an analysis of their previous activity on the Website. Such profiling requires the Data Controller to hold the person’s personal data in order to subsequently send them, for example, a discount code or an offer.

3. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

6) RIGHTS OF THE DATA SUBJECT

1. Right of access, rectification, restriction, erasure or data portability – the data subject has the right to request from the Controller access to their personal data, its rectification, erasure (‘right to be forgotten’) or restriction of processing, and has the right to object to the processing, as well as the right to data portability. The detailed conditions for exercising the above rights are set out in Articles 15–21 of the GDPR.

4. The right to withdraw consent at any time – a data subject whose data is processed by the Controller on the basis of consent (pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR), has the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent prior to its withdrawal.

5. Right to lodge a complaint with a supervisory authority – a data subject whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and in accordance with the procedures set out in the GDPR and under Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office.

6. Right to object – the data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data based on Article 6(1)(e) (public interest or public tasks) or (f) (the controller’s legitimate interest), including profiling based on those provisions. In such a case, the controller may no longer process that personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject

the data relates to, or the grounds for establishing, pursuing or defending claims.

7. Right to object to direct marketing – where personal data is processed for the purposes of direct marketing, the data subject has the right to object at any time to the processing of their personal data for such marketing purposes, including profiling, to the extent that the processing is related to such direct marketing.

8. To exercise the rights referred to in this section of the privacy policy, you may contact the Controller by sending a written request or an email to the Controller’s address provided at the beginning of the privacy policy.

7) COOKIES ON THE WEBSITE AND ANALYTICS

1. Cookies are small pieces of text information in the form of text files, sent by the server and stored on the device of the person visiting the Website (e.g. on the hard drive of a computer or laptop, or on a smartphone’s memory card – depending on the device used by the visitor to the Website). Detailed information regarding cookies, as well as the history

Information on their origins can be found, for example, here: https://pl.wikipedia.org/wiki/HTTP_cookie.

2. Cookies that may be sent by the Website can be categorised into different types according to the following criteria:

Depending on their source: 1) proprietary (created by the Administrator’s website) and 2) belonging to third parties (other than the Administrator)Depending on how long they are stored on the device of a visitor to the Website: 1) session cookies (stored until the user logs out of the Website or closes their web browser) and 2) persistent cookies (stored for a specified period, as defined by the parameters of each fileDepending on their purpose: 1) essential (enabling the proper functioning of the Website), 2) functional/preference-based (enabling the Website to be tailored to the visitor’s preferences), 3) analytical and performance-related(collecting information on how the Website is used or until manually deleted), 4) marketing, advertising and social media (collecting information about the visitor to the Website in order to display advertisements to that person, personalise them and carry out other marketing activities, including on websites separate from the Website, such as social media platforms or other sites belonging to the same advertising network as the Website)

3. The controller may process the data contained in cookies when visitors use the website for the following specific purposes:

The purposes of using cookies on the Administrator’s websiteto identify Users as logged in to the Website and to display that they are logged in (necessary cookies)
to remember the products added to the online shopping basket so that an order can be placed (essential cookies)
storing data from completed forms, surveys or login details for the Website (essential, functional or preference cookies)
to tailor the content of the Website to the User’s individual preferences (e.g. regarding colours, font size and page layout) and to optimise the use of the Website (functional/preference cookies)
to compile anonymous statistics on how the Website is used (analytical and performance cookies)
displaying and rendering adverts, limiting the number of adverts displayed and blocking adverts that a person does not wish to see, measuring the effectiveness of adverts, as well as personalising adverts, i.e. analysing the behavioural characteristics of visitors to the Website through anonymous analysis of their activities (e.g. repeated visits to specific pages, keywords, etc.) in order to create a profile of them and deliver advertisements tailored to their anticipated interests, including when they visit other websites within the advertising networks of Google Ireland Ltd. and Facebook, i.e. Meta Platforms Ireland Ltd. (marketing, advertising and social media cookies)

4. You can check which cookies (including their duration and provider) are currently being sent by the Website in the most popular web browsers as follows:

In Chrome: (1) click the padlock icon on the left-hand side of the address bar, (2) go to the ‘Files’ tabIn Firefox: (1) click the shield icon on the left-hand side of the address bar, (2) go to the ‘Allowed’ tab orIn Internet Explorer: (1) click the ‘Tools’ menu, (2) go to the ‘Internet Options’ tab, (3) go to ‘Cookies’. “Blocked”, (3) click the “Cross-site tracking cookies”, “Social tracking elements” or “Content with tracking elements” checkbox on the “General” tab, (4) go to the “Settings” tab, (5) click the “View files” button
In the Opera browser: (1) click the padlock icon on the left-hand side of the address bar, (2) go to the ‘Cookies’ tab.In Safari: (1) click the ‘Preferences’ menu, (2) go to the ‘Privacy’ tab, (3) click the ‘Manage website data’ boxRegardless of which browser you use, you can use the tools available, for example, on the following websites: https://www.cookiemetrix.com/lub: https://www.cookie-checker.com/

5. By default, most web browsers available on the market accept cookies. Everyone has the option to specify the conditions for the use of cookies via their own web browser settings. This means that you can, for example, partially restrict (e.g. temporarily) or completely disable the saving of cookies – in the latter case, however, this may affect certain features of the Website.

6. Your web browser’s cookie settings are relevant to your consent to the Website’s use of cookies – in accordance with the relevant regulations, such consent may also be given via your web browser settings. Detailed information on changing cookie settings and deleting cookies yourself in the most popular web browsers is available in the browser’s help section and at the following links

on the following pages:

  • in the Chrome browser
  • in the Firefox browser
  • in Internet Explorer
  • in the Opera browser
  • in the Safari browser
  • in the Microsoft Edge browser

4. The Controller may use Google Analytics and Universal Analytics services on the Website, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These services help the Administrator to compile statistics and analyse traffic on the Website. The data collected is processed within the framework of the above services to generate statistics that assist in the administration of the Website and the analysis of traffic on the Website. This data is of an aggregated nature. By using the above services on the Website, the Administrator collects data such as sources and

the source of visitors to the Website and their behaviour on the Website, information about the devices and browsers they use to visit the site, their IP address and domain, geographical data, demographic data (age, gender) and interests.

5. Users can easily prevent their activity on the Website from being shared with Google Analytics – to do so, they can, for example, install the browser add-on provided by Google Ireland Ltd., which is available here: https://tools.google.com/dlpage/gaoptout?hl=pl.

7. As the Controller may use advertising and analytics services provided by Google Ireland Ltd. on the Website, the Controller notes that full information regarding the rules for the processing of data relating to visitors to the Website (including information stored in cookies) by Google Ireland Ltd. can be found in Google’s privacy policy, available at: https://policies.google.com/technologies/partner-sites.

8) FINAL PROVISIONS

The Website may contain links to other websites. The Administrator urges you to familiarise yourself with the privacy policy in place on those websites once you have visited them. This privacy policy applies only to the Administrator’s Website.