Privacy Policy

I. General provisions
The privacy policy defines how personal data necessary for the provision of electronic services through the www.healthandnuts.eu website (hereinafter: the Service) are collected, processed, and stored.
The Service collects only personal data necessary for the provision and development of the services offered in it.
Personal data collected through the Service are processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter GDPR) and the Personal Data Protection Act of 10 May 2018.
II. Data Controller
The data controller for personal data collected through the Service is H&N Katarzyna Oskaldowicz, address: ul. Niedzwiedzia 20, 02-737 Warsaw, NIP: 9462487478, REGON: 525793391, email address: admin@healthandnuts.eu (hereinafter: the Administrator).
III. Purpose of collecting personal data
The Administrator processes personal data necessary for the provision and development of the services offered through the Service and its individual functionalities.
Personal data will be processed for the following purposes:

  • registration of an account, verification of the User’s identity, and the implementation of the agreement for the provision of electronic services in accordance with the Act of 18 July 2002 on the provision of electronic services, in particular by providing the User with the opportunity to use the User account – based on the acceptance of the terms of the Regulations (Article 6(1)(b) GDPR);
  • communication with the User to provide him with necessary information and build positive and reliable relationships with him, which constitutes the Administrator’s legitimate interest (Article 6(1)(f) GDPR);
  • promotion by the Administrator of its own products and/or services, as well as those of its Partners, by sending electronic information (newsletter) if the User has consented to receive such notifications via email (Article 6(1)(a) GDPR);
  • providing access to information about industry news directly related to the Administrator’s business, if the User has consented to receive such notifications via email (Article 6(1)(a) GDPR);
  • for analytical and statistical purposes based on the Administrator’s legitimate interest in verifying User activity and preferences to optimize the services and products as well as the functionalities of the Service (Article 6(1)(f) GDPR);
  • for the possible establishment, investigation of claims, or defense against them based on the Administrator’s legitimate interest in protecting its rights (Article 6(1)(f) GDPR).
  • In each of the cases mentioned above (point 2), providing data is voluntary but necessary to conclude an agreement or use other functionalities of the Service.

IV. Type of processed personal data
The Administrator may process User’s personal data: first and last name, date of birth, address, email address, phone number, and NIP.
V. Period of personal data processing
User’s personal data will be processed for the period:

  • when the basis for data processing is the performance of the contract – until the expiration of claims after its performance,
  • when the basis for data processing is consent – until its withdrawal, and after the withdrawal of consent until the expiration of claims.
  • In both cases, the limitation period is 6 years, and for claims for periodic benefits and claims related to business activity – 3 years (unless a specific provision provides otherwise).

VI. Disclosure of personal data
User’s personal data may be transferred to entities affiliated with the Administrator, its subcontractors, entities cooperating with the Administrator, e.g., companies handling e-payments, courier/postal service companies, law firms.
User’s personal data will not be transferred outside the European Economic Area (EEA).
VII. User’s rights
The Service User has the right to: access their personal data, rectify, delete, limit processing, transfer, object to processing, withdraw consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal).
A User’s request related to the rights mentioned above should be sent to the address kasia@healthandnuts.eu.
The Administrator fulfills or refuses to fulfill the request immediately, but no later than within one month of its receipt.
The User has the right to lodge a complaint with the President of the Office for Personal Data Protection if they believe that the processing violates their rights and freedoms (GDPR).
VIII. Cookies
The Service collects information using cookies – session, permanent, and external entities.
Collecting cookies supports the proper provision of services on the Service and serves statistical purposes.
The User can specify the scope of access for cookies to their device in the browser settings.
IX. Automated decision-making and profiling
User data cannot be processed automatically in a way that would result in any decisions being made about them.
User data may be profiled to adapt content and personalize offers after their consent.
X. Final provisions
The Administrator has the right to make changes to the Privacy Policy, without limiting the User’s rights.
Information about the introduced changes will appear in the form of a message available on the Service.
In matters not regulated by this Privacy Policy, the provisions of the GDPR and the Polish law apply.