Elfa|Group Privacy Statement

Welcome! Elfa Group ("Elfa Group," "we" or "us") respects your personal data and fulfils all mandatory requirements.
We are committed to protecting the rights of individuals in line with the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.

Personal Data collected in the course of your business relationship with Elfa Group and during your usage of our websites is processed by us in accordance with the legal regulations in force for the countries in which Elfa Group does business and where these websites are maintained. However, your business relationship with Elfa Group and the Website may include links to other websites or applications that are not necessarily covered by this Privacy Statement. In this case, we recommend that you carefully read the relevant privacy policies.

Unless a specific Privacy Statement is configured for processing as defined here below, this Privacy Statement informs you of the Personal Data that we collect in the course of Elfa Group's activities.

Determination what is Personal Data

Personal Data is information that can be used to directly or indirectly identify a person. "Personal identifier" is information that can identify a person. This definition covers the wide range of personal identifiers that constitute personal data, including name, identification number, location data, address, email address, or online identifier.

Sources of Personal Data

During the contractual or customer relationship between you or your organization and Elfa Group when accessing use of Elfa Group websites, we will collect, use and process the Personal Data you provide when necessary. The following data categories may be collected:

    • Identification data: name, surname, date of birth, contact information (position, work phone number, employer's name), photos, videos, voice.
    • Economic and financial data: for processing payments and preventing fraud, such as the organization's IBAN, bank identification number and other payment information.
    • IT data: IP address, user account, type of web browser, operating system incl. user interface, the website from which you are visiting us, the date and duration of your visit,
    • We may collect this Personal Data together:
    • directly from you by filling out the form, providing your contact details by going to our websites,
    • indirectly from your organization where you work, when necessary, to achieve one or more of the objectives listed below.

Purposes for Personal Data processing

While you work with Elfa Group or use the Website(s), Elfa Group may process your Personal Data for the following purposes such as:

1. Administration.

• We may use your Personal Information for administrative purposes, such as: to help us better understand how our customers, suppliers and third parties access and use our Websites; to provide reports to potential partners, service providers, regulators and others; to enforce and maintain security, and enforce our policies, directives and processes.

2. Marketing.

• Subject to conditions permitted by law and where appropriate, we may use your Personal Data for marketing and advertising purposes, including communications by email or similar electronic means.

Elfa Group processes your Personal Data to carry out marketing activities, which may consist of:

• directing e-mail notifications of offers or content that in some cases contain commercial information;
• other direct marketing of goods and services (electronic commercial communication and telemarketing).

3. Communication.

• We may use your Personal Information to contact you, including sending you requests for assistance. We may communicate with you in a variety of ways, including email, your social media accounts (if your agreement is granted), and contact forms.
• We may use your Personal Data for our internal and external communications, public social networks, and for managing events (conferences, fairs, seminars).
• We may collect your personal information in order to inform you about the Elfa Group, its financial results, its products and other issues related to the Elfa Group. Information includes regular updates on major events, such as financial results publication, event invitations, special campaigns, and other items related to Elfa Group's business, securities and performance.

4. Customer service.

• We may use your Personal Data for sales and customer service of the Elfa Group, including customer relationship management, for technical support or other similar purposes, and for the creation and maintenance of customer accounts.
• We may process your Personal Data in the course of Elfa Group's procurement activities (contracts for new products or services and supplier management).
• We may process your Personal Data in the course of managing public relations of Elfa Group and / or managing intellectual property rights, managing guest trips.
•We may use your Personal Data for research and development purposes, including improving our websites, applications, services, customer experience, and for other research and analytical purposes dedicated to improving our products, services, businesses, operations and processes.

5. To protect us and others.

We will only use your Personal Data for the Purposes listed above unless we deem it reasonable that we need to use it for another reason and that reason is consistent with the original purpose (to retain specific evidence in accordance with applicable data protection laws and regulations or in the context of the statute of limitations, for example). If we need to use your Personal Data for unrelated purposes, we will notify you prior to this further processing of Personal Data and provide you with an appropriate Privacy Statement.

Legal grounds for Personal Data processing

We process your Personal Data only where there are legal grounds to do so.

The legal basis for the processing of your Personal Data is:

1. Compliance with contractual obligations.
When you subscribe to a particular service through the Website, the purposes of processing your Personal Data are primarily determined by that service, and we will process your information so that we can provide you with this service.

2. As a result of your consent.

If you have consented to our processing of your Personal Data for certain services through the Website, you can withdraw consent at any time by following the instructions provided in the application process or by contacting us at -[email protected]

3. Within the framework of a legitimate interest.

The processing of your personal data is necessary for our legitimate interests. We believe that our processing of your personal data is within our legitimate interests and within your reasonable expectations in a number of situations, including but not limited to:

• To protect the rights, property or safety of us or our affiliates, business partners or customers;
• To help us better understand our customers and provide them with better and more relevant services;
• To ensure the smooth operation of our Services;
• To help us keep our systems secure and prevent unauthorized access or cyber attacks;
• To anonymize personal data.

4. Based on a legal obligation of the Elfa Group or in the public interest.

Transfers of Personal Data outside the EEA

Our mandatory corporate policies allow us to transfer Personal Data within our global organization for the day to day operations and internal organization of the Elfa Group, and this includes a list of countries (see below) that are structured to allow us to transfer Personal Data to Elfa Group. Branches of the group located in these countries.

The level of protection of personal data outside the European Economic Area (EEA) differs from the level provided for by European legislation. For this reason, Elfa Group transfers personal data outside the EEA only when necessary and with an appropriate level of protection, in particular through:

• cooperation with organizations that process personal data in countries for which the relevant decision of the European Commission has been adopted;
• use of the standard contractual clauses of the European Commission;
• application of binding corporate rules approved by the relevant supervisory authority;
• in the case of data transfer to the United States - cooperation with organizations participating in the Privacy Shield program approved by the European Commission.

Personal Data processing terms

We process and store your Personal Data for as long as it is necessary to fulfil our contractual and statutory obligations.

Personal Data processing conditions by the Elfa Group depend on the type of service provided and the purpose of the processing. As a rule, the data is processed until the consent is withdrawn or the valid objection to the data processing is lifted, in cases where the legal basis for the data processing is in the legitimate interest of the Elfagroup.

The terms for data processing may be extended if the processing is necessary to assert and defend against possible claims, to the extent required by law. After the processing period has expired, the data will be permanently deleted or anonymised.

Security of your Personal Data

We use technical and organizational security measures to protect Personal Data under our control from accidental or deliberate manipulation, loss, destruction and access by unauthorized persons.

Our security procedures are constantly being improved as new technologies become available at selected branches of the Elfa Group.

We guarantee that all transactions with Personal Data are recorded and performed only by authorized employees.

Individual rights

Under certain circumstances required by law, you can exercise your Personal Data protection rights listed below at any time by contacting us at the contact details provided in the section Contact Elfa Group Your Personal Data:

• Right to information on personal data processing – on this basis Elfa Group shall provide the person making such a request with information on personal data processing, including in particular the purposes and legal grounds for processing, the scope of data held, entities to which personal data are disclosed and the planned date of their deletion;
• Right to obtain a copy of data – on this basis Elfa Group transfers a copy of the processed data concerning the person making the request;
• Right to rectify data – on this basis, Elfa Group removes any possible inconsistencies or errors concerning the personal data being processed, and completes or updates them if they are incomplete or have changed;
• Right to delete data – on this basis, you may request the deletion of data whose processing is no longer necessary for the fulfilment of any of the purposes for which they were collected;
• Right to restrict processing – on this basis, Elfa Group ceases to perform operations on personal data, with the exception of operations to which the data subject has consented and their storage, in accordance with the accepted principles of retention, or until the reasons for limiting the processing of data cease to exist (e.g. a decision of the supervisory authority is issued allowing further processing of data);
• Right to transfer data – on this basis, to the extent that the data are processed in connection with the concluded agreement or consent, Elfa Group shall issue the data provided by the data subject in a format that allows their reading by a computer. It is also possible to request that such data be sent to another entity – however, provided that there are technical possibilities in this respect on the part of both Elfa Group and the other entity;
• Right to object to the processing of data for marketing purposes – the data subject may object at any time to the processing of personal data for marketing purposes, without the need to justify such objection;
• Right to object to other purposes of processing – the data subject may object at any time to the processing of personal data on grounds of legitimate interest of Elfa Group (e.g. for analytical or statistical purposes or for reasons related to the protection of property). The objection in this respect should contain a justification and is subject to Elfa Group’s assessment;
• Right to withdraw consent – if data are processed on the basis of consent, the data subject has the right to withdraw it at any time, but this does not affect the lawfulness of the processing carried out before the withdrawal of consent;
• Right to complain – in case of recognition that the processing of personal data violates the provisions of the GDPR or other regulations concerning the protection of personal data, the data subject may lodge a complaint with the President of the Office for the Protection of Personal Data.

A request for the exercise of data subjects’ rights:

If you want to exercise your rights, or if you are unsatisfied with the way in which your Personal Data has been processed, or should you have questions regarding the processing of your Personal Data, you may refer in the first instance to the Elfa Group Data Protection Officer, who is available at the following email address: [email protected]

Or you can write to the address below: Elfa Pharm sp. z o.o., Chociw 99, 98-170 Widawa, Polska.

Cookies and similar technology

Cookies are small files or pieces of information that can be stored, accessed and deleted from your device when you browse the Elfa Group websites.

They are widely used to make websites work or work more efficiently and to provide information to the website owners.

In particular, cookies enable us to recognize your device and store information about your preferences or past activities.

We may use tracking technologies (including unique device identifiers, referrer URL and location from your devices) when you use certain apps or features.

Service Cookies

We use the so-called service cookies primarily to improve the quality of these services. Therefore, Elfa Group and other entities providing analytical and statistical services to Elfa Group use cookies to store information or gain access to information already stored in the telecommunications terminal device (computer, telephone, tablet, etc.). Cookies used for this purpose include:

• cookies with data entered by our users (session ID) for the duration of the session (userinputcookies);
• authentication cookies used for services requiring authentication for the duration of the session (authenticationcookies);
• security cookies, e.g. used to detect authentication breaches (usercentricsecuritycookies);
• session cookies of media players (e.g. flash player cookies), for the duration of the session (multimedia playersessioncookies);
• permanent cookies used to personalize the User interface for the duration of the session or slightly longer (userinterfacecustomizationcookies),
• cookies used to memorize the contents of the shopping cart for the duration of the session (shopping cartcookies);
• cookies used to monitor traffic on the website, i.e. data analytics, including Google Analytics cookies (these are files used by Google to analyze the use of the Website by the User, to create statistics and reports on the functioning of the Website). Google will not use the information collected to identify you or to link this information to any other personally identifiable information. Detailed information about the scope and principles of data collection in connection with this service can be found at: https://www.google.com/intl/pl/policies/privacy/partners.

Marketing cookies

We use cookies for marketing purposes, e.g. in connection with directing behavioural advertising. For this purpose, we shall store information or access information already stored in the telecommunications terminal equipment (computer, telephone, tablet, etc.). The use of cookies and personal data collected through them for marketing purposes, in particular to promote the services and goods of third parties, shall require the User’s consent. This consent may be expressed through the appropriate configuration of the browser, and can be revoked at any time, in particular by clearing the cookie history and disabling cookies in the browser settings.

How can you delete or disable cookies?

If the cookies we use are strictly necessary for technical reasons, they are marked as “required” in the table above. These cookies do not require your consent. However, if you choose not to accept cookies, which are strictly necessary for the provision of our services provided by our website, this may lead to a decrease in the availability of such services.

For cookies that require your consent (“optional cookies”), please note that you can give your consent and withdraw this consent at any time. You can also manage and control the additional cookies we use and delete them directly on our websites through the cookie settings interface.

In addition, you can prevent the storage of additional cookies on your device by setting your browser so that it does not accept cookies. The exact instructions for this can be found in the manual for your browser. You can also delete the cookies already on your device at any time in your browser settings. Learn how to manage cookies in popular browsers: Google Chrome, Apple Safari, Mozilla Firefox, Microsoft Internet Explorer, Opera.

For information regarding other browsers, visit the browser developer's website.

For statistical analysis, we use analytics tools based on certain cookies. You can object to the collection and analysis of statistical data regarding your access to and use of our websites at any time through the cookie settings interface mentioned above. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.

Modification of the Privacy Data Statement

Elfa Group will update this Privacy Data Statement from time to time in order to reflect the changes in our practices and services and to remain compliant to Data Protection Laws and Regulations. We will inform you of any substantial modification in how we process your Personal Data.