PRIVACY POLICY AND USE OF COOKIES

PRIVACY POLICY AND USE OF COOKIES

I. GENERAL INFORMATION

  1. This Privacy and Cookie Use Policy is a set of rules for the processing of personal data and the collection of cookies by „!Fest Coffee Mission” Ltd with its registered office at Lviv, Ukraine, address: 24-26, Staroznesenska street (hereinafter: "Administrator"), inter alia on https://festcoffeemission.com/ (hereinafter: "Website"), and sets out what personal data we collect, how we use it and with whom we share it. This notice also describes the measures we take to protect personal data.
  2. This document is addressed to all persons who visit the website https://festcoffeemission.com/, contact the Administrator of personal data (by telephone, e-mail, letter), including if they are employees, co-workers or representatives of the Administrator’s contractors (hereinafter: "Users").
  3. Users can contact the Administrator in the following ways:
    1. by letter to: 24-26 STAROZNESENSKA STREET, Lviv city, Lviv region, Ukraine, 79044;
    2. via email: welcome@festcoffeemission.com;
    3. by phone: +380 95 498 80 35.
  4. Personal data is any information relating to an identified or identifiable natural person. This type of data includes, but is not limited to, name, address, telephone number and e-mail address. Information that cannot be linked to a specific or identifiable person (such as statistical data) is not considered personal data.
  5. Before using the Website and the services of the Administrator, the User should read this privacy and cookie use policy. The purpose of the document is, inter alia, to fulfil the information obligation referred to in Articles 13(1) and (2) and 14(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), (hereinafter: "GDPR").

II. PROTECTION OF DATA

  1. The Administrator, through the use of appropriate technical and organisational measures, shall make every effort to protect personal data against loss or misuse.
  2. All data protection notifications are recorded and thoroughly explained and analysed based on the applicable legislation.

III. DATA SUBJECTS' RIGHTS

  1. The data subject has the right:
    1. to be informed of and have access to the data concerning them (the data subject's right of access under Article 15 GDPR);
    2. to rectify his or her personal data that are incorrect and to update his or her data (right of rectification, Article 16 GDPR);
    3. to request the erasure of his or her personal data (right to erasure, under Article 17 GDPR);
    4. to request the cessation of processing (right to restrict processing, under Article 18 GDPR);
    5. to request the transfer of data to another Administrator (right to data portability, under Article 20 GDPR);
    6. to object to the processing of his/her personal data (right to object, under Article 21 GDPR).
  2. The data subject also has the right to lodge a complaint with a supervisory authority in the EU Member State of their habitual residence, place of work or place of the alleged infringement (Article 77 GDPR).

IV. WITHDRAWAL OF CONSENT TO THE PROCESSING OF PERSONAL DATA AND THE MECHANISM OF WITHDRAWAL OF CONSENT

  1. Where processing is based on the person’s consent, we would like to inform you that the person has the right to withdraw consent at any time. The declaration of withdrawal of consent shall be made by submitting a statement to the Administrator by email or via post.
  2. The receipt of such a statement does not affect the lawfulness of prior processing of personal data.
  3. The withdrawal of consent for the processing of personal data shall be ineffective to the extent necessary for the proper provision of the services or the provisions of the ongoing contract, including the complaint process. In such a case, the withdrawal of the aforementioned consent shall become effective upon cancellation of the services, termination of the ongoing contract or the complaint process.
  4. Despite the effective withdrawal of consent to process the data, the Administrator is entitled to process the data to the extent necessary for:
    1. the assertion of contractual claims;
    2. fulfilment of a legal obligation incumbent on the Administrator;
    3. the performance of a task carried out in the public interest or in the exercise of official authority vested in the Administrator;
    4. purposes resulting from legitimate interests pursued by the Administrator or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
  5. In connection with a declaration of withdrawal of consent to data processing, for the purposes of identifying the person making the declaration and in order to protect against unauthorised access to the data, the Administrator shall be entitled to obtain additional confirmation of the identity of the person making such declaration.

V. CATEGORIES OF PERSONAL DATA, PURPOSES OF PROCESSING AND LEGAL BASIS

  1. In order to provide the Services and to fulfil the Contract with its Customers [pursuant to Article 6(1)(b) GDPR], the Administrator may process necessary data, such as registration data, data of contact persons on the Customer's side, i.e. name, surname, official position, telephone, signature, e-mail address, work position, delivery address.
  2. The provision of personal data is voluntary, but is necessary for the performance of the Services provided by the Administrator.
  3. The Administrator also processes data in connection with the performance of its Services:
    1. on the basis of consent [pursuant to Article 6(1)(a) and Article 7 GDPR] — in particular for marketing purposes or in order to respond to a request to the Administrator;
    2. on the basis of the Administrator's legitimate interests [pursuant to Article 6(1)(f) GDPR] — in particular such as: satisfaction surveys of the services provided (and also for the purpose of analysing the results of the surveys completed as part of this survey and the possibility of contacting the person responding back);
    3. in order to fulfil its legal obligations [pursuant to Article 6(1)(c) GDPR], such as: correct billing of the Service provided, processing of complaints, tax settlements;
    4. for the purpose of defending against and pursuing claims [pursuant to Article 6(1)(f) GDPR].
  4. The use of the Website may involve the processing of personal data by the Administrator for the following purposes:
    1. Placing of an order by a contractor and activities aimed at its fulfilment — data sent for the purpose of order fulfilment such as: registration data, name of the representative, address, delivery address, e-mail, telephone number;
    2. Contact via the contact form [pursuant to Article 6(1)(f) GDPR] — data sent via the contact form such as: name, email address, telephone number, which is required for processing and responding to the enquiry; [pursuant to Article 6(1)(a) GDPR] consent for processing such data as: e-mail address, telephone number is required for contact for the purpose of making a commercial offer;
    3. Contacting a consultant via chat or redirecting to WhatsApp messenger [pursuant to Article 6(1)(f) GDPR] — data sent during a conversation with a consultant, such as email address, name, telephone number, may be processed in order to verify the question asked and to provide an answer;
    4. Ensuring the security, stability and proper functioning of the Website [pursuant to Article 6(1)(f) GDPR — the Administrator's legitimate interest in maintaining a secure and reliable Website] — technical data automatically transmitted by the User's device, including the IP address, browser type and version, operating system, date and time of the request, and technical error diagnostics data. This data is processed by means of an error-monitoring service (Sentry) solely for the purpose of detecting and fixing technical faults and security incidents. It is not used for profiling or marketing and is retained for no longer than 90 days, after which it is automatically deleted.

VI. DATA SHARING

  1. The Administrator may share personal data:
    1. with the Administrator's group companies and subcontractors (e.g. transport partners) for the purpose of processing orders, including the delivery of parcels;
    2. with entities that are under contract to provide services to the Administrator, in particular IT service providers — including providers of website hosting, database infrastructure and error-monitoring services — which act as processors on the basis of data processing agreements and process personal data solely on the Administrator's documented instructions;
    3. with other persons or organisations on the basis of the applicable legislation;
    4. with state authorities, officers and law enforcement agencies in order to meet national security requirements or as part of ongoing investigations.

VII. RETENTION PERIOD AND DELETION OF DATA

  1. The Administrator processes personal data only for as long as is necessary to fulfil the purpose for which they were collected.
  2. Where personal data is processed in connection with the performance of a contract concluded with the Client, we will retain it for the period of performance of the contract and, to the extent necessary, for 5 years counting from the end of the calendar year in which the deadline for payment of tax due in connection with the conclusion and performance of the contract has expired, or longer if required by law.
  3. Where the User has contacted the Administrator — their data will be processed for the period necessary for the purposes of contacting the User and for a period of 2 years after the end of the contact.
  4. If personal data is processed based on the User's consent, it will be processed until the consent is withdrawn.
  5. If the User's personal data are no longer necessary for the purposes for which they were processed, the Administrator will keep them for the purpose of establishing, investigating or defending against possible claims on the part of both the Administrator and the User only for the periods of limitation of claims, as defined by law.
  6. Technical data processed for error-monitoring purposes (Section V) is retained for no longer than 90 days.
  7. After the expiry of the entitlement period for storing personal data, it is permanently deleted.

VIII. TRANSFER OF PERSONAL DATA TO COUNTRIES OUTSIDE THE EUROPEAN ECONOMIC AREA

  1. Personal data may be transferred to third countries in the event that the services that the Administrator provides are also to be performed in the territory of a third country. Personal data may also be transferred to the Administrator's subcontractors (e.g. entities that deliver a consignment in the territory of a third country) and entities that provide tax, legal, audit and billing advice to the Administrator, if they carry out their activities in the territory of a third country.
  2. The Administrator's IT infrastructure providers (including website hosting and error-monitoring services) may be established in the United States or otherwise outside the EEA. In such cases, the transfer of personal data is carried out on the basis of appropriate safeguards within the meaning of Article 46 GDPR, in particular the European Commission's Standard Contractual Clauses, or on the basis of an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified under it).
  3. The Administrator does not transfer personal data to international organisations.
  4. The Administrator does not transfer personal data to third countries where this is impossible or would be incompatible with generally applicable law.
  5. The level of protection of Personal Data outside the European Economic Area ("EEA") is not the same as that provided by European law. Accordingly, the Administrator transfers Personal Data outside the EEA only when necessary, while ensuring an adequate level of data protection in accordance with applicable regulations.

IX. SOURCE OF PERSONAL DATA

  1. Personal data of Users that is not collected from them directly may be obtained from their employers, colleagues or entities that the User represents. The Administrator may also process personal data from publicly available sources.

X. COOKIES

  1. Cookies are small text files which are stored on the User's terminal device (computer, mobile phone, tablet). They typically contain the name of the website of their origin, a unique identifier and the period for which they are stored on the device.
  2. The Website uses only strictly necessary (functional) cookies, which are required for the proper functioning of the Website. The Website does not use any analytics, statistical, advertising or marketing cookies, and no third-party tracking tools (such as Google Analytics, Meta Pixel or Microsoft Clarity) are active on the Website.
  3. The only cookie currently stored by the Website is:
    1. NEXT_LOCALE — a first-party functional cookie which remembers the language version of the Website selected by the User. It is set when the User chooses a language and is stored for 12 months. It does not contain any personally identifiable information and is not shared with any third party.
  4. Since strictly necessary cookies are exempt from the consent requirement under applicable law, the Website does not display a cookie consent banner. Up-to-date information about the cookies used is always available on the Cookies Settings page: https://festcoffeemission.com/en/cookies-settings.
  5. If the User visited the Website in the past, cookies set by analytics tools used previously may still be present in the User's browser. These cookies are no longer in use, are not read by the Administrator and are automatically removed by the Website on the User's next visit. The User may also delete them manually at any time in the browser settings.
  6. Should the Administrator decide to introduce analytics or marketing tools in the future, such tools will be activated only after obtaining the User's prior, freely given and informed consent, in accordance with the applicable law. The User will then be provided with a consent-management mechanism allowing them to accept, refuse or withdraw consent at any time.

XI. BLOCKING COOKIES

  1. In many cases, web browsers allow cookies to be stored on the User's terminal equipment by default. Users of the Website may at any time make changes to their settings concerning cookies, e.g. in such a way as to block the automatic handling of cookies or to be informed each time cookies are placed on the User's device. Detailed information on the possibility and methods of handling cookies is available in the settings of the browser or on the following websites:
    1. in the Google Chrome browser: https://support.google.com/chrome/answer/95647
    2. in the Mozilla Firefox browser: https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop
    3. in the Safari browser: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
    4. in the Microsoft Edge browser: https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
    5. in the Opera browser: https://help.opera.com/en/latest/web-preferences/#cookies
  2. However, the Administrator informs that restricting the use of strictly necessary cookies may affect some of the functionalities available on the Website (for example, the selected language version may not be remembered).
Argentina
Türkiye
Poland
Ukraine
El Salvador
© !Fest Coffee Mission. All rights reserved.by Radar