Privacy Policy

The following Privacy Policy is intended to inform you about how we use your personal data. In doing so, we adhere to the strict provisions of Poland`s Personal Data Protection Act (“PDPA”) as well as the requirements of the European General Data Protection Regulation (“GDPR”).

Data Controller 

The person responsible for the meaning of the DPA and PDPA is:

Ezotic sp. z o.o trading as Educational Maps 
Pod Gora 2, 
32-031 Gaj
Lesser Poland Voivodeship, Poland
Email: office@educafional-maps.com
www.educational-maps.com

Scope of the processing of personal data

As a matter of principle, we only collect and use personal data from you insofar as this is necessary to provide a functional website and our content and services, e.g., when you register on our website or log in to an existing customer account or when you order products. The collection and use of your personal data regularly only takes place with your consent. An exception applies in cases where prior consent is not possible for actual reasons and the processing of the data is permitted by applicable law.

Security

The security of your personal data is a high priority for us. We, therefore, protect your data stored with us by technical and organizational measures in order to effectively prevent loss or misuse by third parties. In particular, our employees who process personal data are bound to data secrecy and must comply with it. To protect your personal data, it is transmitted in encrypted form; for example, we use SSL=Secure Socket Layer for communication via your Internet browser. You can recognize this by the lock symbol that your browser displays when an SSL connection is established. In order to ensure the permanent protection of your data, the technical security measures are regularly checked and, if necessary, adapted to the state of the art. These principles also apply to companies that process and use data on our behalf and in accordance with our instructions.

Purposes of processing and legal basis 

We collect, process, and use your personal data for the following purposes:

• Establishment and performance of contractual relationships;
• Sending newsletters;
• Marketing measures;
• Customer satisfaction surveys and analyses;
• Product evaluations;
• Customer service and customer support;
• To process orders for our online range of goods

The processing of your personal data may be based on the following legal grounds:

• Art. 6 (1) lit. a GDPR serves as our legal basis for processing operations where we obtain your consent for a specific processing purpose.
• Art. 6 (1) lit. b GDPR, insofar as the processing of personal data is necessary for the performance of a contract, e.g., if you purchase a product. The same applies to such processing operations that are necessary for the performance of pre-contractual measures, for example in the case of enquiries about our products or services.
• Art. 6 (1) lit. c GDPR, insofar as we are subject to a legal obligation that requires the processing of personal data, such as for the fulfillment of tax obligations.
• Art. 6 (1) lit. f GDPR applies on the basis of our legitimate interests, e.g., when using service providers as part of order processing, such as shipping service providers or when carrying out statistical surveys and analyses and logging registration procedures. Our interest is directed towards the use of a user-friendly, appealing, and secure presentation as well as optimization of our website, which serves our business interests as well as meeting your expectations.

Duration of storage and routine deletion of personal data

We process and store your personal data only for the period of time required to fulfill the purpose of storage or if this has been provided for in laws or regulations. After the purpose has ceased to exist or has been fulfilled, your personal data will be deleted or blocked. 

In the case of blocking, deletion will take place as soon as legal, statutory, or contractual retention periods do not conflict with this; there is no reason to assume that deletion would impair your interests worthy of protection and deletion would not cause a disproportionately high expense due to the special nature of the storage.

Log files

If you visit our website for information purposes only, without providing personal data via registration or in any other way, only the Internet connection data that your browser transmits to our server will be processed. Our website collects a series of general data and information with each call, which is temporarily stored in the log files of a server. A log file is created in the course of an automatic protocol of the processing computer system. The following can be recorded:

• Access to the website (date, time, and frequency)
• How you arrived at the website (previous page, hyperlink, etc.)
• Amount of data sent
• Which browser and browser version you are using
• The operating system you are using
• Which internet service provider do you us
• Your IP address, which your Internet access provider assigns to your computer when you connect to the Internet

The legal basis for this data processing is Article 6 (1) sentence 1 lit. b of the GDPR, as the collection and storage of this data, is necessary for the operation of the website in order to ensure the functionality of the website and to deliver the content of our website correctly. 

In addition, the data serve us to optimize our website and to ensure the security of our IT systems, and the processing is based in this respect on Art. 6 (1) lit. f GDPR. For this reason, the data is stored for a maximum of 7 days as a technical precaution.

We also use this data for the purposes of advertising, market research, and to design our services to meet your needs by creating and evaluating user profiles under pseudonyms, but only if you have not exercised your right to object to this use of your data (see information on the right to object under “Your rights”).

Use of cookies

We use so-called cookies on our website. Cookies are small text files that are stored on your respective device (PC, smartphone, tablet, etc.) and saved by your browser. For further information, please refer to our Cookie Policy. The legal basis for the use of cookies is your consent in accordance with Art. 6 (1) a) GDPR as well as our legitimate interest in accordance with Art. 6 (1) f) GDPR.

Sending information

We use your data for sending information ordered by you about our offer and other promotions from us to the e-mail address provided by you.

If you purchase goods or services on our website, we may send you information on our own similar goods to your specified e-mail address even without your consent. The legal basis for this data processing is Art. 6 (1) p. 1 lit. f GDPR, because advertising related products and services by way of direct advertising represents a legitimate interest for us as the provider of this website. You may object to the processing of your personal data for the purpose of direct advertising at any time. We will then refrain from further processing for such purposes. You can send us your objection as described below. In addition, you can object to the sending of such newsletters at any time in the future without giving reasons by unsubscribing via the unsubscribe link at the end of each newsletter or by contacting us.

We would like you to enjoy reading our e-mails. Therefore, we try to only include content that you are likely to be interested in. We, therefore, measure and store opening and click-through rates in your user profile, i.e., whether and when you open our emails, which content of the emails you click on, and when, as well as whether and why our emails could possibly not be delivered. We also use this data for statistical purposes. 

In particular, this serves our legitimate interest to evaluate the performance of the individual newsletter campaigns and to define optimization measures in order to make the newsletter as attractive and suitable as possible for you. The legal basis for the processing is, therefore Art. 6 (1) lit. f GDPR.

Of course, you can unsubscribe from receiving our information at any time, i.e., revoke your consent with effect for the future or object to data processing. For this purpose, you will find a corresponding unsubscribe link in every mail or newsletter. You can also contact us for cancellation at any time.

Contacting us, registration or placing orders

a) Contacting us

When you contact us via email or the contact form, the data you provide will be stored by us based on Art. 6 (1) lit. b of the GDPR, insofar as it is necessary to answer your questions. The contact is logged in order to be able to prove the contract in accordance with the legal requirements. We delete the data accruing in this context when the respective conversation with you has ended, and the facts concerned have been conclusively clarified.

We use the communication tool Facebook Messenger on our website. The service provider is Meta Platforms Inc, 1 Hacker Way, Menlo Park, CA 94025, USA, or if you are a resident of the EU, Meta Platforms Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. 

The legal basis of the data processing mentioned under this section is our obligation to fulfill the contract and/or to fulfill our pre-contractual obligations in accordance with Art. 6 (1) lit. b GDPR and/or our legitimate interest in processing your inquiry in accordance with Art. 6 (1) lit. f GDPR.

b) Registration

On our website, we offer you the opportunity to register by providing personal data. The data is entered in an input mask, transmitted to us, and stored. Registration is necessary in order to set up your customer account, which you can use to place orders and services. The processing of the data for this registration thus serves the fulfillment of the contract of use or the implementation of pre-contractual measures and is based on Art. 6 (1) lit. b GDPR. You can delete your customer account at any time on our website.

c) Storage of data in the user account

For the conclusion and processing of contracts, we require contact details, such as name, delivery and billing address and e-mail address, as well as information on the type of payment method you have chosen, depending on the individual case. You can store this data in your user account. In addition, we use your data to maintain our customer database so that only accurate data is stored there. In order to avoid typing errors and to ensure that the items you have ordered reach you, we check the completeness and accuracy of your address when you enter it.

Following your order, you will receive a corresponding order confirmation as well as further documents, which we are obliged to provide in order to fulfill our legal information obligations for an effective conclusion of a contract with you. The processing of your data is, therefore, necessary for the conclusion of the contract with you and is therefore based on Art. 6 (1) lit. b GDPR.

d) Guest order

You have the option to place your orders as a guest. If you choose this order type, you do not have to register before placing an order. Please note that you will have to enter your data again for each subsequent order.

We collect, process, and use the information you provide in the context of a guest order for the purpose of executing the contract in accordance with Art. 6 (1) lit. b GDPR. We store the information you provide for the period of processing and handling your order. Afterwards, your data will be deleted unless you decide to activate your customer account within 14 days after placing your order. Data that we are required to store due to legal, statutory or contractual retention obligations will be blocked instead of being deleted to prevent it from being used for other purposes.

e) Order confirmation/dispatch confirmation

In order to process the contract and provide you with our services, for example, the web shop or to send you a package for which a fee is charged, we use your contact details to send you registration confirmations, customer service information, order confirmations, contract documents or payment processing information. We are obliged to send you these documents in order to comply with our legal information obligations for an effective conclusion of a contract with you. The processing of your data is, therefore, necessary for the conclusion of the contract with you and is based on Art. 6 (1) lit. b GDPR.

f) Other

Based on Art. 6 (1) lit. c and f GDPR, we use and store your personal data and technical information to the extent necessary to prevent or prosecute misuse or other illegal behavior on our website, e.g., to maintain data security in the event of attacks on our IT systems. This also takes place insofar as we are legally obliged to do so, for example, due to official or court orders, and for the exercise of our rights and claims as well as for legal defense.

Disclosure of personal data to third parties

Your personal data will only be passed on if there is a legal obligation to do so or to service providers and partner companies that have been carefully selected in advance and are contractually obliged to comply with the requirements of data protection law.

a) Disclosure within affiliated companies pursuant to Art. 6 (1) lit. b GDPR

We pass on your personal data for the conclusion and processing of contracts for offers on our website to affiliated companies. This is particularly necessary so that you can use all our offers. If you contact us with questions, complaints or returns as well as other complaints, they will also receive access to your order data in order to be able to process your request.

b) Disclosure to service providers according to Art. 6 (1) lit. b and f GDPR

For the operation and optimization of our website and our services and for the processing of contracts, various service companies work for us, e.g., for central IT services or the hosting of our website, for the payment and delivery of products or for the dispatch of your order, to whom we pass on the data required for the fulfillment of the task (e.g., name, address).

Some of these companies act for us by way of commissioned processing and may therefore use the data provided exclusively in accordance with our instructions. In this case, we are legally responsible for appropriate data protection precautions at the companies we commission. We, therefore, agree on specific data security measures with these companies and monitor them regularly.

In contrast to order processing, in the following cases, we transmit data to third parties for their own use in order to process the contract:

• In the case of delivery of goods to logistics companies and the postal service provider specified when the order was placed.
• In the case of payment for goods to the payment service provider specified when the order was placed. 

We do not collect or store any payment transaction information such as credit card numbers or bank details during the payment process. You only provide this information directly to the respective payment service provider. 

c) Disclosure to other third parties pursuant to Art. 6 (1) lit. c and f GDPR

We will disclose your data to third parties or government agencies within the framework of existing data protection laws if we are legally obliged to do so, e.g., due to official or court orders, or if we are entitled to do so, e.g., because this is necessary for the prosecution of criminal offenses or for the exercise and enforcement of our rights and claims.

Payments

If you choose to use PayPal, payment will be processed through the payment system of PayPal. If you have selected PayPal Express as your method of payment, it is necessary for PayPal to transmit the following personal data to PayPal (Europe) S.á.r.l. & Cie, S.C.A. in order to process your payment: Total amount of the order, Reference on the PayPal account, your e-mail address of the PayPal account, Encrypted PayPal account number. The legal basis for the processing of your personal data is the establishment and implementation of the user contract for the use of the service in accordance with Art. 6 (1) b) GDPR.

Payment by credit card and debit card are made via our payment service provider Stripe, Inc.,to which we pass on your mandatory details provided during the checkout, for payment processing. Your data will only be passed on for the purpose of payment processing with the payment service provider and only insofar as it is necessary for this purpose. The legal basis for the processing of your personal data is the establishment and implementation of the user contract for the use of the service in accordance with Art. 6 (1) b) GDPR.

Order fulfillment 

In order to fulfil the contract with you, we may pass on your data to the order fulfillment and shipping company (Amazon Fulfillment Service) commissioned with the fulfillment and delivery, insofar as this is necessary for the delivery of ordered goods. The legal basis for the processing of your personal data is the establishment and implementation of the user contract for the use of the service in accordance with Art. 6 (1) b) GDPR.

Data transfer to third countries

If we use service providers in third countries, we take additional measures to ensure an adequate level of data protection for the transfer of personal data in accordance with Art. 44 of the GDPR and thus ensure that the transfer is generally permissible and that the special requirements for a transfer to a third country are met (e.g., by concluding standard contracts and additional guarantees, supplementary technical and organizational measures such as encryption or anonymization).

Tracking and Analytics 

a) Google Analytics 

We use Google Analytics, web analytics services provided by Google Inc (“Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there. In the event that IP anonymization is activated on this website, your IP address will be truncated beforehand by Google within member states of the European Union or in other contracting states to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity, and providing other services relating to website activity and internet usage to the website operator. Various reports can be viewed, and configurations of a website can be made in the Search Console.

You may refuse the use of cookies by selecting the appropriate settings on your browser; however, please note that if you do this, you may not be able to use the full functionality of this website. In addition, you can prevent the collection of the data generated by the cookie and related to your use of the website (incl. your IP address) by Google as well as the processing of this data by Google by downloading and installing the browser plug-in available at the following link: http://tools.google.com/dlpage/gaoptout?hl=en

The legal basis for the processing of the data with the help of Google Analytics is your consent in accordance with Art. 6 para. (1) a) GDPR for the analysis and better design of our website.

Information from the third-party provider: Google Dublin, Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, and Goole Inc., 1600 Amphitheatre Parkway Mountain View, CA 94043, US. We have concluded a third-party processing agreement with Google for this purpose. Google LLC, based in California, USA, and possibly US authorities can access the data stored by Google. A transfer of data to the USA cannot be ruled out. The privacy policy of Google can be found here.

b) Facebook Remarketing

Within our platform, so-called “Facebook pixels” of the social network Facebook, which is operated by Meta Platforms Inc., 1 Hacker Way, Menlo Park, CA 94025, USA, or if you are a resident of the EU, Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”), are used. With the help of the Facebook pixel, it is possible for Facebook to determine the visitors to our offer as a target group for the display of advertisements, so-called “Facebook ads”. Accordingly, we use the Facebook pixel to display the Facebook ads placed by us only to those Facebook users who have also shown an interest in our platform. This means that with the help of the Facebook pixel, we want to ensure that our Facebook ads correspond to the potential interest of the users and do not have a harassing effect. With the help of the Facebook pixel, we can also track the effectiveness of the Facebook ads for statistical and market research purposes by seeing whether users were redirected to our platform after clicking on a Facebook ad.

You can object to the collection by the Facebook pixel and use of your data for the display of Facebook ads. To do so, you can visit the page set up by Facebook and follow the instructions there on the settings for usage-based advertising: https://www.facebook.com/settings?tab=adsor declare the objection via the US page http://www.aboutads.info/choices/ or the EU page http://www.youronlinechoices.com/.  The legal basis for this processing is Art. 6 (1) f) GDPR, our legitimate interest, and your consent according to Art. 6 (1) a) GDPR.

c) Jetpack 

On the basis of our legitimate interests (i.e., interest in the analysis, optimization, and economic operation of our online offer within the meaning of Art. 6 (1) f) GDPR) the plugin integrates a tool for the statistical evaluation of visitor access and is provided by Automattic, Inc. 132 Hawthorne Street San Francisco, CA 94107, USA. Jetpack uses so-called “cookies”, text files that are stored on your device and which enable an analysis of your use of the website. The information generated by the cookie about your use of this Website is stored on a server in the USA. User profiles can be created from the processed data, whereby these are only used for analysis and not for advertising purposes. For more information, please refer to Automattic’s privacy policy.

Your rights

Of course, you have rights with regard to the collection of your data, which we are pleased to inform you of herewith. If you would like to make use of one of the following free rights, a simple message to us will suffice. For your own protection, we reserve the right, in the case of an existing inquiry, to obtain further information necessary to confirm your identity and, if identification is not possible, to refuse to process the inquiry.

a) Right to information

You have the right to request information and/or copies of the personal data stored about you.

b) Right to rectification

You have the right to request that personal data relating to you be corrected and/or completed without delay.

c) Right to object to processing

You have the right to request the restriction of the processing of your personal data, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you object to its erasure, and we no longer require the data, but you need it for the assertion, exercise or defense of legal claims or you have lodged an objection to the processing.

d) Right to deletion

You have the right to request the erasure of your personal data stored by us, unless the exercise of the right to freedom of expression and information, the processing is necessary for compliance with a legal obligation, for reasons of public interest or for the assertion, exercise, or defense of legal claims.

e) Right to information

Where you have exercised the right to rectification, erasure, or restriction of processing, we will notify all recipients to whom personal data relating to you has been disclosed of such rectification, erasure, or restriction of processing unless this proves impossible or involves a disproportionate effort.

f) Right to data portability

You have the right to have the personal data you provided to us handed over to you or to a third party in a structured, common, and machine-readable format. If you request the direct transfer of the data to another responsible party, this will only be done insofar as it is technically feasible.

g) Right of objection

Insofar as your personal data are processed on the basis of legitimate interests pursuant to Article 6 (1) (f) of the GDPR, you have the right to object to the processing at any time pursuant to Article 21 (1) of the GDPR.

If we process your data for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing in accordance with Art. 21 (2) GDPR; this also applies to profiling insofar as it is related to such direct marketing.

h) Right to withdraw consent

You have the right to cancel your consent to the collection of data at any time with effect for the future. The data collected until the cancellation becomes legally effective will remain unaffected. Please understand that the implementation of your cancellation may take a little time for technical reasons and that you may still receive messages from us in the meantime.

i) Right to complain to a supervisory authority

If the processing of your personal data violates data protection law or if your data protection rights have otherwise been violated in any way, you may complain to the supervisory authority.

You can also exercise your rights of rectification and deletion most quickly, easily, and conveniently by logging into your customer account and directly editing or deleting your data stored there. 

j) Automated decision-making, including profiling

You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.

The Supervisory Authority

We encourage you to get in touch if you have any concerns with how we collect or use your personal data. You also have the right to lodge a complaint directly with the Polish Data Protection Supervisory Authority, Urząd Ochrony Danych Osobowych; their contact details are as follows: Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, https://uodo.gov.pl/en

Social Media

We are present in various “social media” platforms in order to communicate with our customers, interested parties and users registered there and to be able to inform them about our offers there. We would like to point out that you use these platforms and their functions on your own responsibility. This applies in particular to the use of the interactive functions (e.g., commenting, sharing, rating). 

In addition, your data may be processed for market research and advertising purposes. For example, usage profiles can be created from your usage behavior and the resulting interests. This allows, for example, advertisements to be placed within and outside the platforms that presumably correspond to your interests. Cookies are usually stored on your computer for this purpose. Independently of this, data that is not directly collected from your devices may also be stored in the usage profiles (especially if you are a member of the respective platforms and are logged in to them).

As the provider of this information service, we do not collect and process any data from your use of our service beyond this.

The processing of users’ data is based on our legitimate interests in providing users with effective information and communicating with users pursuant to Art. 6 (1) p.1 lit. f. GDPR. If you are asked by the respective providers for a consent to data processing, the legal basis for processing is Art. 6 (1) sentence 1 lit. a., Art. 7 GDPR.

If you are a member of a social network and do not want the network to collect data about you via our website and link it to your stored membership data with the respective network, you must

• log out of the respective network before visiting our website,
•delete the cookies on your device and
• close and restart your browser.

After logging in again, however, you will be recognizable to the network as a specific user. In the case of requests for information and the assertion of user rights, we would also like to point out that these can most effectively be asserted with the providers. Only the providers can access the users’ data and take appropriate measures and provide information directly. If you still need help, you can contact us.

Updating your information

If you believe that the information we hold about you is inaccurate or that we are no longer entitled to use it and want to request its rectification, deletion, or object to its processing, please do so within your account or contact us. For your protection and the protection of all of our users, we may ask you to provide proof of identity before we can answer the above requests.

Remember that we may reject requests for certain reasons, including if the request is unlawful or if it infringes on trade secrets or intellectual property or the privacy of another user. Also, we may not be able to accommodate certain requests to object to processing personal information, notably where such requests would not allow us to provide our service to you anymore.

Links to other providers

Our website also contains – clearly recognizable – links to other companies websites. Insofar as there are links to websites of other providers, we do not influence their contents. Therefore, no guarantee or liability can be assumed for these contents. The respective provider or operator of the pages is always responsible for the content of these pages.

The linked pages were checked for possible legal violations and recognizable infringements at the link time. Illegal contents were not recognizable at the time of linking. However, permanent monitoring of the content of the linked pages is not reasonable without concrete indications of a legal violation. Such links will be removed immediately if infringements of the law become known.

Personal information and children 

Our services are aimed at people aged 18 and over. We will not knowingly collect, use or disclose personal information from minors under the age of 18 without first obtaining consent from a legal guardian through direct offline contact. 

Changes 

To ensure that our Privacy Policy always complies with the current legal requirements, we reserve the right to make changes at any time. This also applies if the Privacy Policy has to be adapted due to new or revised offers or services.