Welcome to the new PITBULL online store!

GDPR Information Obligation

The following information is a concise, clear, and transparent summary of the details included in the Privacy Policy regarding the Data Controller, the purpose and method of processing personal data, and your rights related to this processing, in the form required to fulfill the GDPR information obligation. Details regarding the processing method and entities involved in the process are available in the referenced policy.

Who is the Data Controller?
The Personal Data Controller (hereinafter referred to as the "Controller") is the company "Pitbull Spółka z ograniczoną odpowiedzialnością," operating at the address: ul. Ogrodowa 100, 62-003 Biedrusko, Poland, Tax ID (NIP): 7661965063, KRS: 0000331946, providing electronic services via the Website.

How can you contact the Data Controller?
You can contact the Controller in one of the following ways:

Postal address: Pitbull Spółka z ograniczoną odpowiedzialnością, ul. Ogrodowa 100, 62-003 Biedrusko, Poland

Email address: pitbull@pitbull.pl

Phone: +48 888 409 904

Has a Data Protection Officer been appointed?
In accordance with Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
For matters related to data processing, including personal data, please contact the Controller directly.

Where do we obtain personal data from and what are their sources?
Personal data is obtained from the following sources:

From the data subjects

In the case of registration via social media platforms, from those platforms with the informed consent of the user

What personal data do we process?
The Website processes standard personal data voluntarily provided by the data subjects (e.g., name and surname, username, email address, phone number, IP address, etc.).
A detailed list of processed data is available in the Privacy Policy.

What are the purposes of data processing?
Personal data voluntarily provided by Users is processed for one of the following purposes:

Provision of electronic services:

Registering and maintaining a User account and associated functionalities

Newsletter service (including sending promotional content with consent)

Commenting/liking content on the Website without requiring registration

Communication between the Controller and Users regarding the Website and data protection

Ensuring the Controller’s legitimate interests

What are the legal bases for data processing?
The Website collects and processes User data based on:

Regulation (EU) 2016/679 (General Data Protection Regulation):

Art. 6(1)(a): The data subject has given consent to the processing of their personal data for one or more specific purposes

Art. 6(1)(b): Processing is necessary for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract

Art. 6(1)(f): Processing is necessary for the purposes of the legitimate interests pursued by the Controller or a third party

The Personal Data Protection Act of May 10, 2018 (Journal of Laws 2018, item 1000)

The Telecommunications Law of July 16, 2004 (Journal of Laws 2004, No. 171, item 1800)

The Copyright and Related Rights Act of February 4, 1994 (Journal of Laws 1994, No. 24, item 83)

What is the legitimate interest pursued by the Controller?

Establishing, pursuing, or defending legal claims – the legal basis is our legitimate interest (Article 6(1)(f) GDPR), including:

Assessing risks of potential clients

Evaluating marketing campaigns

Performing direct marketing

How long do we process personal data?
As a rule, personal data is stored only for the duration of the service provision by the Controller. The data is deleted or anonymized within 30 days of the service ending (e.g., account deletion, newsletter unsubscribing).

In exceptional cases, to protect the Controller's legitimate interests, this period may be extended. In such cases, the data will be stored for no longer than 3 years from the user's request to delete it, if there is a violation or suspected violation of the site's regulations.

Who are the recipients of the data, including personal data?
As a rule, the Controller is the sole recipient of the data.
However, data processing may be outsourced to third parties that provide services to the Controller necessary for Website operation, such as:

Hosting providers

Newsletter service providers

Online payment intermediaries

Shipping and delivery companies (postal/courier services)

Will your personal data be transferred outside the EU?
Yes, personal data may be transferred outside the EU.
This is due to the use of service providers located outside the EU, or user activity (e.g., submitting comments or posts) that makes the data publicly available.
In such cases, data is processed based on a contract between the Controller and the Service Provider.

Will personal data be used for automated decision-making?
No, personal data will not be used for automated decision-making (profiling).

What rights do you have regarding your personal data?

Right of access: You can request access to your personal data at any time.

Right to rectification: You can request the correction of inaccurate or incomplete data.

Right to erasure: You can request deletion of your data (e.g., by deleting your account or using the unsubscribe link in newsletters).

Right to restrict processing: You can request restriction of data processing under certain conditions (e.g., when accuracy is contested).

Right to data portability: You can request a copy of your data in a structured, commonly used format.

Right to object: You can object to processing in situations outlined in Article 21 of the GDPR.

Right to lodge a complaint: You can lodge a complaint with a data protection supervisory authority.