Privacy Policy
Privacy Policy
At muscle-zone.com, we respect your right to privacy and place great importance on the protection of personal data. This Privacy Policy (hereinafter: Privacy Policy) explains how we collect, use, share, and protect the data you entrust to us when using our online store available at www.muscle-zone.com (hereinafter: the Store).
We operate in accordance with applicable laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR), as well as Polish regulations on the protection of personal data.
Providing personal data is generally voluntary, but it is necessary for the conclusion and performance of the Sales Agreement, the provision of electronic services, handling inquiries, returns, and complaints, and the fulfillment of legal obligations. Failure to provide such data may prevent you from using certain services or features of the Store.
We reserve the right to verify the accuracy of the data provided during registration in the Online Store. If it is determined that the data is inaccurate, we have the right to delete the Customer’s Account after first sending the Customer an email informing them that the Account will be deleted due to inaccurate data.
1. Who is the Controller of your personal data?
The personal data of Sellers and Buyers, as defined in the Store’s Terms and Conditions, is processed by the Administrator as the controller of personal data within the meaning of Article 4(7) of the GDPR and other applicable laws.
The controller of personal data is:
MZ-Store S.A.47 Cypriana Kamila Norwida St., 84-240 Reda
KRS: 0000877266, REGON: 38787611700000, NIP: 5862363341, BDO: 000517970
Share capital: 5,000,000.00 PLN, fully paid in
Contact regarding personal data: email: biuro@muscle-zone.pl, phone: +48 510 054 085 (Mon–Fri 8:00 a.m.–4:00 p.m., standard call rates apply according to the operator’s price list) or in writing to the registered office address.
The controller has not appointed a Data Protection Officer. For matters related to the processing of personal data, you may contact Muscle-Zone directly using the contact information provided in this section.
2. What personal data do we collect, for what purposes, and on what basis?
2.1. Data provided during account registration and when placing an order
- Identification and contact information: first name, last name, email address, phone number, shipping address (street, house/apartment number, ZIP code, city, country).
- Purpose: order fulfillment, payment processing, issuing invoices, communication regarding the order, handling complaints and returns, maintaining the user account, and fulfilling statutory obligations (taxes, accounting).
- Legal basis: Article 6(1)(b) of the GDPR (performance of a contract), Article 6(1)(c) of the GDPR (legal obligation), and, with regard to the pursuit of claims, Article 6(1)(f) of the GDPR (legitimate interests of the Controller).
2.2. Payment Data
- Scope: first name, last name, address, information necessary to process payments (e.g., card type, bank details).
- Purpose: accepting payments, fulfilling statutory obligations.
- Legal basis: Article 6(1)(b) of the GDPR, Article 6(1)(c) of the GDPR, and Article 6(1)(f) of the GDPR with regard to the protection of the Controller’s rights.
2.3. Data Collected Automatically When Using the Website
- Technical data: IP address, browser type, operating system, device type, access time, pages and products viewed.
- Purpose: to ensure the proper functioning of the website, security, statistics, personalization of content and offers, and fraud prevention.
- Legal basis: Article 6(1)(f) of the GDPR (the Controller’s legitimate interest).
2.4. Data Collected Through Cookies
- Scope: preferences, items in the shopping cart, browsing history.
- Purpose: improving website performance, personalization, traffic analysis, and marketing.
- Legal basis: Article 6(1)(a) of the GDPR (consent) for analytical and marketing cookies, and Article 6(1)(f) of the GDPR for essential cookies.
2.5. Data from correspondence
- Scope: data provided in messages (form, email, phone).
- Purpose: handling inquiries and complaints.
- Legal basis: Article 6(1)(b) of the GDPR or Article 6(1)(f) of the GDPR, and, with regard to the assertion of claims, Article 6(1)(f) of the GDPR.
2.6. Marketing data (newsletter)
- Scope: email address.
- Purpose: Sending the newsletter; informing you about news, promotions, and offers.
- Legal basis: Article 6(1)(a) of the GDPR (consent), and, with regard to the assertion of claims, Article 6(1)(f) of the GDPR.
2.7. Social media data
- Scope: data made available on profiles (e.g., username, message content).
- Purpose: handling inquiries, brand promotion.
- Legal basis: Article 6(1)(f) of the GDPR (communication and promotion).
The controller may also process personal data to fulfill obligations arising from national law, in particular the Act on the Provision of Electronic Services, the Consumer Protection Act, the Anti-Money Laundering Act, and other legal acts.
3. To whom do we disclose personal data?
The Data Controller may entrust the processing of personal data to third parties with whom it has entered into appropriate data processing agreements pursuant to Article 28(3) of the GDPR.
Data may be disclosed to external entities, including in particular: couriers, customs agencies, marketing agencies, IT and hosting service providers, online payment processors, providers of analytics and marketing tools, as well as accounting and legal service providers.
Data is also disclosed to external Sellers offering goods on the Website as part of the marketplace functionality. These entities process data based on a contract with us and only in accordance with our instructions, ensuring appropriate data protection measures. A list of current data processors may be provided to the user upon request.
In the event of a complaint, data may be transferred to the Seller, distributor, manufacturer, or warranty provider, depending on the product subject to the complaint.
With the user’s consent, data may be shared with other entities for their own purposes, including marketing. If you choose to pay online, the data necessary to process the payment will be transferred to the payment processor. Selecting a specific payment method constitutes consent to the transfer of data to the payment processor.
All entities to which we disclose data are obligated to protect it in accordance with the GDPR and the agreements concluded with us.
When you make a purchase in the Store, we provide your first name, email address, and order number to Trustpilot A/S, based in Copenhagen, Denmark, which, on our behalf, sends you an invitation to leave a review of your purchase. Trustpilot processes this data as a data processor under a data processing agreement (Article 28 of the GDPR). The basis for processing is our legitimate interest (Article 6(1)(f) of the GDPR), which consists of assessing customer satisfaction and building the Store’s credibility. Submitting a review is voluntary, and the invitation data is stored by Trustpilot for no longer than 3 years. You may request its earlier deletion by contacting us using the contact information provided in section 1.
4. Transfer of Data Outside the European Economic Area
We may transfer personal data to recipients located outside the EEA, in so-called third countries. Before transferring data, we ensure an adequate level of protection on the recipient’s side (e.g., an EU Commission decision on an adequate level of protection or EU standard contractual clauses) or rely on the user’s consent.
Information about recipients in third countries and copies of the safeguards in place can be obtained using the contact details provided in Section 1.
5. How long do we retain personal data?
The duration of data processing depends on the type of service or contract and the purpose of the processing. As a general rule, data is processed for the duration of the service or the performance of the contract, until consent is withdrawn or an objection is effectively raised, provided that the basis for processing is the Controller’s legitimate interest. This period may be extended if processing is necessary to establish, assert, or defend legal claims, and after that time, only to the extent required by law.
- the duration of the contract and the period for asserting claims (up to 6 years),
- the period required by law, including tax laws (at least 5 years from the end of the tax year),
- until consent is withdrawn (for data processed on the basis of consent),
- until the Controller’s legitimate interest continues to exist (no longer than 3 years from the last contact).
After the expiration of the specified periods, the data is permanently deleted or anonymized.
6. Your Rights Regarding the Protection of Personal Data
The data subject has rights under the GDPR, including:
- The right of access to data and information regarding processing.
- The right to rectify inaccuratedata and to have incomplete data completed.
- The right to erasure in the cases specified in the GDPR.
- The right to restrict processing.
- The right to data portability in a structured format when the basis is consent or a contract and the processing is automated.
- Right to object:
- on grounds relating to your particular situation regarding processing based on Article 6(1)(f) of the GDPR, including profiling, unless we demonstrate compelling legitimate grounds,
- to direct marketing at any time.
- Right to withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal.
- The right to lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, tel. 22 531 03 00, website: uodo.gov.pl.
To exercise your rights, please contact us as described in section 1. For security reasons, we may ask for additional information to verify your identity. A response will be provided no later than 1 month after receipt of a complete request.
7. Security Measures
We use appropriate technical and organizational measures to protect data against unauthorized access, loss, destruction, modification, or disclosure, including:
- Data encryption: SSL/TLS-encrypted connections.
- Access control: access restricted to authorized individuals bound by confidentiality obligations.
- Pseudonymization and anonymization where possible.
- Regularbackups.
- Monitoring of systems for threats and vulnerabilities.
We systematically improve our security measures to ensure the highest level of data protection.
8. Direct Marketing
With your separate consent, we may use your data to send you marketing offers available in the Store, newsletters, surveys, and invitations via email, text message, or phone, in accordance with the scope of the consent you have provided.
Data may be transferred to third-party companies solely for the purpose of providing these services to our company (distribution of marketing materials). We do not sell data or transfer it to other entities for their own purposes without your explicit consent.
You may withdraw your consent at any time, for example, by editing your account settings or by sending an email to: biuro@muscle-zone.pl. Once you withdraw your consent, we will no longer engage in direct marketing toward you.
9. Profiling and Automated Decision-Making
As part of our direct marketing activities, we may make automated decisions, including profiling, based on the data we hold (purchase history, products viewed, preferences). On this basis, we tailor our offers and potential discounts.
The legal basis is the user’s consent for direct marketing purposes (Article 6(1)(a) of the GDPR in conjunction with Article 22(2)(c) of the GDPR). Consent may be withdrawn at any time. If the user does not accept the automated assessment, they may file a complaint through the channels indicated in section 1.
10. Information for Sellers
Sellers who gain access to Buyers’ data must enter into a separate data processing agreement with us in accordance with Article 28 of the GDPR. The absence of such an agreement prevents the use of the Store’s features that allow access to Buyers’ data.
Sellers act as independent data controllers with respect to the independent processing of Buyer data (e.g., fulfillment of sales contracts). They are required to fully comply with the GDPR and to fulfill their obligation to inform data subjects.
Data may be transferred to third parties only to the extent necessary, including IT providers, courier services, accounting firms, payment service providers, payment operators, consulting firms, and law firms, based on appropriate legal grounds. These entities are required to maintain confidentiality and comply with applicable regulations.
The Data Controller is not liable for how data is processed by Sellers acting as separate data controllers; however, it exercises due diligence in verifying the legality of their activities, including through documentation, data processing agreements, and control procedures.
Sellers are prohibited from using Buyers’ data for marketing or other commercial purposes not directly related to the performance of a sales contract concluded through the Store.
11. Changes to the Privacy Policy
We reserve the right to amend this Privacy Policy at any time to adapt it to changes in the law or in our data processing practices. Any changes will be posted on this page and will take effect on the date of publication, unless otherwise specified.
We recommend that you review the Privacy Policy regularly to stay informed about how we protect your data. We will notify you of significant changes via email if you have a Customer Account with us or have subscribed to our Newsletter.