1. General Information1.1. This Privacy Policy explains how LULLLIO processes the personal data of visitors to the website located at:
https://lulllio.com, as well as other language and regional LULLLIO pages intended for users in the European Union, including Germany, Poland, Italy, France, the Netherlands and other Member States of the European Union.
1.2. This Policy has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, hereinafter referred to as the GDPR, and taking into account Directive 2002/58/EC on privacy and electronic communications, hereinafter referred to as the ePrivacy Directive, and the applicable national laws of the Member States of the European Union.
1.3. The controller of personal data, i.e. the entity that determines the purposes and means of processing personal data, is:
SONTELA SP. Z O.O.
Address: Brzozowa 3, 05-840 Brwinów, Poland
VAT: PL5213926190
Representative: Andrii Pukhalsky
Phone: +48 664 035 742
E-mail for enquiries regarding personal data:
support@sontela.euhereinafter referred to as the “Company”, “we”, “us” or “LULLLIO”.
1.4. This Policy applies to visitors to the LULLLIO website, blog readers, users following links placed on the website, as well as other persons interacting with the LULLLIO website.
1.5. The LULLLIO website is an informational website and blog. The website publishes information about the LULLLIO brand, LULLLIO products, materials for parents and other thematic articles.
1.6. The website does not use contact forms, subscription forms, order forms, comment forms, review publication forms, advertising pixels, remarketing tools or web analytics systems.
1.7. If a user follows links from the LULLLIO website to third-party websites, including marketplaces, social networks, messengers, video hosting platforms, map services, payment services, logistics services or other external platforms, the processing of personal data on such websites is carried out by the respective third parties in accordance with their own privacy policies. LULLLIO does not control such websites and is not responsible for their data processing rules.
2. Key Definitions2.1. Personal data means any information relating to an identified or identifiable natural person, as defined in Article 4 of the GDPR.
2.2. Data subject means the natural person to whom the personal data relates.
2.3. Processing means any operation or set of operations performed on personal data, including collection, recording, storage, use, transfer, erasure and other operations specified in Article 4 of the GDPR.
2.4. Controller means the entity that determines the purposes and means of processing personal data.
2.5. Processor means the entity that processes personal data on behalf of the controller.
2.6. Cookies means small text files and similar technologies that are stored on the user’s device or allow access to information on the user’s device.
3. What Personal Data Is Processed When Visiting the Website3.1. The LULLLIO website does not collect personal data through forms, subscriptions, comments or user accounts.
3.2. When visiting the website, limited technical data necessary for displaying the website, ensuring its security and stable operation may be processed automatically, including:
- IP address;
- date and time of the website visit;
- address of the requested page;
- browser type and version;
- device type;
- operating system;
- browser language;
- technical data regarding the transmission of the request;
- server log data;
- information about website loading errors.
3.3. The above technical data is processed automatically when the user’s browser interacts with the website and the server infrastructure necessary for the operation of the website.
3.4. We do not use the above technical data to identify the user independently.
3.5. We do not request or collect through the website special categories of personal data referred to in Article 9 of the GDPR, including health data, biometric data, information about religious beliefs, political opinions, ethnic origin or sexual life.
3.6. We do not intentionally collect personal data of children. The website is intended for adult users, including parents, guardians and other adults interested in LULLLIO products and materials.
4. Purposes of Personal Data Processing4.1. Technical data of website visitors is processed for the following purposes:
- ensuring that the website is displayed in the user’s browser;
- ensuring the stable and secure operation of the website;
- diagnosing technical errors;
- preventing abuse, unauthorised access and technical attacks;
- ensuring compatibility of the website with users’ devices and browsers;
- administering the website and server infrastructure;
- fulfilling the Company’s legal obligations;
- protecting the rights, legitimate interests and security of the Company, users and third parties.
4.2. We do not use website visitors’ data for behavioural advertising, remarketing, profiling, newsletters or automated decision-making.
5. Legal Bases for Processing under the GDPR5.1. Personal data is processed only where there is a legal basis provided for in Article 6 of the GDPR.
5.2. To ensure the technical operation of the website, its security, error diagnostics and prevention of abuse, the Company processes technical data on the basis of Article 6(1)(f) of the GDPR — the Company’s legitimate interest in ensuring the stable, secure and correct operation of the website.
5.3. To comply with legal obligations, where such obligations apply to the Company, processing is carried out on the basis of Article 6(1)(c) of the GDPR.
5.4. To protect the Company’s rights and legitimate interests, including recording technical events, investigating security incidents and defence in the event of claims, processing is carried out on the basis of Article 6(1)(f) of the GDPR.
5.5. Since the website does not contain forms, subscriptions, comments, advertising pixels, remarketing or web analytics, the Company does not request the user’s consent to process personal data through such tools.
6. Cookies and Similar Technologies6.1. The website may use only necessary technical cookies and similar technologies that are required for the proper operation of the website, its display, security and the storage of basic technical settings.
6.2. Necessary cookies are not used for advertising, remarketing, behavioural profiling or marketing analytics.
6.3. Necessary cookies may be used without the user’s separate consent if they are strictly necessary to provide the service requested by the user and for the proper operation of the website, in accordance with the ePrivacy Directive and applicable national law.
6.4. The user may restrict or delete cookies through the settings of their browser. Disabling necessary cookies may result in the incorrect operation of certain elements of the website.
6.5. The website is hosted on the Tilda platform. In this regard, technical cookies and similar technologies may be used by the Tilda platform to ensure the operation, display and security of the website.
6.6. The website does not use advertising cookies, analytics cookies, pixels, remarketing or other non-essential tracking technologies.
7. To Whom Personal Data May Be Disclosed7.1. Technical data of website visitors may be disclosed or made available to a limited group of recipients if this is necessary for the operation of the website, ensuring its security or fulfilling legal obligations.
7.2. Recipients of such data may include:
the website platform provider Tilda;
hosting and server infrastructure providers;
domain and technical website administration service providers;
information security service providers;
legal, tax, accounting and other professional advisers of the Company;
public authorities, courts and regulators, where disclosure is required by law.
7.3. If a third party processes personal data on behalf of the Company, it is a processor within the meaning of Article 28 of the GDPR. In such a case, the Company uses appropriate contractual mechanisms with the processor, including a data processing agreement or other terms compliant with Article 28 of the GDPR.
7.4. The Company does not sell personal data of website visitors to third parties.
8. International Data Transfers8.1. The Company is located in Poland and strives to process users’ personal data within the European Economic Area, hereinafter referred to as the EEA.
8.2. Some technical service providers necessary for the operation of the website may use infrastructure outside the EEA. In such cases, personal data may be transferred to third countries.
8.3. Transfers of personal data outside the EEA are carried out only where one of the mechanisms provided for in Chapter V of the GDPR applies, including:
- an adequacy decision of the European Commission regarding the protection of data in the relevant country, Article 45 of the GDPR;
- standard contractual clauses of the European Commission, Article 46 of the GDPR;
- binding corporate rules, where applicable;
- other lawful mechanisms provided for in Articles 46–49 of the GDPR.
8.4. If data is transferred to providers in the USA, such transfer may be carried out, in particular, on the basis of the EU-U.S. Data Privacy Framework, provided that the relevant provider participates in that programme, or on the basis of the European Commission’s standard contractual clauses and additional safeguards, where necessary.
9. Data Retention Periods9.1. The Company retains personal data no longer than is necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
9.2. Technical data and server logs are stored for the period necessary to ensure website security, diagnose technical errors and prevent abuse.
9.3. As a rule, technical logs are retained for no longer than 12 months, unless longer retention is required to investigate a security incident, protect the Company’s rights or fulfil a legal obligation.
9.4. Data necessary to protect the Company’s rights and legitimate interests may be retained for the limitation period applicable to the relevant claim.
9.5. Cookies are stored for the technically necessary period determined by their purpose and the settings of the website platform.
10. User Rights under the GDPR10.1. In accordance with the GDPR, the user has the following rights:
- the right to receive information about data processing, Articles 12–14 of the GDPR;
- the right of access to personal data, Article 15 of the GDPR;
- the right to rectification of inaccurate data, Article 16 of the GDPR;
- the right to erasure of data, Article 17 of the GDPR;
- the right to restriction of processing, Article 18 of the GDPR;
- the right to data portability, Article 20 of the GDPR;
- the right to object to processing, Article 21 of the GDPR;
- the right not to be subject to a decision based solely on automated processing, including profiling, Article 22 of the GDPR;
- the right to lodge a complaint with a supervisory authority, Article 77 of the GDPR.
10.2. The user has the right to object to the processing of personal data based on the Company’s legitimate interests under Article 6(1)(f) of the GDPR.
10.3. To exercise their rights, the user may send a request to the e-mail address specified in Section 16 of this Policy.
10.4. To protect the user’s data, the Company may request additional information necessary to confirm the identity of the applicant.
10.5. The Company responds to user requests without undue delay and, as a rule, within one month of receiving the request. This period may be extended by a further two months, taking into account the complexity and number of requests, of which the user will be notified in accordance with Article 12 of the GDPR.
11. Right to Lodge a Complaint with a Supervisory Authority11.1. The user has the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data violates the GDPR.
11.2. Since the Company is located in Poland, the main supervisory authority may be the Polish data protection authority:
Prezes Urzędu Ochrony Danych Osobowych, UODO
ul. Stawki 2, 00-193 Warszawa, Poland
Website:
https://uodo.gov.pl11.3. The user may also contact the supervisory authority of the country of their habitual residence, place of work or place of the alleged infringement.
11.4. For users in the countries targeted by the LULLLIO website, the competent supervisory authorities may include, in particular:
12. Data Security12.1. The Company takes appropriate technical and organisational measures to protect personal data in accordance with Article 32 of the GDPR.
12.2. Such measures may include restricting access to data, using a secure connection, technical administration of the website, security monitoring, backups, vendor management, contractual obligations of processors and other security measures.
12.3. Despite the measures taken, data transmission over the internet cannot be completely secure. The user should take this into account when using the website.
13. Security Incidents13.1. In the event of a personal data breach, the Company assesses the risks to the rights and freedoms of users and takes the necessary measures.
13.2. If a personal data breach creates a risk to the rights and freedoms of natural persons, the Company notifies the competent supervisory authority in accordance with Article 33 of the GDPR.
13.3. If the breach is likely to result in a high risk to the rights and freedoms of the user, the Company notifies the user in accordance with Article 34 of the GDPR, where such notification is required by law.
14. Automated Decision-Making and Profiling14.1. The Company does not make decisions based solely on automated processing of personal data that produce legal effects concerning the user or similarly significantly affect the user, within the meaning of Article 22 of the GDPR.
14.2. The Company does not use personal data of website visitors for behavioural profiling, remarketing or personalised advertising.
15. Children’s Data15.1. The LULLLIO website is intended for adult users, including parents, guardians and other adults interested in LULLLIO products and materials.
15.2. The Company does not ask children to provide personal data independently and does not direct the website for independent use by children.
15.3. The Company does not intentionally collect children’s personal data through the website.
16. ContactsFor all matters related to the processing of personal data and the exercise of rights under the GDPR, the user may contact the Company:
SONTELA SP. Z O.O.
Brzozowa 3
05-840 Brwinów
Poland
VAT: PL5213926190
Representative: Andrii Pukhalsky
Phone: +48 664 035 742
E-mail:
support@sontela.euCountries whose users the website is aimed at: Germany, Poland, Italy, France, the Netherlands and other Member States of the European Union.
17. Links to Third-Party Websites17.1. The website may contain links to third-party websites, including marketplaces, social networks, messengers, video hosting platforms, information resources and other external platforms.
17.2. By following such a link, the user leaves the LULLLIO website. Further processing of personal data is carried out by the relevant third-party platform in accordance with its own privacy policy.
17.3. The Company does not control the rules for processing personal data on third-party websites and recommends that the user read their privacy policies before providing personal data.
18. Changes to the Policy18.1. The Company may update this Policy periodically.
18.2. The new version of the Policy becomes effective from the moment it is published on the website, unless otherwise stated therein.
18.3. If changes significantly affect users’ rights or the nature of personal data processing, the Company will take reasonable measures to inform users, where required by law.