22/02/2024
Both e-commerce terms and conditions and privacy policies are documents that cause sellers a lot of problems. Admittedly, the law indicates mandatory elements of both documents, but this does not mean that the regulations and privacy policies used by many sellers are legal and free of prohibited provisions. How to create them?
Entrepreneurs selling online must remember to post their store’s terms and conditions and privacy policy on their website. These documents should be drawn up in a transparent manner. In addition, both the terms and conditions and the privacy policy should be written in simple language that potential customers can understand. The documents should be placed in an easily accessible place so that users accessing the e-store have no problem reading them. According to the law, the buyer should be able to read the terms and conditions of the online store at the latest when he places an order. According to the case law, “if one of the parties uses a model contract in electronic form, it should make it available to the other party before the conclusion of the contract in such a way that it can store and reproduce the model in the ordinary course of business” (Judgment of the SA in Warsaw of March 15, 2013, VI ACa 1245/12). The privacy policy, on the other hand, should be made available at the latest at the time of data collection.
The seller should ensure that the content of the terms and conditions of the online store is correct, and that all necessary provisions are included. Why is this important? Since, according to Art. 8 paragraph. 2 of the Law on Provision of Electronic Services, the buyer is not bound by the provisions of the e-store regulations that were not made available to him in the manner indicated in Art. 8 paragraph. 1(2) of the aforementioned law, according to which “the service provider shall make the rules and regulations available to the service recipient free of charge prior to the conclusion of the contract for the provision of such services, and – upon the recipient’s request – in such a manner that allows the content of the rules and regulations to be acquired, reproduced and recorded by means of the information and communication system used by the service recipient.”
The law indicates what information should be included in the e-commerce terms and conditions. According to Art. 8 paragraph. 3 of the Law on Provision of Electronic Services, it should include provisions on:
The content of the terms and conditions of the online store should compulsorily include data identifying the seller. In doing so, it does not matter whether the seller is an individual, a sole proprietorship or a corporation. Among these figures are. Company name, business address, registration data (NIP, KRS) and contact information.
The law imposes an obligation on entrepreneurs to include in the regulations of e-commerce stores the technical requirements that the devices of potential customers who want to use the online store should have. This includes. o guidelines for the operating system, browser version and the obligation to install additional plug-ins necessary to operate the site. It is good practice to include in the document a prohibition on users providing unlawful content.
E-shop owners must include information on the type and scope of services provided in their terms and conditions. It should be emphasized that it is not only about selling products, but also about all other services that the seller performs. Listed among them are. newsletter mailing, account registration options, etc.
Another mandatory element of the e-commerce terms and conditions is the terms of conclusion and termination of contracts. The seller is obliged to indicate to buyers what type of contract will be concluded between the parties, as well as at what point the conclusion of the contract occurs – for example, whether the conclusion of the contract occurs when the buyer places an order, or perhaps, however, only after the acceptance of the order placed by the entrepreneur. In addition, the entrepreneur is required to specify the rules and methods of payment, as well as the term of the contract. The store should also specify the delivery methods for the order. Besides, the wording of the terms and conditions should instruct buyers about their right to withdraw from the contract.
According to the law, a consumer who has entered into a remote contract has the right to withdraw from it without giving a reason. In the case of online purchases, he has 14 days from receipt of the order by him or his designee. It is worth noting that the entrepreneur is obliged to notify him of this right. If he fails to do so, the buyer can exercise this right in the following 12 months. However, if the store provides the buyer with such information within this period, the deadline for withdrawal expires 30 days after receipt. In addition, a trader that allows buyers to submit a withdrawal declaration electronically is obliged to promptly confirm to the buyer the receipt of the withdrawal declaration submitted in this manner.
Another element of the regulations of the online store is a description of the complaint procedure. The entrepreneur is obliged to inform customers about the complaint procedure. The regulations should include provisions on the time limits for filing and processing complaints. The next issues that should be described in the body of the e-store regulations concern the rights that a consumer has in connection with a complaint and the course of the complaint procedure.
Sellers should beware of prohibited provisions in the text of the terms and conditions. What are they? Illegal provisions are also called abusive clauses. These are provisions that have not been individually agreed with consumers, and grossly violate their interests and shape their rights and obligations in a manner contrary to good morals. It is worth knowing that such provisions are not binding on buyers.
Among the prohibited provisions included in the terms and conditions of online stores, we can mention first of all those that limit or exclude the seller’s responsibility for the conformity of the ordered goods with the description. Other examples are clauses that limit or exclude a store’s liability for the actions of entities supplying consumers with a purchased product, and limit a consumer’s right to withdraw from a distance contract.
Privacy policy is a document that contains the information indicated in Art. 13 and Art. 14 RODO. This document must be posted on its website by any business that collects personal data from Internet users accessing its site. The purpose of the privacy policy is to provide users with the information required by the General Data Protection Regulation. The content of the privacy policy should be accessible to potential customers, that is, it must be written in simple language that they can understand.
According to Art. 13 and Art. 14 RODO, the content of the privacy policy should primarily include the entrepreneur’s data, including contact information. If the entrepreneur has appointed a data protection officer, his details are also to be included in the body of this document. Besides, the privacy policy should include the purposes of personal data processing and the legal basis for processing, as well as the legitimate interests pursued by the controller or by a third party. The entrepreneur is also required to include in the privacy policy information about the recipients of personal data or categories of recipients. In addition, according to Art. 13 and Art. 14 of the RODO, the vendor must include in the body of the document, “where applicable, information about the intention to transfer personal data to a third country or an international organization and the Commission’s finding or lack of finding of an adequate level of protection, or in the case of a transfer, mention of adequate or appropriate safeguards and information about how to obtain a copy of the safeguards or where they can be accessed.”
In particular, the seller is obliged to inform buyers about the period for which it stores their personal data. Besides, it must notify users of their right to request access to their personal data from the controller, as well as the right to rectify, erase or restrict processing, or the right to object to processing, and the right to data portability. The content of the privacy policy should also include information:
What about cookies? Does the privacy policy have to include them? The obligation to post them on the website stems not from RODO or the Electronic Services Act, but from the Telecommunications Law. so-called. A cookie policy is a document in which the seller informs users who use its website about the tracking tools used through it, so-called “cookies”. cookies. It should be noted that the cookie policy can be a separate document, but it can just as well function as part of the privacy policy. The law allows both options.