Legal Document · GDPR Compliant
Effective Date
May 20, 2026
Regulatory Basis
GDPR Art. 13 & 14
Version
1.0
This Privacy Policy ("Policy") is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) and sets out the mandatory disclosures that must be provided to data subjects at the time their personal data is collected or, where data is obtained from third parties, within a reasonable period. This Policy applies to all personal data processed by the operator of this platform ("we", "us", "our") acting as Data Controller.
The Data Controller is the operator of this platform. For all data-protection enquiries, you may contact us via:
Where a DPO has been appointed, their contact details are provided separately upon request and displayed in the cookie consent interface.
We process personal data for the following purposes and on the following legal bases:
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Account creation and management | Art. 6(1)(b) — Contract |
| Order fulfilment and payment processing | Art. 6(1)(b) — Contract |
| Legal and tax compliance | Art. 6(1)(c) — Legal obligation |
| Platform security and fraud prevention | Art. 6(1)(f) — Legitimate interests |
| Analytics and platform improvement | Art. 6(1)(a) — Consent |
| Direct marketing and newsletters | Art. 6(1)(a) — Consent |
| Responding to support enquiries | Art. 6(1)(b) — Contract / Art. 6(1)(f) — Legitimate interests |
| Business claim processing | Art. 6(1)(b) — Contract |
Depending on the nature of your interaction with the platform, we may collect:
Your personal data may be shared with or accessed by:
All third-party processors are engaged under data processing agreements compliant with Art. 28 GDPR. We do not sell personal data to third parties.
Where personal data is transferred outside the European Economic Area (EEA), such transfers are made only when one of the following safeguards is in place:
Details of applicable safeguards are available upon written request to our DPO contact.
We retain personal data only for as long as necessary for the stated purposes:
Upon expiry of the applicable period, data is securely deleted or irreversibly anonymised.
Under GDPR Chapter III, you have the right to:
To exercise any of these rights, please contact us via the details in Section 1. We will respond within 30 calendar days. We may request proof of identity before processing your request.
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Where any such processing is introduced in the future, you will be informed and your rights under Art. 22 GDPR will apply, including the right to human review.
Where processing is based on consent, you have the right to withdraw it at any time. Withdrawal may be effected through:
Withdrawal does not affect the lawfulness of any processing that took place prior to withdrawal. We will action the withdrawal within 72 hours of receipt.
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent data protection supervisory authority. In Poland, this is:
Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa
Website: uodo.gov.pl
Phone: +48 22 531 03 00
We nevertheless encourage you to contact us first so that we may resolve any concern directly and promptly.
Where personal data is not collected directly from the data subject, it may be obtained from:
In such cases, we will provide the disclosures required by Art. 14 GDPR within a reasonable period and no later than one month after obtaining the data.
We use cookies and similar tracking technologies. A full description of the types of cookies we use, their purposes, and retention periods is set out in our separate Cookie Policy. A consent banner is presented on first visit allowing you to accept or reject non-essential cookies by category. Your preferences can be updated at any time via the Cookie Settings panel.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
We may update this Policy periodically. Material changes will be communicated via a platform notification or email at least 14 days before taking effect. The date of the last update is shown at the top of this document. Where required by law, we will re-request your consent.