EN

AR

Privacy Policy

1. What Data We Collect

Category Examples Legal Basis (GDPR1)
Account Data name, email, password (hash) Art. 6(1)(b) — performance of a contract
Technical Data IP address, browser, device, cookies Art. 6(1)(f) — legitimate interest (security and analytics)
Payment Data last 4 digits of card, payment system token Art. 6(1)(b)
Marketing Data (opt.) preferences, click history Art. 6(1)(a) — consent

1 GDPR — General Data Protection Regulation (Regulation (EU) 2016/679).

2. How We Collect Data

  • When filling in forms — registration, orders, feedback.
  • Automatically — through cookies and similar technologies.
  • From third-party services — payment providers, social networks (with user permission).

3. How We Use Your Data

  • provision and personalisation of services;
  • processing payments and invoicing;
  • website analytics and UX improvement;
  • marketing communications (only with consent);
  • security and fraud prevention;
  • compliance with legal requirements.

4. Cookies and Trackers

Cookie Type Purpose Retention Period
Strictly Necessary login, cart, security session / 1 year
Analytics (e.g. Google Analytics)* visit statistics up to 2 years
Marketing* personalised advertising 3–12 months

* Set only after explicit consent requested via a banner on the first visit.

5. Sharing Data with Third Parties

Recipient Purpose Safeguards
Payment Providers payment processing EU Standard Contractual Clauses (SCC)
Hosting / Cloud Services data storage and backup data centres within the EEA
Marketing Platforms (opt.) email newsletters provider's privacy policy

We never sell personal data.

6. Storage and Security

  • Data is retained only as long as necessary for processing purposes or as required by law.
  • We use encryption: TLS in transit, AES-256 at rest.
  • Two-factor access to the admin panel, regular audits and penetration tests.

7. User Rights (GDPR)

  • access to a copy of your data;
  • rectification of inaccuracies;
  • erasure ("right to be forgotten");
  • restriction of processing;
  • data portability;
  • withdrawal of consent at any time;
  • objection to profiling and direct marketing.

To exercise any of these rights, please use the feedback form on the website. A response will be provided within 30 days.

8. Children's Policy

The website is not intended for persons under the age of 16 (or such other age as may be required by local law). We do not knowingly process children's data.

9. International Data Transfers

When transferring data outside the EEA, the following mechanisms apply:

  • European Commission adequacy decision;
  • Standard Contractual Clauses (SCC);
  • Binding Corporate Rules (BCR).

10. Policy Updates

This policy may be updated. The current version is always available on this page; we will notify you of any material changes via a notice on the website or by other appropriate means. Date of last update: .