Privacy Policy
1. What Data We Collect
| Category | Examples | Legal Basis (GDPR1) |
|---|---|---|
| Account Data | name, email, password (hash) | Art. 6(1)(b) — performance of a contract |
| Technical Data | IP address, browser, device, cookies | Art. 6(1)(f) — legitimate interest (security and analytics) |
| Payment Data | last 4 digits of card, payment system token | Art. 6(1)(b) |
| Marketing Data (opt.) | preferences, click history | Art. 6(1)(a) — consent |
1 GDPR — General Data Protection Regulation (Regulation (EU) 2016/679).
2. How We Collect Data
- When filling in forms — registration, orders, feedback.
- Automatically — through cookies and similar technologies.
- From third-party services — payment providers, social networks (with user permission).
3. How We Use Your Data
- provision and personalisation of services;
- processing payments and invoicing;
- website analytics and UX improvement;
- marketing communications (only with consent);
- security and fraud prevention;
- compliance with legal requirements.
4. Cookies and Trackers
| Cookie Type | Purpose | Retention Period |
|---|---|---|
| Strictly Necessary | login, cart, security | session / 1 year |
| Analytics (e.g. Google Analytics)* | visit statistics | up to 2 years |
| Marketing* | personalised advertising | 3–12 months |
* Set only after explicit consent requested via a banner on the first visit.
5. Sharing Data with Third Parties
| Recipient | Purpose | Safeguards |
|---|---|---|
| Payment Providers | payment processing | EU Standard Contractual Clauses (SCC) |
| Hosting / Cloud Services | data storage and backup | data centres within the EEA |
| Marketing Platforms (opt.) | email newsletters | provider's privacy policy |
We never sell personal data.
6. Storage and Security
- Data is retained only as long as necessary for processing purposes or as required by law.
- We use encryption: TLS in transit, AES-256 at rest.
- Two-factor access to the admin panel, regular audits and penetration tests.
7. User Rights (GDPR)
- access to a copy of your data;
- rectification of inaccuracies;
- erasure ("right to be forgotten");
- restriction of processing;
- data portability;
- withdrawal of consent at any time;
- objection to profiling and direct marketing.
To exercise any of these rights, please use the feedback form on the website. A response will be provided within 30 days.
8. Children's Policy
The website is not intended for persons under the age of 16 (or such other age as may be required by local law). We do not knowingly process children's data.
9. International Data Transfers
When transferring data outside the EEA, the following mechanisms apply:
- European Commission adequacy decision;
- Standard Contractual Clauses (SCC);
- Binding Corporate Rules (BCR).
10. Policy Updates
This policy may be updated. The current version is always available on this page; we will notify you of any material changes via a notice on the website or by other appropriate means. Date of last update: .