§ 1. General information
- This Privacy Policy sets out the rules for processing personal data of users of the Ciao Cane Lusso online store at ciaocanelusso.com (the “Store”), and the use of cookies and similar technologies.
- The Policy fulfils, in particular, information obligations under Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and takes account of the Polish Electronic Communications Act of 12 July 2024.
- Capitalised terms not defined here have the meaning given to them in the Store Terms and Conditions.
§ 2. Data controller
- The controller of personal data is Ciao Cane Łukasz Drwal, NIP: 513 029 53 67, ul. Cegielniana 27A/2, 32-085 Modlnica, Poland (the “Controller”).
- You can contact the Controller by email: kontakt@ciaocanelusso.pl; by phone: +48 731 461 471; or by post at the address above.
- The Controller has not appointed a data protection officer. For personal-data matters, please contact the Controller directly.
§ 3. Purposes, legal bases and retention periods
| Purpose and scope | Legal basis | Retention period |
|---|---|---|
| Accepting and fulfilling an order: identification, contact and address data, order information and, for a business purchase, company details and NIP. | Article 6(1)(b) GDPR. | Until performance of the contract and then until the relevant limitation period expires. |
| Settlements, accounting records and tax duties. | Article 6(1)(c) GDPR. | For the period required by tax and accounting rules, generally 5 years from the end of the relevant tax year. |
| Customer Account: email address, address details and order history. | Article 6(1)(b) GDPR. | Until Account deletion, then only to the extent required by law or needed to handle claims. |
| Complaints, withdrawals, returns and other Customer rights. | Article 6(1)(b) and (c) GDPR. | Until the matter ends and then until the relevant limitation period expires. |
| Email or phone contact: data included in an enquiry. | Article 6(1)(f) GDPR — legitimate interest in handling correspondence. | Up to 12 months after correspondence ends unless longer retention is needed for claims. |
| Security, fraud prevention, diagnostics and technical logs, including IP address, time and request details. | Article 6(1)(f) GDPR — Store security and defence against abuse. | For the time needed for diagnostics and security, generally no longer than 12 months. |
| Establishing, pursuing or defending claims. | Article 6(1)(f) GDPR. | Until the relevant limitation period expires. |
| Newsletter or other electronic marketing, where available and consented to by the user. | Article 6(1)(a) GDPR and Article 398 of the Polish Electronic Communications Act. | Until consent is withdrawn, the service ends, or the purpose permanently ceases to be current. |
Providing data is voluntary, but fields marked as required are needed, as applicable, to place and fulfil an order, maintain an Account or provide a response.
§ 4. Sources and recipients of data
- We obtain data primarily directly from the person concerned. If an ordering customer gives us another recipient’s delivery data, the ordering customer is the source of that data and should inform the recipient that their data were provided to the Controller.
- Only to the extent necessary, data may be received by hosting, email, website-maintenance and IT-support providers; couriers, postal operators and other delivery providers selected for the order; payment providers or banks, depending on the chosen payment method; accounting, legal and claims-support providers; and public authorities where disclosure is required by law.
- Some recipients act as processors on the Controller’s documented instructions. Others, in particular banks, payment providers, carriers and public authorities, may act as separate controllers under their own legal obligations.
- The Controller does not receive full payment-card data. Where online payment is made available, card data are processed directly by the selected payment provider; the Store receives mainly a transaction identifier and status.
§ 5. Transfers outside the EEA
- The Controller does not plan to independently transfer data outside the European Economic Area.
- If a necessary service provider uses infrastructure outside the EEA, a transfer may take place only using a GDPR-permitted mechanism, in particular an adequacy decision or standard contractual clauses with the required safeguards. Information about the mechanism used is available from the Controller.
§ 6. Your rights
- Subject to the conditions in the GDPR, you have the right to access data and receive a copy, rectification, erasure, restriction, portability, objection to processing based on Article 6(1)(f) GDPR, and withdrawal of consent at any time.
- Withdrawing consent does not affect the lawfulness of processing carried out before it was withdrawn. Individual rights are not absolute and their scope depends on the GDPR conditions, in particular the basis and purpose of further processing.
- Requests may be sent using the contact details in § 2. The Controller may request information needed to confirm the requester’s identity.
- The Controller responds without undue delay, normally within one month of receipt. Where necessary due to complexity or the number of requests, this may be extended by two further months; you will be informed of the extension and reasons within one month.
- If you believe data are processed unlawfully, you may lodge a complaint with the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.
§ 7. Automated decisions
Data are not used to make decisions concerning a Customer based solely on automated processing that produce legal effects or similarly significantly affect the Customer. The Store does not carry out profiling in that sense.
§ 8. Cookies and similar technologies
- The Store uses necessary cookies and similar mechanisms for the bag, session, login, security, technical settings and correct display of the website.
- Use of information stored on a device takes place in accordance with Article 399 of the Polish Electronic Communications Act. Necessary cookies are used to provide functions explicitly requested by the user and to ensure security; they are not used for advertising.
- The Store currently does not use analytics or advertising cookies. If introduced, they will be activated only after prior, voluntary consent, which can be withdrawn just as easily.
- You can delete and block cookies in browser settings. Blocking necessary cookies may prevent login, bag retention or placing an order.
§ 9. Security
- The Controller applies technical and organisational measures appropriate to the risk, including HTTPS transmission encryption, access controls, software updates and backups.
- Only authorised persons and entities requiring access to perform a service or legal duty have access to data.
§ 10. Changes to this Policy
- This Policy may be updated if law, the Store’s operation or services used change.
- The current version, with its effective date, is always available at ciaocanelusso.com/polityka-prywatnosci/.