PRIVACY POLICY

1. General Provisions

This Privacy Policy defines the rules for the processing and protection of personal data of users of the online store website operated by EGRAS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).

By using the website, placing an order or contacting the Administrator, the user accepts the terms of this Privacy Policy.


2. Personal Data Administrator

The administrator of personal data is:

EGRAS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Address: Al. Armii Krajowej 45, 50-541 Wrocław, Poland
NIP: 8993008694
REGON: 54015432800000
KRS: 0001137259
E-mail for personal data matters:
📧 [email protected]


3. Scope of Processed Personal Data

The Administrator may process the following personal data of users:

  • first and last name

  • e-mail address

  • phone number

  • delivery address

  • company details (company name, VAT/NIP number) – in case of business purchases

  • order details (ordered products, value, payment and delivery method)

  • IP address

  • data provided via contact forms or e-mail correspondence

  • data collected through cookies


4. Purposes of Personal Data Processing

Personal data are processed for the following purposes:

  • conclusion and performance of sales contracts

  • handling and fulfillment of orders

  • organization of product delivery

  • processing payments

  • contacting customers regarding orders

  • fulfillment of accounting and tax obligations

  • ensuring proper operation of the website

  • website analytics and statistics (Google Analytics)


5. Legal Grounds for Data Processing

Personal data are processed on the basis of:

  • Article 6(1)(b) GDPR – performance of a contract

  • Article 6(1)(c) GDPR – compliance with a legal obligation

  • Article 6(1)(f) GDPR – legitimate interests of the Administrator

  • Article 6(1)(a) GDPR – user consent (e.g. cookies, analytics)


6. Recipients of Personal Data

Personal data may be transferred to the following categories of recipients:

  • payment service providers (including Stripe, banks)

  • courier and logistics companies

  • parcel locker operators

  • accounting offices and legal advisors

  • hosting and IT service providers

  • analytics service providers (Google Analytics)

Personal data are transferred only to the extent necessary to achieve a given purpose.


7. Transfer of Data Outside the EU

Due to the use of Google Analytics and Stripe services, personal data may be transferred outside the European Union. Such transfers are carried out in accordance with GDPR, in particular on the basis of standard contractual clauses approved by the European Commission.


8. Data Retention Period

Personal data are stored:

  • order-related and accounting data – for the period required by applicable law

  • contract-related data – for the duration of the contract and after its termination as required by law

  • analytical data – in accordance with Google Analytics settings

  • data processed on the basis of consent – until the consent is withdrawn


9. User Rights

The user has the right to:

  • access their personal data

  • rectify personal data

  • request deletion of personal data (“right to be forgotten”)

  • restrict processing

  • data portability

  • object to processing

  • withdraw consent at any time

  • lodge a complaint with a supervisory authority

The supervisory authority in Poland is the President of the Personal Data Protection Office (PUODO).


10. Cookies

The website uses cookies to ensure proper operation and for analytical purposes (Google Analytics). Detailed information about cookies is available in a separate Cookie Policy.

Users may manage cookies through browser settings or via the cookie banner available on the website.


11. Data Security

The Administrator applies appropriate technical and organizational measures to protect personal data, including:

  • SSL encryption

  • server security measures

  • restricted access to data

  • regular system updates


12. Contact

For matters related to personal data processing, users may contact the Administrator at:
📧 [email protected]


13. Changes to the Privacy Policy

The Administrator reserves the right to make changes to this Privacy Policy. The current version of the document is always available on the website.