1. Data Controller
[TO BE FILLED] The data controller is ZŁOTNIK – JUBILER WOJCIECH ARASZKIEWICZ, al. Wyzwolenia 41/u 1, 70-531 Szczecin, Poland, NIP: [TO BE FILLED], REGON: [TO BE FILLED]. Contact for data protection matters: info@jubileraraszkiewicz.pl
2. Types of Personal Data Collected
[TO BE FILLED] We collect the following personal data: account data (name, email, phone), order data (delivery address, billing address), payment data (method, transaction ID - card details processed by Przelewy24), newsletter data (email), contact form data (name, email, phone, message), technical data (IP address, browser type, cookies).
3. Purpose and Legal Basis for Processing
[TO BE FILLED] We process data for: order fulfillment (Art. 6(1)(b) GDPR), payment processing (Art. 6(1)(b)), shipping (Art. 6(1)(b)), customer accounts (Art. 6(1)(a)), newsletters (Art. 6(1)(a)), responding to inquiries (Art. 6(1)(f)), invoicing (Art. 6(1)(c)), website analytics (Art. 6(1)(a)), security (Art. 6(1)(f)).
4. Data Recipients
[TO BE FILLED] Data may be shared with: Przelewy24 (PayPro S.A.) - payment processing, FedEx - delivery, email provider - transactional emails, Google Analytics - website analytics (with consent), hosting provider - server infrastructure.
5. Data Retention Periods
[TO BE FILLED] Order data: 5 years (tax law requirement). Account data: until account deletion. Newsletter: until unsubscribe. Server logs: 14 days. Contact forms: 12 months. Cookies: per cookie duration (see cookie policy).
6. Your Rights
[TO BE FILLED] You have the following rights: right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restrict processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21), right to withdraw consent at any time, right to lodge a complaint with the supervisory authority (UODO).
7. Cookies
[TO BE FILLED] Our website uses cookies: necessary (session, CSRF token, locale preferences), analytics (Google Analytics - with consent), marketing (Microsoft Clarity - with consent). See the cookie consent banner for details.
8. International Data Transfers
[TO BE FILLED] Data may be transferred outside the European Economic Area through Google Analytics services. The legal basis is Standard Contractual Clauses.
9. Data Security
[TO BE FILLED] We implement appropriate technical and organizational measures, including TLS encryption, access controls, and regular security audits.
10. Changes to This Policy
[TO BE FILLED] This privacy policy may be updated. Significant changes will be communicated through our website. We recommend reviewing this policy regularly.