top of page

Privacy Policy

Information about the processing of personal data in accordance with the GDPR

1. Controller and Contact Details

  1. The controller of personal data is Leather Element Anna Jabłko, Niedźwiedzice 58, 59-225 Niedźwiedzice, Poland, Tax Identification Number (NIP): 9512233924.

  2. For matters concerning personal data, the Controller may be contacted by email at flocketroll@gmail.com, by telephone at +48 535 883 548 or by post at the Controller’s address.

  3. The Controller has not appointed a data protection officer. Privacy-related enquiries should be addressed directly to the Controller.

2. Scope and Sources of Data

  1. The Controller may process data provided by the User or Customer, in particular: name and surname, business name, NIP or another tax identification number, billing and delivery address, email address, telephone number, Account details, order information, correspondence and the content of complaints.

  2. Technical data relating to the use of the Store may also be processed, such as IP address, device and cookie identifiers, browser and system data, approximate location, website events and security data, to the extent determined by the selected cookie settings.

  3. Data is obtained directly from the User, from the device used to access the Store or from providers involved in processing the transaction, such as the payment service provider, Wix or UPS.

  4. The Seller does not receive full payment card details. These are processed directly by the authorised payment service provider.

3. Purposes, Legal Bases and Retention Periods

Account management, orders, payments, deliveries and Digital Content

Legal basis: Article 6(1)(b) GDPR — performance of a contract or steps taken before entering into a contract.

Retention period: for the duration of the contract and subsequently until the applicable limitation periods expire; as a rule, no longer than 6 years, taking into account end-of-year rules and specific provisions.

Accounting and tax records and legal obligations

Legal basis: Article 6(1)(c) GDPR.

Retention period: for the period required by law; as a rule, tax documents are retained for 5 years from the end of the year in which the tax payment deadline expired.

Complaints, contact, establishment, exercise and defence of claims

Legal basis: Article 6(1)(c) or (f) GDPR — legal obligation and legitimate interests.

Retention period: until the matter is concluded and subsequently until the applicable limitation period for claims or proceedings expires.

Store security, fraud prevention and diagnostics

Legal basis: Article 6(1)(f) GDPR — legitimate interests.

Retention period: for the period necessary to analyse the incident and defend against claims; for a shorter period if the data is no longer required.

Traffic measurement and statistics using Google Analytics

Legal basis: Article 6(1)(a) GDPR — consent.

Retention period: until consent is withdrawn or the purpose ceases to apply; Google Analytics user and event data is retained for 14 months, while the retention period for cookies is described in the Cookie Policy.

Evidence of consent and compliance with information obligations

Legal basis: Article 6(1)(c) and (f) GDPR.

Retention period: until the expiry of the period for possible claims or audits relating to the relevant consent.

If a single item of information is subject to several retention periods, the Controller applies the longest period required by law or necessary to protect legitimate rights. Once that period expires, the data is deleted or anonymised.

4. Recipients of Data

  1. Data may be entrusted or disclosed only to the extent necessary to achieve the relevant purpose: to Wix as the provider of the Store platform, hosting and Account functions; to Stripe and the relevant banks and payment service providers; to UPS as the carrier; to Google as the provider of Google Analytics after consent has been obtained; and to IT providers, accountants, legal advisers or public authorities where there is a legal basis for doing so.

  2. Not every recipient receives all data. The scope is limited to the necessary information; for example, UPS receives the information required for delivery, while the payment service provider receives the information required to authorise and secure the transaction.

  3. Providers may act as processors on behalf of the Controller or as separate controllers where they independently determine the purposes and means of processing required, for example, under payment, tax or transport law.

  4. The Controller does not sell personal data. The Controller currently does not conduct direct email marketing; introducing such a function will require this information to be updated and consent to be obtained where required by law.

5. Transfers of Data Outside the European Economic Area

  1. The use of Wix, Stripe, Google or other global providers may result in data being accessed from countries outside the European Economic Area, in particular the United States. The Controller uses providers that declare that they apply mechanisms provided for under the GDPR, such as a European Commission adequacy decision, the EU–US Data Privacy Framework or standard contractual clauses.

  2. When delivery is made to a country outside the EEA, the recipient’s data may be transferred to local UPS entities, customs agents or authorities where this is necessary to perform the contract with the Customer or take steps before entering into it.

  3. Information about the safeguards applied, or a copy of them with protected information removed, may be obtained by contacting the Controller.

6. Rights of the Data Subject

  1. Within the limits set out in the GDPR, the data subject has the rights to access their data and receive a copy, rectify or erase the data, restrict processing and receive data portability for data processed by automated means on the basis of consent or a contract.

  2. Where processing is based on legitimate interests, the data subject may object at any time on grounds relating to their particular situation. The Controller will cease processing unless it demonstrates compelling legitimate grounds that override the rights of the data subject or the need to establish, exercise or defend legal claims.

  3. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal. Consent to analytical cookies may be withdrawn through the cookie settings described in Part III.

  4. If a person believes that their data is being processed unlawfully, they may lodge a complaint with the President of the Polish Personal Data Protection Office. Information about lodging a complaint is available at https://uodo.gov.pl/pl/p/skargi.

  5. Requests may be submitted using the contact details in section 1. The Controller may request information necessary to confirm the identity of the data subject.

7. Voluntary Provision of Data and Automated Decisions

  1. Providing data is voluntary, but data marked as required is necessary to create an Account, accept an order, process payment, arrange delivery or handle a complaint. Without that data, the relevant service may not be possible.

  2. Consent to analytical cookies is voluntary, and refusing consent does not restrict the ability to place an order or use the Store’s basic functions.

  3. The Controller does not make decisions about Customers that produce legal effects or similarly significantly affect them based solely on automated processing. Payment service providers may use their own fraud-prevention mechanisms in accordance with their policies and legal obligations.

8. Security, Minors and Amendments

  1. The Controller applies technical and organisational measures appropriate to the risk, including access controls, secure connections and the use of providers that ensure appropriate safeguards.

  2. The Store is intended for adults. The Controller does not intend knowingly to collect data from persons under the age of 18 for the purpose of allowing them to enter into contracts in the Store.

  3. This Policy may be updated if the law, providers or the operation of the Store changes. The new version will be published together with its effective date. Amendments do not restrict acquired rights or change the legal basis for processing without the requirements of law being met.

bottom of page