Privacy Policy
of the "Cat's Atelier" Online Store
www.catsatelier.com 

 

TABLE OF CONTENTS:

  1. GENERAL PROVISIONS

  2. BASIS OF DATA PROCESSING

  3. PURPOSE, LEGAL BASIS, AND PERIOD OF DATA PROCESSING IN THE ONLINE STORE

  4. DATA RECIPIENTS IN THE ONLINE STORE

  5. PROFILING IN THE ONLINE STORE

  6. RIGHTS OF THE DATA SUBJECT

  7. COOKIES IN THE ONLINE STORE AND ANALYTICS

  8. FINAL PROVISIONS

 

1.  GENERAL PROVISIONS

1.1. This privacy policy of the "Cat's Atelier" Online Store is of an informative nature, which means it is not a source of obligations for Service Recipients or Customers of the Online Store. The privacy policy primarily contains rules regarding the processing of personal data by the Administrator in the Online Store, including the legal basis, purposes, and duration of personal data processing, as well as the rights of individuals whose data is processed. It also includes information about the use of Cookies and analytical tools in the Online Store.

1.2. The Administrator of personal data collected through the "Cat's Atelier" Online Store is Jerzy Wołk, conducting business under the name WOMAT - Jerzy Wołk, registered in the Central Register and Information on Economic Activity of the Republic of Poland, maintained by the minister responsible for economic affairs, with a business address and correspondence address at: Poland, 63-600 KĘPNO, ul. Wiosenna 7. Tax Identification Number (NIP): 6190006321, National Business Registry Number (REGON): 003350858, email address: hello@catsatelier.com - hereinafter referred to as the "Administrator," who is also the Service Provider of the Online Store and the Seller.

1.3. Personal data in the Online Store is processed by the Administrator in accordance with applicable legal regulations, especially with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as "GDPR" or "GDPR Regulation." The official text of the GDPR Regulation can be found at: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

1.4. Using the Online Store, including making purchases, is voluntary. Likewise, providing personal data by the Service Recipient or Customer using the Online Store is voluntary, with two exceptions:
(1) Entering into agreements with the Administrator - failure to provide the necessary personal data in cases and to the extent indicated on the Online Store's website, as well as in the Online Store Regulations and this privacy policy, necessary for the conclusion and performance of a Sales Agreement or an Electronic Service Agreement with the Administrator, will result in the inability to conclude the respective agreement. Providing personal data is a contractual requirement in such cases, and if the data subject wishes to enter into a specific agreement with the Administrator, they are obliged to provide the required data. The scope of data required to conclude an agreement is indicated in advance on the Online Store's website and in the Online Store Regulations.
(2) Legal obligations of the Administrator - providing personal data is a legal requirement arising from universally applicable legal regulations that impose an obligation on the Administrator to process personal data (e.g., processing data for tax or accounting purposes), and failure to provide them will prevent the Administrator from fulfilling these obligations.

1.5. The Administrator takes special care to protect the interests of individuals whose personal data is processed by ensuring that the collected data are:
(1) Processed lawfully,
(2) Collected for specified, lawful purposes and not subjected to further processing incompatible with those purposes,
(3) Accurate and relevant in relation to the purposes for which they are processed,
(4) Stored in a form that allows the identification of individuals for no longer than necessary to achieve the processing purpose, (5) Processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage, using suitable technical or organizational measures.

1.6. Considering the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the Administrator implements appropriate technical and organizational measures to ensure that processing complies with this regulation and can demonstrate it. These measures are periodically reviewed and updated if necessary. The Administrator employs technical measures to prevent unauthorized acquisition and modification of personal data transmitted electronically.

1.7. All words, phrases, and acronyms starting with capital letters (e.g., Seller, Online Store, Electronic Service) in this privacy policy should be understood in accordance with their definitions provided in the Online Store Regulations available on the Online Store's website.

2.  BASIS OF DATA PROCESSING
2.1. The Administrator is authorized to process personal data when - and to the extent - at least one of the following conditions is met:
(1) The data subject has given consent to the processing of their personal data for one or more specific purposes.
(2) Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.
(3) Processing is necessary to comply with a legal obligation to which the Administrator is subject.
(4) Processing is necessary for the purposes of legitimate interests pursued by the Administrator or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, which require the protection of personal data, especially when the data subject is a child.

2.2. The processing of personal data by the Administrator always requires the existence of at least one of the bases mentioned in point 2.1 of the privacy policy. The specific legal bases for processing the personal data of Service Recipients and Customers of the Online Store by the Administrator are indicated in the subsequent section of the privacy policy, concerning the specific purpose of data processing by the Administrator.

3.  PURPOSE, LEGAL BASIS, AND PERIOD OF DATA PROCESSING IN THE ONLINE STORE

3.1. Each time, the purpose, legal basis, period, and recipients of personal data processed by the Administrator are determined by the actions taken by the individual Service Recipient or Customer in the Online Store or by the Administrator.

3.2. The Administrator may process personal data in the Online Store for the following purposes, based on the legal grounds and periods indicated in the table below:

Purpose of data processing 

Legal basis for data processing

Data retention period

Execution of a Sales Agreement or an Electronic Service Agreement or taking actions at the request of the data subject prior to entering into the aforementioned agreements.

Article 6(1)(b) of the GDPR (execution of a contract) – processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract.

The data is retained for the period necessary for the performance, termination, or other expiry of the concluded Sales Agreement or Electronic Service Agreement.

Direct marketing

Article 6(1)(f) of the GDPR (legitimate interests of the data controller) – processing is necessary for the purposes of the legitimate interests pursued by the Administrator – which include safeguarding the interests and good reputation of the Administrator, their Online Store, and the pursuit of product sales.

The data is retained for the period of the existence of the legitimate interest pursued by the Administrator, but no longer than the limitation period for the Administrator's claims against the data subject arising from the Administrator's business activity. The limitation periods are determined by the applicable law, especially the Civil Code (the basic limitation period for claims related to business activity is three years, and for Sales Agreements, it's two years). The Administrator cannot process data for direct marketing purposes in case of an effective objection raised by the data subject in this regard.

Marketing

Article 6(1)(a) of the GDPR (consent) – the data subject has provided consent for the processing of their personal data for marketing purposes by the Data Controller.

Marketing - Article 6(1)(a) of the GDPR (consent) – the data subject has given consent to the processing of their personal data for marketing purposes by the Administrator.

The data is stored until the data subject withdraws their consent for further processing of their data for this purpose.

Keeping tax books

Article 6(1)(c) of the GDPR in conjunction with Article 86(1) of the Tax Ordinance Act, dated January 17, 2017 (Journal of Laws of 2017, item 201, as amended) – processing is necessary to fulfill a legal obligation incumbent on the Controller.

The data is stored for the period required by legal provisions obliging the Controller to keep tax records (until the expiration of the statute of limitations for tax liability, unless tax laws provide otherwise).



Establishment, investigation, or defense of claims that the Administrator may assert or that may be asserted against the Administrator.

Article 6(1)(f) of the GDPR (legitimate interests of the data controller) – processing is necessary for the purposes of the legitimate interests pursued by the Administrator, which include establishing, investigating, or defending claims that the Administrator may assert or that may be asserted against the Administrator.

The data is retained for the duration of the legitimate interest pursued by the Administrator but no longer than the limitation period for claims that may be asserted against the Administrator (the basic limitation period for claims against the Administrator is six years).

Using the Online Store website and ensuring its proper functioning.

Article 6(1)(f) of the GDPR (legitimate interests of the data controller) – processing is necessary for the purposes of the legitimate interests pursued by the Administrator, which include running and maintaining the Online Store website.

Using the Online Store website and ensuring its proper functioning. Article 6(1)(f) of the GDPR (legitimate interests of the data controller) – processing is necessary for the purposes of the legitimate interests pursued by the Administrator, which include running and maintaining the Online Store website.

The data is retained for the duration of the legitimate interest pursued by the Administrator, but no longer than the limitation period for claims that may be asserted against the Administrator arising from the Administrator's business activity. The limitation periods are determined by the applicable law, especially the Civil Code (the basic limitation period for claims related to business activity is three years, and for Sales Agreements, it's two years).

Maintaining statistics and analyzing traffic on the Online Store.

Article 6(1)(f) of the GDPR (legitimate interests of the data controller) – processing is necessary for the purposes of the legitimate interests pursued by the Administrator, which include maintaining statistics and analyzing traffic on the Online Store for the purpose of improving the functioning of the Online Store and increasing product sales.

The data is retained for the duration of the legitimate interest pursued by the Administrator, but no longer than the limitation period for claims that may be asserted against the Administrator arising from the Administrator's business activity. The limitation periods are determined by the applicable law, especially the Civil Code (the basic limitation period for claims related to business activity is three years, and for Sales Agreements, it's two years).

 

4.  RECIPIENTS OF DATA IN THE ONLINE STORE

4.1. For the proper functioning of the Online Store, including the execution of Sales Agreements, the Administrator may need to use the services of external entities (such as software providers, couriers, or payment processors). The Administrator only uses the services of such data processors who provide sufficient guarantees for the implementation of appropriate technical and organizational measures to ensure that the processing complies with the requirements of the GDPR and protects the rights of the individuals whose data is being processed.

4.2. Personal data may be transferred by the Administrator to third countries. In such cases, the Administrator ensures that the transfer is made to a country that provides an adequate level of protection in accordance with the GDPR. For other countries, the transfer will be based on standard data protection clauses. The Administrator ensures that the data subject has the opportunity to obtain a copy of their data. The Administrator only transfers the collected personal data when it is necessary for the specific purpose of processing data in accordance with this privacy policy.

4.3. The transfer of data by the Administrator does not occur in every case and not to all recipients or categories of recipients mentioned in the privacy policy. The Administrator only transfers data when it is necessary to achieve the specific purpose of processing personal data and only to the extent necessary to achieve that purpose. For example, if a customer chooses personal pickup, their data will not be transferred to a courier working with the Administrator.

4.4. Recipients or categories of recipients to whom the personal data of Service Recipients and Customers of the Online Store may be disclosed include:
4.4.1. Carriers / freight forwarders / courier brokers / entities handling warehouse and/or shipping processes – In the case of a Customer who chooses postal or courier delivery for a Product purchased in the Online Store, the Administrator provides the collected personal data of the Customer to the selected carrier, freight forwarder, or intermediary responsible for shipping on behalf of the Administrator. If the shipment is made from an external warehouse, the data may also be provided to entities handling the warehouse and/or shipping processes, to the extent necessary to fulfill the delivery of the Product to the Customer. Specifically, the companies FedEx, UPS, and Poczta Polska fall under this category.
4.4.2. Entities providing electronic payment or credit card payment services – In the case of a Customer who uses electronic payment methods or credit card payments in the Online Store, the Administrator provides the collected personal data of the Customer to the selected entity responsible for processing these payments in the Online Store on behalf of the Administrator. This is done to facilitate the payment process initiated by the Customer. Specifically, this may include entities such as Google Pay, Apple Pay, PayPal, Stripe, and Klarna, which facilitate payment channels.
4.4.3. Credit providers / lessors – In the case of a Customer who chooses the payment installment option in the Online Store, the Administrator provides the collected personal data of the Customer to the selected credit provider responsible for processing these payments in the Online Store on behalf of the Administrator. This is done to facilitate the payment installment process initiated by the Customer. Specifically, Klarna is an example of a company handling installment payments.
4.4.4. Suppliers of services providing the Administrator with technical, IT, and organizational solutions necessary for the Administrator to conduct business activities, including the Online Store and the provision of Electronic Services through it (especially computer software providers for operating the Online Store, email and hosting providers, and software providers for managing the business and providing technical support to the Administrator) – The Administrator provides the collected personal data of the Customer to selected suppliers who act on its behalf only when necessary to achieve the specific purpose of data processing in accordance with this Privacy Policy. Specifically, entities mentioned in this point may include companies such as Google (Google Analytics tool), SeoHost (hosting), MailerLite (newsletters), BaseLinker (sales support), and Hotjar (traffic analysis).
4.4.5. Providers of accounting, legal, and advisory services, providing the Administrator with accounting, legal, or advisory support (especially accounting firms, law firms, or debt collection companies) – The Administrator provides the collected personal data of the Customer to selected providers who act on its behalf only when necessary to achieve the specific purpose of data processing in accordance with this Privacy Policy. Specifically, the entity referred to in this point is the accounting office ATRIUM
4.4.6. Providers of social media plugins, scripts, and similar tools placed on the Online Store's website, allowing the browser of the visiting person to retrieve content from these plugin providers (e.g., logging in using social media credentials) and, for this purpose, transferring personal data of the visiting person, including:
4.4.6.1. Meta Platforms Ireland Ltd. – The Administrator uses social media plugins from Facebook on the Online Store's website (e.g., "Like" button, "Share" button, or login using Facebook credentials). Therefore, the Administrator collects and shares the personal data of the Service Recipient using the Online Store's website with Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland) to the extent and in accordance with the privacy principles available here: