Privacy Policy
Store address: https://ozzidesign.eu
Controller:
OZZI DESIGNE Dominik Ozga,
Świętojańska 101, 35-304 Rzeszów, Poland,
VAT EU: PL8133870856,
e-mail: shop@ozzidesign.eu,
Tel.:
+48 667 634 678 (PL)
+48 721 506 234 (EN)
1) Zakres dokumentu i powiązania
This document describes the processing of personal data in the Store and communication channels (forms, e-mail, phone, newsletter, customer account). Cookie rules are described in a separate Cookie Policy.
2) Categories of data
- Identification data;
- contact data; order data;
- account data; marketing data (with consent);
- technical data (logs, device identifiers – details in the Cookie Policy).
3) Purposes and legal bases
- Order fulfillment and contract performance – Art. 6(1)(b) GDPR.
- Customer account management – Art. 6(1)(b) GDPR.
- Contact and handling inquiries – Art. 6(1)(b/f) GDPR.
- Newsletter/marketing – Art. 6(1)(a) GDPR (consent) and/or Art. 6(1)(f) GDPR (legitimate interest) in compliance with electronic communications regulations.
- Analysis and statistics – Art. 6(1)(f) GDPR (analytics/marketing tools activated after consent in the cookie banner).
- Legal claims and archiving – Art. 6(1)(f) GDPR.
- Legal obligations (accounting, taxes) – Art. 6(1)(c) GDPR.
4) Data recipients
- Payment operators and banks;
- courier/transport companies; IT/hosting providers and mailing tool providers;
- accounting office;
- analytics/marketing tool providers (after consent in the cookie banner); service partners.
5) Transfers of data outside the EEA (international transfers)
- adequacy decisions issued by the European Commission (Art. 45 GDPR), if applicable to the given country/recipient;
- standard contractual clauses of the European Commission (Art. 46 GDPR) and – where necessary – additional technical and organizational safeguards;
- exceptionally – if the safeguards under Art. 46 cannot be applied – one of the exceptions provided in Art. 49 GDPR (e.g., necessity for contract performance or your explicit consent, about which you will be informed before the transfer).
- cloud/hosting and CDN providers;
- e-mail and newsletter tool providers;
- analytics/marketing tool providers (activated only after your consent in the cookie banner).
6) Data retention periods
- Transaction data – for the duration of the contract and the limitation period for claims, as well as the period required by accounting and tax regulations;
- Customer account – until the account is deleted;
- Newsletter/marketing – until consent/objection is withdrawn;
- Correspondence – until the matter is resolved and for the necessary archiving period;
- Cookies – according to the periods specified in the Cookie Policy.
7) Rights of data subjects
- Right of access to data;
- Right to rectification of data;
- Right to erasure of data;
- Right to restriction of processing;
- Right to data portability;
- Right to object (including objection to marketing),
- Right to withdraw consent at any time;
- Right to lodge a complaint with the President of the Personal Data Protection Office (UODO).
8) Obligation to provide data
Providing data is voluntary but necessary to conclude and perform the contract. Data for marketing/newsletter purposes is voluntary and you may withdraw your consent at any time.
9) Automated decisions and profiling
We do not make decisions producing legal effects based solely on automated processing. Marketing profiling may be applied only with your consent – with the possibility to withdraw it.
10) Commercial information
Sending newsletters and marketing messages requires consent and we provide an easy way to unsubscribe (link in the footer or STOP for SMS).
11) Policy changes
We may update this Policy, in particular due to changes in law, tools, and processes. Changes will be announced on the website.
