Privacy Policy of the tarabaseny.com.pl Online Store
Privacy Policy of the tarabaseny.com.pl Online Store
Date of publication: April 2026 Date of effect: from the date of publication
This Privacy Policy (hereinafter "the Policy") sets out the rules for the processing of personal data by the tarabaseny.com.pl online store (www.tarabaseny.com.pl).
§1. General information
1.1. Data controller
The controller of personal data is:
**Patryk Reksa Gold Frieza ul. Kościelna 1 62-030 Luboń, Poland VAT ID: 6652931130 REGON: 544343262 Email: kontakt@tarabaseny.com.pl Phone: +48 88 1212 777
1.2. Data Protection Officer
The appointed Data Protection Officer (DPO): Email: iod@tarabaseny.com.pl
1.3. Scope of application
This Policy applies to:
- All users visiting the Store
- Customers placing orders
- Persons using contact forms
- Newsletter subscribers
§2. Definitions
For the purposes of this Policy, the following definitions apply:
-
GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
-
Personal data - any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
-
Processing - any operation or set of operations which is performed on personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (Art. 4(2) GDPR).
-
Processor - a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
-
Data subject - an identified or identifiable natural person.
-
Consent - any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
§3. Categories of data processed
3.1. User-provided data
-
Registration data:
- First name and surname
- Email address
- Telephone number
- Password (encrypted)
-
Address data:
- Delivery address (street, house number, postal code, city, country)
- Invoice address
-
Transaction data:
- Order history
- Payment data (last 4 digits of card, payment method)
- Communication history
-
Contact data:
- Messages sent via the contact form
- Email correspondence
3.2. Automatically collected data
-
Device data:
- IP address
- Browser type and operating system
- Screen resolution
-
Behavioural data:
- Pages visited
- Time spent on the page
- Clicks and interactions
- Products searched
-
Cookie data:
- Session identifier
- Language preferences
- Cart contents
- Browsing history
§4. Purposes and legal bases of processing
4.1. Performance of contract (Art. 6(1)(b) GDPR)
| Purpose of processing | Scope of data | Retention period |
|---|---|---|
| Placing and fulfilling an order | First name, surname, address, email, phone, product data | 5 years from the end of the tax year |
| Payment processing | Transaction data, payment history | 5 years from the end of the tax year |
| Order delivery | Address data, telephone number for the courier | Delivery fulfilment period + 30 days |
| Handling complaints and returns | Data related to the complaint | 5 years from the end of the tax year |
4.2. Compliance with a legal obligation (Art. 6(1)(c) GDPR)
| Purpose of processing | Legal basis | Retention period |
|---|---|---|
| Accounting and invoicing | Art. 74 of the Accounting Act | 5 years from the end of the tax year |
| Retention of tax data | Art. 70 §1 of the Tax Ordinance | 5 years from the end of the tax year |
| Handling complaints | Art. 558 of the Civil Code | 3 years |
4.3. Legitimate interests of the controller (Art. 6(1)(f) GDPR)
| Purpose of processing | Interest | Retention period |
|---|---|---|
| Direct marketing of own products and services | Development of business activity | Until withdrawal of consent or objection |
| Fraud prevention | Security of transactions | 2 years from the transaction |
| Analysis and optimisation of the Store | Improvement of services | 2 years |
| Handling legal enquiries | Customer service | 3 years from the submission of the enquiry |
4.4. Consent of the data subject (Art. 6(1)(a) GDPR)
| Purpose of processing | Scope of data | Retention period |
|---|---|---|
| Newsletter and email marketing | Email address, first name | Until withdrawal of consent |
| Ad personalisation | Behavioural data, device data | Until withdrawal of consent |
| Processing of sensitive data | Special categories of data (if provided) | Until withdrawal of consent |
§5. Sharing data with third parties
5.1. Processors (Poland)
| Entity | Purpose of processing | Location |
|---|---|---|
| OVH | Website and database hosting | France (data centres in Poland) |
| Medusa.js | E-commerce platform | Servers in the EU |
| Brevo | Newsletter and email marketing | France/EU |
5.2. Processors (EU)
| Entity | Purpose of processing | Location |
|---|---|---|
| Stripe | Online payments | United States |
| Przelewy24 | Online payments | Poland/EU |
| Google Analytics | Website analytics | USA (Standard Contractual Clauses) |
| Facebook/Meta | Marketing and remarketing | USA (Standard Contractual Clauses) |
5.3. Courier companies (Poland and EU)
| Entity | Purpose of processing | Location |
|---|---|---|
| GlobKurier | Domestic delivery | Poland |
| Furgonetka | Domestic delivery | Poland |
| DHL | Domestic and international delivery | Germany/EU |
| Raben | Domestic and international delivery | Poland/EU |
5.4. Transfers outside the EEA
In the case of transfers of data to third countries (e.g. USA - Google, Meta), the following safeguards apply:
- Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR)
- Guidelines of the European Data Protection Board
Transfers are based on a European Commission decision establishing an adequate level of protection (Art. 45 GDPR) or on Standard Contractual Clauses (Art. 46 GDPR).
§6. Rights of data subjects
6.1. Catalogue of rights
In accordance with the GDPR, the data subject has the following rights:
-
Right of access (Art. 15 GDPR)
- Receiving information about the data being processed
- Receiving a copy of the personal data
-
Right to rectification (Art. 16 GDPR)
- Requesting the correction of inaccurate data
- Requesting the completion of incomplete data
-
Right to erasure - "right to be forgotten" (Art. 17 GDPR)
- Requesting the erasure of data in the following cases:
- Data are no longer necessary for the purposes for which they were collected
- The data subject has withdrawn consent
- Data were processed unlawfully
- Data must be erased in order to comply with a legal obligation
- Requesting the erasure of data in the following cases:
-
Right to restriction of processing (Art. 18 GDPR)
- Restriction of processing in the following cases:
- The accuracy of the data is contested
- Processing is unlawful
- The controller no longer needs the data but they are required by the data subject
- An objection to processing has been lodged
- Restriction of processing in the following cases:
-
Right to data portability (Art. 20 GDPR)
- Receiving data in a commonly used electronic format
- Transmitting data to another controller
-
Right to object (Art. 21 GDPR)
- Objecting to processing based on the controller's legitimate interests
- Objecting to direct marketing
-
Right to withdraw consent (Art. 7(3) GDPR)
- Withdrawing consent at any time
- Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal
6.2. Exercising rights
-
How to exercise rights:
- A request may be submitted:
- Electronically: kontakt@tarabaseny.com.pl
- Via the customer panel in the Store
- A request may be submitted:
-
Response time:
- The controller responds to a request within 1 month of receipt
- In the case of complex requests, the period may be extended by a further 2 months (the data subject is informed of this)
-
Free of charge:
- The exercise of rights is free of charge
- In the case of manifestly unfounded or excessive requests (e.g. frequent repetition), the controller may charge a reasonable fee or refuse to act
6.3. Complaint to a supervisory authority
The data subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement.
In Poland: President of the Personal Data Protection Office Address: ul. Stawki 2, 00-193 Warszawa Email: kancelaria@uodo.gov.pl Tel.: 22 531 03 00
In other EU countries: Contact details of national data protection authorities are available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
§7. Data security
7.1. Technical measures
-
Encryption:
- SSL/TLS protocol for all connections
- Encryption of data in the database
- Password hashing (bcrypt algorithm)
-
Access:
- Restricted access to data (principle of least privilege)
- Multi-factor authentication for the administrative panel
- Logging of all data access
-
Infrastructure:
- Hosting in certified data centres (OVH)
- Regular software updates
- Intrusion detection and prevention systems
7.2. Organisational measures
- Employees with access to personal data are bound by confidentiality obligations.
- Regular data protection training is conducted.
- Data processing agreements have been concluded with all processors.
- Periodic security audits are carried out.
§8. Data retention periods
| Data category | Retention period | Legal basis |
|---|---|---|
| Order data | 5 years from the end of the tax year | Art. 74 of the Accounting Act |
| Accounting data/invoices | 5 years from the end of the tax year | Art. 70 §1 of the Tax Ordinance |
| Customer account data | Until account deletion by the customer + 30 days | Contract (order fulfilment) |
| Server logs | 12 months | Legitimate interest (security) |
| Marketing consents | Until withdrawal of consent | Consent |
| Analytics cookie data | 26 months (Google Analytics 4) | Consent |
| Email correspondence | 3 years from the closure of the matter | Legitimate interest |
After the retention period has elapsed, data are deleted or anonymised in a manner that prevents identification of the individual.
§9. Cross-border processing (Art. 49 GDPR)
9.1. General principles
For customers from the European Union, personal data may be processed in the following cross-border scenarios:
-
Processing within the EEA:
- Data are processed exclusively within the European Economic Area (EU + Norway, Iceland, Liechtenstein) or in countries ensuring an adequate level of protection.
-
Transfers to third countries:
- In the case of transfers to third countries (e.g. USA), the following safeguards apply:
- Standard Contractual Clauses (Art. 46 GDPR)
- EDPB guidelines on transfers
- In the case of transfers to third countries (e.g. USA), the following safeguards apply:
9.2. Information clauses for individual EU countries
Germany:
- Supervisory authority: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)
- Right to lodge a complaint with the competent authority in Germany
France:
- Supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL)
Spain:
- Supervisory authority: Agencia Española de Protección de Datos (AEPD)
Italy:
- Supervisory authority: Garante per la Protezione dei Dati Personali
Netherlands:
- Supervisory authority: Autoriteit Persoonsgegevens
Other countries: Contact details of supervisory authorities of all EU countries are available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
9.3. Transfer information
-
Google (USA):
- Transfer based on Standard Contractual Clauses
- More information: https://privacy.google.com/businesses/controllerterms/
-
Meta/Facebook (USA):
- Transfer based on Standard Contractual Clauses
- More information: https://www.facebook.com/legal/EU_data_transfer_addendum
-
Stripe (United States):
- Transfer based on Standard Contractual Clauses
- More information: https://stripe.com/privacy
§10. Automated decision-making
10.1. Profiling
-
The Store uses automated processing for:
- Personalisation of offers and product recommendations
- Fraud and abuse detection
- Behavioural marketing
-
Profiling is based on:
- Browsing and purchase history
- Product preferences
- Location (country)
10.2. Rights of the individual
- The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her (Art. 22 GDPR).
- In the case of anti-fraud systems, decisions are made for the purpose of protection against fraud, and the data subject has the right to obtain human intervention.
§11. Contact and information
11.1. Controller
Patryk Reksa Gold Frieza VAT ID: 6652931130 REGON: 544343262 Email: kontakt@tarabaseny.com.pl Phone: +48 88 1212 777
11.2. Data Protection Officer
Email: iod@tarabaseny.com.pl
11.3. Questions and requests
Any questions regarding the protection of personal data should be sent to: kontakt@tarabaseny.com.pl
§12. Final provisions
12.1. Version and updates
- This Policy is version 1.0, dated April 2026.
- The Seller reserves the right to change the Policy at any time.
- Users will be informed of changes by publication of a new version on the Store's website.
12.2. Guidelines and case law
In the interpretation of this Policy, the guidelines of the European Data Protection Board (EDPB) and the case law of the Court of Justice of the EU are applied.
Date of publication: April 2026 Version: 1.1