Privacy Policy
Data Controller
The controller of your personal data is [NAZWA FIRMY], with its registered address at [ADRES], email: [EMAIL].
The controller processes personal data in accordance with the General Data Protection Regulation (EU Regulation 2016/679, GDPR) and applicable Polish law.
What Data We Collect
When you use the website and purchase the Product, we may collect the following data:
— Email address (provided during checkout via Gumroad). — Technical data: IP address, browser type, operating system, visit timestamps (collected automatically). — Analytics data: information about how you interact with the website, collected via Google Analytics (anonymized).
We do not collect sensitive personal data (racial origin, health status, etc.).
Purpose of Processing
Your data is processed for the following purposes:
— Contract performance: providing access to the purchased Product, processing your order. — Communication: responding to inquiries and handling complaints. — Analytics: improving the website and Product based on anonymized usage data. — Legal obligations: fulfilling tax and accounting requirements.
Legal Basis
Personal data is processed on the following legal grounds (Article 6 GDPR):
— Article 6(1)(b): performance of a contract — processing your order and delivering the Product. — Article 6(1)(f): legitimate interest of the controller — website analytics, fraud prevention. — Article 6(1)(a): consent — use of analytical cookies (where consent is given). — Article 6(1)(c): legal obligation — tax and accounting compliance.
Retention Period
Personal data is retained for the following periods:
— Order data: 5 years from the date of purchase (in accordance with Polish tax law). — Analytics data: up to 14 months (standard Google Analytics retention period). — Communication data: up to 12 months after the last contact.
After the applicable retention period expires, data is deleted or anonymized.
Cookies
The website uses cookies — small text files stored in your browser.
Types of cookies we use:
— Essential: ensure the website functions correctly. These do not require consent. — Analytical: Google Analytics — help us understand how visitors use the website. These are only set with your consent.
You can disable cookies in your browser settings. Please note that this may affect the functionality of the website.
Third-Party Services
We use the following third-party services that may process your data:
— Gumroad (Gumroad, Inc., USA): payment processing and digital product delivery. Gumroad acts as the merchant of record and an independent data controller. Review their policy at: https://gumroad.com/privacy
— Google Analytics (Google LLC, USA): website usage analytics. Data is transferred in anonymized form. Data transfers to the USA are covered by the EU-US Data Privacy Framework (DPF).
— Vercel Inc. (USA): website hosting. Vercel processes technical data (IP address, headers) to deliver content. Data transfers covered by DPF.
— Neon Inc. (USA): cloud database for storing contact form submissions and site settings.
We do not sell your personal data to third parties.
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
— Right of access: find out what data we process about you. — Right to rectification: request correction of inaccurate data. — Right to erasure: request deletion of your data ("right to be forgotten"). — Right to restriction: request temporary restriction of processing. — Right to data portability: receive your data in a structured format. — Right to object: object to processing based on legitimate interest. — Right to withdraw consent: at any time, without affecting the lawfulness of prior processing.
To exercise your rights, contact [EMAIL]. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority — the President of the Polish Personal Data Protection Office (UODO): https://uodo.gov.pl/
Data Security
We implement technical and organizational measures to protect your personal data from unauthorized access, loss, or destruction.
The website uses HTTPS protocol to encrypt data in transit. Access to data is limited to authorized personnel only.
Despite these measures, no system can guarantee absolute security. In the event of a data breach, we will notify you and the relevant authorities as required by GDPR.
Changes to Policy
We may update this Privacy Policy from time to time. The current version is always available on the website with the date of the last update indicated.
Significant changes will be communicated through the website. Continued use of the website after changes are published constitutes acceptance of the updated Policy.
Contact
For any questions regarding the processing of personal data, please contact:
[NAZWA FIRMY] Address: [ADRES] Email: [EMAIL]
We aim to respond to all inquiries within 30 days.