Privacy Policy — “Zhyttevyi Kapital” (EN)

Last updated: 08 Oct 2025

This Policy explains how “Zhyttevyi Kapital” (“we”, “us”, the “Service”) collects, uses, and safeguards your personal data when you use our website, online store, mobile/web apps, participate in events, or subscribe to newsletters (collectively, the “Service”).

1. Who we are

Data Controller: [Company/Sole Trader Name]
Address: [Full address]
E-mail: [Privacy contact e-mail]
If you are in the EEA/UK, we process data under the GDPR/UK GDPR.

2. Data we collect

  • Identity: first and last name, nickname.

  • Contact: e-mail, phone, shipping/billing address.

  • Account: username, password hash (we do not store plain passwords).

  • Transactions: order history, amounts, statuses (payment details are handled by our payment provider, e.g., Stripe/PayPal; we do not store full card data).

  • Communications: support requests, feedback, survey responses.

  • Technical: IP address, device/browser type, cookies, log data, approximate location.

  • Marketing/Analytics: data from pixels/tags (e.g., visits, conversions).

3. Sources

We obtain data directly from you, automatically via cookies/analytics, and from third parties (payment, shipping, and marketing providers) as permitted by law.

4. Purposes & legal bases

  • Provide the Service and perform a contract (accounts, orders).

  • Communicate and support (legitimate interest/contract).

  • Marketing with your consent (newsletters, promos).

  • Analytics and Service improvement (legitimate interest).

  • Legal compliance (accounting, tax, regulatory requests).

5. Cookies & similar tech

We use essential, analytics, and marketing cookies. You can manage consent via our banner or your browser settings. Disabling non-essential cookies may impact functionality.

6. Sharing with third parties

We share data only as needed with:

  • payment processors;

  • shipping/courier services;

  • hosting/analytics/marketing platforms;

  • contractors under data-processing agreements;

  • public authorities when legally required.

7. International transfers

Where data is transferred outside the EEA/UK, we rely on appropriate safeguards (e.g., Standard Contractual Clauses).

8. Retention

We keep data only as long as necessary:

  • account/transaction data — typically 6–10 years (legal obligations);

  • marketing data — until you withdraw consent/unsubscribe;

  • technical logs — typically 12–24 months.

9. Security

We apply technical and organizational measures (in-transit encryption, access controls, backups). No method is 100% secure.

10. Your rights (GDPR)

You may request access, rectification, erasure, restriction, objection, data portability, and withdraw consent without affecting prior lawful processing.
Complaints: Polish Personal Data Protection Office (UODO) or your local supervisory authority.

11. Children

The Service is not intended for children under 13. For users aged 13–16, parental/guardian consent may be required where applicable.

12. Communications & marketing

We send service emails (required) and marketing emails only with consent. You can unsubscribe via the link in each email or by contacting us.

13. Changes to this Policy

We may update this Policy; the new version takes effect upon posting. The date above shows the current version.