Privacy Policy (GDPR / RODO) details
Data controller
The controller of personal data is ZEU GLOBAL SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Spółka z ograniczoną odpowiedzialnością, entered in the Polish National Court Register under KRS 0001098319, NIP 6783215517, REGON 528281817, with its registered office at ul. Igołomska 1, lok. 56, 31-983 Kraków, Poland.
Privacy requests may be sent to cookartpolska@zeuglobal.com, by phone at +48 690 300 948, or by post to Aleja Najświętszej Maryi Panny 9, 42-200 Częstochowa, Poland.
Personal data we process
We process information supplied during checkout or customer contact, including name, email address, phone number, delivery address, order contents, delivery selection, correspondence, complaints, returns, and transaction or payment status information made available to us.
We may also process essential technical information such as IP address, request logs, device or browser information, security events, and cart or session data stored in the browser.
Purposes and legal bases
We process order and delivery data to take steps requested before entering into a contract and to perform the sales contract under Article 6(1)(b) GDPR. Providing the checkout data marked as required is necessary to place and fulfil an order.
We process records needed for tax, accounting, consumer-protection, and other legal duties under Article 6(1)(c) GDPR. We process information needed to prevent misuse, secure the store, handle claims, and establish, exercise, or defend legal claims on the basis of our legitimate interests under Article 6(1)(f) GDPR.
Where optional marketing or non-essential cookies are introduced, they will be used only on an appropriate legal basis, including consent under Article 6(1)(a) GDPR where required. Consent may be withdrawn at any time without affecting earlier lawful processing.
Recipients and international transfers
Personal data may be disclosed only where necessary to hosting, database and storage providers, delivery operators selected for the order, Przelewy24 and its participating payment providers when online payment is selected, email or communications providers, accountants, legal advisers, and public authorities entitled to receive it.
Some technology providers may process data outside the European Economic Area. Where that occurs, CookArt will rely on a lawful transfer mechanism, such as an adequacy decision or approved standard contractual clauses, and any required supplementary safeguards.
Retention
Order, payment, invoice, and accounting records are kept for the period required by applicable tax and accounting law. Contract, complaint, return, and correspondence records may be retained until the relevant claims expire or disputes are finally resolved.
Security logs are retained only for a proportionate period needed to protect the service and investigate incidents. Data processed solely on the basis of consent is retained until consent is withdrawn or the stated purpose ends, unless another legal basis requires continued storage.
Your GDPR rights
Subject to the conditions in the GDPR, you may request access to your data, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time where processing relies on consent.
To exercise a right, contact cookartpolska@zeuglobal.com. You also have the right to complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) through uodo.gov.pl.
Automated decisions and data requirement
CookArt does not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects. Required checkout information is contractual: without it, we cannot accept or deliver an order.
Cookies, local storage, and security
The storefront uses essential browser storage or cookies needed for the shopping cart, session, checkout, and security. Non-essential analytics or marketing technologies will not be activated without the notice and consent required by law.
We use appropriate technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration, or disclosure. This policy may be updated when processing activities, providers, or legal requirements change.
