Cookie Policy

PRIVACY POLICY

 

§1

GENERAL PROVISIONS

1. This document sets forth the Privacy Policy of the Sensi Materie online store, operating at www.sensimaterie.com, run by Iga Majorek, conducting sole proprietorship business under the name: “Studio Iga Majorek” with its registered office in Wrocław (50-109) at ul. Kiełbaśnicza 29/4, NIP [Tax Identification Number]: 9730912729, REGON [National Business Registry Number]: 389774409, phone: + 48 797 848 748, e-mail address: info@sensimaterie.com.

2. Store – the online store maintained by the Seller at www.sensimaterie.com.

3. The Privacy Policy constitutes an integral attachment to the Terms and Conditions of the Sensi Materie online store, www.sensimaterie.com.

 

§2

DEFINITIONS

The terms used in this document mean:

1. Personal Data Controller (also referred to as the Controller) – Iga Majorek, conducting sole proprietorship business under the name: “Studio Iga Majorek” with its registered office in Wrocław (50-109) at ul. Kiełbaśnicza 29/4, NIP [Tax Identification Number]: 9730912729, REGON [National Business Registry Number]: 389774409,

2. Website – the website available at www.sensimaterie.com and all its subpages,

3. User – a natural person who uses the Website and provides their personal data through it,

4. Personal Data – information relating to an identified or identifiable natural person, identifiable directly or indirectly by reference to one or more specific factors determining physical, physiological, genetic, mental, economic, cultural or social identity, including image, voice recording, contact details, location data, information contained in correspondence, and information collected via recording equipment or similar technologies,

5. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC,

6. Terms and Conditions – the Terms and Conditions of the Sensi Materie online store, www.sensimaterie.com.


§3

PERSONAL DATA PROTECTION

1. The Controller is the controller of personal data within the meaning of the GDPR.

2. The Controller collects and processes personal data in accordance with applicable laws, in particular the GDPR and in accordance with the principles provided for therein.

3. The Controller informs the User about data processing at the time of collection. The Controller processes data to the extent, for the duration, and for the purposes indicated each time in the content made available under the forms used to collect Personal Data from the User.

4. The Controller transfers Personal Data exclusively to trusted subcontractors of the Controller, i.e., couriers, providers responsible for IT system management, entities such as warehouses, banks and payment operators, entities providing accounting and legal services, marketing agencies (in the scope of marketing services), entities providing other IT and software services.

5. The Controller has the right to transfer selected Personal Data of the User to competent authorities and third parties if such necessity arises from applicable law and when those entities request their provision based on an appropriate legal basis.

6. The Controller ensures the security of processed personal data and their confidentiality, and also enables the User access to information about data processing. Should a breach of Personal Data protection occur despite the security measures applied (e.g., a data “leak” or loss) and such a breach could pose a high risk of violation of the User’s rights or freedoms, the Controller will notify the User of such an event in accordance with applicable regulations.

7. The User may contact the data controller. Contact details are as follows:

Correspondence address:

ul. Kiełbaśnicza 29/4, 50-109 Wrocław

E-mail address:

info@sensimaterie.com

 

§4

PERSONAL DATA SECURITY

1. The Controller uses all available technical and organizational means to ensure the security of the User’s personal data and to protect it against accidental or intentional destruction, accidental loss, modification, unauthorized disclosure, or access. Users’ Personal Data is stored and processed on highly secured servers, with appropriate security measures in place, meeting the requirements of Polish law.

2. The entrusted data is stored on top-of-the-line hardware and servers in appropriately secured data storage centers, accessible only to authorized individuals.

3. The Controller performs activities related to the processing of personal data with respect for all legal and technical requirements imposed on it by personal data protection regulations. The Controller continuously analyzes the risks associated with its processing of personal data and ensures that access to data is granted only to authorized persons and only to the extent necessary to perform their duties.

4. The Controller takes all necessary steps to ensure that its subcontractors and other cooperating entities also guarantee the application of appropriate security measures whenever they process Personal Data on behalf of the Controller.

5. The Controller undertakes to maintain backup copies containing the User’s personal data.


§5

USER’S RIGHTS

1. In the event of a change in personal data, the User should update it by sending an appropriate message to the Controller.

2. The User has the following rights: a. the right to information about the processing of Personal Data,

b. the right to obtain copies of Personal Data processed by the Controller,

c. the right to rectification of Personal Data,

d. the right to erasure of Personal Data (on this basis, one may request the deletion of data whose processing is no longer necessary for any of the purposes for which it was collected),

e. the right to restrict the processing of Personal Data,

f. the right to portability of Personal Data,

g. the right to object to the processing of Personal Data for marketing purposes (the User may at any time object to the processing of Personal Data for marketing purposes, without the need to justify such objection),

h. the right to object to other purposes of data processing (the User may at any time object – for reasons related to their particular situation – to the processing of Personal Data carried out on the basis of the Controller’s legitimate interest; such an objection requires justification),

i. the right to withdraw consent if Personal Data is processed based on consent (withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal),

j. the right to lodge a complaint with the supervisory authority responsible for overseeing the processing of Personal Data, competent for the User’s place of habitual residence, place of work, or place of the alleged infringement. In Poland, the supervisory authority is the President of the Office for Personal Data Protection.

3. The Controller may refuse to erase the User’s personal data if the retention of personal data is required by an obligation imposed on the Controller by law.

4. The User has the right to submit a request regarding the exercise of their rights listed above by mail or electronically (e-mail). The Controller’s contact details are provided in §3(7).

5. In cases where, based on the request referred to in paragraph 4, the Controller is unable to identify the natural person to whom the request pertains, it will ask the applicant for additional information. Failure to provide additional information will result in the rejection of the applicant’s request.

6. The Controller responds to a request within one month of receiving it. If it is necessary to extend this deadline, the Controller will notify the applicant of the reasons and the anticipated response date.


§6

LEGAL BASIS, PURPOSE AND RETENTION PERIOD OF PERSONAL DATA 

1. Personal data is processed for the following purposes and on the following legal bases: a. Use of the Website:

Personal data of all persons using the Website (including IP addresses or other identifiers and information collected via cookies or similar technologies) is processed by the Controller for the purposes of:

i. providing electronic services (legal basis: necessity of processing for the performance of a contract – Article 6(1)(b) of the GDPR),

ii. analytical and statistical purposes (legal basis: consent – Article 6(1)(a) of the GDPR),

iii. establishing and pursuing claims or defending against claims (legal basis: legitimate interest of the Controller – Article 6(1)(f) of the GDPR, consisting in protecting the Controller’s rights).

b. Order Form:

To place an order on the Website, the User is requested to provide the personal data specified in the order form. Providing this data is not mandatory, but refusal to provide it will prevent the placement of the order. Personal Data provided by the User is processed by the Controller for the purposes of:

i. providing electronic services and entering into a sales contract (legal basis: necessity of processing for the performance of a contract – Article 6(1)(b) of the GDPR),

ii. analytical and statistical purposes (legal basis: consent – Article 6(1)(a) of the GDPR),

iii. establishing and pursuing claims or defending against claims (legal basis: legitimate interest of the Controller – Article 6(1)(f) of the GDPR, consisting in protecting the Controller’s rights).

c. Marketing

The Controller processes Users’ Personal Data for the purpose of carrying out marketing activities, which may consist in particular of displaying marketing content to the User that corresponds to their interests or sending commercial information electronically for purposes related to the direct marketing of goods and services. In such cases, the User’s Personal Data is processed by the Controller based on the User’s consent (Article 6(1)(a) of the GDPR), which may be withdrawn. The fulfillment of the Controller’s marketing purposes may be carried out through profiling, consisting of automated processing and evaluation of Personal Data for the purpose of analyzing user behavior and creating future predictions, which allows for displaying content to the User in accordance with their individual preferences and interests.

d. Traditional and electronic correspondence (e-mail):

The User may send messages to the Controller using electronic mail, using the Controller’s contact details available on the Website, the Terms and Conditions, or this Privacy Policy. The Controller uses the Personal Data contained in such correspondence solely for the purpose of communication and handling the matter to which the correspondence relates. The legal basis for processing this Data is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR) – maintaining correspondence related to its business activities, and, in the case of contact related to services or contracts, necessity of processing for the performance of a contract (Article 6(1)(b) of the GDPR).

e. Phone contact

The User may contact the Controller by phone regarding services or contracts, as well as other matters. In case of contact unrelated to a contract or service, the Controller may request Personal Data only if it is necessary to handle the reported matter. The legal basis for processing is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR) – the necessity to resolve matters related to its business activities, and, for contact related to services or contracts, necessity of processing for the performance of a contract (Article 6(1)(b) of the GDPR).

f. Social media profiles

The Controller maintains profiles on social media - Instagram. The Controller processes Personal Data left by persons interacting with the profiles, such as comments or online identifiers. The Controller uses this data for the purpose of effectively managing the profiles, enabling activity on those profiles, as well as for analytical and statistical purposes. The legal basis for processing Personal Data is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR) – consisting in promoting its business and services, or, if necessary, for establishing, exercising, or defending legal claims. The above does not apply to the processing of Personal Data by social media platforms themselves. To learn about the data processing rules applied by social media platforms, please refer to their privacy policies.

2. The period of data processing depends on the service provided, the purpose, and the legal basis for processing. As a principle, data is processed for the duration of the service or the order. If the legal basis for processing Personal Data is consent, the data is processed until consent is effectively withdrawn. If the legal basis for processing Personal Data is the Controller’s legitimate interest, the data is processed until an effective objection is submitted.

3. The retention period referred to in paragraph 2 may be extended if processing is necessary to establish, exercise, or defend possible claims. After that time, Personal Data may be processed only where and to the extent required by applicable law.

4. Upon expiration of the Personal Data retention period, Personal Data is deleted or irreversibly anonymized.


§7

COOKIES POLICY

1. The Controller uses cookies. Cookies are small text files sent (saved) by the Website on your terminal device (e.g. computer, smartphone).

2. The Controller uses cookies to provide services electronically, to improve and enhance their quality, as well as for analytical and statistical purposes and to customize the Website to the needs of its Users. Through the use of cookies, the Controller personalizes content and advertising. The Controller shares information about how the User uses the Website with trusted social, advertising, and analytics partners, for the purpose of providing the highest quality services in terms of e-store functionality, analytics, targeting, and personalization.

3. The Website uses two types of cookies: “session cookies” and “persistent cookies”. Session cookies are temporary files stored on the User’s end device until the User logs out, leaves the website, or closes the software (web browser). “Persistent” cookies are stored on the User’s end device for the period specified in the cookie parameters or until deleted by the User.

4. The Controller uses the following types of cookies on the Website:

a. required – they enable the use of services and features available within the Website, e.g., they are used for user authentication or to fill the shopping cart during online purchases;

b. personalized – they enable the User’s preferences to be remembered and saved, and to be customized within the Website, e.g., regarding language preferences, font size, Website appearance, etc.;

c. analytical – they enable the collection of a range of information, including the number of visits and traffic sources in the Website. The collection of this data is used to determine which pages are most frequently visited and leads to the creation of statistics regarding traffic in the Website. The collection of this data is used by the Controller to improve the performance of the Website. The collected data is processed in anonymized form;

d. advertising – they enable the tailoring of content displayed within and outside the Website, including advertisements, to Users’ interests. Data relating to browsing history, activity on platforms (e.g., purchase history, manner of using services, type of content and advertisements displayed), or geolocation data may be used to present personalized content. Based on information from the Website and the User’s activity on other platforms, a User interest profile is built.

5. Functional, analytical, and advertising cookies may be installed by the Controller and its trusted partners through the Website.

6. The legal basis for processing data in connection with the use of necessary cookies is the necessity of processing Personal Data for the performance of a contract (Article 6(1)(b) of the GDPR). In the case of other cookies, the legal basis for processing Personal Data is the Controller’s legitimate interest or the User’s consent (Article 6(1)(a) and (f) of the GDPR). The Controller must obtain the User’s consent in order to use functional, analytical, and advertising cookies.

7. The consent referred to in paragraph 6 is granted through an appropriate form displayed during the first visit to the Website. The consent given may be withdrawn or adjusted at any time.

8. The User may change cookie settings from within their web browser.

9. Changing cookie and similar technology settings may affect the way the Website and its services function.

10. The Website uses tools provided by trusted third parties for the collection of cookies. These entities process cookies in accordance with the principles set out in their privacy policies and other documents defining cookie standards. The Controller’s trusted third parties include:

a. Shopify Inc. – tool: e-commerce platform Shopify – privacy policy: https://www.shopify.com/legal/privacy;

b. Meta Platforms, Inc. – tool: Meta Pixel/ Instagram – privacy policy: https://www.facebook.com/privacy/policy/;

c. Klaviyo, Inc. - tool: mailing system Klaviyo - privacy policy: https://www.klaviyo.com/legal/privacy/privacy-notice.

 

§8

LOGS 

1. In accordance with standard practice of most websites, the Controller stores HTTP requests directed to its server (server logs). Accordingly, the Controller stores the following information: a. IP addresses from which users browse the informational content of the Website;

b. time of receiving the request,

c. response time;

d. name of customer’s station – identification carried out via HTTP;

e. information about errors that occurred during HTTP transaction processing,

f. the URL of the page previously visited by the user (referrer link),

g. information about the user’s browser.

2. The collected logs are stored for an indefinite period as auxiliary material used for Website administration. The information contained therein is not disclosed to anyone other than persons authorized to administer the Website. Statistics may be generated based on log files to assist in Website administration. Aggregate summaries in the form of such statistics do not contain any characteristics identifying visitors to the Website.

3. The Controller processes the information contained in logs for technical and administrative purposes, for the purpose of ensuring the security of the IT system and managing that system, as well as for analytical and statistical purposes – in this regard, the legal basis for processing Personal Data is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR).


§9

TRANSFER OF DATA OUTSIDE THE EEA

1. As part of the Controller’s use of tools supporting day-to-day operations provided, for example, by Google, Users’ Personal Data may be transferred to a country outside the European Economic Area (EEA), in particular to the United States of America (USA) or another country in which an entity cooperating with the Controller maintains tools used for processing Personal Data in cooperation with the Controller. The Controller transfers Personal Data outside the EEA only when necessary and with an appropriate level of protection ensured, primarily through the use of standard contractual clauses issued by the European Commission.


§10

FINAL PROVISIONS

1. This Privacy Policy is subject to updates in connection with the ongoing analysis of technical and legal conditions related to the processing of personal data.

2. This Privacy Policy is effective as of 01.05.2026.