Privacy Policy

1. This Privacy Policy sets out the rules governing the processing of personal data collected via the website piercingdonut.com, hereinafter referred to as: „the Website”.

2. The owner of the website and, at the same time, the Data Controller is Piercing Donut Maria Lidak, Tax Identification Number (NIP): 8881624005, hereinafter referred to as the Data Controller.

3. Personal data collected by the Controller via the Website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as GDPR.

4. The Data Controller takes particular care to respect the privacy of Customers visiting the Website.

§ 1 Type of data processed, purposes and legal basis

1. The data controller collects information concerning natural persons carrying out a legal transaction not directly related to their business activities, natural persons carrying out business or professional activities in their own name, and natural persons representing legal persons or organisational units which are not legal persons but to which the law confers legal capacity, carrying out business or professional activities in their own name, hereinafter collectively referred to as Clients.

2. The Controller processes Customers’ personal data in connection with the use of the contact form on the Website to the extent necessary for the performance of a contract or for taking steps prior to entering into a contract – the legal basis for processing is Article 6(1)(b) of the GDPR

3. When using the contact form, the Customer provides the following details:

  • email address
  • first name
  • telephone number

4. Whilst using the Website, additional information may be collected, in particular: the IP address assigned to the Customer’s computer or the external IP address of the internet service provider, the domain name, browser type, time of access and operating system type. Navigation data may also be collected from Customers, including information about the links and hyperlinks they choose to click on or other actions undertaken on the Website for purposes related to the provision of services, as well as for technical, administrative, analytical and statistical purposes – in this respect, the legal basis for processing is also Article 6(1)(f) of the GDPR, i.e. necessity for the purposes arising from the Controller’s legitimate interest, which is to ensure IT security and the management of the Website, as well as to improve the functionality of the Website and the services provided.

§ 2 Recipients of the data

1. The Customer’s personal data is disclosed to service providers used by the Controller in the operation of the Website. The service providers to whom personal data is disclosed, depending on contractual arrangements and circumstances, either follow the Controller’s instructions regarding the purposes and methods of processing such data (data processors) or determine for themselves the purposes and means of processing (administrators).

  • 1.1. Data processors. The Controller uses service providers who process personal data solely on the Controller’s instructions. These include, amongst others, providers of hosting services, accounting services, marketing systems, website traffic analysis systems and systems for analysing the effectiveness of marketing campaigns
  • 1.2. Administrators. The Data Controller uses service providers who do not act solely on its instructions and who themselves determine the purposes and means of processing Customers’ personal data. They provide electronic payment and banking services.

2. Location. Service providers are mainly based in Poland and in other countries within the European Economic Area (EEA).

3. Where a request is made, the Controller shall disclose personal data to the competent state authorities, in particular to organisational units of the Public Prosecutor’s Office, the Police, the President of the Office for Personal Data Protection, the President of the Office of Competition and Consumer Protection or the President of the Office of Electronic Communications.

§ 3 Data retention period

1. Customers’ personal data is stored:

  • 1.1. Where the basis for the processing of personal data is consent, the Customer’s personal data shall be processed by the Controller until such time as the consent is withdrawn, and, following the withdrawal of consent, for a period corresponding to the limitation period for claims that the Controller may bring and that may be brought against it. Unless otherwise provided for by a specific provision, the limitation period is six years, and for claims relating to periodic payments and claims arising from the conduct of business activities – three years.
  • 1.2. Where the basis for data processing is the performance of a contract, the Customer’s personal data shall be processed by the Controller for as long as is necessary to perform the contract, and thereafter for a period corresponding to the limitation period for claims. Unless otherwise provided for by a specific provision, the limitation period is six years, and three years for claims relating to periodic payments and claims arising from the conduct of business activities.

§ 4 Cookies and IP addresses

1. The website uses small files known as cookies. These are stored by the Administrator on the end-user’s device when they visit the website, provided that their web browser permits this. A cookie usually contains the name of the domain from which it originates, its „expiry time” and a unique, randomly generated number identifying the cookie. The information collected using such files helps to tailor the products offered by the Administrator to the individual preferences and actual needs of visitors to the website

2. The controller uses two types of cookies:

  • 2.1. Session cookies: Once the browser session has ended or the computer has been switched off, the stored information is deleted from the device’s memory. The mechanism of session cookies does not allow any personal data or confidential information to be retrieved from customers’ computers.
  • 2.2. Persistent cookies: They are stored in the memory of the Customer’s device and remain there until they are deleted or expire. The mechanism of persistent cookies does not allow any personal data or confidential information to be retrieved from the Customer’s computer.

3. The Data Controller uses first-party cookies for the following purposes:

  • 3.1. analyses, research and audience audits, and in particular to compile anonymous statistics that help us understand how Customers use the Website, thereby enabling us to improve its structure and content.

4. The controller uses third-party cookies for the following purposes:

  • 4.1. displaying, on the Website’s information pages, a map showing the location of the Controller’s office, using the maps.google.com website (third-party cookie controller: Google Inc, based in the USA)

5. The use of cookies is safe for the computers of Customers visiting the Website. In particular, it is not possible for viruses, other unwanted software or malware to enter Customers’ computers via this method. However, customers can restrict or disable the use of cookies on their computers via their web browsers. If this option is selected, the Website can still be used, with the exception of features which, by their very nature, require cookies.

6. The Data Controller may collect Clients’ IP addresses. An IP address is a number assigned to a visitor’s computer by their internet service provider when they visit the Website. An IP address enables access to the internet. In most cases, it is assigned to a computer dynamically, i.e. it changes with every connection to the internet and is therefore generally regarded as non-personally identifiable information. The IP address is used by the Administrator to diagnose technical problems with the server, to compile statistical analyses (e.g. to determine from which regions we receive the most visits), as information useful for administering and improving the Website, as well as for security purposes and the potential identification of unwanted automated programmes that place a load on the server whilst browsing the Website’s content.

§ 5 Rights of data subjects

Data subjects have the right to:

1. The right to withdraw consent to the processing of data at any time:

  • 1.1. The customer has the right to withdraw any consent they have given
  • 1.2. The withdrawal of consent takes effect from the moment consent is withdrawn
  • 1.3. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal
  • 1.4. Withdrawing consent does not entail any adverse consequences for the Customer; however, it may prevent the Customer from continuing to use services or features which, by law, the Controller may only provide with the Customer’s consent

2. The right to object to the processing of data:

  • 2.1. The data subject has the right at any time to object – on grounds relating to their particular situation – to the processing of their personal data based on Article 6(1)(e) or (f) of the GDPR, including profiling carried out on the basis of those provisions. The controller may no longer process such personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
  • 2.2. Opting out by email of marketing communications relating to products or services shall constitute the Customer’s objection to the processing of their personal data, including profiling, for these purposes

3. The right to erasure („the right to be forgotten”):

  • 3.1. The customer has the right to request the erasure of all or some of their personal data
  • 3.2. The customer has the right to request the erasure of personal data if:
    • 3.2.1. the personal data are no longer necessary for the purposes for which they were collected or for which they were processed
    • 3.2.2. has withdrawn a specific consent, to the extent that the personal data were processed on the basis of that consent
    • 3.2.3. has objected to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or has objected to the processing pursuant to Article 21(2) of the GDPR
    • 3.2.4. personal data is processed unlawfully
    • 3.2.5. personal data must be erased in order to comply with a legal obligation under Union law or the law of a Member State to which the Controller is subject
    • 3.2.6. personal data was collected in connection with the provision of information society services
  • 3.3. Notwithstanding a request for the erasure of personal data, following the lodging of an objection or the withdrawal of consent, the Controller may retain certain personal data to the extent that processing is necessary to establish, assert or defend legal claims, as well as to comply with a legal obligation requiring processing under Union law or the law of a Member State to which the Controller is subject. This applies in particular to personal data comprising: first name, surname and email address, which are retained for the purposes of handling complaints and claims relating to the use of the Controller’s services, or, additionally, residential address/correspondence address and and order number, which are retained for the purposes of handling complaints and claims relating to concluded sales contracts or the provision of services

4. The right to restrict data processing:

  • 4.1. The customer has the right to request that the processing of their personal data be restricted. Until the request has been dealt with, making such a request will prevent the customer from using certain features or services whose use would involve the processing of the data covered by the request. The Data Controller will also not send any communications, including marketing communications
  • 4.2. The customer has the right to request that the use of their personal data be restricted in the following cases:
    • 4.2.1. where the data subject disputes the accuracy of their personal data – in such cases, the Controller shall restrict the use of such data for the time necessary to verify its accuracy, but for no longer than 7 days
    • 4.2.2. where the processing of data is unlawful and, instead of having the data erased, the Customer requests that its use be restricted
    • 4.2.3. where personal data are no longer necessary for the purposes for which they were collected or used, but are required by the Customer for the establishment, exercise or defence of legal claims
    • 4.2.4. where the data subject has objected to the processing of their data – until it has been determined whether the controller’s legitimate grounds override the data subject’s grounds for objection

5. The right to request access to your personal data from the Controller and to receive a copy of it:

  • 5.1. The Customer has the right to obtain confirmation from the Controller as to whether personal data is being processed, and if so, the Customer has the right to:
    • 5.1.1. to access your personal data
    • 5.1.2. to obtain information on the purposes of processing, the categories of personal data being processed, the recipients or categories of recipients of such data, the intended period for which the Customer’s data will be stored, or the criteria for determining that period (where it is not possible to specify the intended period for data processing), on the rights to which the Customer is entitled under the GDPR and on the right to lodge a complaint with a supervisory authority, if the personal data have not been collected from the data subject – any available information regarding the source of the data, automated decision-making, including profiling as referred to in Article 22(1) and (4) of the GDPR, and – at least in such cases – relevant information on the principles governing such processing, as well as on the significance and anticipated consequences of such processing for the data subject, and on the safeguards applied in connection with the transfer of personal data outside the European Union
    • 5.1.3. to obtain a copy of their personal data. The right to obtain a copy must not adversely affect the rights and freedoms of others

6. The right to rectify (correct) data:

  • 6.1. The Data Subject has the right to request that the Controller rectify any inaccurate personal data concerning them without delay. Taking into account the purposes of the processing, the data subject has the right to request that incomplete personal data be completed, including by providing an additional statement, by sending a request to the email address specified in §6 of the Privacy Policy

7. Right to data portability:

  • 7.1. The Customer has the right to receive the personal data they have provided to the Controller and to subsequently transfer it to another data controller of their choice. The Customer also has the right to request that the personal data be transferred directly by the Controller to such a data controller, provided that this is technically feasible. In such a case, the Controller shall send the Customer’s personal data in the form of a CSV file, which is a commonly used, machine-readable format that allows the data received to be transferred to another data controller.

8. The right to lodge a complaint with the supervisory authority:

  • 8.1. The customer has the right to lodge a complaint with the President of the Office for Personal Data Protection regarding any breach of their rights to the protection of personal data or other rights granted under the GDPR

9. Where a Data Subject exercises a right arising from the above provisions, the Controller shall comply with or refuse to comply with the request without delay, but no later than one month after receiving it. However, if – due to the complex nature of the request or the number of requests – the Controller is unable to comply with the request within one month, it shall comply within the following two months, having first informed the Customer, within one month of receiving the request, of the intended extension of the deadline and the reasons for it

10. The data subject may submit complaints, enquiries and requests to the Controller regarding the processing of their personal data and the exercise of their rights

§ 6 Changes to the Privacy Policy

1. The Privacy Policy may be amended, and the Controller is under no obligation to provide notice of such amendments.

2. Please send any enquiries regarding the Privacy Policy to the following email address: krzoliwia01@gmail.com

3. Date of last modification: 25 August 2025.