Privacy Policy

JERZY STORE PRIVACY AND COOKIE POLICY

This policy is effective as of September 29, 2026.

I. GENERAL PROVISIONS

1. This policy sets forth the rules for the processing of personal data and the use of cookies on the website https://sklep.jerzy.info.pl (hereinafter: the Store).

2. Data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the Act of May 10, 2018, on the Protection of Personal Data, and other applicable laws and regulations.

3. Providing data is voluntary, but certain data is necessary to enter into and perform a contract, fulfill an order, process a payment, or respond to an inquiry.

II. DATA CONTROLLER

1. The controller of personal data is Lidia Nieboras, who operates a business under the name P.P.H.U. „JERZY” Lidia Nieboras, ul. Graniczna 3, 43-445 Dzięgielów, NIP: 548-144-87-21, REGON: 072256373 (hereinafter: the Controller).

2. Contact information for matters related to personal data:
– email: sklep@jerzy.info.pl,
– Address: P.P.H.U. „JERZY” Lidia Nieboras, 3 Graniczna St., 43-445 Dzięgielów.

III. PURPOSES AND LEGAL BASIS FOR DATA PROCESSING

Data may be processed for the following purposes:

1. Conclusion and performance of a sales contract, order processing, deliveries, payments, and communication regarding the order—Article 6(1)(b) of the GDPR.

2. Creation and management of an optional Customer account and storage of order history as part of the account service – Article 6(1)(b) of the GDPR.

3. Fulfillment of accounting, tax, documentation, and other legal obligations—Article 6(1)(c) of the GDPR.

4. Handling contract cancellations, complaints, and returns—Article 6(1)(b) and (c) of the GDPR, and, to the extent applicable, Article 6(1)(f) of the GDPR.

5. Responding to inquiries and handling correspondence – Article 6(1)(f) of the GDPR, i.e., a legitimate interest consisting of handling inquiries and communicating with individuals interested in our offerings.

6. Identifying, investigating, and defending against claims; preventing abuse; and ensuring the security of the Store—Article 6(1)(f) of the GDPR.

7. Sending commercial information or newsletters—Article 6(1)(a) of the GDPR and the applicable provisions on electronic communications, only after obtaining the required consent.

8. Analytics, personalization, and marketing that use cookies or similar technologies that are not necessary for the operation of the Store—Article 6(1)(a) of the GDPR, based on the consent provided through the cookie management mechanism.

IV. SCOPE OF PROCESSED DATA

Depending on how you use the Store, the Administrator may process:

1. Identification and contact information, such as first and last name, email address, and phone number.

2. Billing address, shipping address, and selected shipping method.

3. For business purchases—the company name, tax ID number, and other information provided on the sales document.

4. Order details, purchase history, correspondence, complaint reports, and return information.

5. Information about the payment method and status, as well as the transaction ID. The administrator does not receive the full payment card details or bank login credentials.

6. The Customer's account information, if an account has been created.

7. Technical and usage data, such as IP address, date and time of the request, device type, operating system, browser type, technical logs, cookie identifiers, and consent information.

8. Other information voluntarily provided in the form or in correspondence, if necessary to process the matter.

V. DATA SOURCE

1. The data is primarily obtained directly from the data subject, specifically from the order form, the customer’s account, the contact form, and correspondence.

2. Information about payment status may come from the payment processor or the bank, and information about delivery may come from the carrier.

VI. DATA RECIPIENTS

Data may be transferred to entities that assist the Controller in operating the Store, solely to the extent necessary to achieve a specific purpose, in particular:

1. Providers of hosting, website maintenance, backup, security, and IT support.

2. Providers of e-commerce platforms and order management, warehouse integration, and ERP systems, including WooCommerce, Base.com, SubSync, and Subiekt nexo, in accordance with each entity’s role and the agreements in place.

3. Payment processors, in particular Przelewy24, and banks involved in processing payments.

4. Courier companies, carriers, and other entities involved in the delivery.

5. Providers of email, SMTP, and transactional messaging tools.

6. Accounting firms, legal and tax advisors, and entities authorized by law to receive such data.

7. Providers of analytics, marketing, translation, or embedded content tools—only to the extent necessary for the functions used and the consents granted.

VII. TRANSFER OF DATA OUTSIDE THE EEA

1. Some technology providers may process data outside the European Economic Area or use subcontractors located outside the EEA.

2. In such a case, the transfer takes place exclusively through a mechanism compliant with the GDPR, in particular a European Commission decision recognizing an adequate level of protection, standard contractual clauses, or another appropriate legal basis.

3. Information about specific providers enabled based on consent can also be found in the cookie management tool, if the provider in question uses cookies or similar technologies.

VIII. DATA RETENTION PERIOD

1. Order data and accounting records are retained for the period required by tax and accounting regulations, generally for 5 years from the end of the year in which the applicable tax payment deadline expired.

2. The data necessary to perform the contract is retained for the duration of the contract and thereafter until the statute of limitations for claims expires or until proceedings concerning such claims are concluded.

3. The Customer’s account data is retained until the account is deleted, except for data that must continue to be retained on another legal basis.

4. Data processed on the basis of consent is retained until such consent is withdrawn, the purpose for which it was collected no longer applies, or the data is deleted earlier.

5. Correspondence data is retained for the period necessary to handle the matter and for the time needed to document the course of communication and protect against claims.

6. Technical logs and security-related data are retained for a period that is justified by the purpose of their processing and the configuration of the Administrator’s systems.

IX. RIGHTS OF DATA SUBJECTS

The data subject has the right—in the cases and under the conditions set forth in the GDPR—to:

1. Access to data and obtaining copies of it.

2. Data Corrections.

3. Data deletion.

4. Restrictions on processing.

5. Data transfers.

6. Object to processing based on a legitimate interest.

7. You may withdraw your consent at any time, without affecting the lawfulness of the processing carried out prior to the withdrawal.

8. File a complaint with the President of the Personal Data Protection Office.

To exercise your rights, please contact us at sklep@jerzy.info.pl. The data controller may request information to verify the identity of the person making the request.

X. COOKIES AND SIMILAR TECHNOLOGIES

1. The store uses cookies and similar technologies.

2. Essential cookies are used to ensure the basic functionality of the Store, such as maintaining the session, the shopping cart, login, security, storing consents, and the proper processing of orders. Their use is necessary to provide the requested service.

3. Functional cookies may be used to remember the User's preferences, such as language settings.

4. Analytical cookies may be used to measure traffic, detect errors, and improve the Store's performance.

5. Marketing cookies may be used to measure the effectiveness of campaigns, personalize communications, or display content from third-party providers.

6. Functional cookies that are not required for the Store to operate, as well as analytical and marketing cookies, are enabled only after consent is obtained, if consent is required.

7. The user may grant, deny, or withdraw consent using the banner or the cookie management panel available in the Store. Withdrawing consent should be just as easy as granting it.

8. You can also manage cookies in your browser settings. Blocking essential cookies may prevent you from using the shopping cart, logging in, or placing orders.

9. The retention period for individual cookies and their providers depends on the Store’s current configuration and is indicated in the consent management panel, provided that the tool makes such information available.

XI. AUTOMATED DECISION-MAKING

1. The Administrator does not make decisions regarding Users based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect the User, unless the Administrator provides separate notice of this and ensures the safeguards required by law.

2. Once the appropriate consent has been obtained, the data may be used for simple marketing profiling, such as tailoring content to the User’s interests. Such profiling does not have any legal consequences for the User.

XII. DATA PROTECTION

The controller shall implement appropriate technical and organizational measures to protect the data, taking into account the nature, scope, context, and purposes of the processing, as well as the risk of infringement of the rights or freedoms of natural persons.

XIII. POLICY CHANGES

1. This policy may be updated in the event of changes to the law, technology, the Store’s functionality, or data processing methods.

2. The current version of the Policy is published in the Store along with its effective date.

3. In matters not covered herein, the provisions of the GDPR and applicable Polish law shall apply.

JERZY'S SKI SHOP

EXPERIENCE. QUALITY. PASSION.

For over 30 years, we've been helping our customers enjoy the winter. Visit us in Dzięgielów or order online.