This document sets out the Privacy and Cookies Policy for the website available at https://printella.pl, owned by Printella Sp. z o.o., ul. Stefana Batorego 18, 77-300 Człuchów, Poland.
§1 Controller of Personal Data
- The controller of your personal data is Printella Sp. z o.o., ul. Stefana Batorego 18, 77-300 Człuchów, Poland, NIP: 8431625364, REGON: 520763824, KRS: 0000941953 (hereinafter: the “Controller”).
- Contact details of the Controller:
- Correspondence address: Printella Sp. z o.o., ul. Stefana Batorego 18, 77-300 Człuchów, Poland
- E-mail address: privacy@printella.com
- Telephone: +48 577 700 144
- Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer (DPO) and performs the obligations related to personal data protection on its own.
§2 Definitions
Controller
The controller of personal data, i.e. the entity which determines the purposes and means of the processing of personal data.
Personal data
Information about natural persons, relating to an identified or identifiable person, directly or indirectly; personal data includes in particular an identification number and factors specific to the physical, physiological, mental, economic, cultural or social identity of that person.
GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Privacy and Cookies Policy
This document, hereinafter referred to as the “Policy”.
Service
The website available at: https://printella.pl.
Service User
Any natural person visiting the Service or using at least one service provided by the Controller or one of the functions of the Service.
Cookies
Small pieces of information in the form of text strings placed or read by a website in the web browser used by the User.
Sole traders (JDG)
Natural persons conducting business activity on the basis of an entry in the Central Registration and Information on Business (CEIDG).
§3 General Provisions
- The Controller collects data of Service Users within the domain: https://printella.pl.
- The type of data collected by the Controller depends on the service offered by Printella Sp. z o.o. which the User uses.
- Personal data will be processed by the Controller in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, known as the General Data Protection Regulation, hereinafter the “GDPR”.
- Providing any personal data is voluntary and depends on the User’s decision. However, in some cases providing specific personal data is necessary in order to meet the User’s expectations as regards the use of the services offered by the Controller.
- The services provided by Printella Sp. z o.o. within the Service are offered to persons who are at least 18 years of age. Accordingly, the Controller does not knowingly process children’s personal data.
§4 Purpose, Legal Basis and Period of Processing
Customer Account registration
- Whose data is processed?
The data of persons who have registered their account in the Service https://printella.pl is processed. - What data is processed?
- first name and surname
- e-mail address
- telephone number
- delivery address
- billing address
- company name and NIP (tax identification number) (Sole traders – JDG)
- What is the purpose of the processing?
The data will be processed for the purpose of providing services related to the maintenance and operation of the account in the Service. - What is the legal basis for the processing?
- Preparation and performance of a contract – Article 6(1)(b) of the GDPR.
- The legitimate interest of the Controller, consisting in the optimisation of the services provided – Article 6(1)(f) of the GDPR.
- What is the data retention period?
The data is processed until the contract has been performed (e.g. the account is deleted from the Service), and subsequently for the period necessary to establish, pursue or defend against claims. - Is providing the data necessary?
Providing the data is voluntary; however, without providing it an account cannot be created.
Order processing in the store
- Whose data is processed?
The data of persons who have placed an order on the website https://printella.pl. - What data is processed?
- first name and surname
- e-mail address
- telephone number
- delivery address
- billing address
- company name and NIP (tax identification number) (Sole traders – JDG)
- What is the purpose of the processing?
The data will be processed for the purpose of order fulfilment, complaint handling, pursuing claims or defending against them, as well as in connection with the performance of obligations arising from tax and accounting regulations. - What is the legal basis for the processing?
- Preparation and performance of a contract – Article 6(1)(b) of the GDPR.
- The legitimate interest consisting in establishing, pursuing and defending against potential claims – Article 6(1)(f) of the GDPR.
- Compliance with a legal obligation to which the Controller is subject – Article 6(1)(c) of the GDPR.
- What is the data retention period?
- The data is processed until the contract has been performed, whereas data obtained for the purpose of fulfilling legal obligations is processed until those obligations have been fulfilled.
- Data processed on the basis of a legitimate interest is processed until that interest has been realised or until the User raises an effective objection. The above processing periods may be extended by no more than the time necessary to establish, pursue or defend against claims. After that period, the personal data will be anonymised or deleted.
- Is providing the data necessary?
Providing the data is voluntary; however, without providing it the order cannot be processed.
Contact form
- Whose data is processed?
The data of persons who contact us through the contact form. - What data is processed?
- e-mail address
- first name
- What is the purpose of the processing?
Identification of the User making contact and providing an answer to the question asked. - What is the legal basis for the processing?
Legitimate interest – Article 6(1)(f) of the GDPR. - What is the data retention period?
Until the limitation period for claims expires. - Is providing the data necessary?
Providing the data is voluntary, but necessary in order to verify the User.
Product availability notification
- Whose data is processed?
The data of persons who wish to receive information about the availability of a product. - What data is processed?
- e-mail address
- first name
- What is the purpose of the processing?
Providing information about the availability of a product. - What is the legal basis for the processing?
Providing information about the availability of a product on the basis of the consent given – Article 6(1)(a) of the GDPR. - What is the data retention period?
The data is processed for the period necessary to provide the information or until the consent is withdrawn, whichever occurs first. - Is providing the data necessary?
Providing the data is voluntary, but necessary in order to provide the information.
Newsletter
- Whose data is processed?
The data of persons who have subscribed to the Newsletter. - What data is processed?
- e-mail address
- first name
- date of birth (optional)
- What is the purpose of the processing?
- Performance of the Newsletter service, providing information about discounts, promotions and new offers.
- Adjusting the content of the Newsletter service ordered to the User’s activity in the Service.
- What is the legal basis for the processing?
- Performance of the contract for the provision of the Newsletter service – Article 6(1)(b) of the GDPR.
- The legitimate interest consisting in direct marketing (information about the offer, news, content personalisation) – Article 6(1)(f) of the GDPR.
- What is the data retention period?
Personal data will be processed until the User withdraws consent to the processing, and subsequently for the period necessary to establish, pursue or defend against claims. After that period, the personal data will be anonymised or deleted. - Is providing the data necessary?
Providing the data is voluntary; however, without providing it, subscribing to the Newsletter will not be possible.
§5 Entrusting and Disclosing Personal Data
In connection with its business activity, the Controller may disclose personal data to the following entities, where this is necessary to achieve the purposes of the processing:
- Companies providing IT services or supplying IT solutions,
- Banks and other financial and payment institutions,
- Companies providing transport services, carriers,
- Public authorities receiving data in connection with the performance of the Controller’s legal obligations,
- Companies providing accounting and bookkeeping services,
- The company providing marketing services for the Controller,
- Employees and associates.
§6 Rights of the Service User
- In connection with the processing of personal data, the User has the following related rights:
- the right of access to their data – the User has the right to obtain information about the personal data concerning them held by the Controller, including a copy of that data.
- the right to rectification of their data – the User has the right to request rectification of their personal data which is inaccurate or incomplete.
- the right to erasure of data – the User has the right to request the erasure of their personal data held by the Controller in the following cases: (a) the User’s personal data is no longer necessary for the purposes for which it was collected, (b) the User has withdrawn the consent on which the processing is based and there is no other legal basis for the processing, (c) the User has objected to the processing and there are no overriding legitimate grounds for the processing, or the objection concerns the processing of data for direct marketing purposes, (d) the User’s personal data has been processed unlawfully, (e) the personal data must be erased in order to comply with a legal obligation provided for in Union law or national law.
- the right to withdraw consent to the processing of personal data for marketing purposes at any time – the User has the right to withdraw the consent given to the processing of personal data at any time. Withdrawal of consent to the processing does not affect the lawfulness of the processing carried out before its withdrawal.
- the right to restriction of the processing of data – the User has the right to request that the processing of their personal data be restricted in the following cases: (a) the User contests the accuracy of the personal data, for a period enabling the Controller to verify the accuracy of that data, (b) the processing is unlawful and the User opposes the erasure of the personal data and requests instead the restriction of its use, (c) the Controller no longer needs the personal data for the purposes of the processing, but it is required by the User for the establishment, exercise or defence of claims, (d) the User has objected pursuant to Article 21(1) of the GDPR to the processing – pending verification whether the legitimate grounds of the Controller override those of the User.
- the right to object to the processing of data (objection on grounds relating to the User’s particular situation) – where the User’s personal data is processed on the basis of the Controller’s legitimate interest, the User has the right to object to the processing at any time, in accordance with Article 21 of the GDPR.
- the right to data portability – the User has the right to receive the personal data concerning them which they have provided to the Controller, in a structured, commonly used and machine-readable format, and has the right to transmit that personal data to another controller without hindrance from the Controller to which the personal data has been provided, where the processing is based on consent and is carried out by automated means.
- the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) in Poland.
- If you wish to exercise the rights listed in §6 of the Privacy Policy, please contact the Controller.
§7 Transfer of Personal Data to Third Countries
- The User’s personal data may be transferred outside the European Economic Area.
§8 Cookies Policy
- Purpose of the use of cookies:
- The Controller does not collect any information automatically, with the exception of the information contained in cookies.
- Cookies are used in many ways.
- Cookies are used for functional purposes, content personalisation, and statistical, analytical and marketing purposes.
- Types of cookies:
- The Service uses the following types of cookies:
- “session cookies”, which are deleted from the hard drive once the browser session is ended or the computer or mobile device is switched off,
- “persistent cookies”, which are stored in the memory of the computer or mobile device until they are manually deleted by the User using the appropriate tools in the web browser, or until they expire,
- “third-party cookies”, which are pieces of information placed by scripts of other websites.
- The following types of cookies are used within the Service:
- “necessary” cookies, enabling the use of the services available within the Service,
- “performance” cookies, enabling the collection of information about the way the Service is used,
- “functional” cookies, enabling the settings selected by the User to be “remembered” and the User interface to be personalised, e.g. as regards the selected language or region,
- “advertising” cookies, enabling advertising content better tailored to the Users’ interests to be delivered to them.
- The Service uses the following types of cookies:
Meta Pixel (Facebook)
- The Service uses the marketing tool Meta Pixel (formerly: Facebook Pixel), provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, and, in the case of users outside the EEA, by Meta Platforms, Inc., 1601 Willow Road, Menlo Park, CA 94025, USA.
- Meta Pixel is a piece of code placed in a website which makes it possible to measure the effectiveness of advertising and to deliver personalised advertising content. The legal basis for the processing of data within Meta Pixel is the user’s consent (Article 6(1)(a) of the GDPR), given by means of a consent management platform (CMP).
- The data collected by Meta Pixel includes, among other things, information about the user’s activity in the website, the device, the browser and the IP address. This data is anonymised as far as we are concerned (we do not see data enabling the user to be identified); however, Meta may combine this information with data from the user’s account and use it for its own advertising purposes in accordance with its privacy policy.
- Meta’s privacy policy is available at:
https://www.facebook.com/privacy/explanation - The user may manage their advertising preferences at:
https://www.facebook.com/ads/preferences - In connection with the use of Meta Pixel, data may be transferred to third countries, including the USA. In this respect Meta applies the Standard Contractual Clauses (SCC) approved by the European Commission. The user may obtain a copy of them by contacting the controller.
Google Analytics
- The Service uses the analytical tool Google Analytics, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and, in the case of users outside the EEA, by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
- Google Analytics is a tool used to analyse website traffic, making it possible, among other things, to examine the way the Service is used, to create statistics and reports, and to optimise its operation. The legal basis for the processing of data within Google Analytics is the user’s consent (Article 6(1)(a) of the GDPR), given by means of a consent management platform (CMP).
- Within Google Analytics, information may be processed concerning the user’s activity in the Service, the type of device, the operating system, the browser, the approximate location, the IP number and advertising and analytical identifiers. This data is pseudonymised as far as we are concerned – it does not allow a specific person to be identified. Google may, however, combine it with other information about the user if the user has a Google account, and use it on its own terms, described in Google’s privacy policy.
- Google’s privacy policy is available at:
https://policies.google.com/privacy - The user may manage their privacy settings and personalised Google advertising at:
https://adssettings.google.com - In connection with the use of Google Analytics, data may be transferred to third countries, including the USA. In this respect Google applies the Standard Contractual Clauses (SCC) approved by the European Commission. The user may obtain a copy of the relevant safeguards by contacting the controller.
Google Ads
- The Service uses the marketing tools Google Ads, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and, in the case of users outside the EEA, by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
- Google Ads makes it possible to run advertising campaigns and to direct personalised advertisements to users, including remarketing based on activity in the Service. The legal basis for the processing of data within Google Ads is the user’s consent (Article 6(1)(a) of the GDPR), expressed by means of a consent management platform (CMP).
- Within Google Ads, data may be processed concerning the user’s activity in the Service, advertising identifiers, information about the device, the browser and the IP address, and events related to conversions (e.g. clicks, purchases, form submissions). This data is pseudonymised as far as we are concerned; however, Google may combine it with other user data (e.g. a Google account) and use it in accordance with its privacy policy.
- Google’s privacy policy is available at:
https://policies.google.com/privacy - The user may manage the personalisation of Google advertising at:
https://adssettings.google.com - In connection with the use of Google Ads, data may be transferred to third countries, in particular to the USA. In this respect Google applies the Standard Contractual Clauses (SCC) approved by the European Commission. The user may obtain a copy of these safeguards by contacting the controller.
Brevo (Sendinblue)
- The Service uses the tool Brevo (formerly: Sendinblue), provided by Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France. Brevo acts as a processor of data on the basis of a data processing agreement.
- Brevo is used to operate the newsletter, send e-mail messages, automate marketing and manage the subscriber database. The legal basis for the processing of data in this respect is the user’s consent (Article 6(1)(a) of the GDPR), expressed when subscribing to the newsletter or in other forms.
- When Brevo is used, data such as the e-mail address, first name, IP address, technical data concerning opens of and clicks in e-mail messages, and communication preferences may be processed. This data is visible to us in the form of statistics; however, Brevo may process it in accordance with its privacy policy.
- Brevo’s privacy policy is available at:
https://www.brevo.com/legal/privacypolicy/ - As a rule, data processed in Brevo is not transferred outside the European Economic Area. Should such a transfer be necessary, Brevo applies appropriate safeguards, including the Standard Contractual Clauses (SCC).
Managing cookies
- Most often, browser settings allow cookies and other information to be placed on the end device by default. If the User does not agree to such files being saved, the settings of the web browser must be changed accordingly. It is possible to disable their saving for all connections from a given browser or for a particular website, and to delete them. The way files are managed depends on the software used. The current rules for managing files can be found in the settings of the web browser used.
- Information on managing cookies on a mobile phone can be found in the User Manual of the phone concerned.
- Consent to the processing of cookies is voluntary. It should be remembered, however, that restrictions on their use may hinder or prevent the use of some functionalities of the Service operated at: https://printella.pl.
§9 Data Security
- The User’s personal data is stored and protected with due diligence, in accordance with the internal procedures implemented by the Controller. The Controller processes information about the User using appropriate technical and organisational measures which meet the requirements of generally applicable law, in particular the provisions on personal data protection. The purpose of these measures is above all to protect Users’ personal data against access by unauthorised persons.
- In particular, access to Users’ personal data is available only to authorised persons, who are obliged to keep this data confidential, or to entities to which the processing of personal data has been entrusted on the basis of a separate data processing agreement.
§10 Final Provisions
- The Controller reserves the right to amend this Privacy and Cookies Policy. In such a case, its updated version will be published in this location.
- In matters not regulated by this Privacy Policy, the provisions on personal data protection apply.
- This Privacy Policy is effective as of 1 September 2026.