← Back to KwiaciarniaOnline.com

Privacy Policy

Last updated: April 5, 2026 | GDPR Compliant

1. Data Controller

The data controller for personal data collected through kwiaciarniaonline.com ("Website") is KwiaciarniaOnline.com, operated by its registered business entity ("we", "us", "Controller"). Contact: kontakt@kwiaciarniaonline.com.

2. Legal Basis for Processing

We process personal data based on the following legal grounds under Article 6 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"):

PurposeLegal Basis (Art. 6 GDPR)
Order fulfillment and deliveryPerformance of a contract (Art. 6(1)(b))
Payment processingPerformance of a contract (Art. 6(1)(b))
Account registrationPerformance of a contract (Art. 6(1)(b))
Customer service and complaintsPerformance of a contract (Art. 6(1)(b))
Tax and accounting obligationsLegal obligation (Art. 6(1)(c))
Fraud preventionLegitimate interest (Art. 6(1)(f))
Marketing emails (newsletter)Consent (Art. 6(1)(a))
Analytics and website improvementLegitimate interest (Art. 6(1)(f))
Cookie-based trackingConsent (Art. 6(1)(a)) — see Cookie Policy

3. What Data We Collect

Data you provide directly:

Data collected automatically:

4. Data Recipients and Processors

We share personal data only with trusted third-party processors who assist in operating our business:

ProcessorPurposeLocation
SIX Payment Services (Saferpay)Payment processingSwitzerland / EU
Supabase Inc.Database and authenticationEU (Frankfurt)
Netlify Inc.Website hostingUSA (with EU SCCs)
SendGrid (Twilio)Transactional emailsUSA (with EU SCCs)
Shipping carriersOrder deliveryEU

All processors are bound by data processing agreements (DPAs) ensuring GDPR compliance. Where data is transferred outside the EU/EEA, appropriate safeguards (Standard Contractual Clauses) are in place.

5. Data Retention

6. Your Rights

Under the GDPR, you have the following rights:

To exercise your rights, contact us at: kontakt@kwiaciarniaonline.com. We will respond within 30 days.

7. Security

We implement appropriate technical and organizational measures to protect personal data, including: TLS/SSL encryption for all data in transit, encrypted password storage (bcrypt hashing via Supabase Auth), PCI-DSS compliant payment processing, access controls and regular security reviews.

8. Children

Our Website is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us for immediate deletion.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of the Website after changes constitutes acceptance of the revised policy.

10. Contact

Data Controller: KwiaciarniaOnline.com
Email: kontakt@kwiaciarniaonline.com
Website: kwiaciarniaonline.com