Last updated: {Insert Date}
1. Who We Are
We are the data controller of this website and are responsible for how your personal information is collected and used.
Company: AR-CHEM ANNA SEREDA
Registered Address: 23-420 Różaniec Pierwszy 160, district Biłgorajski, commune Tarnogród, province LUBELSKIE, Poland
Email: moc.sbalelcsumxam@troppus
We comply with:
- UK GDPR
- EU GDPR (where applicable)
- Data Protection Act 2018
- PECR (Privacy & Electronic Communications Regulations)
2. What Personal Data We Collect
We collect the following categories of personal data when you use our site:
2.1 Information You Provide Directly
- Name
- Email address
- Billing address
- Shipping address
- Phone number
- Order information
- Support enquiries
- Account login details (if you register)
2.2 Information Collected Automatically
- IP address
- Browser type and version
- Device information
- Cookies, tracking pixels and browsing activity (pages visited, time on page, referring sites)
2.3 Payment Information
Payments are processed securely by third-party payment providers (e.g., Stripe, PayPal).
We never store full card details on our servers.
2.4 Age Verification (If Required)
We may request confirmation that you are 18+, to comply with product regulations and safe handling policies.
3. How We Use Your Personal Data
We process your data for:
- Fulfilling and managing your orders
- Providing customer support
- Sending service emails related to your purchase
- Fraud prevention and security monitoring
- Improving website functionality and analytics
- Marketing (where legally permitted and only with consent)
- Compliance with legal obligations (tax, accounting, anti-fraud)
We do not use your data for automated decision-making that has legal or significant effects.
4. Legal Bases for Processing (UK GDPR Article 6)
We use your data under these lawful bases:
- Contract – to fulfil your order
- Legitimate Interest – security, fraud prevention, analytics, website improvement
- Consent – for email marketing or optional cookies
- Legal Obligation – accounting, VAT, regulatory reporting
5. How Long We Keep Your Data
We retain your information only as long as necessary:
- Order + account records: 6 years (legal requirement)
- Support messages: up to 3 years
- Analytics/cookie data: up to 26 months
- Marketing data: until you unsubscribe or request deletion
6. How We Share Your Data
We do not sell your data.
We may share it with trusted third parties:
- Payment processors (Stripe, PayPal)
- Shipping carriers
- Customer support systems
- Analytics tools (Google Analytics, server logs)
- Email service providers
- Legal/regulatory authorities (only when required by law)
All third-party processors comply with GDPR and have data-processing agreements in place.
7. International Data Transfers
Some of our service providers may operate outside the UK/EU.
When this happens, we ensure:
- UK GDPR-approved transfer mechanisms
- Adequacy decisions OR
- Standard Contractual Clauses (SCCs)
Data is protected to the same standard as within the UK/EU.
8. Your Rights Under GDPR
You have the right to:
- Request access to your personal data
- Correct inaccurate data
- Request deletion (“right to be forgotten”)
- Restrict processing
- Object to processing (including marketing)
- Request data portability
- Withdraw consent at any time
- Lodge a complaint with the ICO (UK Information Commissioner’s Office)
To exercise these rights, email us at {Your Support Email}.
9. Cookies & Tracking Technologies
We use:
- Essential cookies (site functionality)
- Analytics cookies
- Ads/remarketing cookies (only with consent)
On your first visit, you will see a cookie consent banner that allows you to accept or manage cookies.
You can change your cookie preferences at any time.
10. Marketing Communications
We only send marketing emails if:
- You explicitly opt in, OR
- You are an existing customer and PECR permits “soft opt-in”
You can unsubscribe instantly via any marketing email footer.
11. Security
We take appropriate technical and organisational measures to protect your data, including:
- Encryption (HTTPS/SSL)
- Secure server environment
- Access controls
- Regular security audits
- Encrypted backups
No method is 100% secure, but we follow industry-standard best practices.
12. Children
This website is not intended for individuals under 18.
We do not knowingly collect children’s data.
13. External Links
Our site may contain links to external websites.
We are not responsible for their privacy practices.
14. Changes to This Policy
We may update this Privacy Policy when needed.
The latest version will always be posted on this page.
15. Contact Us
If you have questions about this Privacy Policy or want to exercise your rights:
