Privacy and Cookies Policy
PRIVACY AND COOKIES POLICY OF THE ONLINE SHOP
patternsbypaulina.pl
The administrator of your personal data is Paulina Matykiewicz-Bury, conducting a non-registered business activity (NDG), address: ul. Turkusowa 9/24, 43-100 Tychy, Poland.
You can contact the Administrator:
- in writing: ul. Turkusowa 9/24, 43-100 Tychy, Poland
- by e-mail: biuro@patternsbypaulina.pl
Your personal data, as a user (“User”) of the website patternsbypaulina.pl (“Website”), are processed in accordance with applicable laws, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (GDPR), as well as with the Polish Act on the Provision of Electronic Services of 18 July 2002.
Are Your Data Safe?
The Administrator undertakes to apply all required technical and organizational measures to ensure the security and protection of personal data as required by applicable law. All data are collected with due care and protected against unauthorized access or disclosure.
Purposes of Data Processing
The Administrator may process your personal data when it is necessary for you to use the Website.
The legal basis for processing your personal data is to enable you to use the Website, including the use of the Contact Form.
Your personal data may be processed for the following purposes:
a) Provision of electronic services, including:
- concluding and performing sales agreements for designs ordered by the User through the Website – legal basis: Article 6(1)(b) GDPR,
- creating and managing a User Account on the Website – legal basis: Article 6(1)(b) GDPR;
b) Compliance with legal obligations, including accounting, billing, and financial reporting – legal basis: Article 6(1)(c) GDPR;
c) Legitimate interests pursued by the Administrator – legal basis: Article 6(1)(f) GDPR – which include:
- conducting marketing activities, including sending newsletters,
- communicating with you regarding messages sent via the contact form,
- ensuring proper functioning of the Website, including the contact form, registration form, and order form,
- archiving, statistics, and possible claims handling or defense against claims related to the performance of electronic services.
Data Retention Period
Your personal data will be processed for as long as necessary to achieve the purposes for which they are processed, i.e.:
- until the expiration of limitation periods for any claims related to the Website’s operation, including contracts concluded through it,
- until a justified objection is submitted – for data processed based on the Administrator’s legitimate interest,
- until withdrawal of consent to receive marketing communications by e-mail or telephone, or until an objection to such processing is raised,
- until the expiry of legal obligations related to data retention, including accounting documentation requirements.
Categories of Data Recipients
Your data may be transferred to entities that assist the Administrator in the operation of the Website and business activities. These may include:
- IT service providers,
- accounting service providers,
- online payment operators.
Your data may also be shared with other entities authorized by law to access such data.
All recipients process personal data using appropriate technical and organizational safeguards.
The Administrator does not intend to transfer your data to countries outside the European Economic Area (EEA) or to any international organizations.
Automated Decision-Making and Profiling
The Administrator does not make decisions based on automated processing, including profiling, that could affect you legally or significantly.
Your Rights
You have the right to:
- access your personal data and request their rectification, erasure, or restriction of processing,
- data portability,
- withdraw consent to processing (where consent is the legal basis for processing); withdrawal of consent does not affect the lawfulness of processing prior to withdrawal,
- object to the processing of your data where it is based on the Administrator’s legitimate interests,
- lodge a complaint with the President of the Personal Data Protection Office (UODO) if you believe the processing violates GDPR.
To exercise your rights, please contact the Administrator using the details provided above.
Is Providing Data Mandatory?
Providing your personal data is voluntary but necessary to achieve the purposes described in this Privacy Policy.
Cookies
Cookies are small text-numeric files stored by the Website’s IT system on your device (computer, phone, or other device used to access the Website). Cookies allow the Website to recognize your device upon return visits.
The Website uses the following types of cookies:
- session cookies, automatically deleted after closing the web browser;
- persistent cookies, stored on your device for a defined period (not dependent on closing the browser);
- first-party cookies, set by this Website;
- third-party cookies, set by external services such as Google Analytics.
The Administrator uses both first-party and third-party cookies.
The Website uses Google Analytics (provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to create statistics, analyze Website performance, and improve user experience – based on the Administrator’s legitimate interest.
The primary purpose of using cookies is to manage and enhance the Website’s functionality and content quality.
Cookies are necessary for the correct display and operation of the Website.
They may also be used for anonymous statistical purposes, such as analyzing Website traffic and average visit duration. Cookies are not used to identify users personally.
Cookies are used only with your consent. The Administrator does not sell or share cookies with other companies.
Your consent is expressed through your browser settings that allow storing cookies on your device.
Most browsers accept cookies by default. You can withdraw or modify your consent to the use of cookies at any time, as well as delete stored cookies. You can also restrict or disable cookies via your browser settings – either blocking them completely or prompting warnings before saving them.
However, please note that disabling cookies may affect your ability to access certain Website content, or, in extreme cases, may prevent the Website from displaying correctly.
Server Logs
Using the Website involves sending queries to the server on which it is hosted.
Each query is recorded in the server logs, which may include:
your IP address, server request date and time, information about your browser, and operating system.
These logs are stored on the server for administrative purposes only.
The data in the logs are not associated with specific individuals and are not used to identify you.
They serve solely as technical material for managing the Website and are accessible only to authorized personnel.

