Privacy policy
Last updated: June 3, 2026
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy & Cookies Policy.
§1. Personal Data Controller
-
The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR), is Soft Authority Nataliia Nahaievska, a sole proprietorship established under the laws of Poland, with its registered address at ul. Jutrzenki 92/8, 02-230 Warsaw, Poland, entered into the Central Registration and Information on Business (CEIDG), VAT Identification Number (NIP): PL6772427339, REGON: 543961360.
-
E-mail address of the Data Controller: hello@soft-authority.com.
-
In accordance with Article 32(1) GDPR, the Controller observes the principle of data protection and applies appropriate technical and organisational measures to prevent accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed in connection with its business activities.
-
Providing personal data by the customer is voluntary but necessary to conclude a contract with the Data Controller.
-
The Data Controller processes personal data only to the extent necessary for the performance of a contract or the provision of services to the data subject.
§2. Purposes and Legal Bases for Personal Data Processing
The Data Controller processes personal data for the following purposes:
a) Preparation of a commercial offer in response to a customer’s enquiry – the legitimate interest of the Data Controller (Article 6(1)(f) GDPR);
b) Conclusion and performance of sales contracts with customers – based on the contract concluded with the customer (Article 6(1)(b) GDPR);
c) Provision of electronic services via the online store – based on the contract concluded with the customer (Article 6(1)(b) GDPR);
d) Handling of complaints – based on the legal obligations incumbent on the Controller (Article 6(1)(c) GDPR);
e) Accounting and invoicing – based on tax law provisions (Article 6(1)(c) GDPR);
f) Archiving of data for the purpose of establishing, pursuing, or defending legal claims or for evidentiary purposes – the legitimate interest of the Controller (Article 6(1)(f) GDPR);
g) Telephone or e-mail contact, particularly in response to enquiries directed to the Controller – the legitimate interest of the Controller (Article 6(1)(f) GDPR);
h) Transmission of technical information regarding the operation of the online store and the services used by the customer – the legitimate interest of the Controller (Article 6(1)(f) GDPR);
i) Marketing activities – based on the Controller’s legitimate interest (Article 6(1)(f) GDPR) or on the customer’s prior consent (Article 6(1)(a) GDPR).
§3. Data Recipients and Transfer of Data to Third Countries
-
The recipients of personal data processed by the Controller may include entities cooperating with the Controller when necessary for the performance of a contract concluded with the data subject.
-
The recipients of personal data processed by the Controller may also include subcontractors – entities whose services the Controller uses in the course of data processing, such as accounting offices, law firms, and IT service providers (including hosting services).
-
The Controller may be required to disclose personal data pursuant to applicable laws, in particular to authorised public authorities or state institutions.
-
Personal data may also be transferred to an entity established outside the European Economic Area (EEA) in connection with the Controller’s use of tools for website traffic analysis and tracking, e.g., Google LLC or Meta Platforms Inc.
As an appropriate data protection safeguard, the Controller has entered into Standard Contractual Clauses (SCCs) with the providers of these services, in accordance with Article 46 GDPR.
More information on data transfers outside the EU is available at:
https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu_en.
§4. Period of Personal Data Retention
-
The Controller stores personal data for the duration of the contract concluded with the data subject and after its termination for purposes related to the pursuit of claims arising from the contract and the performance of obligations resulting from applicable laws, but no longer than the limitation period as defined in the Civil Code.
-
The Controller stores personal data contained in accounting and settlement documents for the period specified in the provisions of the Value Added Tax Act and the Accounting Act.
-
The Controller stores personal data processed for marketing purposes for a period of 10 years, but no longer than until consent for data processing is withdrawn or an objection to data processing is raised.
-
The Controller stores personal data for purposes other than those indicated in paragraphs 1–3 for a period of one year, unless consent for data processing has been withdrawn earlier and the processing cannot be continued on any basis other than the data subject’s consent.
§5. Rights of the Data Subject
-
Every data subject has the right to:
a) Access – obtain confirmation from the Controller as to whether personal data concerning them are being processed. If such data are being processed, the data subject has the right to access the data and receive information regarding: the purposes of processing, categories of personal data, the recipients or categories of recipients to whom the data have been or will be disclosed, the period of data retention or the criteria used to determine that period, the right to request rectification, erasure, or restriction of processing, and the right to object to such processing (Article 15 GDPR);
b) Receive a copy of the data – obtain a copy of the personal data being processed; the first copy is provided free of charge, while the Controller may charge a reasonable administrative fee for additional copies (Article 15(3) GDPR);
c) Rectification – request correction of inaccurate personal data or completion of incomplete data (Article 16 GDPR);
d) Erasure (“right to be forgotten”) – request the deletion of personal data if the Controller no longer has a legal basis for processing or if the data are no longer necessary for the purposes for which they were collected (Article 17 GDPR);
e) Restriction of processing – request restriction of processing of personal data (Article 18 GDPR) where:-
the accuracy of the personal data is contested by the data subject – for a period enabling the Controller to verify the accuracy of the data;
-
the processing is unlawful, and the data subject opposes erasure, requesting restriction instead;
-
the Controller no longer needs the data, but the data are required by the data subject for the establishment, exercise, or defence of legal claims;
-
the data subject has objected to processing – pending verification of whether the legitimate grounds of the Controller override those of the data subject;
f) Data portability – receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and transmit those data to another controller where the processing is based on consent or on a contract and carried out by automated means (Article 20 GDPR);
g) Objection – object to the processing of their personal data for the Controller’s legitimate purposes on grounds relating to their particular situation, including profiling. In such a case, the Controller shall assess whether there are compelling legitimate grounds for processing that override the interests, rights, and freedoms of the data subject, or grounds for the establishment, exercise, or defence of legal claims. If the data subject’s interests are deemed to prevail, the Controller shall cease processing the data for those purposes (Article 21 GDPR).
-
-
To exercise the above rights, the data subject should contact the Controller using the provided contact details and specify which right and to what extent they wish to exercise.
-
The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) in Warsaw.
§6. Profiling
-
Personal data obtained by the Controller may be processed automatically, including through profiling. Profiling by the Controller consists of evaluating selected information about the data subject to analyse and predict their personal preferences and interests, in particular to provide personalised offers.
-
Automated data processing by the Controller does not produce any legal effects for the data subject. The data subject may object at any time to the automated processing of their data.
§7. Google Analytics
The Controller uses Google Analytics, a web analytics service provided by Google Inc., based in the USA.
Google Analytics uses cookies that enable the analysis of how users use the website. Information generated by cookies about website usage is transmitted to and stored on Google’s servers. On behalf of the Controller, Google will use this information to analyse website usage, prepare reports on website activity, and provide other services related to website and internet usage for the Controller.
The data will not be used for the purpose of identifying any individual.
-
The user may prevent the storage of cookies by adjusting their browser settings; however, in such cases, full website functionality may not be available. In addition, users can prevent Google from collecting and processing data generated by cookies and related to their use of the website (including the IP address) by downloading and installing a browser plugin available at:
https://tools.google.com/dlpage/gaoptout?hl=pl -
At any time, the user may object to the collection and processing of data related to website usage by Google by downloading and installing the browser plugin available at:
-
At any time, the user may object to the collection and processing of data related to website usage by Google by downloading and installing the browser plugin available at:
https://tools.google.com/dlpage/gaoptout.
§8. Facebook Pixel
-
The Controller uses Facebook Pixel, an analytical tool that helps measure the effectiveness of advertisements based on the analysis of user actions on the website.
-
The Controller uses Facebook Pixel to deliver personalised advertisements to customers on the Facebook platform. This involves the use of Facebook cookies. The legal basis for the Controller’s use of Facebook Pixel is Article 6(1)(f) GDPR, as it constitutes the Controller’s legitimate interest.
COOKIES POLICY
-
The online store does not automatically collect any information, except for information contained in cookies.
-
Cookies are IT data, in particular text files, which are stored on the Client’s end device and intended for use on the online store’s websites. Cookies usually contain the name of the website from which they originate, the duration of their storage on the end device, and a unique number.
-
The entity placing cookies on the Client’s end device and having access to them is Soft Authority Nataliia Nahaievska, with its registered office in Warsaw, Poland.
-
Cookies are used for the following purposes:
a) To tailor the content of the online store’s websites to the Client’s preferences and optimise the use of the websites; in particular, cookies allow the recognition of the Client’s device and proper display of the website adapted to their individual needs.
b) To create statistics that help understand how Clients use the websites, which enables improvement of their structure and content.
c) To maintain the Client’s session to allow returning to the content of the shopping cart. -
The online store uses the following types of cookies:
a) Session cookies and persistent cookies. Session cookies are temporary files stored on the Client’s device until logout, leaving the website, or closing the browser. Persistent cookies are stored on the Client’s device for the time specified in the cookie parameters or until deleted by the Client.
b) Necessary cookies, enabling the use of services available on the online store, e.g., authentication cookies used for services that require login.
c) Cookies used to ensure security, e.g., for detecting abuse in authentication processes within the online store.
d) Performance cookies, enabling the collection of information on how the online store’s websites are used.
e) Functional cookies, enabling the “remembering” of selected Client settings and interface personalization, e.g., selected language or region, font size, website appearance, etc.
f) Advertising cookies, enabling the delivery of advertising content more tailored to the Client’s interests. -
In many cases, software used to browse the internet (web browser) allows cookies to be stored on the Client’s device by default. Clients can change their cookie settings at any time. These settings can, in particular, block automatic handling of cookies in the browser settings or notify the Client each time cookies are placed on their device. Detailed information on the possibilities and methods of handling cookies is available in the software (browser) settings.
-
The Seller informs that restrictions on the use of cookies may affect some functionalities available on the online store.
-