Privacy policy

Privacy Policy

 1. Definitions 

Administrator – m-maciejewska studio Weronika Maksimowicz-Maciejewska
Personal data – information about a person identified or identifiable through one or more specific factors determining the physical, physiological, genetic, psychological, economic, cultural or social identity, including the device IP, internet identifier and information collected via cookies and other similar technology.
Policy – this Privacy Policy.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.
Service
– website run by the Administrator at www.m-maciejewska.com
User – any physical person visiting the Service or using one or more services or functionalities described in the Policy.
Cookies - computer data, in particular text files, are stored in the user's end device.

2. Processing of Personal Data in connection with the use of the Service
In connection with the User's use of the Service, the Administrator collects data to the extent necessary to provide individual services offered. Detailed principles and purposes of processing Personal Data collected during the use of the Service by the User are described below. 

3. Purposes and legal basis for processing Personal Data on the Website 
1. Using the Website
The personal data of all persons using the Website are processed by the Administrator:
a) in order to provide services electronically in the scope of making the content collected on the Website available to Users - then the legal basis for processing is the necessity of processing to perform the contract (art. 6 sec. 1 letter b of the GDPR),
b) in order to establish and pursue claims or defend against claims - the legal basis for processing is the legitimate interest of the Administrator (art. 6 sec. 1 letter f of the GDPR), consisting in the protection of its rights,
c) in order to perform concluded contracts or take action (at the request of the Client) before concluding such contracts, on the basis of: art. 6 sec. 1 letter b of the GDPR. 
2. Contact form
The Administrator provides the possibility of contacting them using an electronic contact form. Using the form requires providing Personal Data necessary to establish contact with the User and to respond to the inquiry. The User may also provide other data to facilitate contact or handle the inquiry. Providing data marked as mandatory is required in order to accept and process the query, and failure to provide it results in the inability to process it. Providing the remaining data is voluntary.

Personal data is processed in order to identify the sender and process their query sent via the provided form - the legal basis for processing is the necessity of processing to perform the service agreement (Article 6, paragraph 1, letter b of the GDPR); in the scope of data provided optionally, the legal basis for processing is consent (Article 6, paragraph 1, letter a of the GDPR). 

3. Marketing The User's personal data may also be used by the Administrator to send marketing content to them via various channels, i.e. via e-mail, MMS/SMS. Such actions are taken by the Administrator only if the User has given consent, which they may withdraw at any time.
Personal data is processed:
1. for the purpose of sending the ordered commercial information - the legal basis for processing, including using profiling, is the legitimate interest of the Administrator (Article 6, paragraph 1, letter f of the GDPR) in connection with the expressed consent,
2. for analytical and statistical purposes - the legal basis for processing is the legitimate interest of the Administrator (Article 6, paragraph 1, letter f of the GDPR), consisting in conducting analyses of User activity on the Service in order to improve the functionalities used. 

4. User account
The Administrator also provides the possibility of creating a user account on the Service. In order to create a profile, you must provide data such as: name, surname, e-mail address, password. The User can complete their profile with their residential address and telephone number - providing this data is voluntary.
Personal data are processed:
1. for analytical and statistical purposes - the legal basis for processing is the legitimate interest of the Administrator (Article 6, paragraph 1, letter f of the GDPR), consisting in conducting analyses of Users' activity on the Website in order to improve the functionalities used,
2. in order to identify the sender and handle their inquiry sent via the provided form - the legal basis for processing is the necessity of processing to perform the contract for the provision of the service (Article 6, paragraph st. 1 letter b GDPR); in the scope of optionally provided data, the legal basis for processing is consent (art. 6 sec. 1 letter a GDPR), in order to perform concluded agreements or take action (at the request of the Client) before concluding such agreements, on the basis of: art. 6 sec. 1 letter b GDPR. 

4. Cookies
1. The Administrator uses cookies within the Service.
There are two types of cookies:
1. Session cookies, which remain on the device until you leave the page, turn off the used web browser or device (depending on which of the above circumstances occurs first),
2. Persistent cookies, which remain on the device for the time specified in their parameters or until they are deleted by the user (depending on which of the above circumstances occurs first).

2. The purpose of cookies is to improve the operation of the website and increase its efficiency, as well as to provide information to the owners of the website.
3. Consent to the use of cookies can be managed from the privacy settings of the page or the settings of the web browser.
4. Instructions for disabling cookies in individual web browsers can be found on the websites of their publishers.
5. Disabling the use of cookies may disrupt the operation of some functions of the website and reduce its ease of use.
6. Resignation from cookies will only apply to a specific browser. Therefore, appropriate actions will have to be taken in the case of any other browser used on the same or another device. 

5. Period of processing of Personal Data
The period of data processing by the Administrator depends on the type of service provided and the purpose of processing. As a rule, data is processed for the duration of the service, until the withdrawal of the expressed consent or the submission of an effective objection to data processing in cases where the legal basis for data processing is the legitimate interest of the Administrator.
The period of data processing may be extended in the event that processing is necessary to establish and pursue potential claims or defend against claims, and after that time only in the case and to the extent required by law. After the processing period has elapsed, the data is irreversibly deleted or anonymized.
6. User Rights
1. The User has the right to access the content of the data and to request its rectification, deletion, restriction of processing, the right to transfer data and the right to lodge a complaint with the supervisory body responsible for the protection of Personal Data.
2. The User also has the right to object to the processing of data, which is based on the legitimate interest of the Administrator.
3. To the extent that the User's data is processed on the basis of consent, this consent may be withdrawn at any time by contacting the Administrator via e-mail: werka.m.maciejewska@gmail.com 

7. Recipients of Personal Data
In connection with the provision of services, Personal Data will be disclosed to external entities, including:
a) IT service providers enabling the proper use of the Service,
b) entities authorized under agreements concluded by the entrepreneur to the extent necessary to perform said agreements, including entities providing services and maintaining the entrepreneur's e-mail,
c) entities conducting postal or courier activities,
d) entities enabling the entrepreneur to perform remote payment operations,
e) banks, in the event of the need to conduct settlements,
f) state authorities or other entities authorized under the provisions of law,
g) entities supporting the entrepreneur in the conducted business on behalf of the entrepreneur, in particular suppliers of external systems supporting the entrepreneur's activities.
2. In the event of obtaining the User's consent, their data may also be made available to other entities for their own purposes, including marketing purposes. 

8. Transfer of Personal Data outside the EEA
The level of protection of Personal Data outside the European Economic Area (EEA) differs from that provided by European law. For this reason, the Administrator transfers Personal Data outside the EEA only when necessary and with an adequate level of protection, primarily through:
a) cooperation with entities processing Personal Data in countries for which an appropriate decision of the European Commission has been issued regarding the adequate level of protection of Personal Data,
b) use of standard contractual clauses issued by the European Commission,
c) use of binding corporate rules approved by the relevant supervisory authority.
The Administrator always informs about the intention to transfer Personal Data outside the EEA at the stage of their collection. 

9. Security of Personal Data
The Administrator conducts an ongoing risk analysis in to ensure that Personal Data is processed by him in a secure manner – ensuring, above all, that only authorized persons have access to the data and only to the extent necessary for the tasks they perform. The Administrator ensures that all operations on Personal Data are recorded and performed only by authorized employees and collaborators.
The Administrator takes all necessary actions so that its subcontractors and other collaborating entities also guarantee the application of appropriate security measures in each case when they process Personal Data on behalf of the Administrator. 

10. Contact details Contact with the Administrator is possible via e-mail: werka.m.maciejewska@gmail.com 

11. Changes to the Privacy Policy The Policy is verified on an ongoing basis and updated if necessary. The current version of the Policy has been adopted and is effective from February 13, 2025