Przerwa urlopowa 14–24.08.2026 | Wszystkie zamówienia złożone w tym czasie zostaną wysłane po 25.08.2026. Dziękuję za wyrozumiałość! Dismiss
Skip to content§1 Administration of Personal Data
1. The administrator of personal data is Martyna Krajewska-Nawój, conducting business under the name INTERY Martyna Krajewska-Nawój, at ul. W. Reymonta 10H/57, 50-225 Wroclaw. The business is registered in the Central Register and Information on Economic Activity under the NIP number: 8911612700, REGON 385721801.
2. Contact with the person supervising the processing of personal data in the organization is possible electronically at the email address: art@sienapaloma.com, in writing to the Administrator’s address or by phone at 667 242 572.
3. This Policy contains the principles regarding the processing of personal data by the Administrator in the Internet Service, including the basis, purposes, and scope of personal data processing, as well as the rights of the individuals whose data is processed.
4. Personal data is processed by the Administrator in accordance with applicable laws, in particular, in accordance with the regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data as well as repealing directive 95/46/EC (General Data Protection Regulation) Official text of the GDPR:
http://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679.
5. User rights are not absolute and do not apply to all processing activities concerning personal data.
§2 Definitions
1. Administrator – Martyna Krajewska-Nawój, conducting business under the name INTERY Martyna Krajewska-Nawój, at ul. W. Reymonta 10H/57, 50-225 Wroclaw. The business is registered in the Central Register and Information on Economic Activity under the NIP number: 8911612700, REGON 385721801.
2. Personal Data – information about a natural person that is identified or identifiable by one or more specific factors defining physical, physiological, genetic, mental, economic, cultural, or social identity, including device IP, internet identifier, and information collected through cookies and other similar technologies.
3. Policy – this Privacy Policy.
4. GDPR / GDPR Regulation – regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data as well as repealing directive 95/46/EC.
5. Service – the internet service operated by the Administrator at the address sienapaloma.com.
6. User – any natural person visiting the Service or using one or several services or functionalities described in the Policy.
§3 Security
1. The Administrator has implemented appropriate technical and organizational measures to ensure the security of personal data processing and is particularly responsible and ensures that the data collected is:
processed lawfully;
collected for specified, lawful purposes and not further processed in a manner inconsistent with those purposes;
factually correct and adequate in relation to the purposes for which they are processed; stored in a form which permits identification of the data subjects for no longer than is necessary to achieve the purpose of the processing; and
processed in a manner ensuring appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
§4 Purposes and Legal Bases for Data Processing
1. Based on Article 6(1)(a) of the GDPR (consent), personal data will be processed for the purposes of:
marketing products and services of the Administrator and the Administrator’s partners, newsletter distribution,
moderating content in the Service,
saving data in cookies, as well as using cookies for the proper functioning of the Service,
issuing opinions on products or services, participation in webinars or online training,
contact through remote communication tools, in particular: telephone, email, or applications.
2. Based on Article 6(1)(b) of the GDPR (performance of a contract), personal data will be processed for the purposes of:
Performing the sales contract or service agreement or taking actions requested by the data subject before the conclusion of the indicated contract or after its conclusion, in particular: the right to warranty, handling complaints or withdrawal from a distance contract.
3. Based on Article 6(1)(c) of the GDPR (legal obligation of the Administrator), personal data will be processed for the purposes of:
Issuing and storing invoices, bills, or fulfilling other obligations arising from tax and accounting regulations (archive obligation regarding accounting documents).
Creating registers and other documentation required by the GDPR.
4. Based on Article 6(1)(f) of the GDPR (legitimate interest of the Administrator), personal data will be processed for the purposes of:
Correctly executing the contract, processed for the duration of the contract and the rights arising from it, e.g., the right to a complaint. Providing data is voluntary but necessary.
Ensuring the security of the Service, managing the Service, and its proper functioning.
Conducting statistics and analyzing traffic in the Internet Service. Direct marketing.
Establishing claims raised by or against the Administrator. Contacting the User.
Service operation of sienapaloma.com.
Managing the Instagram account and interacting with users of the indicated platforms.
Data may be transmitted to the following recipients or categories of recipients of personal data, such as courier companies, postal operators, law firms, accounting firms, IT service providers.
1. The GDPR imposes an obligation on the Administrator to inform about automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR, and – at least in these cases – significant information on the principles of its making, as well as the significance and anticipated consequences of such processing for the data subject. With this in mind, the Administrator provides in this point of the privacy policy information regarding possible profiling.
2. The Administrator may use profiling in the Service for marketing purposes utilizing personal data provided by the User.
3. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
§6 Period of Personal Data Processing
1. The period of data processing by the Administrator depends on the type of service rendered and the purpose of processing. As a rule, data is processed for the duration of the service provision, until withdrawal of the consent given or filing an effective objection against the processing of data in cases where the legal basis for data processing is the legitimate interest of the Administrator.
2. The period of data processing may be extended when processing is necessary for the establishment and pursuit of potential claims or defense against claims, and after that time, only to the extent required by law. After the expiration of the processing period, data is irreversibly deleted or anonymized.
§7 Rights of the User
1. The User has the following rights regarding their personal data: access to their personal data,
rectification of personal data at any time, deletion of their personal data at any time, receipt of a copy of their data,
restriction of processing of personal data, objection to the processing of personal data, data portability,
withdrawal of consent; withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal,
objection to the processing of personal data on the basis of the legitimate interest of the Administrator for marketing purposes, direct marketing, and for purposes other than marketing,
to lodge a complaint with a supervisory authority.
§8 Recipients of Personal Data
1. The Administrator, for the proper operation of the Service, provides the User’s personal data to other external entities, in particular: hosting company, courier companies, payment operators.
2. The Administrator reserves the right to disclose personal data in situations where it results from applicable laws, including the obligation to provide information to relevant administrative authorities or law enforcement agencies.
§9 Transfer of Personal Data Outside the EEA
1. The level of protection of personal data outside the European Economic Area (EEA) differs from that provided by European law. For this reason, the Administrator transfers personal data outside the EEA only when necessary, in particular when using the services of an international entity. However, it always ensures an appropriate level of protection, primarily through:
cooperation with entities processing personal data in countries for which a relevant decision of the European Commission regarding the assurance of an appropriate level of protection of personal data has been issued; applying binding corporate rules approved by international certification standards and the relevant supervisory authority;
using standard contractual clauses issued by the European Commission based on Article 46 of the GDPR.
Personal data may also be transferred outside the EEA based on the User’s consent. The User is informed beforehand about this event.
§10 Security of Personal Data
1. The Administrator continuously conducts a risk analysis to ensure that personal data is processed securely. Through its actions, it ensures, first and foremost, that access to data is limited to authorized persons and only to the extent necessary for the tasks performed by them.
2. The Administrator is required to take all actions permitted by law to ensure that all operations on personal data are recorded and made only by authorized entities.
3. The Administrator is also required to ensure that other entities cooperating with the Administrator guarantee to apply appropriate security measures in every case when processing personal data on behalf of the Administrator.
§11 Changes to the Privacy Policy
1. The Policy is continuously reviewed and updated.
2. The current version of the Policy was adopted and is in effect from 2024-09-01.