3. Privacy Policy

3.1. Introduction & controller identification

The data controller (“Controller”) for the personal data processed in connection with our services is

Casa De La Vida Sp. z o.o., KRS: 0000824533

REGON: 38537872800000

NIP: 7010966699

registered office: ul. Aleje Ujazdowskie 47/17 00-536 Warszawa, Mazowieckie

e-mail: admin@blancetrouge.pl

We are committed to protecting your personal data and processing it in accordance with the General Data Protection Regulation (GDPR) and Polish implementing law (Act of 10 May 2018 on Personal Data Protection and other relevant legislation)

This Policy explains how we collect, use, disclose and protect your personal data, and your rights in relation to your data.

3.2. What personal data we collect

We may collect the following categories of personal data:

Identity data: name, surname, title, date of birth (where required)

Contact data: delivery address, billing address, email address, phone number

Payment data: bank account or payment card details (or other payment instrument) – note: we do not store full card details unless acting as processor; payment may be processed by a payment service provider

Transaction data: products purchased, order date, order number, payment status, delivery status

Technical data: IP address, browser type/version, time zone setting, browser plug-in types and versions, operating system and platform, other technology on the devices you use to access our website

Usage data: information about how you use our website, products and services

Marketing & communications data: your preferences in receiving marketing from us and your communication preferences

(Optional) Any other data you choose to provide (e.g., reviews, feedback, user‐generated content)

3.3. Legal basis for processing

We process personal data on one or more of the following bases:

  • Performance of a contract: processing necessary for fulfilling the sales contract you have with us (e.g., order processing, payment, delivery). 

  • Legal obligation: processing necessary to comply with legal obligations (e.g., tax, accounting, consumer rights, anti-money-laundering)

  • Legitimate interests: processing for our legitimate interests (e.g., improving our services, analysing how users use our site, prevention of fraud) provided this does not override your rights and freedoms.

  • Consent: in cases such as direct marketing, cookies (beyond strictly necessary), we will ask for your prior explicit consent. You can withdraw your consent at any time.

3.4. Purposes of processing and data categories

To provide our website and services, process orders and payments, deliver products, manage returns, refunds and complaints.

To administer your account, customer support, manage your legal rights (warranty, guarantee, consumer rights).

To comply with legal and regulatory obligations (tax, accounting, auditing, fraud prevention).

To send you marketing communications (if you have opted in), offers, newsletters.

To improve our website, products and services, via analytics, trends, usage data.

(If applicable) To customise your user experience, personalise product recommendations.

(If applicable) To monitor and prevent fraudulent or unauthorised transactions and maintain security of our systems.

3.5. Recipients / categories of recipients

Your data may be shared with:

Payment service providers, banks, courier/delivery companies, logistics partners (only to the extent necessary for fulfilment of delivery)

External IT/hosting providers, analytics providers, marketing service providers (under appropriate data‐processing agreements)

Public authorities/tax authorities to the extent required by law

Other third parties if you give your consent or in the event of business restructuring (merger, sale of business) with appropriate safeguards

3.6. International transfers

Should we transfer your personal data outside the European Economic Area (EEA), we will ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses, adequacy decisions) in line with GDPR requirements. 

3.7. Data retention / storage periods

We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the period required by applicable law (e.g., tax, accounting) and in accordance with our internal retention policies. After the expiry of these periods, data will be securely deleted or anonymised.

3.8. Your rights

Under GDPR you have the following rights:

Right of access: you can request a copy of your personal data we hold. 

Right to rectification: you can request correction of inaccurate or incomplete data.

Right to erasure (“right to be forgotten”): in certain circumstances you can request deletion of your data. 

Right to restriction of processing: you can request us to restrict processing where certain conditions apply.

Right to data portability: you can request a copy of your data in a structured, commonly used machine-readable format, and transmit to another controller where the processing is based on consent or contract. 

Right to object: you can object to processing based on legitimate interests or for direct marketing; we will stop processing unless we have compelling legitimate grounds. 

Right to withdraw consent: where processing is based on consent, you may withdraw it at any time; withdrawal does not affect processing before withdrawal.

Right to lodge a complaint with a supervisory authority: in Poland the supervisory authority is the Urząd Ochrony Danych Osobowych (UODO).

3.9. Cookies and tracking

We use cookies and similar tracking technologies on our website. Some cookies are strictly necessary for the site to function; others are optional (analytics, advertising, personalisation). We will obtain your consent before placing non-essential cookies and provide information about them in our Cookie Policy or via a banner.

3.10. Security measures

We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure or destruction. We regularly review our systems and procedures to ensure data security and compliance with GDPR and Polish law. 

3.11. Links to other websites

Our website may include links to third-party sites. This Policy does not cover their processing of your personal data. We encourage you to review their privacy policies separately.

3.12. Changes to this Policy

We may update this Privacy Policy from time to time (for example due to changes in legal requirements). When we do so, we will publish the revised Policy on our website along with the date of last revision. Your continued use of our website after such changes constitutes acceptance of the revised Policy.

3.13. Contact details

If you have any queries about this Policy or wish to exercise your rights, please contact us at:

E-mail: admin@blancetrouge.pl

Address: ul. Aleje Ujazdowskie 47/17 00-536 Warszawa, Mazowieckie

We have not appointed a separate Data Protection Officer. All inquiries, requests, or complaints regarding the processing of your personal data should be directed to our contact email: admin@blancetrouge.pl.