Privacy policy
PRIVACY POLICY
1. Introduction
This Privacy Policy (the “Policy”) explains how the personal data of users and customers of the online store (the “Store”) is collected and processed. This is a general, international version of the Policy and is not tied to the law of any single country; where a user is located in the European Economic Area, or in another country with equivalent data protection law, the applicable mandatory provisions of that law (such as the General Data Protection Regulation (EU) 2016/679, the “GDPR”) apply.
By using the Store, the user acknowledges that they have read this Policy.
2. Data Controller
The controller of personal data collected through the Store is:
● NIZIO Sp. z o.o. — a limited liability company under Polish law (spółka z ograniczoną odpowiedzialnością)
● Registered with the KRS (Polish National Court Register) under number 0001248872
● NIP (Polish tax number): 9182194114 — REGON: 545042746 — EU VAT number: PL9182194114
● Registered office: ul. Krzeszowska 47, 23-400 Biłgoraj, Poland
● Legal representative: Mr Jan Nizio, Prezes Zarządu
● Email: office@niziohome.com
● Phone: +48 531 631 535
As the company is established in Poland, a member state of the European Union, it is not required to appoint a representative under Article 27 GDPR for EEA users. A data protection officer (DPO) only needs to be appointed under Article 37 GDPR where a business carries out large-scale, regular and systematic monitoring of individuals, or large-scale processing of special categories of data — which is not the case for a standard online furniture retail business; no DPO has therefore been appointed to date.
3. Data Collected
Depending on how the Store is used, the following categories of data may be collected:
● identification data: name;
● contact data: email address, phone number, postal address, delivery address;
● business data: VAT/tax number, for purchases made by a business;
● order data: products purchased, order history, preferences;
● payment data: processed directly by payment service providers (see clause 5); the Seller does not store or process full card details;
● connection and browsing data: IP address, browser type, pages visited, data collected via cookies and similar technologies (see clause 9).
Providing the data marked as mandatory when placing an Order or creating an account is necessary to perform the sale contract; without it, the Order cannot be processed. Other data (for example, signing up to the newsletter) is provided voluntarily.
4. Purposes and Legal Bases for Processing
● Handling orders, invoicing and delivery — performance of a contract (Art. 6(1)(b) GDPR);
● Creating and managing a customer account — performance of a contract / consent (Art. 6(1)(b) and (a) GDPR);
● Processing payments — performance of a contract (Art. 6(1)(b) GDPR);
● Customer support, handling complaints and warranty claims — performance of a contract and legitimate interest (Art. 6(1)(b) and (f) GDPR);
● Complying with legal and accounting obligations (invoicing, retention of accounting records) — legal obligation (Art. 6(1)(c) GDPR);
● Sending the newsletter and marketing communications — prior, revocable consent (Art. 6(1)(a) GDPR);
● Audience measurement, improving the Store, fraud prevention and IT security — legitimate interest (Art. 6(1)(f) GDPR) or consent depending on the tool concerned (see clause 9);
● Managing customer reviews and post-purchase satisfaction surveys — legitimate interest / consent, depending on the case.
5. Recipients of Data
Personal data is disclosed to the controller and, to the extent strictly necessary for the purposes described above, to the following categories of recipients:
● online payment service providers (for example Stripe, PayPal, or other providers integrated into the Store);
● carriers and logistics providers responsible for delivering orders;
● the provider of the Store's technical platform and hosting: Shopify International Limited, an Irish company (registration number 560279), 2nd Floor, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland, and the Shopify group's technical subprocessors;
● accounting service providers and, where applicable, an external accountant;
● providers of marketing email tools and of audience-measurement or advertising tools (see clause 9);
● administrative or judicial authorities, on request and within the limits allowed by law.
The Seller does not sell or transfer customers' personal data to third parties for commercial purposes.
6. Transfers of Data Outside the European Economic Area
Some of the providers listed in clause 5 (in particular hosting, payment, analytics or advertising tools) may be established, or may process data, outside the European Economic Area, in particular in the United States. In that case, the controller ensures that such transfers are subject to appropriate safeguards within the meaning of Articles 44 et seq. GDPR, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or the recipient's participation in the EU-U.S. Data Privacy Framework.
7. Data Retention
● Customer account data: for as long as the account exists, then 3 years from the last active contact for marketing purposes, unless earlier deletion is requested;
● Order and invoice data: 10 years from the end of the relevant accounting period, in line with legal requirements to retain commercial and accounting records;
● Payment method data: held solely by payment service providers, in accordance with their own retention periods;
● Marketing data (newsletter): 3 years from the last active contact, or until consent is withdrawn;
● Cookies and similar technologies: up to 13 months from being set (see clause 9).
8. Your Rights
Where the GDPR or equivalent data protection law applies, individuals have the following rights over their personal data:
● right of access (Art. 15): to obtain confirmation of whether data is being processed and, if so, to access it;
● right to rectification (Art. 16): to have inaccurate or incomplete data corrected;
● right to erasure / “right to be forgotten” (Art. 17), in the cases set out in the GDPR;
● right to restriction of processing (Art. 18), in the cases set out in the GDPR;
● right to data portability (Art. 20), where processing is based on consent or on a contract and is carried out by automated means;
● right to object (Art. 21), in particular at any time and without justification to direct marketing;
● right to withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing based on consent before its withdrawal;
● right to lodge a complaint with the data protection supervisory authority of the country in which the individual lives, works, or where the alleged infringement took place; for the controller's home authority, this is the Polish Data Protection Authority (Urząd Ochrony Danych Osobowych — UODO), ul. Stawki 2, 00-193 Warsaw, Poland — www.uodo.gov.pl.
These rights may be exercised by writing to office@niziohome.com or by post to the controller's address given in clause 2, enclosing proof of identity where there is reasonable doubt as to the requester's identity. The controller will respond within one month, which may be extended by a further two months for complex requests, in accordance with Article 12 GDPR.
9. Cookies and Similar Technologies
The Store uses cookies and other tracking technologies. Where the applicable law of a user's country requires consent for non-essential cookies (as is generally the case in the EEA and the UK), the Store obtains that consent before placing such cookies.
9.1 Obtaining consent
On first visiting the Store, an information banner lets the user accept, reject, or customise, cookie by cookie or category by category, the placing of cookies that are not strictly necessary for the Store to function. Rejecting is offered just as easily as accepting (the “Reject all” button is as visible and accessible as the “Accept all” button), and no box is pre-ticked. The user may change their choices at any time via the “Cookie settings” link in the Store's footer.
9.2 Categories of cookies used
The Store distinguishes between two types of cookies based on how long they last: “session” cookies, temporary files kept on the user's device until they log out, leave the Store, or close their browser; and “persistent” cookies, kept on the device for the period set by their own parameters, or until deleted by the user. The Store uses the consent-management tool built into its technical platform (Shopify Customer Privacy), which sorts cookies and similar technologies into the following four universal categories:
|
Category |
Purpose |
Consent required? |
Maximum retention |
|
Necessary / essential |
Needed for the Store to function and for its core features: cart, order session, customer account login, security, remembering language and currency |
No (performance of the contract / legitimate interest) — cannot be switched off |
Session length, or up to 13 months for persistent necessary cookies |
|
Analytics (statistics) |
Understanding how visitors use the Store (pages visited, browsing path, errors) in order to improve its functioning and performance |
Yes |
Up to 13 months |
|
Marketing / advertising |
Tracking browsing behaviour to show personalised advertising and communications on the Store and on third-party sites, and to measure campaign performance |
Yes |
Up to 13 months |
|
Preferences / functionality |
Remembering user choices (display settings, recently viewed products, wishlist) to personalise the browsing experience |
Yes, except where strictly necessary for a feature the user has expressly requested |
Up to 13 months |
9.3 Browser settings
Users may also configure their browser to refuse cookies, although this may prevent access to certain features of the Store (for example, the cart or customer account).
10. Newsletter and Marketing
Signing up to the Store's newsletter requires the user's prior consent (an unticked box, or a double opt-in process), where required by applicable law. Every communication includes an unsubscribe link, allowing the user to opt out at any time, free of charge, without needing to give a reason or delete their customer account.
11. Data Security
The controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in particular encryption of data in transit (TLS/SSL protocol), restricting access to data to authorised personnel, and backup procedures. Despite these measures, the controller cannot guarantee absolute security, given the inherent risks of any open network such as the internet.
Content that users voluntarily post in public areas of the Store (product reviews, comments) is visible to any visitor to the Store; publishing such content is done at the sole responsibility of its author.
12. Minors
The Store is not directed at minors. Orders and account creation should be carried out by an adult, or by a minor with the consent of their legal guardian.
13. Changes to this Policy
This Policy may be updated from time to time, in particular to reflect legal, regulatory, editorial or technical developments. The version published on the Store at the time of a visit applies. Users with an account will be notified by email of any material change.
14. Contact
If you have any questions about this Policy or about how your personal data is processed, you can contact the controller at office@niziohome.com.
Last updated: 17 September 2026