Documents to download

  • Privacy policy – Full privacy and cookies policy (PDF) DOWNLOAD

I. Controller and contact details

I. Controller and contact details

  1. The controller is Oliwier Kopaczel, conducting business as MEHENKER-Oliwier Kopaczel, ul. Skłodowskiej-Curie 10, 35-036 Rzeszów, Poland, Tax ID (NIP): 7322153291, REGON: 101642097 (“Controller” or “MEHENKER”).
  2. For privacy matters contact: biuro@mehenker.com; telephone +48 732 760 770; or MEHENKER, ul. Skłodowskiej-Curie 10, 35-036 Rzeszów, Poland.
  3. No data protection officer has been appointed. Please use the contact details above for all privacy matters.

II. Scope

II. Scope

  1. This Policy covers processing connected with https://mehenker.com/, including browsing, Accounts, Orders, payments, deliveries, enquiries, withdrawals, complaints and warranties.
  2. Providing data is voluntary, but required fields are necessary for the requested activity. Failure to provide them may prevent us from creating an Account, answering an enquiry or fulfilling an Order.
  3. MEHENKER does not currently operate a newsletter. If this changes, the Policy will be updated and marketing messages will only be sent on an appropriate legal basis.

III. Data we process

III. Data we process

  1. Depending on how the website is used, we may process: identification and invoice data; contact and delivery details; Account identifiers, encrypted password, preferences and Order history; contract, Product, payment, delivery, correspondence, return, complaint and warranty data; payment status and identifiers and, where needed, a bank account for refunds; technical data such as IP address, online and cookie identifiers, visit time, device, browser, operating system, approximate location, referral source and usage; and content, documents or images voluntarily supplied.
  2. MEHENKER does not receive full payment-card details.
  3. Please do not provide unnecessary data, particularly special categories of personal data.

IV. Purposes, legal bases and retention

IV. Purposes, legal bases and retention

Purpose Legal basis Retention
Creating and operating an Account Performance of the electronic-services contract – GDPR Art. 6(1)(b) Until Account deletion, then for the period required for claims.
Order, contract, payment, delivery and related contact Contract and pre-contractual steps – Art. 6(1)(b) During performance and until applicable limitation periods expire.
Invoices, tax and accounting records Legal obligation – Art. 6(1)(c) For the statutory period, generally five years calculated under applicable law.
Returns, complaints, warranties and after-sales service Art. 6(1)(b), (c) and legitimate interests under (f) During handling and until relevant limitation periods expire.
Answering enquiries unrelated to an existing contract Pre-contractual steps under Art. 6(1)(b) or legitimate interest in communication under (f) Until correspondence ends and then as needed to evidence it or defend claims.
Security, fault diagnosis and fraud prevention Legitimate interests – Art. 6(1)(f) As needed to investigate and secure an incident; routine logs according to system settings and security needs.
Establishing, pursuing or defending claims Legitimate interests – Art. 6(1)(f) Until limitation expires or proceedings end finally.
Website analytics using optional cookies Consent – Art. 6(1)(a) and device-storage rules Until consent is withdrawn or identifiers expire; aggregated reports may be retained longer.
Google Ads conversion measurement, remarketing and ad personalisation Consent – Art. 6(1)(a) Until withdrawal or expiry of relevant cookies and identifiers.

Consent may be withdrawn at any time without affecting earlier lawful processing. Data is deleted or anonymised after these periods unless law requires further retention.

V. Recipients

V. Recipients

  1. Data may be provided, as necessary, to hosting, email, IT, security and backup providers; sales and Order systems including PrestaShop and BaseLinker; Comarch ERP Optima and accounting, tax or legal providers; payment operators including Stripe and Przelewy24; carriers including DPD, InPost and FedEx; Google in connection with Google Ads, Google Analytics and Google Tag Manager subject to enabled services and consent; providers of embedded social-media content where activated with consent; and banks, insurers, authorities or other legally authorised recipients.
  2. We do not sell personal data. Processors act under contract and our instructions unless they determine their own purposes and means as separate controllers.

VI. Transfers outside the EEA

VI. Transfers outside the EEA

  1. Some providers, particularly Google, Stripe or their subprocessors, may process data outside the European Economic Area, especially in the United States.
  2. Transfers are made under GDPR Chapter V, particularly an adequacy decision including the EU–US Data Privacy Framework where applicable, or Standard Contractual Clauses with supplementary safeguards where required.
  3. Information about the transfer basis or a copy of relevant safeguards may be requested from the Controller.

VII. Your rights

VII. Your rights

  1. Subject to GDPR conditions, you may request access and a copy, rectification, erasure, restriction, portability of automatically processed data based on consent or contract, object to processing based on legitimate interests, object at any time to direct marketing and related profiling, and withdraw consent.
  2. Contact the Controller to exercise a right. We may request information necessary to confirm identity.
  3. We respond without undue delay, normally within one month. Where permitted, this may be extended by two months and we will explain why.
  4. You may complain to the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, https://uodo.gov.pl/en, or the competent EU supervisory authority.

VIII. Automated decisions and profiling

VIII. Automated decisions and profiling

  1. MEHENKER does not make decisions based solely on automated processing that produce legal or similarly significant effects for Customers.
  2. With consent, Google may use activity data for conversion measurement, audience creation, remarketing and ad personalisation. This may constitute profiling, but does not itself decide whether MEHENKER enters into a contract or its terms.
  3. Analytics and advertising consent can be changed or withdrawn through the website's cookie settings.

IX. Cookies and similar technologies

IX. Cookies and similar technologies

  1. Cookies are small files or information stored on or read from a device. Similar functions may be performed by identifiers, pixels, local storage and other technologies.
Category Purpose Basis
Strictly necessary Basket, login, session, security, language, country or currency selection and recording cookie choices. Necessary for the requested service; no consent where permitted by law.
Analytics Measuring use and performance, particularly through Google Analytics. Activated after consent.
Advertising Google Ads conversions, remarketing, frequency control and interest-based ads. Activated after consent.
External content Embedded videos, maps or social-media elements that may use third-party technologies. Activated after consent unless storage or access is strictly necessary.
  1. On the first visit, users can accept all optional technologies, reject them or choose categories. Refusing analytics or advertising cookies must not prevent basic Store use.
  2. Consent can later be changed or withdrawn as easily as it was given through cookie settings. Cookies may also be deleted in the browser.
  3. Blocking necessary cookies in the browser may impair the basket, login, payment and other core functions.
  4. Duration depends on function and provider settings. Session cookies expire after a session; persistent cookies remain until expiry, deletion or consent withdrawal deactivates them where technically possible.
  5. Further information about Google technologies and advertising controls is available in Google's policies and Google Account ad settings.

X. Security

X. Security

  1. The Controller applies technical and organisational measures appropriate to risk, including access controls, transmission security, backups, updates and incident procedures.
  2. No transmission or storage method is completely secure. Users should protect passwords, keep software current and report suspected Account compromise.

XI. Sources of data

XI. Sources of data

  1. We generally obtain data directly from the person concerned.
  2. We may also receive data from a payment provider, carrier, BaseLinker, ERP system, sales platform or a person ordering for another recipient, as necessary for payment, fulfilment, delivery, return or complaint.

XII. Changes

XII. Changes

  1. This Policy may change following changes to law, website functions, providers or processing.
  2. A new version will be published here with its number and effective date. Where fresh consent is required, the user will be asked for it.