Privacy & Security

SATIS Privacy Policy

This Privacy Policy explains what personal data we process in connection with the use of our online store, purchases, enquiries, complaints, the Newsletter and cookies, as well as the rights available to individuals whose personal data is processed.

Effective from 5 August 2026
Data Controller

SATIS INTERNATIONAL S.C.

ul. Przeskok 53
63-400 Ostrów Wielkopolski
Poland

Company details NIP (Tax ID): 6222754286 REGON: 301625431
01
Responsible entity

Data Controller and contact details

  1. The controller of personal data of users of the online store is SATIS INTERNATIONAL S.C., ul. Przeskok 53, 63-400 Ostrów Wielkopolski, Poland, NIP 6222754286, REGON 301625431.
  2. For matters concerning privacy, personal data processing or the exercise of your rights, you may contact us by e-mail at biuro@satispolska.pl, by telephone at +48 62 592 42 77, or in writing at the Controller's postal address.
  3. This Privacy Policy applies to personal data processed in connection with the use of the online store, placing and fulfilling orders, maintaining a Customer Account, enquiries, complaints, returns, the Newsletter, website security, cookies and similar technologies.
02
Types of information

Personal data we collect

  1. Depending on how you use our online store, we may process in particular: your name and surname, company name, tax identification number, billing and delivery address, e-mail address, telephone number, Customer Account information, order history, payment and delivery details, correspondence and information provided in connection with a complaint or return.
  2. If you represent a business customer, we may process your identification details, business contact information, job title or function and information necessary to manage our business relationship.
  3. When you use our website, certain technical information may be recorded automatically, including your IP address, device and browser type, operating system, cookie identifiers, date and time of your visit, pages visited, referral source and information relating to technical and security events.
  4. We do not require special categories of personal data, such as information concerning health, racial or ethnic origin, political opinions, religious beliefs or similar sensitive information. Please do not provide such data unless it is necessary for handling a specific matter.
  5. Providing personal data is voluntary; however, certain information is necessary to enter into and perform a contract, issue accounting documents, arrange delivery, maintain a Customer Account, process a complaint or respond to your enquiry.
03
Why we process your data

Purposes and legal bases

Purpose Legal basis
Processing orders and performing contracts

Article 6(1)(b) GDPR, including taking steps at the customer's request prior to entering into a contract.

Invoices, accounting and tax obligations

Article 6(1)(c) GDPR, i.e. compliance with a legal obligation applicable to the Controller.

Customer Account and online store functionality

Article 6(1)(b) GDPR, i.e. performance of a contract for the provision of electronic services.

Enquiries, quotations and after-sales service

Article 6(1)(b) GDPR where communication concerns entering into or performing a contract, or Article 6(1)(f) GDPR, i.e. our legitimate interest in communicating with customers and handling enquiries.

Complaints, returns, warranties and claims

Article 6(1)(b) and (c) GDPR and Article 6(1)(f) GDPR, including establishing, pursuing or defending legal claims.

Newsletter and electronic marketing

Article 6(1)(a) GDPR, i.e. consent, as well as any consent required under applicable electronic communications legislation.

Store security, logs and fraud prevention

Article 6(1)(f) GDPR, i.e. our legitimate interest in protecting the website, users, transactions and records of relevant events.

Analytics and non-essential cookies

Article 6(1)(a) GDPR where consent is required and provided through the cookie consent panel.

04
Purchases and electronic services

Orders and Customer Account

  1. Personal data provided during the purchase process is used to prepare and fulfil the order, communicate with you regarding the purchase, process payment, issue documents, arrange delivery, provide after-sales support and comply with applicable legal obligations.
  2. Customer Account data is processed for as long as the Account remains active. Customers may be able to purchase without registration where this option is available in the store.
  3. After deletion of the Customer Account, we may continue to retain information relating to completed transactions, accounting documents, complaints and claims where required by law or justified by the Controller's legitimate interests.
  4. Where an order is placed on behalf of a company, the contact person's information may be provided directly by that person, their employer or colleague, or obtained from public business registers and sources related to business activity.
05
Correspondence and support

Contact, complaints and returns

  1. Personal data provided by e-mail, telephone, contact form or other communication channels is used to respond to your enquiry, prepare an offer, handle your request or take steps prior to entering into a contract.
  2. When handling a complaint, return, warranty claim or service request, we may process contact details, purchase information, a description of the issue, photographs, serial numbers, technical information and correspondence relating to the matter.
  3. Correspondence may also be retained after the matter has been closed where necessary to document its handling, protect the Controller's rights or comply with legal obligations.
06
Commercial communications

Newsletter and marketing

  1. The Newsletter is sent only to persons who have provided their e-mail address and given the appropriate consent. Subscription may require confirmation of the e-mail address.
  2. You may withdraw your consent at any time by using the unsubscribe link included in the message or by contacting the Controller. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  3. We may retain information concerning the granting and withdrawal of consent where necessary to demonstrate compliance and protect against legal claims.
  4. Behaviour-based marketing and marketing involving non-essential technologies is carried out only after obtaining consent where such consent is required.
07
Transaction fulfilment

Payments and delivery

  1. For the purpose of processing payments, information necessary to complete the transaction may be transferred to the payment provider selected by the customer. The payment provider may act as an independent data controller in accordance with its own privacy policy.
  2. For payments processed via Przelewy24, personal data is transferred to the extent necessary to initiate, authorise and settle the payment.
  3. For delivery purposes, the recipient's name, address, telephone number, e-mail address and shipment information may be provided to the courier, carrier, freight forwarder or logistics provider.
  4. The scope of transferred personal data is limited to the information necessary to provide the selected service, handle transport-related complaints and settle the transaction.
08
Service providers and partners

Recipients of personal data

  1. Personal data may be disclosed to service providers supporting the Controller with hosting, IT services, PrestaShop maintenance, e-mail services, cybersecurity, backups and technical support.
  2. Recipients may also include payment operators, banks, courier companies, carriers, freight forwarders, logistics providers, accounting system providers, accounting firms, legal advisers, insurers and providers involved in complaints and service support.
  3. Where the appropriate consent has been given, recipients may also include providers of analytics, advertising, marketing tools, Newsletter services and social media platforms.
  4. Personal data may be disclosed to public authorities, courts or other authorised entities where required by applicable law.
  5. The Controller does not sell personal data.
09
Data retention

How long we keep your data

  1. Personal data relating to a contract is retained for the duration of the contract and afterwards for periods required under accounting and tax legislation and until the expiry of applicable limitation periods for potential claims.
  2. Customer Account data is processed until the Account is deleted and afterwards to the extent necessary to comply with legal obligations, complete settlements and protect against claims.
  3. Data relating to complaints, warranties, returns and servicing is retained for the period necessary to handle the matter and until the expiry of relevant liability and claim periods.
  4. Data processed on the basis of consent is retained until consent is withdrawn, the purpose becomes obsolete or the data is deleted earlier, unless information concerning the consent must be retained for evidential purposes.
  5. Data processed on the basis of legitimate interests is retained until the relevant purpose ceases to apply, an effective objection is made or an overriding obligation to delete the data arises, taking into account periods necessary to protect against claims.
  6. Security logs may be retained for a period appropriate for detecting incidents, ensuring business continuity and pursuing or defending claims.
10
Control over your personal data

Your data protection rights

Right of access

You may request information about the processing of your personal data and obtain a copy of it.

Right to rectification

You may request correction of inaccurate personal data or completion of incomplete data.

Right to erasure

You may request deletion of your personal data in the circumstances provided for under the GDPR.

Right to restriction

You may request temporary restriction of the way your personal data is processed.

Right to data portability

You may receive your personal data and transmit it to another controller where the conditions set out in the GDPR are met.

Right to object

You may object to processing based on legitimate interests.

Withdrawal of consent

You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Right to lodge a complaint

You may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO) or, where applicable, with the competent supervisory authority in your country.

How can you exercise your rights?

Please contact us at biuro@satispolska.pl. We may request additional information necessary to verify your identity and ensure that personal data is not disclosed to an unauthorised person.

11
Online technologies

Cookies and similar technologies

  1. Cookies are small files stored on the user's device. They may contain information necessary for the website to function, preferences, session identifiers and information about how the website is used.
  2. Essential cookies are used for the proper functioning of the online store, shopping cart, login process, security features, privacy settings and order fulfilment. Their use does not require consent to the extent permitted by applicable law.
  3. Functional, analytical, advertising and social media cookies are activated only after the appropriate consent has been provided where such consent is required.
  4. Users may accept all categories, reject non-essential technologies or select individual categories in the cookie settings panel.
  5. Consent may be changed or withdrawn at any time using the cookie settings panel. Withdrawal of consent does not affect the lawfulness of any previous use of the relevant technologies.
  6. Your browser also allows you to delete and block cookies. Blocking essential cookies may prevent the shopping cart, login functionality or other parts of the online store from working correctly.
  7. A detailed list of active cookies, their providers, purposes and retention periods should be available in the consent management panel accessible on the website.
Essential

Online store functionality, sessions, shopping cart, security and storing privacy preferences.

Functional

Additional settings and features that improve the use of the website.

Analytics

Statistics, traffic measurement and website improvement after obtaining consent where required.

Marketing

Campaign measurement and advertising personalisation after obtaining the appropriate consent.

12
International processing

Transfers outside the European Economic Area

  1. Some technology, analytics, marketing, e-mail or infrastructure providers may process personal data outside the European Economic Area (EEA).
  2. Where this occurs, personal data is transferred only using a mechanism permitted under the GDPR, in particular an adequacy decision or Standard Contractual Clauses, together with additional safeguards where necessary.
  3. Information about specific providers activated on the basis of consent should be available in the cookie settings panel or in the privacy policies of those providers.
13
Automation

Profiling and automated decision-making

  1. If a user consents to analytics or marketing, information about their activity may be used to create audience groups, measure campaign effectiveness and tailor displayed content or advertising.
  2. Marketing profiling based on consent does not produce legal effects concerning the user or similarly significantly affect them.
  3. The Controller does not make decisions concerning customers based solely on automated processing where such decisions would produce legal effects or similarly significantly affect the individual, unless information about such processing is provided separately.
14
Information protection

Data security

  1. The Controller implements appropriate technical and organisational measures taking into account the nature, scope and risks associated with the processing of personal data.
  2. Protection measures may include, in particular, encrypted transmission, access controls, backups, software updates, system protection, event logging, access authorisation procedures and confidentiality obligations applicable to persons processing personal data.
  3. No method of transmitting or storing information can guarantee complete elimination of risk. In the event of a personal data breach, we follow the procedures required under the GDPR.
  4. Users should protect their Customer Account passwords, use up-to-date software and never disclose login credentials to third parties.
15
Policy updates

Changes to this Privacy Policy

  1. This Privacy Policy may be updated where there are changes to applicable law, online store functionality, technologies used, processing activities, recipients of personal data or the Controller's details.
  2. The current version of the Privacy Policy is published on the online store website together with its effective date.
  3. If a change materially affects the processing of personal data relating to persons who maintain a Customer Account or use ongoing services, information about the change may also be provided by e-mail or through the Customer Account.