Privacy policy
PRIVACY POLICY OF WWW.VERYYOU.PL & WWW.VERYYOU.EU
§1 Administration of Personal Data
-
The personal data controller of the Users of the Websites at www.veryyou.pl and www.veryyou.eu is VERY YOU SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office in NOWOGARD, WOJCIESZYN 32, entered into the register of entrepreneurs of the National Court Register kept by the District Court SZCZECIN-CENTRUM in Szczecin, 13th Commercial Division of the National Court Register under KRS number 0001141560, NIP (VAT ID): 8561938185, REGON: 540306962, share capital in the amount of PLN 48,000.00 (hereinafter referred to as the "Controller").
-
Contact with the Controller regarding matters related to personal data processing is possible electronically at the e-mail address:
contact@veryyou.eu, in writing to the Controller's registered office address, or by phone at+48 880 589 060. -
This Policy sets out the rules for the processing of personal data by the Controller on the Website, including the legal basis, purposes, and scope of personal data processing, as well as the rights of data subjects.
-
Personal data is processed by the Controller in accordance with applicable legal provisions, in particular with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – hereinafter referred to as "GDPR").
§2 Definitions
-
Controller – the entity indicated in §1 sec. 1 of this Policy, which alone or jointly with others determines the purposes and means of the processing of personal data.
-
Personal Data – information about an identified or identifiable natural person through one or more specific factors determining physical, physiological, genetic, mental, economic, cultural, or social identity, including device IP, internet identifier, and information collected via cookies and other similar technologies.
-
Policy – this Privacy Policy.
-
Cookies Policy – a document specifying the rules for using cookies on the Website, available at: https://www.veryyou.pl/pages/polityka-cookies.
-
Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning the User's personal preferences and interests.
-
Website – the internet service operated by the Controller at www.veryyou.pl and www.veryyou.eu.
-
User – any natural person visiting the Website or using one or more services or functionalities described on the Website.
§3 Data Processing Principles
The Controller ensures that the data collected by them is:
-
Processed lawfully, fairly, and in a transparent manner in relation to the data subject ("lawfulness, fairness, and transparency").
-
Collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes ("purpose limitation").
-
Adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed ("data minimization").
-
Accurate and, where necessary, kept up to date ("accuracy").
-
Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed ("storage limitation").
-
Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures ("integrity and confidentiality").
§4 Purposes and Legal Bases of Data Processing
1. Based on Art. 6(1)(a) GDPR (User's consent):
-
Sending the Newsletter (ordered commercial information electronically).
-
Publishing User's reviews about Products or the Website.
-
Saving and accessing data in marketing, analytical, and functional cookies (in accordance with the Cookies Policy).
-
Retargeting and behavioral advertising, including displaying personalized ads based on activity on the Website.
-
Participation in contests, loyalty programs, and surveys/market research, provided that participation requires separate consent.
2. Based on Art. 6(1)(b) GDPR (Necessity for the performance of a contract or to take steps prior to entering into a contract):
-
Registration, operation, and maintenance of the User Account on the Website.
-
Performance of a Goods sales contract or a contract for the provision of Electronic Services (including the shipping process, payment execution).
-
Handling requests related to withdrawal from a distance contract.
-
Contacting the User regarding the processing of a placed order.
3. Based on Art. 6(1)(c) GDPR (Legal obligation incumbent on the Controller):
-
Issuing and storing invoices and accounting documents, as well as fulfilling other obligations resulting from tax and accounting regulations.
-
Fulfilling obligations arising from warranty regulations and non-conformity of goods with the contract (handling complaints).
-
Fulfilling orders and obligations under the Digital Services Act (DSA) and cooperating with authorized state authorities.
4. Based on Art. 6(1)(f) GDPR (Legitimate interests pursued by the Controller):
-
Establishing, exercising, or defending legal claims that may arise in connection with the use of the Website or the purchase of Goods.
-
Ongoing contact with the User (including handling inquiries via the contact form or e-mail not directly related to the execution of an active contract).
-
Conducting statistics, analyzing traffic, and User behavior to optimize the Website's operation.
-
Ensuring the security of the Website, preventing fraud and abuse.
-
Conducting direct marketing of the Controller's own products and services.
-
Managing the Controller's official social media profiles (Facebook, Instagram, TikTok, LinkedIn, YouTube) and interacting with their users.
§5 Profiling and Automated Decision-Making
-
The Controller uses profiling for marketing purposes, which involves analyzing the User's activity on the Website (e.g., viewed products, products added to the cart) using cookies and similar technologies.
-
This profiling serves to better tailor the displayed advertising content and offers on the Website and on external platforms (e.g., Google Ads, Meta Ads).
-
Profiling for marketing and analytical purposes takes place solely on the basis of the User's voluntary consent expressed via the cookie banner.
-
The User may withdraw consent to profiling at any time by changing the cookie settings in their browser or by contacting the Controller.
-
Despite using profiling, the Controller does not make decisions based solely on automated processing concerning the Users that would produce legal effects concerning them or similarly significantly affect them.
§6 Personal Data Storage Period
Personal data is stored for the period necessary to fulfill the purposes specified in §4, and in particular:
-
Data related to the execution of the contract and the User Account – for the duration of the contract/Account ownership, and after its termination until the expiry of the statute of limitations for potential civil law claims (generally 6 years, and 3 years for claims related to business activity).
-
Accounting and tax data – for the period required by tax law, i.e., for 5 years, starting from the end of the calendar year in which the tax payment deadline related to a given transaction expired.
-
Data processed on the basis of consent (e.g., Newsletter, marketing cookies) – until the User withdraws consent or the Controller ceases to conduct specific marketing activities.
-
Data related to ongoing contact and inquiries – for the period necessary to clarify the matter, but no longer than 12 months from the end of correspondence, unless further storage is justified by defense against claims.
§7 User's Rights
-
Every User has the right to:
-
access their personal data and receive a copy of it;
-
rectify (correct) their data;
-
erase data ("right to be forgotten") – in situations specified in Art. 17 GDPR;
-
restrict data processing;
-
transfer data to another controller (if processing is based on a contract or consent and is carried out by automated means);
-
object to processing – for reasons relating to the User's particular situation (when the basis is a legitimate interest) or at any time against direct marketing;
-
withdraw consent at any time (if processing is based on consent), whereby the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
-
-
In order to exercise their rights, the User may contact the Controller at the e-mail address:
contact@veryyou.plor in writing to the registered office address. -
The Controller provides information on action taken without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests, about which the Controller shall inform the User.
-
The User also has the right to lodge a complaint with a supervisory authority – the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, Stawki 2, 00-193 Warsaw, Poland), if they consider that the processing of their data infringes the provisions of the GDPR.
§8 Data Recipients and Transfers Outside the EEA
-
Users' personal data may be transferred to external entities cooperating with the Controller to ensure the proper functioning of the Website and order fulfillment. The recipients include in particular: hosting service providers, courier and logistics companies, online payment operators, accounting offices, providers of marketing and mailing tools, CRM/ERP system providers, and dropshipping partners.
-
Due to the Controller's use of modern tools provided by entities such as Google LLC, Meta Platforms Ireland Ltd., TikTok Technology Limited, Users' personal data (in particular IP numbers or identifiers from cookies) may be transferred outside the European Economic Area (EEA), including to the United States.
-
The Controller ensures that data transfers to third countries are carried out with appropriate legal safeguards required by the GDPR, in particular on the basis of European Commission decisions finding an adequate level of protection (e.g., Data Privacy Framework) or using Standard Contractual Clauses approved by the European Commission.
§9 Personal Data Security
-
The Controller conducts ongoing risk analysis to ensure that personal data is processed securely.
-
The Controller applies advanced technical and organizational measures to prevent unauthorized access, modification, or loss of data. The connection to the Website is fully encrypted using the SSL/TLS protocol.
-
Access to personal data is granted only to authorized employees and associates of the Controller and only to the extent necessary to perform their duties.
-
Entities processing data on behalf of the Controller (so-called processors) are obliged under data processing agreements to apply adequate data protection measures analogous to the Controller's standards.
§10 Final Provisions
-
The Privacy Policy is regularly reviewed and updated as necessary, including in the event of changes in the functioning of the Website or changes in generally applicable legal provisions.
-
The current version of the Privacy Policy enters into force on 2026-06-23.
