Privacy Policy
1. Who We Are
This Privacy Policy explains how Esthe Depot collects, uses, shares and protects personal data when you visit esthedepot.eu, create an account, place an order, contact us, request product training or technical support, subscribe to marketing communications, or otherwise interact with us.
For the purposes of Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and other applicable European data protection laws, the data controller is:
Legal entity: ESTHE DEPOT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Trading name: Esthe Depot
Registered address: ul. Franciszka Klimczaka 5, lok. 95, 02-797 Warszawa, Poland
Email: info@esthedepot.eu
Phone: +48 732 108 367
2. Personal Data We Collect
Depending on how you use our website and services, we may collect the following categories of personal data.
Identity and contact data
Your name, business name, billing address, delivery address, email address, telephone number, account details and other contact information you provide.
Order and transaction data
Information relating to your purchases, including products ordered, order value, currency, payment status, invoices, tax or VAT information, delivery details, returns, refunds, warranty or service claims and previous transactions.
Payment data
Payment information is generally processed directly by our payment service providers. Esthe Depot does not ordinarily receive or store your complete payment-card number. We may receive limited information such as the payment method, payment confirmation, card type, last digits of a card, transaction identifier, payment status and fraud-screening result.
Account data
Information associated with your customer account, including login details, saved addresses, preferences and account activity.
Technical and usage data
IP address, browser type, device and operating-system information, time zone, cookie or similar identifiers, pages viewed, referral source, interactions with the website, and diagnostic, security and fraud-prevention data.
Communications and support data
Emails, contact-form submissions, chat messages, product enquiries, training bookings, technical-support requests, equipment serial numbers, photographs, videos and other information you choose to provide.
Marketing data
Your marketing preferences, newsletter subscriptions, consent records and interactions with marketing communications.
3. How We Collect Personal Data
We may collect personal data:
- directly from you when you place an order, create an account, contact us, request support or training, or submit a form;
- automatically through cookies, server logs, pixels and similar technologies;
- from payment processors, fraud-prevention providers, delivery carriers, warehouses and fulfilment providers;
- from manufacturers, service providers or business partners where necessary and lawful; and
- from publicly available business sources where permitted by law.
Where personal data are obtained from a source other than you, we will provide any additional information required by Article 14 GDPR within the applicable legal time limits, unless an exemption applies.
4. Why We Process Personal Data and Our Legal Bases
We process personal data only where a lawful basis applies. The basis used depends on the purpose and the circumstances.
|
Purpose |
Typical legal basis |
|
Creating and administering a customer account |
Art. 6(1)(b) GDPR where necessary for a requested service or contract; otherwise Art. 6(1)(f) GDPR where appropriate |
|
Processing orders, payments, delivery, returns and refunds |
Art. 6(1)(b) GDPR - performance of a contract or steps requested before entering into a contract |
|
Providing product guidance, training, warranty or service assistance and technical support |
Art. 6(1)(b) GDPR and, where appropriate, Art. 6(1)(f) GDPR |
|
Issuing invoices and maintaining tax, accounting or legally required records |
Art. 6(1)(c) GDPR - compliance with a legal obligation |
|
Preventing fraud, misuse, chargebacks, security incidents and protecting our systems and legal rights |
Art. 6(1)(f) GDPR; Art. 6(1)(c) GDPR where a legal obligation applies |
|
Operating and improving the website, service quality and business processes |
Art. 6(1)(f) GDPR for necessary operational improvements; consent under Art. 6(1)(a) GDPR where required for non-essential cookies or tracking |
|
Sending electronic marketing communications |
Art. 6(1)(a) GDPR and prior consent where required by applicable electronic communications law; another specific legal permission only where applicable |
|
Personalised advertising and non-essential analytics |
Art. 6(1)(a) GDPR - consent where required |
|
Establishing, exercising or defending legal claims |
Art. 6(1)(f) GDPR |
|
Responding to courts, regulators, law-enforcement bodies or other lawful authority requests |
Art. 6(1)(c) GDPR or another applicable legal basis |
Where we rely on legitimate interests, our interests may include operating and securing our business, preventing fraud, improving customer service, maintaining business records and protecting or enforcing our legal rights. We assess those interests against your rights, freedoms and reasonable expectations.
5. When Providing Personal Data Is Required
Certain personal data are necessary to enter into or perform a contract with you, comply with legal requirements, process payment, arrange delivery or provide requested support. For example, we normally need your name, contact details, billing and delivery information and relevant transaction information to process an order.
If required information is not provided, we may be unable to create or administer an account, accept or fulfil an order, process a payment or refund, arrange delivery, or provide requested support. Information requested for optional marketing or non-essential cookies is voluntary.
6. Cookies and Similar Technologies
We use cookies and similar technologies to operate and secure the website. Cookies that are strictly necessary for a service you request, such as maintaining the shopping basket, account session, security or checkout, may be used without consent where permitted by law.
Where consent is required, non-essential cookies or similar technologies - including analytics, advertising, marketing and personalisation technologies - are activated only after you give consent.
You can accept, reject or manage non-essential cookies through our cookie banner or cookie-preferences tool. You can change or withdraw your consent at any time through the cookie-preferences link, and withdrawing consent will not affect the lawfulness of processing that took place before withdrawal.
The cookie-preferences panel should identify the active cookie categories and relevant providers. Blocking or withdrawing consent to some technologies may affect optional website features but should not prevent access to services that do not require them.
7. Marketing Communications
We send electronic direct marketing only where we have the consent required by applicable law, or where another specific legal permission applies. You can withdraw marketing consent or unsubscribe at any time using the unsubscribe method provided in the message or by contacting info@esthedepot.eu.
We will not require consent to marketing as a condition of purchasing a product where that consent is not necessary for the transaction.
8. How We Share Personal Data
We may share personal data only where reasonably necessary with categories of recipients such as:
- Shopify and providers involved in hosting, operating and securing our online store;
- payment processors, financial institutions and fraud-prevention providers;
- delivery carriers, freight companies, warehouses and fulfilment providers;
- manufacturers, suppliers and technical partners where necessary to fulfil an order or provide support;
- email, communications, customer-service, training-booking and technical-support providers;
- IT, hosting, cybersecurity, analytics and advertising providers, subject to consent where required;
- accountants, auditors, insurers, lawyers and other professional advisers;
- public authorities, courts or regulators where disclosure is required or permitted by law; and
- a buyer, investor or successor in connection with a lawful corporate transaction.
We seek to limit the personal data shared to what is necessary for the relevant purpose. Service providers that act as processors are required to process personal data only on documented instructions and subject to appropriate contractual and security obligations.
We do not sell customer personal data.
9. Shopify and Payment Providers
Our online store is hosted using Shopify. Shopify processes personal data necessary to provide, operate and secure the online-store, customer-account and checkout services. Depending on the processing activity, Shopify may act as our processor or may process certain information under its own responsibilities.
When you select a payment method, the relevant payment provider may process information needed to complete the transaction, prevent fraud and comply with financial or regulatory requirements. Payment providers may act as processors or independent controllers depending on the service.
Shopify and individual payment providers maintain their own privacy information describing their processing activities.
10. International Data Transfers
Some service providers, manufacturers, fulfilment partners or technical-support providers may process personal data outside Poland or the European Economic Area (“EEA”).
Where a transfer of personal data to a country outside the EEA is subject to Chapter V GDPR, we use or rely on an appropriate transfer mechanism, such as an adequacy decision of the European Commission, Standard Contractual Clauses approved by the European Commission, or another legally recognised safeguard. Where appropriate, supplementary measures may also be used.
You may contact info@esthedepot.eu for information about the safeguards relevant to a particular transfer and, where applicable, how to obtain a copy of those safeguards.
11. How Long We Keep Personal Data
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and to comply with applicable legal, tax, accounting and regulatory obligations. Retention periods vary depending on the type of information and the relevant legal requirements.
- Order, invoice, accounting and tax information is retained for the period required under applicable Polish and EU law.
- Customer account information may be retained while the account remains active and for a reasonable period afterwards.
- Warranty, service, technical-support and training records may be retained for the service relationship and relevant claim or limitation periods.
- Customer correspondence may be retained for as long as necessary to resolve enquiries, complaints, disputes or legal claims.
- Marketing consent and preference records may be retained while marketing continues and for a reasonable period afterwards to demonstrate compliance or honour an objection.
- Security and technical logs are retained for a limited period appropriate to system security, fraud prevention and incident investigation.
Personal data may be retained for longer where necessary to establish, exercise or defend legal claims, comply with a legal obligation, or preserve evidence relating to a dispute.
12. Your Data Protection Rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- receive clear information about how your personal data are processed;
- request access to your personal data and receive a copy;
- request correction of inaccurate or incomplete personal data;
- request erasure of personal data where the legal conditions are met;
- request restriction of processing;
- receive certain personal data in a portable format where the right to data portability applies;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal; and
- lodge a complaint with a competent data-protection supervisory authority.
To exercise a right, contact info@esthedepot.eu. We may request information reasonably necessary to verify your identity and protect your data.
We normally respond without undue delay and within one month of receiving a valid request. Where permitted by GDPR, that period may be extended by up to two additional months where necessary because of complexity or the number of requests; if so, we will inform you within the first month.
If you object to direct marketing, we will stop using your personal data for that purpose.
13. Automated Decision-Making and Profiling
We may use automated tools to identify possible fraud, payment risk or security threats. We do not intend to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects on you, unless a lawful basis and the safeguards required by Article 22 GDPR apply.
If we introduce such decision-making in the future, we will provide the additional information required by law about the logic involved, its significance and the envisaged consequences.
14. Data Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are reviewed in light of the nature of the processing, available technology and the risks involved.
No internet transmission or storage system can be guaranteed completely secure. Customers are responsible for keeping account credentials confidential and should contact us promptly if they suspect unauthorised account activity.
15. Special-Category Data and Client Information
Our store and ordinary support channels are not intended for the collection of medical records or other special-category personal data about your clients. Please do not send client medical records, identifiable treatment histories, sensitive health information or other unnecessary special-category data through ordinary email, chat or website forms.
When requesting technical support, please remove or obscure information that identifies your own clients wherever possible. If special-category data are provided unexpectedly, we will handle them only to the extent lawful and reasonably necessary, which may include deleting or returning unnecessary information.
16. Children
Our website, products and services are intended for adults and professional users. We do not knowingly collect personal data directly from children. If we become aware that personal data relating to a child have been collected inappropriately, we will take reasonable steps to address the situation.
17. Third-Party Links
Our website may contain links to websites, platforms or services operated by third parties. We do not control their privacy practices. We recommend reviewing the privacy information of an external service before providing personal data to it.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, service providers, processing activities or legal obligations. The latest version will be published on this page with an updated revision date. Where required by law, we will provide additional notice of material changes.
19. Contact and Complaints
For privacy questions, data-protection requests or complaints, contact:
Controller: ESTHE DEPOT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Trading name: Esthe Depot
Registered address: ul. Franciszka Klimczaka 5, lok. 95, 02-797 Warszawa, Poland
Email: info@esthedepot.eu
Phone: +48 732 108 367
You also have the right to lodge a complaint with the supervisory authority in the EU/EEA country of your habitual residence, place of work, or place of the alleged infringement.
For a controller established in Poland, the Polish supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland.
