Privacy Policy

1. Data Controller

The data controller is deFox. For matters concerning personal data protection, please contact: marcin@defox.pl

2. Purpose of Data Processing

Personal data is processed for:

  • Order fulfillment and service provision
  • User account management
  • Sending subscription expiration notifications
  • Handling inquiries and complaints
  • Fulfilling legal obligations (e.g., accounting)

3. Legal Basis

The legal basis for data processing is:

  • Contract performance (Art. 6(1)(b) GDPR)
  • Legitimate interest of the controller (Art. 6(1)(f) GDPR)
  • Legal obligation (Art. 6(1)(c) GDPR)

4. Data Recipients

Data may be shared with:

  • Payment operators (PayU, Stripe)
  • Hosting service providers
  • Public authorities, if required by law

5. Retention Period

Data is stored for:

  • Account data - until account deletion
  • Transaction data - as required by law (5 years)
  • Contact form data - up to 2 years from last contact

6. User Rights

Users have the right to:

  • Access their data
  • Rectify data
  • Erase data ("right to be forgotten")
  • Restrict processing
  • Data portability
  • Object to processing
  • Lodge a complaint with a supervisory authority

7. Cookies

The website uses cookies for:

  • Maintaining user sessions
  • Remembering language preferences
  • Shopping cart functionality

Users can manage cookies through browser settings.

8. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or destruction.

9. Contact

For data protection matters: marcin@defox.pl