Privacy policy
Effective date: August 11, 2026
§1. General Provisions
1.1. This Privacy Policy sets out the rules for processing and protecting the personal data of Customers and other persons using the online store operating at fondori.com (the "Store"), as well as the rules governing the use of cookies.
1.2. The data controller is:
ADACTUS Sp. z o.o.
Plac Bankowy 2, 00-095 Warsaw, Poland
VAT ID: PL5252829597 · Company registration number (KRS): 0000850984
email address: sales@fondori.com
(the "Controller" or the "Seller")
1.3. For matters related to the processing of personal data, please contact the Controller at sales@fondori.com.
1.4. At its current stage of operations, the Controller has not appointed a Data Protection Officer (DPO) — in the Controller's assessment, the processing of personal data in the Store does not meet the conditions requiring mandatory appointment of a DPO set out in Article 37 GDPR. Any matters relating to the protection of personal data should be directed to the Controller as indicated in point 1.3.
1.5. This Privacy Policy fulfills the information obligation arising from Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
§2. What Data We Process
2.1. In connection with the use of the Store, the Controller may process the following categories of personal data:
a) Data provided when placing an Order
- first and last name or company name;
- delivery address and billing address;
- e-mail address and phone number;
- data necessary to issue a sales document (including the VAT number for business Customers);
- Order information (ordered Products, value, selected delivery and payment method).
Data relating to the payment transaction itself (e.g. payment card number) is not processed or stored by the Controller — it is handled directly by the payment operator referred to in §5.
b) Data provided when creating a Customer Account
e-mail address, password (in encrypted form) and — optionally — data saved for shipping (first name, last name, address). Creating an Account is voluntary — the Store also allows placing an Order without creating an Account, as a "guest checkout."
c) Data submitted in the personalization Creator (Line B)
within the configurator available for Personalized Products, the Customer uploads their own photo or artwork, which is used to produce the print on the Product. These photos may contain personal data in the form of an image — including, given the nature of the themes offered (e.g. christening, birth of a child), often images of children. The Controller does not verify, as a matter of course, whose image appears in the uploaded material — in accordance with the Store's Terms and Conditions (§3.3), the Customer placing the Order declares that they hold the right to use the submitted content, including — where the image is of a person other than themselves — the consent of that person or their legal guardian.
This category of data is treated by the Controller with particular care — see the retention rules in §6 and the recipients of data in §5 (in particular the external technology tool that handles uploading and preview of artwork in the Creator).
d) Data provided via the contact form
name, e-mail address, optionally phone number, message content and — if the Customer chooses to include them — attachments (e.g. photos related to the matter being reported).
e) Data provided when signing up for the Newsletter
e-mail address, provided voluntarily on the basis of a separate consent.
f) Technical data
IP address, device and browser information, information collected automatically via cookies and similar technologies — details in §9.
§3. Purposes and Legal Bases for Processing
3.1. Personal data is processed for the following purposes:
- conclusion and performance of the Sales Agreement, including fulfillment of the Order, delivery of the Product and handling of payment — legal basis: Article 6(1)(b) GDPR (necessity for the performance of a contract or to take steps prior to entering into a contract);
- production of the Personalized Product in accordance with the design submitted by the Customer in the Creator (processing of the submitted artwork/photo) — legal basis: Article 6(1)(b) GDPR, and, to the extent the submitted material contains the image of a person other than the Customer — on the basis of the Customer's declaration that they hold the right to do so (Article 6(1)(b) in conjunction with the Customer's contractual liability set out in the Terms and Conditions);
- creation and maintenance of the Customer Account — legal basis: Article 6(1)(b) GDPR;
- handling of complaints and withdrawals from the contract — legal basis: Article 6(1)(c) GDPR (legal obligation arising from consumer rights law) and Article 6(1)(b) GDPR;
- handling of inquiries submitted via the contact form — legal basis: Article 6(1)(f) GDPR (the Controller's legitimate interest in responding to inquiries);
- maintaining accounting records and fulfilling tax obligations — legal basis: Article 6(1)(c) GDPR in conjunction with accounting and tax legislation;
- establishing, pursuing or defending against claims — legal basis: Article 6(1)(f) GDPR (the Controller's legitimate interest);
- sending the Newsletter — legal basis: Article 6(1)(a) GDPR (consent), which may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal;
- ensuring the security of the Store and its forms (including the reCAPTCHA mechanism described in §5) — legal basis: Article 6(1)(f) GDPR (the Controller's legitimate interest in preventing abuse).
3.2. Providing data is voluntary, but to the extent necessary to conclude and perform the Sales Agreement or to use a selected electronic service — failure to provide it prevents fulfillment of the Order or the given service.
§4. Automated Decision-Making
4.1. The Controller does not make decisions concerning Customers based solely on automated processing of data, including profiling, which would produce legal effects concerning the Customer or similarly significantly affect them.
§5. Recipients of Data — Data Processors
5.1. Personal data may be shared with the following categories of recipients, who process data on the basis of data processing agreements concluded with the Controller (or as independent controllers with respect to their own services, e.g. the payment operator):
- the Shopify e-commerce platform provider — handles hosting of the Store, the order placement process, cart, and Customer account;
- the payment operators available in the Store — Shopify Payments, PayPal and PayU — handle online payments for Orders; the Controller does not have access to the Customer's full payment card details, and each operator processes payment data as an independent controller, under the terms of its own privacy policy;
- an external provider of the technology tool supporting the Product personalization Creator (Line B) — processes the photos/artwork submitted by the Customer for the purpose of design preview and preparation of the production file. Due to the confidential nature of the technology solutions used by the Store (the Seller's trade secret), the name of this provider is not disclosed publicly in this document; the Customer may ask the Controller about it individually. The UV printing itself is carried out entirely in-house by the Seller, without the involvement of an external print shop — the file from the Creator goes directly into production;
- Hulk Contact Form Builder — handles the contact form available on the Contact page, including the receipt of attachments; the form also uses the Google reCAPTCHA mechanism as an anti-bot safeguard;
- the courier company fulfilling delivery of the Order — the scope of data shared is limited to information necessary to deliver the shipment (first and last name, address, phone number);
- Klaviyo — the e-mail marketing service provider, with respect to the Newsletter, only for persons who have given separate consent to this;
- Google (Google Analytics, Google Ads) and Meta (Meta Pixel) — with respect to traffic analytics in the Store and marketing, only for persons who have given consent via the cookie consent banner/panel — see §9;
- providers of accounting and tax services;
- providers of IT services (hosting, e-mail, backups) to the extent necessary to ensure continuity of the Store's operations;
- public authorities, where the obligation to disclose data arises from legal provisions.
5.2. The Controller does not sell Customers' personal data or share it with third parties for marketing purposes without separate consent.
§6. Data Retention Period
6.1. Data related to the performance of the Sales Agreement and handling of the Customer Account is retained for the duration of the agreement, and after its conclusion — for the period necessary to handle any complaints, withdrawals and claims, but no longer than the limitation period for claims under the Polish Civil Code.
6.2. Documents related to sales, which the Controller is required to retain under tax and accounting legislation (e.g. invoices), are retained for the period required by that legislation — as a rule 5 years, counted from the end of the calendar year in which the tax payment deadline related to the given transaction fell.
6.3. Data provided when signing up for the Newsletter is retained until consent is withdrawn.
6.4. Data from the contact form is retained for the time necessary to respond to and handle the inquiry, and thereafter — if the matter requires it — for the period referred to in §6.1.
6.5. Design files (photos/artwork) uploaded by the Customer in the personalization Creator are retained for a period of 30 days from the date the Order is fulfilled (the Product is produced and dispatched), after which they are permanently deleted. If, during this period, the Customer files a complaint or withdraws from the contract, the file is retained for an additional period necessary to conclude that procedure.
6.6. After the periods indicated above have elapsed, data is deleted or anonymized, unless further processing is necessary to fulfill a legal obligation incumbent on the Controller.
§7. Transfer of Data Outside the European Economic Area
7.1. Some of the providers indicated in §5 (in particular the provider of the Shopify platform, the provider of the tool supporting the personalization Creator, Klaviyo, and Google/Meta with respect to analytics and marketing) may process personal data on servers or within infrastructure located outside the European Economic Area (EEA), including in the United States.
7.2. In such cases, the transfer of data takes place on the basis of mechanisms provided for by GDPR that ensure an adequate level of data protection, in particular standard contractual clauses approved by the European Commission or European Commission decisions finding an adequate level of data protection in the given country.
7.3. The Customer may obtain a copy of the relevant safeguards applied to transfers of data outside the EEA by contacting the Controller at sales@fondori.com.
§8. Rights of Data Subjects
8.1. A data subject has the following rights:
- the right of access to their data and to obtain a copy of it (Article 15 GDPR);
- the right to rectification (correction) of their data (Article 16 GDPR);
- the right to erasure of data, in the situations provided for by GDPR (Article 17 GDPR);
- the right to restriction of processing (Article 18 GDPR);
- the right to data portability (Article 20 GDPR), to the extent data is processed on the basis of consent or a contract and in an automated manner;
- the right to object to processing of data based on the Controller's legitimate interest (Article 21 GDPR);
- the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal — to the extent processing is based on consent (e.g. the Newsletter);
- the right to lodge a complaint with a supervisory authority — in Poland this is the President of the Personal Data Protection Office (PUODO), and for Customers from other European Union countries — the competent supervisory authority of their country of residence.
8.2. To exercise the above rights, please contact the Controller at sales@fondori.com.
§9. Cookies
9.1. The Store uses cookies and similar technologies — small text files saved on the Customer's device while using the Store.
9.2. Depending on their purpose, cookies are divided into the following categories:
- necessary — required for the Store to function correctly (e.g. handling the cart, the order placement process, maintaining a logged-in Customer's session, remembering the selected language and currency). These files are used at all times, regardless of consent — on the basis of the Controller's legitimate interest (Article 6(1)(f) GDPR) in ensuring the Store functions properly;
- analytics — Google Analytics, used to understand how visitors use the Store (visit statistics, traffic sources, popularity of Products and categories);
- marketing — Meta Pixel (Facebook/Instagram) and Google Ads, used to measure the effectiveness of advertising campaigns and to display Store advertisements tailored to the visitor's interests, including as part of remarketing advertising on external platforms.
9.3. Cookies other than necessary ones (including Google Analytics, Meta Pixel and Google Ads) are used only with the Customer's consent, expressed through the relevant settings in the cookie consent banner/panel available in the Store, and are not loaded before such consent is given. Consent may be withdrawn or changed at any time via the same panel.
9.4. The Customer may at any time independently change their cookie settings using their web browser's settings, including blocking cookies from being saved or deleting cookies already saved. Restricting the use of cookies may affect some functionalities available in the Store.
§10. Data Security
10.1. The Controller applies technical and organizational measures ensuring protection of the processed personal data appropriate to the risks and the categories of data covered by protection, in particular safeguarding data against disclosure to unauthorized persons, loss, damage or destruction.
10.2. Access to personal data is granted only to persons authorized by the Controller, to the extent necessary to perform the tasks assigned to them.
§11. Changes to the Privacy Policy
11.1. The Controller reserves the right to make changes to this Privacy Policy, in particular in connection with changes to legal provisions, the scope of the Store's activities, or the tools/technologies used.
11.2. The Controller will inform of significant changes by publishing the updated content of the Privacy Policy on the Store's website, indicating the date it takes effect.
11.3. This Privacy Policy takes effect on August 11, 2026.
§12. Contact
12.1. For all matters related to the protection of personal data and this Privacy Policy, please contact the Controller:
ADACTUS Sp. z o.o., Plac Bankowy 2, 00-095 Warsaw, Poland, e-mail: sales@fondori.com.