Privacy policy

Pursuant to Article 13(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1), we inform you that:

The controller of your personal data is THE FUTURE IS HERS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered seat in Warsaw, at the address: ul. Śląska 47a/13, 70-431 Szczecin, Poland, entered into the Register of Entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register under KRS number: 0000909235, NIP: 5223205486, REGON: 38934224, with a share capital of PLN 20,000.00.

You can contact the Data Controller at the email address: hello@hibestie.eu, or by phone at +48 514 058 159, on Business Days between 9:00 AM and 3:00 PM CET.

The joint controllers of personal data are:

  • Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA, the operator of WordPress.com, processing data in accordance with the privacy policy available at https://automattic.com/privacy/;

  • PayU S.A. with its registered seat in Poznań, 60-166 Poznań, ul. Grunwaldzka 186, entered into the Register of Entrepreneurs kept by the District Court Poznań – Nowe Miasto and Wilda in Poznań, 8th Commercial Division of the National Court Register under KRS number 0000274399, NIP: 779-23-08-495; a domestic payment institution supervised by the Polish Financial Supervision Authority, entered into the Register of Payment Services under number IP1/2012;

  • MailerLite Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland.

Joint control is connected with the Data Controller's use of social media platforms.

Personal data is processed by the Data Controller for the following purposes:

  1. Conducting promotional and marketing activities by the Seller electronically or by telephone, consisting of providing information about the Seller and its business, communicating regarding the services provided by the Seller and their quality, in particular using the email address and contact telephone number provided for this purpose, on the basis of: Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (OJ L 119, 4.5.2016, p. 1) [hereinafter: GDPR];

  2. Performing concluded contracts or taking steps (at the Customer's request) prior to entering into such contracts, on the basis of: Article 6(1)(b) of the GDPR;

  3. Performing contracts with an entity whose representative the Customer is in contacts with the Seller, or taking steps prior to entering into such contracts, on the basis of: Article 6(1)(f) of the GDPR;

  4. Handling complaints or withdrawals from distance contracts – on the basis of: Article 6(1)(b) and (c) of the GDPR;

  5. Conducting promotional and marketing activities by the Seller by means other than electronic communication, in particular: providing information about the Seller and its business, answering questions asked, on the basis of: Article 6(1)(f) of the GDPR;

  6. Conducting promotional and marketing activities by the Seller electronically, in particular: sending Newsletters, on the basis of: Article 6(1)(a) of the GDPR;

  7. Conducting statistical measurements regarding: the Online Store; users of the Online Store and their preferences; monitoring traffic in the Online Store; distinguishing users of the Service (without identifying them); ensuring the security of the Online Store and services provided within the Online Store (including detecting cases of malfunction of the Online Store); continuously improving the quality of services provided within the Online Store and adapting them to user preferences, on the basis of: Article 6(1)(a) of the GDPR;

  8. Saving data in functional, analytical, and necessary cookies used for the proper functioning of the Website and collecting data from its subpages – on the basis of Article 6(1)(a) and (b) of the GDPR;

  9. Contacting via telephone, email, or remote communication applications regarding standard personal data and data other than standard personal data – on the basis of: Article 6(1)(a) and (b) of the GDPR;

  10. Issuing invoices, bills, or fulfilling other obligations arising from tax and accounting regulations, including for archiving purposes – on the basis of: Article 6(1)(c) of the GDPR;

  11. Ensuring accountability and demonstrating compliance with obligations imposed on the Controller by law, including creating registers and other documentation resulting from the GDPR – on the basis of: Article 6(1)(c) of the GDPR;

  12. Establishing, pursuing, and defending against claims, on the basis of: Article 6(1)(f) of the GDPR;

  13. Storing data for archiving and evidentiary purposes, for the purpose of securing information that could serve to prove facts – on the basis of: Article 6(1)(f) of the GDPR;

  14. Providing electronic services – on the basis of Article 6(1)(b) of the GDPR;

  15. Expressing opinions about products or services – on the basis of Article 6(1)(a) of the GDPR.

The legitimate interest of the Seller or third parties in processing personal data constitutes:

  • In relation to item 3 above – performing contracts with an entity whose representative the Customer is in contacts with the Seller, or taking steps prior to entering into such contracts;

  • In relation to item 5 above – the Seller's marketing and promotional activities by means other than electronic communication;

  • In relation to item 7 above – conducting statistical measurements regarding the Online Store, monitoring traffic in the Online Store, and improving the quality of provided services;

  • In relation to item 8 above – saving data in functional and analytical cookies used for the proper functioning of the Website;

  • In relation to item 12 above – establishing, pursuing, and defending against claims;

  • In relation to item 13 above – storing data for archiving and evidentiary purposes, for the purpose of securing information that could serve to prove facts.

Users have the following rights regarding their personal data:

  • Access to personal data, i.e., the possibility to obtain information about the processing of their data, including the purposes and legal bases for processing – pursuant to Article 15 of the GDPR;

  • Rectification of data, i.e., the right to correct inaccurate or incorrect data and complete incomplete data – pursuant to Article 16 of the GDPR;

  • Receiving a copy of data, i.e., the possibility to obtain a copy of the data processed by the Controller – pursuant to Article 15(3) of the GDPR;

  • Erasure of data, i.e., the right to request the deletion of data that is no longer necessary to achieve the purposes for which it was collected – pursuant to Article 17 of the GDPR;

  • Restriction of processing, i.e., the right to request the cessation of certain data processing operations, in particular in the event of a dispute regarding data accuracy or the lawfulness of processing – pursuant to Article 18 of the GDPR;

  • Data portability, i.e., the possibility to receive data in a structured, commonly used, and machine-readable format and transmit it to another entity, if technically feasible – pursuant to Article 20 of the GDPR;

  • Objection to the processing of personal data for marketing purposes, which can be submitted at any time without stating reasons – pursuant to Article 21(2) of the GDPR;

  • Objection to the processing of data based on the Controller's legitimate interest for other purposes, if it arises from the User's particular situation – pursuant to Article 21(1) of the GDPR;

  • Withdrawal of consent to data processing, to the extent that processing takes place on its basis, which does not affect the lawfulness of processing carried out prior to its withdrawal – pursuant to Article 7(3) of the GDPR;

  • Lodge a complaint with a supervisory authority, if the data processing violates the provisions of the GDPR; in Poland, the supervisory authority is the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw) – pursuant to Article 77 of the GDPR.

Users may exercise their rights by contacting the Controller via email at hello@hibestie.pl or by post to the address:

ul. Quo Vadis 3/152, 02-495 Warsaw, Poland

The request should specify the scope of the demand and data allowing for the identification of the person submitting the request. User rights are not absolute and their realization depends on the purpose of processing and the legal bases.

The business activity conducted by the Seller is supported by external entities to which personal data may be disclosed. This data is transferred solely to the extent necessary to fulfill specific purposes and in accordance with legal regulations. In particular, personal data may be disclosed to:

  • Entities authorized under legal provisions to the extent necessary to fulfill the Seller's obligation to transfer data;

  • Future is Hers sp. z o.o., ul. Quo Vadis 3/152, 02-495 Warsaw, the owner and controller of the online store;

  • Entities authorized under contracts concluded by the Seller to the extent necessary to perform said contracts, in particular: providers of services related to providing access to the service and maintaining the Seller's email or running the Website;

  • Suppliers responsible for servicing IT systems and ensuring the proper functioning of the technical infrastructure;

  • Accounting and bookkeeping offices to fulfill tax and accounting obligations;

  • Entities enabling the Seller to perform remote payment operations;

  • Banks and payment operators to process financial transactions;

  • Other entities supporting the Seller's operations if such cooperation requires the processing of personal data.

The Seller does not intend to transfer personal data to a third country or an international organization.

Each entity to which data is transferred acts on the basis of data processing agreements concluded with the Seller or under applicable provisions of law, guaranteeing compliance of processing with GDPR principles.

The Controller reserves the right to disclose personal data when such an obligation arises from provisions of law. In particular, this may include the obligation to transfer information to relevant administrative authorities, law enforcement agencies, courts, or other institutions authorized to obtain it under applicable regulations.

Any such disclosure will be carried out solely to the extent necessary to fulfill the imposed duties and in accordance with the principles of personal data protection provided for in the GDPR.

The Controller transfers personal data outside the European Economic Area (EEA) only when necessary, primarily in connection with using the services of international entities. In such cases, service providers have branches or subsidiaries within the EEA, ensuring compliance with European data protection standards.

Personal data is stored for the period necessary to achieve the purposes for which it was collected, in accordance with the following rules:

  • Data processed on the basis of consent – until its withdrawal or the achievement of the processing purpose;

  • Data processed in connection with the conclusion or performance of a contract – for the duration of negotiations, performance of cooperation, and the limitation period for claims;

  • Data processed in connection with the Controller's legal obligations – for the period required by legal provisions, including tax law, accounting law, and the GDPR;

  • Data processed on the basis of the Controller's legitimate interest – until an effective objection is lodged;

  • Data processed for analytical and administrative purposes – until it becomes outdated, loses its usefulness, or an objection is lodged.

Additionally, personal data may be stored to protect the Controller's rights, including establishing, pursuing, or defending against claims, in accordance with applicable provisions on the limitation of claims.

Providing personal data is voluntary. However, failure to provide personal data may result in the inability to use certain functionalities of the website, access specific content, or the impossibility of performing the service.

The Controller uses cookies to provide electronic services and improve their quality, ensure the proper functioning of the website, including improving navigation, remembering cookie preferences, ensuring security, managing the website, conducting statistical and analytical research, and carrying out marketing activities.

During the first visit to the website, the User is shown a message regarding the use of cookies. This message contains information about their types and allows the User to give consent to the use of selected categories of cookies.

Accepting cookies results in saving information from the service provider on the User's device (e.g., computer, phone, tablet). However, please note that the Controller does not have full control over cookies originating from third-party providers.

Users can manage cookies in the following ways:

  • During the first visit to the website – the user can give consent to selected cookies or reject their use in whole or in part;

  • Deleting cookies from the device – the user can delete all cookies by clearing the browsing history in their browser. Please note that deleting cookies results in the loss of saved information, such as login details;

  • Preventing the storage of cookies – it is possible to configure the browser to prevent cookies from being saved. However, please note that this may affect the proper functioning of the website and prevent the use of certain functionalities;

  • Using incognito mode – in incognito mode, cookies are stored only until the browser is closed, ensuring their automatic deletion after ending the session;

  • Using other devices or browsers – when using another terminal device, user profile on a computer, or another browser, it will be necessary to redefine cookie preferences.

When changing cookie settings, the User should be aware that preventing their storage or deleting them may result in reduced functionality of the website. Some content or features may be unavailable, and saved settings (e.g., cookie preferences) may be lost.

The Controller continuously improves personal data procedures and security measures, which is why the Privacy Policy is regularly reviewed and updated as necessary. Users are advised to regularly read its content to stay up to date with changes. The latest version of the Privacy Policy is always available on the website.

Cookies:

There are two types of cookies:

  • Session cookies, which remain on the device until leaving the page, turning off the browser, or turning off the device (whichever occurs first), and

  • Persistent cookies, which remain on the device for the period specified in their parameters or until deleted by the user (whichever occurs first).

The detailed list of Cookies used on the website includes:

  • _ga – Google Analytics cookies;

  • cc_ – cookie saving consents granted for cookie files.

Consents for the use of cookies can be managed via the website's privacy settings or the settings of the web browser you use.

Instructions for disabling Cookies in individual web browsers can be found on the websites of their publishers.

Disabling the use of cookies may interfere with certain features of the website and reduce its ease of use.

Opting out of cookies will apply only to that specific browser. Therefore, relevant actions will need to be taken for every other browser used on the same or another device.

This privacy policy is effective as of February 13, 2025.

The Controller reserves the right to amend and update this policy.