Skip to content

PRIVACY POLICY
www.rodowicz.art

Version dated 26.06.2026

§ 1. Data controller

  1. The controller of personal data collected through the website www.rodowicz.art (hereinafter: the “Gallery”) is Antoni Rodowicz (hereinafter: the “Controller” or the “Artist”).
  2. The Controller may be contacted regarding personal data matters electronically at: antoni@rodowicz.art.
  3. The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the Polish Personal Data Protection Act of 10 May 2018.

§ 2. Scope, purposes and legal bases of processing

The Controller processes personal data for the following purposes:

  1. Order fulfilment — full name, delivery address, e-mail address, order details and, in the case of a Personalised Artwork, the content of the dedication. Legal basis: necessity for the performance of the contract (Article 6(1)(b) GDPR). Providing these data is voluntary but necessary to place an order.
  2. Payment processing — payment data are processed directly by the payment operator Stripe (§ 4). The Controller has no access to full payment card data.
  3. Handling complaints and withdrawals — contact details, order data, content of correspondence. Legal basis: performance of the contract and the Controller’s legal obligations (Article 6(1)(b) and (c) GDPR).
  4. Performance of tax and accounting obligations — data contained in receipts/invoices. Legal basis: legal obligation (Article 6(1)(c) GDPR).
  5. Maintaining a customer account — the Gallery allows the creation of a customer account (“My account”); the data provided upon registration and the order history are processed. Legal basis: performance of the contract for the provision of the account service (Article 6(1)(b) GDPR). Creating an account is voluntary — purchases may also be made without registration.
  6. E-mail correspondence — data provided by the person contacting the Controller. Legal basis: the Controller’s legitimate interest in conducting correspondence (Article 6(1)(f) GDPR).
  7. Establishing, pursuing or defending legal claims — based on the Controller’s legitimate interest (Article 6(1)(f) GDPR).

§ 3. Data retention period

  1. Data related to orders are stored for the period necessary to perform the contract and subsequently for the period required by tax and accounting regulations (as a rule, 5 years from the end of the calendar year in which the tax obligation arose).
  2. Data related to complaints and claims are stored until the expiry of the limitation period for claims.
  3. Customer account data are stored until the account is deleted by the user or the Controller; data of orders linked to the account are stored in accordance with point 1.
  4. Correspondence unrelated to orders is stored for the period necessary to handle it, no longer than 3 years.

§ 4. Data recipients

Personal data may be transferred to the following categories of recipients, solely to the extent necessary to achieve the purposes described in § 2:

  1. Stripe (Stripe, Inc. / Stripe Payments Europe Ltd.) — payment operator, acting as a separate data controller with respect to payment data; the rules of data processing by Stripe are described in Stripe’s privacy policy (https://stripe.com/privacy).
  2. Carriers and courier companies — with respect to data necessary to deliver the parcel (full name, address, and, where applicable, telephone number and e-mail).
  3. Giclée printing studio — only where dispatch directly from the studio so requires; only the address data necessary to send the parcel are transferred.
  4. Website hosting provider — with respect to data stored in the server infrastructure.
  5. Accounting service providers — with respect to data contained in sales documents, if the Controller uses such services.

Data are not sold or made available to third parties for marketing purposes.

§ 5. Transfer of data outside the European Economic Area

  1. As a rule, the Controller processes data within the European Economic Area.
  2. In connection with the use of Stripe’s services, payment data may be transferred to the United States. The transfer takes place on the basis of safeguards provided for in the GDPR, including the European Commission’s adequacy decision (EU–US Data Privacy Framework) or standard contractual clauses.

§ 6. Rights of data subjects

  1. Every person whose data are processed has the right to:
    • access their data and obtain a copy thereof,
    • rectify (correct) their data,
    • erase their data (to the extent that the Controller’s legal obligations do not preclude this),
    • restrict processing,
    • data portability,
    • object to processing based on legitimate interest.
  2. To exercise the above rights, please contact the Controller at the e-mail address indicated in § 1.
  3. Every person also has the right to lodge a complaint with the supervisory authority — the President of the Polish Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl).

§ 7. Cookies and technical data

  1. The Gallery uses cookies (small text files saved on the user’s device) to the extent necessary for the proper functioning of the website — in particular WooCommerce session cookies supporting the shopping cart, the ordering process and customer account login (necessary cookies). The basis for processing is the Controller’s legitimate interest in ensuring the operation of the Gallery (Article 6(1)(f) GDPR). Necessary cookies do not require the user’s consent.
  2. The payment operator Stripe may save its own cookies necessary for the secure processing of payments and fraud prevention.
  3. The Gallery does not use marketing cookies and does not operate a newsletter.
  4. Users may manage cookies themselves in their browser settings, including blocking or deleting them. Blocking necessary cookies may make it impossible to place an order.
  5. The website server automatically records technical data (server logs: IP address, date and time of the request, browser type) used solely for the purposes of website administration and ensuring its security.

§ 8. Data security

  1. The Controller applies technical and organisational measures appropriate to the risk, including an encrypted SSL/TLS connection on the Gallery’s website and restricted access to data.
  2. Payments are processed in the Stripe environment, which complies with the PCI DSS security standard.

§ 9. Final provisions

  1. The Controller does not make decisions concerning users based solely on automated processing, including profiling, that produce legal effects.
  2. The Privacy Policy may be updated, in particular in the event of changes in the law or in the operation of the Gallery. The current version is always available on the Gallery’s website.
  3. The Privacy Policy is drawn up in Polish, French and English versions. The foreign-language versions are for information purposes; in the event of any discrepancy, the Polish version shall prevail.
  4. The Policy is effective as of 26.06.2026.