Skip to content
Dary pszczół
Home Shop News Our apiary Contact
PL EN
Account Basket 0

Shop information

Privacy policy

Information about the processing of personal data of Dary pszczół customers.

Last updated: 06.08.2026
Documents Store terms and conditions Privacy policy Delivery and returns

Effective from 6 August 2026.

This Policy explains what personal data are processed when darypszczol.com is used, why and for how long, and the rights of data subjects. We do not operate a newsletter or marketing profiling.

1. Controller

The controller is Pasieka rodzinna Dary pszczół Wojciech Lisecki, Dyniska 8, 22-678 Ulhówek, Poland. Privacy enquiries may be sent to darypszczol@gmail.com or to the postal address above.

No data protection officer has been appointed. Requests concerning personal data can be sent directly to the e-mail address above.

2. Data we process

The scope depends on how the Store is used and may include:

  • identity and contact data: first name, surname, e-mail address and telephone number;
  • delivery data: street, building or unit number, postcode, town, and selected parcel locker, machine, point or branch;
  • order data: products, variants, quantities, prices, weight, delivery and payment methods, order number and status, notes and service history;
  • Account data: e-mail, name, telephone, saved addresses, order history and a secure password hash; the plain password is not stored;
  • payment data: method, amount, status and transaction identifier; full card details are handled by the payment provider rather than the Store;
  • complaint, withdrawal and correspondence data, including photographs and the requested resolution;
  • technical data: IP address, date and time, requested page, browser and device type, session identifier, error logs and security events;
  • data required for a sales document where applicable to the transaction.

Most data come directly from the user. Payment status may come from a bank or payment provider, and shipment status or point data from a carrier. When buying for another person, the Customer should give that person this Policy and provide their data only with a lawful basis.

3. Purposes and legal bases

  • Cart, order, payment, delivery, collection and contract communication – steps before and performance of a contract, Article 6(1)(b) GDPR.
  • Account registration, saved addresses, order history and password reset – performance of the electronic service contract, Article 6(1)(b).
  • Sales documentation, settlements and duties toward authorities – compliance with a legal obligation, Article 6(1)(c).
  • Complaints, withdrawals, refunds and responses under consumer law – contract performance and legal obligations, Article 6(1)(b) and (c).
  • Establishing, pursuing and defending claims, preventing fraud and documenting service – legitimate interests of the Controller and Customers in protecting their rights and demonstrating proper performance, Article 6(1)(f).
  • Store, session and Account security, abuse detection, error diagnosis and availability – legitimate interests in protecting the service and data, Article 6(1)(f).
  • Answering a question before a contract – steps requested before entering a contract, Article 6(1)(b), or the legitimate interest in correspondence, Article 6(1)(f).
  • An expressly offered voluntary function requiring consent – Article 6(1)(a). Consent can be withdrawn at any time without affecting prior lawful processing.

Special-category data, such as health information, are not needed for ordinary orders. Please do not include them in notes or correspondence unless truly necessary to resolve a specific matter.

4. Whether data are required

Providing fields marked as required is voluntary but necessary to conclude and perform the contract. Without an e-mail the Store cannot send confirmation; without recipient details it cannot deliver; and the chosen payment cannot be handled without relevant payment data. A telephone number is used for delivery and order contact.

An Account is voluntary and guest checkout remains available. Optional data can be omitted unless required for a particular service selected by the Customer.

5. Recipients

Data are disclosed only where necessary. Recipients or processors may include:

  • the hosting and server maintenance provider in OVHcloud infrastructure and administrative tooling providers such as Plesk;
  • Resend where it is the active e-mail delivery service, and other e-mail infrastructure providers;
  • the selected carrier or point operator: InPost, Pocztex/Poczta Polska or a courier, to deliver and track the parcel;
  • Stripe or Autopay only where the Customer selects an active payment handled by that provider, and banks involved in settlement;
  • IT, security, accounting, legal or maintenance suppliers where required and governed by an appropriate agreement;
  • public authorities or other entities entitled by law.

A selected provider may be a separate controller for some data, especially payment or carriage data. The chosen service is identified before transfer and that provider's own privacy information applies to its independent processing.

6. Transfers outside the European Economic Area

The Store's primary infrastructure is maintained in Europe. Some technology providers, especially an e-mail or payment provider, may use subcontractors or systems outside the European Economic Area.

Any such transfer is made only under Chapter V GDPR, for example an adequacy decision, the recipient's valid participation in recognised privacy arrangements, or Standard Contractual Clauses with additional safeguards where needed. Information about the mechanism used by a particular provider and a copy of relevant safeguards may be requested from the Controller.

7. Retention

  • Order and contract data are kept for fulfilment and then until the relevant limitation periods expire.
  • Sales, tax or accounting records are kept for the period required by law; where the standard Polish tax period applies, this is generally five years from the end of the calendar year in which the relevant tax payment deadline expired.
  • Account data are kept until deletion or termination, then only where a legal duty or claims protection requires retention.
  • A password reset token expires after 30 minutes and can be used only once. Related technical records are deleted or anonymised when no longer useful, except where needed to investigate an incident.
  • Correspondence, complaints, withdrawals and refunds are kept until completion and then for relevant claims or evidential periods.
  • E-mail queue messages are kept as needed for delivery, error handling and proof of communication; successful technical entries are periodically removed.
  • Server and security logs are kept for a period proportionate to diagnosis and protection, and longer only where they concern an incident, abuse or claim.

If different purposes require different periods, the data are restricted to the purpose that remains valid and deleted or anonymised when it ends.

8. Data subject rights

Subject to the GDPR, you have the right to:

  • access and receive a copy of your data;
  • rectify inaccurate and complete incomplete data;
  • erasure where no further basis exists;
  • restriction of processing;
  • portability of data processed automatically on the basis of consent or contract;
  • object, on grounds relating to your particular situation, to processing based on Article 6(1)(f);
  • withdraw consent at any time where processing relies on consent;
  • lodge a complaint with the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl.

Send a request to darypszczol@gmail.com. To protect data, the Controller may request proportionate information to confirm identity. A response will be provided without undue delay, generally within one month. Erasure, objection and portability do not apply in every situation; if a request cannot be fulfilled, the legal reason and available remedies will be explained.

9. Automated decisions and marketing

The Controller does not make decisions producing legal or similarly significant effects solely by automated means and does not conduct marketing profiling. Automatic calculation of delivery price from selected order parameters is part of order performance and is not profiling.

The Store currently has no newsletter and sends no direct marketing. Registration, password reset, order, payment, shipment, sales document and complaint messages are transactional communications.

10. Cookies and similar technologies

The Store uses cookies and session data necessary for the cart, login, security, language preference and movement between checkout steps. Some core functions cannot work without them. Their use is based on providing a service expressly requested by the user and the legitimate interest in security.

The Store currently uses no advertising or analytics cookies. If optional technologies are added, they will not be activated before any required consent and consent will be as easy to withdraw as to give.

When an InPost or Pocztex map, payment provider or another external service is opened, that provider may receive technical data such as IP address and browser information and use its own technologies under its policy. The selected point is saved with the order for delivery.

Cookies can be controlled in browser settings. Deleting or blocking necessary cookies may sign the user out, remove the current session or prevent checkout.

11. Security

The Controller uses measures appropriate to risk, including HTTPS encryption, access controls, secure password hashes, form protection, restricted administration, backups and updates. Access is limited to people and suppliers who need it for assigned tasks.

No system can guarantee absolute security. Suspected Account takeover, misdirected communication or a data breach should be reported promptly.

12. Children and Policy changes

The Store is not specifically directed to children. A person unable to conclude an effective contract independently should use it with a legal representative. The Controller does not knowingly collect children's data for marketing.

This Policy may be updated when law, data use, functions or providers change. A new version will be published with an update date. An amendment cannot legitimise earlier processing that lacked a basis or restrict acquired rights.

Questions about this document?

Use the contact details in the footer. We will explain the relevant rules before you place an order.

Family apiary since 1921.

Visit us

Dyniska 8
22-678 Ulhówek

Wojciech +48 609 108 583

Magdalena +48 517 443 436

Helpful links

Shop News Account Basket

Shop information

Terms and conditions Privacy policy Delivery and returns Administrator panel
© 2026 Dary pszczół Created by Prytulko
Honey and bee products directly from our family apiary