Privacy Policy

Last Updated: 3 lipca 2026

This Privacy Policy is provided in English for the convenience of non-Polish-speaking customers. The Polish-language version is the legally binding original; in case of any discrepancy, the Polish version prevails. Processing of personal data described here is subject to Polish and EU (GDPR) law.

§1 Data controller

The controller of personal data processed in connection with the use of the portal operated under the Penthus brand, available at penthus.pl (the Portal), is JMDomaradzki & Co Sp. z o.o., with its registered office at Śliczna 12a/17, 31-444 Kraków, Poland, entered in the National Court Register (KRS) under number 0000839997, NIP 6793199240, REGON 386013584 (the Controller). Penthus is a trade name under which the Controller operates the Portal.

§2 Contact regarding data protection

For any matters concerning the processing of personal data, you may contact the Controller electronically at kontakt@penthus.pl, in writing at the registered office address indicated in §1, or via the contact form available on the Portal.

§3 What data we process

In connection with the use of the Portal, the Controller may process the following categories of data:

  • Identification and contact data — first name, last name, email address, phone number;
  • Account data — password (stored in encrypted form) or a Google account identifier if login is via Google, as well as a two-factor authentication (2FA) secret, if the Customer enables it;
  • Order and delivery data — delivery address, selected Project and Add-ons, Order history;
  • Contact form data — first name, email address, optional phone number, and the content of the message;
  • Technical data — IP address, browser and device information, recorded in server logs for security and diagnostic purposes;
  • Statistical and analytics data — information about how the Portal is used (pages visited, traffic source, events such as adding a Project to the cart or placing an Order), collected via Google Analytics only after the Customer has consented to analytics cookies — see §12.

§4 Purpose and legal basis for processing

Personal data is processed for the following purposes:

  • concluding and performing the Sales Agreement and fulfilling the Order, including delivery and payment handling — Article 6(1)(b) GDPR;
  • creating and maintaining the Customer Account — Article 6(1)(b) GDPR;
  • responding to a message sent via the contact form — Article 6(1)(b) and (f) GDPR;
  • fulfilling legal obligations incumbent on the Controller, in particular tax and accounting obligations (e.g. issuing and storing sales documents) — Article 6(1)(c) GDPR;
  • establishing, pursuing or defending against claims and ensuring the security of the Portal (including login and two-factor authentication mechanisms) — Article 6(1)(f) GDPR, as the Controller's legitimate interest;
  • analysing how the Portal is used and improving its functionality using Google Analytics — Article 6(1)(a) GDPR, based on consent given via the cookie banner, see §12.

The Controller does not currently carry out consent-based marketing activities (e.g. a newsletter) — if such functionality is introduced in the future, this Privacy Policy will be updated accordingly and consent will be collected separately.

§5 Recipients of data

Personal data may be shared with entities supporting the Controller in operating the Portal and fulfilling Orders, including:

  • the online payment provider — Stripe, to the extent necessary to process payments;
  • carriers performing delivery — InPost, DPD, to the extent of address and contact data necessary to deliver the shipment;
  • the Google login service provider, if the Customer chooses to log in via a Google account;
  • the Google Analytics provider (Google Ireland Limited) — only in respect of data collected once the Customer has consented to analytics cookies, see §12;
  • the cookie consent management provider — Cookiebot (Cybot A/S), through which the Customer gives, restricts, or withdraws consent for individual cookie categories;
  • email service providers used to send transactional messages (order confirmations, password resets);
  • providers of hosting and technical infrastructure maintenance services for the Portal;
  • the accounting office and legal advisors, to the extent necessary to fulfil tax, accounting, and legal obligations.

With each of these entities, the Controller has entered into, or is entering into, the legally required data processing agreements, or uses their services under the standard data processing terms offered by those entities.

§6 Transfer of data outside the European Economic Area

Some of the recipients listed in §5 (in particular the payment provider Stripe, the Google login service provider, and the Google Analytics provider) may process data outside the European Economic Area, including in the United States. In such cases, the transfer of data is carried out with appropriate safeguards required by the GDPR, in particular the Standard Contractual Clauses approved by the European Commission.

§7 Data retention period

Personal data is stored for the period necessary to achieve the purposes for which it was collected, in particular:

  • Account data — for as long as the Account exists, until it is deleted at the Customer's request;
  • Order data and sales documents — for the period required by tax and accounting law (including Article 74 of the Accounting Act) and until claims arising from the Sales Agreement become time-barred under the Civil Code;
  • the content of messages sent via the contact form — for no longer than 3 years from the last contact, unless longer retention is justified by an ongoing matter.

§8 Rights of the data subject

The data subject has the right to:

  • access their personal data;
  • rectify their data;
  • request erasure of data ("the right to be forgotten");
  • restrict processing;
  • data portability;
  • object to processing based on Article 6(1)(f) GDPR;
  • lodge a complaint with the President of the Polish Data Protection Authority (Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw), if they consider that the processing of their data infringes the GDPR.

To exercise the rights above, please contact the Controller as indicated in §2.

§9 Voluntariness of providing data

Providing personal data is voluntary, but necessary to create an Account, place an Order, or receive a response to a message sent via the contact form — failure to provide the required data prevents the use of these Portal features.

§10 Data security

Communication between the Customer's device and the Portal takes place over an encrypted connection (HTTPS/TLS). Account passwords are stored in encrypted form and are not known to the Controller. The Customer may additionally secure their Account by enabling two-factor authentication (2FA). Access to data in the Portal's admin panel is restricted to persons with appropriate permissions.

§11 Automated decision-making

The Controller does not make decisions concerning Customers based solely on automated processing of personal data, including profiling, which produce legal effects concerning them or similarly significantly affect them.

§12 Cookies and similar technologies

The Portal uses cookies and browser storage (local storage) in the following categories:

  • Necessary cookies — ensure the basic functionality of the Portal, including maintaining a logged-in Customer's session, remembering the Portal's selected language, recording the Customer's cookie consent choice, and storing the contents of the cart and the list of favourite Projects in browser storage (this data is not transmitted to the Controller until the Customer places an Order or logs into an Account). These cookies are always active and do not require the Customer's consent.
  • Analytics cookies — used by Google Analytics (provider: Google Ireland Limited) to collect statistical information about how the Portal is used, including pages visited, traffic source, and events such as adding a Project to the cart, starting the checkout process, or placing an Order, allowing the Controller to analyse and improve the Portal's functioning. These cookies are loaded only after the Customer has given consent and may be withdrawn at any time.

Cookie consent is managed via Cookiebot (provider: Cybot A/S, Denmark), which displays a banner on the Customer's first visit allowing them to give, restrict, or refuse consent for individual cookie categories, and blocks analytics cookies from loading until consent is given. The Customer may change their preferences at any time via the Cookiebot widget settings available on the Portal.

The legal basis for processing data via analytics cookies is the Customer's consent (Article 6(1)(a) GDPR in conjunction with Article 173 of the Polish Telecommunications Law). Giving consent is entirely voluntary, and refusing or withdrawing it does not limit the Customer's ability to use the Portal's core functionality, including placing Orders. Withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal.

Data collected by Google Analytics may be transferred outside the European Economic Area, including to the United States — the rules governing such transfers are described in §6.

The Customer may delete cookies and data stored in browser storage at any time via their browser's settings, which may however affect the Portal's functionality, including the loss of saved cart contents or the need to log in again.

§13 Changes to the Privacy Policy

The Controller reserves the right to amend this Privacy Policy, in particular in connection with changes in the law or in the scope of the Portal's functionality. The current version of the Privacy Policy, together with the date of its last update, is published on this page.