Boggini

Information

Polityka Prywatności.

Last update: 6 June 2026

1.

Data administrator

The administrator of personal data is:

Admintes Sp. z o.o.

ul. Zamknięta 10 / 1.5, 30-554 Kraków

NIP: 6793210415

tel.: +48 729 109 623

office@boggini.pl

The Administrator processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and other applicable provisions of law.

The Administrator has not appointed a Data Protection Officer. In all matters relating to the protection of personal data, you may contact us directly at office@boggini.pl.

2.

Scope of the policy

This privacy policy applies to the BOGGINI service available at boggini.pl. It defines the rules for processing personal data of users, including persons browsing the catalogue, placing orders, using the contact form and holding a customer account.

3.

Legal basis for data processing

Users' personal data is processed on the basis of:

  • art. 6(1)(b) GDPR — performance of a contract (order fulfilment, maintenance of the account),
  • art. 6(1)(c) GDPR — legal obligation (accounting and tax regulations),
  • art. 6(1)(a) GDPR — user consent (newsletter, marketing),
  • art. 6(1)(f) GDPR — legitimate interest of the administrator (analytics, security, handling of enquiries).
4.

What data we collect

The Administrator may process the following personal data of users:

  • first name and surname,
  • e-mail address,
  • telephone number,
  • company data (name, registered office address, tax identification number) — in the case of business orders,
  • delivery address,
  • order history (purchased products, quantities, amounts, dates, statuses),
  • list of products saved as favourites,
  • content of messages sent via the contact form,
  • account settings (marketing consents, preferences),
  • technical data of the browser and system,
  • IP address and cookie identifiers.

The Administrator does not collect or process special categories of data (including biometric, medical data, data concerning origin, political or religious views) within the meaning of art. 9 GDPR.

5.

Purposes of data processing

Users' personal data is processed for the following purposes:

  • maintaining the customer account and authorising access,
  • fulfilment of orders (delivery valuation, product preparation, dispatch),
  • issuing VAT invoices or personal receipts,
  • contact with the customer regarding orders and quotations,
  • handling enquiries sent via the contact form,
  • sending the newsletter and marketing information (with consent expressed via a double opt-in procedure),
  • analysing traffic on the website and improving services,
  • fulfilment of legal obligations (accounting, tax).
6.

Customer account

The user may create an account in the BOGGINI service to use its functionalities, such as placing orders, saving favourite products, tracking order history, managing billing data and sending enquiries through the contact form. Account data is stored until the account is deleted by the user or by the administrator.

7.

Payments

The BOGGINI service does not support online payments. Payment for the order is made outside the service (including bank transfer).

The Administrator does not collect or store payment card data or online banking login credentials.

Settlement data (invoice number, amount, payment status) is stored as part of order documentation, in accordance with applicable accounting and tax regulations.

8.

Communication with users

The Administrator may contact users via:

  • e-mail,
  • telephone,
  • the contact form in the customer panel.
9.

Personalisation

The service may analyse user activity to personalise the content presented, adjust product recommendations and improve the quality of services. Profiling does not produce legal effects on the user, nor does it significantly affect their situation.

The Administrator does not make decisions about the user based solely on automated processing of data (including profiling) which would produce legal effects or significantly affect the user's situation within the meaning of art. 22 GDPR.

10.

Cookies

The service uses cookies for the following purposes:

  • ensuring the proper operation of the service (session cookies, authorisation),
  • remembering user preferences,
  • traffic and statistics analysis,
  • marketing and remarketing activities.

Analytical and marketing cookies are installed only after the user's consent has been expressed via the cookie banner displayed on the first visit. Cookies necessary for the operation of the service (authorisation, cart) do not require consent.

Consent can be changed or withdrawn at any time using the "Cookie settings" link available in the website footer. The user may also manage cookies in the browser settings.

11.

Analytical and marketing tools

The Administrator may use the following analytical and marketing tools:

  • Google Analytics,
  • Google Tag Manager,
  • Google Ads,
  • Meta Pixel,
  • TikTok Pixel,
  • Microsoft Clarity,
  • Hotjar.
12.

Recipients of data

Data may be transferred to the following categories of recipients:

  • OVH SAS — infrastructure hosting,
  • Cloudflare, Inc. — CDN, DNS and protection against attacks,
  • Resend, Inc. — provider of transactional e-mail services,
  • Google LLC — Google Analytics, Tag Manager, Ads,
  • Meta Platforms, Inc. — Meta Pixel,
  • TikTok Pte. Ltd. — TikTok Pixel,
  • Microsoft Corporation — Microsoft Clarity,
  • Hotjar Ltd. — behavioural analytics tool,
  • courier and transport companies — delivery fulfilment,
  • accounting and tax office — settlement handling,
  • law firm — in case of disputes or legal advice.

With each entity processing personal data on behalf of the Administrator (including OVH, Cloudflare, Resend, Google), a data processing agreement has been concluded in accordance with art. 28 GDPR.

In the case of marketing and analytical tools based on third-party cookies (including Meta Pixel, certain Google cookies), the Administrator and the provider may act as joint controllers of personal data within the meaning of art. 26 GDPR, to the extent specified in separate agreements.

13.

Data transfer outside the EEA

When transferring data outside the European Economic Area (including to providers from the USA — Resend, Cloudflare, Google, Meta, TikTok, Microsoft, Hotjar), standard contractual clauses approved by the European Commission (SCC) and additional security measures are applied.

14.

Data retention period

Personal data is stored for the period necessary to achieve the purposes for which it was collected:

  • customer account data — until the account is deleted,
  • order and invoice data — for 5 years from the end of the accounting year (accounting requirement),
  • data processed on the basis of consent — until consent is withdrawn,
  • analytical data — up to 26 months according to the settings of the tools.
15.

User rights

The user has the following rights:

  • the right of access to their data,
  • the right to rectify their data,
  • the right to delete data ("the right to be forgotten"),
  • the right to restrict processing,
  • the right to data portability,
  • the right to object,
  • the right to withdraw consent at any time (without affecting the lawfulness of processing prior to withdrawal).

Marketing consent can be withdrawn in the customer panel in the "Consents" section, by clicking the unsubscribe link in the footer of the newsletter e-mail or by writing to office@boggini.pl.

The right to delete data (art. 17 GDPR) may be limited to the extent that the data is subject to mandatory retention under accounting and tax regulations (5 years from the end of the accounting year) or other legal provisions.

The Administrator responds to the user's requests without undue delay, no later than within 30 days of their receipt. In complex cases or with a large number of requests, the deadline may be extended by another 60 days, of which the user will be informed (art. 12 GDPR).

A copy of personal data provided as part of the exercise of the right of access (art. 15 GDPR) is made available in a commonly used electronic format (PDF or JSON).

16.

Right to complain

The user has the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) — ul. Stawki 2, 00-193 Warszawa.

17.

Data security

The Administrator applies technical and organisational measures to protect data, including SSL/TLS encryption, server security, firewall, system log monitoring, protection against DDoS attacks and hashing of user passwords. Login credentials are not stored in plain form.

The Administrator collects server logs (IP address, browser identifier, time and access paths) on the basis of legitimate interest in order to ensure the security of the service, troubleshoot errors and detect abuse.

In the event of a personal data breach which may result in a high risk to the rights or freedoms of the user, the Administrator shall promptly — no later than within 72 hours of identifying the breach — notify the President of the UODO and, where required, the user themselves (in accordance with art. 33 and 34 GDPR).

18.

Contact regarding data

In matters concerning the protection of personal data, the user may contact the administrator:

e-mail: office@boggini.pl

tel.: +48 729 109 623

address: Admintes Sp. z o.o., ul. Zamknięta 10 / 1.5, 30-554 Kraków

19.

Changes to the privacy policy

The Administrator reserves the right to make changes to this privacy policy. Users will be informed of any significant changes via the service or directly at the provided e-mail address.