---
type: "Legal Document"
title: "Privacy Policy"
description: "Privacy policy of the HARTA.agency website - data controller, purposes and legal bases for processing, data recipients, user rights."
resource: "https://harta.agency/en/privacy-policy/"
lang: "en"
status: "stable"
headline: "Privacy policy"
generated:
  by: "process:harta-okf/1.0"
  at: "2026-08-19T18:40:03+00:00"
verified:
  - by: "human:m.gawanowski@harta.agency"
    at: "2026-08-19"
sources:
  - resource: "https://harta.agency/en/privacy-policy/"
    last_modified: "2026-08-19"
stale_after: "2027-08-19"
---

In order to fulfil the obligations imposed on personal data controllers under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, hereinafter "RODO" (GDPR)), we hereby inform you of the following matters.

### I. General provisions
Array

### II. Purposes and legal bases for the processing of personal data
Array
- Responding to enquiries - in order to answer your enquiries, including those sent via the contact form (Article 6(1)(f) RODO).
- Newsletter - in order to send a newsletter containing offers, promotions, events and educational materials related to e-commerce (Article 6(1)(f) in conjunction with recital 47 of the preamble to RODO).
- Promotion of services - in order to pursue the Controller's legitimate interests, such as promoting its services (Article 6(1)(f) in conjunction with recital 47 of the preamble to RODO).
- Compliance with legal obligations - including issuing an invoice or a bill and retaining documentation for reporting and accounting purposes (Article 6(1)(c) RODO).
- Performance of a contract - to which you are a party as a natural person, or taking steps at your request prior to entering into it, in particular a contract for marketing services (Article 6(1)(b) RODO).
- Contact under a contract - in connection with the performance of a contract concluded by the Controller with your employer, your principal or the legal person you represent (Article 6(1)(f) RODO).
- Consent - if you have given the Controller your voluntary consent to the processing of data for any of the above purposes (Article 6(1)(a) RODO).

### III. Requirements regarding the provision of personal data
Array
- fulfilling a statutory obligation (e.g. an accounting one) - providing the data is a statutory requirement;
- performing a contract - providing the data is voluntary, but necessary for its performance, e.g. issuing invoices and settling payments;
- performing a contract with your employer, your principal or the legal person you represent - providing the data is voluntary, but necessary to ensure proper contact with the contracting party;
- responding to your enquiries - providing the data is voluntary, but necessary in order to reply.

### IV. Recipients of personal data
Array
- the Controller, as well as its representatives, employees, associates and advisers;
- entities cooperating with the Controller, in particular those personally connected with it;
- entities providing services to the Controller (including accounting and IT services);
- entities supporting the Controller in the area of promotional, marketing and analytical services.
- the payment operator Stripe (Stripe Payments Europe Ltd.) - for processing online payments for orders placed on the website, including billing details provided at payment;
- the invoicing system provider (Fakturownia sp. z o.o.) - for issuing and sending invoices.
- In connection with the use of Stripe and of Google, Meta and Microsoft tools, data may be transferred outside the European Economic Area, in particular to the USA - on the basis of a European Commission adequacy decision (EU-U.S. Data Privacy Framework) or standard contractual clauses (Article 46 GDPR).

### V. Expected period of processing of personal data
Array
- the fulfilment of the legal obligation is completed - where the basis for processing is Article 6(1)(c) RODO;
- the claims arising from the contract concluded and performed become time-barred - where the basis is Article 6(1)(b) RODO;
- consent is withdrawn - where the basis is Article 6(1)(a) RODO;
- an objection is raised - where the basis is the Controller's legitimate interest (Article 6(1)(f) RODO).
- cancellation and deletion of data of unpaid orders (interrupted payments) - the order is cancelled automatically after 30 days and its data deleted after 12 months; data of completed orders and accounting documents are kept for the period required by tax and accounting regulations.

### VI. Your rights related to the processing of data
Array

### VII. Data safeguards applied by the Controller
Array
- an internal information flow control policy, based on the principle of limited trust towards third parties and on minimising the transfer of confidential data by electronic means;
- data protection systems within IT systems, ensuring, among others, that third parties have no access to the content and that complex, strong passwords are used.
- encryption of the data of orders placed on the website - the data is stored in encrypted form, and the encryption key is kept outside the database and its backups.

### VIII. Automated processing of personal data
Array
Last updated: 10 August 2026


# Wersje językowe
- [PL](/pl/company/polityka-prywatnosci.md)
- [RO](/ro/company/politica-de-confidentialitate.md)
