Skip to content

1. General information

(including the Cookie Policy)

This Privacy Policy sets out the rules for the collection, processing and use of personal data obtained from you by the online store available at iwchome.com (hereinafter: "Service" or "Online Store"), operated by IWC HOME sp. z o.o. (hereinafter: "Administrator" or "ADO"). The processing of personal data is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, "GDPR") and the Act of 10 May 2018 on the protection of personal data.

2. Personal Data Administrator

IWC HOME sp. z o.o. with its registered office in Spalice, ul. Warszawska 28, 56-400 Spalice, entered into the register of entrepreneurs of the National Court Register under KRS number 0000950683, NIP 9112025317, REGON 36895348500000, is the Administrator of your personal data within the meaning of Art. 4 point 7 of the GDPR.

In all matters related to the processing of personal data, you can contact the Administrator by e-mail: sklep@iwchome.pl or in writing to the Administrator's registered office address indicated above.

The Administrator has not appointed a data protection officer.

3. Scope of Data Processed

For the purposes of this Policy, personal data means any information relating to an identified or identifiable natural person, including in particular: name and surname, delivery address and correspondence address, email address, telephone number, and in the case of Entrepreneurs - also company name, business address and tax identification number (NIP).

The Administrator also collects certain technical information and information regarding the use of the Website, including: device IP address, location data, internet identifier, type of device, browser and operating system, and information collected through cookies and other similar technologies.

4. Purposes, legal bases and periods of processing

Your personal data is processed for the following purposes:

Setting up and maintaining an Account in the Online Store

  • Legal basis (GDPR): Article 6(1)(b) GDPR – performance of the Account service agreement
  • Data recipients: IT, hosting and email service providers, administrative support entities
  • Retention period: until the termination of the Account agreement

Conclusion and performance of the Sales Agreement and order fulfillment

  • Legal basis (GDPR): Article 6(1)(b) GDPR – performance of a contract or taking steps prior to entering into a contract
  • Data recipients: carriers and courier companies, payment operators, accounting firms, IT and hosting providers
  • Retention period: until the performance of the contract, and then until the expiration of the limitation periods for claims

Processing complaints and handling withdrawals from the contract

  • Legal basis (GDPR): Article 6(1)(c) GDPR in conjunction with the provisions of the Consumer Rights Act and the Civil Code
  • Data recipients: accounting firms, law firms, IT providers, carriers
  • Retention period: until the complaint is processed, then until the expiration of the limitation periods for claims

Fulfilling tax and accounting obligations (invoices)

  • Legal basis (GDPR): Article 6(1)(c) GDPR in conjunction with Article 74 of the Accounting Act and tax regulations
  • Data recipients: accounting firms, invoicing service providers, tax authorities, IT providers
  • Retention period: 5 years, counting from the end of the calendar year in which the tax payment deadline expired

Establishing, pursuing, or defending claims

  • Legal basis (GDPR): Article 6(1)(f) GDPR – legitimate interest of the Administrator
  • Data recipients: law firms, debt collection service providers, IT providers
  • Retention period: until the expiration of the limitation periods for claims

Handling correspondence and inquiries (contact form, email)

  • Legal basis (GDPR): Article 6(1)(f) GDPR – legitimate interest (providing a response)
  • Data recipients: IT, hosting, and email service providers
  • Retention period: until the correspondence is concluded, then until the expiration of the limitation periods for claims

Sending Newsletters and commercial information electronically, as well as direct marketing and remarketing activities

  • Legal basis (GDPR): Article 6(1)(a) GDPR – consent, in conjunction with the Act on Providing Services by Electronic Means and the Electronic Communications Law
  • Data recipients: marketing and mailing service providers, IT and hosting providers
  • Retention period: until consent is withdrawn

Marketing of the Administrator's own products and services

  • Legal basis (GDPR): Article 6(1)(f) GDPR – legitimate interest of the Administrator
  • Data recipients: marketing and PR service providers, advertising agencies, IT providers
  • Retention period: until an effective objection is raised

Collecting and presenting Product Reviews

  • Legal basis (GDPR): Article 6(1)(a) GDPR – consent; Article 6(1)(f) GDPR – legitimate interest (reliability of Reviews)
  • Data recipients: providers of review collection systems, IT and hosting providers
  • Retention period: until consent is withdrawn or an objection is raised

Statistics, analytics, and website security (cookies)

  • Legal basis (GDPR): Article 6(1)(a) GDPR – consent (cookies other than necessary); Article 6(1)(f) GDPR – legitimate interest (security)
  • Data recipients: providers of analytical and advertising tools, IT and hosting providers
  • Retention period: until consent is withdrawn or the cookie validity period expires

Obligations arising from the Digital Services Act (DSA)

  • Legal basis (GDPR): Article 6(1)(c) GDPR in conjunction with Regulation (EU) 2022/2065 (DSA)
  • Data recipients: IT and hosting providers, law firms
  • Retention period: until the expiration of the limitation periods for claims

The above list may be supplemented or clarified as appropriate to the tools and services actually used by the Administrator (e.g., specific providers of review systems, payment systems, analytics).

5. Providing personal data

The provision of personal data is voluntary; however, it is necessary to create an Account, place an Order, and conclude and execute a Sales Agreement. Failure to provide the data will prevent the use of these functionalities. In relation to data processed based on consent (e.g., Newsletter, certain cookies), providing data and giving consent are entirely voluntary, and consent can be withdrawn at any time, which does not affect the lawfulness of processing carried out before its withdrawal.

6. Data Subject Rights

In connection with the processing of personal data, you have the following rights:

  • the right to access your data and obtain a copy thereof;
  • the right to rectify inaccurate data and complete incomplete data;
  • the right to erasure of data ("right to be forgotten"), in cases provided for in Article 17 of the GDPR;
  • the right to restriction of processing in cases provided for in Article 18 of the GDPR;
  • the right to data portability of data processed on the basis of consent or a contract by automated means (Article 20 of the GDPR);
  • the right to object to processing based on the legitimate interest of the Administrator, and in the case of direct marketing – to object at any time and without the need for justification (Article 21 of the GDPR);
  • the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.

To exercise the above rights, please contact the Administrator via email at sklep@iwchome.pl or in writing to the Administrator's registered office address.

If you believe that the processing of personal data violates the provisions of the GDPR, you have the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw).

7. Data recipients and transfers outside the EEA

The recipients of personal data may include entities cooperating with the Controller based on data processing agreements, including the Store's software provider (Shopify platform), IT, hosting, and email service providers, carriers and courier companies, payment operators, accounting firms, law firms, and marketing and analytical service providers. These entities process data solely in accordance with the Controller's instructions and with confidentiality.

Some cooperating entities (e.g., providers of social media services or advertising tools) may act as separate controllers or joint controllers of data, operating under their own privacy policies.

As a rule, the Controller does not transfer personal data outside the European Economic Area (EEA). If such a transfer proves necessary (e.g., due to the use of tools from providers outside the EEA), it will only take place in compliance with GDPR requirements, in particular on the basis of a European Commission decision stating an adequate level of protection or standard contractual clauses adopted by the European Commission.

8. Data Security

The Administrator carefully selects and applies appropriate technical and organisational measures to ensure the protection of processed personal data, suitable for the risks and categories of data. Access to data is restricted to authorised persons who are bound by confidentiality.

The Administrator uses security measures for servers, connections and the Service, including encrypted data transmission (SSL/TLS). All connections related to electronic payments are made via a secure, encrypted connection provided by an authorised payment operator.

To maintain security, we recommend keeping your account login and password confidential and not sharing them with third parties, and logging out after you have finished using the Service.

Activity on the Service may be recorded in system logs, which are processed to ensure the security and proper functioning of IT systems (e.g., performing backups, detecting irregularities, protecting against abuse).

9. Profiling and automated decision-making

For marketing and analytical purposes, the Administrator may, to a limited extent, use profiling, i.e., automated assessment of certain user information (e.g., activity on the Website) to tailor presented content and advertisements. This profiling does not produce legal effects for the user or similarly significantly affect them.

The Administrator does not make decisions concerning users based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect them, within the meaning of Article 22 of the GDPR.

10. Cookies

This chapter constitutes the cookie policy and sets out the rules for storing and accessing information on the user's end devices using cookies and other similar technologies.

Cookies are IT data, in particular small text files, saved and stored on the user's end device (e.g., computer, tablet, phone). Cookies usually contain the name of the website they come from, their storage time, and a unique number. In addition to cookies, the Administrator may use other related technologies, such as pixels (web beacons), plug-ins, browser local storage, and tracking codes.

Depending on their storage duration, cookies are divided into session cookies (deleted when the browser is closed) and persistent cookies (stored for a specified period or until deleted by the user). Depending on their origin, they are divided into first-party cookies (placed by the Administrator) and third-party cookies (placed by cooperating providers).

The Administrator uses the following categories of cookies:

Essential

  • Purpose of use: Enable the proper functioning of the Website (placing Orders, operation of the Cart, maintaining sessions and login, security). Without them, the Website would not function correctly.
  • Basis and consent: Legitimate interest of the Administrator; always active – do not require consent.

Functional

  • Purpose of use: Enable remembering user choices and preferences (e.g., language, settings, form data).
  • Basis and consent: User's consent (Art. 6(1)(a) GDPR).

Analytical / performance

  • Purpose of use: Allow analysis of traffic and how the Website is used, and measure its performance. Data is aggregated and generally anonymous.
  • Basis and consent: User's consent (Art. 6(1)(a) GDPR).

Advertising / marketing

  • Purpose of use: Enable marketing activities, including remarketing and personalized advertising, using tools from external providers (e.g., Google, Meta).
  • Basis and consent: User's consent (Art. 6(1)(a) GDPR).

A detailed, up-to-date list of specific cookies (name, provider, purpose, storage time) is available in the consent management panel on the Website.

Upon the first visit to the Website, a cookie banner (panel) is displayed, allowing to express or refuse consent for cookies other than essential, in particular by selecting: "Accept all", "Customize", and "Reject". Essential cookies always remain active.

The user can change or withdraw their consent at any time via the consent management panel available on the Website. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. Regardless of this, the user can manage cookies using their web browser settings.

Restricting or disabling cookie support may negatively affect some functionalities of the Website, and in extreme cases, hinder or prevent its use.

If the user gives consent, third-party cookies may be used on the Website, in particular from providers of analytical and advertising tools such as:

Google Ireland Limited / Google LLC

Provider of Google Analytics, Google Ads, Google Tag Manager, Google reCAPTCHA, and Google Pay tools. Google cookies and similar technologies may be used for analytics, measuring advertising effectiveness, remarketing, ad personalization, form protection, and handling selected payment services.

Meta Platforms Ireland Limited / Meta Platforms, Inc.

Provider of Meta advertising tools, including Meta Pixel / Facebook Pixel. Meta cookies and similar technologies may be used to measure the effectiveness of advertising campaigns, conduct remarketing, create audience groups, and present ads tailored to user activity on and off the Website.

Pinterest Europe Limited / Pinterest, Inc.

Provider of Pinterest advertising tools. Pinterest cookies may be used to measure the effectiveness of advertising campaigns, remarketing, and ad targeting based on user activity.

Shopify Inc.

Provider of the e-commerce platform and services related to the operation of the Website, including login and user account management. Shopify cookies may be used to support the cart, session, user account, orders, product recommendations, A/B tests, analysis of entry sources, pop-up messages, remembering consents, and the proper functioning of store features.

11. Changes to the Privacy Policy

The Administrator reserves the right to amend this Privacy Policy (including the cookie policy), in particular in the event of changes in legal regulations or the operation of the Service. The date of publication of the latest changes will always be indicated. Rights arising from this Policy will not be restricted without the express consent of the data subject.

12. Contact

For matters concerning personal data protection, please contact us at sklep@iwchome.pl or in writing at: IWC HOME sp. z o.o., ul. Warszawska 28, 56-400 Spalice.

Your cart Product added to cart

Your cart is empty

Check our offer and get inspired by
selected products

Select country

Select language

Product added to wishlist
Go to wishlist

Log in to your account to save it permanently.

Add-on removed from your configuration

Cart was not updated

Add-on restored to your configuration

Your configuration needs a change