Privacy Policy of JYOCO
1. General Information
This Privacy Policy sets out the rules governing the processing of personal data and the use of cookies in connection with the use of the JYOCO online store available at jyoco.com.
The Controller exercises particular care to protect the privacy of users and the security of personal data provided, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR").
2. Personal Data Controller
The Controller of personal data is:
JYOCO Joanna Krotofil-Owsian
ul. Szkolna 4E/1
62-023 Borówiec
Poland
e-mail: contact@jyoco.com
hereinafter referred to as the "Controller" or "JYOCO".
For matters relating to the processing of personal data, the Controller may be contacted at:
3. Scope of Data Collected
The Controller may process the following personal data:
first and last name,
e-mail address,
telephone number,
delivery address,
billing address,
business details and VAT identification number (NIP),
order history,
payment-related information,
information provided through contact forms,
information relating to bespoke and personalised projects,
inspiration photographs submitted by the customer,
technical data concerning the device used and the manner of using the website.
Providing personal data is voluntary; however, in certain cases it is necessary for the performance of an order or for communication purposes.
4. Purposes and Legal Bases for Data Processing
Order Fulfilment
Including payment processing, shipment of orders and communication concerning the order.
Legal basis:
Article 6(1)(b) GDPR – performance of a contract.
Customer Account and Wishlist Management
Including enabling login functionality, saving preferences and maintaining order history.
Legal basis:
Article 6(1)(b) GDPR – performance of a contract.
Handling Contact Forms and Individual Enquiries
Including the preparation of quotations and communication regarding bespoke and personalised projects.
Legal basis:
Article 6(1)(b) and Article 6(1)(f) GDPR.
Marketing of the Controller's Products and Services
Including newsletters and promotional activities.
Legal basis:
Article 6(1)(a) GDPR – consent;
Article 6(1)(f) GDPR – the Controller's legitimate interest.
Analytical and Statistical Purposes
Including website traffic analysis and improvement of the Store's functionality.
Legal basis:
Article 6(1)(f) GDPR – the Controller's legitimate interest.
Compliance with Legal Obligations
In particular tax and accounting obligations.
Legal basis:
Article 6(1)(c) GDPR – compliance with a legal obligation.
5. Data Recipients
Personal data may be disclosed to entities supporting the operation of the Store, in particular:
Shopify – e-commerce platform provider,
Przelewy24,
Google Pay,
Apple Pay,
InPost,
DPD,
DHL,
providers of accounting, hosting and analytical services,
providers of IT and marketing services.
Personal data is disclosed only to the extent necessary for the provision of such services.
6. Transfers of Data Outside the European Economic Area
Due to the use of Shopify services and certain analytical and marketing tools, personal data may be transferred outside the European Economic Area, in particular to Canada or the United States.
The Controller uses only service providers that ensure an adequate level of data protection in accordance with GDPR requirements.
7. Data Retention Period
Personal data shall be retained:
for the duration necessary to perform the contract,
for the period required by applicable tax and accounting laws,
until consent for marketing activities is withdrawn,
until an effective objection to processing is submitted,
for the period necessary for the establishment, exercise or defence of legal claims.
8. Rights of the Data Subject
The user has the right to:
access their personal data,
rectify personal data,
erase personal data,
restrict processing,
data portability,
object to processing,
withdraw consent at any time without affecting the lawfulness of processing carried out before such withdrawal,
lodge a complaint with the competent supervisory authority responsible for personal data protection.
In Poland, the competent supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
9. Cookies and Tracking Technologies
The Store uses cookies for the following purposes:
ensuring proper operation of the website,
maintaining user sessions,
operating the shopping cart and customer account,
analysing website traffic,
conducting marketing and advertising activities.
The following tools may be used within the Store:
Google Analytics,
Meta Pixel,
Pinterest Analytics.
Users may manage cookie preferences through their browser settings or through the cookie consent banner available on the website.
10. Data Security
The Controller implements appropriate technical and organisational measures designed to protect personal data against loss, unauthorised access, disclosure, alteration or unlawful processing.
11. Amendments to the Privacy Policy
The Controller reserves the right to amend this Privacy Policy in the event of legal, technological or organisational changes.
The current version of this Privacy Policy shall always be available on the Store's website.
12. Contact
For all matters relating to privacy and the processing of personal data, please contact: