Documents · your data
Privacy policy
We care about your privacy. Below you will find all the information about how your personal data is processed in our shop.
1.1. This privacy policy of the Online Shop is informative in nature, which means that it is not a source of obligations for the Service Recipients or Customers of the Online Shop. The privacy policy contains above all the rules on the processing of personal data by the Controller in the Online Shop, including the grounds, purposes and scope of the processing of personal data and the rights of the data subjects, as well as information on the use of cookies and analytical tools in the Online Shop.
1.2. The controller of the personal data collected through the Online Shop is Satto Media Sp. z o.o., with its registered office at ul. Owsiana 62, 40-780 Katowice, Poland, entered in the register of entrepreneurs kept by the District Court Katowice-Wschod in Katowice, 8th Commercial Division of the National Court Register, under KRS number 0001142702, holding: NIP (tax identification number) 6343050029, REGON (statistical number) 540531914, contact telephone: +48 32 720 94 75, email address: info@wallyboards.eu, hereinafter referred to as the "Controller" and being at the same time the Service Provider of the Online Shop and the Seller.
1.3. Personal data in the Online Shop is processed by the Controller in accordance with applicable law, in particular with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the "GDPR" or the "GDPR Regulation". The official text of the GDPR Regulation: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
1.4. Using the Online Shop, including making purchases, is voluntary. Likewise, providing personal data by a Service Recipient or Customer using the Online Shop is voluntary, with two exceptions:
- entering into contracts with the Controller: failure to provide, in the cases and to the extent indicated on the Online Shop website, in the Terms and Conditions of the Online Shop and in this privacy policy, the personal data necessary to conclude and perform a Sales Contract or a contract for the supply of an Electronic Service with the Controller means that such a contract cannot be concluded. In such a case, providing personal data is a contractual requirement, and if a data subject wishes to conclude a given contract with the Controller, they are obliged to provide the required data. In each case the scope of data required to conclude a contract is indicated in advance on the Online Shop website and in the Terms and Conditions of the Online Shop;
- statutory obligations of the Controller: providing personal data is a statutory requirement arising from generally applicable law which imposes on the Controller an obligation to process personal data (for example processing data in order to keep tax or accounting books), and failure to provide it will make it impossible for the Controller to fulfil those obligations.
1.5. The Controller takes particular care to protect the interests of the data subjects whose personal data it processes, and in particular is responsible for and ensures that the data it collects is:
- processed lawfully;
- collected for specified, lawful purposes and not further processed in a way incompatible with those purposes;
- substantively correct and adequate in relation to the purposes for which it is processed;
- kept in a form which permits identification of the data subjects for no longer than is necessary to achieve the purpose of the processing
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
1.6. Taking into account the nature, scope, context and purposes of the processing and the risk of infringement of the rights or freedoms of natural persons, of varying likelihood and severity, the Controller implements appropriate technical and organisational measures so that the processing is carried out in accordance with this regulation and so that this can be demonstrated. These measures are reviewed and updated where necessary. The Controller applies technical measures to prevent the acquisition and modification by unauthorised persons of personal data sent electronically.
1.7. All words, expressions and acronyms used in this privacy policy that begin with a capital letter (for example Seller, Online Shop, Electronic Service) are to be understood in accordance with their definition in the Terms and Conditions of the Online Shop available on the pages of the Online Shop.
2.1. The Controller is entitled to process personal data in cases where, and to the extent to which, at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specified purposes; (2) the processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract; (3) the processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) the processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
2.2. Each instance of processing personal data by the Controller requires at least one of the grounds indicated in point 2.1 of the privacy policy to apply. The specific grounds on which the Controller processes the personal data of Service Recipients and Customers of the Online Shop are indicated in the next point of the privacy policy, in relation to the given purpose of the processing of personal data by the Controller.
3.1. In each case the purpose, grounds, period and recipients of the personal data processed by the Controller follow from the actions taken by a given Service Recipient or Customer in the Online Shop or by the Controller.
3.2. The Controller may process personal data (first name, surname, home and delivery address, email address, telephone number and so on) within the Online Shop for the following purposes, on the following grounds and for the periods indicated in the table below:
| Purpose of processing | Legal basis for processing and data retention period | Scope of processed data |
|---|---|---|
| Performance of a Sales Contract or a contract for the supply of an Electronic Service, or taking steps at the request of the data subject prior to entering into those contracts | Article 6(1)(b) of the GDPR Regulation (performance of a contract): the processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract | The data is stored for the period necessary to perform, terminate or otherwise bring to an end the Sales Contract or the contract for the supply of an Electronic Service that has been concluded. |
| Direct marketing | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller): the processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in looking after the interests and good image of the Controller and its Online Shop and in seeking to sell Products | The data is stored for as long as the legitimate interest pursued by the Controller exists, but no longer than the limitation period for the Controller's claims against the data subject arising from the business activity conducted by the Controller. The limitation period is set by law, in particular by the Civil Code (the basic limitation period for claims connected with conducting a business is three years, and for a Sales Contract two years). The Controller may not process data for direct marketing purposes where the data subject has effectively objected to it. |
| Marketing | Article 6(1)(a) of the GDPR Regulation (consent): the data subject has given consent to the processing of their personal data for marketing purposes by the Controller | The data is stored until the data subject withdraws consent to the further processing of their data for this purpose. |
| The Customer giving a review of the Sales Contract concluded | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller): the processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in looking after the interests and good image of the Controller and its Online Shop and in seeking to sell Products | The data is stored for as long as the legitimate interest pursued by the Controller exists, but no longer than the limitation period for the Controller's claims against the data subject arising from the business activity conducted by the Controller. The limitation period is set by law, in particular by the Civil Code (the basic limitation period for claims connected with conducting a business is three years, and for a Sales Contract two years). |
| Keeping tax books | Article 6(1)(c) of the GDPR Regulation in conjunction with Article 86 § 1 of the Tax Ordinance, consolidated text of 17 January 2017 (Journal of Laws of 2017, item 201): the processing is necessary for compliance with a legal obligation to which the Controller is subject | The data is stored for the period required by law obliging the Controller to keep tax books (until the limitation period for the tax liability expires, unless tax legislation provides otherwise). |
| Establishing, pursuing or defending claims that the Controller may raise or that may be raised against the Controller | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller): the processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in establishing, pursuing or defending claims that the Controller may raise or that may be raised against the Controller | The data is stored for as long as the legitimate interest pursued by the Controller exists, but no longer than the limitation period for claims that may be raised against the Controller (the basic limitation period for claims against the Controller is six years). |
| Use of the Online Shop website and ensuring that it works correctly | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller): the processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in running and maintaining the Online Shop website | The data is stored for as long as the legitimate interest pursued by the Controller exists, but no longer than the limitation period for the Controller's claims against the data subject arising from the business activity conducted by the Controller. The limitation period is set by law, in particular by the Civil Code (the basic limitation period for claims connected with conducting a business is three years, and for a Sales Contract two years). |
| Keeping statistics and analysing traffic in the Online Shop | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller): the processing is necessary for the purposes of the legitimate interests pursued by the Controller, consisting in keeping statistics and analysing traffic in the Online Shop in order to improve how the Online Shop works and to increase sales of Products | The data is stored for as long as the legitimate interest pursued by the Controller exists, but no longer than the limitation period for the Controller's claims against the data subject arising from the business activity conducted by the Controller. The limitation period is set by law, in particular by the Civil Code (the basic limitation period for claims connected with conducting a business is three years, and for a Sales Contract two years). |
| Handling an enquiry submitted through the contact form, including the files sent with the enquiry | Article 6(1)(b) of the GDPR Regulation (taking steps at the request of the data subject prior to entering into a contract) and Article 6(1)(f) of the GDPR Regulation (the legitimate interest of the Controller consisting in preparing and presenting a quote). Files sent with an enquiry are stored for 90 days from the day they are sent, after which they are deleted automatically. The content of the enquiry and the contact details are stored for as long as the legitimate interest pursued by the Controller exists, but no longer than the limitation period for the Controller's claims against the data subject arising from the business activity conducted by the Controller. | Email address, the content of the enquiry and the content of the files sent with the enquiry, for example artwork, room plans and lists of signage wording. The files sent may contain personal data if the sender puts it in them, for example the names of employees on door plates. |
4.1. For the Online Shop to function properly, including for the performance of the Sales Contracts concluded, it is necessary for the Controller to use the services of external entities (such as a software supplier, a courier or a payment handling entity). The Controller uses only the services of processors who provide sufficient guarantees of implementing appropriate technical and organisational measures, so that the processing meets the requirements of the GDPR Regulation and protects the rights of the data subjects.
4.2. Personal data may be transferred by the Controller to a third country, whereby the Controller ensures that in such a case this will take place in relation to a country ensuring an adequate level of protection in line with the GDPR Regulation, and in the case of other countries, that the transfer will take place on the basis of standard data protection clauses. The Controller ensures that a data subject is able to obtain a copy of their data. The Controller passes on the personal data collected only in the case of, and to the extent necessary for, achieving the given purpose of the data processing in accordance with this privacy policy.
4.3. The Controller does not pass on data in every case, nor to all the recipients or categories of recipients indicated in the privacy policy. The Controller passes on data only where this is necessary to achieve a given purpose of the processing of personal data, and only to the extent necessary to achieve it.
4.4. The personal data of Service Recipients and Customers of the Online Shop may be passed on to the following recipients or categories of recipients:
4.4.1. carriers, freight forwarders and courier brokers: in the case of a Customer who uses delivery of a Product by post or by courier in the Online Shop, the Controller makes the Customer's personal data collected available to the chosen carrier, freight forwarder or intermediary handling shipments on behalf of the Controller, to the extent necessary to deliver the Product to the Customer.
4.4.2. entities handling electronic or card payments: in the case of a Customer who uses electronic or card payment in the Online Shop, the Controller makes the Customer's personal data collected available to the chosen entity handling those payments in the Online Shop on behalf of the Controller, to the extent necessary to handle the payment made by the Customer.
4.4.3. credit providers and lessors: in the case of a Customer who uses instalment payment or lease payment in the Online Shop, the Controller makes the Customer's personal data collected available to the chosen credit provider or lessor handling those payments in the Online Shop on behalf of the Controller, to the extent necessary to handle the payment made by the Customer.
4.4.4. providers of the review survey system: in the case of a Customer who has agreed to give a review of the Sales Contract concluded, the Controller makes the Customer's personal data collected available to the chosen entity providing the system of surveys reviewing Sales Contracts concluded in the Online Shop on behalf of the Controller, to the extent necessary for the Customer to give a review through the review survey system.
4.4.5. service providers supplying the Controller with technical, IT and organisational solutions that allow the Controller to conduct its business, including the Online Shop and the Electronic Services supplied through it (in particular suppliers of computer software for running the Online Shop, providers of email and hosting, and suppliers of business management software and of technical support to the Controller): the Controller makes the Customer's personal data collected available to the chosen supplier acting on its behalf only in the case of, and to the extent necessary for, achieving the given purpose of the data processing in accordance with this privacy policy.
4.4.6. providers of accounting, legal and advisory services giving the Controller accounting, legal or advisory support (in particular an accounting office, a law firm or a debt collection company): the Controller makes the Customer's personal data collected available to the chosen supplier acting on its behalf only in the case of, and to the extent necessary for, achieving the given purpose of the data processing in accordance with this privacy policy.
5.1. The GDPR Regulation places on the Controller an obligation to inform about automated decision making, including profiling, referred to in Article 22(1) and (4) of the GDPR Regulation, and, at least in those cases, to provide meaningful information about the logic involved and about the significance and the envisaged consequences of such processing for the data subject. With this in mind, the Controller gives in this point of the privacy policy information about the profiling that may take place.
5.2. The Controller may use profiling in the Online Shop for direct marketing purposes, but the decisions the Controller takes on that basis do not concern the conclusion or refusal to conclude a Sales Contract, nor the possibility of using Electronic Services in the Online Shop. The effect of using profiling in the Online Shop may be, for example, granting a person a discount, sending them a discount code, reminding them about an unfinished purchase, sending them a suggestion for a Product that may match their interests or preferences, or offering better terms compared with the standard offer of the Online Shop. Despite the profiling, it is the person who freely decides whether they want to use the discount or the better terms received in this way and make a purchase in the Online Shop.
5.3. Profiling in the Online Shop consists in the automatic analysis or prediction of a person's behaviour on the Online Shop website, for example through adding a particular Product to the basket, viewing the page of a particular Product in the Online Shop, or through analysing the history of purchases made so far in the Online Shop. A condition of such profiling is that the Controller holds the personal data of the given person, so that it can then send them, for example, a discount code.
5.4. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
6.1. Right of access, rectification, restriction, erasure or portability: the data subject has the right to request from the Controller access to their personal data, its rectification, erasure (the "right to be forgotten") or restriction of processing, and has the right to object to processing, as well as the right to data portability. The detailed conditions for exercising the rights indicated above are set out in Articles 15 to 21 of the GDPR Regulation.
6.2. Right to withdraw consent at any time: a person whose data is processed by the Controller on the basis of consent given (under Article 6(1)(a) or Article 9(2)(a) of the GDPR Regulation) has the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out on the basis of the consent before its withdrawal.
6.3. Right to lodge a complaint with a supervisory authority: a person whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and under the procedure set out in the provisions of the GDPR Regulation and of Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office (UODO).
6.4. Right to object: the data subject has the right at any time to object, on grounds relating to their particular situation, to the processing of personal data concerning them which is based on Article 6(1)(e) (public interest or public tasks) or (f) (legitimate interest of the controller), including profiling based on those provisions. In such a case the Controller may no longer process that personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims.
6.5. Right to object regarding direct marketing: where personal data is processed for direct marketing purposes, the data subject has the right at any time to object to the processing of personal data concerning them for such marketing, including profiling, to the extent that the processing is related to such direct marketing.
6.6. In order to exercise the rights referred to in this point of the privacy policy, you can contact the Controller by sending an appropriate message in writing or by email to the address of the Controller given at the beginning of the privacy policy, or by using the contact form available on the Online Shop website.
Consents and the full list of files. The shop collects cookie consents through its own panel hosted on our server. You can open it at any time in the cookie settings or with the cookie icon in the bottom left corner of the page. A full list of the files, together with their providers and retention times, is in the cookies policy. The provisions below describe the general rules for the use of cookies in the Online Shop.
7.1. Cookies are small pieces of text information, in the form of text files, sent by the server and saved on the side of the person visiting the Online Shop website (for example on the hard drive of a computer or laptop, or on the memory card of a smartphone, depending on the device the visitor to our Online Shop is using). Detailed information about cookies, and the history of how they came about, can be found among other places here: https://en.wikipedia.org/wiki/HTTP_cookie.
7.2. The cookies that may be sent by the Online Shop website can be divided into different kinds, according to the following criteria:
| By their provider: | By how long they are stored on the device of the person visiting the Online Shop website: | By the purpose they are used for: |
|---|---|---|
| 1) first party (created by the Controller's Online Shop website) and 2) belonging to third parties (other than the Controller) | 1) session cookies (stored until you log out of the Online Shop or close the web browser) and 2) persistent cookies (stored for a set time, defined by the parameters of each file, or until they are deleted manually) | 1) necessary (allowing the Online Shop website to work properly), 2) functional and preference cookies (allowing the Online Shop website to be adjusted to the preferences of the person visiting the site), 3) analytical and performance cookies (collecting information on how the Online Shop website is used), 4) marketing, advertising and social cookies (collecting information about the person visiting the Online Shop website in order to display advertisements to that person, personalise them, measure their effectiveness and carry out other marketing activities, including on websites separate from the Online Shop website, such as social networks or other sites belonging to the same advertising networks as the Online Shop) |
7.3. The Controller may process the data contained in cookies while visitors use the Online Shop website for the following specific purposes:
| Purposes for which cookies are used in the Controller's Online Shop | identifying Service Recipients as logged in to the Online Shop and showing that they are logged in (necessary cookies) |
| remembering Products added to the basket in order to place an Order (necessary cookies) | |
| remembering data from completed Order Forms, surveys or Online Shop login details (necessary cookies and/or functional and preference cookies) | |
| adjusting the content of the Online Shop website to the individual preferences of the Service Recipient (for example colours, font size, page layout) and optimising the use of the Online Shop pages (functional and preference cookies) | |
| keeping anonymous statistics showing how the Online Shop website is used (statistical cookies) | |
| displaying and rendering advertisements, limiting the number of times advertisements are shown and skipping advertisements the Service Recipient does not want to see, measuring the effectiveness of advertisements, and personalising advertisements, that is studying the behavioural characteristics of people visiting the Online Shop through anonymous analysis of their actions (for example repeat visits to particular pages, keywords and so on) in order to create their profile and deliver advertisements matched to their expected interests, including when they visit other websites in the advertising network of Google Ireland Ltd. and Meta Platforms Ireland Ltd. (marketing, advertising and social cookies) |
7.4. In the most popular web browsers, you can check which cookies (including how long they last and who provides them) are being sent at a given moment by the Online Shop website in the following way:
| In Chrome: (1) click the padlock icon on the left of the address bar, (2) go to the "Cookies" tab. | In Firefox: (1) click the shield icon on the left of the address bar, (2) go to the "Allowed" or "Blocked" tab, (3) click "Cross site tracking cookies", "Social media trackers" or "Tracking content" | In Internet Explorer: (1) click the "Tools" menu, (2) go to "Internet options", (3) go to the "General" tab, (4) go to "Settings", (5) click "View files" |
| In Opera: (1) click the padlock icon on the left of the address bar, (2) go to the "Cookies" tab. | In Safari: (1) click the "Preferences" menu, (2) go to the "Privacy" tab, (3) click "Manage website data" | Whichever browser you use, with tools available for example at: https://www.cookiemetrix.com/ or: https://www.cookie-checker.com/ |
7.5. As standard, most web browsers on the market accept the saving of cookies by default. Everyone can set the conditions for the use of cookies through the settings of their own web browser. This means that you can, for example, partly limit (for example temporarily) or completely switch off the ability to save cookies, although in the latter case this may affect some functions of the Online Shop (for example it may turn out to be impossible to go through the Order path using the Order Form, because Products in the basket are not remembered during the successive steps of placing an Order).
7.6. Web browser settings regarding cookies matter from the point of view of consent to the use of cookies by our Online Shop, since under the applicable rules such consent may also be given through web browser settings. Detailed information on changing cookie settings and on deleting cookies yourself in the most popular web browsers is available in the help section of the browser and on the pages below (just click the relevant link):
7.7. The Controller may use in the Online Shop the Google Analytics and Universal Analytics services provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These services help the Controller keep statistics and analyse traffic in the Online Shop. The data collected is processed within those services to generate statistics that help in administering the Online Shop and analysing traffic in the Online Shop. This data is aggregate in nature. Using these services in the Online Shop, the Controller collects data such as the sources and medium through which visitors reach the Online Shop and how they behave on the Online Shop website, information about the devices and browsers they visit the site from, the IP address and domain, geographic data and demographic data (age, gender) and interests.
7.8. A person can easily block Google Analytics from receiving information about their activity on the Online Shop website. To do so, they can install the browser add on provided by Google Ireland Ltd., available here: https://tools.google.com/dlpage/gaoptout?hl=en.
7.9. In connection with the possibility of the Controller using advertising and analytical services provided by Google Ireland Ltd. in the Online Shop, the Controller points out that full information on how Google Ireland Ltd. processes the data of people visiting the Online Shop (including information saved in cookies) can be found in the privacy policy of Google services, available at: https://policies.google.com/technologies/partner-sites.
7.10. The Controller may use in the Online Shop the Facebook Pixel service provided by Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). This service helps the Controller measure the effectiveness of advertisements and find out what actions visitors to the online shop take, as well as display matched advertisements to those people. Detailed information about how the Facebook Pixel works can be found at the following address: https://www.facebook.com/business/help/742478679120153?helpref=page_content.
7.11. The Facebook Pixel can be managed through the advertising settings in your account on Facebook.com: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen.
7.12. The Controller may use in the Online Shop the Klaviyo marketing tool provided by Klaviyo, Inc. (125 Summer Street, Boston, Massachusetts 02110, USA). These services help the Controller run a mailing system, segment Customers, track user behaviour and integrate with Facebook in order to display advertisements to the right users. Using these services in the Online Shop in order to build a user profile, the Controller collects data such as the sources and medium through which visitors reach the Online Shop and how they behave on the Online Shop website, information about the devices and browsers they visit the site from, the IP address and domain, geographic data and demographic data (age, gender) and interests.
8.1. The Online Shop may contain links to other websites. The Controller encourages you to read the privacy policy set out there once you move to other sites. This privacy policy applies only to the Controller's Online Shop.
