PRIVACY POLICY
for the Online Store www.miaandlou.com
Effective Date: 29.07.2026
1. General Provisions
This Privacy Policy sets out the principles governing the processing of personal data and the use of cookies and similar technologies in connection with the use of the online store www.miaandlou.com (the "Store").
This Privacy Policy has been prepared in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR");
- the Polish Personal Data Protection Act of 10 May 2018;
- applicable European Union legislation governing electronic communications and the use of cookies; and
- the guidelines issued by the European Data Protection Board (EDPB).
The purpose of this Privacy Policy is to provide Users with transparent information regarding the processing of their personal data, the security measures applied by the Data Controller, and the rights available to individuals under applicable data protection laws.
2. Data Controller
The controller of your personal data is:
KIDSARI EWA DEJA I ARIEL DEJA CIVIL LAW PARTNERSHIP
(Solely trading as Kidsari s.c.)
ul. Słowiańska 34/62
80-381 Gdańsk
Poland
VAT No. (NIP): 5842771812
REGON: 380027214
E-mail: biuro@miaandlou.pl
(hereinafter referred to as the "Data Controller" or "Controller").
The Controller is responsible for ensuring that personal data are processed lawfully, fairly, transparently and securely.
3. Contact Regarding Personal Data
If you have any questions regarding this Privacy Policy or the processing of your personal data, you may contact the Controller at:
E-mail:
biuro@miaandlou.pl
or by post at the registered office address provided above.
The Controller will respond to requests concerning personal data within the time limits required under applicable data protection legislation.
4. Scope of this Privacy Policy
This Privacy Policy applies to all users of the website:
including, but not limited to:
- customers purchasing products through the Store;
- registered account holders;
- customers purchasing without creating an account;
- newsletter subscribers;
- individuals contacting the Controller;
- visitors browsing the Store.
5. Definitions
For the purposes of this Privacy Policy, the following definitions shall apply:
Controller means KIDSARI EWA DEJA I ARIEL DEJA CIVIL LAW PARTNERSHIP.
GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
User means any individual visiting or using the Store.
Customer means any natural person, legal entity or organisational unit purchasing products or services through the Store.
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on Personal Data as defined in Article 4 of the GDPR.
6. Principles of Personal Data Processing
The Controller processes Personal Data in accordance with the following principles:
- lawfulness;
- fairness;
- transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality; and
- accountability.
The Controller collects and processes only the Personal Data that are necessary to fulfil the purposes described in this Privacy Policy.
7. Categories of Personal Data We Collect
Depending on how you use the Store, the Controller may collect and process the following categories of Personal Data.
Identification Data
- first name;
- last name.
Contact Details
- e-mail address;
- telephone number;
- billing address;
- delivery address.
Billing Information
- company name;
- VAT identification number;
- billing address.
Order Information
- purchase history;
- order numbers;
- order value;
- returns;
- complaints;
- customer service communications.
Technical Information
When you browse the Store, certain technical information may be collected automatically, including:
- IP address;
- browser type;
- operating system;
- device identifiers;
- cookie identifiers;
- language preferences;
- website activity;
- date and time of access;
- pages viewed;
- referring website.
8. Purposes and Legal Bases for Processing Personal Data
The Controller processes Personal Data only where there is an appropriate legal basis under the GDPR.
8.1 Performance of a Sales Contract
Legal basis:
Article 6(1)(b) GDPR
Your Personal Data are processed for the purpose of:
- accepting and processing orders;
- confirming purchases;
- processing payments;
- preparing orders for dispatch;
- delivering products;
- providing customer support;
- communicating regarding your order.
8.2 Customer Account Management
Legal basis:
Article 6(1)(b) GDPR
Where you create a customer account, your Personal Data are processed to establish, maintain and manage your account, including enabling you to access your order history and account preferences.
8.3 Accounting and Tax Obligations
Legal basis:
Article 6(1)(c) GDPR
The Controller is legally required to retain accounting records, invoices and other documentation necessary to comply with applicable tax and accounting legislation.
8.4 Complaints, Returns and Warranty Claims
Legal basis:
- Article 6(1)(b) GDPR
- Article 6(1)(c) GDPR
Your Personal Data are processed for the purpose of handling complaints, warranty claims, product returns and exercising statutory consumer rights.
8.5 Customer Communications
Legal basis:
- Article 6(1)(b) GDPR; or
- Article 6(1)(f) GDPR,
depending on the nature of the communication.
The Controller processes Personal Data when responding to enquiries, providing customer support, and communicating with customers regarding products or services.
8.6 Marketing of the Controller's Own Products and Services
Legal basis:
Article 6(1)(f) GDPR
The Controller may process Personal Data to promote its own products and services where permitted by applicable law and where such processing is based on the Controller's legitimate interests.
Where consent is required by law, marketing communications will only be sent after obtaining the appropriate consent.
8.7 Newsletter
Legal basis:
Article 6(1)(a) GDPR
Where you subscribe to our newsletter, your Personal Data will be processed for the purpose of sending newsletters, promotional offers and information about new products.
You may withdraw your consent at any time by clicking the unsubscribe link included in every newsletter or by contacting the Controller directly.
8.8 Establishment, Exercise or Defence of Legal Claims
Legal basis:
Article 6(1)(f) GDPR
The Controller may process Personal Data where necessary to establish, exercise or defend legal claims.
8.9 Compliance with Legal Obligations
Legal basis:
Article 6(1)(c) GDPR
The Controller processes Personal Data where necessary to comply with legal obligations arising under tax law, accounting regulations, consumer protection legislation and other applicable legal requirements.
9. Recipients of Personal Data
The Controller discloses Personal Data only where necessary to achieve the purposes described in this Privacy Policy and only to entities that provide appropriate safeguards for the protection of Personal Data in accordance with applicable data protection laws.
Personal Data may be disclosed to the following categories of recipients:
- payment service providers;
- banks and financial institutions;
- courier and postal service providers;
- logistics providers;
- IT service providers;
- cloud hosting providers;
- e-mail service providers;
- accounting and tax advisers;
- legal advisers;
- providers of customer service systems;
- providers of marketing and advertising services;
- providers of analytics and website optimisation tools;
- public authorities where disclosure is required by applicable law.
The Controller ensures that all recipients process Personal Data only to the extent necessary for the performance of their services and in accordance with applicable legal requirements.
10. Payment Service Providers
Where you choose to pay for your order using an electronic payment method, your Personal Data may be transferred to the payment service provider selected during checkout.
Depending on the payment method selected, the Controller may cooperate with one or more of the following providers:
- PayU S.A.
- PayPal (Europe) S.à r.l. et Cie, S.C.A.
- Klarna Bank AB
- Stripe Payments Europe Ltd.
- Apple Pay
- Google Pay
- other payment providers made available within the Store.
Payment service providers act as independent controllers of Personal Data to the extent necessary to process payment transactions and comply with applicable financial regulations.
The Controller does not collect, process or store customers' payment card numbers or other sensitive payment credentials.
11. Delivery Service Providers
To fulfil customer orders, the Controller shares the Personal Data necessary for delivery with courier and logistics companies.
Depending on the delivery option selected, Personal Data may be disclosed to providers including, but not limited to:
- InPost Sp. z o.o.
- DPD Polska Sp. z o.o.
- GLS Poland Sp. z o.o.
- DHL Parcel Polska Sp. z o.o.
- FedEx Express Polska Sp. z o.o.
- UPS Polska Sp. z o.o.
- other shipping providers available during the ordering process.
The information shared is limited to that required to complete the delivery, including:
- recipient's name;
- delivery address;
- telephone number (where required);
- e-mail address (where required);
- order reference number.
12. IT Service Providers
The Controller uses specialised third-party service providers to ensure the secure operation of the Store.
These providers may include:
- e-commerce platform providers;
- website hosting providers;
- cloud infrastructure providers;
- e-mail hosting providers;
- customer relationship management (CRM) providers;
- customer support software providers;
- accounting software providers;
- newsletter service providers;
- fraud prevention providers;
- cybersecurity service providers;
- website maintenance providers.
Where required by Article 28 GDPR, Personal Data are processed by such providers solely under a written Data Processing Agreement and only on documented instructions from the Controller.
13. International Transfers of Personal Data
As a general rule, Personal Data are processed within the European Economic Area ("EEA").
However, certain service providers used by the Controller may process Personal Data outside the EEA, including in countries that may not provide the same level of data protection as required under European Union law.
Where such transfers occur, the Controller ensures that they are carried out in accordance with Chapter V of the GDPR using one or more of the following safeguards:
- an adequacy decision issued by the European Commission;
- the European Commission's Standard Contractual Clauses (SCCs);
- participation in an approved international data transfer framework where applicable;
- any other safeguard recognised under the GDPR.
International transfers may occur in connection with services provided by companies such as:
- Google LLC;
- Meta Platforms, Inc.;
- Microsoft Corporation;
- Stripe, Inc.;
- PayPal.
The Controller regularly reviews the legal basis for such transfers and implements additional safeguards where appropriate.
14. Data Retention Periods
The Controller retains Personal Data only for as long as necessary to fulfil the purposes for which the data were collected or to comply with applicable legal obligations.
Different categories of Personal Data are retained for different periods.
Customer Accounts
Personal Data associated with customer accounts are retained for the duration of the account and, where necessary, for up to five (5) years following account deletion or the customer's last activity, where required by law or the Controller's legitimate interests.
Orders
Personal Data relating to completed orders are retained for the period required under applicable tax and accounting legislation, generally five (5) years from the end of the financial year in which the transaction occurred.
Complaints and Returns
Data relating to complaints, product returns and warranty claims are retained until the matter has been fully resolved and thereafter for the applicable statutory limitation period.
Newsletter
Personal Data processed for newsletter subscriptions are retained until the User withdraws consent or unsubscribes from receiving marketing communications.
Marketing Activities
Where Personal Data are processed on the basis of the Controller's legitimate interests, they will be retained until the User successfully objects to such processing or until the data are no longer required for the relevant purpose.
Technical and Analytics Data
Technical logs and analytical data are retained for periods determined by the configuration of the relevant analytical tools and applicable legal requirements.
15. Profiling
The Controller may analyse information relating to Users' activity within the Store in order to:
- improve website functionality;
- personalise product recommendations;
- optimise marketing activities;
- analyse purchasing trends;
- improve customer experience.
Profiling is used solely to enhance the services provided by the Store.
The Controller does not make decisions based solely on automated processing that produce legal effects concerning Users or similarly significantly affect them within the meaning of Article 22 of the GDPR.
16. Security of Personal Data
The Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with the processing of Personal Data.
Such measures include, where appropriate:
- SSL/TLS encryption for all communications;
- secure server infrastructure;
- restricted access to Personal Data;
- role-based access controls;
- authentication and authorisation procedures;
- regular software updates;
- malware protection;
- firewall protection;
- encrypted backups;
- security monitoring systems;
- incident response procedures;
- regular assessment of technical and organisational safeguards.
Employees and authorised contractors who have access to Personal Data are subject to confidentiality obligations and receive appropriate training regarding data protection and information security.
The Controller regularly reviews and updates its security measures to ensure an appropriate level of protection in light of technological developments, evolving cybersecurity risks and applicable legal requirements.