Privacy policy
In force as of: 3 July 2026
§1. General provisions and Data Controller
1. This Privacy Policy sets out the rules for processing the personal data of Customers and users of the online store available at https://maisonachi.com (the “Store”).
2. The controller of personal data is: UNITY PRIME GROUP sp. z o.o. (a Polish limited liability company), with its registered office in Warsaw (postal code 04-109), at ul. Korytnicka 46/52, entered into the Register of Entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw, 14th Commercial Division, under number (KRS) 0001225215, NIP 1133194860, REGON 544044387, share capital of PLN 5,000, e-mail: support@maisonachi.com, telephone: +48 888 909 476 (the “Controller”).
3. For all matters concerning the processing of personal data and the exercise of rights, the Controller may be contacted at the e-mail address: support@maisonachi.com or by post to the address indicated above.
4. The Controller has not appointed a Data Protection Officer (DPO).
5. Personal data is processed in accordance with generally applicable law, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”), the Act of 10 May 2018 on the Protection of Personal Data and the Act of 18 July 2002 on the Provision of Electronic Services.
§2. Purposes, legal bases and retention periods
In connection with users’ use of the Store, the Controller collects personal data to the extent necessary to provide the individual services offered. The detailed rules and purposes of processing are set out below:
|
PURPOSE |
WHAT PERSONAL DATA IS PROCESSED? |
PURPOSE, LEGAL BASIS AND RETENTION |
|---|---|---|
|
Placing an order and performing the contract |
Name, e-mail, billing address, delivery address, phone number, NIP (tax ID) and business data (optional – only where the user provides data for a company invoice). Providing data is voluntary but necessary to place an order and perform the contract. |
Performance of the contract (Art. 6(1)(b) GDPR) – processed for the period needed to fulfil the order and perform the contract. Issuing and booking invoices and including them in the Controller’s records (Art. 6(1)(c) GDPR) – accounting data processed until the retention periods under applicable tax law expire. Establishing or defending against claims – legitimate interest of the Controller (Art. 6(1)(f) GDPR) – until the limitation period for claims under the contract expires. Archival or statistical purposes – legitimate interest (Art. 6(1)(f) GDPR), i.e. identifying returning customers – until an effective objection is raised or the purpose is achieved. |
|
Handling e-mail correspondence |
E-mail address, name and other information the user includes in the message. Providing this data is voluntary but necessary to send and respond to the message. |
Responding to the message – legitimate interest (Art. 6(1)(f) GDPR), i.e. replying to the message – processed for the period needed to respond and conduct correspondence. Archival purposes – legitimate interest (Art. 6(1)(f) GDPR), i.e. the ability to demonstrate facts in the future – until an effective objection is raised or the purpose is achieved. |
|
Administering the Store website |
IP address and data on user behaviour on the Store website. Providing the IP address and technical data is necessary to display the Store website correctly. Other data, e.g. on user behaviour, is collected only with the user’s consent via the cookie banner. |
Studying user activity on the website – consent (Art. 6(1)(a) GDPR) for data collected optionally via cookies. Managing the website – legitimate interest (Art. 6(1)(f) GDPR), i.e. ensuring website functionality – processed until outdated or no longer useful. |
|
Studying user activity on the Store website |
User device IP address, date and time of visit, time spent on the website, approximate location, browser type, and data on the user’s behaviour. Providing data is voluntary; its scope depends on the user’s choices in the cookie banner. The user may use the website without consenting to analytical tools, but accepting them helps the Controller improve the Store’s offer and functionality. |
Studying user activity – consent (Art. 6(1)(a) GDPR) for data collected optionally via analytical and marketing cookies. Optimizing the Store – legitimate interest (Art. 6(1)(f) GDPR), i.e. improving the Store’s operation and functionality. |
|
Registration of a user account in the Store |
Name, e-mail, billing address, delivery address, phone number, NIP and business data (optional – only for a company invoice). |
Performance of the account provision contract (Art. 6(1)(b) GDPR) – processed until the user deletes the account. Establishing or defending against claims (Art. 6(1)(f) GDPR) – until the limitation period expires. Archival or statistical purposes (Art. 6(1)(f) GDPR), i.e. identifying returning customers – as above. |
|
The Controller’s social media profiles |
Publicly available profile data, such as: profile name, name, image in the profile picture, data in comments and messages, statistical and advertising data collected by the social media platforms the Controller uses. Providing this data is voluntary but necessary to use the Controller’s profile or to contact it. When interacting with the Controller via social media, the platform is a separate controller of the user’s data and processes it under its own privacy policy: Meta Platforms Ireland Limited – https://privacycenter.instagram.com/policy; Google LLC – https://policies.google.com/privacy; TikTok Technology Limited – https://www.tiktok.com/legal/page/eea/privacy-policy/pl. |
Managing social media profiles and informing about the Controller’s activities and services – legitimate interest (Art. 6(1)(f) GDPR), i.e. running profiles and marketing – until an effective objection is raised or the purpose is achieved. If interested in the Controller’s products – steps to conclude a contract (Art. 6(1)(b) GDPR) – until the contract is concluded and performed, then until the limitation period under the Civil Code expires. Statistical purposes (Art. 6(1)(f) GDPR) – until an effective objection is raised or the purpose is achieved. |
|
Newsletter |
Name, e-mail, information on newsletter dispatch and the subscription date. Providing data is voluntary but necessary to receive the Newsletter. |
Subscription based on consent (Art. 6(1)(a) GDPR) – processed until consent is withdrawn, which may be done at any time. Marketing activities – legitimate interest (Art. 6(1)(f) GDPR), i.e. promoting the Controller’s own products or services – until an effective objection is raised or the purpose is achieved. Establishing or defending against claims (Art. 6(1)(f) GDPR) – until the limitation period expires. |
|
Reviews of services or products |
Name, username, image (where the user adds a review by private message on social media), e-mail address and other information the user includes in the review. Providing data is voluntary but necessary to submit a review. |
Adding a review is based on consent (Art. 6(1)(a) GDPR) – processed until consent is withdrawn, which may be done at any time. |
|
Complaint or withdrawal process |
Name, e-mail, billing address, delivery address, phone number, bank account number, NIP and business data. Providing data is voluntary but necessary to exercise the right to submit a complaint or withdraw from the contract. |
Conducting the complaint or withdrawal process (Art. 6(1)(c) GDPR) – processed until the process is completed. Establishing or defending against claims (Art. 6(1)(f) GDPR) – until the limitation period expires. Archival purposes (Art. 6(1)(f) GDPR) – until an effective objection is raised or the purpose is achieved. |
|
Keeping records required under the GDPR |
Name, e-mail, billing address, delivery address, phone number, NIP and business data. |
Keeping records required under the GDPR (Art. 6(1)(c) GDPR) – processed until the limitation period for claims expires. |
§3. Data recipients
1. The Controller will disclose personal data to the following categories of recipients, solely to the extent necessary to achieve the stated purposes:
– a) payment service providers such as Stripe, Apple Pay, Google Pay, Shop Pay, iDEAL, Bancontact, BLIK operators / banks – to handle payments,
– b) carriers and logistics operators – to deliver the shipment,
– c) we use hosting and IT infrastructure providers. Some of them are established outside the European Economic Area. In such cases, data is transferred on the basis of Article 46 GDPR, under standard contractual clauses approved by the European Commission. A detailed list of data recipients is available on request — simply write to support@maisonachi.com.
– d) the Store platform / software provider: Shopify International Limited (Ireland) and Shopify Inc. (Canada),
– e) providers of analytical and marketing tools: Google Analytics, Meta Pixel, Google Ads,
– f) newsletter dispatch system provider: the Store operates the Maison ACHI newsletter. Subscription is voluntary and requires providing an e-mail address and giving separate consent. Data is processed for the purpose of sending commercial and marketing information about the Maison ACHI brand (new collections, previews, offers), on the basis of consent — Art. 6(1)(a) GDPR. Consent may be withdrawn at any time by clicking the unsubscribe link in any message or by writing to support@maisonachi.com; withdrawal does not affect the lawfulness of processing carried out before withdrawal. Data is stored until consent is withdrawn. Dispatch is carried out via the Shopify platform (Shopify International Ltd.), acting as a data processor.
– g) entities providing accounting, legal and advisory services to the Controller,
– h) manufacturers of goods established within the EU – to exercise guarantee rights.
2. Entities processing data on behalf of the Controller (processors) do so under concluded data processing agreements and solely in accordance with the Controller’s instructions.
3. The Controller may disclose selected information about a Store user to the competent authorities or third parties that request such information, on an appropriate legal basis and in accordance with applicable law.
§4. Transfers of data outside the European Economic Area (EEA)
1. In connection with the Controller’s use of the Shopify platform and other analytical or marketing tools, personal data will be transferred outside the European Economic Area, including to the United States and Canada.
2. In such cases, the transfer takes place on the basis of an adequacy decision pursuant to Article 45 GDPR or appropriate safeguards referred to in Article 46 GDPR, in particular standard contractual clauses approved by the European Commission, or on the basis of a European Commission adequacy decision (e.g. the Data Privacy Framework for certified entities in the USA).
3. A copy of the safeguards applied may be obtained by contacting the Controller.
§5. Rights of data subjects
1. Data subjects have the following rights:
– a) the right of access to data and to obtain a copy of it (Art. 15 GDPR),
– b) the right to rectification of data (Art. 16 GDPR),
– c) the right to erasure of data (Art. 17 GDPR),
– d) the right to restriction of processing (Art. 18 GDPR),
– e) the right to data portability (Art. 20 GDPR),
– f) the right to object to processing based on legitimate interest, including profiling (Art. 21 GDPR),
– g) the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal (Art. 7(3) GDPR).
Not all of the above rights will apply in every case, as follows from the law. To obtain detailed information and to exercise these rights, please contact the Controller at support@maisonachi.com or the Controller’s registered office address indicated above.
2. The Controller responds to a request without undue delay, no later than within one month of receiving it.
3. Right to lodge a complaint: the data subject has the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (PUODO), ul. Moniuszki 1A, 00-014 Warsaw – if they consider that the processing of their data infringes the GDPR.
§6. Profiling and automated decision-making
1. To prevent fraud and secure payments, the Store uses a fraud analysis function provided by Shopify Inc. and by payment service providers. Under this function, order data (including address, payment data, IP address, device information) is automatically analysed and a risk level is assigned to each order — this constitutes profiling within the meaning of Article 4(4) GDPR.
2. The basis for processing is the Controller’s legitimate interest (Art. 6(1)(f) GDPR). The analysis serves solely to flag higher-risk orders for manual verification and does not constitute automated decision-making producing legal effects or similarly significantly affecting the Customer (Art. 22 GDPR).
3. Data under this function is processed by Shopify Inc.; it may be transferred outside the European Economic Area on the basis of standard contractual clauses approved by the European Commission. The Customer has the right to object to processing based on legitimate interest (Art. 21 GDPR).
§7. Cookies
The Store uses cookies and similar technologies. Detailed information on this is contained in a separate document – the Cookies Policy, available on the Store website.
§8. Data security
1. The Controller applies technical and organizational measures appropriate to the risks and categories of data processed, in particular protecting data against disclosure to unauthorized persons, loss or damage.
2. The connection to the Store is encrypted (SSL/TLS protocol).
§9. Changes to the Privacy Policy
1. The Controller reserves the right to amend this Privacy Policy in the event of changes in the law, technology or the manner in which the Store operates.
2. The current version of the Policy is published on the Store website each time, together with its effective date.