Privacy

Privacy policy

This document states who processes your data, for what purpose, on what legal basis, who receives it and how long it is kept. Without generalities, because nothing follows from generalities.

Effective from:

1.Who is the controller

1.The controller is Artur Hebenstreit, carrying out unregistered business activity under the AEJaCA brand, correspondence address: ul. Nowy Świat 33 lok. 13, 00-029 Warszawa.

2.Contact on data matters: contact@aejaca.com, phone +48 780 737 786.

3.No data protection officer has been appointed, because the law does not require one here. All data matters are handled by the controller in person.

2.Where your data comes from

1.From you and only you: the contact form, an order, a newsletter signup, a conversation with the assistant on the site, or an email. We do not buy databases and do not harvest data from other services.

3.Purposes, legal bases and retention

1.Each purpose has its own basis and its own period. The list is complete, not illustrative.

  • β€’Handling an order, including delivery and contact about the job. Basis: Article 6(1)(b) GDPR, performance of a contract. Period: for the duration of the order, then until claims become time-barred, usually 6 years.
  • β€’Accounting and sales records. Basis: Article 6(1)(c) GDPR, legal obligation. Period: 5 years from the end of the year in which the tax obligation arose.
  • β€’Complaints, withdrawals and defence against claims. Basis: Article 6(1)(c) and (f) GDPR. Period: until claims become time-barred.
  • β€’Quoting and answering an enquiry, also when it does not end in an order. Basis: Article 6(1)(b) GDPR, steps prior to entering into a contract. Period: 24 months from the last contact.
  • β€’Files uploaded for a quote (3D models, artwork). Basis: as above. Period: 30 days from upload if no order follows; with an order, together with its documentation.
  • β€’Newsletter and marketing messages. Basis: Article 6(1)(a) GDPR, your consent. Period: until consent is withdrawn, which is possible at any time and needs no justification.
  • β€’Conversation with the assistant on the site. Basis: Article 6(1)(f) GDPR, answering questions and improving the answers. Period: 12 months.
  • β€’Visit statistics, without identifying a person. Basis: Article 6(1)(f) GDPR. Period: 24 months.
  • β€’Abuse prevention, including a shortened record of the IP address with an order or a conversation. Basis: Article 6(1)(f) GDPR. Period: 12 months.

2.The IP address is stored only as an irreversible hash, used to count requests from one place, not to establish who sent them.

3.What happens to an order once its period runs out: the sales record itself stays, because tax law requires it, but your data leaves it. After six years we erase the name, phone number, delivery address and hashed IP from the order, and replace the email address with a placeholder. Only amounts, dates, the order number and what was bought remain. A job does this daily; it does not depend on anyone remembering.

4.Raw messages from the payment provider, kept to settle a disputed payment, are cleared after 12 months. The record that a payment happened, and for how much, stays with the order.

4.Who receives the data

1.We do not sell data and do not share it with anyone for their own marketing. We do rely on services without which the site would not run at all. Each of them processes data on our instructions:

  • β€’Railway Corp. (United States) and Cloudflare, Inc. (United States), running the application, the database and the site.
  • β€’Google Ireland Ltd., email, panel sign-in and the business profile with reviews.
  • β€’OpenAI Ireland Ltd., running the assistant on the site.
  • β€’Autopay S.A. (Sopot, Poland), payment handling. Autopay is a separate controller of payment data; we have no access to card details or bank credentials.
  • β€’InPost S.A. and courier companies, delivery. They receive the name, the address or locker number and the phone number.
  • β€’The workflow automation provider (n8n), sending notifications and messages.

2.Data may also be passed to public authorities where the law requires it.

5.Transfers outside the European Economic Area

1.Some of the services we use have servers or parent companies outside the European Economic Area, mainly in the United States. This concerns hosting of the application and the database, and the assistant on the site.

2.Transfers rely on standard contractual clauses approved by the European Commission or on an adequacy decision, depending on the provider. A copy of the safeguards applied is available on request.

3.The practical point for you: the content of a conversation with the assistant leaves the European Economic Area. Do not enter data there that you would rather not send outside. For anything requiring personal data, use the contact form or email.

6.Your rights

1.You have the right to:

  • β€’access your data and receive a copy of it,
  • β€’have inaccurate data corrected and incomplete data completed,
  • β€’have data erased, unless a legal obligation stands in the way, for example the duty to keep sales records,
  • β€’restrict processing,
  • β€’port data you gave us on the basis of consent or a contract,
  • β€’object to processing based on our legitimate interest,
  • β€’withdraw consent at any time, without affecting the lawfulness of what was done before the withdrawal.

2.To exercise any of these rights, an email to contact@aejaca.com is enough. We answer without undue delay and within one month at the latest.

3.You also have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.

7.Is providing data mandatory

1.Providing data is voluntary, but without some of it the service cannot be delivered. Placing an order requires an email address, a full name and a phone number: the name goes on the parcel label, the courier calls before delivery, and the locker texts the pickup code. Courier delivery also requires an address.

2.A newsletter signup needs an email address and consent. You can unsubscribe at any time.

8.Automated decisions and profiling

1.We do not take decisions based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you. We do not profile you for advertising.

2.The calculators on the site compute a price from the parameters you enter. That is arithmetic on numbers, not an assessment of a person.

9.Data stored in your browser

1.The site stores a few things in the browser, without which it would not work or would work worse:

  • β€’the contents of the basket, so it survives a page refresh,
  • β€’calculator settings, so they need not be entered again,
  • β€’the chosen light or dark mode,
  • β€’the assistant conversation, for the duration of one visit.

2.These are necessary for the service you asked for, so they require no consent. We use no tracking files, we have no advertising or third-party advertising tools, and we embed no social network pixels.

3.Visit statistics are kept in-house, without identifying a person and without sending anything outside. They store nothing in your browser: events go straight to our server, and the visit identifier dies with the page, so it cannot link two visits by the same person.

10.Security

1.The connection to the site is encrypted. Access to the admin panel requires a Google sign-in from a list of permitted addresses. Payment details never reach our servers; the payment provider handles them.

2.Bank account numbers and payment system keys live only in the server configuration, never in the site's code.

11.Changes to this policy

1.Version effective from 2026-08-03. We announce material changes on the site, and newsletter subscribers also receive a message.

Contact on data matters