Privacy Policy
Effective from 1 May 2025.
1. Data controller
The controller of your personal data is EVS sp. z o.o., a Polish limited liability company with its registered office at ul. Bolesława Prusa 7A, 16-001 Kleosin, Poland, VAT EU: PL5423491568.
Contact with the Controller: kontakt@ledguard.pl
2. Purpose and legal basis of processing
We process your personal data for the following purposes:
- Order fulfilment — first name, surname, delivery address, e-mail, phone number. Legal basis: Article 6(1)(b) GDPR (performance of a contract).
- Issuing VAT invoices — company details, VAT ID. Legal basis: Article 6(1)(c) GDPR (legal obligation).
- Customer account — e-mail, order history. Legal basis: Article 6(1)(b) GDPR.
- Marketing — e-mail (with consent only). Legal basis: Article 6(1)(a) GDPR (consent).
- Site analytics — anonymous traffic data (Google Analytics 4). Legal basis: Article 6(1)(f) GDPR (legitimate interest).
3. Data recipients
We share your data only with entities necessary for fulfilling orders:
- Payment processors: Stripe Inc. (United States, Standard Contractual Clauses)
- Couriers: InPost S.A., DPD Polska sp. z o.o.
- E-mail provider: Resend Inc.
- Google LLC — Google Analytics 4 (IP anonymisation enabled)
We do not sell personal data to third parties.
4. Retention period
- Order data: 5 years from the end of the tax year (statutory tax obligation)
- Customer account data: until the account is deleted or 3 years from the last login
- Marketing consent: until consent is withdrawn
- Analytics data: 14 months (Google Analytics default TTL)
5. Your rights
Under the GDPR, you have the following rights:
- Access — the right to obtain a copy of your data
- Rectification — the right to have inaccurate data corrected
- Erasure — the right to have data deleted ("right to be forgotten")
- Restriction of processing — the right to restrict processing
- Portability — the right to receive your data in CSV/JSON format
- Objection — the right to object to marketing processing
- Withdrawal of consent — possible at any time (without affecting the lawfulness of processing carried out before withdrawal)
To exercise your rights, write to: kontakt@ledguard.pl. We will respond within 30 days.
You have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
6. Cookies
The ledguard.eu site uses cookies for the following purposes:
- Necessary — cart session, login, CSRF token
- Analytics — Google Analytics 4 (with consent)
- Marketing — Meta Pixel, Google Ads (with consent)
You can withdraw your consent at any time via your browser settings or the consent management panel available on the site.
7. Security
We apply technical and organisational measures to protect your data, including HTTPS/TLS encryption for all traffic, encryption of payment data by Stripe (PCI DSS certified), and regular database backups.