Privacy Policy

§1 Data Controller

The Data Controller of personal data collected through the online store https://whalehug.com/ (hereinafter referred to as the “Store”) is: WYOLA Aleksandra Wyporkiewicz, Ferdynanda Magellana 37/6, 51-505 Wrocław, Poland, Tax ID (NIP): 8971724495, email: contact@whalehug.com (hereinafter referred to as the “Controller”).

§2 Categories, Purposes, and Legal Bases of Processing

The Controller processes personal data in compliance with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). The details of processing are outlined below:

Personal Data CategoriesProcessing PurposeLegal Basis under GDPRRetention Period
Contact & Delivery Details (Name, email, shipping address, phone)Order processing, fulfillment, shipment, and customer supportArt. 6(1)(b) GDPR (Necessary for contract performance)For the period necessary to complete the contract and secure potential claims
Transactional & Billing Logs (Payment status, invoice metadata)Compliance with accounting, bookkeeping, and tax regulationsArt. 6(1)(c) GDPR (Compliance with a legal obligation)Standard statutory retention period under local tax laws
Return & Warranty Submissions (Claim records, return tracking, photos)Processing statutory withdrawal requests, returns, and warranty claimsArt. 6(1)(c) GDPR (Compliance with a legal obligation)2 years from delivery date (statutory warranty period)
Technical & Tracking Data (IP addresses, clickstream logs, device type)Analytics, performance optimization, and personalized advertisingArt. 6(1)(f) GDPR (Legitimate interest) or Art. 6(1)(a) GDPR (Consent)Until consent is withdrawn or an objection is submitted

§3 Data Recipients and Subprocessors

  1. To ensure seamless order fulfillment and Store operation, the Controller shares personal data with authorized third-party service providers.. All recipients are contractually bound under Article 28 GDPR to process data strictly in accordance with the Controller’s instructions:

    a) Production, Fulfillment, and Delivery Partners – To fulfill and deliver your orders, we share your shipping and contact details (such as your name, delivery address, and email) with our production and logistics partners located within the European Union. These partners use this information solely to print, package, and ship your ordered items directly to your address.

    b) Payment Gateway Providers – Secure payment processors managing checkout transactions.

    c) IT & Technical Infrastructure Providers – Hosting services and customer support systems.

§4 International Data Transfers

When transferring personal data outside the European Economic Area (EEA), the Controller ensures that appropriate safeguarding mechanisms under Chapter V of the GDPR are utilized, specifically the Standard Contractual Clauses (SCCs) approved by the European Commission, alongside rigorous technical encryption protocols.

§5 Rights of Data Subjects

Data subjects possess the following statutory rights under the GDPR:

  1. Right of Access – To obtain information on how their personal data is processed and request copies of the data.
  2. Right to Rectification – To request corrections or updates to inaccurate or incomplete personal data.
  3. Right to Erasure (“Right to be Forgotten”) – To demand deletion of personal data under specific statutory grounds.
  4. Right to Restriction of Processing – To restrict processing activities in legally defined circumstances.
  5. Right to Data Portability – To receive personal data in a structured, machine-readable format.
  6. Right to Object – To object to data processing carried out based on legitimate interests or for direct marketing.
  7. Right to Withdraw Consent – To withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
  8. Right to Lodge a Complaint – To file a complaint with a supervisory authority (such as the Polish Urząd Ochrony Danych Osobowych – UODO).

§6 Security Measures

The Controller implements robust technical and organizational security measures, including SSL/TLS transfer encryption, database access restrictions, and secure API data transmission protocols, to protect personal data from unauthorized access, loss, alteration, or disclosure.