Dentistique.pl store privacy policy

effective from September 19, 2026

This Privacy Policy explains how we process the personal data of visitors to the website and online store operating at https://dentistique.pl (hereinafter: "Store") and what rights these individuals have. The document takes into account the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR). The principles of using cookies are described in a separate Cookie Policy.

§ 1 Data Controller

The controller of personal data is DENTISTIQUE spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw, ul. Złota 75A lok. 7, 00-819 Warsaw, entered into the Register of Entrepreneurs of the National Court Register kept by the District Court for the capital city of Warsaw in Warsaw, 13th Commercial Division of the National Court Register, under KRS number 0001254826, NIP: 5273227863, REGON: 545300036, share capital: 10,000 PLN (hereinafter: "Controller").

In matters concerning personal data, you can contact the Controller via e-mail at: bonjour@dentistique.pl or in writing to the registered office address. The Controller has not appointed a data protection officer.

§ 2 Purposes and legal bases for data processing

Depending on how you use the Store, we process the following categories of data: identification data (e.g., name and surname), contact data (e-mail address, phone number), order-related data, delivery and billing data (including invoice details), customer account data, newsletter-related data, data contained in correspondence, technical data (e.g., IP address, device and browser information), information provided in the toothpaste selection quiz, and information regarding granted consents.

We process personal data for the following purposes:

  • Execution of orders and sales contracts – including order acceptance and handling, product delivery, payment processing, and communication related to order fulfillment (Art. 6(1)(b) GDPR – performance of a contract).
  • Handling of recurring purchases (subscriptions) – if the Buyer uses them: fulfillment of subsequent orders as part of the subscription, management of delivery frequency, communication regarding the subscription, and handling of related payments (Art. 6(1)(b) GDPR – performance of a contract).
  • Maintaining a customer account – if the Buyer decides to create one (Art. 6(1)(b) GDPR).
  • Issuing sales documents and accounting – including receipts and invoices (Art. 6(1)(c) GDPR – legal obligation arising from tax and accounting regulations).
  • Handling complaints and declarations of withdrawal from the contract (Art. 6(1)(b) and (c) GDPR).
  • Sending newsletters – information about news, promotions, and discounts in the Store – based on voluntarily granted consent, which can be withdrawn at any time, e.g., by clicking the unsubscribe link in the message or by writing to bonjour@dentistique.pl (Art. 6(1)(a) GDPR). Sending commercial information and direct marketing by electronic means are conducted with the consent required by Art. 398 of the Act of July 12, 2024 – Electronic Communications Law. Withdrawal of consent does not affect the lawfulness of processing performed before its withdrawal.
  • Toothpaste selection quiz – calculating product matching based on answers provided in the quiz, presenting recommendations, and – upon the user's request – sending the result to the provided e-mail address (Art. 6(1)(a) GDPR – consent; to the extent that answers constitute health data – Art. 9(2)(a) GDPR – explicit consent). Details are described below.
  • Handling correspondence – via e-mail or telephone (Art. 6(1)(f) GDPR – Controller's legitimate interest consisting of providing a response).
  • Analytics and website traffic statistics – using optional analytical tools: Google Analytics 4 (traffic statistics) and Microsoft Clarity (analysis of user interactions with the site, e.g., clicks, scrolling, and session playback), used only after obtaining the user's consent (Art. 6(1)(a) GDPR); details in § 7 and in the Cookie Policy.
  • Establishing, pursuing, or defending against claims (Art. 6(1)(f) GDPR – Controller's legitimate interest).

Toothpaste selection quiz. The Store features a toothpaste selection quiz where the user answers questions regarding their needs, preferences, teeth, and gums. The answers are used to calculate product suitability and present recommendations; they are stored in the user's browser while using the quiz. The user may provide an e-mail address to receive the quiz result. The link to the result may contain the user's answers in a shortened form, enabling the result to be reconstructed. Answers used to prepare and send the result message are deleted immediately after it is sent – only the e-mail address remains, along with information that it was provided in the quiz and the designation of the recommended product. The e-mail address may continue to be processed in accordance with the newsletter rules described above. Answers regarding the condition of teeth or gums may in certain cases constitute health data within the meaning of the GDPR – in such scope, we process them only based on the user's explicit consent (Art. 9(2)(a) GDPR), which can be withdrawn at any time. The quiz is for informational and product-related purposes – it does not constitute a medical diagnosis or dental advice.

§ 3 Data recipients

Personal data may be transferred to the following categories of recipients – solely to the extent necessary to fulfill individual purposes:

  • online store platform provider – Shopify International Ltd. based in Ireland (Shopify platform), on which the Store operates and where data from orders, customer accounts, newsletter subscriptions, and e-mail addresses provided in the toothpaste selection quiz are stored;
  • payment operator – Shopify Payments (Shopify International Ltd.), handling electronic payments in the Store (payment cards, BLIK, Apple Pay, Google Pay, Shop Pay, Klarna);
  • order management system provider – Apilo sp. z o.o., whose software is used for handling orders and preparing shipments, acting on behalf of the Controller as a data processor;
  • carriers and logistics operators handling deliveries – in particular InPost sp. z o.o. (courier shipments);
  • e-mail service provider – Google Ireland Ltd. (Google Workspace), handling the bonjour@dentistique.pl mailbox;
  • hosting and DNS service provider – cyber_Folks S.A., handling the dentistique.pl domain;
  • entities providing accounting, legal, and IT services to the Controller;
  • analytical tool providers – Google Ireland Ltd. (Google Analytics 4) and Microsoft Ireland Operations Limited (Microsoft Clarity) – to the extent described in § 7 and only after consent is granted;
  • consent management tool provider – iSenseLabs based in Sofia (Bulgaria), provider of the Consentmo application, used for managing cookie preferences and storing information about granting, denying, or changing consent;
  • public authorities – only when the obligation to provide data arises from legal regulations.

§ 4 Transfer of data outside the European Economic Area

As a rule, we process data within the European Economic Area. The Shopify platform provider belongs to the Shopify Inc. group based in Canada and may process data also in Canada and the United States. In connection with the use of Google and Microsoft tools, data (in particular data related to cookies) may be transferred to the United States or other countries outside the EEA. Transfers of data outside the EEA are conducted using mechanisms provided for in the GDPR, in particular: European Commission adequacy decisions (e.g., regarding Canada), the EU-U.S. Data Privacy Framework – if the recipient is covered by it, standard contractual clauses approved by the European Commission, or other mechanisms provided by the GDPR. Information about the security measures used can be obtained by contacting the Controller.

§ 5 Data retention period

  • data related to orders – for the duration of the contract execution, and then until the expiration of the appropriate statute of limitations for claims arising from the contract;
  • data contained in accounting and tax documents – for the period required by relevant tax and accounting regulations;
  • customer account data – until the account is deleted by the Buyer or the Controller upon their request;
  • data processed based on consent (newsletter, analytical and marketing cookies) – until consent is withdrawn, provided that information necessary to demonstrate the fact of granting consent may be stored longer – until the expiration of the statute of limitations for potential claims, for the purpose of defending against them;
  • answers provided in the toothpaste selection quiz – stored in the user's browser, and in the case of sending the result via e-mail, deleted immediately after the message is sent; e-mail address provided in the quiz – in accordance with the newsletter rules;
  • correspondence – for the period necessary to handle the matter, no longer than until the expiration of the statute of limitations for potential claims.

§ 6 Rights of data subjects

Every person whose data we process has the right to:

  • access their data and receive a copy thereof;
  • rectify (correct) data;
  • delete data ("right to be forgotten");
  • restrict processing;
  • transfer data;
  • object to processing based on the Controller's legitimate interest;
  • withdraw consent at any time – without affecting the lawfulness of processing carried out before its withdrawal;
  • lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.

To exercise the above rights, simply send a message to bonjour@dentistique.pl.

Providing data is voluntary, but necessary to place an order, create an account, subscribe to the newsletter, receive a quiz result via e-mail, or receive a response to a message. The Controller does not make decisions towards Buyers based solely on automated processing that would produce legal effects. The toothpaste selection quiz automatically calculates product matching and presents recommendations – this does not produce legal effects for the user nor does it significantly affect them in a similar way within the meaning of Art. 22 GDPR.

§ 7 Cookies

The Store uses cookies – small text files saved on the user's device. We use the following categories of cookies:

  • essential – enabling the proper functioning of the website (e.g., shopping cart handling, logging into an account, remembering cookie preferences); set by the Shopify platform and the Consentmo consent management tool; their use does not require consent as they are necessary for providing the service requested by the user (Art. 399(3) of the Act – Electronic Communications Law); if information from these cookies constitutes personal data, we process it to ensure the Store's operation and contract fulfillment (Art. 6(1)(b) GDPR), to ensure the Store's security (Art. 6(1)(f) GDPR), and information about granting, denying, or changing consent – for the purpose of demonstrating compliance with regulations (Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR);
  • analytical – Google Analytics 4 (Google Ireland Ltd.), used to create website traffic statistics, and Microsoft Clarity (Microsoft Ireland Operations Limited), used to analyze user interactions with the site (e.g., clicks, scrolling, and session playback); used only with the user's consent (Art. 6(1)(a) GDPR);
  • marketing – we do not currently use marketing cookies; if we begin using them, they will be launched only after consent is granted in the cookie banner, and this Policy will be updated.

Consent to analytical and marketing cookies can be granted, denied, or withdrawn at any time in the cookie banner displayed during the first visit and in the cookie settings available on the Store's website. Cookies can also be deleted and blocked in your browser settings, although blocking essential cookies may make it difficult to use the Store. A detailed description of the cookies used is contained in the Cookie Policy.

§ 8 Data security

The Controller uses technical and organizational measures to ensure the protection of processed personal data appropriate to the risks, in particular an encrypted SSL/TLS connection, data access control, and cooperation only with entities that provide sufficient guarantees to implement GDPR requirements.

§ 9 Final provisions

The Controller reserves the right to change this Privacy Policy, particularly in the event of changes in legal regulations, tools used, or the scope of the Store's activities. The current version of the Policy is always available at https://dentistique.pl/pages/polityka-prywatnosci. In matters not regulated, the provisions of the GDPR and relevant Polish law shall apply.