This Privacy Policy describes how the personal data of users of the website available at www.czapkireklamowe.pl (hereinafter: the “Shop” or the “Website”) are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: the “GDPR”), the Act of 10 May 2018 on the Protection of Personal Data, the Act of 18 July 2002 on the Provision of Services by Electronic Means and the Act of 12 July 2024 – Electronic Communications Law (hereinafter: the “PKE”), as regards access to terminal equipment and direct marketing.

The Shop is B2B in nature and is addressed to businesses. It offers caps and promotional clothing that can be decorated to the customer's own design (embroidery, print, patches), from a single piece, with quotes prepared using an online designer that uses artificial intelligence.

1. Data controller

The controller of your personal data is Jakub Słowik, conducting business activity under the business name “JM Group”, entered in the Central Register and Information on Economic Activity (CEIDG):

  • Tax identification number (NIP): 1231097508
  • Statistical identification number (REGON): 140921585
  • Registered office address (registered address / address for service): ul. Mickiewicza 1, 05-504 Złotokłos
  • Office and correspondence address: ul. Instalatorów 23, brama 9, 02-237 Warszawa

Contact details for matters relating to the protection of personal data:

  • E-mail: [email protected]
  • Telephone: +48 22 224 29 92
  • Showroom: ul. Instalatorów 23, brama 9, Warszawa

The Controller has not appointed a data protection officer. In all matters relating to the processing of personal data, the Controller may be contacted using the contact details above.

2. Definitions and scope

For the purposes of this Policy, the following terms have the meanings given below:

  • Controller – the entity indicated in section 1 above, which determines the purposes and means of the processing of personal data.
  • Personal data – information relating to an identified or identifiable natural person.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
  • PKE – the Act of 12 July 2024 – Electronic Communications Law (in force since 10 November 2024, replacing, to the relevant extent, the previous Telecommunications Law).
  • User – a natural person using the Shop, including a person acting on behalf of or for the benefit of a business (e.g. an employee or a company representative).
  • Shop / Website – the website available at www.czapkireklamowe.pl.
  • Online designer – a software tool used for quoting and visualising decoration, which uses artificial intelligence.
  • Cookies – computer data stored on the User's terminal equipment.

This Policy applies to personal data processed in connection with the use of the Shop, including maintaining a customer account, placing orders, using the online designer and the offer system, using live chat, contacting the Controller, and the use of cookies and analytics and marketing tools.

3. What data we process, for what purposes and on what legal basis

The table below sets out the purposes of processing personal data, the categories of data processed and the legal bases for their processing. Where processing involves storing or reading data on terminal equipment (cookies and similar technologies), the ePrivacy layer described in section 7 (Article 173 PKE) also applies.

Purpose of processing Categories of data Legal basis
Creating and maintaining a B2B customer account (registration, logging in) First name, surname, e-mail address, password (stored in encrypted form), account settings Article 6(1)(b) GDPR – performance of the contract for maintaining an account and taking steps at the request of the data subject prior to entering into a contract
Fulfilment of orders and recording of company details and delivery addresses First name, surname, company name, tax ID (NIP), address, postcode, town/city, country, telephone, e-mail address Article 6(1)(b) GDPR – performance of the contract of sale and delivery
Issuing and storing invoices and keeping accounting records Company name, tax ID (NIP), address, data necessary for the accounting document Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject (tax legislation and the Accounting Act)
Contacting the Controller and preparing a quote/offer on request (including offers from the online designer and offers prepared by a sales representative in the CRM) First name, surname, e-mail address, telephone, tax ID (NIP), company name, address, town/city, content of the enquiry/comments, decoration parameters, quantities and prices of items Article 6(1)(b) GDPR – taking steps at the request of the data subject prior to entering into a contract; with regard to the data of contact persons representing a company (where they are not a party to the contract), also Article 6(1)(f) GDPR – the Controller's legitimate interest in handling enquiries and conducting B2B business correspondence with the appropriate person at the counterparty
Use of the online designer — uploading a logo/artwork and automatic quotation of decoration (including estimation of the stitch count by the Controller's proprietary machine learning model, which runs exclusively on its own infrastructure) Uploaded image file (logo/artwork), e-mail address, IP address, file name, decoration parameters, result of the analysis Article 6(1)(b) GDPR – preparation of a quote or fulfilment of an order with decoration; with regard to linking the file to an existing business relationship, Article 6(1)(f) GDPR – the Controller's legitimate interest in retaining the counterparty's history of quotes and artwork for handling subsequent orders
Access to the customer panel (logging in via an activation link / magic link) E-mail address, access token, IP address, timestamp Article 6(1)(b) GDPR – providing access to one's own offers and orders; Article 6(1)(f) GDPR – legitimate interest in ensuring security and verifying the authorisation of the person logging in
Acceptance of an offer by the User (public acceptance link) IP address, timestamp of acceptance Article 6(1)(b) GDPR – conclusion of the contract; Article 6(1)(f) GDPR – legitimate interest in retaining proof of acceptance of the offer (accountability, defence against claims)
Handling live chat Content of the chat conversation, e-mail address or other contact details provided voluntarily during the conversation, IP address, device and browser data, chat online identifiers Article 6(1)(f) GDPR – the Controller's legitimate interest in handling enquiries on an ongoing basis and communicating with persons using the Shop; to the extent that the conversation is aimed at entering into or performing a contract, also Article 6(1)(b) GDPR
Newsletter and direct marketing (e-mail / SMS) E-mail address, telephone number, content of the consent and its timestamp Article 6(1)(a) GDPR – the User's consent to the processing of data for marketing purposes; the basis for sending marketing communications by means of electronic communication is Article 10 of the Act on the Provision of Services by Electronic Means and Article 398 PKE (consent to the use of telecommunications terminal equipment and automated calling systems for direct marketing purposes)
Analysis of the effectiveness of communications (e-mail opens, clicks on links in offers) The fact and time of opening a message, the fact and time of clicking a link, association with the customer's e-mail address Article 6(1)(f) GDPR – the Controller's legitimate interest in assessing the effectiveness of the offers and communications sent and tailoring communications to the needs of recipients
Analysis of traffic and of the quality of use of the Shop (Google Analytics 4, Microsoft Clarity) Online identifiers (cookies), IP address, device and browser data, browsing events, recordings of interactions within a session, heatmaps Article 6(1)(a) GDPR – consent given via the consent manager (Klaro), “analytics” category, in conjunction with Article 173 PKE (consent to access to terminal equipment)
Identification of companies visiting the Shop – script and cookies on the website (Apollo.io – B2B marketing) IP address, online identifiers, data on pages viewed Article 6(1)(a) GDPR – consent given via the consent manager (Klaro), “marketing” category, in conjunction with Article 173 PKE (consent to access to terminal equipment)
Firmographic profiling and enrichment of company data from external databases (Apollo.io) Data identifying the company/organisation, firmographic information, business contact details of persons acting on behalf of or for the benefit of companies (not obtained from the data subject) Article 6(1)(f) GDPR – the Controller's legitimate interest in conducting B2B direct marketing and acquiring business customers; processing preceded by a balancing test (LIA). Details regarding the source and the information obligation – section 11
Displaying reviews of the company (Google Places API) No personal data of the User transferred externally; server-to-server request for the company's public reviews Article 6(1)(f) GDPR – the Controller's legitimate interest in presenting reviews of the company on the Website
Establishment, exercise and defence of claims Data necessary for the above purposes, to the extent necessary to pursue or defend claims Article 6(1)(f) GDPR – the Controller's legitimate interest in protecting its rights and pursuing/defending claims
Operation of the Shop and consent management (session, basket, security, remembering the cookie decision) Session cookies, security token (CSRF), cookie remembering the consent decision Article 6(1)(b) GDPR – provision of the Shop service at the User's request and Article 6(1)(f) GDPR – legitimate interest in ensuring the proper and secure operation of the Website; access to these cookies is exempt from the consent requirement as necessary (Article 173(3) PKE)

4. Data retention periods

We store personal data for the period necessary to achieve the purposes for which they were collected and, after that period has elapsed, for the period required by law or until the limitation period for any claims has expired.

  • Customer account data – for as long as the account exists; the account may be deleted at the User's request (we carry out the deletion within 7 days of the request). After the account has been deleted, the data may be stored until the limitation period for claims has expired (as a rule up to 6 years, and in the case of claims related to business activity up to 3 years).
  • Data contained in invoices and accounting records – for 5 years counted from the end of the calendar year in which the tax payment deadline expired.
  • Data for the fulfilment of orders and delivery – for the duration of the fulfilment of the order and thereafter until the complaints period and the limitation period for claims have expired (as a rule up to 6 years, and for claims related to business activity up to 3 years).
  • Offers from the online designer – an offer expires 14 days after it is issued; we delete offers that have not been accepted no later than 12 months from the date of expiry, unless they have led to the establishment of a business relationship.
  • Uploaded logo/artwork files – we store them for the time necessary to prepare the quote or carry out the order; if the quote has not led to an order, we delete the files no later than 12 months after the last contact regarding the quote. A file uploaded in the online designer which has not been saved in a project or sent for a quote is stored by us (together with the file name and IP address) for 14 days from upload, so that it is possible to return to a project that has been started, after which it is automatically deleted.
  • Content of chat conversations (transcripts) – we store it for no longer than 12 months from the end of the conversation, unless the conversation relates to entering into or performing a contract or to a claim – in which case for the limitation period for claims.
  • Customer panel access tokens (magic link) – a token remains valid for 24 hours, after which it expires and is deleted.
  • Data processed on the basis of consent (newsletter, e-mail/SMS marketing, analytics and marketing cookies) – until consent is withdrawn and, in the case of cookies, no later than the expiry of the validity period of the cookie concerned (specified in section 7). We keep proof that consent was given until the limitation period has expired for any claims related to demonstrating that it was given.
  • Firmographic and contact data obtained for B2B marketing purposes (Apollo.io) – until an objection to direct marketing is raised and, in the absence of an objection, for no longer than 24 months from the last contact or activity indicating an interest in cooperation.
  • Other data processed on the basis of legitimate interest – until an objection is effectively raised or until the purpose justifying the processing ceases to exist (e.g. completion of the handling of an enquiry or the end of the business relationship), whichever occurs first.

5. Data recipients and processors

Your personal data may be disclosed to entities that support the Controller in running the Shop and providing services. Some of them are processors, acting on the basis of data processing agreements and solely in accordance with the Controller's instructions; others are separate controllers, who independently determine the purposes and means of processing with regard to their own services (in which case their own privacy policies also apply). Below we set out a list of the recipients together with their role.

Entity Role and nature Country / location
Hosting service provider Hosting of the Shop and infrastructure (the Shop server and the online designer server) – processor (data processing agreement) Poland (EU)
Microsoft Corporation (Microsoft Clarity) Qualitative analytics, session recording and heatmaps (activated after consent is given) – processor USA
Apollo.io (ZenLeads Inc. / Apollo.io) Identification of companies visiting the Shop and firmographic profiling for B2B marketing purposes. With regard to the script on the website, it acts as a processor; with regard to its own firmographic databases and making them available, it may act as a separate controller USA
Google LLC / Google Ireland Ltd. (Google Analytics 4) Traffic analytics (activated after consent is given) – processor USA / Ireland
Google LLC (Google Fonts) Web font provider – recipient of the User's IP address when fonts are downloaded (separate controller of the technical data of the request) USA
Google LLC (Google Places API) Provider of company review data – server-to-server requests, without transferring the User's personal data USA
Tawk.to Inc. Handling live chat – processor USA

In addition, depending on requirements, the recipients of the data may include:

  • the provider of the system used for issuing invoices and keeping accounts – for the purpose of issuing and circulating accounting documents (processor, data processed in the EEA);
  • the provider of SMS messaging services – with regard to SMS notifications (processor, data processed in the EEA);
  • the courier company delivering the consignments – as a separate controller with regard to carrying out the delivery;
  • entities authorised to obtain data under applicable law (e.g. public authorities), solely upon their justified request.

Note: this Policy does not name an online payment operator because, as at the date on which it was drawn up, no payment gateway integration was identified on the Website. If online payments are implemented, the Policy will be supplemented with the relevant operator, the categories of payment data and the transfer mechanism.

6. Transfers of data outside the European Economic Area (EEA)

Some data recipients are based outside the European Economic Area, primarily in the United States. Data are transferred to a third country only using one of the mechanisms provided for in Chapter V GDPR (Articles 44–49). Below we indicate the mechanism for each recipient in the USA:

Recipient in the USA Transfer mechanism
Google LLC (Google Analytics 4, Google Fonts, Google Places API) European Commission adequacy decision – EU-US Data Privacy Framework (Google LLC is included on the list of certified entities)
Microsoft Corporation (Microsoft Clarity) EU-US Data Privacy Framework (Microsoft is included on the list of certified entities); additionally, standard contractual clauses (SCCs)
Apollo.io (ZenLeads Inc. / Apollo.io) EU-U.S. Data Privacy Framework — Apollo (ZenLeads Inc.) is listed as a DPF participant; additionally, standard contractual clauses (SCCs) under Apollo's Data Processing Addendum (DPA).
Tawk.to Inc. EU-U.S. Data Privacy Framework (tawk.to has self-certified under the DPF) and standard contractual clauses (SCCs) under the DPA.

Quotation of decoration in the online designer, including estimation of the stitch count based on the uploaded logo, is carried out using the Controller's proprietary machine learning model running on its own infrastructure — the uploaded logo/artwork is not transferred outside the EEA for this purpose.

You may obtain a copy of the safeguards applied, or information on where they have been made available, by contacting the Controller.

7. Cookies and tracking tools

The Shop uses cookies and similar technologies. Two layers of regulation should be distinguished:

  • ePrivacy layer (access to the device) – the mere storing or reading of information on the User's terminal equipment is governed by Article 173 PKE. For cookies necessary to provide the service requested by the User, consent is not required (Article 173(3) PKE). For other cookies (analytics, marketing), consent to access to the device is required.
  • GDPR layer (processing of data) – further processing of data obtained from cookies takes place on the bases indicated in section 3 (for necessary cookies – Article 6(1)(b)/(f) GDPR; for analytics and marketing cookies – Article 6(1)(a) GDPR, i.e. consent).

7.1. Necessary cookies

They are required for the Shop to function properly and do not require the User's consent. They make it possible, among other things, to maintain the session, operate the basket, log in and ensure security.

Cookie Purpose Storage period
PrestaShop-* (and security token) Customer session, basket, protection against attacks (CSRF) Until the browser is closed / in accordance with the session settings
klaro-czapki Remembering the User's decision regarding consents to cookies 365 days

7.2. Analytics cookies (consent required)

They make it possible to analyse how the Shop is used and to improve its operation. They are activated only after consent has been given in the “analytics” category.

Tool / provider Purpose Cookies and storage period
Google Analytics 4 (Google) Traffic analysis and measuring effectiveness _ga (2 years), _gid (24 hours), _gat (1 minute)
Microsoft Clarity (Microsoft) Qualitative analysis: session recording, heatmaps MUID (approx. 1 year), _clck (1 year), _clsk (1 day) and others: CLID, MR, SM, ANONCHK

7.3. Marketing cookies (consent required)

They are used to identify companies visiting the Shop and for B2B marketing activities. They are activated only after consent has been given in the “marketing” category.

Tool / provider Purpose Cookies and storage period
Apollo.io Website Visitors (ZenLeads Inc. / Apollo.io) Identification of companies visiting the Shop (de-anonymisation of the IP address to the name of a company/organisation) and firmographic profiling for B2B marketing purposes. The tool identifies companies, not private consumers. Consent to cookies applies only to the script running on the website; further enrichment of company data from external databases is described in section 11 and is based on Article 6(1)(f) GDPR. apollo* / _apollo* cookies

7.4. Other third-party technologies

  • Google Fonts – the Shop loads web fonts from Google's servers. Each time the website is visited, the User's IP address is transferred to Google (USA), regardless of cookie consents. This is the current situation, not a planned one. The Controller is analysing moving the fonts to its own server (self-hosting), which would eliminate this transfer.
  • Tawk.to (live chat) – the Shop uses a live chat widget provided by Tawk.to Inc., enabling real-time contact. At present, the chat script loads on every page regardless of the decision expressed in the consent manager and may store its own cookies (e.g. __tawkuuid, valid for approx. 6 months) even before consent has been given. The Controller is working on bringing the chat within the consent mechanism.

7.5. Managing cookie consents

Consents to analytics and marketing cookies are collected on an opt-in basis (disabled by default) via the Klaro consent manager. You may change or withdraw your decisions at any time using the “Cookie settings” button available in the Shop. You may also manage cookies in your browser settings, including deleting or blocking them. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. Restricting the use of cookies may affect certain functions of the Shop.

8. Profiling and automated decision-making

As part of our B2B marketing activities, we use profiling consisting in the identification of companies visiting the Shop and their firmographic profiling (the Apollo.io tool). This profiling concerns companies/organisations, not private consumers. The Microsoft Clarity tool analyses behaviour within a session (recording of interactions, heatmaps) only after consent has been given.

The Controller does not make decisions concerning Users based solely on automated processing which would produce legal effects concerning them or similarly significantly affect them within the meaning of Article 22 GDPR. The online designer using artificial intelligence is solely a tool supporting the quotation and visualisation of decoration, and the final offer is verified and approved by a human.

Right to object to direct marketing

You have the right to object at any time – on grounds relating to your particular situation or, with regard to direct marketing, unconditionally – to the processing of your data for direct marketing purposes, including firmographic profiling carried out using the Apollo.io tool (Article 21(2) and (4) GDPR). Once an objection to direct marketing has been raised, the Controller ceases to process the data for that purpose. You may raise an objection in any form, using the contact details indicated in section 1. This right may be exercised free of charge and is communicated clearly and separately from any other information.

9. Rights of data subjects

In connection with the processing of personal data, you have the following rights:

  • the right of access to the data and to obtain a copy of them;
  • the right to rectification (correction) of the data;
  • the right to erasure of the data (the “right to be forgotten”);
  • the right to restriction of processing;
  • the right to data portability – with regard to data processed by automated means on the basis of consent or a contract;
  • the right to object to processing based on legitimate interest (Article 6(1)(f) GDPR) – on grounds relating to your particular situation; with regard to direct marketing (including Apollo.io profiling), the objection is unconditional and is described separately in section 8;
  • the right to withdraw consent at any time – without affecting the lawfulness of processing carried out before its withdrawal. Withdrawal of consent is the appropriate instrument for data processed on the basis of Article 6(1)(a) GDPR, i.e. for the newsletter, e-mail/SMS marketing and analytics and marketing cookies. Please note that withdrawal of consent (which concerns processing based on consent) is a right separate from an objection (which concerns processing based on legitimate interest);
  • the right to lodge a complaint with the supervisory authority, which is the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warszawa), if you consider that the processing of your data infringes the law.

To exercise the above rights, please contact the Controller using the details indicated in section 1. The Controller will respond without undue delay, as a rule within one month of receipt of the request.

10. Voluntary nature of providing data

Providing personal data is voluntary; however, in some cases it is necessary in order to achieve a specific purpose:

  • providing the data necessary to create an account, place an order, prepare a quote or carry out a delivery is a condition for entering into and performing the contract – failure to provide them will make it impossible to carry out these actions;
  • the provision of invoice data (including company name, tax ID (NIP), address) results from the Controller's legal obligations regarding the issuing of accounting documents;
  • providing data for marketing purposes (newsletter, e-mail/SMS marketing) and giving consent to analytics and marketing cookies is entirely voluntary and is not a condition for using the Shop.

11. Source of data (information obligation where data have not been obtained from the data subject)

As a rule, we process personal data obtained directly from you.

With regard to B2B direct marketing carried out using the Apollo.io tool, we also process data obtained other than from the data subject. Pursuant to Article 14 GDPR, we inform you that:

  • Source of data – the data come from company databases maintained by Apollo.io and may be enriched on the basis of information about activity in the Shop (the visitor's IP address mapped to a company/organisation). Apollo.io aggregates data from, among other things, publicly available sources (public registers, company websites, professional profiles) and from its own datasets.
  • Categories of data – name of the company/organisation, identifying and firmographic data (including industry, size, location, the company's address and contact details) and business contact details of persons acting on behalf of or for the benefit of the company (including first name and surname, job title, business e-mail address, business telephone number).
  • Purpose and basis – conducting B2B direct marketing and acquiring business customers, on the basis of Article 6(1)(f) GDPR (legitimate interest, preceded by a balancing test/LIA).
  • Fulfilment of the information obligation – with regard to persons whose data have been obtained from external databases, we fulfil the information obligation at the latest within one month of obtaining the data and, if the data are to be used for communication with the person concerned, at the latest at the time of the first communication (Article 14(3) GDPR). In the first communication, we refer to this Policy and to the information on the right to object (section 8).

Please note that persons whose data are enriched from external databases may never have visited the Shop or used the consent manager. For this reason, the basis for processing these data is not consent to cookies but the Controller's legitimate interest, in respect of which an unconditional right to object is available with regard to direct marketing.

12. Data security

The Controller applies appropriate technical and organisational measures to ensure the protection of the personal data processed, appropriate to the threats and to the categories of data protected. In particular:

  • the connection to the Shop is secured with an encrypted protocol (SSL/TLS);
  • account passwords are stored in encrypted form (using a hash function);
  • only authorised persons have access to the data, to the extent necessary to perform their tasks;
  • access to the customer panel is secured with tokens of limited validity;
  • the Controller works only with processors that provide sufficient guarantees of implementing appropriate data protection measures.

13. Changes to the Privacy Policy

The Controller reserves the right to make changes to this Privacy Policy, in particular in the event of changes in legislation, in the technologies used or in the scope of the services provided. The current version of the Policy is always available in the Shop. Users may be informed of significant changes in the manner adopted in the Shop.

Date of last update: 25 June 2026