Privacy Policy
Last updated: February 17, 2025
1. Introduction
Brandsparkle Sp. z o.o. ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your information when you use our website and services.
2. Information We Collect
We may collect the following types of information:
- Contact Information: Name, email address, phone number, company name
- Business Information: VAT number, billing address, shipping address
- Project Information: Product specifications, formulations, designs
- Technical Data: IP address, browser type, device information, cookies
- Communication Records: Emails, chat logs, meeting notes
3. How We Use Your Information
We use your personal data for the following purposes:
- Providing manufacturing and co-packing services
- Processing orders and managing projects
- Communicating about your projects and inquiries
- Improving our website and services
- Legal compliance and regulatory requirements
- Fraud prevention and security
4. Legal Basis for Processing
We process your personal data based on:
- Contract: Processing necessary to fulfill our contract with you
- Legal Obligation: Compliance with tax, accounting, and regulatory requirements
- Legitimate Interests: Business operations, fraud prevention, and security
- Consent: Where you have given explicit consent (e.g., marketing communications)
5. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes outlined in this policy:
- Customer data: 10 years (legal requirement for tax/accounting)
- Project files: 7 years after project completion
- Marketing data: Until consent is withdrawn
- Website analytics: 26 months
6. Your Rights
Under GDPR, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data (where applicable)
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- SSL encryption for data transmission
- Access controls and authentication
- Regular security assessments
- Employee training on data protection
- Secure data storage with redundancy
8. Third-Party Processors
We may use third-party service providers to process your data:
- Cloud hosting providers (EU-based)
- Email service providers
- Payment processors
- Analytics providers
All third parties are contractually bound to process data only on our instructions and maintain appropriate security measures.
9. International Transfers
Your data is primarily stored and processed within the European Union. If we transfer data outside the EU, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions.
10. Contact Us
For privacy-related inquiries or to exercise your rights, contact us:
Data Protection Officer
Brandsparkle Sp. z o.o.
ul. Zlota 59
00-120 Warsaw, Poland
Email: [email protected]