Szef Donald

Legal

Privacy Policy

Last updated 24 June 2026

This Privacy Policy explains how we process your personal data when you use our website and ordering service, in line with the EU General Data Protection Regulation (GDPR) and Polish data-protection law (RODO).

1. Who we are (data controller)

Szef Donald
Ul. Ks. Piotra Ściegiennego 68a
25-115 Kielce
Polska
NIP 6572959741
info@szefdonald.com · +48 883 953 589

For privacy requests you can also write to info@szefdonald.com.

2. What data we collect

  • Account: name, email, phone, password (hashed), language preference.
  • Orders & delivery: delivery address and map location, order contents, notes, order history.
  • Payments: handled by our payment provider — we never see or store your full card number, only a token and the last 4 digits / card brand.
  • Contact, reviews, reservations, loyalty & referrals: the details you provide in those forms (where the feature is enabled).
  • Technical: limited usage/diagnostic data and security logs (no advertising cookies — see our Cookie Policy).

3. Why we use it & legal basis

  • Performing your order / account (Art. 6(1)(b) GDPR): taking and delivering orders, managing your account, customer support.
  • Consent (Art. 6(1)(a)): the marketing newsletter — only if you opt in, withdrawable anytime.
  • Legitimate interests (Art. 6(1)(f)): securing the service, preventing fraud, and basic, privacy-friendly diagnostics.
  • Legal obligation (Art. 6(1)(c)): keeping invoices/accounting records.

4. Processing activities (Art. 13/14 GDPR)

The table below summarises each processing activity by data flow.

Activity / data flowData categoriesSourcePurposeLegal basisRequired?RecipientsTransfer mechanismRetention
Account & authenticationname, email, phone, password (hashed), language preferencefrom youcreating and running your account, authenticationcontract (Art. 6(1)(b))required to create an accounthosting (Contabo)Within EEA; if outside — Standard Contractual Clauses (see §6)while the account exists
Orders (guest & registered)contact details (name, email, phone), order contents, notes, amountsfrom youtaking, fulfilling and confirming your ordercontract (Art. 6(1)(b))required to fulfil the orderhosting (Contabo), email, SMS, payment providerWithin EEA; if outside — Standard Contractual Clauses (see §6)as required by accounting law
Addresses & map locationdelivery address, geolocation pin (map point)from you; address lookup via OpenStreetMap/Nominatimdetermining the delivery area and delivering the ordercontract (Art. 6(1)(b))required for delivery ordersOpenStreetMap/Nominatim (address search), hosting (Contabo)Within EEA; if outside — Standard Contractual Clauses (see §6)with the order, or in your address book until deleted
Online paymentspayment token, last 4 digits / card brand, amount; anti-fraud signals (e.g. IP, device) processed by the payment providerfrom you via the payment provider’s secure form (we never see the full card number)taking payment, fraud prevention (eService / Global Payments fraud checks, 3-D Secure)contract (Art. 6(1)(b)); legitimate interest — payment security (Art. 6(1)(f))required for online payment (cash on delivery is an alternative where available)payment provider (eService / Global Payments) acting as separate controller/processorWithin EEA; if outside — Standard Contractual Clauses (see §6)payment references with the order records
Receipts, accounting, refundsinvoice/receipt data, amounts, refunds and disputesgenerated from the orderissuing the document and handling refunds/disputeslegal obligation (Art. 6(1)(c))required by tax lawemail provider (receipt), payment provider, hostingWithin EEA; if outside — Standard Contractual Clauses (see §6)the period required by tax law (currently 5 years)
Contact messagesname, email, message contentfrom youresponding to your enquirylegitimate interest — handling enquiries (Art. 6(1)(f))optional; without them we cannot replyemail provider, hostingWithin EEA; if outside — Standard Contractual Clauses (see §6)for as long as needed to handle the matter
Newsletter (double opt-in)email, consent statusfrom yousending the marketing newsletter after confirmed opt-inconsent (Art. 6(1)(a))optional; consent can be withdrawn anytimeemail provider, hostingWithin EEA; if outside — Standard Contractual Clauses (see §6)until consent is withdrawn / you unsubscribe
SMS notificationsphone number, order statusfrom you (order/account)order-status notificationscontract (Art. 6(1)(b))if enabled — for order notificationsTwilio (if enabled), hostingWithin EEA; if outside — Standard Contractual Clauses (see §6)for the duration of the order
Reviews, reservations, loyalty, referrals (if enabled)data provided in that form (e.g. review text, points, referral codes)from yourunning the relevant feature when it is enabledcontract or consent, depending on the featureoptionalhosting (Contabo)Within EEA; if outside — Standard Contractual Clauses (see §6)until deleted or the feature is disabled
Security, audit & server logs, backupsIP address, technical events, access logs, database/file backupsautomatically as you use the servicesecurity, diagnostics, abuse prevention, disaster recoverylegitimate interest — service security (Art. 6(1)(f))inherent to running the servicehosting (Contabo); diagnostics (PostHog/Sentry) if enabledWithin EEA; if outside — Standard Contractual Clauses (see §6)a limited log/backup retention period

5. Recipients & processors

We use trusted service providers (processors) acting on our instructions. The processors actually used are:

  • Contabo — server hosting, database, file storage and backups (our infrastructure provider).
  • eService (part of Global Payments) — online card/BLIK payment processing and fraud prevention on its hosted payment page, when online payments are enabled. eService acts as an independent controller for some of this processing under its own privacy policy.
  • Email provider — transactional email (order confirmations, receipts, account messages) via Resend or our SMTP provider.
  • Twilio — SMS order notifications, if enabled.
  • OpenStreetMap / Nominatim — address search and the map shown at checkout.
  • Diagnostics (PostHog / Sentry) — product analytics and error monitoring, only if enabled in production.

We do not sell your personal data.

6. Transfers outside the EEA

Some providers may process data outside the European Economic Area. Where that is the case, transfers are protected by appropriate safeguards (e.g. Standard Contractual Clauses).

7. How long we keep it

We keep account and order data for as long as you have an account and as required to provide the service. Invoicing/accounting records are retained for the period required by Polish tax law (currently 5 years). Newsletter data is kept until you unsubscribe.

8. Your rights

You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent at any time (without affecting prior processing). We respond to requests within one month (extendable for complex requests as permitted by the GDPR). To exercise any of these, contact us at info@szefdonald.com. You also have the right to lodge a complaint with the Polish supervisory authority — the President of the Personal Data Protection Office (UODO), uodo.gov.pl.

Where online payments are enabled, an automated fraud assessment may be applied to a transaction by our payment provider (eService / Global Payments) to protect against fraud; you can contact us to ask about a decision.

You can ask us to delete or anonymise your account. We retain only the records we are required to keep (e.g. accounting, fraud and dispute records) for the applicable period.

9. Cookies

We use essential and functional cookies, plus conditional payment-provider cookies during online payment. For the full list and how to manage them, see our Cookie Policy.

10. Changes

We may update this policy; the “last updated” date above reflects the current version. Material changes will be highlighted on this page.

Questions about this policy? Contact us