Legal
Privacy Policy
Last updated 24 June 2026
This Privacy Policy explains how we process your personal data when you use our website and ordering service, in line with the EU General Data Protection Regulation (GDPR) and Polish data-protection law (RODO).
1. Who we are (data controller)
Szef Donald
Ul. Ks. Piotra Ściegiennego 68a
25-115 Kielce
Polska
NIP 6572959741
info@szefdonald.com · +48 883 953 589
For privacy requests you can also write to info@szefdonald.com.
2. What data we collect
- Account: name, email, phone, password (hashed), language preference.
- Orders & delivery: delivery address and map location, order contents, notes, order history.
- Payments: handled by our payment provider — we never see or store your full card number, only a token and the last 4 digits / card brand.
- Contact, reviews, reservations, loyalty & referrals: the details you provide in those forms (where the feature is enabled).
- Technical: limited usage/diagnostic data and security logs (no advertising cookies — see our Cookie Policy).
3. Why we use it & legal basis
- Performing your order / account (Art. 6(1)(b) GDPR): taking and delivering orders, managing your account, customer support.
- Consent (Art. 6(1)(a)): the marketing newsletter — only if you opt in, withdrawable anytime.
- Legitimate interests (Art. 6(1)(f)): securing the service, preventing fraud, and basic, privacy-friendly diagnostics.
- Legal obligation (Art. 6(1)(c)): keeping invoices/accounting records.
4. Processing activities (Art. 13/14 GDPR)
The table below summarises each processing activity by data flow.
| Activity / data flow | Data categories | Source | Purpose | Legal basis | Required? | Recipients | Transfer mechanism | Retention |
|---|---|---|---|---|---|---|---|---|
| Account & authentication | name, email, phone, password (hashed), language preference | from you | creating and running your account, authentication | contract (Art. 6(1)(b)) | required to create an account | hosting (Contabo) | Within EEA; if outside — Standard Contractual Clauses (see §6) | while the account exists |
| Orders (guest & registered) | contact details (name, email, phone), order contents, notes, amounts | from you | taking, fulfilling and confirming your order | contract (Art. 6(1)(b)) | required to fulfil the order | hosting (Contabo), email, SMS, payment provider | Within EEA; if outside — Standard Contractual Clauses (see §6) | as required by accounting law |
| Addresses & map location | delivery address, geolocation pin (map point) | from you; address lookup via OpenStreetMap/Nominatim | determining the delivery area and delivering the order | contract (Art. 6(1)(b)) | required for delivery orders | OpenStreetMap/Nominatim (address search), hosting (Contabo) | Within EEA; if outside — Standard Contractual Clauses (see §6) | with the order, or in your address book until deleted |
| Online payments | payment token, last 4 digits / card brand, amount; anti-fraud signals (e.g. IP, device) processed by the payment provider | from you via the payment provider’s secure form (we never see the full card number) | taking payment, fraud prevention (eService / Global Payments fraud checks, 3-D Secure) | contract (Art. 6(1)(b)); legitimate interest — payment security (Art. 6(1)(f)) | required for online payment (cash on delivery is an alternative where available) | payment provider (eService / Global Payments) acting as separate controller/processor | Within EEA; if outside — Standard Contractual Clauses (see §6) | payment references with the order records |
| Receipts, accounting, refunds | invoice/receipt data, amounts, refunds and disputes | generated from the order | issuing the document and handling refunds/disputes | legal obligation (Art. 6(1)(c)) | required by tax law | email provider (receipt), payment provider, hosting | Within EEA; if outside — Standard Contractual Clauses (see §6) | the period required by tax law (currently 5 years) |
| Contact messages | name, email, message content | from you | responding to your enquiry | legitimate interest — handling enquiries (Art. 6(1)(f)) | optional; without them we cannot reply | email provider, hosting | Within EEA; if outside — Standard Contractual Clauses (see §6) | for as long as needed to handle the matter |
| Newsletter (double opt-in) | email, consent status | from you | sending the marketing newsletter after confirmed opt-in | consent (Art. 6(1)(a)) | optional; consent can be withdrawn anytime | email provider, hosting | Within EEA; if outside — Standard Contractual Clauses (see §6) | until consent is withdrawn / you unsubscribe |
| SMS notifications | phone number, order status | from you (order/account) | order-status notifications | contract (Art. 6(1)(b)) | if enabled — for order notifications | Twilio (if enabled), hosting | Within EEA; if outside — Standard Contractual Clauses (see §6) | for the duration of the order |
| Reviews, reservations, loyalty, referrals (if enabled) | data provided in that form (e.g. review text, points, referral codes) | from you | running the relevant feature when it is enabled | contract or consent, depending on the feature | optional | hosting (Contabo) | Within EEA; if outside — Standard Contractual Clauses (see §6) | until deleted or the feature is disabled |
| Security, audit & server logs, backups | IP address, technical events, access logs, database/file backups | automatically as you use the service | security, diagnostics, abuse prevention, disaster recovery | legitimate interest — service security (Art. 6(1)(f)) | inherent to running the service | hosting (Contabo); diagnostics (PostHog/Sentry) if enabled | Within EEA; if outside — Standard Contractual Clauses (see §6) | a limited log/backup retention period |
5. Recipients & processors
We use trusted service providers (processors) acting on our instructions. The processors actually used are:
- Contabo — server hosting, database, file storage and backups (our infrastructure provider).
- eService (part of Global Payments) — online card/BLIK payment processing and fraud prevention on its hosted payment page, when online payments are enabled. eService acts as an independent controller for some of this processing under its own privacy policy.
- Email provider — transactional email (order confirmations, receipts, account messages) via Resend or our SMTP provider.
- Twilio — SMS order notifications, if enabled.
- OpenStreetMap / Nominatim — address search and the map shown at checkout.
- Diagnostics (PostHog / Sentry) — product analytics and error monitoring, only if enabled in production.
We do not sell your personal data.
6. Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where that is the case, transfers are protected by appropriate safeguards (e.g. Standard Contractual Clauses).
7. How long we keep it
We keep account and order data for as long as you have an account and as required to provide the service. Invoicing/accounting records are retained for the period required by Polish tax law (currently 5 years). Newsletter data is kept until you unsubscribe.
8. Your rights
You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent at any time (without affecting prior processing). We respond to requests within one month (extendable for complex requests as permitted by the GDPR). To exercise any of these, contact us at info@szefdonald.com. You also have the right to lodge a complaint with the Polish supervisory authority — the President of the Personal Data Protection Office (UODO), uodo.gov.pl.
Where online payments are enabled, an automated fraud assessment may be applied to a transaction by our payment provider (eService / Global Payments) to protect against fraud; you can contact us to ask about a decision.
You can ask us to delete or anonymise your account. We retain only the records we are required to keep (e.g. accounting, fraud and dispute records) for the applicable period.
9. Cookies
We use essential and functional cookies, plus conditional payment-provider cookies during online payment. For the full list and how to manage them, see our Cookie Policy.
10. Changes
We may update this policy; the “last updated” date above reflects the current version. Material changes will be highlighted on this page.
Questions about this policy? Contact us