Privacy Policy

Privacy Policy

PRIVACY POLICY OF THE FILLORA.STORE ONLINE STORE

§ 1. General information

  1. This Privacy Policy defines the rules for processing personal data of users and customers of the Fillora.store online store, available at www.fillora.store.
  2. The controller of personal data is:

Bella Barbara Wischott
ul. Jaworzyńska 7/1
00-634 Warszawa
Poland
NIP: 7731112993
E-mail: info@fillora.store
Phone / WhatsApp: +48 796 011 956

hereinafter referred to as the “Controller” or “Seller”.

  1. The Controller may be contacted regarding personal data at: info@fillora.store.
  2. The Controller processes personal data in accordance with applicable law, in particular Regulation (EU) 2016/679, known as GDPR.
  3. Using the online store may involve the processing of personal data for the purpose of creating an account, placing and fulfilling an order, handling payment, delivery, complaints, returns, customer communication, accounting, marketing and ensuring website security.

§ 2. Scope of processed data

  1. The Controller may process the following personal data:
    a) name and surname,
    b) company name,
    c) tax identification number or other company identification number, if provided,
    d) delivery address,
    e) billing address,
    f) e-mail address,
    g) phone number,
    h) order details,
    i) payment-related data received from the payment provider,
    j) complaint, return and correspondence data,
    k) IP address,
    l) technical data related to website use, including cookies or similar technologies.
  2. Providing personal data is voluntary, but necessary to create an account, place an order, complete delivery, issue a sales document, handle complaints or contact the Seller.
  3. Failure to provide data required to fulfill the order may prevent the conclusion or performance of the sales agreement.

§ 3. Purposes and legal bases of processing

  1. Personal data is processed for the following purposes:
    a) creating and managing a customer account,
    b) accepting, handling and fulfilling orders,
    c) processing payments,
    d) delivering orders,
    e) issuing invoices and keeping accounting records,
    f) handling complaints, returns and withdrawals,
    g) contacting the Customer and responding to messages,
    h) establishing, pursuing or defending against claims,
    i) ensuring website security and preventing abuse,
    j) sending newsletters or marketing information, if consent has been given,
    k) using analytical, marketing or advertising cookies, if consent is required and has been given.
  2. The legal bases for processing include performance of a contract, compliance with legal obligations, the Controller’s legitimate interest and consent, depending on the specific purpose.

§ 4. Data recipients

  1. Personal data may be transferred to entities supporting the Controller in running the online store, in particular:
    a) hosting and IT service providers,
    b) store platform providers,
    c) payment providers,
    d) banks,
    e) courier companies and carriers,
    f) accounting and tax service providers,
    g) e-mail service providers,
    h) analytical, marketing or advertising tool providers,
    i) customer service, complaint and return handling providers,
    j) public authorities, if required by law.
  2. Data is transferred only to the extent necessary for a given purpose.
  3. Payment providers and courier companies may act as separate data controllers in the scope in which they independently determine the purposes and means of processing.

§ 5. Transfer of data outside the European Economic Area

  1. The Controller may use tools provided by entities based outside the European Economic Area, in particular analytical, marketing, advertising, hosting or communication tools.
  2. If personal data is transferred outside the European Economic Area, such transfer takes place using appropriate safeguards required by GDPR, in particular standard contractual clauses or other mechanisms provided by law.
  3. The user may obtain more information about the safeguards by contacting the Controller.

§ 6. Data retention period

  1. Data related to order fulfillment is stored for the time necessary to perform the sales agreement and then for the period required by law or the limitation period for possible claims.
  2. Data included in accounting and tax documents is stored for the period required by applicable law.
  3. Data processed for handling complaints, returns or withdrawals is stored for the time necessary to handle the case and then for the limitation period for possible claims.
  4. Data processed on the basis of consent, for example for newsletter purposes, is processed until the consent is withdrawn.
  5. Technical data and cookie data are stored for the period resulting from browser settings, cookie settings or retention periods of specific tools.

§ 7. Rights of data subjects

  1. The data subject has the following rights:
    a) right of access to data,
    b) right to rectification of data,
    c) right to erasure of data,
    d) right to restriction of processing,
    e) right to data portability,
    f) right to object to processing,
    g) right to withdraw consent at any time, if processing is based on consent,
    h) right to lodge a complaint with the supervisory authority.
  2. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  3. To exercise these rights, please contact the Controller at: info@fillora.store.
  4. The Controller may request additional information necessary to confirm the identity of the person submitting the request.

§ 8. Newsletter and marketing

  1. The user may voluntarily consent to receiving newsletters or marketing information by electronic means.
  2. For newsletter purposes, the Controller processes the user’s e-mail address and, if applicable, name or other data provided during subscription.
  3. The user may unsubscribe from the newsletter at any time using the unsubscribe link in the e-mail or by contacting the Controller.

§ 9. Cookies and similar technologies

  1. The store uses cookies and similar technologies.
  2. Cookies are small text files stored on the user’s device while using the website.
  3. The store may use the following types of cookies:
    a) necessary cookies — required for the proper operation of the store, cart, login, payment and website security,
    b) analytical cookies — used to analyze website usage,
    c) functional cookies — used to remember user settings,
    d) marketing and advertising cookies — used for marketing, content personalization or measuring advertising effectiveness.
  4. Necessary cookies are used to ensure the proper operation of the website and do not require user consent.
  5. Analytical, marketing and advertising cookies are used in accordance with applicable law, in particular after obtaining user consent, if such consent is required.
  6. The user may change cookie settings in their browser or consent management panel, if available on the website.

§ 10. External tools

  1. The store may use external tools for:
    a) payment processing,
    b) delivery handling,
    c) website analytics,
    d) marketing and advertising,
    e) e-mail communication,
    f) website security,
    g) customer communication,
    h) sales statistics.
  2. External tool providers may process user data in accordance with their own privacy policies.

§ 11. Automated decision-making and profiling

  1. Personal data may be used for basic analysis of activity in the store, for example to assess marketing effectiveness or adjust website content.
  2. The Controller does not make decisions based solely on automated processing that would produce legal effects concerning users or similarly significantly affect them.

§ 12. Data security

  1. The Controller applies appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, alteration or disclosure.
  2. Access to personal data is limited to persons and entities for whom it is necessary to perform specific purposes.
  3. The store uses technical security measures, such as SSL encrypted connection, if active on the website.

§ 13. Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy, in particular in case of changes in law, store functionality, payment methods, delivery methods, external tools or scope of processed data.
  2. The current version of the Privacy Policy is always available on the store website.

Last updated: 2026-04-30

Dear User Please be advised that the shopping platform fillora.store and all information contained therein is intended for professionals related to aesthetic medicine.
By proceeding further you declare that: You are a professional related to aesthetic medicine, you are qualified in this field or you have a business related to the medical industry.