Privacy policy
Effective: 12 May 2026 · Version 1.0
1. Data controller
The controller of your personal data is:
Praveer Lakhani, sole proprietor trading as "Smart Trade Praveer Lakhani"
al. Krakowska 27, 05-090 Sękocin Nowy, Poland
VAT (NIP): PL7010945438 · REGON: 384383242
Privacy contact: privacy@printextiles.com
General contact: shop@printextiles.com · +48 509 788 633
We have not appointed a Data Protection Officer. Please address all enquiries to the email above.
2. Purposes, legal bases, and retention periods
We process your data for the following purposes:
| Purpose | Legal basis | Retention period |
|---|---|---|
| Fulfilling orders and contracts (intake, quoting, printing, delivery, order-related contact) | Art. 6(1)(b) GDPR – performance of contract | Until completion + statutory limitation period (3 years B2B, 6 years general) |
| Issuing invoices and maintaining accounting records | Art. 6(1)(c) GDPR – legal obligation (Polish Accounting Act, Tax Ordinance) | 5 years from end of the tax year in which the payment deadline fell |
| Operating the Customer account on the Service | Art. 6(1)(b) GDPR – performance of the account-service contract | Until account deletion + 30 days (claim safeguard) |
| Handling complaints, withdrawals, and contact enquiries | Art. 6(1)(b) and (f) GDPR – contract / legitimate interest | 3 years from case closure |
| Marketing of our own products to existing Customers (offers, new releases by email) | Art. 6(1)(f) GDPR – legitimate interest of the controller | Until objection, max. 24 months from the last order |
| Site traffic analytics (Google Analytics 4) – analytics cookies | Art. 6(1)(a) GDPR – your consent (cookie banner) | Until withdrawal, max. 14 months (GA4 default) |
| Security of the Service, abuse detection (server logs, anti-spam data) | Art. 6(1)(f) GDPR – legitimate interest | Logs: 12 months. Anti-spam (rate-limit): 24 hours |
| Asserting or defending against legal claims | Art. 6(1)(f) GDPR – legitimate interest | Until the limitation period for claims expires |
3. Categories of data processed
Depending on the activity, we process the following categories:
- Identification data: first name, last name, company name
- Contact data: email address, phone, postal address
- Business data (B2B): VAT number, REGON, industry
- Order data: order history, product specifications, artwork files submitted for printing
- Payment data: we do not store card details — these are handled by the payment processor
- Technical data: IP address, session identifier, browser type, operating system
- Analytics data (on consent): Google Analytics cookie identifiers, anonymised IP, on-site events
4. Recipients of data
Your data may be transferred to the following categories of recipients (only to the extent necessary):
- Hosting provider – storage of Service data (hosting.com / cPanel hosting)
- Online payment operator – transaction processing (Viva Wallet or equivalent — to be confirmed after integration)
- Courier companies – delivery fulfilment (DPD, InPost, FedEx, DHL — depending on Customer's choice)
- Accounting office – maintenance of the controller's accounting records
- Email / SMTP provider – transactional email delivery
- Google LLC – Google Analytics 4 service (only with your consent)
- Google reCAPTCHA – bot protection on contact and registration forms
- Entities authorised by law – courts, law-enforcement bodies, tax authorities — only on request and to the extent required
All processors acting on our behalf have signed data-processing agreements compliant with art. 28 GDPR.
5. Transfers outside the EEA
Some of our providers are based in the United States (Google LLC). Transfers to the US are based on:
- Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate protection of personal data under the EU-US Data Privacy Framework (DPF) — Google LLC holds a current DPF certification.
- Additional Standard Contractual Clauses (SCC) as a fallback mechanism.
We do not transfer data to other third countries.
6. Your rights
Under GDPR you have the following rights:
- Right of access to your data (art. 15)
- Right of rectification of inaccurate data (art. 16)
- Right to erasure ("right to be forgotten") (art. 17)
- Right to restriction of processing (art. 18)
- Right to data portability in a structured format (art. 20)
- Right to object to processing based on legitimate interest, in particular marketing (art. 21)
- Right to withdraw consent – at any time, without affecting the lawfulness of processing before withdrawal (art. 7(3)). Cookie consent is withdrawn via the banner or the "Change cookie preferences" link in the footer.
- Right to lodge a complaint with the supervisory authority – in Poland: the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl). EU residents may also approach their local supervisory authority.
To exercise these rights, email privacy@printextiles.com. We reply within 30 days (extendable by 60 days in complex cases — you will be notified).
7. Voluntary provision of data
Providing personal data is voluntary, but:
- Without identification and contact data, we cannot conclude a sales contract or fulfil an Order.
- Without a VAT number, we cannot issue a VAT invoice to a company.
- Without consent to analytics cookies, the site still works — you only lose the ability for us to improve it based on anonymous statistics.
8. Profiling and automated decision-making
We do not make decisions affecting you based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect you (art. 22 GDPR).
9. Cookies
Rules on cookies, their categories, and consent management are set out in our separate Cookie policy.
10. Data security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, modification, or loss, in particular: encrypted connections (HTTPS/TLS), passwords stored as bcrypt hashes, restricted employee access to data on a need-to-know basis, regular backups, and anti-spam protection on forms (Google reCAPTCHA v3).
11. Changes to this policy
Customers with accounts will be notified by email of material changes at least 14 days before they take effect. The current version of the policy is always available at this URL.