Privacy Policy

PRIVACY AND COOKIE POLICY

www.evolpe.shop

In force as of: 14 September 2026

This document sets out the rules for processing personal data and for using cookies and similar technologies on the website available at www.evolpe.shop (the “Site”).

It has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”), the Polish Personal Data Protection Act of 10 May 2018, and Article 173 of the Polish Telecommunications Act of 16 July 2004.

I. Data Controller

The controller of your personal data is Evolpe Consulting Group Spółka z ograniczoną odpowiedzialnością spółka komandytowa, with its registered office in Poznań, ul. Piątkowska 161, 60-650 Poznań, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court Poznań – Nowe Miasto i Wilda in Poznań under KRS number 0000494749, tax ID (NIP) 7811892697 (the “Controller”).

Contact regarding personal data protection:

E-mail: office@evolpe.shop

Phone: +48 783 372 094

Postal address: ul. Piątkowska 161, 60-650 Poznań, Poland

II. Purposes, legal bases and retention periods

We process your personal data only for specified, explicit and legitimate purposes:

Purpose Legal basis Scope of data Retention period
Conclusion and performance of the sales contract, order and delivery handling Art. 6(1)(b) GDPR – necessary for the performance of a contract name, address, e-mail, phone, company details, tax ID for the duration of the contract
Maintaining a user account on the Site Art. 6(1)(b) GDPR – performance of the account service agreement username, e-mail, password (hashed), order history until the account is deleted
Compliance with accounting and tax obligations Art. 6(1)(c) GDPR – legal obligation (Polish Accounting Act, Tax Ordinance) invoice and accounting data 5 years from the end of the tax year
Handling complaints, statutory warranty and guarantee claims Art. 6(1)(b) and (c) GDPR contact details, order data, content of the claim until claims become time-barred
Responding to enquiries sent via the contact form Art. 6(1)(f) GDPR – legitimate interest (communication with interested parties) name, e-mail, phone, message content up to 12 months after the correspondence ends
Sending the newsletter and marketing information Art. 6(1)(a) GDPR – consent; Art. 10 of the Polish Act on Electronic Services and Art. 172 of the Telecommunications Act e-mail address, first name until consent is withdrawn
Statistics and analysis of Site traffic Art. 6(1)(a) GDPR – consent (statistical cookies); Art. 6(1)(f) GDPR – legitimate interest (cookieless statistics) cookie identifier, IP address, device data, pages visited up to 24 months or until consent is withdrawn
Marketing, remarketing and identification of visiting companies Art. 6(1)(a) GDPR – consent cookie identifiers, IP address, activity on the Site until consent is withdrawn, max. 24 months
Ensuring security, protection against abuse and spam Art. 6(1)(f) GDPR – legitimate interest IP address, server logs, browser data up to 12 months
Establishing, exercising or defending legal claims Art. 6(1)(f) GDPR – legitimate interest data necessary to substantiate a claim until claims become time-barred

Providing your data is voluntary; however, where it is necessary to conclude and perform a contract or to comply with a legal obligation, failure to provide it makes it impossible to process the order or deliver the service.

III. Your rights

In connection with the processing of your personal data, you have the following rights under the GDPR:

  1. Right of access (Art. 15 GDPR) – to obtain confirmation as to whether we process your data, to access it and to receive a copy.
  2. Right to rectification (Art. 16 GDPR) – to have inaccurate data corrected and incomplete data completed.
  3. Right to erasure, the “right to be forgotten” (Art. 17 GDPR) – to request deletion of your data, for example where it is no longer necessary for the purposes for which it was collected, or where you have withdrawn your consent.
  4. Right to restriction of processing (Art. 18 GDPR) – to request that operations on your data be suspended, e.g. while its accuracy is verified.
  5. Right to data portability (Art. 20 GDPR) – to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller. This applies to data processed by automated means on the basis of consent or a contract.
  6. Right to object (Art. 21 GDPR) – to object at any time to processing based on our legitimate interest. Where data is processed for direct marketing purposes, the objection is unconditional – we will stop such processing immediately.
  7. Right to withdraw consent (Art. 7(3) GDPR) – at any time and without giving reasons; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
  8. Right not to be subject to a decision based solely on automated processing (Art. 22 GDPR).

To exercise any of these rights, please contact us at office@evolpe.shop. We respond without undue delay and no later than one month from receipt of the request.

Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych)
ul. Stawki 2, 00-193 Warsaw, Poland
uodo.gov.pl

IV. Recipients of the data

Your data may be disclosed to the following categories of recipients, solely to the extent necessary to achieve the purposes described above:

  • hosting and server infrastructure providers,
  • providers of the analytics and marketing tools listed in Section VI,
  • electronic payment operators – for transaction handling,
  • courier companies and postal operators – for delivery,
  • accounting office and tax advisors,
  • law firms – in connection with pursuing or defending claims,
  • public authorities – only where disclosure is required by law.

We have concluded data processing agreements pursuant to Art. 28 GDPR with all entities processing data on our behalf.

V. Transfers outside the European Economic Area

Some of the tools we use are supplied by entities that may process data outside the European Economic Area, in particular in the United States.

This concerns primarily Google services (Google Ireland Limited, with possible transfer to Google LLC in the USA). Such transfers take place on the basis of:

  • the European Commission implementing decision of 10 July 2023 establishing an adequate level of data protection under the EU–U.S. Data Privacy Framework, with respect to entities certified under that framework, and
  • Standard Contractual Clauses (SCC) approved by the European Commission pursuant to Art. 46(2)(c) GDPR, together with supplementary safeguards.

The Plausible Analytics tool and the Mautic system are hosted on the Controller’s own infrastructure within the European Union – data from these tools is not transferred outside the EEA.

You have the right to obtain a copy of the safeguards applied by contacting us at office@evolpe.shop.

VI. Cookies and similar technologies

Cookies are small text files stored on your terminal device when you use the Site. Alongside cookies we also use technologies with similar effect, such as the browser’s localStorage and sessionStorage.

1. Managing your consent

On your first visit to the Site we display a consent banner where you can accept or reject individual cookie categories. Only cookies strictly necessary for the Site to function are used without your consent.

Changing or withdrawing consent at any time

You can change your settings by clicking the “Manage consent” button visible in the bottom-right corner of every page of the Site. Withdrawing consent is as easy as giving it and carries no negative consequences.

You can also delete and block cookies in your browser settings. Restricting cookies may, however, affect certain features of the Site, in particular the shopping cart and the checkout process.

2. Categories of cookies used

Category Purpose Legal basis Description
Necessary
(functional)
Ensuring the basic operation of the Site Art. 173(3) of the Telecommunications Act – consent not required Cart, session and login handling, language and currency selection, remembering your cookie decision, spam protection
Preferences Remembering individual user settings Art. 6(1)(a) GDPR – consent Remembering choices that affect the appearance and behaviour of the Site
Statistics Audience measurement and analysis of how the Site is used Art. 6(1)(a) GDPR – consent Counting visits, traffic sources and page popularity in order to improve the Site
Marketing Marketing, remarketing, identification of companies visiting the Site Art. 6(1)(a) GDPR – consent Building profiles for advertising purposes, measuring campaign effectiveness, embedding third-party content

3. Detailed list of services and cookies

Category: Necessary (used without consent)

Service Provider Cookies / data Purpose Duration
WooCommerce Controller
(Automattic software)
woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*, wc_cart_hash_* and wc_fragments_* (localStorage / sessionStorage) Shopping cart, purchase session and checkout handling session – 48 hours
Complianz Controller cmplz_policy_id, cmplz_banner-status, cmplz_functional, cmplz_preferences, cmplz_statistics, cmplz_marketing, cmplz_consented_services Remembering your cookie decision 365 days
Polylang Controller pll_language Remembering the selected language version of the Site 1 year
WooCommerce Multi Currency Controller wmc_current_currency, wmc_ip_info Remembering the selected currency; determining the country from the IP address in order to suggest the appropriate currency up to 30 days
Cap (anti-spam mechanism) Controller
(cap.evolpe.cloud)
no cookies; script and WebAssembly module loaded from the jsDelivr CDN Protecting forms against automated spam not applicable
Google reCAPTCHA Google Ireland Limited _GRECAPTCHA and related identifiers Protecting login and registration forms against automated attacks. Used only on the user account page and the login page. up to 6 months

Category: Statistics (consent required)

Service Provider Cookies / data Purpose Duration
Google Analytics 4
(property G-HLH3N14Y4L)
Google Ireland Limited _ga, _ga_HLH3N14Y4L Traffic measurement and analysis of user behaviour and Site performance. The service runs in Google Consent Mode v2: until consent is given it does not store identifiers on your device and data is transmitted only as anonymised signals without ad personalisation. up to 24 months
Google Tag Manager
(container GTM-NC7B486)
Google Ireland Limited does not set its own cookies Tag management tool that controls the firing of the remaining tags in line with your choices in the consent banner not applicable
Plausible Analytics Controller – self-hosted instance
(plausible.evolpe.it, EU server)
does not use cookies or any identifiers stored on your device; does not collect data allowing identification of an individual Aggregated audience statistics for the Site. As nothing is stored on the terminal device and no personal data is collected, the tool operates on the basis of the Controller’s legitimate interest (Art. 6(1)(f) GDPR). not applicable

Category: Marketing (consent required)

Service Provider Cookies / data Purpose Duration
Albacross Albacross Nordic AB (Sweden) nQ_cookieId, nQ_userVisitId Identifying companies visiting the Site on the basis of their IP address for B2B marketing purposes up to 12 months
WooCommerce – order attribution
(Sourcebuster)
Controller sbjs_first, sbjs_current, sbjs_first_add, sbjs_current_add, sbjs_session, sbjs_udata, sbjs_migrations Determining the traffic source an order originated from, in order to assess the effectiveness of marketing activities session – up to 6 months
Mautic Controller – self-hosted instance
(mautic.evolpe.it, EU server)
mtc_id, mtc_sid Handling the newsletter sign-up form available in the footer of every page and the contact forms, and linking Site activity to a marketing contact up to 12 months

4. Content embedded from external services

As at the date of this Policy, the Site does not embed content from external platforms – it contains no YouTube or Vimeo video players, no Google Maps, and no social plugins from Facebook, Instagram, LinkedIn or X (formerly Twitter).

Should such content be added in the future, it will be blocked by default by the consent management mechanism used on the Site and loaded only after you consent to the marketing category. This Policy will be updated accordingly.

An up-to-date, detailed list of all cookies used on the Site, together with their descriptions, is available in the “Manage consent” window under Manage services.

VII. Information in forms

  1. The Site collects information provided voluntarily by users in contact, registration, order and newsletter sign-up forms.
  2. The Site may record information about connection parameters, including the IP address and timestamp, for technical and security purposes.
  3. Data provided in a form is processed for the purpose arising from the function of that particular form, indicated each time next to the form.
  4. Form data may be passed to entities that technically deliver the relevant services – in particular payment operators, courier companies and the Mautic system provider – only to the extent necessary to fulfil the order or provide a response.

VIII. Profiling and automated decision-making

As part of our marketing activities – and only after you have consented to the marketing category – we may carry out profiling consisting of analysing your activity on the Site in order to tailor marketing messages.

We do not take decisions in relation to you based solely on automated processing, including profiling, which would produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22(1) GDPR.

IX. Data security

  1. The Controller applies technical and organisational measures appropriate to the risk to the rights and freedoms of data subjects, in accordance with Art. 32 GDPR.
  2. Data transmission between the user’s browser and the Site is encrypted using the TLS protocol.
  3. Access to personal data is granted only to authorised persons bound by confidentiality obligations.
  4. The Controller regularly reviews the safeguards in place and keeps the software used up to date.

X. Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy, in particular in connection with changes in legislation, the deployment of new tools or the extension of the Site’s functionality.
  2. Users will be informed of material changes through a notice on the Site and, where the change affects processing that requires consent, by displaying the consent banner again.
  3. The current version of the Policy is always available at evolpe.shop/privacy-policy-2/.

Last updated: 14 September 2026

Subscribe to our Newsletter!

Leave us your e-mail and let us keep you up to date with latest whitepapers, e-books and news from the world of open source IT systems for business.