NESTROVIA PRIVACY AND COOKIE POLICY
1. Data Controller IdentityThe Data Controller for all personal data collected through the Nestrovia digital storefront is Ihar Shabalouski, operating under the legal entity NEVQ.
Registered physical address:.
NIP: 5214019123 | REGON: 525299188
Contact Email: info@nestrovia.com | Phone: +48451200203
2. Scope and Legal Basis of Data ProcessingWe collect and process personal data solely for specific, explicit, and legitimate purposes:
- Contract Execution (Art. 6(1)(b) GDPR): Processing is necessary to fulfill the Distance Contract, including bespoke furniture manufacturing, delivery logistics, and handling statutory warranty or Right to Repair claims.
- Legal Obligations (Art. 6(1)(c) GDPR): Processing is required to comply with Polish tax and accounting regulations, specifically the mandatory issuance of electronic invoices via the National e-Invoicing System (KSeF) effective in 2026.
- Legitimate Interests (Art. 6(1)(f) GDPR): Fraud prevention, network security, and defense against legal claims.
- Consent (Art. 6(1)(a) GDPR): Deployment of non-essential cookies and direct electronic marketing.
3. Data Sharing and Third-Party ProcessorsTo provide our services, data is shared with vetted third-party processors bound by Data Processing Agreements (DPAs):
- Payment Infrastructure (Stripe): Financial data is processed securely by Stripe. We do not store full credit card numbers on our servers. In compliance with Stripe's 2026 updated terms, any Provisioning Data or payment data is strictly restricted from being sold or used for unrelated advertising. Stripe maintains commercially reasonable administrative, technical, and physical safeguards to protect this data.
- Logistics Partners: Freight forwarders receive necessary delivery details (name, address, phone number) to coordinate the shipment of bulky goods.
- Government Authorities: Fiscal data is transmitted to Polish tax authorities via the KSeF API.
4. Data Retention Periods- Data related to sales contracts and KSeF electronic invoices are retained for a minimum of 5 years from the end of the calendar year in which the tax obligation arose, as mandated by Polish tax law.
- Account data is kept until the user requests account deletion, after which it is purged within 30 days unless a longer retention period is legally required.
5. Consumer Rights under GDPRConsumers possess the following absolute rights regarding their personal data:
- Right to Access, Rectification, and Erasure ("Right to be Forgotten").
- Right to Restrict Processing and Data Portability.
- Right to Object to processing based on legitimate interests.
- Right to withdraw consent at any time.
- To exercise these rights, consumers must email info@nestrovia.com. If a consumer believes their data is mishandled, they have the right to lodge a formal complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (PUODO).
6. Cookie Policy and Opt-in RegimeThe Nestrovia platform utilizes cookies to ensure core functionality and enhance the user experience.
- Strictly Necessary Cookies: Essential for the shopping cart and secure checkout (Stripe functionality).
- Analytical/Marketing Cookies: Only deployed with the explicit, active consent of the user. In strict adherence to Polish e-commerce compliance standards, Nestrovia operates on a strict "opt-in" regime for all non-essential cookies. Users can manage or revoke their preferences at any time via the Cookie Preferences panel located in the website footer.