Privacy Policy
Last updated: 8 March 2026
1. Data Controller
The controller of your personal data is Lenanto Spółka z Ograniczoną Odpowiedzialnością (Lenanto Ltd.) with its registered office in Mogilany, os. Parkowe Wzgórze 126, 32-031 Mogilany (Lesser Poland Voivodeship), Poland, KRS: 0001122004, NIP: 9442290063, REGON: 529412300 (hereinafter: the “Controller”). Contact for personal data matters: [email protected].
2. Scope and Purposes of Processing
We process your personal data for the following purposes:
- Order fulfilment (first name, last name, address, e-mail, telephone number, invoice data) — legal basis: Art. 6(1)(b) GDPR (performance of a contract).
- Handling complaints and returns — legal basis: Art. 6(1)(b) and (c) GDPR (performance of a contract, legal obligation).
- Maintaining a customer account — legal basis: Art. 6(1)(b) GDPR.
- Accounting and tax obligations — legal basis: Art. 6(1)(c) GDPR (legal obligation). Retention period: 5 years from the end of the tax year.
- Direct marketing (newsletter) — legal basis: Art. 6(1)(a) GDPR (consent). Consent may be withdrawn at any time.
- Analytics and service improvement (anonymised traffic data) — legal basis: Art. 6(1)(f) GDPR (legitimate interest).
3. Data Recipients
Your data may be disclosed to the following categories of recipients:
- Payment processor — Paynow (mBank S.A.) — solely to the extent necessary to process payments.
- Courier companies (InPost, DPD) — to the extent necessary to fulfil delivery.
- E-mail service provider (Resend) — to the extent necessary for sending transactional messages.
- Hosting provider (Railway) — to the extent necessary for data storage on servers.
Payment data (card numbers, BLIK details) are processed exclusively by the payment operator and are not stored by the Controller.
