# PRIVACY AND COOKIE POLICY This Privacy and Cookie Policy sets out the rules for the processing and protection of personal data and the use of cookies in connection with the use of services provided by the Controller through websites, social media profiles, communication platforms and business tools. **§1. Definitions** 1. For the purposes of this Privacy and Cookie Policy, the following definitions shall apply. **1.1 Controller** Marta Mielcarek, conducting business under the name MARTA MIELCAREK DESIGN, with its registered address at: ul. Kartuska 430c/22 80-125 Gdańsk Poland VAT ID (NIP): PL6961880264 REGON: 363793982 Email: marta.weronika.mielcarek@gmail.com **1.2 Websites** https://www.designer20.com **1.3 Social Media Profiles** 1\. The Controller operates the following communication channels: a) LinkedIn https://www.linkedin.com/in/designer20/ b) Instagram https://www.instagram.com/designer\_\_\_2.0 c) Facebook Private groups and https://facebook.com/designer20 d) Telegram Private groups e) WhatsApp Private groups f) Google Meet Individual meeting links g) Zoom Individual meeting links h) Evenea https://evenea.pl and individual event pages 2\. Through the Websites and communication channels listed above, the Controller promotes and sells: a) consulting services, b) mentoring, c) workshops, d) digital products, e) memberships, f) educational materials, g) online courses, h) events, i) other business-related services. **1.4 Calendly Profile** 1\. The Controller’s profile on Calendly used for scheduling: a) consultations, b) meetings, c) mentoring sessions, d) sales calls. **1.5 User** 1\. Any natural person interacting with the Controller through: a) the Websites, b) Social Media Profiles, c) Calendly, d) email, e) payment systems, f) messaging applications, g) other communication channels. **1.6 GDPR** 1\. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data. **§2. Personal Data** 1. The Controller processes Users’ personal data for specified purposes and on appropriate legal grounds, including: a) the User’s freely given consent, b) the performance of a contract, c) compliance with legal obligations, d) the Controller’s legitimate interests. 2\. Users may provide personal data through: a) forms available on the Websites, b) EasyTools, c) Social Media Profiles, d) Calendly, e) Naffy, f) messaging applications, g) email, h) other communication tools. **2.2. Calendly Booking Forms** 1. Personal data provided through Calendly booking forms is processed for the purpose of: a) scheduling meetings, b) scheduling consultations, c) performing contracts concluded with the Controller. 2\. The legal basis for processing is Article 6(1)(b) GDPR. 3\. Providing personal data is voluntary but necessary to conclude and perform a contract with the Controller. 4\. Personal data will be processed: a) for the duration of the contract, b) for the period required by applicable tax and accounting regulations, c) for the establishment, exercise or defence of legal claims. **2\. 3 Payments via Stripe** 1. Personal data provided during purchases made through Stripe or Naffy is processed for the purpose of: a) fulfilling Orders, b) processing payments, c) performing contracts. 2\. The legal basis for processing is Article 6(1)(b) GDPR. 3\. Providing personal data is voluntary but necessary to complete a purchase. 4\. Personal data will be stored for the period necessary to: a) perform the contract, b) comply with legal obligations, c) defend against legal claims. 5\. Where required by law, the Controller may process billing information including: a) full name, b) address, c) company details, d) VAT identification number, e) other information necessary for invoicing, accounting and tax compliance. 6\. Personal data may also be processed for the purpose of providing access to: a) memberships, b) online programs, c) workshops, d) private communities, e) events, f) educational resources. **2.4 Newsletter Subscription** 1. Personal data provided through Newsletter subscription forms is processed for the purpose of: a) delivering Newsletters, b) marketing communications, c) updates, d) promotional information. 2\. The Newsletter is delivered using MailerLite Classic. 3\. The legal basis for processing is: a) Article 6(1)(a) GDPR (consent), b) Article 6(1)(b) GDPR, where applicable. 4\. Providing personal data is voluntary but necessary to subscribe to the Newsletter. 5\. Users may withdraw their consent at any time by: a) clicking the unsubscribe link included in every Newsletter, b) contacting the Controller directly. **2.4 Email and Messaging Applications** 1. Personal data provided through: a) email, b) WhatsApp, c) Telegram, d) Facebook Messenger, e) Instagram Direct Messages, f) LinkedIn messages, g) other communication channels, is processed for the purpose of responding to inquiries and maintaining communication. 2\. The legal basis for processing is Article 6(1)(f) GDPR, namely the Controller’s legitimate interest. 3\. The data will be processed until: a) the correspondence ends, b) the expiry of the period necessary to establish, exercise or defend legal claims. **2.5 Social Media Profiles** 1. Personal data provided through social media platforms is processed for the purpose of: a) communication, b) responding to inquiries, c) managing communities, d) promoting the Controller’s Services. 2\. The legal basis for processing is Article 6(1)(f) GDPR. 3\. The data will be processed until communication ends and for the period necessary to establish, exercise or defend legal claims. **2.6 User Content Reports** 1. Personal data provided when reporting content considered illegal or inconsistent with applicable rules may be processed for: a) moderation, b) verification, c) compliance purposes. 2\. The legal basis for processing is: a) compliance with legal obligations, b) the legitimate interests of the Controller. 3\. The Controller may disclose personal data to trusted processors acting on behalf of the Controller where necessary for the provision of the Services, including: a) Stripe, b) Naffy, c) Calendly, d) MailerLite Classic, e) EasyTools, f) Google Workspace, g) Google Meet, h) Zoom, i) Meta Platforms (Facebook, Instagram, WhatsApp), j) LinkedIn, k) Telegram, l) accounting service providers, m) hosting providers, n) cloud service providers. 4\. Personal data may be transferred outside the European Economic Area where necessary for the provision of services by the providers listed above. 5. Such transfers are carried out in accordance with GDPR requirements and rely on appropriate safeguards, including: a) adequacy decisions adopted by the European Commission, b) Standard Contractual Clauses. 6\. The Controller ensures the confidentiality of all personal data provided. 7\. Personal data is collected with due care and protected against unauthorized access. 8\. Processing takes place in accordance with: a) GDPR, b) applicable Polish data protection laws. **§3. Purpose of Data Processing** 1. The Controller processes personal data for the following purposes: a) providing Services, b) providing Digital Products, c) managing customer relationships, d) scheduling consultations, e) scheduling meetings, f) processing payments, g) processing Orders, h) sending Newsletters, i) sending marketing communications, j) responding to inquiries, k) managing online communities, l) managing Social Media Profiles, m) ensuring Website functionality, n) ensuring Website security, o) complying with legal and regulatory obligations, p) protecting and defending legal rights, q) improving Services, r) improving User experience. **§4. Data Retention Period** 1. Personal data shall be retained only for as long as necessary to fulfil the purposes for which it was collected, including compliance with legal, accounting, tax and reporting obligations. 2. In particular: a) Customer and transaction data may be retained for the period required by applicable tax and accounting regulations. b) Personal data processed for the performance of a contract may be retained for: i. the duration of the Agreement, ii. the limitation period applicable to legal claims. c) Marketing and Newsletter data shall be retained until: i. the User withdraws consent, ii. the User unsubscribes from marketing communications. d) Correspondence data may be retained until: i. communication has been completed, ii. the expiry of the period necessary to establish, exercise or defend legal claims. 3. Upon expiry of the applicable retention period, personal data shall be: a) permanently deleted, or b) anonymized, where permitted by applicable law. **§5. User Rights** 1. Users have the following rights regarding their personal data: a) the right of access to personal data, b) the right to rectification, c) the right to restriction of processing, d) the right to object to processing, e) the right to erasure (“right to be forgotten”), f) the right to data portability, g) the right to withdraw consent at any time where processing is based on consent, h) the right to lodge a complaint with the competent supervisory authority. 2. To exercise any of these rights, Users may contact the Controller at: marta.weronika.mielcarek@gmail.com 1. Users have the right to lodge a complaint with the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych) or another competent supervisory authority if they believe that the processing of their personal data violates applicable data protection laws. **§6. Cookies** 1. The Websites may use cookies and similar technologies to: a) improve functionality, b) enhance the User experience, c) ensure the proper operation of the Websites. 2. Cookies are small text files stored on a User’s device when visiting a Website. 3. The Controller may use cookies necessary for: a) Website functionality, b) Website security, c) storing User preferences, d) session management, e) statistical purposes, f) performance monitoring. 4. The Websites are built and operated using EasyTools. 5. EasyTools may place technical and functional cookies necessary for the operation of: a) landing pages, b) forms, c) automations, d) Digital Products, e) customer accounts. 6. MailerLite subscription forms embedded on the Websites may also use cookies necessary for: a) Newsletter subscriptions, b) email marketing functionality. 7. Users may manage or disable cookies through their browser settings. Where required by applicable law, non-essential cookies are used only after obtaining the User’s consent through the cookie banner available on the Website. 8. Disabling certain cookies may affect the functionality of the Websites. 9. Information collected through cookies is not used by the Controller to directly identify individual Users. 10. Users should review the privacy and cookie policies of those providers separately. 11. The Controller does not control cookies independently used by third-party platforms, including but not limited to: a) Facebook, b) Instagram, c) LinkedIn, d) Calendly, e) Stripe, f) Naffy, g) Google, h) WhatsApp, i) Telegram, j) Zoom, k) MailerLite. **§7. Automated Decision Making and Profiling** 1. The Controller does not make decisions based solely on automated processing, including profiling, which produce legal effects concerning Users or similarly significantly affect them. 2. The Controller may use limited analytical and marketing tools to: a) better understand User preferences, b) improve the Services, c) improve Website content, d) improve communications, e) improve the User experience. 3. Such activities do not result in automated decisions that produce legal effects concerning Users or similarly significantly affect them. **§8. Data Security** 1. The Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risks associated with personal data processing. 2. Such measures include, where appropriate: a) access controls, b) authentication procedures, c) secure storage of personal data, d) the use of trusted service providers, e) protection against unauthorized access, f) protection against accidental or unlawful loss, g) protection against destruction, h) protection against unauthorized alteration of personal data, i) regular review of security procedures, j) regular review of data protection practices. 3. Despite implementing appropriate safeguards, no method of transmission over the Internet or electronic storage can be guaranteed to be completely secure. **§9. Contact Information** 1. For any questions regarding this Privacy and Cookie Policy, the processing of personal data or the exercise of data protection rights, Users may contact the Controller: Controller: Marta Mielcarek MARTA MIELCAREK DESIGN Email: marta.weronika.mielcarek@gmail.com Website: https://www.designer20.com 2\. Users have the right to lodge a complaint with: a) the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych), or b) another competent supervisory authority within the European Union. **§10. Final Provisions** 1. This Privacy and Cookie Policy may be updated from time to time due to: a) changes in applicable laws, b) technological developments, c) changes in business practices, d) changes in the Services provided by the Controller. 2. Any significant changes to this Privacy and Cookie Policy will be: a) published on the Websites, b) made available in an easily accessible form. 3. Questions regarding this Privacy and Cookie Policy may be sent to: marta.weronika.mielcarek@gmail.com 4\. If any provision of this Privacy and Cookie Policy is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. 5\. This Privacy and Cookie Policy becomes effective on the date of its publication on the Websites. Effective Date: 6 July 2026 Last Updated: 6 July 2026