01Legal information
Privacy policy
Short and without the legal fog: what happens to your data when you visit this site, write to us or place an order.
Last updated: 25.09.2026
This is a translation. The original of this document is written in Polish, and if the two ever differ, the Polish version is the one that applies.
01Who is responsible for your data
The controller of your personal data is Kawiarnia Palone Masło Apolonia Doganowska, a sole proprietorship entered in the Polish Central Register and Information on Economic Activity (CEIDG), with its place of business at ul. Jedności 3A, 65-018 Zielona Góra, NIP 9292087069, REGON 540340090.
You can contact us about personal data at any time. Write to [email protected], call 725 843 586 or come and see us at ul. Jedności 3A.
We haven't appointed a data protection officer, because at our size there's no obligation to. Everything comes straight to us.
02Why we process data and on what basis
We only collect what a particular matter needs. Below is the full list of situations in which we get any data from you at all.
- Advance order
- We process the data you give us when you order: your name, phone number, what you're ordering and the pickup day, and when you buy as a company, also its name, NIP and address. We do this to accept and prepare your order, that is, to enter into and perform a contract (Article 6(1)(b) GDPR), and we use the company details to issue an invoice, which tax law requires of us (Article 6(1)(c) GDPR).
- Special order
- We process what you describe in the order and what we write to each other in the conversation about it, to agree the details, the price and the date. This is taking steps at your request before entering into a contract, and then performing it (Article 6(1)(b) GDPR).
- Account on the site
- When you create an account, you give us your email address and a password, and your name and phone number if you want to. We don't store your password: the database only holds an irreversible hash of it, from which the password can't be recovered. Each time you sign in, we record the date, the IP address and the browser name, and the most important account events, such as creating the account, changing the password or a failed sign-in, go into an internal log. We run your account to perform the contract for providing an electronic service (Article 6(1)(b) GDPR), and the records of sign-ins and events are there to keep your account secure, which is our legitimate interest (Article 6(1)(f) GDPR).
- Emails about what's new
- If you tick the separate consent box, we send emails to your address about new fillings, new beans and what's happening at the café. We do this only on the basis of your consent (Article 6(1)(a) GDPR), which you can withdraw at any time: with the link at the bottom of any such email or on your account page. Withdrawing it doesn't close your account, doesn't affect orders you've placed and doesn't make earlier emails unlawful.
- Online payment
- Payments are handled by a payment service provider. We don't see or store your card details. We're told whether the payment went through, and we keep that information as part of the order records (Article 6(1)(b) and (c) GDPR, as far as tax and accounting obligations go).
- Accounts and bookkeeping
- If we issue a receipt or an invoice, we process the data that tax law requires. The basis is a legal obligation (Article 6(1)(c) GDPR).
- Messages on Instagram and Facebook
- When you write to us on social media, we see your profile and the content of your message. We reply and carry on the conversation, which is our legitimate interest (Article 6(1)(f) GDPR). These services are run by Meta Platforms Ireland Limited and have their own privacy rules.
- Site security
- The server the site runs on keeps technical logs: IP address, time of the request, the address of the page and the browser type. They're used to keep the site running and to protect it from abuse, which is our legitimate interest (Article 6(1)(f) GDPR). The forms for creating an account, signing in and recovering a password are also protected by Cloudflare Turnstile, a check that the form is being sent by a person rather than a program. On those pages your browser connects to servers run by Cloudflare, Inc., which receive your IP address, the name of your browser (the User-Agent header), technical characteristics of the connection and the address of our site. This is used only to tell people from bots, so that nobody can guess passwords or open fake accounts, which is also our legitimate interest (Article 6(1)(f) GDPR). Cloudflare processes this data on our behalf and, when improving its bot detection itself, also as a separate controller, under the terms of its own privacy policy.
- Visit statistics
- The site counts for itself how many people visit it, where they come from (for example a search engine or Instagram), which page they open, on what device and in what browser, and from which country. We don't use cookies or other companies' tools for this. The IP address together with the browser name is only used to work out a hash that changes every day, because we delete the key to it after two days; the IP address itself is never stored. That means we don't know who you are, and your visits on different days can't be linked together. We take the country from information the server provides. We don't count browsers with the “Do Not Track” or Global Privacy Control signal turned on. We do this to know what works on the site and where our guests come from, which is our legitimate interest (Article 6(1)(f) GDPR). We count clicks on our short links (palonemaslo.pl/l/…) in the same way, the ones we put on Instagram or on posters, for example.
- Cookies
- We store the files the site needs to work on the basis of legitimate interest and Article 398(4) of the Polish Electronic Communications Law. Any other files, should we ever need them, we store only with your consent (Article 6(1)(a) GDPR). The details are in the cookie policy.
The site doesn't show ads and doesn't use other companies' analytics tools; it counts visits itself, as described above. Creating an account is up to you, and you only need one to order through the site: the menu, the photos and everything about the café are there to see without an account and without giving us anything.
03How long we keep data
- Order data: while the order is being fulfilled, and then for the limitation period for claims, which is generally 6 years, and 3 years for claims related to running a business.
- Accounting documents: 5 years from the end of the calendar year in which the tax payment deadline passed.
- Social media correspondence: for as long as the conversation lasts and up to a year after it, unless we need it longer because of a complaint.
- Account data: for as long as the account exists. You can delete your account yourself at any time, on your account page, or by writing to us; we then delete it along with the sign-in records, and the data of settled orders stays for as long as tax law requires.
- Sign-in records: up to 30 days after the session expires or is revoked.
- Account event log: 12 months, unless we're looking into a specific case of abuse.
- Server logs: usually up to 30 days, unless we're looking into a specific case of abuse.
- Visit statistics: 25 months, so one season can be compared with the one before. We delete the key to the daily browser hash after two days.
- Cookie consent: for the period given in the cookie policy, no longer than 12 months, after which we ask again.
04Who we pass data to
We don't sell data or share it with anyone for profit. We do, however, use companies without whose services the site and the café couldn't run. They are:
- the hosting provider the site runs on,
- the payment service provider that online payments go through,
- the provider of email and correspondence tools,
- an accounting office, for accounting documents,
- IT service providers who maintain the site.
Each of them processes data on our instructions and under a data processing agreement, or as an independent controller where their role makes them one. We may also pass data to public authorities when they have a legal basis for it.
05Does data leave Europe
We try to keep data within the European Economic Area. Some of the services we use, however, are companies linked to providers outside the EEA. In such cases the transfer is based on standard contractual clauses approved by the European Commission or on a decision finding an adequate level of protection.
06Your rights
You can use them at any time by writing to us. We reply within a month at the latest.
- access to your data and a copy of it,
- correction of data that's wrong or out of date,
- deletion of data, if we have no basis for keeping it,
- restriction of processing,
- portability of data we process on the basis of a contract or consent,
- objection to processing based on our legitimate interest,
- withdrawal of consent at any time, without affecting anything we lawfully did before it was withdrawn.
If you believe we're processing your data unlawfully, you can lodge a complaint with the President of the Polish Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa.
07Do you have to give us your data
No. Giving us your data is voluntary, but without it we can't accept an order or reply to an enquiry. Just browsing the site doesn't require any data at all.
We don't make automated decisions about you and we don't profile you.
08Changes to this policy
If we change how the site works, we'll update this document and the date at the top. It's worth a look before you place your next order.