PRIVACY POLICY

Major&Maker · personal data

Privacy & Cookies Policy

Information about the data processed by VIVO Sp. z o.o. in connection with Major&Maker purchases, communications and service support, the purposes of processing and your rights as a website user.

One controllerVIVO Sp. z o.o., the Major&Maker store operator.
Optional marketingYou can buy without consenting to marketing.
Cookie choicesOptional technologies require appropriate consent.
Privacy contactFor privacy matters: biuro@majormaker.pl.

1. Data controller and contact

The controller of personal data relating to use of the Major&Maker store is VIVO Spółka z ograniczoną odpowiedzialnością, Bartycka 26/24, 00‑716 Warsaw, Poland; KRS 0000710449, NIP 5342571122, REGON 369057675.

For personal data matters, GDPR rights and account administration, please contact biuro@majormaker.pl or write to the postal address above. Product returns, complaints and repair requests should be sent to serwis@majormaker.pl.

This Policy explains processing for purchases, accounts, communications, service support and website use. Purchase conditions are set out in the Terms & Conditions. This Policy is a privacy notice, not a substitute for separate consent where consent is required.

2. Data we receive and their sources

  • Orders and delivery: name, email address, phone number, delivery address, ordered products, order number, purchase history, and payment and delivery information.
  • Business purchases and invoices: business name and address, NIP, contact details and information required for accounting documents and KSeF.
  • Account: registration information, login data protected within the system, settings and information associated with account management.
  • Communications and service: correspondence, device model, purchase details, fault description, repair history, delivery and collection choices, photos or videos, links to materials, invoice information and bank account details and expense evidence where needed for reimbursement.
  • Technical data: IP address, request date and time, browser, device and operating system information, accessed resources, errors, and cookie or similar identifiers, to the extent resulting from the functions used and consents given.

We obtain data primarily from the customer. Payment or delivery information may come from the chosen payment provider or carrier. Details of a business representative may be supplied by their employer, business partner or the person placing the order. In that case, the data consist of identification and business contact information needed to handle the relationship.

Please do not send card numbers, CVV codes, banking passwords, copies of identity documents or health information unless expressly needed for a particular procedure. Fault photos and videos should show the device; avoid recording people or private information unrelated to the request.

3. Purposes and legal bases

Orders, delivery and performance of a contract
Purchase handling, order-related communications, delivery and payment settlement: Article 6(1)(b) GDPR. For communications with a business representative, the basis is Article 6(1)(f) GDPR: our legitimate interest in concluding and performing a contract with the represented business.
Customer account
Creating and maintaining an account at the user’s request: Article 6(1)(b) GDPR. Securing access and preventing misuse: Article 6(1)(f) GDPR.
Enquiries and correspondence
Responding to an enquiry concerning a proposed or existing contract: Article 6(1)(b) GDPR. Other communications and customer relations: Article 6(1)(f) GDPR, our legitimate interest in answering enquiries and retaining necessary correspondence.
Complaints, warranty, repairs and returns
Compliance with legal obligations, including statutory complaints and withdrawals: Article 6(1)(c) GDPR. Performance of warranty commitments and paid repair contracts: Article 6(1)(b) GDPR and, where appropriate, Article 6(1)(f), our legitimate interest in verifying entitlement and properly handling the request.
Accounting, tax and KSeF
Issuing, providing, correcting and retaining sales documents, including KSeF invoices, and fulfilling tax obligations: Article 6(1)(c) GDPR.
Claims and security
Establishing, pursuing and defending claims, detecting fraud, protecting the website and documenting misuse: Article 6(1)(f) GDPR. Legitimate interests are assessed against the rights and freedoms of the person concerned.
Newsletter and marketing communications
Where a user subscribes to an available newsletter or consents to specified communications, the basis is Article 6(1)(a) GDPR together with the relevant consent required by the Polish Electronic Communications Law. Consent may be withdrawn at any time.
Cookies and optional analytics or advertising
Essential website functions and security: Article 6(1)(b) or (f) GDPR as appropriate, together with the statutory exception for essential technologies. Optional consent-based tools: Article 6(1)(a) GDPR and consent to storing or accessing information on the device under the Polish Electronic Communications Law.

Providing data is voluntary, but the details needed for an order, delivery, settlement or request are necessary to handle it. Omitting optional information, withholding marketing consent or declining optional cookies does not prevent a purchase or the exercise of statutory rights.

4. Recipients of personal data

We disclose data only to the extent needed for the relevant purpose. Recipients may include hosting and IT providers, email services, the store platform, communications and request-handling tools, accounting and legal services, transport and logistics providers, banks and the selected payment and financing providers.

PayPro / Przelewy24

PayPro S.A., Pastelowa 8, 60‑198 Poznań, Poland; KRS 0000347935, NIP 7792369887, REGON 301345068.

When you select a payment handled by this provider, we disclose the data necessary to identify and settle it, such as the order identifier, amount and payer’s contact details.

Comfino

ComfinoPay sp. z o.o., Konstruktorska 13, 02‑673 Warsaw, Poland; KRS 0001102506, NIP 5214067470, REGON 528469633.

Data needed for the selected payment or financing service are disclosed when this method is chosen. Any further information required by the financing institution is supplied by the customer through that institution’s procedure.

Payment providers, banks, financing institutions and carriers may act as separate controllers for their own obligations. Providers processing data on our behalf act under appropriate agreements and instructions. Public authorities and authorised KSeF participants may also receive data where required by law.

Customers sharing materials through Google Drive, OneDrive, WeTransfer or another service are also subject to that provider’s terms and privacy policy. We use the supplied link to handle the request. Please share only the necessary materials, rather than making an entire private drive accessible.

Information about a particular recipient or provider involved in handling your matter is available from the controller. We do not sell customer data as a contact database.

5. Cookies and similar technologies

Cookies are small pieces of information stored on a device by the browser. Local storage, identifiers and website tags may serve similar functions. Not all are essential; their use depends on website functions and the user’s choices.

Essential
Support the cart, sessions, login, security and storage of consent choices. To the extent strictly necessary for transmission or a service explicitly requested by the user, they fall within the statutory exemption from consent.
Preferences
May remember settings such as language. Whether consent is required depends on the actual function and whether it is necessary for a user-requested service, not merely on the category name.
Analytics
Where used, help analyse website use and improve the site. Optional tools that store or read information on the device require prior consent.
Marketing
Where used, measure advertising, personalise advertisements or reach a user again. They require prior consent and are not necessary for a purchase.

The choice is yours

Opening the site, scrolling, continuing to browse or leaving browser defaults unchanged does not constitute consent to optional cookies. Refusal should be as accessible as acceptance. Withdrawal of consent does not affect the lawfulness of earlier processing.

Choices can be changed through the consent settings made available on the website. Cookies can also be deleted or blocked in the browser; deleting them does not necessarily erase data previously received by a provider. Blocking essential cookies may affect the cart or login. If you cannot find the relevant settings, please contact biuro@majormaker.pl.

Session cookies last until the session ends; persistent cookies remain until deleted or until their individual expiry period. There is no single expiry period applicable to all cookies. Information about specific tools, purposes and duration should be available when consent is requested; details of a function used can also be obtained from the controller.

6. Maps, security, chat and external content

The website may display Google Maps, form-security tools such as reCAPTCHA, chat, ratings and content supplied by third parties. Activating such a function may transmit the IP address, browser and device details, interaction data and relevant identifiers to the provider.

These tools are assessed by their actual operation. Functions beyond what is necessary for the requested service require an appropriate legal basis and, where storing or accessing device information requires it, consent. Merely labelling a tool “security” or “functional” does not remove these obligations.

Following a link to an external service, such as maps, social media or a payment provider, takes you to a service governed by that provider’s separate terms and privacy policy. Major&Maker’s Policy does not replace those controllers’ privacy notices.

7. Transfers outside the EEA

Some technical-service or content providers may process data outside the European Economic Area. A transfer is permitted only with a basis under Chapter V GDPR, such as a European Commission adequacy decision or appropriate safeguards, including standard contractual clauses.

Additional safeguards may be needed depending on the risks. Information about a particular provider’s transfers and how to obtain a copy of the relevant safeguards is available at biuro@majormaker.pl. A provider’s location in a third country does not remove the need to assess data protection.

8. How long data are retained

Orders, invoices and accounting documents
For contract performance and then for the periods required by tax and accounting law and needed to pursue or defend claims. KSeF invoice retention is governed by separate rules and is not shortened by deletion of a store account.
Customer account
Until account use ends and subsequently to the extent required by law or needed to resolve settlements or defend claims. Data no longer needed are deleted or anonymised.
Service requests and fault materials
For handling the request, carrying out the repair and settlement, then for as long as necessary for related rights and potential claims. Irrelevant or unnecessary materials should not be retained longer than needed.
Other correspondence
For the time necessary to answer and close the matter, and longer only where justified by its nature, a legal obligation or the need to establish, pursue or defend claims.
Marketing and consents
Until consent is withdrawn or the activity ends. Limited records of consent, its withdrawal or an objection may be retained to demonstrate compliance and honour the opt-out.
Logs and technical data
For a period justified by system operation and security and the investigation of incidents. In cases of misuse, necessary information may be retained until the investigation or proceedings end. Cookie lifetimes depend on the particular cookie and consent settings.

Expiry of the 24-month warranty does not automatically mean deletion of all purchase-related data. Different statutory periods or claim-related periods may apply to individual documents. Once the relevant retention basis ends, we delete or anonymise the data.

9. Your data protection rights

  • Access to your data and a copy of them, correction of inaccurate data and completion of incomplete data.
  • Erasure or restriction in the circumstances provided by the GDPR. Erasure does not cover data we must retain, for example for tax obligations or the necessary defence of claims.
  • Portability of data processed automatically on the basis of consent or a contract, to the extent specified by the GDPR.
  • Objection, on grounds relating to your particular situation, to processing based on legitimate interests. We then assess whether overriding legitimate grounds justify continuing the processing.
  • Objection to direct marketing: after an objection, we stop processing data for that purpose, including related profiling.
  • Withdrawal of consent at any time, without affecting the lawfulness of processing before withdrawal.

Requests may be sent to biuro@majormaker.pl. We may ask for information necessary to verify identity, but should not request excessive documents. We normally respond without undue delay and within one month of receipt. For complex or numerous requests, the period may be extended by a further two months; we notify you of the extension and reasons within the first month.

You may lodge a complaint with the President of Poland’s Personal Data Protection Office (UODO). Current information and contact details are available at uodo.gov.pl. Where applicable, you may also contact the competent supervisory authority in another EEA country.

10. Automation and profiling

We do not make decisions about customers that produce legal or similarly significant effects solely on the basis of automated processing. An automatic order or request acknowledgement is not an assessment of a complaint or a financing approval decision.

Where consent-based marketing tools are used, they may tailor content based on website activity. This does not mean that VIVO makes credit decisions. Assessment of a financing application, including any automation by the financing institution, is covered by that institution’s separate privacy information.

11. Security and Policy updates

We apply technical and organisational measures appropriate to the risks, including access protection, restricted permissions, transmission protection and rules for working with providers. Users should protect passwords, keep software up to date and not disclose login details to unauthorised persons.

We update this Policy when processing practices, website functions or legal requirements change. A new description does not retrospectively authorise earlier activities or automatically extend existing consent. Where a new purpose requires consent, we request it separately.

Document version: 11 September 2026. For privacy matters, please contact biuro@majormaker.pl.

A question about your personal data?

Please describe the matter without providing more personal data than necessary.

Email the data controller