1. Controller
The controller is Studio Kreatywne Mateusz Pawluk, ul. Leśna 12, 84-353 Mosty, Polska, Polish Tax ID 8393015674, REGON 389631147, email: kontakt@pawlukstudio.pl, phone: +48 500 591 594. No data protection officer has been appointed. Privacy requests may be sent to kontakt@pawlukstudio.pl.
2. Categories of data
- Account and sign-in: email, user identifier, sign-in times and technical session data.
- Purchase and billing: name or business name, email, billing address, country, Stripe customer, session and subscription identifiers, Plan, amount, currency, payment status and required checkout acknowledgements. Full card data is not received by the Controller.
- Product use: package identifier and type, download time, allowance use and entitlement status.
- Anonymous Service statistics: visited path without query parameters, referrer, language, screen resolution, device type, browser, operating system, approximate country and non-personal product events such as the opened template identifier, selected filter, Plan and billing period, pricing-entry source or technical download status. We do not send email addresses, search text, payment data or form contents to Umami. Umami sets no cookies and creates no cross-site profile.
- Security: IP address and magic-link request time, technical headers, hosting logs and events necessary to detect abuse and errors.
- Contact and complaints: email, correspondence, order information and attachments voluntarily provided.
3. Purposes and legal bases
- Account creation, authentication, order performance, file delivery, subscription administration and support — Article 6(1)(b) GDPR.
- Tax and accounting duties, statutory consumer rights and responses to authorities — Article 6(1)(c) GDPR.
- Security, abuse prevention, allowance enforcement, diagnostics and legal claims — Article 6(1)(f) GDPR; the legitimate interest is secure operation and protection of the Controller and customers.
- Measurement of anonymous aggregate traffic and non-personal product interactions with self-hosted Umami — Article 6(1)(f) GDPR; the legitimate interest is understanding page and template popularity, evaluating the usability of checkout and downloads, and improving the Service without cookies, advertising profiling or user identification.
- Email marketing, advertising pixels or identifier-based analytics — Article 6(1)(a) GDPR only after consent if introduced. KATALOG currently runs no newsletter or behavioural advertising profile.
4. Is data required?
Providing an email and payment-provider-required data is voluntary but necessary to create an Account, enter into the contract and deliver files. Without it, purchase and supply are impossible. Correspondence data is voluntary, but insufficient information may prevent a response.
5. Recipients and processors
- Supabase, Inc. — authentication, entitlements database, download history and private package storage.
- Stripe Payments Europe, Limited and Stripe group entities — payments, subscriptions, fraud prevention and transaction records; Stripe also acts as an independent controller where financial law requires.
- Resend, Inc. — transactional magic-link and contract-confirmation email.
- Vercel Inc. — hosting, Service delivery, security and short-lived technical logs.
- Umami, self-hosted at studio.73web.agency — cookieless, anonymous and aggregate Service usage statistics.
- Accounting, legal and technical advisers and authorised public bodies — only where necessary for a duty or protection of rights.
6. Transfers outside the EEA
Some technology providers are based or host infrastructure in the United States. Data may be transferred outside the EEA under an adequacy decision, European Commission Standard Contractual Clauses or another Chapter V GDPR mechanism. Details of the relevant safeguard can be requested from the Controller.
7. Retention
- Account, session, entitlements and download history — while the Account is active, followed by technical deletion and any mandatory legal retention.
- Magic-link request log — no more than 7 days, solely for spam and abuse prevention.
- Contract, payment and accounting records — for the period required by tax and accounting law, generally five years calculated under the applicable rules.
- Complaints and correspondence — until closure and then until the relevant limitation period expires, generally no more than six years.
- Hosting security logs — under the provider’s retention, no longer than necessary for incident detection and diagnostics.
- Anonymous aggregate Umami statistics — while needed to analyse and improve the Service; they are not linked to an Account, payment or email address.
8. Your rights
Requests may be sent to kontakt@pawlukstudio.pl. Identity may need to be verified. The Controller responds without undue delay, normally within one month.
- access and a copy of data;
- rectification;
- erasure where no overriding basis requires retention;
- restriction of processing;
- portability of data processed automatically under contract or consent;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time without affecting earlier lawful processing;
- a complaint to the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.
9. Account deletion
A signed-in user can delete the Account at its bottom. The operation cancels active subscriptions, deletes the authentication user and removes operational entitlements, download history and magic-link requests. It cannot be undone.
Deletion does not include payment and accounting records the Controller or Stripe must retain by law or data needed for legal claims. Such data is restricted from unrelated use and erased after the applicable retention period.
11. Automation and children
The Controller does not make solely automated decisions producing legal or similarly significant effects and does not profile users for marketing. Automated sign-in and download limits secure the Service, and a user may request a human explanation.
The offer is intended for persons able to enter into a contract. A minor should use it only with the approval of a legal guardian.
12. Security and changes
Appropriate safeguards include HTTPS encryption, magic links, access controls, private file storage, short-lived signed download URLs and rate limits. No system can provide absolute security.
This Policy may change when law, providers or the Service change. Material changes affecting an active Account will be communicated in the Service or by email. Document version: 2026-07-29.