Privacy Policy
Introduction
At Lumière, operated by Nova Group Sp. z o.o., we value your privacy and are committed to protecting your personal data. This Privacy Policy outlines how we collect, use, store, and protect your personal information when you interact with our website. Please review this policy carefully to understand your rights and how we comply with the General Data Protection Regulation (GDPR).
Who We Are
The data controller responsible for your personal data is:
Nova Group Sp. z o.o.
Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland
TAX ID: PL7011215529
REGON: 529224431
If you have any questions about this policy or your data, please contact us at: [email protected]
What Personal Data We Collect
We collect the following personal data to provide our services:
• Identity Data: Full name.
• Contact Data: Email address, phone number, billing address, and shipping address.
• Transaction Data: Details of your purchases, payment information, and order history.
• Account Data (optional): Username and password for your Lumière account.
We collect this information directly from you during checkout, account registration, or customer service interactions.
Legal Basis for Processing Data
Under GDPR, we process your personal data based on the following legal grounds:
1. Contractual Necessity: To process and deliver your orders and manage your account.
2. Consent: For activities such as sending marketing emails (only if you have opted in).
3. Legal Obligation: To comply with legal requirements, such as tax and accounting regulations.
How We Use Your Personal Data
We use your personal data for the following purposes:
• To process and deliver your orders, including managing payments and shipping.
• To provide customer support and resolve any issues with your orders or account.
• To send updates about your orders, account, or changes to our services.
• To comply with legal and regulatory obligations.
We do not use your data for purposes unrelated to the delivery of our services.
How We Share Your Data
We share your data only when necessary to provide our services or comply with legal requirements:
• Payment Providers: To securely process your payments.
• Shipping Carriers: To ensure timely delivery of your purchases.
• IT Service Providers: For website hosting and maintenance.
All third parties are contractually obligated to handle your data securely and in compliance with GDPR.
Cookies and Tracking Technologies
We use cookies to improve your experience on our website. Cookies allow us to:
• Understand user preferences.
• Enhance website functionality.
You can manage your cookie preferences or disable cookies through your browser settings. For more information, please see our Cookie Policy.
Your Rights
Under GDPR, you have the following rights regarding your personal data:
• Access: Request a copy of your personal data.
• Rectification: Correct any inaccuracies in your data.
• Erasure: Request deletion of your data (“right to be forgotten”).
• Restriction: Limit how we process your data.
• Objection: Object to data processing, including for marketing purposes.
• Data Portability: Receive your data in a structured, commonly used format.
• Withdraw Consent: Withdraw your consent for specific data uses, such as marketing emails.
To exercise your rights, please contact us at [email protected]. You also have the right to lodge a complaint with the supervisory authority in Poland:
President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
Phone: +48 22 531 03 00
Website: www.uodo.gov.pl
Data Retention
We retain your personal data only for as long as necessary for the following purposes:
• Order Information: Retained for six years to comply with tax and legal obligations.
• Account Information: Retained until account deletion or inactivity for three years.
• Marketing Data: Retained until you withdraw consent or unsubscribe.
After the retention period, your data will be securely deleted or anonymized.
Data Security
We prioritize the security of your personal data and implement robust technical and organizational measures, including:
• Data encryption during storage and transmission.
• Secure payment processing through trusted providers.
• Access controls to prevent unauthorized access to your data.
While we strive to protect your data, no system is 100% secure. In the unlikely event of a data breach, we will notify affected users promptly and, if required, report it to the supervisory authority.
Children’s Data
Our website is not intended for children under the age of 16, and we do not knowingly collect their personal data. If we discover that we have inadvertently collected data from a child, we will delete it promptly.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal obligations. Any significant updates will be communicated on our website or via email. The latest version of this policy is always available on our website.
Acknowledgment and Agreement
By using our website and services, you consent to the practices outlined in this Privacy Policy. We are committed to handling your data with care, transparency, and respect.
Contact Us
If you have any questions or concerns about this Privacy Policy or your personal data, please reach out to us at:
Email: [email protected]
Mail: Nova Group Sp. z o.o., Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland