Legal Entity Ownership & Data Controller
The PylonVision platform is legally owned, operated, and managed by the following entity. All references to "Company", "Controller", "we", or "us" refer to:
Company Name:
Cybernia Sp. z o.o.
Address:
ul. Jana Heweliusza 11/811, 80-890 Gdańsk, Poland
VAT ID (NIP):
PL 5833550916
REGON:
543035541
KRS Number:
0001201007
Registry Court:
District Court Gdańsk-Północ in Gdańsk, VII Commercial Division of the National Court Register
Share Capital:
5,000 PLN
Contact E-mail:
contact [at] pylonvision.com
Effective Date: Loading...
Last Updated: Loading...
1. Introduction
This Privacy Policy ("Policy") describes how Cybernia Sp. z o.o., operating the PylonVision platform (the "Company," "Controller," "we," "us," or "our"), collects, uses, discloses, and protects personal data in connection with our online store and related services (the "Service"). Full identification and contact details of the Controller are set out above and repeated in Section 17.
In providing the Service, Cybernia Sp. z o.o. acts as the data controller of your personal data within the meaning of Regulation (EU) 2016/679 (the "GDPR") and is committed to processing personal data lawfully, fairly, and transparently, in accordance with the GDPR and applicable Polish data protection law.
This Policy explains what personal data we collect, why we collect it, the legal grounds on which we rely, how long we retain it, with whom it may be shared, and what rights are available to you. It applies to all personal data processed through the Service, including data collected in connection with related sales, marketing activities, and events.
Please read this Policy carefully. It will help you understand how we handle your personal data and what choices you have.
2. Definitions
For the purposes of this Policy, the following terms have the meanings set out below:
- Cookie — a small file placed on your Device to enable certain features and functionality of the Service.
- Company / Controller / we / us / our — Cybernia Sp. z o.o., the entity that determines the purposes and means of processing personal data collected through PylonVision.
- Country — Poland, being the country in which the Company is established.
- Customer — the company, organization, or natural person that registers to use the PylonVision Service.
- Device — any internet-connected device, such as a phone, tablet, or computer, used to access the Service.
- Personal Data — any information relating to an identified or identifiable natural person, whether directly, indirectly, or in combination with other information.
- Service — the online store and related services provided by PylonVision, as described in the applicable terms and on the Website.
- Third-Party Service — advertisers, contest sponsors, promotional and marketing partners, and other parties providing content or services that may be of interest to you.
- Website — the PylonVision platform, accessible at https://pylonvision.com.
- You / Data Subject — the natural person whose personal data is processed in connection with the Service.
3. Information We Collect
We collect several categories of personal data for the specific purposes described in Section 4 and on the legal grounds described in Section 5.
3.1 Personal Data
While using the Service, we may ask you to provide certain personal data that can be used to contact or identify you, including but not limited to:
- Email address
- First name and last name
- Phone number
- Address, state/province, ZIP/postal code, city
- Cookies and Usage Data (see Sections 3.3 and 3.5)
3.2 Financial Data
Financial information, such as payment method details (including card numbers and banking information), is collected and stored by our payment processors. We may receive limited information from these processors to facilitate payments, but we do not store full payment card details ourselves. All payment data is held by our payment processors (see Section 9.2); we encourage you to review their respective privacy policies.
3.3 Usage Data
We may collect information about how the Service is accessed and used ("Usage Data"), which may include your Device's IP address, browser type and version, the pages of the Service you visit, the time and date of your visit, time spent on those pages, unique device identifiers, and other diagnostic data.
3.4 Location Data
We may use and store information about your location if you grant us permission to do so ("Location Data"), in order to provide, improve, and customize features of the Service. You may enable or disable location services at any time through your Device settings.
3.5 Cookies and Similar Tracking Technologies
We use Cookies and similar tracking technologies (such as web beacons, tags, and scripts) to operate, secure, and improve the Service, and to understand how it is used.
Consent management. On your first visit to the Website, you are shown a cookie banner allowing you to accept or reject non-essential Cookies (Preference, Analytics, and Advertising Cookies) on a category-by-category basis. Strictly necessary Cookies (Session and Security Cookies) are used without consent, as they are essential to the functioning of the Service. You may withdraw or change your Cookie preferences at any time via the cookie settings link in the Website footer, or by configuring your browser to refuse Cookies; note that some parts of the Service may not function correctly if you do so. This Section 3.5 constitutes the Company's Cookie Policy in full; should we publish a separate, standalone Cookie Policy in future, we will link to it here and notify you in accordance with Section 15.
Categories of Cookies we use:
| Cookie Type |
Purpose |
Typical Retention |
Consent Required |
| Session Cookies |
Operate core functionality, such as maintaining your login session and shopping cart |
Deleted when you close your browser |
No — strictly necessary |
| Security Cookies |
Support authentication, fraud prevention, and the general security of the Service |
Session-based, or up to 30 days |
No — strictly necessary |
| Preference Cookies |
Remember your settings and preferences (e.g., language, display options) |
Up to 12 months |
Yes |
| Analytics Cookies |
Measure and analyze use of the Service so we can improve it (see Google Analytics, Section 9.1) |
Up to 14 months for event/user-level data; Google Signals (signed-in) data up to 26 months, per Google's own retention limits |
Yes |
| Advertising Cookies |
Serve and measure advertisements that may be relevant to your interests |
Typically 12–24 months, depending on the advertising partner |
Yes |
Third-party Cookies. Certain Cookies are placed by third-party providers acting on our behalf or in their own capacity, notably Google Analytics (Section 9.1). These providers may process Cookie data under their own privacy policies, which we encourage you to review.
4. How We Use Your Personal Data
PylonVision uses the personal data it collects for the following purposes:
- To provide and maintain the Service
- To notify you of changes to the Service
- To allow you to participate in interactive features of the Service, where you choose to do so
- To provide customer support
- To gather analysis and insight that helps us improve the Service
- To monitor use of the Service
- To detect, prevent, and address technical issues
- To fulfil any other purpose for which the data was provided
- To provide news, offers, and information about goods, services, and events similar to those you have already purchased or enquired about, unless you have opted out
- For any other purpose disclosed to you at the point of collection, or with your consent
5. Legal Basis for Processing Personal Data (Article 6 GDPR)
Where you are located in the European Economic Area (EEA), our legal basis for collecting and using personal data depends on the specific data concerned and the context in which it is collected. In general, we process personal data because:
- Processing is necessary for the performance of a contract with you (Art. 6(1)(b) GDPR);
- You have given consent (Art. 6(1)(a) GDPR);
- Processing is necessary for our legitimate interests, provided those interests are not overridden by your rights (Art. 6(1)(f) GDPR); or
- Processing is necessary to comply with a legal obligation (Art. 6(1)(c) GDPR).
The table below maps each main category of personal data to the specific legal basis relied upon:
| Category of Personal Data |
Legal Basis (Art. 6(1) GDPR) |
Explanation |
| Contact Data (name, email, phone, address) |
(b) Performance of a contract; (f) Legitimate interest |
Necessary to create your account, provide the Service, and respond to support requests |
| Financial Data (billing and payment records) |
(b) Performance of a contract; (c) Legal obligation |
Necessary to process transactions and comply with tax and accounting law |
| Analytical Data (Usage Data, analytics Cookies) |
(a) Consent |
Given via our cookie banner before non-essential analytics Cookies are set; aggregated technical logs needed for security may instead rely on (f) legitimate interest |
| Location Data |
(a) Consent |
Processed only if you actively enable location sharing |
| Marketing Cookies / Communications |
(a) Consent |
You may withdraw consent at any time — see Section 12.2 |
6. Retention of Your Personal Data
We retain personal data only for as long as necessary for the purposes described in this Policy, taking into account the specific category of data concerned. Where a shorter or longer statutory period applies under Polish or EU law, that period prevails over the general periods below.
| Data Category |
Retention Period |
Basis / Reason |
| Account & Contact Data (name, email, phone, address) |
For the duration of your account or contractual relationship with us, plus up to 6 years thereafter |
General limitation period for civil law claims under Article 118 of the Polish Civil Code |
| Financial & Billing Data (invoices, transaction records) |
5 years, counted from the end of the calendar year in which the relevant tax obligation arose |
Polish Tax Ordinance (Ordynacja podatkowa) and Accounting Act (Ustawa o rachunkowości) |
| Order & Subscription Data (purchase history, access logs, licence records for digital content, courses, or software) |
For the duration of the applicable subscription or access period, plus the retention period applicable to Financial Data above |
To fulfil your order, manage your subscription, provide technical support, and comply with tax and regulatory obligations |
| Marketing Data (processed on the basis of consent) |
Until you withdraw your consent |
Art. 6(1)(a) GDPR; we periodically review marketing lists to remove data no longer necessary, consistent with the principle of data minimisation |
| Analytics / Usage Data (e.g., Google Analytics) |
Up to 14 months for event- and user-level data (our configured setting); Google Signals (signed-in) data is capped by Google at 26 months regardless of our settings |
See Sections 3.5 and 9.1 |
| Technical & Security Logs |
Typically up to 12 months, unless a longer period is required to investigate a security incident or comply with a legal obligation |
Legitimate interest in securing the Service (Art. 6(1)(f)) |
At the end of the applicable retention period, we delete or irreversibly anonymize the relevant personal data, except where continued retention is required to comply with a legal obligation or to establish, exercise, or defend legal claims.
7. International Transfers of Your Personal Data
Your personal data may be transferred to, and processed in, countries other than the one in which you are located, including countries outside the European Economic Area ("EEA"), where data protection laws may differ from those of your jurisdiction. If you are located outside Poland, please note that we transfer personal data to Poland, and potentially to other countries as described below, and process it there.
Your acceptance of this Policy, followed by your submission of such information, represents your acknowledgement of this transfer.
7.1 Safeguards for International Transfers
Where personal data is transferred to a recipient located outside the EEA, we ensure the transfer is subject to appropriate safeguards, which may include one or more of the following mechanisms, depending on the recipient and destination country:
- Adequacy decisions — transfers to countries the European Commission has formally recognized as providing an adequate level of data protection under Article 45 GDPR.
- Standard Contractual Clauses (SCCs) — the standard data protection clauses approved by the European Commission, incorporated into our agreements with processors established outside the EEA. SCCs are our primary safeguard for transfers to the United States and other third countries without an adequacy decision.
- EU-U.S. Data Privacy Framework (DPF) — where a US-based service provider maintains a current, valid self-certification under the DPF, we may rely on this framework, in addition to or as an alternative to SCCs. We note that the adequacy decision underlying the DPF is presently subject to ongoing legal proceedings before the Court of Justice of the European Union; we monitor these developments and will implement alternative safeguards without undue delay if the legal basis for a specific transfer changes.
We take all steps reasonably necessary to ensure your data is treated securely and in accordance with this Policy, and no transfer of personal data will take place to a country or organization unless adequate controls are in place. You may request further information about the specific safeguards applicable to a transfer of your personal data by contacting us at [email protected].
8. Disclosure of Your Personal Data
General policy. We do not sell, trade, or rent your personal data to others. We may share generic, aggregated demographic information that is not linked to any identifiable individual with business partners, trusted affiliates, and advertisers for the purposes described in this Policy.
Business transactions. If the Company is involved in a merger, acquisition, or asset sale, your personal data may be transferred as part of that transaction. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.
Disclosure for law enforcement. In certain circumstances, we may be required to disclose your personal data if required to do so by law or in response to valid requests from public authorities, such as a court or government agency.
Legal requirements. We may disclose your personal data where we believe in good faith that doing so is necessary to: comply with a legal obligation; protect and defend the rights or property of the Company; prevent or investigate possible wrongdoing in connection with the Service; protect the personal safety of users of the Service or the public; or protect against legal liability.
9. Third-Party Service Providers
9.1 Analytics
We use third-party service providers to monitor and analyze use of the Service.
- Google Analytics. Google Analytics is a web analytics service offered by Google that tracks and reports on website traffic. Google may use the data collected to contextualize and personalize advertisements within its own advertising network, and this data is shared with other Google services. You may opt out of Google Analytics by installing the Google Analytics opt-out browser add-on, which prevents the Google Analytics JavaScript from sharing visit data with Google Analytics. For more information on Google's privacy practices, please see: https://policies.google.com/privacy
9.2 Payments
We may provide paid products or services within the Service, using third-party payment processors. We do not store or collect your full payment card details; that information is provided directly to our payment processors, whose use of your personal data is governed by their own privacy policies. Our payment processors adhere to the Payment Card Industry Data Security Standard (PCI-DSS), maintained by the PCI Security Standards Council, a joint effort of brands including Visa, Mastercard, American Express, and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
The payment processors we work with are:
9.3 Cloud & Hosting Services
We use third-party cloud service providers and hosting platforms to operate the Service and store your data:
10. Security of Your Personal Data
We implement technical and organizational measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, in accordance with Article 32 GDPR. These measures include, in particular:
Technical measures:
- Encryption of data in transit using TLS/SSL protocols;
- Encryption of sensitive data at rest, where applicable;
- Access controls, including role-based access limited to personnel who require it to perform their duties, and authentication requirements for internal systems;
- Firewalls, system monitoring, and regular security testing of our infrastructure.
Organizational measures:
- Confidentiality obligations for employees and contractors with access to personal data;
- Data protection training for relevant personnel;
- Data Processing Agreements (DPAs) with all third-party processors, requiring safeguards equivalent to those described in this Policy;
- An internal incident-response procedure for handling suspected or actual personal data breaches.
Personal data breach notification. In the event of a personal data breach, we assess the risk to your rights and freedoms and, where required, notify the President of the Personal Data Protection Office (UODO) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 GDPR.
No method of transmission over the Internet, and no method of electronic storage, is 100% secure. While we use commercially reasonable and legally required means to protect your personal data, we cannot guarantee its absolute security.
11. Children's Privacy
The Service is not directed to, and is not intended for use by, individuals under the age of 16. We do not knowingly collect personal data from anyone under the age of 16 without the consent of a holder of parental responsibility.
Legal note. Article 8 GDPR sets the default age at which a child may validly consent to the processing of personal data in connection with information society services at 16 years. EU Member States may, by national law, lower this threshold to no less than 13 years. Poland has not exercised this option and applies the default threshold of 16 years. Accordingly, processing of a child's personal data on the basis of consent is lawful only where the child is at least 16 years old, or where consent has been given or authorized by the holder of parental responsibility for children below that age.
If you are a parent or guardian and become aware that your child has provided us with personal data without your consent, please contact us at [email protected]. If we become aware that we have collected personal data from a child under the applicable age threshold without verified parental consent, we will take reasonable steps to remove that information from our systems.
Where we rely on consent as the legal basis for processing and applicable law requires parental consent, we may require verification of such consent before we collect and use the relevant personal data.
12. Your Data Protection Rights
Depending on your location and applicable law, you have the rights set out below in relation to your personal data. We honor these rights for all users, regardless of location, and are committed to providing reasonable access to information you have shared with us.
12.1 General Data Access & Deletion Rights
- Right of access — request confirmation of whether we process your personal data, and a copy of it in a structured, commonly used, machine-readable format.
- Right to rectification — request that we correct inaccurate or incomplete personal data.
- Right to erasure ("right to be forgotten") — request that we delete your personal data; we will comply unless retention is required by law or for the establishment, exercise, or defense of legal claims.
- Right to restriction of processing — request that we limit how we use your personal data in certain circumstances.
- Right to data portability — request that certain personal data be transferred to another controller, where technically feasible.
- Right to object — object to processing based on our legitimate interests, including profiling, and to processing for direct marketing purposes, at any time.
- Right to lodge a complaint — lodge a complaint with a supervisory authority. If you are located in the EEA, you may contact your local data protection authority or, in Poland, the President of the Personal Data Protection Office (UODO).
To submit a data access, rectification, deletion, restriction, portability, or objection request, please contact us using the details in Section 17. We will respond within 30 days and may need to verify your identity before processing your request.
12.2 Right to Withdraw Consent
Where our processing of your personal data is based on your consent (Art. 6(1)(a) GDPR) — for example, for marketing communications, Location Data, or non-essential Cookies — you have the right to withdraw that consent at any time, free of charge, in accordance with Article 7(3) GDPR. Withdrawing consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
You may withdraw your consent by:
- Emailing us at [email protected];
- Using the unsubscribe link included in any marketing communication; or
- Adjusting your Cookie preferences via the cookie settings link in the Website footer, as described in Section 3.5.
13. Service Providers
We may employ third-party companies and individuals ("Service Providers") to facilitate the Service, to provide the Service on our behalf, to perform Service-related functions, or to assist us in analyzing how the Service is used. These Service Providers have access to your personal data only to perform these tasks on our behalf, are bound by Data Processing Agreements, and are obligated not to disclose or use it for any other purpose.
14. Links to Other Websites
The Service may contain links to third-party websites that are not operated by us. If you click on a third-party link, you will be directed to that party's site. We strongly advise you to review the privacy policy of every website you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.
15. Changes to This Privacy Policy
We may update this Policy from time to time. We will notify you of any changes by posting the revised Policy on this page and updating the "Last Updated" date above; where a change is material, we will also update the "Effective Date" and notify you by email and/or a prominent notice within the Service prior to the change taking effect.
You are advised to review this Policy periodically. Changes become effective as of their stated Effective Date.
16. Your Acceptance of This Policy
By using the Website or the Service, you signify your acceptance of this Policy. If you do not agree to this Policy, please do not use the Website or the Service. Your continued use of the Website and the Service following the posting of changes to this Policy will be deemed your acceptance of those changes.
17. Contact Us
If you have any questions about this Privacy Policy, would like to exercise any of your data protection rights, or would like to withdraw your consent to processing, please contact the Data Controller:
- Data Controller: Cybernia Sp. z o.o.
- Registered Address: ul. Jana Heweliusza 11/811, 80-890 Gdańsk, Poland
- E-mail: contact [at] pylonvision.com
- Registration: KRS 0001201007 (District Court Gdańsk-Północ in Gdańsk, VII Commercial Division of the National Court Register) · NIP PL 5833550916 · REGON 543035541
If you are not satisfied with our response, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland, or with the supervisory authority in your EEA member state of residence.