Privacy Policy

Last updated: 18 August 2026.

This Privacy Policy describes the rules governing the processing of personal data of users of the HEMPMED online store available at https://hempmed.eu, including customers, persons contacting the Seller and recipients of marketing communications.

1. Data Controller

The controller of personal data is Ahura Michał Müller, ul. Łąkowa 7, 66-415 Chwalęcice, Tax ID (NIP): 5993249746, Business Register Number (REGON): 386547570 (“Controller”, “HEMPMED”).

Privacy contact: hempmedkontakt@gmail.com, WhatsApp/tel. +48 575 47 20 50.

2. What data we process

Depending on how the Store is used, we may process: first and last name, company name, Tax ID (NIP), billing and delivery address, email address, telephone number, order, payment and delivery data, correspondence, customer account data, consents and marketing preferences, as well as technical data such as IP address, device and cookie identifiers, browser type, information about activity in the Store and security logs. As a rule, the Controller does not receive full payment card details; these are processed by the selected payment service provider.

3. Purposes, legal bases and retention periods

  • Processing orders, payments, delivery, accounts and pre-contractual contact — Article 6(1)(b) GDPR; for the duration of the contract and thereafter until the expiry of the applicable limitation periods for claims.
  • Issuing and retaining accounting and tax documents and complying with other legal obligations — Article 6(1)(c) GDPR; for the period required by law, generally 5 years calculated in accordance with tax legislation.
  • Handling complaints, returns, enquiries and correspondence — Article 6(1)(b), (c) or (f) GDPR; for the time required to resolve the matter and until the expiry of the limitation period for claims. The legitimate interest is efficient customer service and the establishment, exercise or defence of claims.
  • Preventing abuse, ensuring Store security, documenting events and compiling technical statistics — Article 6(1)(f) GDPR; for the period necessary to protect the Store and investigate an incident. The legitimate interest is the security of services and transactions.
  • Newsletter and electronic marketing — Article 6(1)(a) GDPR and the consent required by electronic communications law; until consent is withdrawn, with evidence of consent retained until any related claims become time-barred.
  • Analytics, personalisation and marketing based on non-essential cookies — Article 6(1)(a) GDPR; until consent is withdrawn or the relevant cookie expires.
  • Maintaining customer account data — Article 6(1)(b) GDPR; until the account is deleted and thereafter to the extent necessary to comply with legal obligations or protect claims.

If a different statutory retention period applies in a specific case, data are retained for that period. Once it expires, the data are deleted or anonymised.

4. Recipients of data

Data may be disclosed only to the extent necessary for the stated purposes to: providers of the e-commerce platform and hosting services (in particular Shopify); providers of IT support, security, analytics and email services; payment operators (e.g. PayPal, banks and, once this method is made available, Przelewy24); courier companies (e.g. InPost Courier, DPD or DHL, where the given method is available); the accounting office; legal advisers; marketing entities acting on the basis of consent; and public authorities where disclosure is required by law. Processors act on the Controller's instructions under appropriate agreements unless the law provides otherwise.

5. Transfers outside the European Economic Area

In connection with the use of Shopify and other technology services, data may also be processed outside the EEA, in particular in Canada or the United States. Transfers take place on the basis of a European Commission adequacy decision, standard contractual clauses or another mechanism provided for in Chapter V of the GDPR. Information about the safeguards used, or a copy of them, may be obtained by contacting the Controller.

6. Voluntary provision of data

Providing data is voluntary, but data marked as required are necessary to conclude and perform the contract, arrange delivery, settle payment or provide a response. Failure to provide such data may make it impossible to place or process an order. Consent to marketing and non-essential cookies is voluntary and is not a condition of purchase.

7. Rights of data subjects

Within the limits set out in the GDPR, you have the right to: access your data and obtain a copy, rectification, erasure, restriction of processing, data portability, object to processing based on legitimate interests, and withdraw consent at any time without affecting the lawfulness of processing carried out before its withdrawal. Requests may be sent to hempmedkontakt@gmail.com.

A person who believes that their data are being processed unlawfully may lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.

8. Automated decision-making

Data may be used for basic content personalisation, analytics or fraud detection. HEMPMED does not make decisions concerning customers based solely on automated processing that produce legal effects or similarly significantly affect them. If such a process is introduced, the customer will receive the separate information required by the GDPR.

9. Cookies and similar technologies

The Store uses cookies that are necessary for the operation of the shopping cart, login, security and remembering settings. With the user's consent, analytics, functional and marketing cookies may also be used. Consent may be given, refused or withdrawn using the privacy/cookie settings tool available in the Store. Browser settings also make it possible to restrict cookies, but blocking essential cookies may interfere with the operation of the Store. Current information about providers and cookie retention periods is available in the Store's privacy settings.

10. Newsletter

The newsletter is sent only to persons who have given their consent. You may unsubscribe at any time using the unsubscribe link in a message or by contacting the Controller. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

11. Data security

The Controller applies appropriate technical and organisational measures, including encrypted connections, access controls, data minimisation and the security measures of the Shopify platform. However, no method of transmitting or storing data guarantees absolute security.

12. Children's data

The Store is not directed at children. A person without full legal capacity should not place an order without the required consent of their legal representative.

13. Changes to this Policy

This Policy may be updated if the law, Store functions or service providers change. The current version and its effective date are published on this page. Changes do not limit rights already acquired by customers.