INFORMATION ON THE PROCESSING OF CLIENTS’ PERSONAL DATA
SHOTTAS | www.shottasseeds.com
Last updated: 22 September 2026
1 — General Information on the Processing of Personal Data
1. Pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [hereinafter the “Regulation”], NEXURA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Kolista 25, 40-486 Katowice, REGON: 529659910, NIP: 6343044968, KRS: 0001127082, as the data Controller, hereby provides the following information on the processing of personal data of Clients using the Shop.
2. The personal data Controller takes care of the security of the data made available to it. All data is protected and secured against disclosure to unauthorised persons, removal by an unauthorised person, processing in breach of the provisions of the Regulation, and unauthorised alteration, loss, damage or destruction. Personal data is processed by the Controller in accordance with the provisions of the GDPR and the Polish provisions supplementing the GDPR.
3. Processing of personal data means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
4. Personal data means information relating to an identified or identifiable natural person (data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2 — Identification Details of the Personal Data Controller
1. The Controller of the Client’s personal data is NEXURA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Kolista 25, 40-486 Katowice, REGON: 529659910, NIP: 6343044968, KRS: 0001127082. In the remainder of this Information, the Controller is also referred to as NEXURA.
2. You can contact the Controller in matters relating to the processing of your personal data, including in order to exercise your rights (access, rectification, erasure, restriction, portability, objection), via:
a. email address: info@shottasseeds.com
b. postal address: ul. Kolista 25, 40-486 Katowice, Poland
3. The Controller has not appointed a Data Protection Officer (DPO). All questions concerning the protection of personal data should be directed to the contact details above.
3 — Legal Basis, Purposes of Processing Personal Data and Requirement to Provide Data
1. NEXURA processes the Client’s personal data primarily for purposes related to the conclusion of the Sale Agreement and the Account Management Agreement (hereinafter also jointly referred to as: the Agreement), and subsequently their performance, settlement and termination. This also includes the processing of personal data related to communication between NEXURA and the Client, to the extent necessary to perform the Agreement. NEXURA processes this personal data on the basis of Article 6(1)(b) of the Regulation, because the processing of this data is necessary for the conclusion and performance of the Agreement to which the Client is a party, and for taking steps related to its conclusion — prior to entering into the Agreement. Providing personal data for this purpose is a contractual as well as a statutory requirement. If the data is not provided, the Controller will not conclude the Agreement.
2. NEXURA also processes personal data for the purpose of handling complaints submitted by the Client concerning the Sale Agreement and/or the Account Management Agreement. NEXURA processes this personal data on the basis of Article 6(1)(f) of the Regulation, i.e. because the processing of this data is necessary for the purposes of the legitimate interests pursued by the Controller in connection with defending against claims. Providing personal data for this purpose is a contractual requirement. If the data is not provided, the Controller will not conclude the Agreement.
3. NEXURA also processes the Client’s personal data for the purpose of possibly pursuing claims related to the non-performance or improper performance by the Client of obligations arising from the Agreement, in particular obligations related to payment of the remuneration due from the Client for the sale of Products. NEXURA processes this personal data on the basis of Article 6(1)(f) of the Regulation. Providing personal data for this purpose is a contractual requirement. If the data is not provided, the Controller will not conclude the Agreement.
4. NEXURA processes the Client’s personal data for the purposes of marketing its own services and services offered by entities affiliated with NEXURA. NEXURA processes this personal data on the basis of Article 6(1)(a) of the Regulation, i.e. on the basis of the Client’s consent.
5. NEXURA also processes the Client’s personal data because of legal obligations incumbent on NEXURA, in particular those arising from tax law. NEXURA processes this personal data on the basis of Article 6(1)(c) of the Regulation, i.e. because the processing of data is necessary for compliance with legal obligations to which the Controller is subject. Providing personal data for this purpose is a statutory requirement. If the data is not provided, the Controller will not conclude the Agreement.
6. NEXURA also processes the Client’s personal data for the purpose of handling requests submitted to the customer service department where they are not directly related to the conclusion or performance of the Agreement. NEXURA processes this personal data on the basis of Article 6(1)(f) of the Regulation, i.e. because the processing of this data is necessary for the purposes of the legitimate interests pursued by the Controller in connection with customer service. Providing personal data for this purpose is a contractual requirement. If the data is not provided, the Controller will not be able to carry out the procedure for handling the request.
7. NEXURA uses Google Analytics 4 to compile traffic statistics for the Shop — in the manner described in the Cookie Policy and only if the Client consents to this in the cookie banner (“Statistics” category). NEXURA processes this data on the basis of the Client’s consent (Article 6(1)(a) of the Regulation). Without consent, the Shop does not load Google Analytics and does not pass any data to this service.
8. NEXURA processes the IP address and technical connection data in order to deliver the Shop and ensure its security — via the traffic intermediary (Cloudflare), the Shop’s server and the form protection service (reCAPTCHA) — on the basis of Article 6(1)(f) of the Regulation, i.e. the Controller’s legitimate interest in ensuring the operation and security of the Shop, including the protection of forms against automated abuse.
9. Displaying the map of pickup points and determining the coordinates of the delivery address (OpenStreetMap) serve the conclusion and performance of the Agreement; the legal basis for the processing is Article 6(1)(b) of the Regulation.
4 — Categories of Personal Data Processed by the Controller
1. NEXURA primarily processes the Client’s personal data necessary for the proper performance of the Agreement and for identifying the Client, including:
a. first name(s) and surname;
b. residential address;
c. email address;
d. bank account number;
e. telephone number.
2. In addition, NEXURA processes:
a. regardless of consent — the device’s IP address and technical connection data: with every connection to the Shop (traffic intermediary Cloudflare, the Shop’s server), when the map of pickup points is displayed (OpenStreetMap) and when forms protected by the reCAPTCHA service are used — details in sections 5 and 6;
b. only after consent has been given to the “Statistics” category — data on the use of the Shop sent to Google Analytics, to the extent described in the Cookie Policy.
3. When an error occurs in the browser while the Shop is being used, the Shop sends a technical report to our server: the type of error with a short description (without addresses, numbers or strings of characters), the subpage without the address parameters, the version of the site, the type of browser and device, and the market. The report does not contain identifiers, cookies or data entered in forms; the IP address serves solely to limit the number of reports and to recognise our own monitoring check, and is not stored in the report. The report is not passed on to third parties and is deleted after 14 days. Like all traffic to the Shop, the report passes through the traffic intermediary (Cloudflare) and is stored on the hosting server — these are the processors indicated in section 5; no one else receives it.
5 — Categories of Data Recipients
1. Under the Regulation, a recipient of data means a natural or legal person, public authority, agency or other body to which the controller discloses personal data, whether a third party or not. A third party, within the meaning of the Regulation, means a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the authority of the controller or processor, are authorised to process personal data. A processor, in turn, means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
2. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients.
In view of the above explanation, NEXURA provides information on the following categories of recipients:
a. entities providing legal and accounting services related to NEXURA’s business;
b. entities providing IT services related to NEXURA’s business, including hosting services;
c. entities providing courier services;
d. subcontractors and entities cooperating with the Controller which may be commissioned to perform individual tasks related to the performance of the Agreement;
e. entities other than those indicated above which, under the law, are entitled to obtain from NEXURA information related to NEXURA’s business, which information may include the Client’s personal data.
f. GetResponse S.A., ul. Grunwaldzka 413, 80-309 Gdańsk — provider of the email marketing platform used by the Controller to send the Newsletter and manage Subscriber data (first name, email address). GetResponse acts as a processor on behalf of the Controller under a data processing agreement pursuant to Article 28 of the GDPR;
g. providers of technical infrastructure and related services, acting as processors on behalf of the Controller pursuant to Article 28 of the GDPR: OVH — hosting of the Shop’s server and database, and therefore of all Client data stored in it; Cloudflare — intermediary for all traffic to the Shop, including the Client’s IP address, request headers (including cookies) and the content of completed forms; the browser may also send Cloudflare reports on connection errors; Hetzner and Backblaze — storage of database backups, encrypted before being sent (the providers do not have the key, and Backblaze stores them in a data centre in Amsterdam, in the Netherlands); GlobKurier and the selected carrier — dispatch of the shipment: first name and surname or company name, delivery address, telephone number and email address of the recipient; CashBill — handling of electronic payments: the payer’s first name, surname and email address; bptech — handling of the Shop’s outgoing mail; OpenStreetMap Foundation — display of the map of pickup points (the Client’s IP address) and determination of the coordinates of the delivery address (postal code, city and street);
h. Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as a processor on behalf of the Controller — provider of Google Analytics 4 and Google Tag Manager, only after consent has been given to the “Statistics” category: data on the use of the Shop described in the Cookie Policy, including the device’s IP address;
i. Google — provider of the reCAPTCHA service protecting selected forms of the Shop: the device’s IP address and data on how the site is used, to the extent described in section 6;
j. the Head of the National Revenue Administration (VAT taxpayer register — “Wykaz podatników VAT”) and the European Commission (VIES system) — where a NIP number or an EU VAT number is provided in the Order, the Shop checks the taxpayer’s status in these registers by transmitting that number.
6 — Intention to Transfer Personal Data to a Third Country or an International Organisation
1. The Shop uses Google Analytics 4 and Google Tag Manager only after the Client has consented to the “Statistics” category. The data collected with them, described in the Cookie Policy, is received by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, acting as a processor on behalf of the Controller. According to Google, this data may be processed outside the European Economic Area, including in the United States. Google LLC, which may receive this data in the United States, is certified under the EU–U.S. Data Privacy Framework, for which the European Commission has found an adequate level of data protection (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, Article 45 GDPR); the terms offered by Google additionally provide for standard contractual clauses approved by the European Commission (Article 46(2)(c) GDPR). The Shop does not use Meta advertising tools or the Meta pixel. The Controller does, however, run profiles on services operated by Meta Platforms Ireland Limited (Facebook, Instagram); as regards the statistical data concerning those profiles, the Controller and Meta Platforms Ireland Limited are joint controllers within the meaning of Article 26 of the GDPR, and the essence of their arrangements is described in the Cookie Policy.
2. In connection with the use of the GetResponse email marketing platform (GetResponse S.A., ul. Grunwaldzka 413, 80-309 Gdańsk, Poland), your personal data (first name, email address) is processed for the purpose of sending the Newsletter. GetResponse S.A. is established in Poland (within the EEA); however, it uses subcontractors (sub-processors) whose infrastructure may be located outside the EEA, including in the United States of America (e.g. Google Cloud). Data is transferred on the basis of Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 (EU–U.S. Data Privacy Framework, Article 45 GDPR) or standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR), depending on the subcontractor. Information on data processing by GetResponse is available at: https://www.getresponse.com/legal/privacy The list of GetResponse sub-processors is available at: https://www.getresponse.com/legal/data-processing-agreement
3. All traffic to the Shop passes through Cloudflare (Cloudflare, Inc., United States), and the map of pickup points and the determination of the coordinates of the delivery address are provided by the OpenStreetMap Foundation (United Kingdom): the browser downloads map tiles from its servers (IP address), and the Shop’s server passes it the postal code, city and street of the delivery address in order to determine the coordinates. Data is transferred to Cloudflare, Inc. on the basis of that company’s certification under the EU–U.S. Data Privacy Framework, for which the European Commission has found an adequate level of data protection (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, Article 45 GDPR), and to the OpenStreetMap Foundation on the basis of the European Commission decision finding an adequate level of protection of personal data in the United Kingdom (Article 45 GDPR).
reCAPTCHA. The newsletter sign-up, login, account registration (including at checkout) and password recovery forms, the contact form and the complaint form are protected by the reCAPTCHA service provided by Google; the Cookie Policy describes when its script loads and which servers the browser then connects to. The browser transmits the device’s IP address and data on how the site is used to Google; the Shop’s server sends Google only the one-time code generated in the browser, in order to obtain the verification result — without the IP address. Processing may take place on servers outside the European Economic Area, including in the United States. The legal basis for the processing is Article 6(1)(f) of the Regulation (section 3, point 8), and the basis for the transfer outside the EEA is the certification of Google LLC under the EU–U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795, Article 45 GDPR) and standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR).
7 — Period of Storage of Personal Data
1. Personal data processed for the purpose of concluding the Agreement will be processed until the Agreement is concluded. If the Agreement is not concluded, the data will be erased no later than one (1) year after the Agreement conclusion procedure was discontinued. The retention periods for data processed on the basis of consent are set out in point 7.
2. Personal data processed in connection with the sale of Products will be processed for the term of the Sale Agreement and, after it expires, for a period of five (5) years from the end of the calendar year in which the tax payment deadline expired, in accordance with Article 70(1) of the Polish Tax Ordinance Act of 29 August 1997 (i.e. the statutory retention period for tax documentation).
3. Personal data processed in connection with maintaining the Account is erased (anonymised) without delay after the Client deletes the Account. Deletion of the Account does not cover data contained in previously placed Orders or in accounting records — we retain these for the periods indicated in points 2 and 5, in accordance with Article 17(3)(b) of the Regulation.
4. Data processed for the purpose of establishing, pursuing or defending claims will be processed until those claims become time-barred. Pursuant to Article 118 of the Polish Civil Code, the general limitation period for claims is six (6) years from the date on which the claim became due. For claims related to conducting business activity, the limitation period is three (3) years. If the limitation period applicable in the Consumer’s country of habitual residence is longer, that longer period applies.
5. Personal data processed in order to fulfil legal obligations incumbent on the Controller — in particular those arising from tax and accounting regulations — will be processed for a period of five (5) years from the end of the calendar year in which the tax payment deadline expired (Article 70(1) of the Tax Ordinance Act), or for a longer period if required by applicable law.
6. Personal data processed for the purposes of the legitimate interests of the Controller (such as handling Client enquiries not directly related to the Agreement) will be processed for the duration of the matter concerned and for a period of one (1) year after its conclusion, unless a longer period is necessary due to the nature of the matter or pending proceedings.
7. Data processed on the basis of marketing consent (section 3, point 4) will be processed no longer than until the day on which that consent is withdrawn. Data collected by Google Analytics on the basis of consent to statistics (section 3, point 7) is retained by Google for 2 months from its collection — both event data and data associated with the browser identifier; this period is not extended by further activity. Withdrawing this consent stops further data collection; it does not delete data collected earlier — Google deletes it once this period has expired.
8 — Information on Automated Decision-Making, Including Profiling
1. The Client’s personal data will not be processed for the purpose of automated decision-making, with one exception: the form protection service (reCAPTCHA) may automatically reject a submission assessed as having been sent by an automated program. In such a case, the Client may contact the Controller (section 2).
9 — Information on Processing Data for a Purpose Other Than the Purpose for Which It Was Collected
1. NEXURA will not process personal data for a purpose other than the purpose for which the personal data was collected.
10 — Information on the Rights of the Client
1. The Client has the right to request from the Controller access to their personal data, including obtaining a copy of the personal data undergoing processing. The first copy is free of charge. For any further copies requested by the Client, the Controller may charge a reasonable fee based on administrative costs.
2. The Client has the right to request from the Controller the rectification of their personal data that is inaccurate, in particular because it was collected with errors or because it has changed since it was collected. This right also includes the completion of missing data.
3. The Client has the right to request from the Controller the erasure of their personal data, subject to the proviso that this right may be exercised in the cases specified in the Regulation. NEXURA may refuse to comply with a request for erasure in cases provided for by law, in particular where further processing is necessary for compliance with a legal obligation which requires processing under Union or Member State law, or for the establishment, exercise or defence of claims.
4. The Client has the right to request from the Controller the restriction of processing of their personal data, under the conditions set out in the Regulation.
5. The Client has the right to object to the processing of their personal data by the Controller pursuant to Article 21(1) of the Regulation, i.e. to object — on grounds relating to the Client’s particular situation — to the processing of their data based on Article 6(1)(f) of the Regulation, including profiling based on those provisions. If such an objection is raised, the Controller may no longer process the personal data concerned unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Client, or grounds for the establishment, exercise or defence of claims.
6. The Client has the right to object to the processing of their data by the Controller pursuant to Article 21(2) of the Regulation, i.e. to object to the processing of their data for direct marketing purposes, including profiling, to the extent that it is related to such direct marketing.
7. The Client has the right to data portability. The right to data portability is the right to receive, in a structured, commonly used and machine-readable format, the personal data which the Client has provided to the Controller, and the right to transmit that personal data to another controller without hindrance from the Controller. This right is available to the Client only in respect of personal data which is processed both on the basis of consent or the Agreement and by automated means. When exercising the right to data portability, the Client may also request that their personal data be transmitted by the Controller directly to another controller, where technically feasible.
8. The Client has the right to withdraw at any time any consent given — the marketing consent referred to in section 3, point 4, and the consent to Google Analytics statistics referred to in section 3, point 7; the latter is withdrawn using the “Cookie settings” link in the footer of every page of the Shop. The withdrawal of consent does not, however, affect the lawfulness of processing carried out on the basis of consent before its withdrawal. Where the Client’s personal data is also processed on a basis other than consent, the Controller may continue to process it on that other basis.
9. The Client has the right to lodge a complaint with a supervisory authority. Pursuant to Article 77(1) of the GDPR, this right may be exercised before the supervisory authority of the EU Member State in which the Client has their habitual residence or place of work, or in which the alleged infringement took place — regardless of where the Controller is established. The lead supervisory authority for the Controller (established in Poland) is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, website: www.uodo.gov.pl. Clients residing in other EU/EEA countries may also contact their national supervisory authority. A full list of data protection authorities in the EU is available at: https://www.edpb.europa.eu/about-edpb/about-edpb/members_pl