Privacy Policy

Last updated: 17 April 2026

1. Data Controller

The data controller for this website is:
ZILIO Marzena Rewers
Gliwicka 35, 42-600 Tarnowskie Góry, Poland
EU VAT ID: PL6451705993
Email: info@nis-2-templates.com

2. What Data We Collect

2.1 Website Visitors (No Account Required)

  • Server log data: IP address, browser type, operating system, referring URL, pages visited, date and time of access. Legal basis: legitimate interest (Article 6(1)(f) GDPR) in website security and performance monitoring.
  • Cookies: See Section 5.

2.2 Customers (Template Purchases)

  • Contact data: name, email address, company name (if provided). Legal basis: performance of contract (Article 6(1)(b) GDPR).
  • Billing data: billing address, VAT ID. Legal basis: performance of contract and legal obligation (Article 6(1)(b) and (c) GDPR).
  • Payment data: processed directly by our payment processor (Stripe); we do not store credit card numbers or full payment details internally.
  • Transaction data: purchase history and download records. Legal basis: performance of contract (Article 6(1)(b) GDPR).

2.3 Contact Form and Email Enquiries

Data submitted via contact form or email is collected solely to respond to your enquiry. Legal basis: legitimate interest or pre-contractual relationship (Article 6(1)(b) and (f) GDPR).

2.4 NIS2 Readiness Check Tool

All answers entered in the Readiness Check tool are processed locally in your browser and are not transmitted to our servers unless you voluntarily submit your email address to receive results.

3. How We Use Your Data

  • Delivering purchased templates and processing payments
  • Issuing invoices and complying with tax and accounting obligations, including mandatory submission to the Polish National e-Invoicing System (KSeF) for domestic B2B invoices
  • Responding to enquiries and providing customer support
  • Improving website content, functionality, and services
  • Ensuring website security and preventing fraud

4. Data Sharing and Sub-Processors

We do not sell personal data. We share personal data only with the recipients listed below, each of whom is bound by a data processing agreement in accordance with Article 28 GDPR.

Recipient Purpose Data categories Location
Stripe Payments Europe, Ltd.
1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
stripe.com/privacy
Payment authorisation and processing, fraud prevention Name, email, billing address, card/payment details, IP, transaction amount EU (Ireland), with limited transfers to Stripe, Inc. (US) under EU Standard Contractual Clauses
Fakturownia (operator established in Poland)
fakturownia.pl/polityka-prywatnosci
Automated invoice generation, invoice storage, KSeF submission Name, company name, billing address, VAT/NIP number, purchase details EU (Poland)
Krajowy System e-Faktur (KSeF)
Ministerstwo Finansów / Krajowa Administracja Skarbowa, Warsaw, Poland
podatki.gov.pl/ksef
Mandatory e-invoice archiving for Polish B2B transactions (legal obligation under Polish VAT law) Invoice data: seller and buyer NIP, amounts, VAT, invoice line items EU (Poland) — government system
cyber_Folks S.A. (hosting)
cyberfolks.pl/polityka-prywatnosci
Website hosting, backup, server security All data transmitted to/stored on the website EU (Poland)
Email / transactional mail
Transactional emails (order confirmations, download links, invoices) are sent via the hosting provider’s mail infrastructure.
Sending transactional and support emails Name, email address, order/invoice details EU
Accountant / tax advisor Statutory bookkeeping and tax filing under Polish law Invoice data, transaction records EU (Poland)
Public authorities Where required by law or to protect our legal rights (e.g., tax authorities, courts) As legally required EU (Poland)

5. Cookies and Tracking Technologies

This website uses cookies. A cookie is a small text file placed on your device when you visit a website. We use a cookie consent management tool to ensure that non-essential cookies are only set with your explicit consent.

You can manage or withdraw your cookie preferences at any time by clicking the Cookie Settings link in the website footer.

5.1 Strictly Necessary Cookies

These cookies are required for the website to function correctly. They cannot be disabled.

Cookie Purpose Duration
WordPress session cookies Core website functionality and authentication Session
woocommerce_cart_hash, woocommerce_items_in_cart Maintains shopping cart state Session / 48 hours
wp_woocommerce_session_* WooCommerce customer session data 48 hours
__stripe_mid, __stripe_sid Stripe fraud prevention during checkout 1 year / 30 minutes
cmplz_* (Complianz) Stores your cookie consent preferences 365 days

5.2 Analytics Cookies

Analytics cookies help us understand how visitors interact with the website. These cookies are only activated with your prior consent.

Cookie Provider Purpose Duration
No analytics cookies are currently active. This table will be updated if analytics tools are introduced.

5.3 Marketing and Third-Party Cookies

We do not use advertising, retargeting, or social media tracking cookies on this website.

6. Data Retention

  • Server log data: deleted after 30 days
  • Customer and transaction data: retained for the duration of the business relationship plus the statutory period under Polish tax law (currently 5 years from the end of the relevant tax year)
  • Invoice data in KSeF: archived by the Polish tax authority for 10 years as required by law — we have no control over deletion
  • Contact enquiries: retained for up to 12 months after the last communication, unless a longer period is required by law
  • Cookie consent records: retained for 12 months in line with the consent period

7. Your Rights Under GDPR

As a data subject you have the following rights:

  • Right of access (Article 15) — request a copy of the personal data we hold about you
  • Right to rectification (Article 16) — request correction of inaccurate or incomplete data
  • Right to erasure (Article 17) — request deletion of your data, subject to legal retention obligations
  • Right to restriction of processing (Article 18) — request that we limit how we process your data
  • Right to data portability (Article 20) — receive your data in a structured, machine-readable format
  • Right to object (Article 21) — object to processing based on legitimate interest
  • Right to withdraw consent (Article 7(3)) — withdraw consent at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at info@nis-2-templates.com. We will respond within 30 days.

8. Supervisory Authority

The lead supervisory authority for ZILIO Marzena Rewers is:

Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
Website: https://uodo.gov.pl/

You also have the right to lodge a complaint with the supervisory authority in your EU member state.

9. International Data Transfers

Personal data is primarily processed and stored within the EEA. Limited transfers may occur to Stripe, Inc. in the United States for global payment processing and fraud prevention; such transfers are governed by EU Standard Contractual Clauses as approved by the European Commission.

10. Security

We implement appropriate technical and organisational security measures including SSL/TLS encryption for all data in transit, access controls, and regular security reviews.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. Updates take effect upon publication. We recommend reviewing this page periodically.

12. Contact

ZILIO Marzena Rewers
Gliwicka 35, 42-600 Tarnowskie Góry, Poland
Email: info@nis-2-templates.com