1General provisions
1.1 The Privacy Policy of the BeautyForms Service (hereinafter: the „Service") is of an informational nature and is not a source of obligations for Visitors.
1.2 The controller of personal data processed via the Service is Rybczak i Wspólnicy Sp. z o.o. with its registered seat in Jankowice (44-264), ul. Przyjemna 4, Poland, entered into the register of entrepreneurs kept by the District Court in Gliwice, 10th Commercial Division of the National Court Register under KRS number 0000520491, NIP (tax ID) 6423187210, REGON 243640719, share capital PLN 17,500.00, e-mail address:
office@beautyforms.eu, hereinafter the „Controller".
1.3 The Visitor's personal data disclosed when using the Service or entered on its pages is collected and processed in accordance with applicable law, in particular with the General Data Protection Regulation (GDPR) and the Polish Personal Data Protection Act of 10 May 2018.
1.4 The Controller processes the Visitor's data within the following scope: first name and surname, e-mail address, IP address, domain name, browser type, operating system type and other data disclosed by the Visitor.
1.5 The Controller processes in particular the first name, surname and e-mail address provided by the Visitor for the purposes indicated in § 3 below.
1.6 The Service's pages use cookies stored on the Visitor's device in order to provide services in accordance with this Policy. By clicking the „I agree" field upon entering the Service, the Visitor consents to the processing by the Controller of their personal data obtained via cookies. Giving consent is voluntary, but its absence may make it impossible to use the Service.
1.7 Detailed matters concerning the cookies used are set out in § 9 below.
1.8 The Controller processes the Visitor's data on a legal basis and lawfully, fairly and honestly, in a manner transparent to the Visitor, for specific purposes and not „just in case", no more than necessary and no longer than necessary, taking care of the accuracy of the data and ensuring appropriate data security.
2Visitor status and type of data
2.1 A Visitor is any person browsing the web pages of the Service.
2.2 While the Visitor browses the web pages of the Service, data concerning the Visitor is collected automatically. This data includes: IP address, domain name, browser type and operating system type. This data may be collected by cookies.
2.3 The Controller also processes anonymised usage data related to the use of the Service to generate statistics used in administering the Service. This data is aggregated and anonymous and is not disclosed to third parties.
3Purpose and legal bases of processing
The Controller processes Visitors' personal data because it is necessary to achieve the purposes indicated below.
3.1 To take steps necessary before concluding an agreement or to perform a concluded agreement, including the provision of the services covered by the agreement (basis: Article 6(1)(b) GDPR).
3.2 To handle and settle payments for the Service's services, including the transfer of data necessary to carry out the transaction to the payment operator (basis: Article 6(1)(b) and (c) GDPR).
3.3 For archival purposes, to safeguard information in case of a legal need to demonstrate facts, which constitutes the Controller's legitimate interest (basis: Article 6(1)(f) GDPR).
3.4 For the possible establishment, pursuit or defence of claims, which constitutes the Controller's legitimate interest (basis: Article 6(1)(f) GDPR).
3.5 To fulfil legal obligations arising from tax and accounting regulations (basis: Article 6(1)(c) GDPR).
3.6 To survey customer satisfaction and determine the quality of service, which constitutes the Controller's legitimate interest (basis: Article 6(1)(f) GDPR).
4Voluntary provision of data
4.1 Providing data is voluntary, but may prove necessary for contact with the Controller and for the provision of services.
4.2 Providing data may also be necessary to receive commercial information about the Controller's services and to carry out payments for the Service's services.
5Transfer of personal data
5.1 The Controller may transfer personal data to the following categories of entities:
- entities whose services the Controller uses to process data, i.e. companies providing telecommunications, IT, legal and accounting services,
- entities involved in the performance of the agreement, in particular entities affiliated with the Controller,
- the electronic payment operator — to the extent necessary to handle payments for the Service's services, on the terms set out in § 6.
5.2 The Controller does not transfer the personal data obtained outside the European Union / European Economic Area or to international organisations.
6Payment operator
Online payments in the Service are handled by CashBill S.A. with its registered seat in Katowice — a domestic payment institution (clearing agent) entered in the register kept by the Polish Financial Supervision Authority (KNF). The Controller does not store payment card data or the User's electronic banking authentication data.
6.1 As part of carrying out the payment, only the data necessary to perform and identify it is transferred to the payment operator, i.e. the transaction amount, the pro-forma invoice number and the payer identification data (company name, e-mail address).
6.2 The basis for transferring data to the payment operator is the necessity to perform the agreement (Article 6(1)(b) GDPR) and the fulfilment of the legal obligations incumbent on the Controller (Article 6(1)(c) GDPR).
6.3 With regard to the transaction carried out, CashBill S.A. acts as a separate data controller. The rules of data processing by the payment operator are set out in its terms and privacy policy available at
cashbill.pl.
6.4 Payment card data and electronic banking authentication data are entered directly on the side of the payment operator or the bank and are not transferred to or processed by the Controller.
6.5 The Controller receives from the payment operator only information about the transaction status (including payment confirmation, amount, date and transaction identifier) for the purpose of settling the service and issuing an accounting document.
6.6 With regard to data processed by the payment operator as a separate controller, requests concerning the exercise of the rights indicated in § 8 should be addressed directly to the payment operator.
7Data retention period
7.1 The Controller processes Visitors' data obtained for the purposes specified in § 3 for the period necessary to safeguard the Controller's rights and claims.
7.2 Data related to carrying out payments and accounting documentation is kept for the period required by tax and accounting regulations.
8Visitor rights
8.1 The Visitor is entitled to the following rights:
- the right to access their data and to obtain a copy of it,
- the right to rectify (correct) their data,
- the right to erase data,
- the right to restrict data processing,
- the right to object to data processing,
- the right to data portability,
- the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO),
- the right to withdraw consent to the processing of personal data.
8.2 The above rights are exercised by submitting a request to the Controller by sending an appropriate message in writing or by e-mail to the Controller's address indicated in § 1.2, or directly at the Controller's registered seat.
8.3 With regard to data processed by the payment operator as a separate controller, § 6.6 applies.
9Cookies policy
9.1 Cookies are IT data, in particular text files, stored on the Visitor's end device.
9.2 Cookies usually contain the name of the website they come from, the time they are stored on the end device and a unique number. These files are safe for the Visitor's device and have no harmful effect on the end device.
9.3 Consent to the storage of cookies is voluntary, but may prove necessary to use the Service or to contact the Controller.
9.4 The Controller may process data contained in cookies for the following purposes:
- to enable the basic functionalities of the Service, such as access to secure areas of the website,
- to determine the Visitor's profile in order to adapt the content of the Service's pages to their preferences,
- to keep anonymous statistics showing how the Service's pages are used,
- to authenticate the Visitor and maintain the session in the Service,
- to ensure the correct and secure course of online payments carried out by the payment operator.
9.5 The Visitor can define the conditions for using cookies through their own web browser settings. The possibility of storing cookies can be partially restricted or completely disabled — in the latter case, this may affect some functionalities of the Service, including the ability to carry out online payments.
9.6 Detailed information on changing cookie settings and deleting them on your own in the most popular web browsers is available in the help section of each browser.
10Cookies used
10.1 The Service uses two basic types of cookies: „session" cookies and „persistent" cookies. Session cookies are temporary files stored until logout or until the browser is closed. Persistent cookies are stored for the time specified in the file parameters or until deleted by the User.
10.2 List of cookies used in the Service:
| Name |
Type |
Expiry time |
Purpose |
| PHPSESSID |
session |
until the browser is closed |
A native PHP file — allows the user's session state data to be remembered. |
| cookies-accepted |
persistent |
1 year |
Stores information about acceptance or rejection of the cookies policy. |
| payment operator cookies |
session |
duration of the transaction |
Files stored in the payment operator CashBill S.A. domain while carrying out online payments — necessary to perform and secure the transaction. The rules of their use are set out in the operator's privacy policy. |
10.3 Information on deactivating cookies in the most popular browsers is available at the following addresses:
11Final provisions
11.1 The provisions of this Privacy Policy are subject to Polish substantive and procedural law.
11.2 The Controller provides the following technical measures to prevent unauthorised persons from obtaining and modifying personal data transmitted electronically:
- protecting data against unauthorised access,
- encrypting transmission with an SSL certificate,
- carrying out online payments solely via a domestic payment operator supervised by the Polish Financial Supervision Authority.
11.3 In matters not regulated by this Privacy Policy, the provisions of the Service's
Terms of Service apply.
11.4 The Controller reserves the right to introduce changes and corrections to the Privacy Policy and the rules for using cookies.
⏰ The Privacy Policy comes into force on: 27 February 2026