Privacy Policy
This privacy policy describes what data we actually process in connection with using this website.
1. Data Controller
The data controller is Vittoria Fiore Gallery. Full registered details of the controller: Vittoria Fiore Gallery Viktoriya Maksysko, ul. Hoserów 56/2, 02-995 Warszawa, Polska. Tax ID (NIP): 9512608235, Business Registry Number (REGON): 540039076. Privacy enquiries may be sent using the details on the Contact page.
2. Data and Purposes
We process information submitted through contact forms, business/hotel enquiries, wedding forms, individual enquiries, workshop bookings, private/corporate workshop enquiries and, where provided, the chatbot contact form. This may include name, email, telephone, message content, event information, preferences, participant numbers, date and location. For children's workshops, only the child's age may be collected where needed to organise the activity.
3. Legal Bases
Data is processed primarily to take steps at the data subject's request before entering into a contract and to perform a contract (Article 6(1)(b) GDPR), for legitimate interests such as handling correspondence, security and the establishment, exercise or defence of legal claims (Article 6(1)(f) GDPR), and, where required, on consent (Article 6(1)(a) GDPR). Data required by tax or accounting law may be processed to comply with a legal obligation (Article 6(1)(c) GDPR).
4. Chatbot
Chat content may be stored server-side to continue the conversation and handle the enquiry. The current conversation identifier is stored in the browser's sessionStorage. Where the user selects “End conversation”, the system deletes the conversation record in accordance with the website's current functionality. Contact data is processed only if the user provides it.
5. Recipients of Data
Data may be processed by infrastructure and technical-service providers to the extent necessary to operate the website, in particular Vercel for hosting, Neon for the database, Cloudinary for storing and delivering photos/videos, and an email-delivery provider used to send notifications, as well as other providers actually used by the service at the relevant time. Links to Google, WhatsApp and social media lead to separate third-party services; their own privacy terms also apply once the user follows such a link.
6. Transfers Outside the EEA
Some providers may process data outside the European Economic Area, particularly in the United States. In such cases the controller relies on a transfer mechanism permitted by Chapter V GDPR and appropriate to the particular recipient and transfer, such as an adequacy decision (including, where applicable, the EU–US Data Privacy Framework) or appropriate safeguards such as Standard Contractual Clauses. The mechanism stated and used must match the provider's actual current terms.
7. Retention
Enquiries that do not lead to a contract: generally up to 12 months after the contact ends, unless longer retention is necessary for the establishment, exercise or defence of legal claims. Chatbot conversations without further cooperation: generally up to 6 months, unless the user deletes the conversation earlier or another lawful basis requires further processing. Data relating to concluded contracts, accounting or complaints: for the periods required by tax/accounting law and as necessary for legal claims. Data processed solely on consent: until consent is withdrawn or the purpose ends, unless another lawful basis applies. The vfg_session analytics identifier: up to 180 days from the last visit. The controller should periodically review stored data and delete data no longer needed.
8. Rights
Subject to the GDPR, data subjects may request access, rectification, erasure, restriction, portability, object to processing based on legitimate interests, and withdraw consent. A complaint may also be lodged with the President of the Polish Personal Data Protection Office (UODO).
9. Cookies and Analytics
Strictly necessary mechanisms may operate without consent where they are necessary to provide a service requested by the user or to transmit a communication. Functional, analytics and marketing mechanisms that require consent are activated only after consent. Google Analytics 4 and Meta Pixel are currently inactive and should not be enabled without appropriate consent configuration and updated user information.
10. Security and Changes
We apply technical and organisational measures appropriate to risk, including HTTPS, protected administrative access, access controls and abuse-prevention mechanisms. This Policy may be updated when processing, providers or applicable law changes. The current version is published on the website.
