Privacy policy

DIAL-HOUSE PRIVACY POLICY

Last updated: 16 June 2026

§ 1. General provisions

This Privacy Policy sets out the rules for the processing of personal data of users of the Dial-House online store, available at: https://dial-house.com.

The controller of personal data is:

Karol Góral
conducting sales as part of a non-registered business activity
address: Stary Szlak 46E, 70-870 Szczecin, Poland
e-mail: kontakt@dial-house.com
phone: +48 504 132 589

The controller conducts sales as part of a non-registered business activity pursuant to Article 5(1) of the Act of 6 March 2018 - Entrepreneurs' Law.

If the controller begins conducting registered business activity, this Privacy Policy will be promptly updated with the controller's registration details, including tax identification number, statistical number and other required information.

The Dial-House store operates using the Shopify platform, which enables the operation of the online store, shopping cart, orders, payments, customer accounts, communication with customers and other functions related to online sales.

Using the store, placing orders, contacting the store, using forms, subscribing to the newsletter or contacting us regarding the purchase, exchange, finding or sourcing of a watch may involve the processing of personal data.

Personal data is processed in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter referred to as the GDPR.

§ 2. What personal data we may process

Depending on how the store is used, we may process the following personal data:

a) identification data - first name, surname, company name, if provided,

b) contact data - e-mail address, phone number, correspondence address, delivery address, billing address,

c) order data - order number, order history, selected products, price, delivery method, order fulfilment status,

d) payment data - information about the payment method, payment status, transaction identifiers, payment confirmations and other data necessary to process payments; full payment card details are processed by payment operators and are not stored directly by Dial-House,

e) customer account data - if the customer creates an account or uses a Shopify customer account,

f) data provided in forms - in particular information regarding the watch being sought, customer preferences, budget, brand, model, reference number, condition of the watch, preferred form of contact, consent to be contacted and the content of the message,

g) data related to purchase or exchange - information about the submitted watch, photographs, condition description, completeness of the set, documents, origin of the watch and contact details of the person submitting it,

h) communication data - the content of e-mails, forms, conversations, enquiries, complaints, returns and other correspondence with the store,

i) technical data - IP address, device data, browser type, operating system, cookie identifiers, data on how the website is used,

j) marketing data - e-mail address, marketing preferences, consent history, information about subscribing to or unsubscribing from the newsletter.

We do not require the provision of special categories of data, such as data concerning health, political opinions, religion, sexual orientation or ethnic origin. Please do not provide such data in forms or messages.

Providing data is voluntary, but in some cases it is necessary to fulfil an order, respond to an enquiry, handle a form, delivery, payment, complaint or return.

§ 3. Sources of personal data

We may receive personal data:

a) directly from the customer - when placing an order, completing a form, contacting us by e-mail or phone, subscribing to the newsletter or creating an account,

b) automatically - when using the website, through cookies and similar technologies,

c) from service providers - in particular from Shopify, payment operators, courier companies, form tools, analytics tools or e-mail service providers,

d) from technical and marketing partners - if we use such services and if this complies with applicable law and the user's consent settings.

§ 4. Purposes and legal bases for processing data

We process personal data for the following purposes:

a) handling orders and sales of products - pursuant to Article 6(1)(b) of the GDPR, that is, for the performance of a contract or in order to take steps prior to entering into a contract,

b) processing payments - pursuant to Article 6(1)(b) of the GDPR and Article 6(1)(c) of the GDPR, if the processing results from legal obligations,

c) delivery of products - pursuant to Article 6(1)(b) of the GDPR,

d) handling the "Find a watch", "Source a watch", "Purchase / exchange" forms and other contact forms - pursuant to Article 6(1)(b) of the GDPR, where the enquiry is aimed at entering into a contract, or Article 6(1)(f) of the GDPR, that is, the legitimate interest of the controller consisting in handling enquiries and communication with the customer,

e) contacting the customer and handling correspondence - pursuant to Article 6(1)(f) of the GDPR,

f) handling complaints, returns and claims - pursuant to Article 6(1)(b) of the GDPR, Article 6(1)(c) of the GDPR and Article 6(1)(f) of the GDPR,

g) fulfilling tax, accounting and legal obligations - pursuant to Article 6(1)(c) of the GDPR,

h) ensuring store security, preventing abuse and fraud - pursuant to Article 6(1)(f) of the GDPR,

i) operating the newsletter and direct marketing by e-mail - on the basis of the user's consent, that is, Article 6(1)(a) of the GDPR,

j) analysing website performance, statistics and improving service quality - pursuant to Article 6(1)(f) of the GDPR or the user's consent, if a given technology requires it,

k) establishing, pursuing, defending or settling claims - pursuant to Article 6(1)(f) of the GDPR.

In the case of electronic marketing, the legal basis for processing is, as a rule, the user's consent. A legitimate interest may constitute the legal basis only in cases permitted by applicable specific provisions.

The controller's legitimate interest includes, in particular:

a) handling customer enquiries,

b) ensuring store security,

c) protection against abuse,

d) pursuing and defending claims,

e) improving the quality of service,

f) analysing the operation of the store,

g) communication with customers in matters related to orders, forms, complaints and returns.

§ 5. "Find a watch", "Source a watch" and "Purchase / exchange" forms

Data provided in the forms is used to handle the customer's enquiry, prepare a response, present a watch proposal, individual offer, the possibility of sourcing a watch, verification of the submitted watch or contact regarding purchase or exchange.

Submitting a form does not constitute the conclusion of a sales agreement or an obligation to purchase a product. Detailed rules for using the forms are set out in the Terms and Conditions of the Dial-House online store, if published on the store's website.

In the forms, we may process data such as:

a) first name and surname,

b) e-mail address,

c) phone number,

d) preferred form of contact,

e) information about the watch being sought,

f) budget,

g) brand, model, reference number,

h) preferred condition and set completeness,

i) message content,

j) photographs or information about a watch submitted for purchase or exchange.

Data from the forms is processed for the time necessary to handle the enquiry, and then for the period necessary to secure possible claims, demonstrate the course of contact or comply with legal obligations.

§ 6. Newsletter and marketing

If the user subscribes to the newsletter or consents to receiving marketing communication, their data may be processed for the purpose of sending information about products, services, news, offers, promotions or content related to the Dial-House store.

Subscribing to the newsletter is voluntary.

Marketing communication by e-mail, SMS, phone or other similar electronic channels will be conducted only if the user has given appropriate consent or if applicable law expressly permits another basis for such communication.

The user may withdraw consent to receiving the newsletter or marketing communication at any time by using the unsubscribe link in the e-mail or by contacting the store at: kontakt@dial-house.com.

Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

Lack of marketing consent does not affect the ability to use the store or place orders.

Messages concerning order fulfilment, payment, delivery, complaint, return or response to a customer enquiry are not a newsletter and may be sent for customer service purposes.

§ 7. Cookies and similar technologies

The store uses cookies and similar technologies.

Cookies may be used in particular for the purpose of:

a) ensuring the proper operation of the store,

b) remembering the contents of the shopping cart,

c) handling login and customer account functions,

d) ensuring security,

e) analysing website traffic,

f) adapting the store's content,

g) conducting marketing activities, if the user has given appropriate consent.

Some cookies are necessary for the proper operation of the store and do not require the user's consent.

Analytical, marketing or similar cookies and technologies are used in accordance with the user's consent settings and applicable law.

The user may change cookie settings in their web browser settings. If the store provides a cookie banner or consent panel, the user may also manage consent through that tool.

Restricting or disabling certain cookies may affect the operation of the store, in particular the shopping cart, login or remembering preferences.

§ 8. To whom we may disclose personal data

Personal data may be transferred to entities that support us in operating the store and serving customers, in particular:

a) Shopify - as the provider of the online store platform,

b) payment operators, including Shopify Payments, PayPal and other available payment methods,

c) courier companies and delivery operators, in particular InPost and other carriers handling order deliveries,

d) providers of e-mail and communication services,

e) providers of contact form tools, if the form is handled by such a tool,

f) providers of IT, hosting, security and website maintenance services,

g) providers of analytics and marketing tools, if they are used in the store and in accordance with the user's consent settings,

h) accounting office, accountants, legal or tax advisers, if we use such services,

i) public authorities, courts, offices or other authorised entities, if the obligation to provide data results from legal provisions.

Data is transferred only to the extent necessary to achieve a given purpose.

Entities processing data on our behalf should process the data on the basis of appropriate agreements and in accordance with applicable law.

§ 9. Shopify and data processing by Shopify

The Dial-House store is operated through the Shopify platform.

Shopify may process users' personal data in connection with the operation of the store, order handling, payments, customer accounts, security, fraud prevention, analytics, shopping functions and other Shopify services.

To the extent that Shopify processes data on behalf of the store, it acts as a data processor.

In certain cases, Shopify may process data as a separate data controller, in particular in the scope of its own services, security, platform development, Shopify functions and Shopify's legal obligations.

More information about Shopify's data processing rules can be found in Shopify's privacy policies.

The user may use Shopify privacy tools, if they are available for the user's country or type of processing.

§ 10. Payments

Payments in the store may be handled by external payment operators, in particular Shopify Payments, PayPal or other methods available in the store.

In the case of electronic payments, payment data is processed by the payment operator. Dial-House does not store the customer's full payment card details.

Payment operators may process data in accordance with their own terms and privacy policies.

§ 11. Delivery

In order to complete delivery, the customer's data may be transferred to the selected carrier or delivery operator.

Data transferred to the carrier may include, in particular:

a) first name and surname,

b) delivery address,

c) phone number,

d) e-mail address,

e) shipment number,

f) information necessary to deliver the parcel.

If the customer chooses delivery to a parcel locker or another form of delivery requiring a phone number or e-mail address, such data may be necessary for proper delivery.

§ 12. Transfer of data outside the European Economic Area

In connection with the use of Shopify, payment operators, IT services, analytics tools, forms, e-mail services or other technology providers, personal data may be transferred outside the European Economic Area.

If data is transferred outside the European Economic Area, this is carried out using appropriate data protection mechanisms provided for by the GDPR, in particular an adequacy decision, standard contractual clauses or other legally permitted safeguards.

§ 13. Data retention period

We store personal data for the period necessary to fulfil the purpose for which it was collected.

Data related to orders, payments, sales documentation, tax documentation and settlement obligations may be stored for the period required by tax regulations, generally for 5 years, counted from the end of the calendar year in which the tax payment deadline expired.

Data related to complaints, returns, correspondence concerning orders and possible claims may be stored for the limitation period for claims resulting from applicable law.

Data processed on the basis of consent, in particular newsletter and marketing data, is processed until consent is withdrawn, and then for the period necessary to demonstrate the fact that consent was given, withdrawn or to defend against possible claims.

Data provided in contact forms, "Find a watch", "Source a watch" and "Purchase / exchange" forms is stored for the time necessary to handle the enquiry, and then for no longer than 2 years from the last contact, unless a contract has been concluded, a complaint has been submitted, a dispute has arisen, claims are being pursued or another legal basis exists for longer data retention.

Technical data and data related to cookies are stored for the period resulting from the settings of a given cookie, tool or browser.

§ 14. User rights

The data subject has the rights set out in the GDPR, in particular:

a) the right of access to data,

b) the right to receive a copy of the data,

c) the right to rectification of data,

d) the right to erasure of data,

e) the right to restriction of processing,

f) the right to data portability,

g) the right to object to data processing,

h) the right to withdraw consent at any time, if the data is processed on the basis of consent,

i) the right to lodge a complaint with a supervisory authority.

To exercise these rights, you may contact the controller at: kontakt@dial-house.com.

The controller may request additional information in order to confirm the identity of the person submitting the request, if this is necessary to protect the data.

A response to the request will be provided within the time limit resulting from applicable law.

The right to erasure, restriction of processing, objection or data portability may be subject to conditions or exclusions resulting from legal provisions, in particular where further processing is necessary to fulfil legal obligations, perform a contract, handle a complaint or pursue or defend claims.

§ 15. Complaint to the supervisory authority

The data subject has the right to lodge a complaint with a supervisory authority if they consider that the processing of their personal data violates the provisions of the GDPR.

The supervisory authority in Poland is the President of the Personal Data Protection Office.

Contact details of the Personal Data Protection Office are available on the UODO website.

§ 16. Data security

The controller applies appropriate organisational and technical measures to protect personal data against unauthorised access, loss, destruction, alteration or disclosure.

Please remember that no method of data transmission over the internet or data storage in electronic systems provides a full guarantee of security.

We recommend that the user does not send any particularly sensitive data, passwords, full payment card details or information that is not necessary to handle an enquiry or order through forms or messages.

§ 17. Children's data

The Dial-House store is not intended for children.

We do not knowingly collect children's personal data.

If a parent or legal guardian believes that a child has provided us with their personal data, they may contact us at: kontakt@dial-house.com to request its deletion, unless further processing is required by law.

§ 18. Links to external websites

The store may contain links to external websites, payment services, service providers, social media or other platforms.

After accessing an external website, the user should read its privacy policy and security rules.

The controller is not responsible for the privacy rules, security or content of websites that are not operated by the controller.

§ 19. Changes to the Privacy Policy

The controller may update this Privacy Policy in particular in the event of:

a) changes in legal provisions,

b) changes in the manner of operation of the store,

c) changes of service providers,

d) changes of technical tools,

e) commencement of registered business activity,

f) the need to clarify the rules for data processing.

The current version of the Privacy Policy is published on the store's website.

In the case of significant changes, users may be informed in a manner appropriate to the nature of the change, if required by law.

§ 20. Contact

In matters concerning privacy, personal data, exercising rights under the GDPR, cookies, newsletter or this Privacy Policy, you may contact the controller:

Karol Góral
Dial-House
Stary Szlak 46E
70-870 Szczecin
Poland
e-mail: kontakt@dial-house.com
phone: +48 504 132 589

The controller has not appointed a Data Protection Officer. In all matters concerning personal data, please contact the controller directly at: kontakt@dial-house.com.