Orvell Privacy Policy
Information on how personal data is processed in connection with using the Orvell website.
§1. Data controller
The controller of personal data processed in connection with the use of the Orvell website is a natural person selling under the Orvell brand within the scope of "działalność nierejestrowana" (unregistered small-scale activity) within the meaning of Art. 5 of the Polish Act of 6 March 2018 – Law on Entrepreneurs. The controller can be contacted via the contact details shown in the Service (e-mail address and phone number).
Unregistered small-scale activity is not entered in the CEIDG register and does not carry its own tax (NIP) or statistical (REGON) business number — which is why those details are not published here at this time. Full registered details (legal name, address, NIP, REGON) will be published if the activity is formally registered as the Service grows. This does not constitute legal advice — if in doubt about what identifying information is required, it is worth consulting a lawyer or accountant.
§2. What data may be processed
The Service does not have a contact form and does not require the User to provide any personal data (e.g. name, phone number, or e-mail address) to browse it.
If a User chooses to contact Orvell on their own initiative — by phone or e-mail — the scope of data processed follows solely from the information the User voluntarily provides during that contact (e.g. name, phone number, e-mail address, message content). The Service does not impose any mandatory fields or required data.
§3. Purposes of processing
Data provided during phone or e-mail contact may be processed to:
- handle correspondence and respond to enquiries,
- continue contact with the User on the matter they raised,
- establish, pursue, or defend against potential claims,
- fulfil legal obligations of the controller, where such obligations arise (e.g. under tax or accounting law).
§4. Legal bases for processing
- handling enquiries and contacting the User — Art. 6(1)(f) GDPR (controller's legitimate interest), and, to the extent contact aims at concluding a contract — Art. 6(1)(b) GDPR,
- establishing, pursuing, or defending against claims — Art. 6(1)(f) GDPR (controller's legitimate interest),
- fulfilling legal obligations — Art. 6(1)(c) GDPR, where such an obligation actually arises.
§5. Recipients of data
Data may be entrusted to parties supporting the controller in operating the Service and handling correspondence — in particular the Service's hosting provider (Netlify, Inc.), its e-mail provider (Google LLC — Gmail), and the provider of the analytics tool (Cloudflare, Inc.) that counts visits to the Service without cookies and without identifying individual Users (see §9).
Beyond the parties listed above, data is not shared with other recipients unless required by law.
§6. Data retention period
Personal data provided during contact with Orvell is retained for as long as necessary to achieve the purpose for which it was provided (in particular, until a reply is given and correspondence concludes), and afterwards — where necessary — for a period resulting from generally applicable law or until any potential claims become time-barred.
§7. User rights
A data subject has the right to:
- access their data,
- rectify (correct) their data,
- erase their data,
- restrict processing,
- data portability — where applicable,
- object to processing based on Art. 6(1)(f) GDPR — where applicable,
- lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) if they believe processing of their data infringes GDPR.
§8. Data security
The controller applies technical and organizational measures appropriate to the nature, scope, and purpose of the data processed, aimed at protecting personal data against unauthorized access, loss, or unauthorized disclosure.
§9. Cookies and similar technologies
The description below reflects the Service's actual technical configuration. In its current version, the Service:
- uses one strictly necessary cookie, set only when an administrator logs into the internal content-management panel (at /admin) — not set during ordinary browsing by a User,
- uses Cloudflare Web Analytics to count visits to the Service — this tool does not use cookies or any other identifier that would let it recognize a specific User across visits; it collects only aggregated, anonymous traffic statistics (e.g. visit counts, pages viewed),
- does not use marketing tools (e.g. Meta Pixel, Google Tag Manager) or Google Analytics,
- does not embed maps, videos (e.g. from YouTube or Vimeo), or other external content that could set their own cookies,
- serves fonts directly from the Service's own server rather than an external service (e.g. Google Fonts).
Accordingly, the Service does not use cookies requiring User consent under Article 173 of the Polish Telecommunications Law — the only cookie in use is strictly necessary and relates solely to the admin panel, and the analytics tool operates without cookies at all. This will be reviewed again if the Service starts using additional analytics tools, marketing tools, or other cookies.
§10. Transfers of data outside the European Economic Area
Using the services of the Service's hosting provider (Netlify, Inc.), e-mail provider (Google LLC — Gmail), and analytics provider (Cloudflare, Inc.) — all headquartered in the United States — may involve transferring data outside the European Economic Area. Each of these providers publishes a Data Processing Agreement incorporating the EU Standard Contractual Clauses approved by the European Commission, which serve as the legal basis for such a transfer under Article 46 GDPR.
This statement is based on the DPA/SCC documentation currently published by the providers listed and does not constitute legal advice. Before the Service goes into production, it is worth confirming this with a lawyer or data protection officer — in particular, whether the relevant Data Processing Agreement has actually been executed/accepted for the account the Administrator uses.
§11. Changes to this Privacy Policy
The controller reserves the right to amend this Privacy Policy, in particular in connection with changes to the Service's functionality, changes in applicable law, or the introduction of new technical tools. The current version of this Policy is always available on the Service.
Last updated: August 18, 2026.