Skip to content
The products offered on this site are intended for research purposes only. They are not intended for consumption or use by humans or animals.
purepoint SUPPLY
  • Shop
  • Vidensbase
  • Juridisk center
  • Contact
  • FAQ
  • Beregner
  • Kvalitet
  • Levering i EU
  • Om os
Languages
🇵🇱PL🇬🇧EN🇩🇪DE🇩🇰DA
Currencies
🇩🇰DKK🇵🇱PLN🇪🇺EUR🇺🇸USD🇬🇧GBP🇸🇪SEK🇨🇿CZK
🇵🇱PolskiPL🇬🇧EnglishEN🇩🇪DeutschDE🇩🇰DanskDA
🇩🇰Dansk kroneDKK🇵🇱Polski złotyPLN🇪🇺EuroEUR🇺🇸US dollarUSD🇬🇧British poundGBP🇸🇪Svensk kronaSEK🇨🇿Česká korunaCZK
Welcome to PUREPOINT Log in Create account
0
Home / Legal Center / Privacy Policy

Legal document

Privacy Policy

Operator
FIRSTSTONE TRADING sp. z o.o.
Version
2.0
Effective date
2026-06-06
Last updated
2026-08-09
Language
Polish
Legal contact
compliance@purepoint.pl

Operator (Data Controller of personal data): FIRSTSTONE TRADING spółka z ograniczoną odpowiedzialnością (FIRSTSTONE TRADING sp. z o.o.) KRS: 0001254766 | NIP: 7831958614 Registry court: District Court Poznań – Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the National Court Register Registered office: ul. Wierzbięcice 44A/40A, 61-568 Poznań, województwo wielkopolskie Voivodeship Correspondence / Shop service address: ul. Wierzbięcice 44A/40A, 61-568 Poznań (one hundred shares of fifty zlotys each) Representation: Krystian Dawidowski — Member of the Management Board (sole-member management board, independent representation) Electronic delivery address (ADE): AE:PL-21312-60691-FGBFV-19 E-mail address (data protection matters): compliance@purepoint.pl E-mail address (Shop service): contact@purepoint.pl Shop domain: purepoint.pl

Document version: 2.0 Publication date: 6 June 2026 Effective date: from 6 June 2026 Review cycle: quarterly


Table of contents

  1. § 1. Introduction and legal framework
  2. § 2. Definitions
  3. § 3. Controller of personal data
  4. § 4. Data Protection Officer — justification for not appointing one
  5. § 5. Categories of personal data processed by the Operator
  6. § 6. Purposes of processing and legal bases (Art. 6(1) GDPR)
  7. § 7. Personal data retention period
  8. § 8. Recipients of personal data
  9. § 9. Transfer of data to third countries — Schrems II analysis
  10. § 10. Rights of data subjects
  11. § 11. Security of personal data
  12. § 12. Personal data breaches (Art. 33–34 GDPR)
  13. § 13. No obligation to appoint a representative in the EU
  14. § 14. Cookies and similar technologies
  15. § 15. Newsletter — reference
  16. § 16. Complaints, complaints to UODO (Polish DPA) and judicial remedies
  17. § 17. Bibliography and sources
  18. § 18. Change history
  19. § 19. Final clause

§ 1. Introduction and legal framework

  1. This document — hereinafter referred to as the “Privacy Policy” — describes the principles for processing the personal data of natural persons using the online shop available at the domain purepoint.pl, hereinafter referred to as the “Shop”. The Shop is operated by FIRSTSTONE TRADING spółka z ograniczoną odpowiedzialnością, with its registered office in Poznań (Kartuzy municipality, Pomeranian Voivodeship), entered in the register of entrepreneurs of the KRS under number 0001254766, hereinafter referred to as the “Operator” or the “Controller”.
  2. The Privacy Policy has been prepared in order to fulfil the information obligation arising from Art. 13 and Art. 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC — General Data Protection Regulation (OJ EU L 119 of 04.05.2016, p. 1, as amended), hereinafter referred to as the “GDPR (RODO)”.
  3. The Operator processes personal data in accordance with the GDPR (RODO), the Act of 10 May 2018 on the Protection of Personal Data (consolidated text: Journal of Laws 2019, item 1781, as amended), hereinafter the “u.o.d.o.”, the Act of 18 July 2002 on Providing Services by Electronic Means (consolidated text: Journal of Laws 2024, item 1513, as amended), hereinafter the “u.ś.u.d.e.”, the Act of 16 July 2004 — Telecommunications Law (consolidated text: Journal of Laws 2024, item 34, as amended) as regards cookies, and specific provisions.
  4. The Shop conducts its activity in the segment of research materials (research use only) and is available exclusively to Qualified Buyers — the detailed qualification rules are set out in the Shop Terms and Conditions. Consequently, the status of the data subject is not identical to the status of a consumer within the meaning of Art. 22(1) of the Act of 23 April 1964 — Polish Civil Code (consolidated text: Journal of Laws 2024, item 1061, as amended), hereinafter the “KC”. Notwithstanding the above, the rights arising from the GDPR (RODO) are vested in every natural person to the full extent, because the GDPR (RODO) protects the natural person regardless of their consumer status.
  5. The Privacy Policy covers in particular: a) identification of the Controller and the contact channels for data protection matters; b) the purposes of processing and the legal bases arising from Art. 6(1) GDPR; c) the categories and sources of the data processed; d) the data retention periods and their justification; e) the categories of data recipients and an analysis of transfers to third countries in light of the judgment of the Court of Justice of the EU in case C-311/18 Data Protection Commissioner v. Facebook Ireland Ltd, Maximillian Schrems (hereinafter “Schrems II”); f) the rights of data subjects and the procedures for exercising them; g) the technical and organisational measures implemented by the Operator.
  6. The Operator declares that it applies the principles arising from Art. 5(1) GDPR: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity and confidentiality. The burden of proof regarding fulfilment of the accountability obligation (Art. 5(2) GDPR) rests with the Operator and is met by maintaining an internal Record of Processing Activities (RCP) in accordance with Art. 30(1) GDPR.
  7. The Privacy Policy is subject to a periodic review at least once a quarter and, in the event of legal, organisational or technological changes affecting the processing of data — without delay. The document’s change history is set out in § 18.

§ 2. Definitions

The terms used in this Privacy Policy mean:

  1. “Shop” — the online shop operated by the Operator at the domain purepoint.pl together with functional subdomains.
  2. “Buyer” — a natural person, a legal person or an organisational unit to which the law grants legal capacity, making a purchase in the Shop or submitting an enquiry. In the context of the Shop, the Buyer is at the same time a “Qualified Buyer”, because the Shop does not serve consumers (Art. 22(1) KC).
  3. “KOP” — the Qualified Profile Declaration, i.e. the set of declarations made by the Qualified Buyer in the course of account registration or placing the first order, described in the Shop Terms and Conditions.
  4. “NK” — abbreviation denoting the Qualified Buyer.
  5. “Personal data” — any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
  6. “Processing” — an operation or set of operations performed on personal data (Art. 4(2) GDPR).
  7. “Processor” — a natural person, legal person, public authority, agency or other body which processes personal data on behalf of the Controller (Art. 4(8) GDPR).
  8. “UODO” — the Personal Data Protection Office with its registered office in Warsaw, ul. Stawki 2, 00-193 Warsaw, the supervisory authority within the meaning of Art. 51 GDPR.
  9. “EROD” — the European Data Protection Board established pursuant to Art. 68 GDPR.
  10. “Third country” — a country not belonging to the European Economic Area (EEA).
  11. “SCC” — the standard contractual clauses referred to in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  12. “Schrems II” — the judgment of the Court of Justice of the EU of 16 July 2020 in case C-311/18.
  13. “Research Material” or “Product” — materials offered in the Shop exclusively for research purposes (research use only), which are not medicinal products, dietary supplements, cosmetics or foodstuffs.
  14. “KC” — the Act of 23 April 1964 — Polish Civil Code (Journal of Laws 2024, item 1061, as amended).
  15. “KK” — the Act of 6 June 1997 — Penal Code (Journal of Laws 2024, item 17, as amended).
  16. “PF” — the Act of 6 September 2001 — Pharmaceutical Law (consolidated text: Journal of Laws 2025, item 750, previously Journal of Laws 2024, item 686, as amended).
  17. “UPK” — the Act of 30 May 2014 on Consumer Rights (consolidated text: Journal of Laws 2024, item 1796, as amended).
  18. “AML” — the Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing (consolidated text: Journal of Laws 2025, item 168, as amended).

§ 3. Controller of personal data

  1. The Controller of personal data within the meaning of Art. 4(7) GDPR is FIRSTSTONE TRADING spółka z ograniczoną odpowiedzialnością (abbreviated company name: FIRSTSTONE TRADING sp. z o.o.) with its registered office in Poznań, ul. Wierzbięcice 44A/40A, 61-568 Poznań, województwo wielkopolskie Voivodeship. The company was entered in the register of entrepreneurs of the National Court Register kept by the District Court Poznań – Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the KRS, under number KRS 0001254766 on 17 February 2026. The company was assigned the tax identification number NIP 7831958614 and the statistical number . The company’s share capital amounts to PLN 5,000.00 (in words: five thousand zlotys) and is divided into 100 (one hundred) shares with a nominal value of PLN 50.00 (fifty zlotys) each.
  2. The company is represented on a sole basis by Krystian Dawidowski — Member of the Management Board (sole-member management board, independent representation in accordance with the company’s articles of association).
  3. The Operator has designated the following contact channels for all matters relating to the processing of personal data: a) postal correspondence address: FIRSTSTONE TRADING sp. z o.o., ul. Wierzbięcice 44A/40A, 61-568 Poznań (operational address dedicated to the Shop service and for all correspondence in GDPR (RODO) matters); b) e-mail address dedicated to data protection matters: compliance@purepoint.pl; c) Shop service e-mail address (matters of orders, complaints, commercial correspondence): contact@purepoint.pl; d) electronic delivery address (ADE) in accordance with the Act of 18 November 2020 on Electronic Deliveries (consolidated text: Journal of Laws 2024, item 723, as amended): AE:PL-21312-60691-FGBFV-19.
  4. Telephone contact is available to Buyers holding an account in the order service panel and on request at compliance@purepoint.pl — the Operator does not provide a public telephone number in consumer transactions, because the Shop does not serve consumers (see § 1 para. 4).
  5. The Operator ensures that the data subject may, in all matters relating to the processing of their personal data, contact the Operator through the channels indicated in para. 3, and the Operator will provide a response within a period not exceeding 30 days from the date of receipt of the request, in accordance with Art. 12(3) GDPR. Where the request is particularly complex in nature or there is a large number of requests, this period may be extended by a further two months, of which the Operator will inform the applicant within one month of receipt of the request, stating the reasons for the delay.

§ 4. Data Protection Officer — justification for not appointing one

  1. In accordance with Art. 37(1) GDPR, the Controller and the processor shall designate a Data Protection Officer (hereinafter the “DPO”) where: a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; b) the core activities of the Controller or the processor consist of processing operations which, by virtue of their nature, their scope or their purposes, require regular and systematic monitoring of data subjects on a large scale; c) the core activities of the Controller or the processor consist of processing on a large scale of special categories of personal data referred to in Art. 9(1) GDPR, and personal data relating to criminal convictions and offences referred to in Art. 10 GDPR.
  2. The Operator carried out an assessment of the obligation to appoint a DPO taking into account the Article 29 Working Party Guidelines on Data Protection Officers (DPOs) WP 243 rev.01, endorsed by the EROD, as well as the explanations of UODO (Polish DPA) published on the website uodo.gov.pl. As a result of the analysis carried out, the Operator finds as follows: a) the Operator is not a public authority or body; b) the core activity of the Operator — the sale of research materials in the B2B segment and to other Qualified Buyers — does not consist of regular and systematic monitoring of natural persons on a large scale; the Operator does not carry out behavioural profiling, does not use cross-site tracking tools, does not use data for advertising microtargeting, and does not use measurement tools based on persistent cookies; c) the Operator does not process on a large scale special categories of data (Art. 9(1) GDPR) or data relating to criminal convictions (Art. 10 GDPR); the Operator does not collect health data, biometric data for the purpose of uniquely identifying a person, or data concerning sexual orientation, religious beliefs, political opinions, etc.
  3. For the purposes of assessing “large scale”, the Operator applied the criteria indicated in guidelines WP 243 rev.01 (number of data subjects, volume of data, duration of processing, geographical scope). The scale of the Operator’s activity in the first twelve months after the launch of the Shop does not meet any of these criteria cumulatively.
  4. The Operator has not appointed a Data Protection Officer. This decision was taken on the basis of the documented assessment described in para. 2 and 3 above and is subject to periodic verification together with updates to the Privacy Policy. In the event of a material change in the scale of processing (e.g. introduction of profiling functionalities, exceeding the threshold of the number of Buyers, expansion of the scope of data), the Operator will carry out a renewed assessment and — should the obligation arise — will appoint a DPO and update this document.
  5. The absence of a DPO does not limit the rights of data subjects. All questions and requests should be directed to compliance@purepoint.pl. Correspondence arriving at this address is handled by a data protection contact person designated by the Operator, acting on behalf of the Management Board and responsible for maintaining the Record of Processing Activities.

§ 5. Categories of personal data processed by the Operator

The Operator processes only such personal data as is necessary to achieve the stated purposes. As part of its activity, the Operator processes the following categories of data:

  1. Qualified Buyer account registration data — comprising: e-mail address, password in encrypted form (cryptographic hash — the Operator does not know the password in plain text), username (if provided), account creation date, date of last login, IP address during account creation, e-mail address verification status.
  2. Identification and contact data — first name and surname, business name of the Buyer that is a legal person, NIP, delivery address, invoice address, telephone number (if provided), contact e-mail address. In the case of Qualified Buyers who are natural persons conducting business activity — also the first name and surname of the person conducting the sole proprietorship (JDG).
  3. Transaction data — order number, list of ordered Products (Research Materials), order value, gross amount, net amount, VAT, order date, order status, payment method (Stripe / BACS transfer), payment references (Stripe transaction identifiers), information on returns and corrective invoices, history of communication with the Shop service.
  4. KOP data — Qualified Profile Declaration — category of the Qualified Buyer (STUDENT / LAB / SCIENTIST / BIZ_RD / OTHER_PRO) and supplementary data required for the given category: for STUDENT — university, field of study (biomedicine, chemistry, biotechnology, pharmacy), year of study; for LAB — NIP and name of the laboratory; for SCIENTIST — ORCID identifier or institutional affiliation; for BIZ_RD — NIP and PKD code (74.10.Z / 72.11.Z / 72.19.Z / 72.20.Z / 21.20.Z); for OTHER_PRO — a declaration at least 100 characters long subject to manual verification by the Operator. The Operator stores the five compliance declarations made by the NK together with the date and time of submission and the IP address.
  5. NK data — supplementary — the NK category marker field in the account database, history of category changes, the manual verification marker (for the OTHER_PRO category) and the verification result marker (accepted / rejected / in progress).
  6. KYC data for AML thresholds — the Operator is not an obliged institution within the meaning of Art. 2 of the Act on Counteracting Money Laundering and Terrorist Financing (AML). Notwithstanding this, the Operator applies proactive Buyer identity verification procedures for orders exceeding the thresholds of EUR 5,000 / EUR 15,000 / EUR 50,000 — respectively: identification data, a copy of an identity document (at the EUR 15,000 threshold), confirmation of the source of funds (at the EUR 50,000 threshold). KYC data is processed as a separate category with a separate retention period (see § 7).
  7. Behavioural data — pseudonymised Plausible analytics — the Operator uses the Plausible analytics service (Plausible Insights OÜ, Tallinn, Estonia). Plausible does not use cookies, does not collect unique identifiers, does not create user profiles and does not store IP addresses in a form that permits identification. Plausible processes only pseudonymised data: device type, operating system, browser, language, country (at country level, without detailed geolocation), entry page, exit page, navigation path within the Shop, visit source (referrer). This data does not permit the identification of a natural person and is processed on the basis of the Operator’s legitimate interest (Art. 6(1)(f) GDPR) consisting of measuring the effectiveness of the Shop and optimising its operation.
  8. Technical data and system logs — IP address, session identifier, login and logout timestamps, HTTP response codes, information on system errors. Logs are stored for a maximum of 30 days from the date of the event, except for logs concerning security incidents, which are stored until the matter is clarified.
  9. Data from contact forms — content of correspondence, e-mail address, any attachments, timestamps.
  10. Newsletter data (if the Buyer has subscribed to the newsletter) — e-mail address, consent marker, date of consent, source of subscription, subscription status. The details are governed by a separate Newsletter Policy (see § 15).

The Operator does not collect special category data within the meaning of Art. 9(1) GDPR (including health data, genetic and biometric data, data revealing racial or ethnic origin, religious beliefs, political opinions, trade union membership, sexual orientation) or data relating to criminal convictions (Art. 10 GDPR).


§ 6. Purposes of processing and legal bases (Art. 6(1) GDPR)

The Operator processes personal data solely for specified, explicit and lawful purposes and only to the extent necessary to achieve those purposes. A legal basis is required for each processing operation.

  1. Art. 6(1)(a) GDPR — consent of the data subject. The Operator processes personal data on the basis of consent for the following purposes: a) sending the marketing newsletter — consent to receive commercial information by electronic means within the meaning of Art. 10(2) u.ś.u.d.e. and consent to the use of telecommunications terminal equipment for direct marketing purposes in accordance with Art. 172(1) of the Telecommunications Law [VERIFY — PKE 2024 replaced the Telecommunications Law; the basis for direct marketing by electronic means is now governed by the Act of 12 July 2024 — Electronic Communications Law (Journal of Laws 2024, item 1221), cf. Art. 398 PKE — the applicable provision to be confirmed by legal counsel]; b) the use of cookies other than strictly necessary ones (analytical, marketing) — consent in accordance with Art. 173(1) and (2) of the Telecommunications Law [VERIFY — PKE 2024 replaced the Telecommunications Law; the applicable PKE provision to be confirmed by legal counsel]; the Operator does not use marketing cookies, and Plausible does not require consent because it does not use cookies; c) the use of optional account functionalities (e.g. wish list, order history visible in the panel). Consent may be withdrawn at any time, which does not affect the lawfulness of processing carried out before its withdrawal (Art. 7(3) GDPR). Withdrawing consent is as easy as giving it — an unsubscribe link in the footer of every newsletter and a consent management function in the Buyer panel.
  2. Art. 6(1)(b) GDPR — necessity for the performance of a contract. The Operator processes personal data for the purpose of concluding and performing the contract for the sale of Products and the contract for the provision of services by electronic means (maintaining the NK account): a) registration and maintenance of the NK account in the Shop; b) acceptance and fulfilment of orders (confirmation, picking, dispatch, tracking); c) handling payments through Stripe Payments Europe Limited and BACS transfers; d) handling returns, complaints arising from the statutory warranty (to the extent that it has not been excluded under Art. 558 § 1 KC) and correspondence relating to the order; e) verification of the Buyer’s status as a Qualified Buyer — including processing of KOP data.
  3. Art. 6(1)(c) GDPR — legal obligation to which the Controller is subject. The Operator processes personal data in order to fulfil obligations arising from legal provisions: a) issuing and storing VAT invoices in accordance with Art. 106e–106q of the Act of 11 March 2004 on the Tax on Goods and Services (Journal of Laws 2024, item 361, as amended); b) keeping accounting books and archiving accounting documents in accordance with the Act of 29 September 1994 on Accounting (Journal of Laws 2024, item 619, as amended); c) fulfilling tax obligations arising from the Act of 29 August 1997 — Tax Ordinance (Journal of Laws 2024, item 1305, as amended); d) making data available to the competent public administration authorities at their request, within the scope and in the manner specified by the provisions; e) exercising the rights of data subjects arising from the GDPR (RODO); f) maintaining the Record of Processing Activities (Art. 30 GDPR) and data protection documentation.
  4. Art. 6(1)(d) GDPR — protection of the vital interests of a natural person. The Operator does not process personal data on the basis of this legal basis in the course of its normal activity. This basis may be used exclusively in an exceptional situation, e.g. in the event of receiving information about a life-threatening incident affecting the Buyer in connection with a received Product — in which case the Operator may process data in order to contact the emergency services or to convey information about the risk.
  5. Art. 6(1)(e) GDPR — performance of a task carried out in the public interest or in the exercise of official authority. The Operator is not an entity performing public tasks and does not process data on the basis of this legal basis.
  6. Art. 6(1)(f) GDPR — legitimate interest of the Controller. The Operator processes personal data on the basis of legitimate interest for the following purposes: a) establishing, pursuing and defending claims arising from sale contracts, including debt recovery, court proceedings, mediation, arbitration — both against the Buyer and in defence against their claims; the processing covers transaction data, contact data and correspondence history; b) ensuring the security of the Shop and IT systems — monitoring access logs, detecting unauthorised access, protection against attacks (e.g. brute force, DDoS, SQL injection) on the basis of Recital 49 GDPR; c) proactive AML procedures — preventing the introduction into circulation through the Shop of financial resources originating from illegal sources and preventing the use of the Shop for criminal activities; although the Operator is not an obliged institution, conducting these procedures constitutes the Operator’s legitimate interest in maintaining the integrity of the sales channel; d) measuring the effectiveness of the Shop — Plausible analytics without cookies and without identification of natural persons; e) improving the Shop — analysis of aggregated data in order to improve the interface, the product offering and customer service; f) conducting direct marketing of the Operator’s own products or services — in accordance with Recital 47 GDPR, exclusively to existing Buyers and exclusively through channels to which the Buyer has not objected; g) pursuing liability in the event of a false KOP declaration — processing the data of a Buyer who made a declaration contrary to the truth, to the extent necessary to file a notification of the commission of an offence under Art. 233 KK and to pursue compensation under Art. 471 KC. The Operator carries out a balancing test (Legitimate Interest Assessment — LIA) for each of the above operations and documents the result in the Record of Processing Activities.

The Operator informs that a person whose data is processed on the basis of Art. 6(1)(f) GDPR has the right to object to the processing (Art. 21 GDPR). An objection to processing for direct marketing purposes is absolutely binding — the Operator ceases processing for that purpose (Art. 21(3) GDPR). An objection to other operations based on Art. 6(1)(f) GDPR requires that the person’s particular situation be taken into account — the Operator ceases processing unless it demonstrates the existence of compelling legitimate grounds overriding the interests, rights and freedoms of the data subject, or the processing is necessary for the establishment, exercise or defence of legal claims (Art. 21(1) GDPR).


§ 7. Personal data retention period

The Operator stores personal data solely for the period necessary to achieve the purposes for which it was collected, taking into account the legal obligations imposed on the Operator and the limitation periods for claims. The retention periods for each category of data are indicated below, together with the legal justification.

  1. Transaction data (invoices, proofs of purchase, records) — retention period: 5 years counted from the end of the calendar year in which the tax payment deadline fell. Basis: Art. 70 § 1 of the Tax Ordinance (limitation of tax liabilities upon the expiry of 5 years counted from the end of the calendar year in which the tax payment deadline fell) and Art. 74(2) of the Act on Accounting (accounting books — at least 5 years).
  2. Registration and transaction data for the purposes of civil-law claims — retention period: 6 years counted from the day on which the claim became due. Basis: Art. 118 KC as worded by the Act of 13 April 2018 amending the Act — Polish Civil Code and certain other acts (Journal of Laws 2018, item 1104), i.e. the general limitation period of 6 years (previously 10 years). The Operator stores the data for this period in order to establish, pursue and defend claims (Art. 6(1)(f) GDPR).
  3. KOP data (Qualified Profile Declaration) — retention period: 6 years from the day of fulfilment of the last order associated with the given KOP. Basis: the Operator’s legitimate interest (Art. 6(1)(f) GDPR) consisting of retaining proof that the Buyer, at the time of purchase, held the status of Qualified Buyer and made the required compliance declarations. This period corresponds to the limitation period for claims under the sale contract and to the limitation period for claims for the redress of damage caused by a tort (Art. 442(1) § 1 KC).
  4. KYC data (AML) — retention period: 5 years counted from the day of termination of the business relationship with the Buyer, in respect of orders exceeding the thresholds of EUR 5,000 / 15,000 / 50,000. Basis: Art. 49 of the AML Act (although the Operator is not an obliged institution, it applies an analogous period in order to maintain consistency and to demonstrate due diligence with regard to the AML provisions).
  5. Buyer account data — retention period: until the account is deleted by the Buyer or a request for erasure of data is made (Art. 17 GDPR) plus 30 days to finalise the deletion process and archive technical logs. If the Buyer does not delete the account but a period of 24 months has elapsed since the date of last login, the Operator may decide to delete the account after prior notification of the Buyer by e-mail with 30 days’ notice.
  6. Data from contact forms — retention period: 24 months from the date of the last correspondence. Basis: the Operator’s legitimate interest (Art. 6(1)(f) GDPR) consisting of maintaining the history of contacts and the context of the matter in the event of resumption of correspondence or any claims.
  7. Newsletter data — retention period: until the day consent is withdrawn plus 30 days to cease sending across all systems. Logs of consent withdrawal — stored for 5 years as proof of its withdrawal (Recital 42 GDPR).
  8. Plausible analytics data — retention period: aggregated data at country and day level is stored without a time limit (it is not personal data). Raw event-level data — deleted after 30 days.
  9. System and security logs — retention period: 30 days from the date of the event for standard logs; until the matter is clarified (a maximum of 12 months) for logs concerning security incidents.
  10. Correspondence in GDPR (RODO) matters (data subject requests, decisions) — retention period: 5 years from the day the matter was closed. Basis: accountability (Art. 5(2) GDPR) and the Operator’s legitimate interest.

Upon expiry of the periods indicated above, the Operator deletes the data or subjects it to irreversible anonymisation. In the event of a concurrence of periods for the same processing operation, the Operator applies the longest period. The internal retention schedule and the audit of data deletion are documented in the Record of Processing Activities.


§ 8. Recipients of personal data

The Operator discloses personal data solely to entities authorised to receive it or to entities to which the Operator has entrusted the processing of data on the basis of a data processing agreement (Art. 28 GDPR). The Operator does not sell personal data, does not exchange it with other entities for marketing purposes and does not make it available for advertising profiling.

  1. Stripe Payments Europe Limited (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland) — a processor of data for the purpose of handling card payments and alternative methods. Stripe Payments Europe Limited is a company under Irish law, providing payment services in the EU and processing Buyers’ data in the EEA. Stripe Payments Europe Limited holds a licence as an e-money institution issued by the Central Bank of Ireland. The agreement concluded with the Operator contains data processing clauses (Data Processing Agreement). The data processed by Stripe comprises card data, transaction number, amount, Buyer identification data, delivery/billing address, e-mail address.
  2. cyber_Folks S.A. (ul. Franklina Roosevelta 22, 60-829 Poznań, Poland) — a processor of data within the scope of hosting services: provision of server infrastructure, databases, backups, DDoS protection, WAF (Web Application Firewall). Hosting takes place on servers located in Poland. With cyber_Folks S.A. the Operator has concluded a data processing agreement in accordance with Art. 28 GDPR.
  3. Accounting firm serving the Operator on the basis of a separate agreement (data controller: FIRSTSTONE TRADING sp. z o.o., processor: the selected accounting firm) — to the extent necessary to keep accounting books, prepare tax returns and archive accounting documents. The accounting firm is located in Poland, is subject to professional secrecy and the requirements of the u.o.d.o., and has been bound by a data processing agreement.
  4. Sendinblue SAS (operating under the Brevo brand, 7 rue de Madrid, 75008 Paris, France) — a processor of data for the purpose of sending transactional e-mail messages (order status notifications, invoices, technical messages) and, where separate consent is given, sending the newsletter. Sendinblue SAS processes data in the EU; the company has implemented ISO 27001 and SOC 2 Type II certification.
  5. Plausible Insights OÜ (Tallinn, Estonia) — an entity providing web analytics services without cookies. Plausible Insights OÜ processes data exclusively in the EEA (servers in Germany) and does not use cloud infrastructure outside the EEA. The Operator does not make data identifying Buyers available to Plausible — Plausible receives only pseudonymised technical data (device type, country, visit source).
  6. Couriers and postal operators — for the purpose of fulfilling the delivery of orders: a) InPost S.A. (ul. Pruszkowska 26C, 02-118 Warsaw, Poland), b) DPD Polska sp. z o.o. (ul. Mineralna 15, 02-274 Warsaw, Poland), c) another postal operator in the event of a change of logistics provider. The Operator provides carriers only with the data necessary to deliver the parcel: first name and surname / business name of the recipient, delivery address, telephone number (for the purpose of contact by the courier), weight and dimensions of the parcel. The Operator does not make available to carriers the list of ordered Products or other information about the content of the parcel beyond what is required for logistics.
  7. Public administration authorities and courts — to the extent specified by legal provisions, at their lawful request (e.g. tax authorities, law enforcement authorities, the Inspector General for Financial Information, common courts).
  8. Entities providing advisory services — advocates and legal advisers, tax advisers, auditors — to the extent necessary to provide advice or perform the service, on the basis of professional secrecy and a data processing agreement.
  9. Entities providing IT and maintenance services — selected software providers (e.g. a ticketing system for handling complaints) — exclusively within the scope of technical maintenance and with a guarantee of data processing in the mode of Art. 28 GDPR.

The Operator does not entrust data to entities in any manner other than indicated above. The Operator may make the current list of processors available upon a request directed to compliance@purepoint.pl.


§ 9. Transfer of data to third countries — Schrems II analysis

  1. The Operator adopts as a principle the processing of personal data within the European Economic Area (EEA) and the avoidance of transfers to third countries. This decision is dictated by the judgment of the Court of Justice of the EU of 16 July 2020 in case C-311/18 Data Protection Commissioner v. Facebook Ireland Ltd, Maximillian Schrems (Schrems II), which affected the practice of transferring data to third countries, including to the United States of America.
  2. Analysis of individual data recipients: a) Plausible Insights OÜ (Estonia) — registered office in the EEA, analytics servers physically located in the territory of the EEA (Germany). No transfer of data to third countries. Plausible does not use cloud providers outside the EEA. Compliance status: full within the EEA. b) Stripe Payments Europe Limited (Ireland) — an entity under Irish law providing services in the EU. The data of EU Buyers is processed by Stripe Payments Europe Limited in the EU (data centre in Ireland and other EU Member States). Stripe Payments Europe Limited does NOT transfer the personal data of EU customers to Stripe Inc. in the USA for the purposes of processing EU customer payments. Compliance status: full within the EEA, subject to the proviso that Stripe may, in exceptional cases, transfer data to a limited extent to its branches in third countries on the basis of SCC 2021/914 and additional technical and organisational measures — which has been regulated in the terms of service of Stripe. c) Sendinblue SAS / Brevo (France) — registered office in the EEA, processing infrastructure in the EU. No transfer of data to third countries. Compliance status: full within the EEA. d) cyber_Folks S.A. (Poland) — registered office in the EEA, server infrastructure in Poland. No transfer of data to third countries. Compliance status: full within the EEA. e) Couriers and postal operators (InPost, DPD) — registered office and activity in the EEA. No transfer of data to third countries. Compliance status: full within the EEA.
  3. No Google Analytics 4 (GA4) — the Operator does NOT use Google Analytics or any other analytics tool whose provider is a company located in a third country. This decision results from the legal risk analysis following Schrems II and following the decisions of European supervisory authorities in matters concerning GA4 (including the Austrian DSB — case CRIF-D122.732/0007-DSB/2021 of 21.12.2021; the Italian Garante — order of 9.06.2022; the French CNIL — decision of 10.02.2022). The Operator chose Plausible Insights OÜ as an EEA-native analytics tool, compliant with the GDPR (RODO) and not requiring cookies.
  4. Standard Contractual Clauses (SCC) — no need to apply them. Since the Operator does not transfer personal data to third countries (with the exception of the incidental transfer by Stripe, for which SCC 2021/914 and additional measures apply — regulated directly by Stripe in the terms of its agreement with the Operator), the Operator does not conclude separate SCC with other data recipients. In the event of a change of providers or the need to introduce a transfer, the Operator will update this Privacy Policy and conclude the appropriate agreements.
  5. Technical and organisational measures minimising risk: a) TLS 1.3 connection encryption in communication between the Shop and all data recipients; b) pseudonymisation of data wherever the nature of the operation permits (especially in analytics); c) minimisation of the scope of data transferred to recipients (data minimisation by design); d) access control based on the need-to-know principle; e) periodic evaluation of providers (Vendor Assessment) with regard to their data protection practices.
  6. Procedure in the event of the disclosure of a transfer to a third country — in the event of detecting that any of the providers transfers data to a third country without a basis under Art. 45–46 GDPR, the Operator: a) immediately suspends the transfer of data to such a provider; b) assesses the possibility of applying a transfer mechanism (adequacy decision, SCC, BCR); c) in the absence of such a possibility — terminates the agreement with the provider and replaces it with an EEA provider; d) informs the data subjects if the transfer may have affected their rights.

The Operator declares that, as at the date of publication of this Privacy Policy, all processing operations on the data of Buyers of the Shop purepoint.pl take place exclusively in the EEA, and a transfer to third countries within the meaning of Art. 44 GDPR does not take place.


§ 10. Rights of data subjects

Every person whose data the Operator processes has the rights arising from Chapter III of the GDPR (Art. 15–22 GDPR). The Operator ensures facilitated exercise of these rights and a response within 30 days from the date of receipt of the request (with the possibility of an extension by a further two months where the request is complex in nature).

  1. Right of access to data (Art. 15 GDPR). The data subject is entitled to obtain from the Operator confirmation as to whether their personal data is being processed and, if so — to obtain access to it and to information about: the purposes of processing, the categories of data, the recipients, the envisaged storage period, the rights vested in the person, the source of the data (if not collected from the person), the existence of automated decision-making, and information about the transfer to third countries. Upon request, the Operator provides a copy of the data. Procedure: request to compliance@purepoint.pl; verification of identity (e.g. confirmation of the e-mail address associated with the account); response within 30 days.
  2. Right to rectification of data (Art. 16 GDPR). The data subject has the right to demand the immediate rectification of data that is inaccurate, and the completion of incomplete data (taking into account the purposes of processing). Procedure: request to compliance@purepoint.pl or direct editing in the Buyer panel; the Operator informs all recipients to whom the data has been disclosed about the rectification (Art. 19 GDPR), unless this proves impossible or involves a disproportionate effort.
  3. Right to erasure of data — the “right to be forgotten” (Art. 17 GDPR). The data subject has the right to demand the immediate erasure of data where one of the following circumstances applies: the data is no longer necessary for the purposes for which it was collected; withdrawal of consent and the absence of another legal basis; an effective objection; unlawful processing; fulfilment of a legal obligation; the data relates to a child and was collected in connection with the offering of information society services. Exceptions: data may still be processed where the processing is necessary for exercising the freedom of expression and information, for compliance with a legal obligation, for archiving purposes in the public interest, for scientific or historical research, for statistics, or for the establishment, exercise or defence of legal claims (Art. 17(3) GDPR). Procedure: request to compliance@purepoint.pl; in the event of refusal, the Operator justifies the decision; erasure covers all copies except those that must be retained by force of law.
  4. Right to restriction of processing (Art. 18 GDPR). The data subject has the right to demand the restriction of processing in the following cases: contesting the accuracy of the data (for the period of verification); unlawful processing where the person objects to erasure; where the Controller no longer needs the data but it is required by the person for the establishment of claims; lodging an objection (for the period of assessment). During the period of restriction, the data may only be stored (and processed with the consent of the person or for the defence of claims, the protection of the rights of another person, or important public interests). Procedure: request to compliance@purepoint.pl; the Operator informs of the lifting of the restriction before it is lifted.
  5. Right to data portability (Art. 20 GDPR). The data subject has the right to receive the personal data concerning them which they have provided to the Operator, in a structured, commonly used, machine-readable format, and to transmit it to another controller, where the processing is carried out on the basis of consent (Art. 6(1)(a) / Art. 9(2)(a) GDPR) or on the basis of a contract (Art. 6(1)(b) GDPR) and is carried out by automated means. Procedure: request to compliance@purepoint.pl; the Operator provides the data in JSON or CSV format within 30 days.
  6. Right to object (Art. 21 GDPR). The data subject has the right at any time to object — on grounds relating to their particular situation — to processing of data based on Art. 6(1)(e) or (f) GDPR. The Operator ceases processing unless it demonstrates the existence of compelling legitimate grounds overriding the interests, rights and freedoms of the person, or the processing is necessary for the establishment, exercise or defence of legal claims. An objection to direct marketing (Art. 21(2) GDPR) is absolutely binding — the Operator ceases such processing immediately and unconditionally. Procedure: objection to compliance@purepoint.pl or clicking the “unsubscribe” link in the newsletter footer.
  7. Right not to be subject to a decision based solely on automated processing (Art. 22 GDPR). The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. The Operator does not make decisions in respect of Buyers based solely on automated processing within the meaning of Art. 22(1) GDPR. All decisions material to NK status (in particular verification of the OTHER_PRO category and KYC verification above the AML thresholds) are subject to the Operator’s manual control.
  8. Right to withdraw consent (Art. 7(3) GDPR). At any time the data subject has the right to withdraw consent to processing, where the processing is carried out on the basis of consent. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. Procedure: link in the newsletter, the Buyer panel or a request to compliance@purepoint.pl.
  9. Right to lodge a complaint with the supervisory authority (Art. 77 GDPR). The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw) or with another competent supervisory authority in the State of habitual residence, place of work or place of the alleged infringement.
  10. Exercise of rights — time limit and procedure. The Operator responds to requests within 30 days from the date of receipt of the request. Where the request is particularly complex or there is a large number of requests, the time limit may be extended by a further two months, of which the Operator informs the applicant within one month of receipt of the request. The Operator may request additional information necessary to confirm the identity of the person (Art. 12(6) GDPR). The exercise of rights is, as a rule, free of charge. The Operator may refuse to act or charge a fee only in the case of requests that are manifestly unfounded or excessive — in particular by reason of their repetitive character (Art. 12(5) GDPR). The burden of proof rests with the Operator.

§ 11. Security of personal data

The Operator ensures appropriate technical and organisational measures intended to ensure a level of security appropriate to the risk, in accordance with Art. 32 GDPR. These measures include in particular:

  1. Encryption in transit — SSL/TLS 1.3. All communication between Buyers’ devices and the Shop, and between the Shop and the processors (Stripe, Sendinblue, Plausible, the accounting firm), takes place using the TLS protocol version 1.3 (with a fallback to TLS 1.2 solely to ensure backward compatibility). The SSL certificate is issued by a trusted certification authority (Let’s Encrypt / DigiCert), with automatic renewal by the Operator. The Operator enforces HSTS (HTTP Strict Transport Security) and the Secure and HttpOnly flags for all session cookies.
  2. Two-factor authentication (2FA) for administrators. All administrative accounts of the Shop, hosting (cyber_Folks), payment tools (Stripe), the newsletter tool (Sendinblue) and SSH service accounts are secured with two-factor authentication (TOTP / U2F hardware key). The Operator does not allow administrative access without 2FA.
  3. Encryption at rest. The Shop databases and backups are stored on media with encryption at rest enabled (AES-256). Buyers’ passwords are stored as cryptographic hashes (bcrypt / argon2id), without the possibility of reading them in plain text.
  4. Backups. The Operator performs regular backups of databases and files (at least once a day — an incremental backup; at least once a week — a full backup). Backups are stored in an isolated location (off-site) with encryption and access control. The Operator performs periodic recovery tests (recovery drills) at least once a quarter.
  5. WordPress hardening. The Shop is based on the WordPress + WooCommerce platform with a dedicated theme developed by the Operator. The Operator applies the following hardening measures: a) disabling XML-RPC; b) changing the default database table prefix; c) hiding the WP version in headers and HTML code; d) disabling file editing from the admin level (DISALLOW_FILE_EDIT); e) disabling PHP execution in the uploads directories; f) enforcing a strong password policy for all admin accounts; g) limiting the number of login attempts (rate limiting); h) disabling the default admin user; i) regular updates of the WP core, the theme and all plugins.
  6. Wordfence — firewall and intrusion monitoring. The Operator uses the Wordfence plugin (or an equivalent WAF solution) for protection against brute force, SQL injection, XSS, malware attacks and the monitoring of suspicious activity.
  7. Log monitoring and alerting. Access logs, error logs and security logs are processed automatically by a monitoring system with defined alert rules (e.g. repeated failed login attempts, access from an anomalous country). Alerts are forwarded to the administrator immediately.
  8. Access management. The Operator applies the principle of least privilege. Only persons authorised to do so under written authorisations (in accordance with Art. 29 GDPR) have access to Buyers’ personal data. The list of authorisations is updated without delay after each change. Each revocation of authorisation is enforced immediately by deactivating the account.
  9. Geo-block for countries subject to restrictions. The Shop blocks access from countries subject to international sanctions or posing an elevated legal risk, including: the Russian Federation (RU), Belarus (BY), Iran (IR), North Korea (KP), Syria (SY), Cuba (CU), Venezuela (VE), Burma/Myanmar (MM). The block takes place at the IP / geoIP level and does not require the processing of personal data other than the visitor’s IP address.
  10. Staff training and confidentiality. All persons authorised to process data are trained in the area of the GDPR (RODO) and cybersecurity. These persons sign a confidentiality undertaking that remains in force also after the end of the cooperation.
  11. Strong password policy. The Operator requires of administrative users passwords at least 14 characters long containing upper-case letters, lower-case letters, digits and special characters. Periodic rotation of administrative account passwords is enforced (every 180 days), as well as immediate rotation upon detection of an incident.
  12. Update policy. The Operator monitors CVE publications and security alerts concerning the technology stack in use (WordPress core, WooCommerce, the plugins used, PHP, MariaDB/MySQL, the operating system). Critical security patches are deployed within 72 hours of disclosure.
  13. Data Protection Impact Assessment (DPIA). The Operator carries out a data protection impact assessment for high-risk operations in accordance with Art. 35 GDPR. As at the date of publication of this Privacy Policy, the Operator has not identified operations requiring a DPIA, because the Shop does not carry out profiling, systematic monitoring, the processing of special categories of data or transfers to third countries.

The Operator regularly verifies the effectiveness of the implemented measures and updates them in the event of the disclosure of new threats or after the deployment of new Shop functionalities.


§ 12. Personal data breaches (Art. 33–34 GDPR)

  1. Definition of a breach. A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data (Art. 4(12) GDPR).
  2. Internal procedure — assessment within 72 hours. In the event of a suspected breach, the Operator: a) immediately takes safeguarding actions aimed at stopping the breach (e.g. cutting off the attacker, key rotation, disabling the compromised functionality); b) documents the breach in an internal Breach Register comprising: a description of the breach, the categories and approximate number of data subjects, the categories and approximate number of personal data records, the likely consequences of the breach, the measures taken or planned; c) assesses the risk to the rights and freedoms of data subjects — within a period not exceeding 72 hours from becoming aware of the breach.
  3. Notification to UODO (Polish DPA). If the risk assessment shows that there is a likelihood of a breach of the rights or freedoms of persons, the Operator notifies the breach to the President of the Personal Data Protection Office no later than within 72 hours after becoming aware of the breach. The notification contains the information required by Art. 33(3) GDPR. In the event of a delay beyond 72 hours, the Operator attaches to the notification a justification of the delay.
  4. Notification of data subjects. If the breach may result in a high risk to the rights or freedoms of natural persons, the Operator notifies the persons without undue delay (Art. 34 GDPR). The notification contains: a description of the nature of the breach, contact details of the person providing further information, a description of the possible consequences, a description of the measures taken or planned. Notification is not required where the Operator has implemented technical measures (e.g. encryption) rendering the data unintelligible to unauthorised persons, has taken subsequent measures eliminating the likelihood of a high risk, or where it would involve a disproportionate effort — in the latter case, a public communication is used.
  5. Cooperation with UODO (Polish DPA). The Operator cooperates with UODO in the course of explanatory and inspection proceedings, providing access to documentation, data and premises to the extent required by the provisions.
  6. Breach Register. The Operator maintains an internal Breach Register independently of the obligation to notify. This register is evidence of accountability in accordance with Art. 33(5) GDPR.
  7. Contact regarding a breach. Any information about suspected breaches should be directed to compliance@purepoint.pl, with the words “RODO — breach” indicated in the subject line of the message.

§ 13. No obligation to appoint a representative in the EU

  1. In accordance with Art. 27(1) GDPR, controllers or processors not established in the European Union who process the data of persons present in the EU are obliged to designate a representative in the EU.
  2. The Operator (FIRSTSTONE TRADING sp. z o.o.) has its registered office in Poland — an EU Member State. Consequently, Art. 27 GDPR does not apply, and the Operator is not obliged to designate a representative in the EU.
  3. All matters relating to the protection of Buyers’ data are handled directly by the Operator at the addresses indicated in § 3 of this Privacy Policy.

§ 14. Cookies and similar technologies

  1. The detailed rules for the use of cookies and similar technologies are governed by the Cookies Policy available at purepoint.pl/polityka-cookies/. This Privacy Policy refers to the Cookies Policy in respect of matters not expressly regulated below.
  2. The Operator uses exclusively cookies strictly necessary for the operation of the Shop (session cookies, shopping cart, language preferences, CSRF protection). The use of these cookies does not require the Buyer’s consent in accordance with Art. 173(3)(1) and (2) of the Telecommunications Law. [VERIFY — PKE 2024 replaced the Telecommunications Law: the Act of 12 July 2024 — Electronic Communications Law (Journal of Laws 2024, item 1221), in force from 10 November 2024, replaced the provisions of Art. 173 of the Telecommunications Law on cookies; the legal basis should be updated to the applicable PKE provision — to be confirmed by legal counsel]
  3. The Operator does NOT use analytical or marketing cookies. The Shop’s analytics is carried out exclusively by Plausible Insights OÜ, which does not use cookies.
  4. Cookie banner — symmetrical. Notwithstanding the above, in the interest of transparency and compliance with the decisions of UODO (Polish DPA) (UODO decision ref. 02/2025 imposing a fine of EUR 420,000 for an asymmetrical cookie banner), the Operator displays a symmetrical cookie banner with equivalent buttons: “Accept”, “Reject”, “Customise”. The banner does not contain so-called “dark patterns”, and the behaviour buttons are visually and functionally equivalent.
  5. Withdrawal of consent to the use of analytical / marketing cookies (should they be introduced in the future) is possible through the cookie preferences panel available in the Shop footer or by changing browser settings.

§ 15. Newsletter — reference

  1. The detailed rules of operation of the Operator’s newsletter are described in the Newsletter Policy / Newsletter Terms and Conditions available at purepoint.pl/regulamin-newslettera/. This Privacy Policy refers to that regulation in respect of matters not expressly regulated.
  2. Subscription to the newsletter is voluntary and requires separate consent in accordance with Art. 6(1)(a) GDPR and Art. 10(2) u.ś.u.d.e.
  3. The Operator applies a double opt-in mechanism — subscription requires confirmation of the e-mail address by clicking a confirmation link.
  4. Unsubscribing from the newsletter is effected by clicking the “unsubscribe” link in the footer of each message or by a request to compliance@purepoint.pl.
  5. The newsletter is sent by Sendinblue SAS (Brevo) on servers in the EU.

§ 16. Complaints, complaints to UODO (Polish DPA) and judicial remedies

  1. GDPR (RODO) complaints directed to the Operator. Any complaints concerning the processing of personal data may be directed to compliance@purepoint.pl or in writing to the correspondence address FIRSTSTONE TRADING sp. z o.o., ul. Wierzbięcice 44A/40A, 61-568 Poznań. The Operator responds to complaints within 30 days from the date of receipt, in accordance with Art. 12(3) GDPR.
  2. Complaint to the supervisory authority. Notwithstanding the use of the complaints procedure with the Operator, the data subject has the right to lodge a complaint with the supervisory authority — in Poland: the President of the Personal Data Protection Office: – address: ul. Stawki 2, 00-193 Warsaw – registry office: Monday to Friday, 8:00–16:00 – helpline: available during UODO (Polish DPA) working hours; current details on the website uodo.gov.pl – website: https://uodo.gov.pl – electronic inbox (ePUAP): /UODO/SkrytkaESP A person may also lodge a complaint with the supervisory authority of the Member State in which they have their habitual residence, place of work or place of the alleged infringement (Art. 77(1) GDPR).
  3. Judicial remedies. Notwithstanding a complaint to the supervisory authority, the data subject has the right to bring an action before a civil court with claims against the Operator (Art. 79 GDPR). Proceedings against a controller or a processor shall be brought before the courts of the Member State in which the controller or the processor has an establishment, or — alternatively — before the courts of the Member State in which the person has their habitual residence, unless the controller or the processor is a public authority of a Member State acting in the exercise of its public powers.
  4. Compensation (Art. 82 GDPR). Any person who has suffered material or non-material damage as a result of an infringement of the GDPR (RODO) has the right to receive compensation from the Operator or the processor. The Operator is exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage (Art. 82(3) GDPR).
  5. Without prejudice to other remedies. The use of any procedure described above does not limit the right to use other legal remedies, including alternative dispute resolution methods, if the person considers it appropriate.

§ 17. Bibliography and sources

EU legal acts:

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC — General Data Protection Regulation (OJ EU L 119 of 04.05.2016, p. 1, as amended; corrigendum: OJ EU L 127 of 23.05.2018, p. 2) — GDPR (RODO).
  2. Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (OJ EC L 201 of 31.07.2002, as amended) — e-Privacy.
  3. Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (OJ EU L 199 of 07.06.2021, p. 31) — SCC 2021/914.

Legal acts of the Republic of Poland:

  1. Act of 10 May 2018 on the Protection of Personal Data (consolidated text: Journal of Laws 2019, item 1781, as amended) — u.o.d.o.
  2. Act of 18 July 2002 on Providing Services by Electronic Means (consolidated text: Journal of Laws 2024, item 1513, as amended) — u.ś.u.d.e.
  3. Act of 16 July 2004 — Telecommunications Law (consolidated text: Journal of Laws 2024, item 34, as amended).
  4. Act of 23 April 1964 — Polish Civil Code (consolidated text: Journal of Laws 2024, item 1061, as amended) — KC.
  5. Act of 6 June 1997 — Penal Code (consolidated text: Journal of Laws 2024, item 17, as amended) — KK.
  6. Act of 6 September 2001 — Pharmaceutical Law (consolidated text: Journal of Laws 2025, item 750, previously Journal of Laws 2024, item 686, as amended) — PF.
  7. Act of 30 May 2014 on Consumer Rights (consolidated text: Journal of Laws 2024, item 1796, as amended) — UPK.
  8. Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing (consolidated text: Journal of Laws 2025, item 168, as amended) — AML.
  9. Act of 18 November 2020 on Electronic Deliveries (consolidated text: Journal of Laws 2024, item 723, as amended).
  10. Act of 29 September 1994 on Accounting (consolidated text: Journal of Laws 2024, item 619, as amended).
  11. Act of 29 August 1997 — Tax Ordinance (consolidated text: Journal of Laws 2024, item 1305, as amended).
  12. Act of 11 March 2004 on the Tax on Goods and Services (consolidated text: Journal of Laws 2024, item 361, as amended).

Case law and guidelines:

  1. Judgment of the Court of Justice of the EU of 16 July 2020 in case C-311/18 Data Protection Commissioner v. Facebook Ireland Ltd, Maximillian Schrems (Schrems II), ECLI:EU:C:2020:559.
  2. Judgment of the Court of Justice of the EU of 6 October 2015 in case C-362/14 Schrems v. Data Protection Commissioner (Schrems I).
  3. Article 29 Working Party Guidelines WP 243 rev.01 on Data Protection Officers (DPOs), endorsed by the EROD.
  4. EROD Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications (adopted on 9.03.2021).
  5. EROD Guidelines 2/2020 on Articles 46(2)(a) and 46(3)(b) GDPR for transfers of personal data between public administration authorities (adopted on 15.12.2020).
  6. EROD Guidelines 3/2018 on the territorial scope of the GDPR (Art. 3), version 2.1 adopted on 12.11.2019.
  7. EROD Guidelines 5/2020 on consent under Regulation 2016/679 (adopted on 4.05.2020).
  8. EROD Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data (Schrems II implementation guidance, version 2.0 of 18.06.2021).

Decisions of national authorities:

  1. Decision of the Personal Data Protection Office of the Republic of Poland — selected decisions published on the website uodo.gov.pl, including (sample reference) UODO decision ref. 02/2025 concerning asymmetrical cookie banners and a fine of EUR 420,000.
  2. Decision of the Austrian Datenschutzbehörde (DSB) of 21.12.2021 (CRIF-D122.732/0007-DSB/2021) — Google Analytics as a tool requiring assessment in light of Schrems II.
  3. Order of the Italian Garante per la protezione dei dati personali of 9.06.2022 — Google Analytics.
  4. Decision of the French CNIL of 10.02.2022 — Google Analytics and transfers to the USA.

Industry documentation:

  1. Stripe Payments Europe Limited — Data Processing Agreement (DPA) and Stripe privacy policy (stripe.com/privacy).
  2. Sendinblue SAS / Brevo — Privacy policy and DPA (brevo.com/legal).
  3. Plausible Insights OÜ — Privacy Policy and technical documentation confirming the absence of cookies and the location of servers in the EU (plausible.io/privacy).
  4. cyber_Folks S.A. — Terms and conditions of service and the data processing agreement in accordance with Art. 28 GDPR.

§ 18. Change history

Version Publication date Scope of changes Author
1.0 22 May 2026 First version of the Privacy Policy. Identification of the Controller, description of the purposes of processing on the basis of Art. 6(1) GDPR, list of recipients, rights of persons, Schrems II section. FIRSTSTONE TRADING sp. z o.o.
1.0.1 24 May 2026 Correction of minor editorial errors, clarification of GDPR (RODO) contact channels, supplementation of information on cookies. FIRSTSTONE TRADING sp. z o.o.
2.0 6 June 2026 Full revision of compliance with the Qualified Buyer model (NK/KOP). Expansion of the DPO section (justification for not appointing one). Expansion of the retention periods section with a legal justification for each category (KC Art. 118, AML, taxes, KOP, account). Extension of the Schrems II analysis — justification for the choice of Plausible (EEA, no cookies) instead of GA4. Update of the catalogue of data recipients: Stripe Payments Europe (Dublin), cyber_Folks, Sendinblue/Brevo, Plausible Insights OÜ, couriers InPost/DPD. Update of the security section to include TLS 1.3, 2FA, encryption at rest, WordPress hardening, Wordfence, log monitoring. Addition of a section on proactive AML procedures (EUR 5k/15k/50k) even though the Operator is not an obliged institution. Update of the bibliography. Correction of the Pharmaceutical Law corrigendum (Art. 124(1) PF — Journal of Laws 2025, item 750). FIRSTSTONE TRADING sp. z o.o.

§ 19. Final clause

  1. In matters not regulated by this document, the mandatory provisions of Polish law and of the European Union apply, in particular the GDPR (RODO), the Act on the Protection of Personal Data, the Act on Providing Services by Electronic Means, the Telecommunications Law, the Polish Civil Code and the relevant specific acts.
  2. In the event of a conflict between the provisions of this Privacy Policy and the provisions of the Shop Terms and Conditions in the area of personal data protection — the provisions of this Privacy Policy take precedence.
  3. The Operator reserves the right to introduce changes to this Privacy Policy. Each change will be published in the Shop with appropriate advance notice, and registered persons will receive information about the change by e-mail if the change materially affects their rights.
  4. The Privacy Policy in version 2.0 enters into force on 6 June 2026 and replaces all earlier versions. Earlier versions remain available in the document archive available on request at compliance@purepoint.pl.
  5. In the event of any doubts of interpretation, contact compliance@purepoint.pl.

Document prepared and digitally signed by the Operator — FIRSTSTONE TRADING sp. z o.o. — on 6 June 2026. Representation: Krystian Dawidowski, Member of the Management Board.

Other Legal Center documents

  • Research Disclaimer
  • Product Disclaimer
  • Acceptable Use Policy
  • Store Terms & Conditions
  • Shipping Policy
  • Returns Policy
  • Complaints Policy
  • Consumer Clauses B2C vs B2B
  • Cookies Policy
  • User Account Terms
  • Newsletter Terms
  • Compliance Notice
  • AML/KYC Policy
  • Sanctions & Export Policy
  • Impressum / Operator Details

Back to the Legal Center — full list of 15 documents

Research newsletter
New write-ups and documentation — straight to your inbox.
purepoint SUPPLY

Laboratory-grade research materials. Verified purity. Batch documentation on every SKU.

Navigation
  • Shop
  • Quality
  • FAQ
  • About
  • Contact
Legal Center

Positioning

  • Research Disclaimer
  • Product Disclaimer
  • AUP

Sales

  • Terms & Conditions
  • Shipping Policy
  • Returns Policy
  • Complaints Policy
  • B2C/B2B Clauses

Privacy

  • Privacy Policy
  • Cookies Policy
  • Account Terms
  • Newsletter Terms

Compliance

  • Compliance Notice
  • Safety Data Sheets (SDS)
  • AML/KYC Policy
  • Sanctions Policy
  • Impressum
Contact
  • contact@purepoint.pl
  • compliance@purepoint.pl
  • @PUREPOINT.pl

Legal disclaimer. All products offered by PUREPOINT Supply are intended for research and laboratory purposes only. They are not intended for human or animal consumption, are not medicinal products, dietary supplements or cosmetics, and must not be used for diagnostic or therapeutic purposes.

Operator: FIRSTSTONE TRADING sp. z o.o. · KRS 0001254766 · NIP 7831958614

© 2026 FIRSTSTONE TRADING sp. z o.o. All rights reserved.

Search products

⌘K

Enter at least 2 characters to see results.

Popular

Searching…

No results for your query.

Try entering a peptide name (e.g. „BPC-157”) or a category (e.g. „regeneration”).

    Full product catalogue → Research materials — for laboratory use only.
    ✓
    Added to cart

    Frequently studied together

    Go to cart →
    Research guide Build the peptide stack your research calls for Pick your direction — we curate the set and explain every choice. Build my stack
    Build my stack
    PurePoint is a brand of FIRSTSTONE TRADING sp. z o.o. — a registered Polish company. KRS 0001254766 · NIP PL7831958614 · Verify us in the KRS register ↗
    Shipped from Poland · VAT invoice · COA for every batch · contact: contact@purepoint.pl
    Materials for research purposes only. Not for human or animal consumption.
    PURE POINTLivechat
    Hi! 👋 How can I help? Ask about ordering, shipping, payment or products.
    For research purposes only · We do not advise on use
    DA/EN/PL
    Research access verification

    Laboratory-grade research materials

    PUREPOINT Supply provides research compounds strictly for laboratory use. Before entering the site, confirm your qualification and research intent.

    For research purposes only. All PUREPOINT products are intended exclusively for research and laboratory use in vitro. They are not intended for consumption or use by humans or animals. They are not medicines, dietary supplements, cosmetics or medical devices and may not be used for diagnostic or therapeutic purposes.

    Select all consents to continue.

    By entering the site you accept PUREPOINT Supply's Research Disclaimer, Terms and Privacy Policy (FIRSTSTONE TRADING sp. z o.o., NIP 7831958614, KRS 0001254766).