Privacy Policy

Privacy Policy

This Privacy Policy describes the principles of personal data processing for users of the online store olero-store.com (hereinafter referred to as the “Store”) in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
  • Belgian and EU regulations on data protection and electronic commerce.

Using the Store is voluntary; however, in some cases, providing personal data is necessary to conclude and perform a sales contract, handle payments or respond to inquiries.


1. Data Controller

The Controller of personal data is:

OLERO
Houthulststraat 29, 2170 Antwerpen, Belgium
BCE/KBO registration number: 0805.407.232
VAT (BTW): BE0805407232
E-mail: info.olero@gmail.com
Phone: +32 472 76 10 30

For matters related to personal data processing, you may contact the Controller at the above address or via the contact form available in the Store.

The Controller has not appointed a Data Protection Officer, as there is no such obligation.


2. Hosting and Data Processing Location

The Store operates on the OpenCart 3 platform, and data is stored on the servers of the hosting provider:

home.pl S.A.
ul. Zbożowa 4,
70-653 Szczecin, Poland
NIP: 852-21-03-252, KRS: 0000431335, REGON: 811158242.

Personal data is stored in the cloud on home.pl servers. A data processing agreement has been concluded with the hosting provider.

The connection to the Store is secured with an SSL certificate, which means that all transmitted data is encrypted.

Additionally, the server stores technical logs (IP address, date, time, browser headers). Legal basis: Art. 6(1)(f) GDPR (legitimate interest – security and keeping logs).


3. Scope of Processed Data

Depending on how the Store is used, the following data may be processed:

  • first and last name,
  • delivery and billing address,
  • e-mail address and phone number,
  • business data (company name, VAT / BTW number) – for B2B transactions,
  • order and payment history,
  • IP address, browser, device and operating system information,
  • information about on-site activity (visited pages, clicks, viewed products) – depending on cookie settings.

4. Purposes and Legal Bases of Processing

  1. Order processing and sales contract execution
    Legal basis: Art. 6(1)(b) GDPR.
  2. Accounting and tax obligations
    Legal basis: Art. 6(1)(c) GDPR.
  3. Contact and inquiry handling
    Legal basis: Art. 6(1)(b) or (f) GDPR.
  4. Customer account creation and management
    Legal basis: Art. 6(1)(b) GDPR.
    The account can be deleted at the user’s request.
  5. Newsletter – sent through the built-in OpenCart system
    Legal basis: Art. 6(1)(a) GDPR (consent).
  6. Statistics, performance analysis and fraud prevention
    Legal basis: Art. 6(1)(f) GDPR.
    For analytical cookies – based on consent.
  7. Marketing (e.g., Google Ads) – if the user has given consent
    Legal basis: Art. 6(1)(a) GDPR.

No profiling is performed in the Store.

Google tools may involve data transfer to the USA. Data transfer is based on Standard Contractual Clauses (SCC).


5. Data Recipients

Personal data may be shared with the following recipients:

  • Mollie B.V. – payment processing,
  • courier companies and carriers,
  • home.pl S.A. – hosting services,
  • accounting, legal and consulting entities,
  • Google Ireland / Google LLC (USA) – analytics and advertising tools (Google Analytics, Google Ads, Tag Manager) – only with consent,
  • modules and custom OpenCart plugins – only to the extent necessary for Store functionality,
  • public authorities – if required by law.

Data is not sold to third parties.


6. Data Retention Periods

  • contract-related data – for the duration of the contract and until claims expire,
  • accounting documentation – as required by law (5–10 years),
  • customer account data – until the account is deleted by the user,
  • data processed based on consent – until consent is withdrawn,
  • technical logs – for the period necessary to maintain server security,
  • cookie data – in accordance with the Cookie Policy.

7. User Rights

The user has the right to:

  • access their data,
  • rectify data,
  • erase data (“right to be forgotten”),
  • restrict processing,
  • data portability,
  • object to processing,
  • withdraw consent at any time,
  • lodge a complaint with a supervisory authority (GBA in Belgium, UODO in Poland).

No automated decisions with legal effects are made in the Store.


8. GDPR Page – Data Management

The Store provides a dedicated page enabling users to exercise their data rights:

https://olero-store.com/gdpr

There, users can:

  • access their personal data,
  • download a copy of their data,
  • submit a request to restrict or delete data,
  • manage marketing consents.

Requests may require identity verification (e.g., verification link).


9. Cookies and Analytical Tools

Detailed information about cookies is available in a separate document: Cookie Policy.

The user must accept or reject non-essential cookies – this is handled by a GDPR-compliant cookie module.


10. Security Measures

  • SSL encrypted connection,
  • administrative panel security measures,
  • regular software updates,
  • procedures for responding to data-related incidents.

11. Final Information

This Privacy Policy may be updated in case of changes to the law, Store functionality or implemented tools.