Privacy policy
Privacy Policy
1. General Information
This Privacy Policy (hereinafter referred to as the “Privacy Policy”) sets out the rules for the collection, storage, processing, and protection of personal data of customers using the online store available at www.qualash.com, as well as the rules for the use of cookies.
Personal data is processed in accordance with applicable data protection laws, including:
-
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR),
-
UK General Data Protection Regulation (UK GDPR),
-
applicable data protection laws of the United States and other jurisdictions.
The Controllers apply appropriate technical and organizational measures to ensure the security of personal data and to protect it against unauthorized access, loss, misuse, or unlawful processing.
2. Personal Data Controllers
Depending on the customer’s place of residence and the scope of services provided, the controllers of personal data are:
🇵🇱 European Union (EU)
Quacosmetics Sp. z o.o.
ul. Domaniewska 37/2.43
02-672 Warsaw
Poland
KRS: 0001136660
NIP (VAT): PL5214093556
📧 Contact email: office@qualash.com
This entity is primarily responsible for:
-
sales within the European Union,
-
fulfillment and logistics from EU warehouses,
-
EU tax and accounting obligations,
-
compliance with Regulation (EU) 2016/679 (GDPR).
🇬🇧 United Kingdom
QUACOSMETICS UK LTD
1st Floor
415 High Street, Suite 1028
Stratford, London E15 4QZ
United Kingdom
📧 Contact email: office@qualash.com
This entity is primarily responsible for:
-
sales to customers located in the United Kingdom,
-
compliance with UK GDPR,
-
UK tax and regulatory obligations.
🇺🇸 United States and Other Non-EU Countries
QUACOSMETICS LLC
244 Madison Avenue #1084
New York, NY 10016
United States
📧 Contact email: office@qualash.com
This entity is primarily responsible for:
-
sales to customers located outside the European Union and the United Kingdom, including the United States,
-
compliance with applicable U.S. and international data protection laws,
-
international business operations and brand management.
3. Flexible Allocation of Sales Entities
In certain situations, depending on operational, logistical, tax, regulatory, or technical considerations, the sale of products to customers located in a given country or region may be carried out by one of the entities listed above, even if that entity is not the primary or dedicated entity for that specific market.
This may include, in particular, situations related to:
-
availability of fulfillment locations or warehouses,
-
cross-border logistics optimization,
-
tax, accounting, or invoicing requirements,
-
payment service provider or platform limitations,
-
temporary operational, legal, or regulatory constraints.
In such cases, the entity that processes the transaction shall be considered the seller and the controller of personal data for that specific transaction. All personal data shall be processed in accordance with applicable data protection laws, including GDPR, UK GDPR, or other relevant regulations.
The customer will be informed of the entity responsible for the transaction through the order confirmation, invoice, payment confirmation, or other transactional documentation.
4. Contact Regarding Personal Data
For all matters related to personal data processing and the exercise of data subject rights, you may contact us at:
Requests will be handled by the appropriate entity depending on the customer’s location and the nature of the request.
5. Data Protection Officer
The Controllers have not appointed a formal Data Protection Officer within the meaning of Article 37 GDPR.
All matters relating to personal data protection may be addressed via:
📧 office@qualash.com
6. Purposes and Legal Basis for Data Processing
Personal data is processed for the following purposes:
-
performance of sales contracts (order processing, delivery, order status notifications, invoicing, complaints, returns, guarantees),
-
responding to inquiries and providing customer support,
-
fulfillment of legal obligations, including tax and accounting requirements,
-
creation and maintenance of a customer account (if applicable),
-
sending newsletters and marketing communications (only with the customer’s consent),
-
enabling customers to submit product reviews,
-
establishment, exercise, or defense of legal claims,
-
ensuring the security and proper operation of the online store.
The legal bases for processing personal data are:
-
performance of a contract or taking steps prior to entering into a contract (Article 6(1)(b) GDPR),
-
compliance with legal obligations (Article 6(1)(c) GDPR),
-
consent of the data subject (Article 6(1)(a) GDPR),
-
legitimate interests of the Controller (Article 6(1)(f) GDPR), including fraud prevention, security, analytics, and internal business administration.
7. Categories of Personal Data Processed
Depending on the services used, the following categories of personal data may be processed:
-
first and last name,
-
billing and delivery address,
-
email address,
-
phone number,
-
account login credentials,
-
company name (for business customers),
-
tax identification number or VAT number (if required for invoicing).
8. Data Retention Period
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, including:
-
the duration of the contract and statutory retention periods,
-
the period necessary to establish, pursue, or defend legal claims,
-
until consent is withdrawn (in cases where processing is based on consent).
9. Data Recipients
Personal data may be shared with trusted third parties only to the extent necessary, including:
-
courier and logistics providers,
-
payment service providers (e.g. PayPal, Stripe, ShopPay),
-
accounting and legal service providers,
-
IT, hosting, and cloud service providers.
All such entities process personal data on the basis of agreements concluded with the Controller and solely in accordance with its instructions.
10. International Data Transfers
Personal data may be transferred between the above-mentioned entities or to third countries where necessary, using appropriate safeguards, including Standard Contractual Clauses, in accordance with applicable data protection laws.
11. Rights of Data Subjects
You have the right to:
-
access your personal data,
-
rectify inaccurate or incomplete data,
-
request deletion of personal data,
-
restrict processing,
-
object to processing based on legitimate interests,
-
data portability,
-
withdraw consent at any time (where processing is based on consent).
You also have the right to lodge a complaint with the competent supervisory authority.
12. Cookies
The online store uses cookies to ensure proper operation of the website, improve user experience, generate statistics, and deliver content tailored to user preferences.
You may change cookie settings at any time via your browser settings. Restricting cookies may affect certain functionalities of the website.
13. Final Provisions
Providing personal data is voluntary but necessary to conclude a sales contract, create a user account, or receive certain services. Failure to provide required data may result in the inability to provide services.
This Privacy Policy may be updated from time to time. The current version is always available at www.qualash.com.

