Privacy policy
Privacy Policy of the Gunfire.com Online Store
I. General Information
-
This Privacy Policy sets out the rules for processing the personal data
of persons using the online store available at
www.gunfire.com
,
hereinafter referred to as the “Store”, including persons who:
- visit the Store’s website;
- create an account in the Store;
- place orders;
- contact the Company, including through the contact form or chat;
- use the Zowie virtual assistant;
- subscribe to the newsletter;
- submit complaints, statements of withdrawal from the contract or other requests.
- The controller of personal data is GF Corp spółka z ograniczoną odpowiedzialnością spółka komandytowa, with its registered office in Wrocław at ul. Jana Długosza 42–46, hereinafter referred to as the “Controller” or the “Company”.
-
The Controller processes personal data in accordance with applicable
laws, in particular:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, hereinafter referred to as the “GDPR”;
- regulations concerning the provision of electronic services and electronic communications;
- Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence, hereinafter referred to as the “AI Act”.
- The Controller has appointed a Data Protection Officer. In matters concerning the processing of personal data, the Data Protection Officer may be contacted at: iod@gfcorp.pl.
- Detailed information on the use of cookies and similar technologies is provided in the Cookie Policy.
II. Sources and Categories of Personal Data
-
The Controller obtains personal data primarily directly from the data
subject, in particular when the person:
- creates an account;
- places and completes an order;
- makes a payment;
- contacts the Company;
- uses the contact form or chat;
- uses the Zowie virtual assistant;
- submits a complaint or a statement of withdrawal from the contract;
- subscribes to the newsletter;
- gives marketing consent;
- uses the Store’s website.
-
Depending on how the Store is used, the Controller may process
the following categories of data:
- identification data, in particular first name and surname;
- contact details, in particular an email address and telephone number;
- address details, including the delivery address and the address used for issuing accounting documents;
- user account data, including the account identifier and activity history;
- data concerning orders, payments, deliveries, returns and complaints;
- data contained in correspondence and conversations conducted through chat;
- data of a person designated as a contact person or parcel recipient;
- date of birth or information confirming that the required age has been reached, where necessary due to the type of product or applicable laws;
- search history, viewed products and interactions with Store content;
- technical data, in particular the IP address, online identifiers, device type, browser type, operating system, date and time of using the Store and system logs;
- marketing preferences and information about consents given;
- other data voluntarily provided to the Controller.
- In the case of electronic payments, payment instrument data is generally processed by the payment service provider. The Controller does not store full payment card details unless expressly stated otherwise.
- If a customer provides the personal data of another person, for example a parcel recipient or contact person, the customer should inform that person that their data has been provided to the Controller and that they may review this Privacy Policy.
III. Purposes and Legal Bases of Data Processing
1. User account management
Personal data is processed to create and maintain an account in the Store and to provide access to its functionalities.
The legal basis for processing is Article 6(1)(b) of the GDPR – the performance of a contract for the provision of electronic services or taking steps at the user’s request before entering into such a contract.
2. Placing and fulfilling orders
Personal data is processed for the purpose of:
- accepting and fulfilling an order;
- entering into and performing a sales contract;
- processing payments;
- organising delivery;
- contacting the customer regarding order fulfilment.
The legal basis for processing is Article 6(1)(b) of the GDPR.
3. Tax, accounting and other legal obligations
Personal data may be processed for the purpose of issuing and retaining invoices and other accounting documents, maintaining accounting records and complying with other obligations arising from applicable laws.
The legal basis for processing is Article 6(1)(c) of the GDPR – compliance with a legal obligation to which the Controller is subject.
4. Returns, complaints and withdrawal from the contract
Personal data is processed for the purpose of:
- accepting and handling complaints;
- handling returns or withdrawal from the contract;
- exercising rights arising from liability for the conformity of goods with the contract, guarantees or other applicable laws.
The legal basis for processing is Article 6(1)(b) and Article 6(1)(c) of the GDPR and, in relation to the establishment, pursuit or defence of claims, Article 6(1)(f) of the GDPR.
5. Contact with the Controller
Personal data provided by email, telephone, contact form or chat is processed for the purpose of responding to and handling the request.
If the request concerns entering into or performing a contract, the legal basis for processing is Article 6(1)(b) of the GDPR. In other cases, the legal basis is Article 6(1)(f) of the GDPR, and the Controller’s legitimate interest is communicating with users and handling their enquiries.
6. Use of the Zowie virtual assistant
- The Store may provide the Zowie virtual assistant, which uses an artificial intelligence system.
- Before starting a conversation, the user is clearly and visibly informed that they are interacting with an AI system. This information is provided independently of the provisions of this Privacy Policy.
-
In connection with the use of Zowie, the Controller may process:
- the content of questions, answers and the entire conversation;
- contact details provided by the user;
- the order number and other data concerning the request, if provided by the user;
- technical data, including the IP address, session identifier, date and time of the conversation and device information;
- information necessary to transfer the conversation to a Company employee.
-
Data provided during a conversation with Zowie is processed for
the purpose of:
- answering the user’s question;
- handling requests concerning orders, returns, complaints and other matters related to the Store;
- transferring the conversation to a customer service representative where necessary or at the user’s request;
- ensuring the security and proper operation of the chat;
- detecting and correcting errors;
- monitoring the quality of customer service;
- establishing, pursuing or defending possible claims.
-
The legal basis for processing is:
- Article 6(1)(b) of the GDPR – where the conversation concerns entering into or performing a contract, an order, return or complaint;
- Article 6(1)(f) of the GDPR – in the case of other enquiries, ensuring security, monitoring quality, detecting errors and establishing, pursuing or defending claims.
- Conversations with Zowie are retained for the period necessary to provide the service, unless longer retention is required in connection with the performance of a contract, handling a complaint, compliance with a legal obligation or the establishment, pursuit or defence of claims.
-
The user should not provide the following information through the chat:
- payment card details;
- passwords and access codes;
- special categories of personal data, in particular health data;
- personal data of other persons, unless necessary to handle the request.
- Zowie supports customer service but does not make decisions concerning the user that produce legal effects or similarly significantly affect the user. In particular, Zowie does not independently resolve complaints or make binding statements on behalf of the Company.
- Responses generated by Zowie may contain errors or inaccuracies. The user may request that the conversation be transferred to a Company employee.
- Conversation content may be used to train artificial intelligence models only after the user has been informed in advance and provided that the Controller has an appropriate legal basis, including obtaining separate consent where required.
- Data processed through Zowie may be entrusted to the chat platform provider and the provider of the AI technology or model. These providers may process the data only on the Controller’s documented instructions, under concluded agreements and with appropriate security measures.
7. Newsletter and marketing communications
- Personal data is processed for the purpose of sending newsletters and other commercial information where the user has given the relevant consent.
- The legal basis for processing is Article 6(1)(a) of the GDPR.
- Email, telephone or other means of electronic communication are used for marketing purposes only in cases permitted by electronic communications laws.
- Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal. The user may unsubscribe from the newsletter, in particular by using the link included in the message.
8. Content personalisation and product recommendations
-
The Controller may analyse how the Store is used, including search
history, viewed products and interactions with content, for the purpose
of:
- adjusting how the Store is presented;
- displaying product recommendations;
- customising search results;
- analysing users’ interests and needs;
- improving the Store’s functionality.
- Where personalisation uses cookies or similar technologies that are not necessary for the Store to operate, personal data is processed based on the user’s consent under Article 6(1)(a) of the GDPR.
- In other cases, the legal basis for processing may be Article 6(1)(f) of the GDPR, and the Controller’s legitimate interest is developing the Store, adapting its functionality to users’ needs and conducting statistical analyses.
- For the personalisation of search results and recommendations, the Controller may use the services of IdoSell (IAI S.A., with its registered office in Szczecin). Detailed information about this provider is available at: www.idosell.com .
9. Security and prevention of abuse
Personal data, in particular the IP address, online identifiers, device data, activity data and system logs, is processed for the purpose of:
- ensuring the security of the Store;
- detecting abuse and fraud;
- preventing unauthorised access;
- ensuring continuity of services;
- enforcing the Store’s terms and conditions.
The legal basis for processing is Article 6(1)(f) of the GDPR, and the Controller’s legitimate interest is protecting the Store, its users and the transactions conducted through it.
10. Claims and accountability
Personal data may be processed for the purpose of establishing, pursuing or defending claims and demonstrating the Controller’s compliance with applicable laws.
The legal basis for processing is Article 6(1)(f) of the GDPR, and the Controller’s legitimate interest is protecting its rights and ensuring accountability.
IV. Cookies and Similar Technologies
-
The Store uses cookies and similar technologies for the purpose of:
- ensuring the proper operation of the website;
- maintaining the user’s session;
- remembering settings;
- conducting statistical analyses;
- personalising content;
- conducting marketing activities;
- ensuring security.
- Cookies that are not necessary for the proper operation of the Store are used only after obtaining the user’s consent.
- The user may change or withdraw their consent at any time using the consent management tool available in the Store.
- Detailed information about the types of cookies, their providers and their periods of operation is provided in the Cookie Policy.
V. Recipients of Personal Data
-
Personal data may be disclosed or entrusted to the following categories
of recipients:
- hosting, cloud and IT service providers;
- providers of software used to operate the Store;
- the chat platform provider and the AI technology provider used by Zowie;
- payment service providers;
- banks and payment institutions;
- courier, postal and logistics companies;
- providers of search, personalisation and product recommendation tools, including Prefixbox;
- email marketing and marketing service providers;
- analytics tool providers;
- entities providing accounting, legal, auditing and debt collection services;
- entities providing system security services;
- public authorities, where the obligation to disclose personal data arises from applicable laws.
- Recipients may process personal data as processors acting on the Controller’s instructions or as separate controllers where they independently determine the purposes and means of processing.
VI. Transfers of Personal Data Outside the European Economic Area
- Some service providers used by the Controller may have their registered offices or infrastructure outside the European Economic Area, in particular in the United States.
-
This applies or may apply in particular to:
- Google LLC;
- the chat platform provider;
- the provider of the AI system or model used by Zowie;
- providers of analytics, hosting or marketing services.
-
Personal data is transferred outside the European Economic Area only
where an appropriate legal basis exists, in particular:
- a European Commission adequacy decision, including, where applicable, the recipient’s participation in the EU–US Data Privacy Framework;
- standard contractual clauses approved by the European Commission;
- other safeguards provided for under the GDPR.
- Where required, the Controller applies additional technical and organisational measures and assesses the risks associated with the transfer of personal data.
- Information about the safeguards applied, or a copy of such safeguards, may be obtained by contacting the Data Protection Officer.
VII. Personal Data Retention Periods
- Account-related data is retained for the period during which the account is maintained and subsequently for the period necessary to comply with legal obligations and until the expiry of the applicable limitation periods for claims.
- Data concerning orders and contracts is retained for the duration of the contract and subsequently until the expiry of the limitation periods for related claims.
- Tax and accounting documentation is retained for the period required by applicable laws, generally for five years, calculated in accordance with the relevant tax and accounting regulations.
- Data concerning complaints, returns and withdrawals from contracts is retained for the period necessary to handle the matter and subsequently until the expiry of the limitation periods for claims.
- Data contained in correspondence is retained for the period necessary to handle the matter and subsequently until the expiry of the limitation periods for possible claims.
- Conversations conducted through Zowie or another chat service are retained for [● months], subject to the possibility of longer retention of data connected with an order, complaint, legal obligation or claim.
- Data processed based on consent is retained until the consent is withdrawn or the purpose of processing ceases to apply. Information about the granting and withdrawal of consent may be retained for longer where necessary to demonstrate the Controller’s compliance with the law.
- Data processed for direct marketing purposes is retained until an objection is raised or the relevant consent is withdrawn.
- System logs are retained for the period necessary to provide the service, unless longer retention is required due to a security incident, proceedings or a claim.
- Data associated with cookies is retained for the periods specified in the Cookie Policy.
- After the relevant retention period expires, personal data is deleted or anonymised in a manner that prevents the identification of the person.
VIII. Profiling, Automation and Artificial Intelligence
-
Personal data may be processed by automated means, including profiling,
for the purpose of:
- customising search results;
- recommending products;
- personalising Store content;
- conducting statistical analyses;
- detecting abuse and ensuring security.
- Profiling may involve analysing search history, viewed products, completed purchases, activity in the Store and declared preferences.
- The results of such analysis may affect the order in which products, recommendations or marketing content are displayed, but they do not produce legal effects concerning the user or similarly significantly affect the user.
- Zowie uses an AI system to analyse the content of a question and generate a response. Data provided during the conversation may be transferred to the AI technology provider to the extent necessary to generate a response and operate the chat.
- Zowie does not make decisions concerning the user based solely on automated processing that would produce legal effects or similarly significantly affect the user.
- If the Controller implements a system making such decisions in the future, it will provide data subjects, before the system is used, with the information required under the GDPR, including information on the logic involved, the significance and the envisaged consequences of such processing.
IX. Rights of Data Subjects
-
Subject to the conditions set out in the GDPR, the data subject has
the right to:
- obtain information about the processing of personal data;
- access personal data and receive a copy of it;
- rectify inaccurate personal data or complete incomplete personal data;
- erase personal data;
- restrict processing;
- data portability;
- object to processing based on Article 6(1)(f) of the GDPR;
- withdraw consent at any time where processing is based on consent;
- not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects the data subject.
- Where personal data is processed for direct marketing purposes, the data subject may object at any time. After an objection is raised, personal data will no longer be processed for such purposes.
- Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
- To exercise their rights, the data subject may contact the Controller or the Data Protection Officer at: iod@gfcorp.pl.
- The Controller may verify the identity of the person submitting the request where necessary to protect personal data against unauthorised disclosure.
- The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office.
X. Voluntary Provision of Personal Data
-
Providing personal data is voluntary, but in some cases it is necessary
to:
- create an account;
- enter into and perform a contract;
- fulfil an order and arrange delivery;
- process a payment;
- handle a complaint;
- respond to a request;
- use specific Store functionalities.
- Failure to provide personal data required for a particular purpose may make it impossible to provide the relevant service or handle the request.
- Providing personal data for the purpose of receiving newsletters or other marketing content is voluntary and is not a condition for entering into a contract.
XI. Personal Data Security
- The Controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with the processing of personal data.
- These measures include, in particular, access controls, permission management, IT system safeguards, backups, incident monitoring and confidentiality obligations imposed on persons with access to personal data.
- The Controller periodically assesses the security of the systems used, including AI systems and service providers involved in personal data processing.
XII. Amendments to the Privacy Policy
-
The Privacy Policy may be updated in particular in the event of:
- changes in applicable laws;
- changes in the scope of the Store’s activities;
- the implementation of new functionalities or technologies;
- changes of service providers;
- changes in how AI systems are used.
- The current version of the Privacy Policy is published in the Store together with its effective date.
- This version of the Privacy Policy is effective from 1 August 2026.
