Privacy Policy
Information on the processing and protection of personal data by ASERIS
Last updated: 9 September 2026
§ 1. Data Controller
The controller of personal data is Aseris Wojciech Miler, address: ul. Leśna 19 m. 11, 43-225 Wola, Poland, Polish Tax Identification Number (NIP): 6381865822, e-mail: biuro@aseris-studio.com.
This Privacy Policy applies to the activities conducted by the Controller under the ASERIS brand, including the website aseris-studio.com, domains redirecting to the Controller's website, including ASERIS.EU, online sales, provision of services, individual orders, sales intermediation, communication with customers, event galleries and the use of external platforms and tools connected with the Controller's business activities.
For matters concerning personal data protection, the exercise of rights under the GDPR and requests concerning the removal of personal data or photographs, the Controller can be contacted at:
§ 2. Categories of personal data processed
Depending on the way in which the website, sales channels or services are used, the Controller may process in particular: first and last name, company name, tax identification number, e-mail address, telephone number, delivery address, correspondence address, invoice details, information relating to an order or service, selected product, variant, personalisation, payment and delivery method, as well as the content of correspondence, complaints, returns and other requests.
In connection with design services, personalisation, 3D printing, 3D scanning, laser engraving, custom-made products, preparation of documentation or other services, the Controller may also process materials provided by the customer, including photographs, graphics, 3D models, design files, technical documentation, measurement data, inscriptions and other information necessary to perform the order.
Event galleries may involve the processing of submitted photographs and the images of persons shown in those photographs.
The Controller does not intentionally request special categories of personal data unless their processing is necessary and permitted by law. The Controller does not use photographs to infer sensitive characteristics of the persons depicted.
§ 3. Sources of personal data
Personal data may be obtained directly from the data subject, from a customer placing an order, from a person acting on behalf of a company, from a participant of an event submitting photographs, or through external sales, payment, communication or social-media platforms.
Where a customer provides personal data relating to another person, the customer should be authorised to provide such data where required by law.
§ 4. Purposes and legal bases of processing
Personal data may be processed for the following purposes: responding to enquiries, taking steps prior to entering into a contract, conclusion and performance of sales and service contracts, execution of individual orders, delivery, payment processing, invoicing and accounting, handling complaints and returns, communication with customers, protection and pursuit of claims, ensuring security of the website and services, operation of event galleries, statistics, analytics and marketing of the Controller's own products and services.
Depending on the circumstances, processing may be based on Article 6(1)(a) GDPR – consent, Article 6(1)(b) GDPR – performance of a contract or taking steps prior to entering into a contract, Article 6(1)(c) GDPR – compliance with a legal obligation, or Article 6(1)(f) GDPR – the Controller's legitimate interests.
Legitimate interests may include in particular handling correspondence, organisation and documentation of business processes, securing claims, prevention of abuse, technical security, development of services and marketing of the Controller's own products and services, provided that the interests or fundamental rights and freedoms of the data subject do not override those interests.
§ 5. Online sales and order fulfilment
In connection with online sales, the Controller processes data necessary to accept and fulfil the order, receive payment, deliver the product, issue accounting documents, communicate with the customer and handle after-sales matters.
Failure to provide data necessary to conclude or perform the contract may make it impossible to accept or fulfil the order.
§ 6. Services and individual orders
The Controller provides various services, which may include in particular design, 3D printing, 3D scanning, reverse engineering, laser engraving, personalisation, preparation of custom-made products, preparation of documentation and selected business-support services.
Data and files received for the purpose of performing a service are used primarily for the execution of the relevant order and are not automatically used in ASERIS advertising, promotional materials or portfolio without a separate legal basis or agreement with the customer.
§ 7. Sales and services through external platforms
Orders may also be placed through external platforms such as Allegro, OLX, Vinted or other sales platforms used by ASERIS.
In such cases, the platform operator may act as a separate controller of personal data in accordance with its own privacy policy. ASERIS processes the data received from the platform to the extent necessary to fulfil the order, communicate with the customer, deliver the goods, process complaints and carry out accounting obligations.
§ 8. Sales intermediation and transaction processing
Where ASERIS acts as an intermediary in a transaction or participates in organising the sale or performance of an order involving another entity, personal data may be transmitted to that entity to the extent necessary for the transaction to be completed.
The customer is informed of the relevant parties and conditions whenever this is required by applicable law.
§ 9. Contact, e-mail, forms and messaging services
When a user contacts ASERIS by e-mail, telephone, contact form, social media or another communication channel, the Controller processes the data provided in order to respond to the enquiry and conduct further correspondence.
Providing contact details is voluntary, but failure to provide information necessary to respond may prevent the Controller from handling the request.
§ 10. Photographs, image rights and event galleries
ASERIS may provide closed or limited-access event galleries in which participants can voluntarily submit photographs from a particular event.
Submitted photographs may contain personal data, including the image of identifiable persons. Such data may be processed in order to receive, technically prepare, store, secure and display photographs within the gallery of the relevant event.
A person submitting a photograph should have the right to share the photograph and should respect the privacy, rights and wishes of the persons shown in it. Where permission is required for dissemination of an identifiable person's image, the person submitting the photograph should have the appropriate permission.
Submission of a photograph does not automatically authorise ASERIS to use it for advertising, commercial promotional materials, social media or other marketing purposes outside the relevant event gallery.
ASERIS may remove photographs that are unrelated to the event, unlawful, infringe the rights or privacy of others or may otherwise create a security or legal risk.
During upload, photographs may be resized, converted to another technical format and stripped of technical metadata. The event-gallery mechanism is not intended to collect geolocation data contained in image metadata.
Storage and technical operation of event photographs may involve services provided by Google, including Google Drive.
A person wishing to request the removal of a photograph should contact: rodo@aseris-studio.com, indicating the event and, where possible, the photograph concerned.
Particular care should be taken when submitting photographs depicting children or other minors.
§ 11. Technical data and server logs
When the website or online services are used, technical information such as IP address, browser type, device type, operating system, request time, visited resources, errors and similar technical information may be processed automatically.
Such information may be processed for security, diagnostics, prevention of abuse, maintenance of the website and services and statistical analysis.
§ 12. Cookies, local storage and similar technologies
The website may use cookies, localStorage, sessionStorage and similar technologies enabling information to be stored on or read from the user's device.
Technologies necessary for the operation of the website may be used to ensure technical functionality, security, forms, uploads, galleries and storage of the user's privacy preferences.
The event-gallery system may store a technical browser identifier used to support uploading, distinguish browser sessions or devices and organise files connected with the relevant event.
Analytics or marketing technologies that are not necessary for the operation of the website are used only where permitted by applicable law and, where required, after obtaining the user's consent.
The user may refuse optional technologies or withdraw previously granted consent through the available cookie or privacy settings.
§ 13. Analytics, statistics and marketing
The Controller may use analytical, statistical and marketing tools, depending on the current configuration of the website, including tools supplied by providers such as Google, Meta or Squarespace.
Where such tools require consent for storage or access to information on the user's device, they are activated only after the required consent has been obtained.
Direct marketing of the Controller's own products and services may be carried out on the basis of a legitimate interest where permitted by law. Where separate consent is required for electronic marketing communications, such communication is carried out only on the basis of the required consent.
§ 14. Social media
ASERIS may operate profiles on social-media platforms. When a user visits such a profile, follows it, comments, reacts or sends a message, personal data may be processed by ASERIS and by the relevant platform operator in accordance with the applicable rules and privacy policies.
§ 15. Recipients of personal data
Personal data may be disclosed, to the extent necessary, to entities supporting the Controller in the operation of the business, including: website and hosting providers, Squarespace, Google, e-mail and IT providers, accounting and tax-service providers, banks and payment operators, courier and postal companies, sales platforms, communication providers, analytical and marketing providers and professional advisers.
Data may also be disclosed to public authorities where such disclosure is required by law.
§ 16. Transfers of data outside the European Economic Area
Some service providers used by the Controller may process data outside the European Economic Area.
Where such transfers occur, they are carried out using mechanisms permitted by Chapter V of the GDPR, such as an adequacy decision, standard contractual clauses or other legally recognised safeguards.
§ 17. Data retention
Personal data is retained only for as long as necessary for the purpose for which it was collected, and thereafter for periods justified by applicable legal obligations, accounting requirements or limitation periods for claims.
Data connected with orders and services may be retained for the duration of the contract and the period necessary to establish, pursue or defend claims. Accounting and tax data is retained for the period required by applicable law.
Data processed on the basis of consent is processed until consent is withdrawn, unless another legal basis allows further processing.
Data used for direct marketing is processed until an effective objection is raised or the relevant consent is withdrawn.
Photographs submitted to an event gallery are stored for the period necessary to operate that gallery. Unless a different period is stated for a particular event, photographs are removed from or made unavailable in the event gallery no later than 12 months after the event, unless another lawful basis justifies longer storage.
§ 18. Rights of data subjects
Subject to the conditions laid down in the GDPR, a data subject may have the right to request access to personal data and obtain a copy, rectify or complete the data, erase the data, restrict processing, receive or transfer the data, object to processing and withdraw consent at any time.
Where personal data is processed for direct marketing purposes, the data subject has the right to object to such processing at any time.
Requests may be sent to: rodo@aseris-studio.com.
§ 19. Right to lodge a complaint
A person who considers that the processing of personal data infringes the GDPR has the right to lodge a complaint with the competent supervisory authority.
In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
§ 20. Automated decision-making and profiling
The Controller does not make decisions based solely on automated processing that produce legal effects concerning a person or similarly significantly affect that person.
Analytical or advertising tools may perform limited technical profiling where such functionality is used and permitted by law, including after obtaining consent where consent is required.
§ 21. Children and minors
The ASERIS website is not primarily directed at children.
Where personal data relating to a minor is processed, the Controller takes particular care and applies the requirements resulting from applicable law, including obtaining consent from a parent or legal guardian where such consent is required.
§ 22. Data security
The Controller applies appropriate technical and organisational measures intended to protect personal data against accidental or unlawful loss, destruction, alteration, unauthorised disclosure or access.
Access to data is limited to persons and entities that require it for legitimate business purposes.
§ 23. External websites and services
The ASERIS website may contain links to external websites, platforms and services operated by other entities.
Those entities apply their own terms and privacy policies and may act as independent controllers of personal data.
§ 24. Changes to this Privacy Policy
The Controller may update this Privacy Policy, in particular where there are changes to applicable law, technologies, service providers, website functionality, business activities or methods of processing personal data.
The current version of the Privacy Policy is published on the Controller's website together with the date of the most recent update.
An amendment to this Privacy Policy does not affect the lawfulness of processing carried out before the amendment.

