Privacy Policy
Last updated: November 13, 2025
This document describes how Mc2 DOO (hereinafter “we”, “us”, or “the Controller”) collects, uses, and protects the personal data of users (hereinafter “you” or “the User”) who visit and interact with the website https://mc2.gallery (hereinafter “the Website”).
1. Data Controller
The Data Controller for personal data is:
Mc2 DOO
21 Novembar 2A, 85320 Tivat, Crna Gora – Montenegro
Contact Email: info@mc2.gallery
2. Types of Data Collected
We collect various types of personal data:
- Data provided voluntarily by the User:
- For purchasing products (WooCommerce): First name, last name, billing and shipping address, phone number, email address, and order details.
- For Newsletter subscription: Email address and name.
- For contact requests: Email address, name, and any other information you include in your message.
- Navigation Data (collected automatically):
- IP addresses, browser type, access times, and other parameters related to the User’s operating system and IT environment, collected via cookies and similar technologies.
3. Purposes and Legal Basis for Processing
We process your data only for specific purposes and when a valid legal basis exists.
| Purpose of Processing | Types of Data Processed | Legal Basis |
|---|---|---|
| Manage and fulfill orders (sale of artworks) | Personal data, contact details, shipping information. | Performance of a contract to which the User is a party. |
| Send our Newsletter (Marketing) | Email address, Name. | Explicit Consent of the User (provided via the subscription form). |
| Respond to contact requests | Contact details and message content. | Legitimate interest of the Controller to respond to User inquiries. |
| Ensure the security and operation of the Website | Navigation data, IP addresses. | Legitimate interest of the Controller. |
| Statistical analysis (in aggregate form) | Navigation data (via statistical cookies). | Consent of the User (managed via the cookie banner). |
| Comply with legal and tax obligations | Billing and transaction data. | Legal obligation. |
4. Data Sharing and Recipients (Third Parties)
We do not sell your data. We share it only when necessary to provide our services, respecting the purposes listed above. Data recipients include:
- Platform Providers: WordPress, Elementor, and WooCommerce, who provide the technical foundation of the site.
- Payment Gateways (e.g., Stripe, PayPal): To process payments. We do not store your full credit card details. (You must list the specific providers you use).
- Shipping Companies and Couriers: To deliver the purchased artworks.
- Newsletter Service Providers: For sending the mailing list. (You must list the service you use, e.g., Mailchimp, MailerLite).
- Analytics and Security Services: Google Analytics, Google reCAPTCHA, and Sourcebuster JS, as detailed in our Cookie Policy.
- Other Third Parties: Google Fonts, Mixpanel, and IAB TCF, as detailed in our Cookie Policy.
- Accountants and Tax Authorities: For tax and legal compliance.
- Competent Authorities: If required by law.
5. Data Transfer Outside the EEA
Some of the services listed (e.g., Google, newsletter services) may be based outside the European Economic Area (EEA). Data transfer only occurs if adequate data protection safeguards are in place, such as the Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Data Retention Period
We retain your data only for the time strictly necessary:
- Contractual Data and Invoices: For the period required by law (e.g., 10 years for tax purposes).
- Marketing Data (Newsletter): Until you withdraw your consent (e.g., by clicking “unsubscribe”).
- Contact Request Data: For the time necessary to process the request.
- Cookie Data: Please refer to our Cookie Policy for specific expiration times (e.g., Google Analytics `_ga` is 2 years).
7. User Rights (GDPR)
As described in our Cookie Policy, you have the following rights regarding your personal data:
- Right of Access: To request a copy of your data we hold.
- Right to Rectification: To correct inaccurate data.
- Right to Erasure (Right to be Forgotten): To request the deletion of your data.
- Right to Withdraw Consent: To withdraw consent for marketing at any time.
- Right to Data Portability: To request your data in a structured, machine-readable format.
- Right to Object: To object to processing based on our legitimate interest.
To exercise these rights, you can contact us at info@mc2.gallery. You also have the right to lodge a complaint with the competent supervisory authority.
8. Cookie Policy
This Privacy Policy is supplemented by our Cookie Policy, which provides detailed information on all cookies and tracking technologies used on this Website.