Privacy Policy
We want you to understand what we do with your data. Each section begins with a brief summary — followed by the full legal text. You have the right to ask us about your data at any time: biuro@pozabankiem.pl.
Table of contents
- Data controller
- Purposes and legal bases for processing
- Categories of data processed
- Data recipients
- Transfer of data outside the EEA
- Data retention period
- Your rights
- Profiling and automated decision-making
- Data security
- Children's personal data
- Changes to the Privacy Policy
- Contact and supervisory authority
1. Data controller
In brief: KB Group Spółka z Ograniczoną Odpowiedzialnością is the controller of your data. You can contact us by email, phone, or post.
The controller of personal data within the meaning of Article 4(7) GDPR is:
KB Group Spółka z Ograniczoną Odpowiedzialnością
Registered office address: Plac Stanisława Małachowskiego 2, 00-066 Warszawa
KRS: 0001249094 · NIP: 5253095134
E-mail: biuro@pozabankiem.pl
Phone: +48 507 440 718
(hereinafter: the „Controller”)
The Controller has not appointed a Data Protection Officer (DPO), as this is not required under Article 37 GDPR given the scale and nature of its business activity. Any questions regarding personal data should be directed to: biuro@pozabankiem.pl with the subject „Personal data”.
2. Purposes and legal bases for processing
In brief: We process your data only when we have a specific reason to do so — responding to your inquiry, performing a contract, complying with a legal obligation, or pursuing a legitimate business interest. Marketing data — only with your consent.
| Purpose of processing | Legal basis (GDPR) | Scope of data |
|---|---|---|
| Handling an inquiry via the contact form or by phone | Art. 6(1)(b) — pre-contractual steps; Art. 6(1)(f) — legitimate interest | First and last name, e-mail, phone, company name, message content |
| Financial capacity analysis and preparation of a financing offer | Art. 6(1)(b) — pre-contractual steps; Art. 6(1)(a) — consent | Identification, financial and asset data provided voluntarily |
| Performance of the financial brokerage agreement | Art. 6(1)(b) — performance of a contract | Data necessary to perform the agreement, data relating to financing and collateral |
| Fulfilment of legal obligations (accounting, AML/CFT, record-keeping) | Art. 6(1)(c) — legal obligation | Data required by law, KYC documents |
| Direct marketing of the Operator's own services | Art. 6(1)(f) — legitimate interest (clients) or Art. 6(1)(a) — consent (other persons) | Name, e-mail address, communication preferences |
| Analysis of website traffic (Google Analytics 4) | Art. 6(1)(a) — cookie consent | IP address (anonymized), browser, device, pages visited |
| Establishment or defense of legal claims | Art. 6(1)(f) — legitimate interest | Data necessary to establish, pursue, or defend legal claims |
3. Categories of data processed
In brief: We only process data that you provide to us yourself — via the form, phone, or e-mail. We do not purchase databases.
3.1. Identification data
- First and last name, or company name;
- PESEL number or NIP (for identity verification during the financing process);
- ID document series and number (only at the contract-conclusion stage).
3.2. Contact data
- E-mail address;
- Phone number;
- Correspondence or registered office address.
3.3. Financial and asset data
- Information about the financial situation of the company or individual (revenue, liabilities);
- Data relating to the real estate serving as collateral (address, value, land and mortgage register number);
- Data relating to receivables in the case of factoring (invoices, counterparties);
- Credit history — only on the basis of separate consent.
3.4. Technical data
- IP address (anonymized after 90 days in GA4);
- Browser and operating system type;
- Time and pages visited within the Service.
The Controller does not process special categories of personal data (Article 9 GDPR), except where the User voluntarily discloses such data and processing is necessary to assess financing eligibility.
4. Data recipients
In brief: We do not sell your data. We share it only with entities that help us provide our services or that are necessary to arrange financing.
- IT and hosting service providers — under data processing agreements (Article 28 GDPR);
- E-mail and CRM providers — solely for handling correspondence;
- Google LLC — Google Analytics 4 (based on cookie consent; SCC + DPF);
- Private investors and private debt funds — only with your express consent, for the purpose of financing analysis;
- Law firms and notaries — for transaction documentation purposes;
- Property valuers — valuation of the real estate serving as collateral;
- Accounting office and auditors — accounting obligations;
- Public authorities — only on the basis of a legal obligation (courts, tax authorities, the General Inspector of Financial Information (GIIF)).
The Controller does not sell Users' personal data to third parties for marketing purposes.
5. Transfer of data outside the EEA
In brief: Google Analytics transfers data to the USA on the basis of standard contractual clauses approved by the European Commission.
As a rule, data is processed on servers within the EEA. Google Analytics 4 (Google LLC, USA) transfers analytical data to the USA on the basis of Standard Contractual Clauses (SCC, European Commission Decision 2021/914) and the Data Privacy Framework (DPF, in effect since 10 July 2023).
6. Data retention period
In brief: Data from forms with no further cooperation — up to 2 years. Data from agreements — 10 years (legal requirement).
| Data category | Period | Basis |
|---|---|---|
| Contact form (no further cooperation) | 24 months from last contact | Legitimate interest |
| Data from the application process (no agreement concluded) | 36 months from completion of the process | Legitimate interest (defense of claims) |
| Data from a concluded brokerage agreement | 10 years from the end of the agreement | Accounting Act; statute of limitations |
| AML/KYC documentation | 5 years from the end of the relationship | Article 49 of the AML Act |
| Marketing data (newsletter) | Until consent is withdrawn or an objection is raised | Consent / legitimate interest |
| Google Analytics 4 | 26 months (IP anonymized after 90 days) | Cookie consent |
| Server logs | 90 days | Legitimate interest (IT security) |
7. Your rights
In brief: You have the full set of GDPR rights. We will handle every request within 30 days. Send an e-mail with the subject „GDPR Request”.
Confirmation of processing and a copy of your data.
Correction of inaccurate data or completion of incomplete data.
Deletion of data once the purpose no longer applies or you have withdrawn consent — provided there is no legal obligation to retain it further.
Suspension of processing in specific situations.
Data in CSV/JSON format, where the basis is consent or a contract.
Objection to processing based on legitimate interest, including marketing.
Possible at any time without giving a reason. Does not affect the lawfulness of processing carried out before withdrawal.
Complaint to the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
Send your request to: biuro@pozabankiem.pl (subject: „GDPR Request”). Response within 30 days; in particularly complex cases — up to 90 days, with notification.
8. Profiling and automated decision-making
In brief: Every financing decision is reviewed by a human. We do not operate on a fully automated basis.
The Controller carries out profiling for analytical and marketing purposes (cookies) — this does not produce legal effects for the User. Decisions to grant or refuse financing are not made solely on an automated basis — each is reviewed by an authorized employee or associate.
9. Data security
In brief: We use TLS encryption, limit access, and regularly review our safeguards.
- Encryption of data transmission using TLS 1.2+ (HTTPS across the entire site);
- Access to data limited exclusively to authorized persons bound by confidentiality obligations;
- Regular backups;
- Two-factor authentication (2FA) for systems processing personal data;
- Data breach response procedures in accordance with Articles 33–34 GDPR.
10. Children's personal data
The Service is not directed at persons under 16 years of age. The Controller does not knowingly process children's data. If such a situation is detected, please contact us so the data can be deleted without delay.
11. Changes to the Privacy Policy
We will inform Users of any material change by posting a notice within the Service and — for persons who have consented to email communication — by electronic message, with at least 14 days' notice.
12. Contact and supervisory authority
- E-mail: biuro@pozabankiem.pl (subject: „Personal data”)
- Phone: +48 507 440 718 (Mon–Sun, 9:00 AM–8:00 PM)
- Address: KB Group Spółka z Ograniczoną Odpowiedzialnością, Plac Stanisława Małachowskiego 2, 00-066 Warszawa
Supervisory authority: President of the Personal Data Protection Office (PUODO)
ul. Stawki 2, 00-193 Warszawa · tel. 22 531 03 00 · uodo.gov.pl