Legal
Privacy policy
In force from 29 May 2026
1. General provisions
1.1. This Privacy Policy ("Policy") sets out the rules for the processing of personal data in connection with the use of the website available at bergopay.com ("Service").
1.2. The Service is informational in nature and is intended primarily to present the Controller's activities, enable contact with potential partners and handle enquiries addressed to the Controller.
1.3. The Service serves as the Controller's online business profile and does not provide for user registration or login. As at the effective date of the Policy, the Service provides, in particular, a contact form. The full functionality of the Service, including the possibility to create a client account, update data and submit a full request/application, will be made available at a later date. The Controller will inform users about the introduction of new functionalities by updating this Policy.
1.4. The Policy covers only the processing of data related to the operation of the Service. It does not cover separate data processing processes carried out outside the Service, in particular in connection with the provision of the relevant financial services, payment services, onboarding procedures, KYC/AML procedures, merchant services or contractual relationships.
2. Data Controller and contact details
2.1. The controller of personal data is BERGOPAY spółka z ograniczoną odpowiedzialnością, with its registered office in Poznań, at pl. Władysława Andersa 3, 11th floor, 61-894 Poznań, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0001087262, NIP 7831897723, REGON 527722573 ("Controller").
2.2. The Controller is a small payment institution (MIP) entered in the Register of Payment Service Providers and Electronic Money Issuers maintained by the Polish Financial Supervision Authority under number MIP250/2024 and provides payment services pursuant to the Payment Services Act of 19 August 2011.
2.3. The Controller does not provide services to consumers. The Service and the services described in it are addressed exclusively to entrepreneurs and other organisational units conducting business or professional activity.
2.4. In matters concerning the processing of personal data, the Controller may be contacted by e-mail at: office@bergopay.com.
2.5. The Company has not appointed a data protection officer (DPO).
3. What data we may process
3.1. Depending on the manner in which the Service is used, we may process, in particular, the following categories of data:
- identification and contact data, such as first name, surname, e-mail address, telephone number, company name, position or function, to the extent that they are provided in the form or during contact;
- data contained in the content of a message, enquiry, contact request or notification sent by the user;
- technical and operational data related to the use of the Service, including IP address, timestamps, information about the device, operating system, browser, server logs and similar diagnostic information;
- data related to granting or withdrawing consents, cookie preference data and, in the case of the newsletter, also data confirming subscription, clicks and unsubscription;
- other data voluntarily provided by the user in connection with the use of the Service or contact with the Controller.
3.2. Scope of form fields and functionalities active in the Service. As at the effective date of the Policy, only the contact form is active in the Service. It includes the following fields: first name and surname, business e-mail address, company name, area of interest (acquiring / alternative payment methods / open banking / checkout / multiple services) and message content. The full functionality of the Service, including the possibility to create a client account, update data and submit a full request/application, will be made available at a later date, at which point this Policy will be updated accordingly.
4. Purposes, legal bases and periods of processing
4.1. Personal data are processed for the following purposes:
| Purpose | Scope of data | Legal basis | Processing period |
|---|---|---|---|
| Handling correspondence, enquiries and contact requests | Identification and contact data, business data, message content, contact preferences and other voluntarily provided data. | Article 6(1)(f) GDPR — the Controller's legitimate interest consisting in conducting communication, handling enquiries and building business relationships; to the extent that the enquiry concerns steps prior to entering into a contract taken at the request of a natural person. | Until the matter is closed, and thereafter for the period necessary to demonstrate the course of contact and for the limitation period for claims, or for 12 months from the last exchange of correspondence in the thread, unless longer storage is justified by the establishment of a business relationship or required by law (in particular for the purpose of defending against claims, until the expiry of the limitation period). |
| Sending the newsletter (if the functionality is active) | E-mail address, optionally first name, data concerning subscription, confirmation of consent, newsletter activity and unsubscription. | Article 6(1)(a) GDPR — consent of the data subject. | Until consent is withdrawn or the newsletter subscription is cancelled, and thereafter, to a limited extent, for the period necessary to demonstrate accountability and defend against claims. |
| Ensuring the security of the Service, keeping logs, diagnostics, preventing abuse and spam | IP address, technical identifiers, device and browser information, timestamps, system logs, information about errors and security events. | Article 6(1)(f) GDPR — the Controller's legitimate interest consisting in ensuring the security of the Service, detecting abuse and maintaining continuity of operation. | Server logs, as a rule, up to 14 days from the date of registration of the entry, unless longer storage is justified by the need to clarify a security incident or fulfil legal obligations, in which case only for the period necessary to achieve that purpose. |
| User verification mechanism (captcha / anti-spam), if used | IP address, browser and device data, data on interaction with the form and other data required by the provider of the verification mechanism. | Article 6(1)(f) GDPR — the Controller's legitimate interest consisting in protecting the Service and forms against automated submissions, spam and abuse. | In accordance with the rules of the mechanism provider and for a period no longer than necessary to verify the submission and prevent abuse, as a rule up to 6 months from the interaction with the form. |
| Analytics, statistics, online marketing and cookie preference management, if such tools are implemented | Data on activity in the Service, online identifiers, cookies and similar technologies, IP address, device data and statistical/marketing data. | With respect to necessary technologies — Article 6(1)(f) GDPR. With respect to optional technologies — Article 6(1)(a) GDPR and consent required under the applicable provisions of the Electronic Communications Law. | In accordance with cookie settings, the lifetime of individual tools and for a period no longer than until the User withdraws consent; with respect to optional cookies, no longer than until the end of the lifetime of the relevant cookie indicated in section 11 of the Policy and in a separate cookie policy. |
| Establishing, pursuing and defending against claims | Data necessary to demonstrate specific circumstances, including contact data, correspondence content, logs and data concerning actions performed. | Article 6(1)(f) GDPR — the Controller's legitimate interest consisting in protecting the Controller's rights and defending against claims. | Until the expiry of the relevant limitation period for claims and for the period necessary to complete proceedings. |
5. Data recipients
5.1. Personal data may be disclosed to entities cooperating with the Controller only to the extent necessary to achieve the purposes indicated in the Policy and in accordance with applicable law.
5.2. The recipients of data may include, in particular:
- authorised employees and associates of the Controller;
- providers of hosting, cloud infrastructure, e-mail, CMS and Service maintenance services;
- providers of contact forms, call scheduling tools, newsletters, captcha, analytics, marketing, CMP / cookie banner and IT support;
- legal advisers, compliance advisers, auditors and other professional advisers, to the extent necessary to protect the Controller's rights;
- entities authorised under legal provisions, in particular public authorities and law enforcement authorities.
5.3. Providers currently used or categories of providers connected with the Service. As at the effective date of the Policy, the Controller uses the following providers in connection with the operation of the Service:
(i) GoDaddy.com, LLC, with its registered office in the United States, a provider of hosting services for the Service, with which the Controller has entered into a data processing agreement (DPA);
(ii) Cloudflare, Inc., with its registered office in the United States, a provider supporting the contact form of the Service (forwarding submissions sent by the User to the Controller and protecting the form against abuse);
(iii) G2 (branch with its registered office in Barcelona, Spain), a provider of solutions supporting the Controller in fulfilling its obligations concerning anti-money laundering and counter-terrorist financing (AML/CTF), including customer identity verification (KYC/KYB) and transaction monitoring (KYT). A data processing agreement has been concluded with this provider. The use of this provider relates primarily to processes carried out outside the Service. In the context of the Service, it may be relevant if an enquiry is submitted that leads to an onboarding process;
(iv) authorised employees and associates of the Controller, to the extent necessary to handle enquiries and conduct ongoing communication with Users of the Service.
If additional tools or functionalities are implemented in the Service (in particular analytics tools, marketing tools, a consent management mechanism, captcha, newsletter or client account functionality), the list of providers will be updated accordingly in the Policy.
5.4. The Controller independently determines the purposes and means of processing personal data in connection with the operation of the Service. Within the Service, the Controller does not act as a joint controller within the meaning of Article 26 GDPR. If cooperation involving joint controllership is established in the future (for example joint partner campaigns involving the sharing of leads), the Policy will be supplemented accordingly.
6. Transfers outside the European Economic Area
6.1. The Controller aims to process data within the European Economic Area. However, if the Controller uses providers whose infrastructure or subcontractors are located outside the EEA, the transfer will take place only in accordance with the law, in particular using standard contractual clauses.
6.2. Information on transfers outside the EEA and the safeguards applied. As at the effective date of the Policy, transfers of personal data outside the European Economic Area related to the operation of the Service may occur, in particular, in connection with: (i) the use of hosting services provided by GoDaddy.com, LLC, with its registered office in the United States, and (ii) the handling of the contact form by Cloudflare, Inc., with its registered office in the United States. As part of these services, the providers may receive, in particular, the User's IP address, technical browser data and, in the case of the contact form, data provided by the User in the content of the submission. The transfer is carried out: (i) with respect to providers certified under the EU-U.S. Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023), on the basis of that adequacy decision; (ii) in other cases, on the basis of standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, together with additional technical and organisational measures if the risk assessment shows that they are necessary. The Controller has entered into a data processing agreement (DPA) with the hosting provider (GoDaddy.com, LLC). A copy of the applicable standard contractual clauses may be obtained by sending a request to the contact details indicated in section 2.4 of the Policy.
7. External tools and integrations
7.1. As at the effective date of the Policy, no call scheduling functionality is available in the Service. If such a functionality is implemented, the Policy will be updated with information concerning the provider and its operating model (redirection to an external service provider or an embedded booking module).
7.2. If such a functionality is implemented, the Controller will update this Policy with information concerning the provider and the rules for processing data within that functionality.
8. Profiling and automated decision-making
8.1. As part of the operation of the Service, Users' personal data are not used for automated decision-making, including profiling, which produces legal effects concerning Users or similarly significantly affects them within the meaning of Article 22(1) GDPR.
8.2. The Controller may use automated technical mechanisms in the Service (in particular mechanisms protecting against abuse and attacks, statistical and analytical tools), but they are not used to make decisions concerning Users within the meaning of section 8.1.
8.3. This section does not apply to onboarding, KYC/KYB, AML/CFT and transaction monitoring (KYT) processes carried out by the Controller outside the Service. With respect to those processes, relevant information is provided to clients in separate documentation.
9. Rights of data subjects
9.1. A data subject has, in the cases specified by law, the right of access to data, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on the Controller's legitimate interest.
9.2. If processing is based on consent, the data subject has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
9.3. The data subject also has the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Moniuszki 1A, 00-014 Warsaw, www.uodo.gov.pl) if they consider that the processing of personal data infringes the law.
10. Voluntary provision of data
10.1. Providing data is generally voluntary, but may be necessary to send a form, obtain a response, request a return contact, subscribe to the newsletter or use a specific functionality of the Service.
10.2. Failure to provide data marked as required may prevent a specific action from being carried out, in particular sending an enquiry or receiving a response.
11. Cookies and similar technologies
11.1. The Service uses cookies and similar technologies necessary for the proper operation of the Service, as well as analytical, statistical or marketing tools.
11.2. With respect to necessary technologies, their use may take place without the user's separate consent if this is necessary to transmit an electronic communication or to provide a service requested by the user. With respect to optional technologies, the user's consent is required and is collected before they are activated.
11.3. Detailed list of tools used, providers, retention periods and information on the cookie settings panel / CMP:
A) Necessary cookies and similar technologies (do not require consent, Article 399(4) of the Electronic Communications Law): as at the effective date of the Policy, no cookies are used in the User's terminal device in the Service. On the side of the hosting provider's infrastructure (GoDaddy.com, LLC), automatic HTTP/HTTPS request logging, integral to the hosting service, is carried out, including recording the User's clicks on Service subpages and timestamps, for the purposes of basic technical operation, diagnostics, statistics and ensuring the security of the Service.
B) External components requiring specific disclosure: (i) Cloudflare, Inc. (USA), used to handle the contact form available in the Service; this may involve providing the provider with the IP address, technical browser data and the form content and, consequently, transferring data outside the EEA (see section 6.2). In the current configuration, the use of this component does not involve saving cookies on the User's terminal device.
C) Optional cookies (require consent, Article 399(1) of the Electronic Communications Law and Article 6(1)(a) GDPR) — currently not used.
D) Consent management mechanism: in the current configuration of the Service, the Controller does not actively display a consent management banner due to the absence of cookies or similar technologies requiring the User's consent. If such technologies are introduced, the Controller will implement an appropriate banner and update this Policy.
The full cookies policy is available here.
12. Minors
12.1. The Service is addressed exclusively to adults. The Controller does not intend to obtain personal data of persons under 18 years of age through the Service.
13. Changes to the Policy
13.1. The Policy may be updated periodically, in particular in the event of changes to the functionality of the Service, changes to the tools used, changes in law or changes in the manner of data processing.
13.2. The current version of the Policy will be published in the Service in a manner that enables users to become familiar with its content.
14. Effective date
This Policy applies from 29 May 2026.