Privacy Policy

§1. General Information

This Privacy Policy (hereinafter: the "Policy") describes in detail the principles of processing personal data and the use of cookies and other tracking technologies within the website www.paygrid.pl (hereinafter: the "Service"). Through the Service, Paygrid Tech presents its technology solutions (including white-label payment solutions, e.g. BLIK integrations) intended for licensed payment institutions (EMIs, PSPs) and communicates with existing and potential business partners. The purpose of this document is to ensure full transparency – we want every User to know exactly what information is collected about them, for what purpose, on what legal basis, and what rights they are entitled to.

The data controller is Paygrid Technologies spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw, ul. Jana Pawła II 43A/37B, 01-001 Warsaw, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0001251334, NIP (Tax ID): 5273225918, REGON (Statistical ID): 545162781, also operating under the brand name Paygrid Tech (hereinafter: the "Controller" or the "Company").

The Controller may be contacted:

  • by post: ul. Palisadowa 20/22, 01-940 Warsaw, Poland,
  • by e-mail: kontakt@paygrid.pl.

Should a Data Protection Officer (DPO) be appointed, the DPO's contact details will be included in this Policy to enable direct contact regarding data protection matters.

The Controller processes data in accordance with:

  • the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council),
  • the Polish Act on the Protection of Personal Data of 10 May 2018,
  • the Polish Act on the Provision of Electronic Services of 18 July 2002,
  • the Polish Telecommunications Law of 16 July 2004.
§2. Definitions

For ease of understanding, below are the key terms used in this Policy, presented in plain language:

  • User – any person visiting our Service or using the Controller's services, whether registered or not, including representatives of the Controller's existing or potential business partners.
  • Personal data – any information that allows identification of a specific individual, e.g. first name, surname, e-mail address, phone number, IP address, or location data.
  • Processing – any operation performed on personal data, whether automated or manual, including collecting, storing, organizing, modifying, sharing, or deleting.
  • Services – functionalities available in the Service, including the contact form, newsletter, scheduling product presentations/demos, and communication with existing and potential business partners (e.g. EMIs, PSPs interested in implementing Paygrid Tech's solutions).
  • Cookies – small text files stored on the User's device, which enable the Service to function and allow traffic analysis and content personalization.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data.
§3. Scope of Data Collected

Depending on how the User interacts with the Service, we may process various categories of personal data:

  1. Data provided voluntarily by the User – provided when contacting us about cooperation, sending a message via the contact form, subscribing to the newsletter, or scheduling a product presentation/demo. This may include: first name, surname, e-mail address, phone number, company name, tax ID (NIP), job title, or the content of the message sent.
  2. Data collected automatically – recorded while using the Service, such as IP address, device and browser identifiers, operating system type, language settings, date and time of visit, pages visited, as well as information from cookies and similar technologies.
  3. Data obtained from third parties – in specific cases, we may receive data from public registers (KRS, CEIDG) or from business partners, to the extent necessary to establish and carry out cooperation.
§4. Purposes and Legal Bases for Processing Data

Personal data is processed only in accordance with the law and only for specified purposes:

  • to conclude and perform an agreement for the use of services provided by the Controller (legal basis: Article 6(1)(b) GDPR);
  • to fulfil legal obligations incumbent on the Controller, including in the area of accounting and taxation (legal basis: Article 6(1)(c) GDPR);
  • for contact and direct marketing of products or services via electronic and telephone communication (legal basis: your consent and Article 6(1)(a) GDPR);
  • to handle inquiries and complaints regarding the services provided (legal basis: Article 6(1)(c) GDPR);
  • to protect against claims or to pursue claims by the data Controller (legal basis: Article 6(1)(f) GDPR).

Data may also be processed (provided it relates to the Controller's activities and the secondary purposes are connected to the purposes listed above) for the following secondary purposes (legal basis: Article 6(1)(f) GDPR):

  • archiving data,
  • ensuring the proper functioning of the Controller's website and tailoring it to users' needs,
  • preparing internal reports and analyses,
  • conducting internal audits.
§5. Voluntary Provision of Data

Providing personal data is voluntary; however, in certain situations it may be a condition for using a specific service (e.g. providing an e-mail address is necessary to receive a reply to an inquiry). Failure to provide the required data may prevent the provision of a given service.

§6. Recipients of Data

Personal data may be disclosed to

  • entities providing services on our behalf, e.g. hosting providers, mailing systems, analytics tools, legal and accounting service providers,
  • payment service providers in connection with settlements for services provided by the Controller,
  • public authorities, where required by law.

Every entity to which we entrust data is obliged to protect it and to process it solely for the purpose of performing the specified services.

§7. Transfer of Data Outside the EEA

As a rule, personal data is not transferred outside the European Economic Area. If we use the services of providers based outside the EEA, the transfer takes place only on the basis of mechanisms ensuring compliance with the GDPR, e.g. European Commission adequacy decisions or Standard Contractual Clauses (SCCs).

§8. Data Retention Period

Personal data will be processed for the period necessary to achieve the purposes indicated in this Policy, in particular:

  • for the performance of the Agreement – for the duration of the agreement;
  • for marketing purposes – until consent to the processing of personal data is withdrawn;
  • for handling complaints and claims – until your claims become time-barred;
  • for debt collection and pursuing claims – until claims become time-barred;
  • for tax and accounting purposes, for 5 years from the end of the financial year in which the agreement between the parties was terminated.
§9. User Rights

The User has the right to:

  • access their data,
  • rectify their data,
  • erase their data ("the right to be forgotten"),
  • restrict processing,
  • transfer data to another controller,
  • object to processing,
  • withdraw consent at any time,
  • lodge a complaint with the President of the Personal Data Protection Office (UODO).
§10. Cookies

The Service uses cookies and similar technologies to ensure proper functioning, analyze traffic, and customize content. We distinguish between the following types of cookies:

  • necessary – required for the Service to function, not requiring consent,
  • analytical – requiring consent, used for traffic analysis,
  • marketing – requiring consent, used for ad personalization.

The User may change their cookie settings at any time in their browser or via the preference panel in the Service.

Necessary cookies serve to guarantee the proper functioning and optimization of the website for the devices and browsers most commonly used by visitors – this ensures the computer or mobile device displays the site correctly and legibly. These files are also used to remember whether a given user has given a particular consent (e.g. to display selected content) or has not. Blocking these cookies may therefore prevent or significantly hinder access to certain functionalities and areas of the Service.

Analytical cookies are used to create aggregate statistics and analyses that help understand how the Website is used – this allows us to continuously improve the structure and content of the pages to better meet the needs of current and potential Users.

§11. Server Logs

Every visit to the Service results in technical information being recorded in server logs, such as IP address, date and time of the request, browser and operating system information, or the URL of the referring page. This data is used solely for administrative, technical, and security purposes.

§12. Security Measures

We ensure data security by applying, among others:

  • transmission encryption (SSL/TLS),
  • access control to data,
  • server protection against attacks,
  • regular backups,
  • ongoing software updates.
§13. Links to Other Websites

The Service may contain links to other websites that are not managed by the Controller. Clicking such a link takes you outside the Service to a third-party website. The Controller is not responsible for the privacy practices in effect on those websites. We encourage you to review the privacy policy and personal data processing rules of any other website you visit. This Policy applies solely to the Service at www.paygrid.pl.

§14. Managing Cookies

Our goal is for the use of cookies and similar technologies to be fully transparent to Users. We use both our own cookies and third-party cookies – in particular for analytical and marketing purposes – as described in §10 of this Policy.

Most web browsers allow users to manage cookies independently, including blocking or deleting them. Detailed instructions on changing cookie settings can be found on the support pages of individual browsers, including: Firefox, Internet Explorer / Edge, Google Chrome, Safari, Opera.

Restricting the use of cookies may affect certain functions of the Service and, in extreme cases, may prevent the use of selected services.

§15. Final Provisions Regarding Changes to the Policy

The Controller reserves the right to introduce changes to this Policy, in whole or in part. Any change becomes effective upon publication of the new version of the Policy in the Service, unless another effective date is expressly indicated. The current version of the Policy is always available at https://www.paygrid.pl.

§16. Changes to the Policy

This Privacy Policy may be amended in the event of changes to legal provisions, the introduction of new technologies, or changes in how the Service operates. The current version of the Policy is always available on the website, together with its effective date.

Paygrid Technologies sp. z o.o.
ul. Aleja Jana Pawła II 43A/37B, 01-001 Warszawa, Polska
KRS: 0001251334 | NIP: 5273225918 | REGON: 545162781

© 2026 Paygrid. All rights reserved.