Skip to content

Privacy on dpay.pl

Privacy policy

This page explains the key rules for processing personal data when you use dpay.pl, contact us or use our services.

Download the Polish policy PDF

Data controller

The controller is Payments Lab sp. z o.o., registered at 2/31 Chmielna Street, 00-020 Warsaw, Poland, KRS 0000845085, tax ID 5252825300, REGON 386243396. Contact info@dpay.pl about personal data.

When and why we process data

Using our services

Data is used to enter into and perform a contract, meet legal duties, handle accounting and establish, pursue or defend claims.

Contact and forms

We use form data to answer a question, handle a request or complaint, or take steps before entering into a contract.

Marketing communication

If you consent, we may send marketing information through the selected channel. You can withdraw consent at any time.

Analytics and advertising

Statistics, personalisation and marketing on the site follow the choice you make in cookie settings.

Security and claims

We may process necessary data to protect the site and its users and to establish, pursue or defend claims.

Legal bases

Depending on the situation, we rely on a contract or pre-contract steps, a legal obligation, your consent or our legitimate interests, such as handling communication, security and claims.

How long we keep data

The period depends on the purpose. Contract data is retained while the contract is performed, for required accounting periods and until claims expire. Consent-based data is used until consent is withdrawn; cookie data follows the period shown in the cookie declaration or remains until deletion.

Your rights

Where provided by the GDPR, you can request:

  • access to personal data and a copy
  • rectification
  • erasure
  • restriction of processing
  • data portability
  • withdrawal of consent
  • an objection to processing based on legitimate interests

You can also complain to the President of the Polish Personal Data Protection Office or your local supervisory authority.

Recipients and transfers outside the EEA

Data may be shared with providers supporting hosting, IT maintenance, office and accounting work, communication, analytics or marketing, only to the extent needed for their work, and with authorised public bodies. For transfers outside the European Economic Area we use a GDPR transfer mechanism, such as an adequacy decision or standard contractual clauses.

Data security

We apply technical and organisational measures appropriate to the risk, including encrypted connections. Do not send passwords or complete card details in a form unless a field explicitly requests them.

Cookies and consent changes

The cookie policy explains cookie categories, shows the current declaration and lets you change your choice.

Open the cookie policy