Data controller
The controller is Payments Lab sp. z o.o., registered at 2/31 Chmielna Street, 00-020 Warsaw, Poland, KRS 0000845085, tax ID 5252825300, REGON 386243396. Contact info@dpay.pl about personal data.
When and why we process data
Using our services
Data is used to enter into and perform a contract, meet legal duties, handle accounting and establish, pursue or defend claims.
Contact and forms
We use form data to answer a question, handle a request or complaint, or take steps before entering into a contract.
Marketing communication
If you consent, we may send marketing information through the selected channel. You can withdraw consent at any time.
Analytics and advertising
Statistics, personalisation and marketing on the site follow the choice you make in cookie settings.
Security and claims
We may process necessary data to protect the site and its users and to establish, pursue or defend claims.
Legal bases
Depending on the situation, we rely on a contract or pre-contract steps, a legal obligation, your consent or our legitimate interests, such as handling communication, security and claims.
How long we keep data
The period depends on the purpose. Contract data is retained while the contract is performed, for required accounting periods and until claims expire. Consent-based data is used until consent is withdrawn; cookie data follows the period shown in the cookie declaration or remains until deletion.
Your rights
Where provided by the GDPR, you can request:
- access to personal data and a copy
- rectification
- erasure
- restriction of processing
- data portability
- withdrawal of consent
- an objection to processing based on legitimate interests
You can also complain to the President of the Polish Personal Data Protection Office or your local supervisory authority.
Recipients and transfers outside the EEA
Data may be shared with providers supporting hosting, IT maintenance, office and accounting work, communication, analytics or marketing, only to the extent needed for their work, and with authorised public bodies. For transfers outside the European Economic Area we use a GDPR transfer mechanism, such as an adequacy decision or standard contractual clauses.
Data security
We apply technical and organisational measures appropriate to the risk, including encrypted connections. Do not send passwords or complete card details in a form unless a field explicitly requests them.
Cookies and consent changes
The cookie policy explains cookie categories, shows the current declaration and lets you change your choice.
Open the cookie policy