Privacy Policy
Last updated: July 2026
1. Who we are
FINOWO sp. z o.o. ("Finowo", "we", "us") is the data controller within the meaning of Regulation (EU) 2016/679 ("GDPR") and the Polish Act of 10 May 2018 on the Protection of Personal Data, for personal data processed through our website at finowo.finance and our platform (the "Service").
| Field | Value |
|---|---|
| Controller | FINOWO sp. z o.o. |
| Registered address | Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland |
| KRS | 0001183467 |
| NIP | 7011269175 |
| REGON | 542227920 |
| Supervisory authority | Urząd Ochrony Danych Osobowych (UODO) — uodo.gov.pl |
| GDPR contact | privacy@finowo.finance |
2. What data we collect
| Category | Examples | Why |
|---|---|---|
| Identity | Name, job title | Account creation and invoicing |
| Contact | Email, phone, billing address | Service delivery and support |
| Account | Company name, VAT number (NIP), country | Workspace configuration |
| Usage | Pages visited, features used, click events | Product improvement |
| Device | IP address, browser type, OS | Security and fraud prevention |
| Communications | Support tickets, email threads | Customer support |
| Financial | Billing history, subscription plan | Payment processing |
We do not collect special category data (Art. 9 GDPR — e.g. health, biometric data, racial or ethnic origin) unless you explicitly provide it in documents you upload to the Service.
3. Legal basis for processing
| Activity | Legal basis | GDPR article |
|---|---|---|
| Providing the Service | Performance of contract | Art. 6(1)(b) |
| Invoicing and tax records | Legal obligation | Art. 6(1)(c) |
| Security monitoring and fraud detection | Legitimate interest | Art. 6(1)(f) |
| Product analytics (aggregated) | Legitimate interest | Art. 6(1)(f) |
| Marketing emails | Consent | Art. 6(1)(a) |
| Compliance with KNF, NBP, GIIF, and other Polish authorities | Legal obligation | Art. 6(1)(c) |
| Establishing or defending legal claims | Legitimate interest | Art. 6(1)(f) |
Legitimate interests (Art. 6(1)(f) GDPR) include: securing the Service, preventing abuse, improving the product based on aggregated metrics, and protecting the Company's rights. You may object to processing based on legitimate interest at any time (see Section 7).
4. How long we keep your data
| Data type | Retention period | Reason |
|---|---|---|
| Account and profile data | Duration of contract + 3 years | Limitation periods under the Polish Civil Code |
| Invoices and transaction records | 5 years from the end of the calendar year in which the tax payment deadline expired | Polish tax and accounting law |
| Support tickets | 3 years | Legitimate interest |
| Session and device data | 30 days | Security |
| Marketing preferences | Until you withdraw consent | Consent |
| Audit logs | Up to 10 years | Regulatory / AML requirement |
When you close your account we delete or anonymise your personal data within 30 days, except where we are required by law to retain it longer.
5. Who we share data with
We do not sell your data. We share it only with the following categories of processors, each bound by a Data Processing Agreement (Art. 28 GDPR):
| Processor type | Purpose | Location |
|---|---|---|
| Cloud infrastructure | Hosting and storage | Germany (EU) — Hetzner |
| Payment processor | Subscription billing | EU |
| Transactional email | Account notifications | EU |
| Analytics | Aggregated product metrics | EU |
All processors are located in the European Economic Area or operate under adequate transfer mechanisms.
We may also disclose data to public authorities (e.g. KNF, NBP, GIIF, tax authorities, courts) where required by law.
6. International transfers
Our primary infrastructure runs on Hetzner servers in Germany (EEA). We do not transfer personal data outside the EEA without either:
- an adequacy decision of the European Commission (Art. 45 GDPR), or
- Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with a transfer impact assessment where required.
7. Your rights
Under GDPR you have the following rights. To exercise any of them, email privacy@finowo.finance — we will respond without undue delay and in any event within 30 days (Art. 12(3) GDPR). Where necessary, this period may be extended by a further two months — we will inform you if so.
| Right | What it means |
|---|---|
| Access (Art. 15) | Receive a copy of all personal data we hold about you |
| Rectification (Art. 16) | Correct inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion — subject to legal retention obligations |
| Restriction (Art. 18) | Limit how we process your data |
| Portability (Art. 20) | Receive your data in a structured format (JSON or CSV) |
| Object (Art. 21) | Object to processing based on legitimate interest |
| Withdraw consent (Art. 7(3)) | Withdraw marketing consent at any time (without affecting lawfulness of processing before withdrawal) |
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO):
Urząd Ochrony Danych Osobowych
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
8. Cookies
We use the following categories of cookies and similar technologies:
| Category | Purpose | Can you opt out? |
|---|---|---|
| Strictly necessary | Session management, authentication, security | No — required for the Service |
| Functional | Language and preference storage | No — required for the Service |
| Analytics | Aggregated usage metrics | Yes — via cookie banner |
| Marketing | Retargeting (only on finowo.finance) | Yes — via cookie banner |
You can manage your preferences at any time via the cookie settings link in the footer. Full details: Cookie Policy.
Necessary cookies are based on Art. 6(1)(f) GDPR (legitimate interest — operating the site). Non-essential cookies are used only with your consent under Polish telecommunications law.
9. Security
We protect your data with technical and organisational measures, including:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Role-based access control — our staff access only what they need
- Audit logging of all access to personal data
- Regular security reviews
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the UODO without undue delay, and where feasible not later than 72 hours after becoming aware of it (Arts. 33–34 GDPR).
10. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@finowo.finance and we will delete it promptly.
11. Automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR), other than fraud/AML tools that may automatically flag transactions for human review.
12. Changes to this policy
We will update this page when our practices change and notify you by email if the change is material. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
Data controller: FINOWO sp. z o.o.
KRS: 0001183467 · NIP: 7011269175
Email: privacy@finowo.finance
Postal: Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland
For data subject requests: privacy@finowo.finance
For general legal matters: legal@finowo.finance