Personal data protection
Information from Pave Poland sp. z o. o. on the processing of personal data
Pave Poland sp. z o. o. with its registered office in Warsaw (“PaveNow”, “Controller”) processes personal data in accordance with applicable personal data protection laws and regulations and makes every effort to ensure the security and protection of personal data during processing.
1. Legal basis for data processing
The information is prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the " GDPR ").
2. Who is the personal data controller and how can I contact them?
The personal data controller is PAVE POLAND sp. z o. o. (ul. Chmielna 73, 00-801 Warsaw) (KRS:001031636; NIP: 7011141512). After conducting an analysis, PaveNow has not appointed a Personal Data Protection Supervisor. You can contact PaveNow as the controller:
a) in writing to the postal address of PaveNow (ul. Chmielna 73, 00-801 Warsaw), preferably with the note"Personal Data Administrator"
b) electronically to the email address: it.admin@pavenow.io.
Detailed information regarding the processing of personal data, such as the source, categories of personal data, purposes of processing, processing time and recipients, together with the processors, is divided below depending on whose personal data is being processed.
3. Information on the processing of personal data for the person/entity concluding the loan agreement ("Borrower"), the Borrower's representatives, their proxies and employees
a) Source of data acquisition
PaveNow obtains personal data from the Borrower or representatives/employees during the process of applying for, negotiating, and concluding a loan agreement (loan application). Providing personal data is voluntary, but its processing is necessary for the performance of the loan agreement, particularly for ongoing contacts, invoice confirmation, debt balances, invoicing, etc. Without access to this data, PaveNow cannot reliably provide its services, or this ability is severely limited.
b) Categories of personal data
PaveNow processes or may process the following categories of personal data of the Borrower/his representatives:
- identification data of the Borrower/representative (e.g. name and surname, company name, registered office/correspondence address, date and place of birth, number and series of the identity document, numbers: NIP, REGON, KRS, PESEL);
- contact details of the Borrower/representative (e.g. e-mail, telephone number, home address);
- data identifying the Borrower/representative (e.g. information from an ID card);
- credentials of the Borrower/representative (e.g. specimen signature);
- data on the Borrower’s liabilities, financial data on the Borrower, data on the Borrower’s economic situation (e.g. data on financial results);
- data on turnover and transactions in the Borrower's bank accounts;
- data on the marital status and marital property regime of the Borrower;
- publicly available data from registry sources regarding the Borrower (e.g. KRS online, CEiDG, REGON register, White List of VAT Taxpayers, KRS files, National Register of Debtors, land and mortgage registers, business intelligence agencies, etc.);
- data for the Customer Panel (e.g. username, password, invoices, etc.).
PaveNow processes or may process the following categories of personal data of employees/persons employed by the Borrower:
- identification and contact details of the Borrower's employees designated for ongoing contacts in the performance of the loan agreement (name and surname, job position, job telephone number, job e-mail address);
- data for the Customer Panel (e.g.username, password, reported invoices, documents, etc.);
- identifying data;
- employee/representative credentials (e.g. specimen signature).
c) Purposes of personal data processing
PaveNow processes (or may process) data in accordance with the principles set out in the GDPR for the following purposes:
- performance of the Agreement (Article 6, paragraph 1, letter b of the GDPR ) – personal data are processed for the purpose of performing the loan agreement and providing services related thereto, including, among others, for the purpose of (i) determining the financial capacity of the Borrower; (ii) granting, changing, suspending loan limits, paying out individual tranches; (iii) conducting debt collection; (iv) conducting correspondence via e-mail addresses used by PaveNow – in the scope of ongoing contact, the process of handling the loan agreement for individual receivables, responding to inquiries, including those regarding the services provided, the sale of services offered by PaveNow; (v) considering complaints; (vi) ensuring the possibility of using the Customer Panel and its functionalities for users;
- fulfilling the Administrator's legal obligations (tax, reporting, fraud prevention, anti-money laundering and counteracting terrorism financing) (Article 6, paragraph 1, letter c of the GDPR; Article 106d of the Act of 29 August 1997 - Banking Law ) - PaveNow is treated as an "obligated institution" within the meaning of the provisions on counteracting money laundering and counteracting terrorism financing. Therefore, PaveNow has a number of obligations arising from the provisions of the law. At the same time, PaveNow remains entitled and obliged to verify the identity of the Borrower (their representatives), as well as to determine the beneficial owner of the Borrower and assess whether they are nota politically exposed person (PEP);
- pursuit of the Controller’s legitimate interests (Article 6, paragraph 1, letter f of the GDPR ) – specifically: (i) exercising the creditor’s rights, including the so-called conservative actions, establishing, pursuing, securing or defending claims between the Borrower/representatives and PaveNow, (ii) detecting abuses and preventing their occurrence; (iii) marketing of own services, (iv) for archival and statistical purposes, including statistics, internal archiving and reporting, development and improvement of services and support systems, as well as ensuring accountability of personal data processing;
- carrying out activities for an additional fee Consent (Article 6, paragraph 1, letter a of the GDPR )– this applies to situations where additional consent has been granted to the processing of data for specific purposes (e.g., transferring data for marketing purposes or receiving a newsletter). Such consent may be withdrawn at anytime. Withdrawal of consent does not affect the processing of data that took place before the consent was withdrawn, i.e., it takes effect from the moment the declaration was made.
d) Data processing time
Personal data will be processed and stored for the period necessary to perform the contract concluded with PaveNow, and after this period, for the purposes and for the time and to the extent required by law or to secure any claims – until the expiry/statute of claims following its termination (generally, this is a period of 3 years from the invoice due date – see Art. 118 et seq. of the Civil Code). If the basis for processing these data is consent, then the data will not be stored after the withdrawal of consent for the purposes for which consent was granted or an effective objection is raised.
e) Recipients of personal data and processors
Personal data may be received by:
- Public institutions – if there is an obligation arising from legal provisions;
- Economic Information Offices, business intelligence agencies, etc. – for the purpose of assessing payment capacity;
- Entities providing insurance services for receivables covered by the contract;
- Entities conducting payment activities (banks, payment institutions) for the purpose of making transfers, refunds, etc.;
- Entities providing services to PaveNow or on its behalf: contract brokerage, IT (including website and Customer Panel management), data aggregation (e.g. Kontomatik sp. z o. o.), legal, accounting, bookkeeping, tax, auditing, debt collection, courier, postal services – under relevant agreements or contract templates, including, where necessary, personal data processing entrustment agreements.
4. Information on the processing of personal data for guarantors, including bills of exchange guarantors
PaveNow processes the data of persons who provide guarantees, including bills of exchange, to secure the repayment of Borrowers’ obligations under the loan agreement on the following principles.
a) Source of data acquisition
PaveNow obtained personal data of the person providing guarantees, including bills of exchange, for the Borrower's obligations either from the guarantor, including the bill of exchange guarantor, or from the Borrower during the process of concluding the loan agreement, including establishing its security (including the guarantee). Providing the data was voluntary, although it was a condition for the effective guarantee, including the bill of exchange guarantor.
b) Categories of personal data
PaveNow processes or may process the following categories of guarantor personal data:
- identification data (name and surname, PESEL);
- contact details (home address, etc.);
- data on marital status and marital property regime;
- publicly available data from registration sources (e.g. KRS online, CEiDG, REGON register, White List of VAT Taxpayers, KRS files, National Register of Debtors, land and mortgage registers, etc.).
c) Purposes of personal data processing
PaveNow processes (or may process) data in accordance with the principles set out in the GDPR for the following purposes:
- execution of the loan agreement (Article 6, paragraph 1, letter b of the GDPR)– specifically, the execution of a guarantee relationship, including a bill of exchange
- fulfilling the legal obligations of the Controller (tax, reporting and fraud prevention as well as counteracting money laundering and terrorism financing) (Article 6, paragraph 1, letter c of the GDPR; Article 106d of the Act of 29 August 1997 – Banking Law) – PaveNow is treated as an "obligated institution" within the meaning of the regulations on counteracting money laundering and terrorism financing. PaveNow is therefore subject to a number of obligations arising from the provisions of the law. At the same time, PaveNow remains entitled and obliged to verify the identity, as well as to determine the beneficial owner and assess whether the person holds a politically exposed position (PEP);
- realization of the legitimate interests of the Controller (Article 6 paragraph 1 letter f of the GDPR) -specifically: establishing, pursuing or defending claims between the guarantor and PaveNow.
d) Data processing time
The guarantor’s personal data will be stored for the duration of the receivable secured by the guarantee, including a bill of exchange, i.e. at the latest until its complete expiry or the limitation period for claims expires.
e) Recipients of personal data and processors
Personal data may (but does not have to) be received by:
- public institutions – if there is an obligation arising from legal provisions;
- entities providing insurance services for receivables covered by the loan;
- entities conducting payment activities (banks, payment institutions) for the purpose of making transfers, refunds, etc.;
- the purchaser of the receivable covered by the guarantee – in the case of the sale of the receivable to the guarantor
- entities providing services to PaveNow or on its behalf: IT, legal, accounting, bookkeeping, tax, auditing, debt collection, courier, postal -under appropriate agreements or contract templates, including, where necessary, personal data processing entrustment agreements - if the Controller uses the services of such entities in connection with the recovery of debts from the guarantor.
The Controller requires service providers to provide a level of protection and security of personal data in accordance with legal provisions.
5. Information on the processing of personal data for spouses of the Borrower/guarantor, including the bill of exchange guarantor
PaveNow processes the data of persons who are in a marital relationship with the Borrower or a guarantor, including a bill of exchange guarantor (" spouse "), on the following principles.
a) Source of data acquisition
PaveNow obtained personal data either from the spouse or from the Borrower during the process of concluding the loan agreement, including establishing security (including guarantees). Providing the data was voluntary, although it was a condition for the effective issuance of a guarantee, including a bill of exchange and the issuance of a bill of exchange guarantor's declaration, or the conclusion of the loan agreement.
b) Categories of personal data
PaveNow processes or may process the following categories of spouse's personal data:
- identification data (name and surname, PESEL);
- contact details (home address, etc.);
- data on marital status and marital property regime;
- publicly available data from registration sources (e.g. KRS online, CEiDG, REGON register, White List of VAT Taxpayers, KRS files, National Register of Debtors, land and mortgage registers, etc.).
c) Purposes of personal data processing
PaveNow processes (or may process) data in accordance with the principles set out in the GDPR for the following purposes:
- execution of the loan agreement (Article 6, paragraph 1, letter b of the GDPR)– specifically the execution of a loan agreement or a guarantee relationship, including a bill of exchange,
- fulfilling the legal obligations of the Controller (tax, reporting and fraud prevention as well as counteracting money laundering and terrorism financing) (Article 6, paragraph 1, letter c of the GDPR; Article 106d of the Act of 29 August 1997 – Banking Law) – PaveNow is treated as an "obligated institution" within the meaning of the regulations on counteracting money laundering and terrorism financing. Therefore, PaveNow has a number of obligations arising from the provisions of the law. At the same time, PaveNow remains entitled and obliged to verify the identity, as well as to determine the beneficial owner and assess whether the person holds a politically exposed position (PEP).
- realization of the legitimate interests of the Controller (Article 6 paragraph 1 letter f of the GDPR) -specifically: establishing, pursuing or defending claims between the guarantor and PaveNow.
d) Data processing time
Personal data will be processed and stored for the period necessary to perform the contract concluded with PaveNow or for the duration of a claim secured by a guarantee, and after this period, for the purposes and for the time and to the extent required by law or to secure any claims – until the expiry/statute of claims following its termination (generally, this is a period of 3 years from the invoice due date – see Art. 118 et seq. of the Civil Code). If the basis for processing these data is consent, then the data will not be stored after the withdrawal of consent for the purposes for which consent was granted or after an effective objection.
e) Recipients of personal data and processors
Personal data may (but does not have to) be received by:
- public institutions – if there is an obligation arising from legal provisions;
- entities providing insurance services for receivables covered by the loan;
- entities conducting payment activities (banks, payment institutions) for the purpose of making transfers, refunds, etc.;
- the purchaser of the receivable covered by the guarantee – in the case of the sale of the receivable to the guarantor
- entities providing services to PaveNow or on its behalf: IT, legal, accounting, bookkeeping, tax, auditing, debt collection, courier, postal -under appropriate agreements or contract templates, including, where necessary, personal data processing entrustment agreements - if the Controller uses the services of such entities in connection with the recovery of debt towards the spouse, Borrower, guarantor, including bill of exchange.
The Controller requires service providers to provide a level of protection and security of personal data in accordance with legal provisions.
6. Information on the processing of personal data of contractors (suppliers of goods and services)("Debtor")
a) Source of data acquisition
PaveNow obtained the Debtor's personal data either from the Debtor or the Borrower during the process of concluding the loan agreement, including establishing security (including the assignment of receivables owed to the Debtor). Providing the data was voluntary, although it was a condition for the effective assignment of receivables and the establishment of security for the loan agreement.
b) Categories of personal data
PaveNow processes or may process the following categories of personal data of the Debtor:
- identification data (name and surname, PESEL, NIP, REGON, KRS);
- contact details (address of residence, registered office, telephone number, e-mail address, etc.);
- data on marital status and marital property regime;
- publicly available data from registration sources (e.g. KRS online, CEiDG, REGON register, White List of VAT Taxpayers, KRS files, National Register of Debtors, land and mortgage registers, etc.).
c) Purposes of personal data processing
PaveNow processes (or may process) data in accordance with the principles set out in the GDPR for the following purposes:
- execution of the loan agreement and the assigned receivable against the Debtor (Article 6, paragraph 1, letter b of the GDPR )
- fulfilling the Controller's legal obligations (tax, reporting, fraud prevention, anti-money laundering and anti-terrorist financing). PaveNow is treated as an "obligated institution" within the meaning of the provisions on anti-money laundering and anti-terrorist financing. Therefore, PaveNow has a number of obligations arising from the provisions of the law. At the same time, PaveNow remains entitled and obliged to verify the identity, as well as to determine the beneficial owner and assess whether the person does not hold a politically exposed position (PEP) (Article 6, paragraph 1, letter c of the GDPR; Article 106d of the Act of 29 August 1997 - Banking Law)
- pursuit of the legitimate interests of the Controller (Article 6, paragraph 1, letter f of the GDPR) -specifically: establishing, pursuing or defending claims between the Debtor and PaveNow.
d) Data processing time
the PaveNow receivable against the seller (assignor) secured by the assignment of the receivable against the Debtor, i.e. at the latest until its complete expiration as a result of settlement or return transfer or expiry of the limitation period for claims.
e) Recipients of personal data and processors
Personal data may (but does not have to) be received by:
- public institutions – if there is an obligation arising from legal provisions;
- entities providing insurance services for receivables covered by the loan;
- entities conducting payment activities (banks, payment institutions) for the purpose of making transfers, refunds, etc.;
- buyer of the receivable covered by the guarantee – in the event of the sale of the receivable against the Debtor
- entities providing services to PaveNow or on its behalf: IT, legal, accounting, bookkeeping, tax, auditing, debt collection, courier, postal – under relevant agreements or contract templates, including, where necessary, personal data processing entrustment agreements – if the Controller uses the services of such entities in connection with debt collection against the Debtor.
The Controller requires service providers to provide a level of protection and security of personal data in accordance with legal provisions.
7. Information on the processing of the pledger's personal data
In order to secure contracts, PaveNow also concludes pledge agreements, including registered pledge agreements, which involve the processing of personal data under the following principles.
a) Source of data acquisition
PaveNow obtained the Debtor's personal data either from the Debtor or the Borrower during the process of concluding the loan agreement, including establishing its security (including the registered pledge). Providing the data was voluntary, although it was a condition for establishing an effective pledge and establishing security for the loan agreement.
b) Categories of personal data
PaveNow processes or may process the following categories of personal data of the pledgor:
- identification data (name and surname, PESEL, NIP, REGON, KRS);
- contact details (address of residence, registered office, telephone number, e-mail address, etc.);
- data on marital status and marital property regime;
- publicly available data from registration sources (e.g. KRS online, CEiDG, REGON register, White List of VAT Taxpayers, KRS files, National Register of Debtors, land and mortgage registers, etc.).
- data contained in the registration certificate or insurance policies (e.g. series and number of the ID card or passport, details of co-owners).
c) Purposes of personal data processing
PaveNow processes (or may process) data in accordance with the principles set out in the GDPR for the following purposes:
- performance of the pledge agreement – specifically the performance of the security (pledge ) (Article 6, paragraph 1, letter b of the GDPR )
- fulfilling the Controller's legal obligations (tax, reporting, fraud prevention, anti-money laundering and anti-terrorist financing). PaveNow is treated as an "obligated institution" within the meaning of the provisions on anti-money laundering and anti-terrorist financing. Therefore, PaveNow has a number of obligations arising from the provisions of the law. At the same time, PaveNow remains entitled and obliged to verify the identity, as well as to determine the beneficial owner and assess whether the person does not hold a politically exposed position (PEP) (Article 6, paragraph 1, letter c of the GDPR; Article 106d of the Act of 29 August 1997 - Banking Law)
- the pursuit of the Controller’s legitimate interests (Article 6, paragraph 1, letter f of the GDPR) – specifically: establishing, pursuing or defending claims between the pledgor and PaveNow regarding the subject of the pledge.
d) Data processing time
the PaveNow receivable against the seller (assigner) secured by a pledge established by the seller, i.e. at the latest until its complete expiration as a result of settlement or return transfer or limitation of claims.
e) Recipients of personal data and processors
Personal data may (but does not have to) be received by:
- public institutions – if there is an obligation arising from legal provisions;
- entities providing insurance services for receivables covered by the loan;
- entities conducting payment activities (banks, payment institutions) for the purpose of making transfers, refunds, etc.;
- the purchaser of the receivable covered by the registered pledge – in the event of the sale of the receivable to the pledgor;
- entities providing services to PaveNow or on its behalf: IT, legal, accounting, bookkeeping, tax, auditing, debt collection, courier, postal -under appropriate agreements or contract templates, including, where necessary, personal data processing entrustment agreements - if the Controller uses the services of such entities in connection with the recovery of debts against the pledgor.
The Controller requires service providers to provide a level of protection and security of personal data in accordance with legal provisions.
8. Information on the processing of personal data of website users and cookie policy
Detailed information is available here.
9. Data transfer
Personal data is generally not transferred to third countries or international organizations or outside the EEA. Data may be transferred to third countries or international organizations only if (1) it is necessary to provide the service in accordance with the Borrower's instructions (e.g., a document assigning receivables – especially cross-border, a transfer order, etc.), (2) it is required by applicable law or necessary for the pursuit of claims, or (3) the data subject has given specific consent to transfer the data.
10. Profiling
Personal data will not be subject to automated decision-making, including profiling, unless consent is provided. Exceptionally, personal data may be profiled to assess anti-money laundering and terrorism financing risks. PaveNow does not make decisions based solely on automated processing, including profiling.
11. Data subject rights and final provisions
Every person whose data is processed by PaveNow has the right to:
a) access to your data in accordance with Article 15 of the GDPR;
b) rectification of data in accordance with Article 16 of the GDPR;
c) deletion of personal data in accordance with Article 17 of the GDPR;
d) restrictions on data processing in accordance with Article 18 of the GDPR;
e) object to the processing of personal data in accordance with Article 21 of the GDPR;
f) data portability in accordance with Article 20 of the GDPR;
g) lodging a complaint with the supervisory authority – the President of the Personal Data Protection Office (current contact details are available at www.uodo.gov.pl).
Any requests can be sent to the Administrator using the contact information provided at the beginning.