MONODAT

Version: 1.3.2 · Effective date: 2026-10-15

The binding version of this document is the Polish version. Other language versions are provided for information only.

MONODAT — Privacy Policy

1. Data Controller

The controller of personal data processed in connection with the use of the MONODAT platform (https://monodat.com) is:

Moises Lopez Otero Studio Programistyczne ul. Osiedle Willowe 5, 31-901 Kraków, Poland NIP: 6793218612 | REGON: 389287603 General address: info@monodat.com

hereinafter the "Controller".

For all matters concerning personal data, privacy and the exercise of your rights, please contact: help@monodat.com. This is the operationally monitored address and the one on which we record statutory deadlines.

2. Data Protection Officer

Given the scale and nature of its activity, the Controller has not appointed a Data Protection Officer (DPO), as the conditions for mandatory appointment under Art. 37(1) GDPR are not met. For all data protection matters you may contact the Controller directly at help@monodat.com.

3. Categories of Data Processed

3.1. Platform Users' Data

In connection with registration, provision of the Services and subscription management, we process:

CategoryPurposeGDPR legal basis
First name, surname, company nameAccount registration, identificationArt. 6(1)(b) – contract
E-mail addressSign-in, communication, notificationsArt. 6(1)(b) – contract
Profile picture (if you sign in with Google)Display in the dashboardArt. 6(1)(b) – contract
Tax ID (NIP), billing addressInvoicing, tax obligationsArt. 6(1)(b)(c) – contract and legal obligation
Sign-in credentials (Firebase Authentication)AuthenticationArt. 6(1)(b) – contract
Session identifier (monodat_session_id)Enforcing single active session per Account, securityArt. 6(1)(b)(f) – contract and legitimate interest
History of company profiles viewedService provision (history, favourites), security, abuse detectionArt. 6(1)(b)(f) – contract and legitimate interest
Content of analytical chat (FIRMAIA) conversationsProviding the chat feature, conversation historyArt. 6(1)(b) – contract
Watchlists of companies, sectors and personsProviding monitoring and alerting ServicesArt. 6(1)(b) – contract
Subscription and paymentsBillingArt. 6(1)(b)(c) – contract and legal obligation
IP address and last sign-in dateSecurity, abuse detectionArt. 6(1)(f) – legitimate interest
IP address and browser/device signals, only when our systems flag a session as potentially automatedAnti-bot verification (Cloudflare Turnstile) to protect the Platform against scraping and credential-stuffing — see section 8Art. 6(1)(f) – legitimate interest
IP address and user-agent on acceptance of legal documentsProof of contract and consent (Art. 7(1) GDPR)Art. 6(1)(c)(f) – legal obligation and legitimate interest
Account preferences (language, sector, voivodeship, theme)PersonalisationArt. 6(1)(b)(f) – contract and legitimate interest
API keys and API call historyProviding and billing the API service, securityArt. 6(1)(b)(f) – contract and legitimate interest

We do not process your password — authentication is handled entirely by Google (Firebase Authentication), and the Controller never receives or stores passwords.

We do not process special categories of data (Art. 9 GDPR) about our Users — we do not collect data on health, opinions, affiliation or orientation.

3.2. Third-Party Data Displayed on the Platform (Art. 14 GDPR)

The Platform presents data from Polish public registers. This data may include names, addresses, positions held in companies, PESEL numbers (to the extent disclosed by the source register) and other identifying data of natural persons, in particular:

  • members of management boards, supervisory boards, proxies, liquidators (KRS),
  • shareholders and partners (KRS),
  • beneficial owners (CRBR),
  • politically exposed persons (PEPs) and persons appearing on sanctions lists,
  • entrepreneurs listed on the VAT White List,
  • public aid beneficiaries (SUDOP),
  • parties to court rulings published in the Portal of Common Court Rulings (SAOS) — see the note on criminal-related rulings below.

Data sources: KRS, CRBR, CEIDG (section 3.3), VAT White List, SUDOP, BZP, KRZ, MSiG, Ministry of Finance e-financial statements, SAOS, KNF, EBA, ESMA and MSWiA registers, and other Polish and EU public registers. In addition: the dlugi.info debt marketplace (debt sale offers — section 3.3) and the GeoNames database (postal-code coordinates for maps — sections 3.3 and 6).

Legal basis:

  • Art. 6(1)(e) GDPR – performance of a task in the public interest (transparency of commerce),
  • Art. 6(1)(f) GDPR – legitimate interest of the Controller and its clients (counterparty verification, compliance, due diligence).

Court-ruling data (SAOS) and Art. 10 GDPR: the common courts whose rulings are published in SAOS adjudicate both civil/commercial and criminal matters. To the extent a ruling ingested by the Platform relates to a criminal conviction or offence, it is personal data within the meaning of Art. 10 GDPR, which the Controller processes only to the extent this is compatible with Art. 10 as implemented under Polish law (in particular, published court rulings that Polish law already requires to be made publicly available in anonymised or pseudonymised form, in the same manner and to the same extent as the source SAOS publication). The Platform does not add any inference, label or score of its own on top of such rulings — it reproduces what the source publication already discloses.

Restrictions we apply voluntarily:

  • PESEL numbers are never displayed in full — the Platform shows only a masked form.
  • Natural persons' data is not publicly accessible — person search requires an authenticated account on a paid plan. Public, search-engine-indexed company profiles contain business entity data only. The sole exception is a narrow set of CEIDG entrepreneurs' registry data, which can be found without logging in only by full NIP, on pages excluded from search-engine indexing (section 3.3, "Public pages").
  • Contact details (e-mail, phone) shown publicly are masked — the full form requires an account.
  • We do not transmit natural persons' data to AI models in a form identifiable by PESEL number — see section 5.

Information for data subjects (Art. 14 GDPR):

If your personal data appears on the MONODAT Platform as a person holding a position in a company, we inform you that:

  • The data was obtained exclusively from sources publicly available by operation of Polish law.
  • The data is processed for professional purposes: counterparty verification, compliance, due diligence, market analysis.
  • You have the rights described in section 11 of this Policy.
  • To exercise your rights, contact the Controller: help@monodat.com.
  • The Controller may refuse erasure where processing is necessary for a task in the public interest or arises from a legal obligation binding the source registers. In such a case we will inform you of the reason for refusal and of your right to lodge a complaint with the President of UODO.
  • Application of the exception in Art. 14(5)(b) GDPR – informing every person whose data appears on the Platform individually would be impossible or require disproportionate effort given the scale of processing (hundreds of thousands of entities). For this reason the information is made publicly available in this Policy.
  • If the Platform has computed a Person Risk Indicator about you (section 4.2), you have specific, heightened rights described there, including the right to request the underlying facts and to have the indicator corrected or suppressed if it rests on inaccurate data.

3.3. Data of Sole Traders Registered in CEIDG

From version 1.3.0 the Platform presents data of natural persons carrying out business activity who are registered in the Central Register and Information on Economic Activity (CEIDG). The data comes from the daily official report "Registered business activities" made available by the minister responsible for the economy in the CEIDG Data Warehouse (dane.biznes.gov.pl) and from the CEIDG API, on the basis of the public nature of CEIDG data (Art. 45(1) of the Act of 6 March 2018 on the Central Register and Information on Economic Activity and the Entrepreneur Information Point) and the rules on re-use of public sector information, subject to the CEIDG Data Warehouse terms.

Scope of data presented (deliberately narrower than the official CEIDG search): the entrepreneur's business name (which contains the first name and surname), NIP, REGON, activity status and dates (start, suspension, resumption, end, deregistration), PKD codes, the address of the fixed place of business as published by CEIDG (street, building and unit number, postal code, town, commune, county, voivodeship — or an indication that there is no fixed place of business; street and number are shown from the effective date of version 1.3.1), participation in civil partnerships, dates of establishment and expiry of succession management, the type, issuing authority and validity of licences, concessions and permits, the entrepreneur's age in whole years, and the history of changes to these data from the day the entry was placed under monitoring.

What we do not present or disclose (restrictions applied voluntarily):

  • contact details (phone, e-mail, website, e-delivery address, correspondence address) — even where CEIDG discloses them,
  • date of birth (only age in whole years is shown), citizenship, marital property regime, date of death, the identity of the succession manager, bankruptcy disclosed in the CEIDG entry, bans, restrictions of legal capacity and guardianship, and the legal grounds for deregistration,
  • the PESEL number — the Platform does not store it in clear form and does not allow searching by PESEL; a digit string of PESEL length typed into the search box is rejected without any search being run,
  • CEIDG entrepreneurs' data in artificial-intelligence features (section 5) — the FIRMAIA chat has no access to this data,
  • the entrepreneur's home address — CEIDG does not disclose it and the Platform does not process it; the address shown is the place of business declared by the entrepreneur in CEIDG.

Place-of-business map: the entrepreneur's profile shows a map with the approximate location of the place of business. The pin marks the centre of the postal-code area (or of the commune or county where the postal code is unknown), not the exact address; the coordinates come from the GeoNames database (CC BY 4.0 licence) stored on the Controller's servers, and no entrepreneur data is transmitted to GeoNames. The map tiles come from OpenStreetMap (section 6). The same point (never the street and number) is shown on the public business profile. In the dashboard, at the User's request, the map may also show other businesses in the same sector and town (CEIDG registry data within the same scope).

Debt sale offers (dlugi.info): the Platform presents debt sale offers published by creditors on the dlugi.info debt marketplace — against companies as well as entrepreneurs registered in CEIDG. For companies the link is confirmed by a NIP search. dlugi.info does not publish the NIP of natural persons, so for CEIDG entrepreneurs the link is a probable match: it results solely from the first name, surname, town and street matching the CEIDG entry with a single possible entrepreneur, is labelled as such on the profile, is not a finding of fact and may concern another person. We show only the offer data (amount, form, date recorded, link to the offer at source); the information comes from the seller of the debt and has not been verified by us, and the absence of offers does not mean the absence of debts. An offer disappears from the Platform once withdrawn at source (checked at least weekly), after a successful objection (Art. 21 GDPR) or after a wrong match is reported to help@monodat.com — a wrong link is removed without delay. Legal basis: Art. 6(1)(f) GDPR (counterparty verification); data source within the meaning of Art. 14 GDPR: dlugi.info.

Access when logged in: searching CEIDG entrepreneurs by business name (including by first name and surname), NIP or REGON, and viewing the entrepreneur's profile within the scope described above, requires an authenticated Account (including a free Account on the Free Plan), subject to the viewing limits of the plan. The change history of the entry and the timeline are available on paid plans only. Even when logged in, the CEIDG entrepreneur search does not accept a PESEL number.

Public pages (without logging in): any visitor to the Platform, including without creating an Account, may, to a limited extent:

  • search for a business only by its full, valid NIP — the public search does not accept a first name, surname, business name, REGON number, town or PESEL number;
  • open the public business profile, which contains only: the entrepreneur's business name, NIP, REGON, activity status and dates, main PKD code, town, postal code, commune, county and voivodeship (or an indication that there is no fixed place of business), and a map with the approximate location at postal-code or commune level; the public profile never contains the street and building or unit number, the entrepreneur's age, signals from other registers, debt sale offers or the change history;
  • see a list of up to 10 businesses most recently registered in CEIDG or most recently changed, within a scope no wider than the public profile (business name, NIP, town, voivodeship, status, date and type of event).

Public pages concerning CEIDG entrepreneurs are excluded from search-engine indexing (noindex), show only entries present in the current CEIDG report and not subject to an objection, are reachable only at an address containing the NIP or the random CEIDG entry identifier (never a sequential internal number that would allow the database to be browsed in order), and access to them is protected by per-IP request limits and anti-bot verification (section 8). Their purpose is to let you check a counterparty whose NIP you already know — not to browse the dataset, search for people by first name and surname, or profile them. Contact details and the other data listed above as not presented are available neither on public pages nor in the dashboard.

Signals and links: the Platform cross-references a CEIDG entry with other public registers (VAT White List, KRZ, sanctions and PEP lists, SUDOP, EU funds, BZP, KNF registers and public warning list, RPWDL, Pharmacy Register, RHF, RPT, RDWW, KOWR, UOKiK decisions and warnings, KREPTD, MSiG, KIO, KRAZ) on the basis of a NIP or REGON match; the exception is building permits (GUNB), matched by the investor's name and address and labelled on the profile with a confidence indicator. Matches by name or surname alone are not presented as fact. A link marked "probable" is the result of a registry-data match presented without disclosing its basis and is not a finding of fact. The Platform does not compute a Monodat Score or a Person Risk Indicator for CEIDG entrepreneurs — signals mirror entries in the source registers without any assessment of the Controller's own.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the Controller and its clients (counterparty verification, fraud prevention, compliance and due diligence in commerce) with respect to data that is public by operation of law; Art. 6(1)(e) GDPR as regards transparency of commerce.

Right to object (Art. 21 GDPR): an entrepreneur registered in CEIDG may at any time object to the presentation of their entry on the Platform by writing to help@monodat.com. We handle objections within 72 working hours; where upheld, the entry is suppressed on the Platform (including its public pages), in the API and in exports (it no longer appears in search results, on the public profile, in the lists of recently registered or changed businesses, on the profiles of linked companies or in notifications) and the Controller does not restore it in subsequent synchronisations with CEIDG. Suppression on the Platform does not alter the data held in CEIDG itself — that requires an application to CEIDG. The Controller may refuse an objection only in the cases referred to in Art. 21(1) GDPR, stating the reason and the right to lodge a complaint with the President of UODO.

Information for CEIDG entrepreneurs (Art. 14 GDPR): the provisions of section 3.2 ("Information for data subjects") apply accordingly, except that the data was obtained from CEIDG (CEIDG Data Warehouse and CEIDG API) on the date shown on the profile as "data as of". Recipients may include Platform Users and API clients (section 8) who — for data retrieved outside the Platform — are independent controllers, and, within the limited scope described under "Public pages", any visitor to the Platform; the Terms of Service prohibit Users and API clients from using this data for direct marketing and from establishing the entrepreneur's home address, PESEL number, date of birth or contact details (re-identification).

4. Profiling and Automated Decisions (Art. 22 GDPR)

4.1. Company-Level Analytical Models

  1. The Platform provides statistical Analytical Models (including Prusak, Hołda, Mączyńska, Altman Z-Score, Beneish M-Score, Health Score, Monodat Score), which constitute profiling within the meaning of Art. 4(4) GDPR. These Models assess business entities using the entity's own public financial data — they do not take a named individual's personal characteristics as an input or produce a score attributed to a named individual.

  2. Profiling logic:

    • The Models are based on public financial data reported by entities to the KRS and the Ministry of Finance e-financial statements.
    • Classical statistical methods are used (regression, discriminant analysis, classification).
    • Results are informational and statistical only.

4.2. Person-Level Risk Indicators

  1. Separately from the company-level Models, the Platform computes a small number of indicators attached directly to an identified natural person, derived from public register data, currently limited to:

    • a director-count pattern ("serial director" indicator): a flag raised when a person holds directorships or equivalent functions in an unusually large number of companies, together with counts of how many of those companies carry a sanctions hit or are otherwise flagged as high-risk by the Platform;
    • sanctions and PEP list matching: whether a person's name matches an entry on a sanctions list or a politically-exposed-persons designation, sourced from the public registers listed in section 3.2.
  2. This is profiling of a natural person within the meaning of Art. 4(4) GDPR. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller and of Users in supporting anti-money-laundering, sanctions and counterparty-risk compliance processes) and, where applicable, Art. 6(1)(e) GDPR (public-interest transparency of commerce, for data that is itself sourced from a public register). These indicators are not based on special categories of data (Art. 9 GDPR): a PEP designation reflects a public office or function, not a political opinion, and is not treated by the Controller as Art. 9 data.

  3. These indicators are shown only to Users holding an authenticated, paid-plan Account, exclusively as part of the Platform's due-diligence and compliance tooling — never on public, search-engine-indexed pages.

  4. The Controller does not take decisions concerning natural persons based solely on automated processing (including this profiling) which produce legal effects or similarly significantly affect them (Art. 22(1) GDPR). A Person Risk Indicator is displayed to a User as one input among others; the User's own human decision-maker determines what, if anything, to do with it. The Terms of Service prohibit Users from using a Person Risk Indicator as the sole or decisive basis for a decision about credit, employment, insurance, housing or any similar decision concerning the individual, and prohibit publishing it outside the User's own organisation (§11(n)-(o) and §12a(6) of the Terms).

  5. Because a Person Risk Indicator is an inference computed by the Controller, not a fact reproduced verbatim from a source register, we apply heightened care to its accuracy (Art. 5(1)(d) GDPR):

    • it reflects a statistical pattern only and is not, and must not be read as, a finding that the person concerned has done anything unlawful;
    • if you believe an indicator computed about you is based on inaccurate underlying register data, you may request rectification (Art. 16 GDPR); we will re-run the computation once the underlying data is corrected at the source register, or suppress the indicator in the meantime;
    • you may object at any time to this processing (Art. 21 GDPR); given the legitimate-interest basis, we will suppress the indicator unless we can demonstrate compelling overriding grounds.
  6. Given the scale of processing and the fact that it involves evaluation/scoring of natural persons, this feature falls within the categories of processing for which Art. 35 GDPR requires the controller to assess the need for a Data Protection Impact Assessment; the Controller keeps this assessment under review as the feature evolves.

  7. Persons subject to either kind of profiling described in this section have the right to obtain information on the logic applied, to object, and to request human review. Requests: help@monodat.com.

5. Artificial Intelligence Features (FIRMAIA Chat)

The Platform provides an analytical chat based on a generative AI model. We disclose exactly how it works:

  1. The model provider is Google Ireland Ltd. / Google LLC (Gemini API).

  2. What we transmit to Google: the content of your question, the history of the current conversation, a description of our database structure, and the result rows of the SQL query generated in response to your question (maximum 20 rows per query). If a query touches Person Risk Indicators (section 4.2), the indicator values themselves are treated exactly like any other database field for the purposes of this section — including the PESEL-stripping described below.

  3. What we do NOT transmit to Google:

    • PESEL numbers are stripped from the results before sending — a technical mechanism unconditionally removes every field containing a PESEL,
    • your identity — Google receives no name, e-mail address, account identifier or IP address of yours,
    • your subscription or payment data.
  4. What may reach Google: result rows may contain public register data, including names and positions of persons holding roles in companies — to the extent publicly disclosed by the source register.

  5. Your conversation history is stored on our server and linked to your account so you can return to it. You may request its deletion — see section 11.

  6. AI-generated content may contain errors and does not constitute legal, financial or investment advice (§14a of the Terms). When using the chat you interact with an AI system, not a human (Art. 50(1) AI Act).

  7. Google's terms for processing data under the Gemini API: https://ai.google.dev/gemini-api/terms

6. Maps and Third-Party Content

Location maps on the Platform use OpenStreetMap base-map tiles, which your browser fetches directly from the servers of the OpenStreetMap Foundation (United Kingdom). The map loads automatically when you open:

  • a public company profile or a public CEIDG entrepreneur profile (pages available without logging in),
  • a company profile or a CEIDG entrepreneur profile in the dashboard, after logging in.

When the tiles are fetched, the OpenStreetMap Foundation receives your IP address and the standard information your browser attaches to every request (including the browser identifier — user-agent — and the Platform's domain), as well as which map area is being displayed. The OpenStreetMap Foundation processes this data under its own privacy policy.

The address of the entity viewed is not transmitted to the OpenStreetMap Foundation or to any external geocoding service. The coordinates of the map point are computed by the Controller on its own servers: for CEIDG entrepreneurs this is the centre of the postal-code area (or of the commune or county — section 3.3), and for companies — in the same way — the centre of the postal-code area of the registered office (or of the commune or county), derived from the GeoNames database stored on the Controller's servers. The map does not show the exact address.

If you do not want your IP address to reach the OpenStreetMap Foundation, you can block content from the openstreetmap.org domains in your browser (for example with a content-blocking extension) — the rest of the profile will display without the map. The complete list of third-party connections is in the Cookie Policy.

7. Purposes and Legal Bases of Processing

PurposeGDPR legal basis
Providing the Services under the AgreementArt. 6(1)(b)
Payment handling and invoicingArt. 6(1)(b)(c)
Communication with the UserArt. 6(1)(b)
Handling complaintsArt. 6(1)(b)(c)
Marketing of the Controller's own services (to Users)Art. 6(1)(f)
Presentation of public register dataArt. 6(1)(e)(f)
Person Risk Indicators (section 4.2)Art. 6(1)(f), and Art. 6(1)(e) where the underlying data is itself sourced from a public register
Legal obligations (tax, accounting)Art. 6(1)(c)
Pursuing/defending claimsArt. 6(1)(f)
Security, abuse and bot detection, AUP enforcementArt. 6(1)(f)
Sanctions compliance verificationArt. 6(1)(c)(f)

8. Data Recipients

The list below is complete and reflects the factual state as at the last update date:

RecipientRoleData receivedLocation
Google Ireland Ltd. / Google LLC (Firebase Authentication)Authentication and sign-in managementE-mail address, name, profile picture, password (Google never passes it to us)EEA / USA
Google Ireland Ltd. / Google LLC (Gemini API)AI model for the analytical chatOnly the data specified in section 5 — without your identity and without PESEL numbersEEA / USA
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment and subscription handlingE-mail address, billing address, tax ID, amounts. Card data never reaches the Controller — payment occurs on Stripe's domainEEA / USA
Brevo (Sendinblue SAS)Sending e-mail notifications and digestsRecipient's e-mail address, notification contentFrance (EEA)
Cloudflare, Inc. / Cloudflare Ireland Ltd. (Turnstile)Anti-bot / anti-abuse verification, shown only when your session is flagged as potentially automatedIP address, browser/device signals used to compute a bot-likelihood scoreEEA / USA — appropriate safeguards under Art. 46 GDPR; details available on request
OpenStreetMap FoundationBase map for the location maps of companies and CEIDG entrepreneursIP address and standard browser request headers (including user-agent) when a profile containing a map is opened — on public pages and in the dashboard (section 6). Without the address of the entity viewedUnited Kingdom
Server infrastructure provider (VPS)Hosting of the Platform and databaseAll data stored on the PlatformDetails available on request
Public authoritiesOnly where required by lawScope determined by the requestPoland

The Controller concludes data processing agreements (Art. 28 GDPR) with its processors and verifies that they ensure an adequate level of data protection.

What we do not do — binding statements:

  • The Controller does not sell personal data and does not share it with data brokers.
  • The Platform uses no analytics or tracking tools for measuring or profiling visitor behaviour — there is no Google Analytics, Meta Pixel, Hotjar or equivalent. The only exception is the narrow, security-purpose Cloudflare Turnstile check described above, which does not track you across visits or sites and is not used for measurement, marketing or profiling of your behaviour.
  • We do not share data with advertising networks.
  • We do not use your data or the content of your conversations to train our own AI models.

We will give notice of any change to the above list of recipients under section 16.

9. Transfers Outside the EEA

Most of our providers process data within the EEA. Brevo (Sendinblue SAS) is a French entity and e-mail data does not leave the EEA.

Google LLC, Stripe, Inc. and Cloudflare, Inc. may process data in the USA. In such cases the transfer is based on:

  • the European Commission's implementing decision of 10 July 2023 on the adequate level of protection (EU–US Data Privacy Framework), where the recipient is DPF-certified,
  • supplementarily: Standard Contractual Clauses (SCC) approved by the European Commission,
  • and other mechanisms compliant with Art. 46 GDPR.

Details available on request: help@monodat.com.

10. Retention Periods

CategoryRetention period
Active Account dataTerm of the Agreement + 3 years (limitation of claims)
Billing data and VAT invoices5 years from the end of the tax year
Activity logs, history of profiles viewed, access logs12 months
Anti-bot / security signals (Cloudflare Turnstile)30 days
AI chat conversation historyUntil deleted by the User, maximum 12 months from the last activity in the conversation
API call history12 months
Correspondence data (e-mail, complaints)3 years from closure of the matter
Data after Account deletionUp to 90 days (backups), then permanent deletion
Third-party data from public registersSynchronised with source registers; deleted when removed from the sources or upon a successful objection
CEIDG entrepreneurs' data (section 3.3)Synchronised daily with the CEIDG report; an entry deregistered or absent from the report is marked inactive; suppressed immediately upon a successful objection and not restored in subsequent synchronisations
Debt sale offers from dlugi.info (section 3.3)Until the offer is withdrawn at source (checked at least weekly), a successful objection or a report of a wrong match
Person Risk Indicators (section 4.2)Recomputed on each source-data refresh; suppressed immediately upon a successful objection or rectification request
Terms acceptance data (audit log)Term of the Agreement + 6 years (proof of contract)
Cookie notice acknowledgement12 months

11. Data Subjects' Rights

Every person has the rights arising from the GDPR:

Right of access (Art. 15) – information about the data processed and a copy of it.

Right to rectification (Art. 16) – correction or completion of data. Data originating from public registers is rectified in line with the state of the source register — if the error exists in the register itself, it must be rectified at source, and we will help by identifying the competent authority. Where the inaccuracy is in a Person Risk Indicator computed by us (section 4.2), see the dedicated procedure there.

Right to erasure (Art. 17) – the "right to be forgotten". May be restricted where processing arises from the public interest or a legal obligation.

Right to restriction of processing (Art. 18).

Right to data portability (Art. 20) – in a structured, machine-readable format.

Right to object (Art. 21) – to processing based on legitimate interest, including profiling. This right applies with particular force to Person Risk Indicators (section 4.2).

Right to withdraw consent – at any time, without affecting the lawfulness of processing before withdrawal.

Right not to be subject to an automated decision (Art. 22) – see section 4.

How to exercise your rights:

  • Requests: help@monodat.com
  • Response time: 30 days from receipt of the request
  • For complex or numerous requests: the period may be extended by 60 days with prior notice
  • Exercising your rights is free of charge. We may charge a fee only for manifestly unfounded or excessive requests (Art. 12(5) GDPR), and will inform you in advance
  • The Controller may verify the requester's identity before responding — only to the extent necessary and without demanding excessive documentation

Right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office (UODO) ul. Stawki 2, 00-193 Warsaw, Poland www.uodo.gov.pl | kancelaria@uodo.gov.pl Helpline: +48 606-950-000

12. Data Security

The Controller applies appropriate technical and organisational measures:

  • Transmission encryption (HTTPS/TLS),
  • Authentication delegated to a specialist provider (Google Firebase Authentication) — the Controller stores no passwords,
  • Automated anti-bot / anti-abuse verification (Cloudflare Turnstile), triggered only for sessions flagged as potentially automated — see section 8,
  • Role-based access control and permission management,
  • Environment separation and restricted access to the production database,
  • Regular backups,
  • Infrastructure security monitoring,
  • Incident response procedures,
  • Pseudonymisation and masking of data where possible (including unconditional masking of PESEL numbers in the interface and their removal before transmission to AI models),
  • Data minimisation principle applied to third-party integrations,
  • Regular review and update of safeguards.

We also recommend that you: use a unique, strong password and enable two-step verification on your Google account if you sign in with Google.

In the event of a personal data breach resulting in a high risk to the rights or freedoms of natural persons:

  • The Controller will report the breach to the President of UODO within 72 hours (Art. 33 GDPR),
  • and notify the data subjects without undue delay (Art. 34 GDPR).

13. Reporting Security Vulnerabilities (Responsible Disclosure)

If you discover a security vulnerability on the MONODAT Platform, please report it to help@monodat.com with the subject "Security – Vulnerability Disclosure".

We ask you to:

  • not disclose the vulnerability publicly before it is fixed,
  • not exploit the vulnerability to gain unauthorised access to data,
  • not download, modify or delete other people's data,
  • provide technical details enabling reproduction of the issue.

The Controller undertakes to acknowledge receipt of the report within 5 business days, to keep you informed of progress, and not to take legal action against reporters acting in good faith and observing the above rules (safe harbour). At the reporter's request we will credit them as the discoverer once the vulnerability is fixed.

14. Cookies

A detailed and complete list of data stored on your device, and of the narrow security exception described in section 8, is set out in the Cookie Policy.

15. Children

The MONODAT Platform is intended exclusively for adults (18 years and over) acting on behalf of professional entities. The Controller does not knowingly collect children's personal data. If you become aware that a child has provided us with data, contact us at help@monodat.com – we will delete it.

16. Changes to this Privacy Policy

The Controller gives Users at least 14 days' notice of material changes by e-mail. The current version is always available at https://monodat.com/en/privacy. Earlier versions are archived and available on request.

A material change includes in particular: the addition of a new data recipient, the introduction of analytics or tracking technology, a new category of Person Risk Indicator, a change of processing purpose, and an extension of a retention period.

17. Contact

MatterAddress
Privacy, GDPR, exercise of rightshelp@monodat.com
Security reportshelp@monodat.com (subject: "Security – Vulnerability Disclosure")
Complaintshelp@monodat.com (subject: "MONODAT Complaint")
DSA reports (illegal content)help@monodat.com (subject: "DSA – Illegal Content Report")
General mattersinfo@monodat.com

18. Language

This is a translation. In the event of any discrepancy, the binding version is the Polish-language version available at https://monodat.com/privacy.

Last updated: 2026-10-02