Document

Privacy Policy

In force from 1 September 2026 · version 3

This is an English translation provided for convenience. The Polish version is legally binding. In case of any discrepancy, the Polish version prevails. Read the Polish version.

Contents · 10 sections
In short
  • We keep your data in Europe and never sell it to anyone.
  • We collect only what the service needs to work and what we need to issue an invoice.
  • On the website we use the cookies it needs to work. We switch on analytics cookies only with your consent.
  • By joining the list, you agree to receive messages about BusiKM. You can withdraw consent using the link in any of them — we record its wording and date so that we can show what you agreed to.
  • You have the right to access, correct, erase and port your data. Write to us and we will do it.

This summary makes the document easier to read but does not replace it. The full document is binding — in its Polish version.

1Who the controller is

The controller of personal data is MOVGRANTO Sp. z o.o., with its registered office in Szczecin, ul. Władysława Łokietka 5/2, 70-254 Szczecin, Poland, tax identification number (NIP) 5993238990, National Court Register (KRS) number 0000767899.

For all matters concerning personal data, write to kontakt@busikm.pl. We have not appointed a data protection officer — we are not required to do so.

This policy covers data for which we are the controller: data of people who contact us, people who create an account and visitors to the website. Data that our clients enter into their accounts — including data of their drivers and business partners — is processed by us as a processor, under the terms described in the Data Processing Agreement document.

2Purposes and legal bases

PurposeCategories of dataLegal basisRetention period
Maintaining the account and providing the servicefirst name, surname, e-mail, company name and details, role in the accountArt. 6(1)(b) of the General Data Protection Regulation (GDPR) — performance of a contractfor the term of the agreement and 30 days after it ends
Billing and accountingcompany details, tax identification number (NIP), payment history, invoicesArt. 6(1)(c) GDPR — legal obligation5 years from the end of the year in which the tax payment deadline expired
Contact and handling of enquiriesfirst name, e-mail address, content of the messageArt. 6(1)(f) GDPR — our legitimate interest2 years from the last message in the matter
Security of the service and detection of abuseIP address, access logs, device identifierArt. 6(1)(f) GDPR — legitimate interest12 months
Establishment and defence of legal claimsdetails of the agreement and correspondenceArt. 6(1)(f) GDPR — legitimate interestuntil the limitation period for claims expires
Messages about BusiKM, including the launch of the demo and the opening of sign-upsfirst name, e-mail addressArt. 6(1)(a) GDPR — your consent, together with Art. 398 of the Electronic Communications Law (Prawo komunikacji elektronicznej, PKE)until consent is withdrawn
Demonstrating that consent was givenwording and version of the consent, channel, date and time it was tickedArt. 6(1)(c) GDPR — the accountability obligation under Art. 7(1) GDPRfor the period of processing based on consent and the limitation period for claims
Website visit statisticsanonymised IP address, traffic source, events on the websiteArt. 6(1)(a) GDPR — your consentuntil consent is withdrawn, no longer than 14 months

3Is providing data mandatory

Providing data is voluntary, but without an e-mail address and company details we cannot create an account or issue an invoice. Without this data, the service cannot be provided.

4Who we share data with

Data may be disclosed to:

  1. providers who help us deliver the service — Amazon Web Services (servers, databases, files), Amazon SES (e-mail), Stripe (payments), Mapbox (routes), Google Cloud Vision (reading receipts), Sentry (errors) and Apple and Google (delivering notifications). We keep the full list, with the scope of processing, in the Subprocessors document;
  2. providers operating the forms on the website — Google Ireland (the Firestore database in which we store the message, European region) and Resend (delivering the notification to our mailbox, Irish region). This applies only to data that you enter yourself — in the contact form or when signing up to be notified of the launch;
  3. our accounting office and advisers, to the extent necessary for billing and accounting;
  4. public authorities, where required by law.

We have a data processing agreement in place with every provider that processes data on our behalf. We do not sell data and do not share it for third parties’ marketing purposes.

5Is data transferred outside Europe

Servers, databases, files, backups, e-mail and payments operate within the European Economic Area. Messages from the contact form do too: the database is located in a European region, and notifications are sent from servers in Ireland.

Two things require entities outside the EEA: recognising text in photos of receipts, and delivering notifications to the driver’s phone, which always goes through Apple or Google. We safeguard the transfer with standard contractual clauses approved by the European Commission, and we set the recognition service to the provider’s European region. Details are set out in the Subprocessors document.

6Your rights

You have the right to:

  1. access your data and obtain a copy of it;
  2. rectify inaccurate data and complete incomplete data;
  3. erasure of your data where we have no basis for further processing;
  4. restriction of processing;
  5. port your data to another controller;
  6. object to processing based on our legitimate interest;
  7. withdraw consent at any time — without affecting the lawfulness of what we did before the withdrawal.

To exercise any of these rights, simply write to kontakt@busikm.pl. We respond within one month; if the matter is complex, we will let you know in advance that it will take longer.

If you believe that we process data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, PUODO), ul. Stawki 2, 00-193 Warsaw, Poland.

7Cookies

Cookies are small files stored in your browser. We use them for two purposes.

Strictly necessary
— they keep you signed in, remember your choice of plan and secure the forms. The service does not work without them, so we do not ask for consent. They expire at the end of the session or after 12 months.
Analytics
— they count visits and show which pages are read. We switch them on only after you consent, and you can withdraw consent at any time. They expire after 14 months.

The strictly necessary cookies also include the “jezyk” cookie. It remembers the language version of the website — Polish or English — that you choose with the EN/PL switch, so that the website opens in the same language on your next visit. We set it only when you choose a language yourself; it expires after one year. We do not ask for consent because it serves solely to provide a function you have requested (Art. 399(3) of the Electronic Communications Law).

We do not use cookies for advertising or for marketing profiling. You give consent to analytics in the window that appears on your first visit — and withdraw it using the “Cookie settings” link at the bottom of every page. Until you consent, the visit counter is not loaded at all.

8Do we make automated decisions

We do not make decisions about you based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.

9How we protect data

We apply measures appropriate to the risk, in particular:

  1. encryption of connections (TLS) and encryption of data on disk;
  2. access to production data only for those who need it, with two-factor authentication;
  3. backups made daily and tested for restorability;
  4. logging of access to data and regular review of permissions.

10Changes to this policy

We notify you of material changes by e-mail at least 30 days in advance. The date of the last change is shown at the bottom of this page.

Last updated: 3 September 2026

Other documents:Terms of ServiceData Processing AgreementSubprocessors

Have a question about this document? Write to: kontakt@busikm.pl