PRIVACY POLICY
Last updated: 24.07.2026
This Privacy Policy («Policy») describes how KASSIR OBMEN / Kassir.pl («Company», «we») collects, uses, stores and protects the personal data of visitors to kassir.pl and clients of our office in Warsaw, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Polish law.
- Data Controller
The data controller is kassir.pl. Contact for data protection matters: phone +48 500 503 161.
- What Data We Collect
— Data submitted through the exchange request form: name, phone number, preferred contact method (phone, WhatsApp, Telegram), and any comments left with the request.
— Data provided for in-person exchanges at our office: identification document, where required under anti-money laundering (AML) and counter-terrorist financing legislation.
— Technical data: IP address, device and browser type, site usage data — collected via cookies and Google Tag Manager.
— Data shared through messaging platforms (WhatsApp, Telegram, Instagram) when you contact us via the channels listed on the site.
- Purposes and Legal Basis for Processing
— Contract performance (Art. 6(1)(b) GDPR) — arranging and completing digital asset exchange transactions, communicating with clients.
— Legal obligation (Art. 6(1)(c) GDPR) — client identification under AML/KYC requirements.
— Legitimate interest (Art. 6(1)(f) GDPR) — transaction security, fraud prevention, basic site analytics.
— Consent (Art. 6(1)(a) GDPR) — marketing communications and marketing cookies (cookie consent banner on the site).
- Cookies
The site uses cookies for analytics and marketing purposes via Google Tag Manager. On your first visit, you can accept («Agree») or reject («Decline») non-essential cookies through the banner displayed on the site. Strictly necessary cookies are used without separate consent, as the site cannot function properly without them.
- Disclosure to Third Parties
We may share data with: analytics providers (Google), messaging platforms (Meta/WhatsApp, Telegram) when you contact us through those channels, and public authorities where legally required under AML legislation. The Company does not sell personal data to third parties.
- International Data Transfers
Some service providers we use (e.g. Google) may process data outside the European Economic Area. In such cases, appropriate GDPR safeguards apply (e.g. Standard Contractual Clauses).
- Data Retention
Data is retained only as long as necessary for the purposes described above: transaction data is retained for the period required under AML legislation (typically 5 years from the date the transaction is completed); request data not resulting in a completed transaction is retained for [period]; analytics data is retained according to the settings of the tools used.
- Your Rights
Under the GDPR, you have the right to: access your data; rectify inaccurate data; request erasure («right to be forgotten»); restrict processing; data portability; object to processing; withdraw consent at any time; and lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office of Poland (UODO), uodo.gov.pl.
- Data Security
We apply appropriate technical and organizational measures (encryption, access controls) to protect your data against unauthorized access, loss or disclosure.
- Children’s Data
Our site and services are not intended for individuals under 18 years of age. We do not knowingly collect data from minors.
- Changes to This Policy
We may update this Policy from time to time. The current version is always available at kassir.pl/en/privacy-policy.
- Contact Us
For any questions regarding the processing of your personal data: [email], phone +48 500 503 161, Telegram: @KassirPL.
US Dollar
Tether USDT