+48 12 352 12 12 Kraków | Warszawa | Wrocław | Katowice | Gdańsk Pon. - Pt. 9:00 - 20:00

PRIVACY POLICY (General Data Protection Regulation GDPR)



  1. The administrator of the personal data collected through the website www.harveofinance.com is Harveo Group Sp. z o.o. , registered office address: Wadowicka 7, 30-347 Kraków, delivery address: j/w , NIP: 6793239689, REGON: 522093204, KRS: 0000973332, e-mail address: rodo@harveo.com, hereinafter referred to as the “Administrator”, being at the same time the Service Provider. Place of business: Wadowicka 7, 30-363 Kraków, address for delivery: Wadowicka 7, 30-347 Kraków, NIP: 6793239689, REGON: 522093204, KRS: 0000973332, electronic mail address (e-mail): rodo@harveo.com, hereinafter referred to as “Administrator”.
  2. Personal data collected by the Administrator through the website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as RODO, and the Law on Personal Data Protection of May 10, 2018.
  3. The Operator is the Administrator of your personal data with respect to the data you voluntarily provide on the Website.
  4. The service uses personal data for the following purposes: 
    • Handling inquiries through the form
    • The service performs functions of obtaining information about users and their behavior in the following ways:
    • Through voluntarily entered data in the forms, which are entered into the
    • Operator’s systems. By storing cookies (so-called “cookies”) in the end devices.



PURPOSE OF PROCESSING AND LEGAL BASIS. The Administrator processes personal data via www.harveofinance.com for:

  1. Running a comment system
  2. Handling inquiries via form

TYPE OF PERSONAL DATA PROCESSED. The Administrator processes the following categories of your personal data:

    • Name
    • Email Address
    • Phone


Users’ personal data are stored by the Administrator:

  1.  where the basis of data processing is the performance of a contract, for as long as it is necessary for the performance of the contract, and thereafter for a period corresponding to the period of limitation of claims. Unless a special provision provides otherwise, the statute of limitations is six years, and for claims for periodic benefits and claims related to the conduct of business – three years.
  2. where the basis for data processing is consent, for as long as the consent is not revoked, and after revocation of consent for a period of time corresponding to the statute of limitations for claims that the Administrator may raise and that may be raised against him. Unless a specific provision provides otherwise, the statute of limitations is six years, and for claims for periodic benefits and claims related to the conduct of business – three years.
  3. When you use the website, additional information may be collected, in particular: the IP address assigned to your computer or your ISP’s external IP address, domain name, browser type, access time, operating system type.
  4. Navigation data may also be collected from users, including information about the links and references they choose to click on or other actions taken on the website. The legal basis for such activities is the Administrator’s legitimate interest (Article 6(1)(f) RODO) in facilitating the use of electronically provided services and improving the functionality of such services.
  5. The provision of personal data by the user is voluntary.
  6. Personal data will also be processed in an automated manner in the form of profiling, provided that the user consents pursuant to Article 6(1)(a) of the DPA. The consequence of profiling will be the assignment of a profile to a person for the purpose of making decisions concerning him or her or analyzing or predicting his or her preferences, behaviors and attitudes.
  7. The controller shall take special care to protect the interests of data subjects, and in particular shall ensure that the data it collects are:
    •  processed in accordance with the law,
    •  collected for designated legitimate purposes and not subjected to further processing incompatible with those purposes,
    •  substantively correct and adequate in relation to the purposes for which they are processed, and stored in a form that allows identification of the persons to whom they relate for no longer than necessary to achieve the purpose of processing.


When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.


  1. The website collects information provided voluntarily by the user, including personal data, if provided.
  2. The website may save information about connection parameters (time stamp, IP address).
  3. In some cases, the website may save information that makes it easier to link the data in the form with the e-mail address of the user completing the form. In this case, the user’s e-mail address appears inside the URL of the page containing the form.
  4. The data provided in the form is processed for the purpose resulting from the function of a specific form, e.g. to process a service request or a commercial contact, register services, etc. Each time, the context and description of the form clearly inform what it is used for.


  1. The Administrator’s website uses “cookies”.
  2. Installation of “cookies” is necessary for the proper provision of services on the website. The “cookies” contain information necessary for the proper functioning of the website, and they also provide the opportunity to develop general statistics of website visits.
  3. The site uses types of “cookies”: session cookies:
    • “Session” cookies are temporary files that are stored on the user’s terminal device until the user logs out (leaves the site).
    • The administrator uses its own cookies to better understand how a user interacts with the website’s content. The files collect information about the user’s use of the website, the type of website from which the user was redirected, and the number of visits and the time of the user’s visit to the website. This information does not record specific personal information about the user, but is used to compile statistics on the use of the site.
    • You have the right to decide on the access of “cookies” to your computer by selecting them in advance in your browser window.  Detailed information about the possibility and methods of handling “cookies” is available in the settings of your software (web browser).



Articles on this site may contain embedded content (e.g. videos, images, articles, etc.). Embedded content from other sites behaves analogously to if you visited a specific site directly.

Sites may collect information about you, use cookies, attach additional third-party tracking systems and monitor your interactions with embedded material, including tracking your interactions with embedded material if you have an account and are logged into that site.


  1. The service is hosted (technically maintained) on the operator’s servers: Kylos.pl
  2. Registration details of the hosting company: Kylos sp. z o.o. with its registered seat at 18 Wróblewskiego Street, 93-578 Łódź, registered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Łódź Śródmieście in Łódź, XX Economic Department of the National Court Register under the KRS number 0000496957 , with NIP number 947-196-00-52, share capital of PLN 60,000 (hereinafter “Kylos” or “Administrator”).
  3. At https://www.kylos.pl/polityka-prywatnosci/ you can learn more about hosting and check the privacy policy of the hosting company. Data protection is carried out in accordance with the requirements of generally applicable laws, and data storage takes place on secured servers.
  4. Web hosting company:
    •   applies measures to protect against data loss (e.g., disk arrays, regular backups),
    • applies adequate measures to protect processing sites in case of fire (e.g., special firefighting systems),
    • applies adequate measures to protect processing systems in case of sudden power failure (e.g., dual power paths, generators, UPS voltage backup systems),
    • applies measures to physically protect access to data processing sites (e.g., access control, monitoring),
    • applies measures to ensure appropriate environmental conditions for servers as elements of the data processing system (e.g. control of environmental conditions, specialized air conditioning systems),
    • applies organizational solutions to ensure the highest possible degree of protection and confidentiality (training, internal regulations, password policies, etc.),
    • has appointed a Data Protection Inspector.

The hosting company, in order to ensure technical reliability, keeps logs at the server level. The record may include:

    • resources specified by the URL identifier (addresses of the requested resources – pages, files),
    • time of arrival of the request,
    • time of sending the response,
    • the name of the client station – identification carried out by the HTTP protocol,
    • information about errors that occurred during the execution of HTTP transactions,
    • URL address of the page previously visited by the user (referer link) – in case the passage to the Site occurred through a link,
    • information about the user’s browser,
    • information about the IP address,
    • diagnostic information related to the process of self-ordering of services through registrars on the site,
    • information related to the handling of e-mails addressed to the Operator and sent by the Operator.



The operator uses statistical analysis of website traffic, through Google Analytics (Google Inc., based in the USA). The operator does not transmit personal data to the operator of this service, only anonymized information. The service is based on the use of cookies on the user’s terminal device. Regarding the information about user preferences collected by the Google advertising network, the user can view and edit the information resulting from cookies using the following tool: https://www.google.com/ads/preferences/


If you leave a comment, its content and metadata will be stored indefinitely. This allows us to recognize and approve subsequent comments automatically, without sending them for moderation each time.

For users who have registered on our website (if any), we also store the personal information entered in the profile. Any user can review, correct or delete his or her personal information at any time (except for the username, which cannot be changed). Site administrators can also view and modify this information.


    • The data subject has the right to access the content of his/her personal data and the right to rectification, erasure, restriction of processing, the right to data portability, the right to object, the right to withdraw consent at any time without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal.
    • Legal basis for the user’s request:
    •  Access to data – article 15 RODO
    • Correction of data – Article 16 RODO.
    • Deletion of data (so-called right to be forgotten) – Article 17 RODO.
    • Restriction of processing – Article 18 RODO.
    • Data portability – Article 20 RODO.
    • Objection – article 21 RODO.
    • Withdrawal of consent – Article 7(3) RODO.
    • In order to exercise the rights referred to in paragraph 2, you can send a relevant email to: rodo@harveo.com
    • In a situation where a user makes a request for an entitlement under the above rights, the Administrator shall either comply with the request or refuse to comply with the request immediately, but no later than one month after receiving it. However, if – due to the complicated nature of the request or the number of requests – the Administrator will not be able to fulfill the request within one month, it will fulfill it within another two months informing the user in advance – within one month of receiving the request – of the intended extension of the deadline and the reasons for it.
    • If it is determined that the processing of personal data violates the provisions of the RODO, the data subject has the right to file a complaint with the President of the Office for Personal Data Protection.


  1. Users’ personal data are transferred to the service providers used by the Administrator in running the website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, are either subject to the Administrator’s instructions as to the purposes and means of processing such data (processors) or determine the purposes and means of processing themselves (controllers).
  2. Your personal data is stored only in the European Economic Area (EEA).


  1. The Administrator shall apply technical and organizational measures to ensure the protection of the processed personal data appropriate to the risks and categories of protected data, and in particular shall protect the data from being disclosed to unauthorized persons, from being taken by an unauthorized person, from being processed in violation of applicable regulations, and from being altered, lost, damaged or destroyed.
  2. The Administrator shall provide appropriate technical measures to prevent unauthorized persons from obtaining and modifying, personal data sent electronically.
  3. In matters not regulated by this Privacy Policy, the provisions of RODO and other relevant provisions of Polish law shall apply accordingly.