Last updated: April 2026
1. Data Controller
The controller of your personal data is:
Andriy Myronyak, conducting business under the name Andriy Myronyak, with its registered office at:
Karmelicka 30
31-128 Kraków, Poland
Tax ID (NIP): 9452269604
E-mail: karat772@gmail.com
Phone: +48 571 940 885
(hereinafter referred to as the “Controller”).
The Controller has not appointed a Data Protection Officer (DPO).
For any questions regarding the processing of personal data, please contact the Controller directly.
2. Categories of Personal Data Processed
The Controller may process the following categories of personal data:
a) Contact form / Exchange rate reservation
- full name;
- telephone number;
- e-mail address.
b) Data related to the services provided by the Controller
- data relating to currency exchange services provided at the physical exchange office;
- data relating to the purchase and sale of gold (including scrap gold, coins, and gold bars);
- data relating to the purchase and sale of luxury watches and diamonds;
- data relating to the exchange of old, withdrawn, or damaged banknotes.
c) Data required by law (AML)
Identification data (such as an identity document) processed where required by applicable law, in particular for transactions exceeding statutory thresholds or in situations requiring customer identification under anti-money laundering and counter-terrorist financing regulations.
d) Marketing
- e-mail address.
e) Technical data
- IP address;
- browser information.
3. Purposes of Data Processing
Personal data is processed for the following purposes:
- providing the services offered by the Controller;
- processing exchange rate reservations;
- responding to customer inquiries;
- complying with legal obligations (including AML, accounting, and tax regulations);
- analysing website traffic and ensuring website security;
- ensuring the security of transactions carried out at the exchange office;
- conducting marketing and advertising activities.
4. Legal Basis for Processing
Personal data is processed on the following legal grounds:
- Article 6(1)(b) GDPR – performance of a contract or taking steps prior to entering into a contract;
- Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject;
- Article 6(1)(f) GDPR – the legitimate interests of the Controller;
- Article 6(1)(a) GDPR – the data subject’s consent (marketing purposes).
5. Voluntary Provision of Data
Providing personal data is voluntary. However, it may be necessary to provide certain data in order for the Controller to deliver the requested services or respond to your inquiry.
6. Sources of Personal Data
The Controller collects personal data exclusively from the individuals to whom the data relates, including when they:
- use the services offered by the Controller;
- submit an inquiry through the contact form;
- browse and use the Website.
7. Data Recipients
In connection with providing the services, the Controller may disclose personal data to entities processing personal data on behalf of the Controller, including:
- IT service providers and website hosting providers;
- postal and e-mail service providers;
- the accounting office providing accounting services to the Controller;
- advertising service providers, including Google Ads.
These entities process personal data solely on the basis of agreements concluded with the Controller and only in accordance with the Controller’s instructions.
The Controller reserves the right to disclose specific personal data to competent public authorities, including the General Inspector of Financial Information (GIIF) or other authorities authorized under applicable law to receive such information.
Personal data is not sold or shared with third parties for commercial purposes.
8. Transfers of Personal Data Outside the European Economic Area (EEA)
Personal data may be transferred to recipients located outside the European Economic Area (EEA), including recipients established in the United States, in particular Google LLC, which participates in the EU–US Data Privacy Framework recognized by the European Commission as providing an adequate level of personal data protection (European Commission Adequacy Decision of 10 July 2023).
Where personal data is transferred to countries not covered by an adequacy decision of the European Commission, the Controller applies appropriate safeguards, including Standard Contractual Clauses (SCCs) or other legally accepted mechanisms ensuring an adequate level of data protection.
9. Data Retention Period
Personal data is retained for the following periods:
- for as long as necessary to provide the requested services and, subsequently, until the expiration of any claims arising from the contractual relationship or until the expiry of legal obligations, including tax and accounting requirements;
- for the period necessary to demonstrate compliance with legal obligations before public authorities, including the supervisory authority responsible for personal data protection;
- until the data subject withdraws consent, where processing is based on consent.
10. Your Rights
You have the right to:
- access your personal data;
- request the rectification of inaccurate personal data;
- request the erasure of your personal data;
- request the restriction of processing;
- object to the processing of personal data based on the Controller’s legitimate interests;
- receive your personal data in a structured, commonly used, and machine-readable format and transmit it to another controller (right to data portability), where processing is carried out by automated means and based on consent or a contract;
- withdraw your consent at any time where processing is based on consent.
To exercise any of your rights, please contact the Controller at:
karat772@gmail.com
11. Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority responsible for the protection of personal data.
In Poland, the supervisory authority is the:
President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO).
12. Profiling and Automated Decision-Making
Users’ personal data is not processed by automated means (including profiling) in a manner that produces legal effects concerning the user or similarly significantly affects them.
13. Data Security
The Controller implements appropriate technical and organizational measures to ensure the security of personal data, including:
- restricting access to personal data;
- protecting IT systems;
- using SSL (Secure Socket Layer) encryption.
The Controller exercises due care to ensure that personal data is adequately protected against unauthorized access, disclosure, alteration, or destruction.
14. Cookies
The Website uses cookies and similar technologies that enable the collection and processing of information about how users interact with the Website.
In general, cookies and similar technologies are not intended to directly identify users. However, in certain circumstances, especially when combined with other information, they may be considered personal data under the GDPR.
Using cookies, the Website may collect the following information about the user’s device and browsing activity:
- date and time of the visit;
- device IP address;
- browser type;
- approximate location data.
You may manage cookie settings at any time through your web browser, including accepting, rejecting, or deleting cookies. Please note that disabling certain cookies may affect the functionality of the Website.
If you continue to use the Website without changing your browser settings to disable cookies, you consent to the use of cookies as described in this Privacy Policy.
Types of Cookies Used
Session Cookies
Session cookies are stored on your device only for the duration of your browsing session. They are automatically deleted once the browser is closed.
Persistent Cookies
Persistent cookies remain on your device for the period specified in the cookie settings or until you manually delete them.
Categories of Cookies
Essential Cookies
These cookies are necessary for the proper functioning of the Website and enable core features such as displaying content correctly.
Functional Cookies
These cookies remember your selected settings and preferences, such as language or display preferences, allowing the Website to provide a more personalized experience.
Analytics Cookies
These cookies collect information about how visitors use the Website, including the number of visits, traffic sources, and navigation behavior. This information helps improve the Website’s performance and content.
Marketing Cookies
These cookies are used to display advertising that is more relevant to your interests and preferences.
Purposes of Cookie Processing
Information collected through cookies may be processed for the following purposes:
- configuring the Website and adapting it to user preferences;
- recognizing the user’s device and displaying the appropriate language or regional version of the Website;
- ensuring the proper operation and security of the Website;
- remembering browsing history to improve the user experience;
- creating anonymous statistics that help us understand how visitors use the Website (including Google Analytics);
- displaying personalized advertising based on user interests.
Legal Basis for Cookie Processing
The legal basis for processing personal data through:
a–c is the Controller’s legitimate interest under Article 6(1)(f) GDPR, consisting of ensuring the proper operation, security, improvement, and development of the Website and providing relevant content.
You may object to such processing by adjusting your browser settings or disabling cookies.
The legal basis for processing personal data through:
d–f is your consent under Article 6(1)(a) GDPR, expressed through your cookie preferences.
You may withdraw your consent at any time by changing your cookie settings.
Third-Party Cookies
Third parties whose cookies are placed on the Website may have access to information collected through those cookies. In such cases, those third parties may act as independent data controllers.
Profiling
Information collected through cookies may be processed automatically, including through profiling.
Profiling is used solely to analyze user activity on the Website in order to better understand preferences and improve the relevance of content and advertising. It does not produce any legal effects or similarly significant consequences for users.
Identification of Users
Based solely on information collected through cookies, the Controller is generally unable to identify individual users.
Therefore, pursuant to Article 11(2) GDPR, the rights provided for in Articles 15–20 GDPR may not apply unless the user provides additional information enabling identification or simultaneously uses services provided electronically by the Controller (for example, by submitting a reservation form).
15. External Services
The Website contains links to external services, including:
- Telegram
Using these services may involve the transfer of personal data to their respective operators, who act as independent data controllers.
The Controller has no control over how these third parties process personal data. We encourage users to review the privacy policies of these external services before using them.
16. Changes to this Privacy Policy
This Privacy Policy is reviewed on a regular basis and may be updated whenever necessary to reflect changes in applicable laws, the services provided, or the way personal data is processed.
The current version of the Privacy Policy is always available on this Website. Any changes become effective upon publication of the updated version.