Privacy Policy
Last updated: 4 April 2026
1. Data controller
The controller of personal data is LuKas Holdings sp. z o.o., ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland. KRS 0001233010, NIP 7011306806, REGON 54439709700000. Contact: kontakt@kreddo.pl.
2. Data we collect
- HTTP request metadata (server-side, no cookies): page URL, referring page, browser and device type (User-Agent), country derived from IP address (CF-IPCountry header — the IP address itself is not stored), campaign parameters (UTM).
- Analytics data (only with your consent): anonymous visitor identifier, session identifier, interaction events (offer clicks, calculator usage, scrolling).
- Voluntarily provided data: email address or other contact details you send us.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing financial offer comparison services | Art. 6(1)(b) GDPR (performance of a service) |
| Server-side traffic analysis (no cookies) | Art. 6(1)(f) GDPR (legitimate interest — site optimisation) |
| Tracking partner offer clicks (/go/ redirects) | Art. 6(1)(f) GDPR (legitimate interest — partner reconciliation) |
| Cookie-based analytics (Google Analytics 4) | Art. 6(1)(a) GDPR (consent) |
| Marketing and advertising | Art. 6(1)(a) GDPR (consent) |
| Legal obligations | Art. 6(1)(c) GDPR |
4. Data recipients
- Google Ireland Limited — analytics data processing via Google Analytics 4. Data transfers to the US under the EU-US Data Privacy Framework.
- Cloudflare, Inc. — site hosting on Cloudflare Workers infrastructure.
- System Partnerski (produktyfinansowe.pl) — redirects to financial partner offers.
5. Data retention
- Server-side analytics: processed in real time, not separately stored by the controller.
- Consent cookie (_kd_consent): 1 year.
- Analytics cookie (_kd_cid): up to 2 years from last visit.
- Data in Google Analytics: per GA4 retention settings (14 or 26 months).
- Contact data: until the enquiry is fulfilled or consent is withdrawn.
6. Your rights
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16)
- Right to erasure — "right to be forgotten" (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object to processing based on legitimate interest (Art. 21)
- Right to withdraw consent at any time (Art. 7(3)) — withdrawal does not affect the lawfulness of processing prior to withdrawal
To exercise your rights, contact us: kontakt@kreddo.pl.
7. Supervisory authority
You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
8. Automated decision-making
The Service does not employ automated decision-making, including profiling, as referred to in Art. 22(1) and (4) GDPR.