GDPR Information Notice
Last updated: 4 April 2026
In accordance with Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), we inform you as follows:
1. Data controller
LuKas Holdings sp. z o.o., ul. Stefana Batorego 18/108, 02-591 Warsaw, Poland. KRS 0001233010, NIP 7011306806, REGON 54439709700000. Contact: kontakt@kreddo.pl.
2. Purposes and legal bases of processing
- Financial offer comparison — Art. 6(1)(b) GDPR (performance of a service)
- Server-side traffic analysis (without cookies: page URL, referer, User-Agent, country, UTM parameters) — Art. 6(1)(f) GDPR (legitimate interest in site optimisation)
- Recording partner offer clicks (/go/ redirects) — Art. 6(1)(f) GDPR (partner reconciliation)
- Cookie-based analytics (Google Analytics 4) — Art. 6(1)(a) GDPR (consent via cookie banner)
- Marketing purposes — Art. 6(1)(a) GDPR (consent)
- Legal obligations — Art. 6(1)(c) GDPR
3. Data recipients
Data may be shared with: Google Ireland Limited (analytics), Cloudflare, Inc. (hosting), System Partnerski / produktyfinansowe.pl (partner offer redirects).
4. International data transfers
Data processed by Google may be transferred to the US under the adequacy decision — EU-US Data Privacy Framework (Art. 45 GDPR). Cloudflare processes data on EU/EEA servers, with possible US transfers on the same basis.
5. Data retention
- Server-side analytics: processed in real time, forwarded to GA4, not separately stored by the controller.
- Analytics cookies: up to 2 years (visitor ID), 30 minutes (session).
- Data in Google Analytics: 14 or 26 months (per GA4 configuration).
- Contact data: until the purpose is fulfilled or consent is withdrawn.
6. Your rights
- Access to data (Art. 15)
- Rectification (Art. 16)
- Erasure — "right to be forgotten" (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interest (Art. 21) — applies to server-side traffic analysis
- Withdrawal of consent at any time (Art. 7(3)) — via the cookie consent mechanism in the page footer or by email
7. Supervisory authority
You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
8. Automated decision-making
The controller does not employ automated decision-making, including profiling, as referred to in Art. 22(1) and (4) GDPR.
9. Voluntary provision of data
Using the Service does not require providing personal data. Granting consent for analytics and marketing cookies is voluntary and does not affect your ability to use the Service.