Privacy Policy of the MyPropFirm.pl Website
Version: 1.1
Effective date: 17.05.2026
Last updated: 17.05.2026
Summary of key information
| Question | Answer |
|---|---|
| Who is the controller of your data? | MYPROPFIRM SP. Z O.O., kontakt@mypropfirm.pl |
| What data do we collect? | Data provided during registration, technical data (IP, logs), analytical data |
| Do we process sensitive data? | No |
| Do we transfer data outside the EEA? | Yes – Google LLC (USA), protected by the EU-U.S. Data Privacy Framework |
| How long do we store data? | It depends on the purpose – details in section 5 |
| What rights do you have? | Access, rectification, erasure, restriction, portability, objection, withdrawal of consent, complaint to the Polish Data Protection Authority (UODO) |
| Where can you file a complaint? | UODO, ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl |
1. Personal data controller
The controller of your personal data within the meaning of Article 4(7) GDPR is:
MYPROPFIRM SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
with its registered office at: Podhalańska 23, Kluszkowce 34-440
NIP: 7352939866 | REGON: 544343026 | KRS: 0001230981
E-mail: kontakt@mypropfirm.pl
(Hereinafter: the “Controller” or “we”)
The Controller has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR.
2. What data do we collect and for what purposes?
2.1. Data you provide voluntarily
a) Account registration
If you decide to create an account, we process:
- email address,
- username (nickname),
- password (stored only in encrypted form),
- country of residence (optional).
Purpose: creating an account, enabling the use of features requiring login, communication regarding the account.
Legal basis: Article 6(1)(b) GDPR – performance of a contract for the provision of electronic services.
Retention period: for the duration of the active account, and after its deletion for up to 3 years for the establishment, exercise or defence of claims.
b) Login through social media accounts (Google SSO)
If you log in through a Google account or another external account, we receive a limited set of profile data from the provider of those services – usually your email address and name/username. Passwords to external accounts are not provided to us and are not stored by us.
Important: Logging in through Google SSO does not automatically subscribe you to the newsletter. If you want to receive the newsletter, you must give separate, voluntary consent through a dedicated subscription form. Combining newsletter consent with login or registration is not permitted (prohibition of bundled consent) under Article 4(11) and Article 7(2) GDPR and Article 398 PKE.
Purpose: simplified registration and login.
Legal basis: Article 6(1)(b) GDPR.
c) Email contact / contact form
We process:
- your email address,
- first name or surname (if provided),
- message content,
- any data you provide yourself in correspondence.
Purpose: responding to your question or handling your request.
Legal basis: Article 6(1)(f) GDPR – the Controller’s legitimate interest (communication with Users).
Retention period: until the matter is resolved, and then for up to 3 years due to possible claims.
d) User Contributions (reviews, comments, ratings)
If you post reviews, comments or ratings, we process:
- the content of your Contribution,
- username/nickname (publicly visible),
- date and time of posting,
- IP address (only for verification and security purposes, not made public).
Purpose: operation of the review section and ensuring the reliability and integrity of opinions in accordance with the DSA and the Omnibus Directive.
Legal basis: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (the Controller’s legitimate interest).
Retention period: for the duration of account activity and up to 3 years after account deletion, or until an effective erasure request is made.
2.2. Data collected automatically
a) Technical data and server logs
During each visit, we automatically record:
- IP address of the device (anonymised after 90 days),
- type and version of the web browser,
- operating system,
- URLs of visited subpages and the referring page (referrer),
- date, time and duration of the visit.
Purpose: security and proper operation of the Website, error diagnosis.
Legal basis: Article 6(1)(f) GDPR – the Controller’s legitimate interest.
Retention period: 90 days in identifiable form, after which the data is anonymised.
b) Cookies and tracking technologies
The Website uses cookies and similar technologies described in detail in the Cookie Policy available at mypropfirm.pl/polityka-cookies.
Legal basis for strictly necessary cookies: Article 6(1)(f) GDPR (legitimate interest) in conjunction with Article 399(3) of the Act of 12 July 2024 – Electronic Communications Law (PKE) – exemption from the consent requirement for cookies necessary to provide the service.
Legal basis for analytical, marketing and affiliate cookies: Article 6(1)(a) GDPR – consent given through the cookie banner, together with Article 399(1) PKE (requirement to obtain consent for access to terminal equipment).
Consent to non-essential cookies is voluntary and may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal (Article 7(3) GDPR, Article 362 PKE).
Tools we use that may process data through cookies:
Google Analytics 4 with Consent Mode v2:
If no consent is given, GA4 sends only anonymised, cookieless signals. If consent is given, GA4 sets cookies to analyse sessions. Data transfers to Google LLC are based on the EU-U.S. Data Privacy Framework.
c) Affiliate links and conversion tracking
Clicking an affiliate link may cause a prop firm or affiliate network to store a cookie in order to calculate a commission. The controller of the data processed through these cookies is the relevant prop firm or affiliate network, not the Website Controller. We encourage you to review the privacy policies of the respective prop firms.
2.3. Newsletter
If you have given separate, voluntary consent to receive the newsletter (through a dedicated subscription form), we process your email address in order to send information about Website updates and partner offers.
Legal basis: Article 6(1)(a) GDPR – consent, in conjunction with Article 398(1) PKE (prohibition of sending commercial information without prior consent).
You may unsubscribe from the newsletter at any time by clicking the “unsubscribe” link in each message or by writing to kontakt@mypropfirm.pl. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
3. Recipients of data
| Recipient category | Purpose of transfer | Transfer safeguard |
|---|---|---|
| Google LLC (Google Analytics) | Analytics | EU-U.S. Data Privacy Framework |
| Hosting / infrastructure provider | Maintaining the Website | Data processing agreement (Article 28 GDPR) |
| Email service providers (newsletter) | Sending messages | Data processing agreement (Article 28 GDPR) |
| Affiliate networks and prop firms | Calculating commissions from affiliate links | Privacy policies of those entities |
| Public authorities (courts, police, UODO, UKE) | Where required by law or the DSA | Legal requirement |
We do not sell your personal data to any third parties for marketing purposes.
4. Transfers of data to third countries
4.1. Data transfers to Google LLC are based on the European Commission’s decision on the EU-U.S. Data Privacy Framework (July 2023).
4.2. For other transfers outside the EEA, the Operator applies standard contractual clauses (SCCs) approved by the European Commission in accordance with Article 46(2)(c) GDPR.
4.3. You may obtain a copy of the safeguards used by writing to kontakt@mypropfirm.pl.
5. Data retention periods
| Data category | Retention period |
|---|---|
| User account data | Account activity period + 3 years after deletion |
| Server logs (full) | 90 days |
| Server logs (anonymised) | Up to 36 months |
| Analytical data (GA4) | Up to 14 months, in accordance with the data retention settings in Google Analytics |
| Email correspondence | Up to 3 years from the date of the message |
| User Contributions (reviews) | Until deletion by the User or account deletion + 3 years |
| Analytical and marketing cookies | Until consent is withdrawn or the cookie expires (max. 400 days) |
| Newsletter data | Until consent is withdrawn |
6. Your rights
To exercise the rights listed below, contact us at kontakt@mypropfirm.pl. We will respond to your request within 30 days of receipt (this period may be extended by 60 days in particularly complex cases).
| Right | Legal basis | Meaning |
|---|---|---|
| Access | Article 15 GDPR | Information about the data processed + a free copy |
| Rectification | Article 16 GDPR | Correction of inaccurate or incomplete data |
| Erasure | Article 17 GDPR | “Right to be forgotten” – subject to legal exceptions |
| Restriction of processing | Article 18 GDPR | Suspension of processing in certain cases |
| Data portability | Article 20 GDPR | Receiving data in CSV/JSON format and transmitting it to another controller |
| Objection | Article 21 GDPR | Objection to processing based on legitimate interest |
| Withdrawal of consent | Article 7(3) GDPR | Withdrawal of consent without affecting the lawfulness of earlier processing |
7. Right to lodge a complaint with a supervisory authority
If you believe that we process your data unlawfully, you have the right to lodge a complaint with:
President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw
Phone: 606 950 000
E-mail: kancelaria@uodo.gov.pl
Website: www.uodo.gov.pl
If you live in another EU/EEA country, you may lodge a complaint with the supervisory authority competent for your place of residence.
8. Data security
8.1. We use appropriate technical and organisational measures, including:
- encrypted HTTPS connection (TLS),
- access control based on the principle of least privilege,
- regular data backups.
8.2. Despite the security measures used, the Operator cannot guarantee the absolute security of data transmission over the Internet.
8.3. In the event of a personal data breach likely to result in a high risk to the rights and freedoms of the User, the Operator will inform the User without undue delay (Article 34 GDPR).
9. Data of persons under 18 years of age
The Website is not intended for persons under 18 years of age. If we become aware that we have collected data of a minor, we will delete it without undue delay. If you are aware of such a situation, please contact us at: kontakt@mypropfirm.pl.
10. Changes to this Privacy Policy
We will inform you of material changes by posting a notice on the Website at least 14 days in advance and – in the case of registered Users – by email. The date of the last update is indicated at the beginning of this document.
11. Contact
MYPROPFIRM SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Podhalańska 23, Kluszkowce 34-440
NIP: 7352939866 | REGON: 544343026 | KRS: 0001230981
E-mail: kontakt@mypropfirm.pl
We respond within 30 days from the date of receiving the inquiry.