Binding language This document is an English translation of the Polish original „Polityka prywatności”, version of 1 September 2026, provided for the convenience of non-Polish-speaking creditors. In the event of any discrepancy between this translation and the Polish text, the Polish version prevails. Read the binding Polish version →
🔒 Privacy policy

Privacy policy and information on the processing of personal data

Full controller's notice under Article 13 GDPR. What we collect, for what purpose, on what legal basis, with whom we share it and what rights you have.

Version of 1 September 2026
Contents
  1. Controller and contact
  2. Who this notice concerns
  3. What data we collect
  4. Data from ID cards, passports and KYC verification
  5. Purposes of processing, legal bases and retention periods
  6. How long we keep the data of your case
  7. Where we get your data from
  8. Recipients of the data
  9. Transfers to Estonia and outside the European Economic Area
  10. Your rights
  11. Is providing data mandatory
  12. Profiling and automated decisions
  13. Data security
  14. Cookies and similar technologies
  15. Webinars and recordings
  16. Changes to this policy

In brief

The controller of your data is Krajowe Centrum Obsługi Długów sp. z o.o. (KCOD) of Olsztyn, Poland.

We collect data in order to file your claim in the Estonian Zondacrypto bankruptcy and to conduct your case.

From your identity document we take down only the data we need. We do not keep scans or photographs of ID cards or passports.

The data goes to the trustee and the court in Estonia. Estonia is in the European Union, so the same GDPR protects it as in Poland.

We do not sell the data and do not pass it to anyone who is not needed to conduct your case.

You may at any time request access to your data, its correction or erasure — write to kontakt@zondaodzyskaj.pl.

1. Controller and contact

The controller of your personal data is Krajowe Centrum Obsługi Długów spółka z ograniczoną odpowiedzialnością, with its registered office in Olsztyn, ul. F. Nowowiejskiego 9/401, 10-162 Olsztyn, Poland, entered in the register of entrepreneurs of the National Court Register under number 0001019984, NIP 7393980771, REGON 524614251, share capital 15,000 PLN paid up in full.

Contact on personal data matters:

  1. e-mail: kontakt@zondaodzyskaj.pl or

  2. telephone: +48 89 675 0002 (Mon–Fri, 8:30–16:00)

  3. post: to the registered office address given above

We have not appointed a data protection officer. All matters are handled by the controller at the addresses given above.

2. Who this notice concerns

  1. people who have submitted their case on ZondaOdzyskaj.pl and concluded a contract with us;

  2. people who completed the form or registered for a webinar but did not conclude a contract;

  3. people representing corporate clients — members of the management board, attorneys, contact persons;

  4. people on whose behalf someone else files a claim — for example heirs or persons acting through a representative;

  5. people contacting us through the form, by e-mail or by telephone;

  6. visitors to our websites.

3. What data we collect

  1. Identification data: first name and surname, PESEL number, date of birth, citizenship, and for companies — name, NIP, KRS and the details of the persons representing them;

  2. Contact data: e-mail address, telephone number, address of residence or registered office, correspondence address;

  3. Case data: the identifier, login or e-mail address of your account on the Zonda platform, the type and quantity of assets, balances, the amount of the claim, transaction history, deposit confirmations, blocked withdrawal instructions, correspondence with Zonda and the other documents you send as evidence;

  4. Identity document data: described separately in point 4;

  5. Financial data: bank account number, invoicing details, information about the payment made received from the payment operator;

  6. Contract conclusion data: the content of the declarations made, the date and time of acceptance, the IP address, the transaction identifier — needed to show when and on what terms you concluded the contract;

  7. Technical data: IP address, session identifier, browser and device data, server logs;

  8. Image and voice: only if you take part in a webinar and switch on your camera or microphone — details in point 15.

4. Data from ID cards, passports and KYC verification

The trustee must know who is filing the claim and be able to link the filing to the account on the Zonda platform and to the KYC documentation the exchange collected when the account was opened. That is why we ask for data from your identity document.

  1. From it we collect only:
  1. the type of document (ID card or passport);

  2. the series and number of the document;

  3. the expiry date and issuing authority;

  4. given names and surname, date of birth, citizenship, PESEL number.

  1. What we do not do:
  1. We do not keep scans, photographs or copies of ID cards or passports;

  2. We do not collect the image from the document, the signature specimen or biometric data;

  3. We do not copy the document in full, so we do not gather fields that are not needed for the filing.

The basis for processing this data is Article 6(1)(b) GDPR — performance of the contract you have concluded with us — and Article 6(1)(c) GDPR to the extent that identification of the creditor is required by the trustee. We pass this data to the trustee and the court in Estonia only to the extent necessary to file and defend your claim.

5. Purposes of processing, legal bases and retention periods

Purpose Legal basis Retention period
Handling the submission on the site and preparing the contract before you conclude it Article 6(1)(b) GDPR — steps prior to entering into a contract Until the contract is concluded. If it is not concluded — 12 months from the last contact, or less if you ask for your data to be erased
Concluding the contract in documentary form and demonstrating when and on what terms it was concluded Article 6(1)(b) and (f) GDPR — demonstrating the content and moment of conclusion As set out in point 6
Preparing and filing the proof of claim and the application to exclude crypto-assets from the estate Article 6(1)(b) GDPR As set out in point 6
Identifying the creditor for the purposes of the proceeding — identity document and KYC data (point 4) Article 6(1)(b) and (c) GDPR As set out in point 6
Conducting the case: correspondence with the trustee and the court, attendance at creditors' meetings, monitoring the proceeding Article 6(1)(b) and (f) GDPR As set out in point 6
Settlements, invoices, accounting Article 6(1)(c) GDPR — the Accounting Act and tax legislation 5 full tax years, counted from the end of the year in which the document was issued
Handling correspondence, enquiries and complaints Article 6(1)(f) GDPR — responding to an enquiry Until the matter is closed, and then until the limitation period for claims expires
Marketing of our own services Article 6(1)(f) GDPR; sending to a particular electronic channel — with your consent, under the Electronic Communications Law Until you object or withdraw consent
Webinars, registration and recording Article 6(1)(a) GDPR — consent Until consent is withdrawn. Once withdrawn, we delete the recording or anonymise your participation in it
Statistics, analytics and remarketing Article 6(1)(a) GDPR — consent given in the cookie panel In line with the validity periods of the individual cookies, no longer than 24 months
Site security, access logs, prevention of abuse Article 6(1)(f) GDPR Logs up to 12 months
Establishing, pursuing or defending claims Article 6(1)(f) GDPR Until the limitation periods expire

6. How long we keep the data of your case

We keep the data of your case — including identification data, identity document data, claim data, evidence, the contract, the power of attorney and correspondence — for the duration of the bankruptcy proceeding of BB Trade Estonia OÜ, and then for 5 years from its final conclusion.

We count that period to the end of the calendar year in which the fifth year expires. This means that if the proceeding ends in, say, March 2030, we will delete the data at the end of 2035.

We do this for two reasons. First, throughout the proceeding and for the limitation period we must be able to show what we filed on your behalf and when. Second, the case file may be needed if you wish to pursue something yourself later on.

Shorter periods apply to technical logs (12 months) and to the data of people who have not concluded a contract with us (12 months). We keep webinar recordings until consent is withdrawn; the rules are set out in point 15. We keep accounting records for 5 full tax years, irrespective of the above rule, because tax legislation requires it.

Once those periods expire we delete or anonymise the data.

7. Where we get your data from

Primarily from you: from the form on the site, from the documents you send and from your correspondence with us.

If someone files on your behalf — for example a representative, a legal guardian or a person acting in a probate matter — we receive your data from that person. In such a case this policy constitutes performance of the information obligation under Article 14 GDPR, and the source of the data is the person who submitted your case. The scope of the data is as described in points 3 and 4.

We verify and supplement company data from public registers: the National Court Register (KRS), CEIDG, REGON (Statistics Poland), the Ministry of Finance's list of VAT taxpayers and the VIES system.

We may also receive information about your case from the trustee, the Estonian court and the Estonian official gazette Ametlikud Teadaanded.

8. Recipients of the data

We pass data only to those entities we need in order to conduct your case or to run the site. We do not sell data. On request we will identify the specific recipients to whom we have disclosed your data.

We may also pass data to: courts, the trustee, the prosecution service and administrative authorities, to the extent required by law or by the proceeding; and to professional supervisory bodies in the event of inspection.

Note one thing which we state openly: a proof of claim becomes part of the file of the bankruptcy proceeding. This means the data it contains may be available to the court, the trustee, the debtor and other participants in the proceeding — to the extent following from Estonian law. Beyond that scope we do not pass your data to the debtor.

In summary, the recipients of the data are the trustee in bankruptcy and the court in Estonia, our partner law firm in Estonia, hosting and database providers, e-mail and SMS providers, the payment operator, the invoicing system, translators, postal operators and couriers, the accounting office, and the controller's legal and tax advisers.

9. Transfers to Estonia and outside the European Economic Area

Estonia is a member state of the European Union. Passing your data to the trustee, the Estonian court and our partner firm in Estonia is not a transfer outside the European Economic Area and requires no additional safeguards: the same GDPR applies there as in Poland, and supervision is exercised by the Estonian counterpart of UODO, Andmekaitse Inspektsioon.

The systems in which we store your case data — the database and hosting — run on servers in the European Union. Backups also remain in the EU.

Data is transferred outside the EEA only in connection with tools for e-mail delivery, analytics, remarketing and the webinar platform. The transfer takes place on the basis of one of the mechanisms in Chapter V GDPR:

  1. an adequacy decision of the European Commission (EU–U.S. Data Privacy Framework) — where the provider is certified under it;

  2. standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR) — where the provider is not certified;

  3. additional technical and organisational safeguards set out in the processing agreements: pseudonymisation and encryption in transit and at rest.

You have the right to obtain information about the safeguards applied — write to kontakt@zondaodzyskaj.pl.

10. Your rights

You have the right to:

  1. access your data and obtain a copy of it;

  2. rectify inaccurate or incomplete data;

  3. erase your data;

  4. restrict processing;

  5. data portability;

  6. object to processing based on our legitimate interest, and to direct marketing — in every case;

  7. withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Send requests to kontakt@zondaodzyskaj.pl, RODO@kcod.pl or by post to the registered office. We reply without undue delay and no later than within one month. In particularly complex matters we may extend that period by two months, informing you within the first month. Exercising your rights is free of charge.

Some rights may be limited. This applies in particular to a request to erase data during the bankruptcy proceeding, where the proof of claim has already been filed with the trustee and we must retain the documentation in order to show what we did in your case. In such a situation we will explain to you exactly what we can delete, what we cannot and why.

Complaint to the supervisory authority. If you consider that we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.

11. Is providing data mandatory

Providing data is voluntary but in part necessary. Without identification data, identity document data, your Zonda account identifier and claim data we cannot conclude a contract or file a claim on your behalf. Without billing data we cannot issue an invoice.

Providing data in the contact form is entirely voluntary and serves solely to answer your enquiry.

12. Profiling and automated decisions

We do not take decisions in relation to you based solely on automated processing, including profiling, which would produce legal effects concerning you or similarly significantly affect you.

Some operations are performed automatically — for example calculating the fee from the amount of the claim stated in the form, converting the value of assets at the rates for the day bankruptcy was declared, or the schedule of notifications. The results of those calculations do not replace the legal assessment, which is carried out by a human being.

Analytics and remarketing tools, if you consent to them, may build profiles for advertising purposes. You may withdraw consent at any time in the cookie settings in the site footer.

13. Data security

We apply technical and organisational measures appropriate to the risk: encryption in transit, encryption at rest, role-based access control, two-factor authentication for those operating the system, logging of operations on data, and regular backups kept in the European Union.

Access to identity document data is limited to the people preparing proofs of claim, to the extent necessary to perform that task.

If a personal data breach occurs which may result in a high risk to your rights, we will inform you without undue delay and notify the President of UODO.

14. Cookies and similar technologies

On the site we use cookies and similar technologies (local storage, web beacons), in accordance with the Electronic Communications Law of 12 July 2024 and Article 6(1)(a) GDPR. We use three categories:

  1. Essential, required for the operation and security of the site, including logging in to the panel and remembering your consent settings. These always operate and require no consent, because without them the site does not work;

  2. Analytics, such as Microsoft Clarity and Google Analytics. These require your consent and do not load before it is given;

  3. Marketing, such as Meta Pixel, Google Ads and Google Tag Manager. These require your consent and do not load before it is given.

You may change or withdraw consent at any time — click "Cookie settings" in the footer of any page of the site, or clear the cookies in your browser. Withdrawing consent does not affect the lawfulness of processing carried out earlier.

15. Webinars and recordings

The webinars we run may be recorded, so that the recording can be made available to participants and to those who registered but were unable to attend.

  1. By default we record the presenter's image and voice and the content of the chat;

  2. We record a participant's image and voice only if they switch on their camera or microphone themselves. If you do not wish to be recorded, leave them switched off — you can still take part in the webinar in full;

  3. We keep the recording until consent is withdrawn. You may withdraw consent at any time by writing to — without giving a reason and with no consequences for your case. Withdrawal does not affect the lawfulness of processing carried out earlier;

  4. You may request that your image or voice be removed from the recording. We will anonymise the relevant passage, and if that is not technically possible we will delete the recording in full.

16. Changes to this policy

We update this policy when the law, the scope of our services or the tools we use change. We will inform you of every material change by e-mail, if we have your address, or by a notice on the site. The current version is always available at zondaodzyskaj.pl/polityka-prywatnosci, and the version date appears at the beginning of the document.

Version of 1 September 2026 · replaces the version of 25 May 2026