Full controller's notice under Article 13 GDPR. What we collect, for what purpose, on what legal basis, with whom we share it and what rights you have.
In brief
The controller of your data is Krajowe Centrum Obsługi Długów sp. z o.o. (KCOD) of Olsztyn, Poland.
We collect data in order to file your claim in the Estonian Zondacrypto bankruptcy and to conduct your case.
From your identity document we take down only the data we need. We do not keep scans or photographs of ID cards or passports.
The data goes to the trustee and the court in Estonia. Estonia is in the European Union, so the same GDPR protects it as in Poland.
We do not sell the data and do not pass it to anyone who is not needed to conduct your case.
You may at any time request access to your data, its correction or erasure — write to kontakt@zondaodzyskaj.pl.
The controller of your personal data is Krajowe Centrum Obsługi Długów spółka z ograniczoną odpowiedzialnością, with its registered office in Olsztyn, ul. F. Nowowiejskiego 9/401, 10-162 Olsztyn, Poland, entered in the register of entrepreneurs of the National Court Register under number 0001019984, NIP 7393980771, REGON 524614251, share capital 15,000 PLN paid up in full.
Contact on personal data matters:
e-mail: kontakt@zondaodzyskaj.pl or RODO@kcod.pl
telephone: +48 89 675 0002 (Mon–Fri, 8:30–16:00)
post: to the registered office address given above
We have not appointed a data protection officer. All matters are handled by the controller at the addresses given above.
people who have submitted their case on ZondaOdzyskaj.pl and concluded a contract with us;
people who completed the form or registered for a webinar but did not conclude a contract;
people representing corporate clients — members of the management board, attorneys, contact persons;
people on whose behalf someone else files a claim — for example heirs or persons acting through a representative;
people contacting us through the form, by e-mail or by telephone;
visitors to our websites.
Identification data: first name and surname, PESEL number, date of birth, citizenship, and for companies — name, NIP, KRS and the details of the persons representing them;
Contact data: e-mail address, telephone number, address of residence or registered office, correspondence address;
Case data: the identifier, login or e-mail address of your account on the Zonda platform, the type and quantity of assets, balances, the amount of the claim, transaction history, deposit confirmations, blocked withdrawal instructions, correspondence with Zonda and the other documents you send as evidence;
Identity document data: described separately in point 4;
Financial data: bank account number, invoicing details, information about the payment made received from the payment operator;
Contract conclusion data: the content of the declarations made, the date and time of acceptance, the IP address, the transaction identifier — needed to show when and on what terms you concluded the contract;
Technical data: IP address, session identifier, browser and device data, server logs;
Image and voice: only if you take part in a webinar and switch on your camera or microphone — details in point 15.
The trustee must know who is filing the claim and be able to link the filing to the account on the Zonda platform and to the KYC documentation the exchange collected when the account was opened. That is why we ask for data from your identity document.
the type of document (ID card or passport);
the series and number of the document;
the expiry date and issuing authority;
given names and surname, date of birth, citizenship, PESEL number.
We do not keep scans, photographs or copies of ID cards or passports;
We do not collect the image from the document, the signature specimen or biometric data;
We do not copy the document in full, so we do not gather fields that are not needed for the filing.
The basis for processing this data is Article 6(1)(b) GDPR — performance of the contract you have concluded with us — and Article 6(1)(c) GDPR to the extent that identification of the creditor is required by the trustee. We pass this data to the trustee and the court in Estonia only to the extent necessary to file and defend your claim.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Handling the submission on the site and preparing the contract before you conclude it | Article 6(1)(b) GDPR — steps prior to entering into a contract | Until the contract is concluded. If it is not concluded — 12 months from the last contact, or less if you ask for your data to be erased |
| Concluding the contract in documentary form and demonstrating when and on what terms it was concluded | Article 6(1)(b) and (f) GDPR — demonstrating the content and moment of conclusion | As set out in point 6 |
| Preparing and filing the proof of claim and the application to exclude crypto-assets from the estate | Article 6(1)(b) GDPR | As set out in point 6 |
| Identifying the creditor for the purposes of the proceeding — identity document and KYC data (point 4) | Article 6(1)(b) and (c) GDPR | As set out in point 6 |
| Conducting the case: correspondence with the trustee and the court, attendance at creditors' meetings, monitoring the proceeding | Article 6(1)(b) and (f) GDPR | As set out in point 6 |
| Settlements, invoices, accounting | Article 6(1)(c) GDPR — the Accounting Act and tax legislation | 5 full tax years, counted from the end of the year in which the document was issued |
| Handling correspondence, enquiries and complaints | Article 6(1)(f) GDPR — responding to an enquiry | Until the matter is closed, and then until the limitation period for claims expires |
| Marketing of our own services | Article 6(1)(f) GDPR; sending to a particular electronic channel — with your consent, under the Electronic Communications Law | Until you object or withdraw consent |
| Webinars, registration and recording | Article 6(1)(a) GDPR — consent | Until consent is withdrawn. Once withdrawn, we delete the recording or anonymise your participation in it |
| Statistics, analytics and remarketing | Article 6(1)(a) GDPR — consent given in the cookie panel | In line with the validity periods of the individual cookies, no longer than 24 months |
| Site security, access logs, prevention of abuse | Article 6(1)(f) GDPR | Logs up to 12 months |
| Establishing, pursuing or defending claims | Article 6(1)(f) GDPR | Until the limitation periods expire |
We keep the data of your case — including identification data, identity document data, claim data, evidence, the contract, the power of attorney and correspondence — for the duration of the bankruptcy proceeding of BB Trade Estonia OÜ, and then for 5 years from its final conclusion.
We count that period to the end of the calendar year in which the fifth year expires. This means that if the proceeding ends in, say, March 2030, we will delete the data at the end of 2035.
We do this for two reasons. First, throughout the proceeding and for the limitation period we must be able to show what we filed on your behalf and when. Second, the case file may be needed if you wish to pursue something yourself later on.
Shorter periods apply to technical logs (12 months) and to the data of people who have not concluded a contract with us (12 months). We keep webinar recordings until consent is withdrawn; the rules are set out in point 15. We keep accounting records for 5 full tax years, irrespective of the above rule, because tax legislation requires it.
Once those periods expire we delete or anonymise the data.
Primarily from you: from the form on the site, from the documents you send and from your correspondence with us.
If someone files on your behalf — for example a representative, a legal guardian or a person acting in a probate matter — we receive your data from that person. In such a case this policy constitutes performance of the information obligation under Article 14 GDPR, and the source of the data is the person who submitted your case. The scope of the data is as described in points 3 and 4.
We verify and supplement company data from public registers: the National Court Register (KRS), CEIDG, REGON (Statistics Poland), the Ministry of Finance's list of VAT taxpayers and the VIES system.
We may also receive information about your case from the trustee, the Estonian court and the Estonian official gazette Ametlikud Teadaanded.
We pass data only to those entities we need in order to conduct your case or to run the site. We do not sell data. On request we will identify the specific recipients to whom we have disclosed your data.
We may also pass data to: courts, the trustee, the prosecution service and administrative authorities, to the extent required by law or by the proceeding; and to professional supervisory bodies in the event of inspection.
Note one thing which we state openly: a proof of claim becomes part of the file of the bankruptcy proceeding. This means the data it contains may be available to the court, the trustee, the debtor and other participants in the proceeding — to the extent following from Estonian law. Beyond that scope we do not pass your data to the debtor.
In summary, the recipients of the data are the trustee in bankruptcy and the court in Estonia, our partner law firm in Estonia, hosting and database providers, e-mail and SMS providers, the payment operator, the invoicing system, translators, postal operators and couriers, the accounting office, and the controller's legal and tax advisers.
Estonia is a member state of the European Union. Passing your data to the trustee, the Estonian court and our partner firm in Estonia is not a transfer outside the European Economic Area and requires no additional safeguards: the same GDPR applies there as in Poland, and supervision is exercised by the Estonian counterpart of UODO, Andmekaitse Inspektsioon.
The systems in which we store your case data — the database and hosting — run on servers in the European Union. Backups also remain in the EU.
Data is transferred outside the EEA only in connection with tools for e-mail delivery, analytics, remarketing and the webinar platform. The transfer takes place on the basis of one of the mechanisms in Chapter V GDPR:
an adequacy decision of the European Commission (EU–U.S. Data Privacy Framework) — where the provider is certified under it;
standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR) — where the provider is not certified;
additional technical and organisational safeguards set out in the processing agreements: pseudonymisation and encryption in transit and at rest.
You have the right to obtain information about the safeguards applied — write to kontakt@zondaodzyskaj.pl.
You have the right to:
access your data and obtain a copy of it;
rectify inaccurate or incomplete data;
erase your data;
restrict processing;
data portability;
object to processing based on our legitimate interest, and to direct marketing — in every case;
withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Send requests to kontakt@zondaodzyskaj.pl, RODO@kcod.pl or by post to the registered office. We reply without undue delay and no later than within one month. In particularly complex matters we may extend that period by two months, informing you within the first month. Exercising your rights is free of charge.
Some rights may be limited. This applies in particular to a request to erase data during the bankruptcy proceeding, where the proof of claim has already been filed with the trustee and we must retain the documentation in order to show what we did in your case. In such a situation we will explain to you exactly what we can delete, what we cannot and why.
Complaint to the supervisory authority. If you consider that we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
Providing data is voluntary but in part necessary. Without identification data, identity document data, your Zonda account identifier and claim data we cannot conclude a contract or file a claim on your behalf. Without billing data we cannot issue an invoice.
Providing data in the contact form is entirely voluntary and serves solely to answer your enquiry.
We do not take decisions in relation to you based solely on automated processing, including profiling, which would produce legal effects concerning you or similarly significantly affect you.
Some operations are performed automatically — for example calculating the fee from the amount of the claim stated in the form, converting the value of assets at the rates for the day bankruptcy was declared, or the schedule of notifications. The results of those calculations do not replace the legal assessment, which is carried out by a human being.
Analytics and remarketing tools, if you consent to them, may build profiles for advertising purposes. You may withdraw consent at any time in the cookie settings in the site footer.
We apply technical and organisational measures appropriate to the risk: encryption in transit, encryption at rest, role-based access control, two-factor authentication for those operating the system, logging of operations on data, and regular backups kept in the European Union.
Access to identity document data is limited to the people preparing proofs of claim, to the extent necessary to perform that task.
If a personal data breach occurs which may result in a high risk to your rights, we will inform you without undue delay and notify the President of UODO.
On the site we use cookies and similar technologies (local storage, web beacons), in accordance with the Electronic Communications Law of 12 July 2024 and Article 6(1)(a) GDPR. We use three categories:
Essential, required for the operation and security of the site, including logging in to the panel and remembering your consent settings. These always operate and require no consent, because without them the site does not work;
Analytics, such as Microsoft Clarity and Google Analytics. These require your consent and do not load before it is given;
Marketing, such as Meta Pixel, Google Ads and Google Tag Manager. These require your consent and do not load before it is given.
You may change or withdraw consent at any time — click "Cookie settings" in the footer of any page of the site, or clear the cookies in your browser. Withdrawing consent does not affect the lawfulness of processing carried out earlier.
The webinars we run may be recorded, so that the recording can be made available to participants and to those who registered but were unable to attend.
By default we record the presenter's image and voice and the content of the chat;
We record a participant's image and voice only if they switch on their camera or microphone themselves. If you do not wish to be recorded, leave them switched off — you can still take part in the webinar in full;
We keep the recording until consent is withdrawn. You may withdraw consent at any time by writing to kontakt@zondaodzyskaj.pl — without giving a reason and with no consequences for your case. Withdrawal does not affect the lawfulness of processing carried out earlier;
You may request that your image or voice be removed from the recording. We will anonymise the relevant passage, and if that is not technically possible we will delete the recording in full.
We update this policy when the law, the scope of our services or the tools we use change. We will inform you of every material change by e-mail, if we have your address, or by a notice on the site. The current version is always available at zondaodzyskaj.pl/polityka-prywatnosci, and the version date appears at the beginning of the document.
Version of 1 September 2026 · replaces the version of 25 May 2026