SteersBiuro Rachunkowe
← Back to home page

Privacy policy

What personal data we collect through the steers.com.pl website and the client portal, why we need it, who we share it with, and what rights you have over it.

Last updated: 19.09.2026

1. Data controller and contact details

The controller of your personal data is the company operating the Steers accounting office (biuro rachunkowe) — its full name, registered office, KRS number, NIP and REGON are given in the site footer and in the box at the end of this document.

For all matters concerning the processing of personal data and the exercise of the rights described in point 9, you can write to the office's email address or by post to the address of its registered office.

We have not appointed a data protection officer (inspektor ochrony danych) — we are not required to under Art. 37 GDPR (RODO). Data protection matters are handled directly by the office's management.

2. Scope of this document

This policy describes data processing in three areas: the steers.com.pl website, the client portal (the Steers platform), and the ongoing accounting, HR and payroll services we provide to our clients.

Separate, condensed information for clients, counterparties and job candidates is available in the GDPR (RODO) information notice. The rules on the use of cookies are described in the Cookie policy. The rules for using the website and the portal are described in the Terms of service.

3. Categories of data we process

We collect only the data we actually need to prepare an offer, conclude a contract and perform it. We do not buy data sets and we do not obtain data from sources you would not know about — except for public registers (KRS, CEIDG, the VAT taxpayer whitelist, CRBR), which we use to verify counterparties.

  • Contact form and enquiry: first and last name or company name, email address, phone number, the price-list package selected, legal form and scale of business, the content of the message, and the language used to browse the site.
  • Client portal — login and technical account data: email address, encrypted password hash, role within the client's organisation, login date and IP address, history of actions in the portal (who uploaded or approved a document, and when).
  • Client portal — content of accounting documents: sales and purchase invoices, receipts, bank statements, cash reports and fiscal-cash-register reports, contracts, minutes, warehouse and stocktaking documents, together with scans and photographs taken in the app.
  • Data of the employees, contractors and counterparties of our clients contained in HR and payroll documents: identification and address data, PESEL number, bank account numbers, data on remuneration, working time, leave, absences and sick leave, data of family members reported for insurance purposes. In this respect we act as a processor — see point 5.
  • Data from integrations set up at a client's request: POS and hospitality sales systems, HR and time-recording systems, e-commerce and marketplace platforms, delivery service providers, bank statements retrieved automatically. The scope of each integration is agreed with the client before it is switched on and is limited to the data needed for settlements.
  • Correspondence: emails, chat conversations in the portal (an accountant's questions about a specific document), notes from meetings with the accountant, service requests.
  • Data collected for anti-money-laundering purposes: documents and information indicated in the AML policy, including data on beneficial owners and information on holding a politically exposed position.
  • Technical data: IP address, browser type and version, operating system, date and time of the request, recorded in server logs and in the portal's security logs.

5. When we are the controller, and when we are a processor

We are the controller with respect to the data of people who contact us through the website, the data of our clients and the people representing them, the data of our counterparties, and the data collected for AML purposes.

We are a processor within the meaning of Art. 28 GDPR with respect to the data of a client's employees, contractors, counterparties and customers that reaches us in documents and through integrations. The controller of that data remains the client, and we process it solely on its documented instructions, under a data processing agreement (umowa powierzenia) attached to the accounting services agreement.

The exception is situations where the law imposes obligations directly on the accounting office — in that case we act as a separate controller with respect to that same data (this applies mainly to AML documentation and to archiving evidence of the services performed).

6. Recipients of data

We do not sell data and do not share it for marketing purposes. We pass it on only where necessary to perform a service or required by law — to subprocessors always under data processing agreements, and only after checking that they provide the guarantees required by Art. 28(1) GDPR.

  • The hosting and server-infrastructure provider, with data centres within the European Economic Area, on which the website, the client portal and backups run.
  • The email and office-productivity tools provider.
  • Providers of accounting, HR/payroll and filing software, including systems for e-Deklaracje and JPK filings.
  • The office's subcontractors: accountants and HR specialists working on a B2B basis, IT support, document archiving and destruction.
  • Operators of integrations set up at a client's request — POS, HR, e-commerce systems and banking service providers, to the extent of the data retrieved for settlements.
  • Public authorities and institutions, where disclosure follows from the law: tax offices, the National Revenue Administration (KAS) and the National e-Invoicing System (KSeF), ZUS, GUS, PFR in respect of PPK, the General Inspector of Financial Information (GIIF) in respect of AML obligations, courts and law-enforcement authorities.
  • Banks and payment institutions — in respect of transfers and statements handled on a client's instruction.
  • Law firms, statutory auditors and the insurer — where a matter requires it.
  • The messaging service through which the office receives notice of a new enquiry from the website; the notification contains the data provided in the form.
  • Google Ireland Limited — the provider of Google Analytics 4, which we use to measure website traffic. It receives the visit data listed in the Cookie policy; we do not pass it the data from the form or clients' documents.

7. Transfers of data outside the European Economic Area

As a rule, data remains within the European Economic Area — we keep infrastructure and backups with providers whose data centres are in the EEA.

If a particular support service involves processing data outside the EEA (this concerns communication tools and website traffic measurement), it takes place on the basis of standard contractual clauses approved by the European Commission or an adequacy decision, together with an assessment of the effects of such a transfer. On request, we provide information about the safeguards applied.

We do not transfer clients' accounting documents or HR documentation outside the EEA.

8. Retention periods

We delete or anonymise data once the basis for its processing ceases to exist. We calculate the periods below in the way indicated by the provisions they refer to.

  • Enquiries that did not result in cooperation — up to 12 months from the last contact; where marketing consent was given — until it is withdrawn.
  • Accounting books, accounting evidence and tax documentation — 5 years counted from the end of the calendar year in which the tax payment deadline fell, in accordance with the Tax Ordinance and the Accounting Act.
  • HR documentation kept for clients — 10 years from the end of the calendar year in which the employment relationship ended, and for people employed before 1 January 1999 — 50 years.
  • Documentation and results of applying financial security measures, together with transaction evidence for AML purposes — 5 years counted from the first day of the year following the year in which the business relationship ended or the occasional transaction was carried out.
  • Contracts, correspondence and settlement documentation with a client — until claims become time-barred, as a rule 3 years for claims related to running a business, and in tax matters — until the tax liability becomes time-barred.
  • The client-portal account and the history of actions in it — for the duration of the contract; after its termination we return or delete the entrusted data in accordance with the client's instruction and the processing agreement, subject to documents we must retain under statutory obligations.
  • Server logs and the portal's security logs — up to 12 months.
  • Backups — up to 30 days, after which they are overwritten; deleting data from the production system means it is also removed from backups no later than by that deadline.

9. Your rights

To the extent we are the controller of your data, you have the right to:

  • access your data and receive a copy of it (Art. 15 GDPR),
  • have inaccurate data rectified and incomplete data completed (Art. 16 GDPR),
  • have your data erased if we no longer have grounds to keep processing it (Art. 17 GDPR),
  • restrict processing (Art. 18 GDPR),
  • data portability, for data processed on the basis of consent or a contract (Art. 20 GDPR),
  • object to processing based on our legitimate interest (Art. 21 GDPR),
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal (Art. 7(3) GDPR),
  • lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.

10. How we handle requests

You can submit a request in any form — the simplest way is by email to the office's address. We reply without undue delay, no later than within one month; in particularly complex cases we may extend this period by a further two months, telling you the reason.

If your data reached us from our client — for example as an employee, contractor or counterparty of theirs — direct your request to them as the controller. We will pass the matter on to them and carry out their instruction within the time set by the processing agreement.

Before acting on a request we may ask for additional information to confirm your identity. This is not about making things difficult — it is about not disclosing data to an unauthorised person.

11. Whether providing data is voluntary

Providing data in the contact form is voluntary, but without an email address or phone number we will not be able to answer your enquiry. The remaining fields make it easier to prepare a specific quote.

Providing data required by tax law, accounting law, labour and social insurance law and AML law is mandatory — without it we cannot keep books, carry out settlements or enter into business relations.

12. Data security

  • Access to documents and to the portal is limited to authorised employees and associates of the office, to the extent required by their assigned tasks; every authorisation is recorded.
  • People with access to data are bound by confidentiality, including after cooperation ends.
  • Connections to the website and the portal are encrypted; the client portal and the office's back-office panel are separate applications with separate authentication and separated permissions.
  • Actions on documents are logged — it is known who uploaded, changed or approved a document, and when.
  • We perform regular backups and test data restoration.
  • We report personal data breaches to the President of UODO within 72 hours of becoming aware of them, and to the data subjects — where a breach is likely to result in a high risk to their rights. We inform clients for whom we act as a processor without undue delay after we become aware of a breach.

13. Profiling and automated decisions

We do not make decisions about you based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect you.

Documents uploaded to the portal are pre-read by the system (text recognition and preliminary categorisation), but every document is checked by an accountant before it is booked. Client risk assessment for AML purposes is supported by tools, but the decision is always made by a person.

14. Cookies

The website stores only cookies necessary for it to function and session cookies of the client portal. We measure website traffic in Google Analytics 4 in a cookieless mode — the tool stores no files and no identifiers on your device. We use no marketing cookies and do not share data with advertising networks. Details, including what data is collected and how to switch the measurement off — in the Cookie policy.

15. Changes to this policy

If we change the scope of data collected, the purposes of processing, the list of recipients or the retention periods, we will update this document and the date of the last update at its top.

We additionally inform you of changes materially affecting clients' rights in the client portal or by email, with at least 14 days' notice.

Privacy policy — Steers