GDPR (RODO) information notice
A condensed notice under Art. 13 and 14 GDPR for the office's clients, their counterparties, contact persons and job candidates, together with the rules on entrusting data processing.
Last updated: 08.09.2026
1. Controller and contact details
The controller of the data is the company operating the Steers accounting office; full registration details are given in the site footer and in the box at the end of this document. For data protection matters, write to the office's email address.
We have not appointed a data protection officer. A full description of processing is in the Privacy policy — below we provide the information in condensed form.
2. Who this notice concerns
- The office's clients and the people representing clients: partners, board members, proxies, attorneys and contact persons — for this data we are the controller.
- The office's counterparties and suppliers, and the people they designate for contact — we are the controller.
- Candidates for employment or cooperation who send us application documents — we are the controller.
- Employees, contractors, counterparties and customers of our clients whose data reaches us in accounting and HR documents — here we are a processor, and the controller remains our client (see point 8).
- People who contact us through the website form — details in the Privacy policy.
3. Source of the data
We receive data either directly from you or from our client, who designated you as their representative, contact person or a party to a document.
We also use publicly available registers: KRS, CEIDG, the register of VAT taxpayers kept by the Head of KAS, and the Central Register of Beneficial Owners (CRBR). The scope of data from these sources covers identification and address data and information on representation.
4. Purposes and legal bases
- Concluding and performing the agreement for accounting, HR/payroll and advisory services — Art. 6(1)(b) GDPR; with respect to people representing a client — Art. 6(1)(f) GDPR.
- Obligations arising from the law: the Accounting Act, the Tax Ordinance, tax acts, social insurance regulations, PPK regulations, and the Act on Counteracting Money Laundering and Terrorist Financing — Art. 6(1)(c) GDPR.
- Special-category data in HR documentation — Art. 9(2)(b) GDPR in conjunction with labour and social insurance law.
- Recruitment: with respect to the data listed in the Labour Code — Art. 6(1)(c) GDPR, and for the remaining scope and for future recruitment — Art. 6(1)(a) GDPR (consent).
- Ongoing contact, handling enquiries and maintaining relationships with counterparties — Art. 6(1)(f) GDPR.
- Establishing, pursuing and defending claims, and handling complaints — Art. 6(1)(f) GDPR.
5. Recipients of data
- Public administration bodies and institutions: tax offices and KAS together with KSeF, ZUS, GUS, PFR in respect of PPK, the General Inspector of Financial Information, courts and law-enforcement authorities.
- Providers of accounting and HR/payroll software and IT infrastructure — under data processing agreements.
- The office's subcontractors, law firms, statutory auditors and the insurer — to the extent necessary for the matter.
- Banks and payment institutions — in respect of payments made on a client's instruction.
6. Retention periods
- Accounting and tax documentation — 5 years counted from the end of the calendar year in which the tax payment deadline fell.
- HR documentation kept for clients — 10 years from the end of the calendar year in which the employment relationship ended; for people employed before 1 January 1999 — 50 years.
- AML documentation — 5 years from the first day of the year following the year in which the business relationship ended or the transaction was carried out.
- Contracts and correspondence — until claims become time-barred.
- Recruitment documents — until the recruitment ends, and where consent for future recruitment was given — up to 12 months or until consent is withdrawn.
- Data entrusted by a client — until the processing agreement ends; afterwards we return or delete it in accordance with the client's instruction.
7. Transfers outside the EEA and profiling
As a rule we do not transfer data outside the European Economic Area. If a provider of a support service processes data outside the EEA, this takes place on the basis of standard contractual clauses approved by the European Commission.
We do not apply automated decision-making that produces legal effects, including profiling.
8. Entrustment of processing — the office as a processor
In keeping books and running payroll, we process the data of people connected with our client — its employees, contractors, counterparties and customers. The controller of that data is our client, and the office acts as a processor within the meaning of Art. 28 GDPR.
The basis is a data processing agreement (umowa powierzenia przetwarzania danych osobowych), concluded in writing or electronically as an annex to the accounting services agreement. We do not begin providing services without a signed processing agreement.
- Subject and purpose: keeping the client's books, tax settlements and HR/payroll documentation, and providing access to the client portal.
- Scope and categories of data subjects: identification and address data, PESEL numbers, employment and remuneration data, counterparties' settlement data; the categories of data subjects are set out in the agreement.
- We process data only on the controller's documented instructions, including with respect to transfers outside the EEA — unless an obligation follows from the law, of which we inform the controller.
- We ensure that people admitted to the data are bound by confidentiality, and we implement security measures corresponding to Art. 32 GDPR.
- Further entrustment (sub-processing) — only with the client's consent, on terms no less stringent; we make the list of standing sub-processors available before concluding the agreement and inform of any planned changes.
- We assist the controller in meeting its obligations under Art. 32–36 GDPR and in handling requests from data subjects.
- We report a personal data breach to the controller without undue delay after becoming aware of it, providing the information needed to notify the supervisory authority.
- After the services end, we return the data or delete it — as chosen by the controller, except for data whose retention is required by law.
- We enable the controller to carry out an audit or inspection, on the terms and within the deadlines agreed in the processing agreement.
9. Rights of data subjects
You have the right to access your data, rectify it, erase it, restrict its processing, port it, and object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warszawa.
Where we process your data on our client's instructions, submit your request to them as the controller. If it reaches us, we will pass it on to the client without undue delay and carry out their instruction.
10. Obligation to provide data
Providing data required by tax law, labour law, social insurance law and anti-money-laundering law is mandatory — without it we cannot carry out settlements or enter into business relations. You provide any other data, including additional contact details, voluntarily.