Search

Privacy policy

Privacy notice of ESG XTB Platform

A. Data Controller

The Data Controller of Your personal data is XTB S.A with its registered office in Warsaw (address: ul. Prosta 67, 00-838 Warsaw).

You can contact with XTB via:

  • e-mail: office@xtb.com,
  • phone: (+48 22 2019560),
  • letter: ul. Prosta 67, 00-838 Warsaw.

B. Data Protection Officer

We would like to inform you that we have appointed a Data Protection Officer, whom you can contact on all matters related to the processing of personal data by e-mail: iod@xtb.com or by post to the registered office address with the note "DPO".

C. Purpose of processing

We would like to inform You, that Your personal data will be processed on the legal basis of the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46 / WE (hereinafter as „GDPR”) for the following purposes:

  • Answering the question and establishing contact, which is our legitimate interest (basis in Article 6 (1) (f) of GDPR). The data will be processed until the conversation is completed. Providing the data is necessary to establish contact.
  • In order to possibly determine, investigate or defend against claims, which is our legitimate interest (the basis of Article 6 (1) (f) of GDPR). The data will be processed until the claims expire
  • Analytical and marketing via our cookies. The processing of personal data is necessary to implement the legitimate interest of XTB, consisting in improving the quality of the services provided and promoting them (legal basis: Article 6 (1) (f) of GDPR). Personal data will be processed until an objection is expressed. Consent to cookies is voluntary.

D. Recipients of Data

  • Collaborating entities - We may share your personal data with cooperating entities, i.e. companies that XTB owns or controls or that are under common control with XTB or are in constant cooperation with XTB. These are in particular banks, investment companies, auditors, companies providing other financial services, IT companies, consulting companies or courier companies), only to the extent necessary to implement such cooperation;
  • Processors - We transfer your personal data to entities providing services and processing on behalf of XTB, i.e. suppliers of IT services and solutions in the following categories: CRM IT tool (customer relationship management), tools for sending e-mails and a tool for managing and recording telephone calls. The data is processed by the above-mentioned suppliers on the basis of a data processing agreement with XTB and only in accordance with its instructions;
  • State authorities - If authorized state authorities, in particular law enforcement authorities, enforcement authorities, fiscal control authorities, courts, public authorities appointed to protect personal data, request the provision of your personal data to XTB, XTB shall provide you with Your personal data if such disclosure is required by law

The provision of services by XTB may require (depending on the scope of activities provided by XTB) the transfer of personal data to entities providing services to XTB in other countries, including countries outside the European Economic Area. In the event of transfer to countries that do not ensure an adequate level of protection of personal data, XTB applies security measures in the form of one of the legal instruments provided for in the GDPR, such as, among others: decisions of the European Commission confirming an adequate level of protection in one of the third countries, standard contractual clauses approved by the European Commission or the supervisory authority of one of the Member States, approved codes of conduct in a given industry or binding corporate rules.

E. Your Rights

  • The right to access personal data processed by XTB (Article 15 of GDPR);
  • The right to rectify entrusted personal data, including its correction (Article 16 of GDPR);
  • The right to erase personal data from XTB systems, the so-called "right to be forgotten" (Article 17 of GDPR);
  • The right to restrict processing of personal data (Article 18 of GDPR);
  • The right to data portability (Article 20 of GDPR);
  • Right to object to processing of personal data (Article 21 of GDPR);
  • If in Your opinion the processing of personal data violates the provisions of GDPR, You have the right to lodge a complaint to the supervisory body, i.e. the President of the Office for Personal Data Protection