Privacy Policy
Version 4.1 · Effective 2026-08-06
FINDIT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
ul. Marii Curie-Skłodowskiej 3/27, 20-029 Lublin, Poland
NIP 7123513870 · KRS 0001245131 · REGON 544892900
1. Controller and contact
The controller of personal data processed for general Findit account operation is Findit Sp. z o.o. Contact details should be published on the website and inside the app. Where a vendor receives customer data to fulfill an order, booking, delivery, service, room viewing, event, or other transaction, that vendor may act as an independent controller for that received data.
2. Controller identity and transaction counterparties
The controller for general Platform operation is FINDIT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, trading as Findit Sp. z o.o., at ul. Marii Curie-Skłodowskiej 3/27, 20-029 Lublin, Poland. Privacy requests may be sent to hello@finditeu.com. The company is registered under KRS 0001245131, NIP 7123513870 and REGON 544892900.
Depending on the transaction, the Contractual Supplier, employer, property advertiser, event organiser, payment provider, carrier or verification provider may be an independent controller for data it receives for its own purposes. Its own notice should explain that processing. Findit does not become controller of every purpose merely because data passes through the Platform.
3. Data we process
Findit may process account data, contact details, profile data, provider details, tax identifiers, business registration data, identity verification data, location data, booking data, transaction data, payout data, listing content, community content, reviews, messages, device-risk signals, support records, moderation records, and legal/compliance records. The exact data collected depends on the feature used, the user category, the country, the payment partner, and the risk level of the activity.
4. Sources, public visibility and data minimisation
Data may come directly from users, transaction counterparties, connected payment or verification providers, devices, public registers, cookies and security tools, or be generated from Platform activity. Public Listings, profiles, reviews and community posts are visible to other users and may be indexed where the interface permits it.
Users should not upload passports, residence documents, health data, criminal-record information, immigration case files or other sensitive material into public Listings or ordinary chats unless a dedicated secure feature expressly requests it. Findit will seek to collect only data reasonably necessary for the relevant purpose.
5. Children and legal capacity
The ordinary marketplace is intended for adults. Findit does not knowingly offer ordinary seller, payment or contracting features directly to children. Where a limited community or informational feature is lawfully available to a minor, age-appropriate information, parental authorisation or other safeguards will be used when required.
6. Purposes and lawful bases
Findit processes personal data to create and manage accounts, operate listings, provide search and local discovery, enable bookings and checkout, route orders to providers, process payments through partners, provide support, prevent fraud, moderate content, enforce terms, comply with tax and reporting obligations, protect users, improve products, and localize listings. Lawful bases may include performance of contract, legal obligation, legitimate interests, consent where required, vital interests in emergencies, and establishment or defense of legal claims.
7. Lawful-basis and balancing transparency
Contract is used where processing is objectively necessary to provide an account or requested feature. Legal obligation covers accounting, tax, safety, regulatory and lawful authority requirements. Legitimate interests may cover security, fraud prevention, service improvement, defence of claims and proportionate moderation after balancing user rights. Consent is used where required for optional marketing, non-essential device access or cookies and may be withdrawn. Findit will not rely on consent where processing is not genuinely optional.
8. Location data and local discovery
Findit may process approximate location, selected municipality, service area, delivery address, and, where enabled by the user and device settings, precise or background geolocation. This helps show nearby services, jobs, rooms, transport, food providers, events, and local community content. Users may disable device location permissions. Some nearby discovery, safety, delivery, or matching features may then be limited.
9. Device-risk, anti-fraud, and single profile controls
To enforce single-profile restrictions, prevent banned-user re-entry, protect wallet payouts, detect review fraud, block scraping, and reduce platform abuse, Findit may process security signals such as IP address, app instance ID, cookies, advertising ID where lawfully available, device model, operating system, browser version, language settings, approximate network path, login timestamps, risk scores, and hashed or pseudonymized device fingerprints. Findit will not rely on raw IMEI, raw MAC address, or similar hardware identifiers unless lawfully available, necessary for a defined security purpose, and permitted by device platform rules and applicable law.
10. Payments, wallet, KYC, AML, and DAC7
Findit may share data with payment institutions, electronic money institutions, banks, acquirers, payment gateways, auditors, regulators, tax authorities, and fraud-prevention partners where needed for payment processing, payout release, chargebacks, KYC, AML, tax reporting, DAC7 reporting, and legal compliance. Findit does not store raw card numbers where card data is handled directly by a licensed payment partner.
11. Provider and category verification
For providers, food listings, transport posts, events, jobs, housing, business directory entries, wallet access, high-value payouts, or high-risk categories, Findit may request identity documents, tax data, business registration data, permits, licenses, insurance documents, sanitary declarations, ownership evidence, employer confirmations, and related metadata. Verification data is used for onboarding, trust badges, fraud prevention, dispute handling, risk review, legal compliance, and category gating.
12. Reviews, NFC cards, and review-session data
When a user taps a Findit review NFC card, QR code, or short review link, Findit may process transient session data such as IP address, browser/app metadata, timestamp, cookie or session token, NFC card identifier, provider identifier, booking reference, and risk signals. This is used to verify that a review is tied to a real or reasonably verifiable transaction before publication.
13. Community moderation and safety processing
Findit may process listing text, community posts, comments, reports, message metadata, review metadata, device-risk signals, location signals, enforcement history, and payment-risk indicators to detect illegal content, scams, harassment, doxxing, unsafe food, illegal work, unlicensed financial activity, transport abuse, review manipulation, and platform-fee bypass. Where required by law, users may receive notices, reasons, complaint routes, and human review safeguards for material moderation or restriction decisions.
14. AI translation, listing intelligence, and localized marketing
Public listing text, menus, catalog feeds, item descriptions, service tags, availability blocks, and non-private storefront metadata may be processed through language-processing and machine-learning systems to generate translations, category matching, spelling cleanup, localized search snippets, multilingual campaigns, and expat-facing recommendations. Private messages, payment details, identity documents, precise location trails, and sensitive data are not used for general-purpose model training unless a separate lawful basis, notice, and required safeguards apply.
15. AI and automated assistance
Findit may process content through automated translation, classification, moderation, search, fraud-prevention and marketplace-assistance tools. These tools may produce errors and are not legal, medical, immigration, recruitment, tax or financial advice. Users remain responsible for content they submit or approve.
Private messages, identity documents, precise location trails and payment information are not used to train a general-purpose model unless a separate notice identifies a lawful basis and the required safeguards. Materially synthetic public-interest content and deepfake media may be labelled where applicable.
16. Cookies, SDKs, and analytics
Findit may use cookies, SDKs, pixels, local storage, and similar tools for login, security, fraud prevention, session management, preferences, performance, analytics, local discovery, advertising measurement, and in-app functionality. Where legally required, optional cookies or similar technologies are used only after consent.
17. Recipients and processors
Personal data may be shared with hosting providers, payment partners, identity verification providers, analytics providers, fraud-prevention tools, customer support tools, communications providers, legal advisers, accounting providers, auditors, tax authorities, law enforcement, regulators, and transaction counterparties where necessary for the relevant feature or legal obligation.
18. International transfers
Where personal data is processed outside the European Economic Area or by providers in countries without an adequacy decision, Findit will use appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms where required.
19. Retention
Findit keeps personal data for as long as necessary for the purposes described in this Policy, including account operation, transaction records, tax/accounting duties, support, disputes, fraud prevention, legal claims, AML/KYC, DAC7 reporting, moderation history, and platform security. Retention periods may differ by data category and legal requirement.
20. Evidence, legal holds and deletion controls
When content, an account, communication or transaction is reported, disputed, restricted or appealed, Findit may retain relevant versions, records and evidence for the period reasonably required for investigation, appeals, safety, legal claims, legal holds or applicable obligations. Retention remains subject to purpose limitation, access control, security and law.
Operational retention periods must be maintained in an internal schedule covering account data, transaction and tax records, identity evidence, messages, moderation records, security logs, marketing consents and backups. Data will be deleted or irreversibly anonymised when the purpose and any lawful hold expire, subject to backup rotation and evidence needed to demonstrate deletion.
21. User rights
Users may request access, correction, deletion, restriction, portability, or a copy of relevant personal data, and may object to processing based on legitimate interests where GDPR allows. Users may object to direct marketing at any time. Where consent is the lawful basis, consent may be withdrawn without affecting earlier lawful processing. Findit may continue processing where necessary for legal claims, tax records, fraud prevention, AML/KYC, chargebacks, safety investigations, statutory retention, or other lawful grounds.
22. How to exercise rights and complain
Requests may be sent electronically to hello@finditeu.com. Findit may verify the requester's identity and will respond without undue delay, ordinarily within one month, subject to lawful extensions. Rights are not absolute and may be limited to protect other persons, confidential information, legal obligations or claims. A requester may complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or seek a judicial remedy.
23. Automated decision-making and human review
Findit may use automated systems to detect fraud, review manipulation, payment risk, suspicious devices, unsafe posts, tax reporting triggers, or fee-circumvention. Decisions producing legal or similarly significant effects will include suitable safeguards where legally required, including human intervention, the ability to express a point of view, and the ability to contest the decision.
24. Profiling safeguards
Risk scores and automated recommendations may support security, moderation, ranking or fraud review. Findit does not intend to make a decision based solely on automated processing that produces legal or similarly significant effects unless law permits it and suitable safeguards apply. Where required, the affected person may request human intervention, express a view and contest the outcome.
25. Security
Findit uses technical and organizational safeguards intended to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. No system is risk-free, and users must keep login credentials secure and report suspected account compromise promptly.
26. Incident handling and processors
Findit applies role-based access, encryption in transit, logging, backups and other measures proportionate to risk, and requires processors to provide appropriate safeguards. Suspected personal-data breaches are assessed, contained and documented; UODO and affected individuals will be notified when the legal threshold is met. Users should report suspected account compromise promptly.
27. Jobs, applications, CVs and Talent Search
When a person creates a candidate profile, uploads a CV, applies for a job, answers recruitment questions, receives an invitation or uses recruitment messaging, Findit may process identity and contact details, CV and profile information, employment and education history, skills, location and work preferences, application answers, attached documents, application status, invitations, messages and related audit and security records. Findit processes this information to provide requested recruitment features, transmit and store applications, enable authorised employer or agency access, support candidate communication, prevent abuse, maintain evidence and operate security and compliance controls.
Findit acts as controller for its own Platform-operation, account, security, audit, moderation and compliance purposes. An employer or employment agency that receives or accesses candidate information for its own recruitment purposes will generally act as a separate controller for those purposes and must provide an applicable privacy notice, establish its own lawful basis, minimise access, secure the data, respect candidate rights and apply appropriate retention periods.
Talent Search is available only where the feature is enabled and the candidate's visibility settings permit it. Approved employers or agencies may access the candidate information made available for genuine recruitment under the Employer & Employment Agency Terms. Candidates may change or withdraw Talent Search visibility using available controls. Withdrawal from Talent Search stops future Platform visibility through that feature, but does not automatically erase information already lawfully received by an employer or agency where that organisation has an independent lawful basis or legal retention obligation.
Talent Search visibility is not permission for unrelated marketing, scraping, resale, bulk harvesting or indefinite candidate databases. Employers and agencies must use candidate information only for compatible recruitment purposes and delete or anonymise it when no longer necessary, subject to any lawful retention basis.
Employer compliance and verification processing may include an authorised representative's name and business contact details, account role, KRAZ status or number where applicable, KRS or CEIDG information, NIP, REGON, registered address, submitted declarations, review status and compliance-event records. Such information is used for account administration, verification, fraud prevention, candidate protection and legal or platform-compliance purposes. Fields identified in the employer interface as private are not displayed publicly merely because they are collected for verification.
28. Updates to this Policy
Findit may update this Privacy Policy to reflect new features, providers, payment partners, legal requirements, countries, or security practices. Significant changes will be communicated where required by law.