Controller – means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
The controller of personal data is PKO Bank Hipoteczny Spółka Akcyjna with its registered office in Warsaw, address: ul. Świętokrzyska 36, 00-116 Warsaw.
The controllers of personal data of Clients of PKO Bank Hipoteczny are PKO Bank Hipoteczny Spółka Akcyjna and PKO Bank Polski Spółka Akcyjna. We provide more information on this subject in the section titled “Information on the processing of personal data of PKO Bank Hipoteczny Clients.”
Personal data – means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Clients’ personal data (e.g. names and surnames, dates and places of birth, residence addresses, PESEL national ID numbers, telephone numbers) are processed by the Bank for the purpose of delivering products and services.
Recipient – means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.
The Bank discloses Clients’ personal data to data recipients, who may be e.g. entities and authorities authorised on the basis of the generally applicable provisions of the law, e.g. other banks, courts, prosecutors, Biuro Informacji Kredytowej S.A.
Supervisory authority – means an independent public authority which is established by a Member State for the purpose of protecting fundamental rights and freedoms of natural persons in relation to data processing.
The supervisory authority is the Head of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
Processing – means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
The Bank processes personal data, i.e. it collects, records, stores, erases and destroys it.
Profiling – means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Profiling-based tools are used by the Bank for several purposes:
- profiling for the purposes of assessing creditworthiness to support the transaction evaluation process and assessing the Client by using historical information on the level of credit risk for particular groups of Clients, e.g. a Client who meets their credit obligations on time receives a higher assessment.
An expression of objection to profiling for purposes of assessing creditworthiness may mean:
- the inability to designate and use a preferential pre-defined offer,
- the inability to conduct an automated assessment of creditworthiness, in effect significantly lengthening the lending process,
- the inability to perform the Bank’s obligation to assess the Client’s request in accordance with the Regulator’s recommendations (e.g. Recommendation T) and a denial of lending.
- profiling carried out for the purpose of preventing crimes and counteracting money laundering, including building models arising from the Bank’s obligations defined by the provisions of generally applicable law.
Consent to the processing of personal data – denotes an expression of will of the individual whose data it applies to, whose content is permission for processing of personal data. The granting of consent should be freely given, specific, informed and unambiguous.
The data subject has the right at any moment to withdraw their consent. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.
In connection with the servicing of banking products or the provision of services, Clients’ data are processed not based on consent but in light of the fact that this is essential to implement authorisations or to fulfil an obligation arising from a provision of the law (e.g. the conclusion of a mortgage loan agreement).