Legal
Cookies policy
In force from 29 May 2026
1. General provisions
1.1. This Cookies Policy ("Policy") sets out the rules for the use, on the website available at https://bergopay.com ("Website"), of cookies and other similar technologies that enable information to be stored or access to be obtained to information already stored in the telecommunications terminal equipment of the user.
1.2. This Policy supplements the Controller's Privacy Policy and should be read together with that policy. To the extent that the use of cookies involves the processing of personal data, the rules for processing personal data set out in the Privacy Policy apply, in particular the legal bases for processing, categories of recipients, storage periods, transfers of data outside the European Economic Area and the rights of data subjects.
1.3. The administrator of the Website and the controller of personal data within the meaning of Article 4(7) GDPR is BERGOPAY spółka z ograniczoną odpowiedzialnością with its registered office in Poznań, pl. Władysława Andersa 3, floor 11, 61-894 Poznań, KRS 0001087262, NIP 7831897723, REGON 527722573 ("Controller" or "Bergopay"). The Controller is a small payment institution (MIP) entered in the register under number MIP250/2024. Detailed details of the Controller and contact details are provided in the Privacy Policy.
1.4. Bergopay does not provide services to consumers within the meaning of Article 22(1) of the Civil Code; the Website and the services described therein are addressed exclusively to entrepreneurs and other organizational units conducting business or professional activity.
1.5. This Policy covers only cookies and similar technologies used within the Website (the public website). This Policy does not cover technical tools used by the Controller in connection with the provision of actual payment services outside the Website, including client panels, authentication applications, KYC/KYB tools and transaction monitoring tools (KYT); those tools are subject to separate documents provided to the Controller's clients.
2. Contact details for cookie matters
2.1. In matters relating to the use of cookies on the Website, including matters concerning giving or withdrawing consent, the Controller may be contacted:
- by email at: office@bergopay.com;
- via the contact form available at: https://bergopay.com/contact;
- by post to the address of the Controller's registered office specified in section 1.3.
3. What are cookies and similar technologies
3.1. Cookies are small text files stored by the Website's server on the user's telecommunications terminal equipment (computer, tablet, smartphone) when the user uses the Website. These files contain information that the Website's server may read on subsequent visits to the Website, in order to recognize the device, adapt the Website content to the user's preferences, ensure security or perform other functions.
3.2. This Policy also applies to other technologies that operate in a manner analogous to cookies, in particular:
- browser local storage (localStorage), a mechanism for persistent data storage in the user's browser, independent of HTTP cookies;
- browser session storage (sessionStorage), a mechanism for temporary data storage in the user's browser, valid until the tab or browser is closed;
- web beacons (pixel tags), small graphic images embedded in the Website content enabling the fact that a page or message has been displayed to be recorded;
- browser fingerprinting mechanisms, mechanisms for identifying the user's device based on a combination of technical parameters of the browser and device.
3.3. All of the above technologies are referred to collectively in this Policy as "cookies" or "cookie files", unless the context requires otherwise. The use of these technologies is subject to the same legal requirements as the use of classic HTTP cookies, in particular with respect to obtaining the user's consent and providing the user with information required by law.
4. Classification of cookies used in the Policy
4.1. Depending on the classification criterion, cookies may be classified as follows:
4.1.1. By origin:
- first-party cookies, files stored by the Website itself (bergopay.com domain);
- third-party cookies, files stored by entities other than the Controller whose components have been embedded in the Website (e.g. providers of web fonts, analytics tools, embedded video content or maps).
4.1.2. By storage period:
- session cookies, stored on the user's terminal equipment until the browser session ends (the tab or browser is closed);
- persistent cookies, stored on the user's terminal equipment for the time specified in the cookie parameters or until they are deleted by the user.
4.1.3. By purpose:
- strictly necessary cookies, necessary for the proper operation of the Website or for providing the telecommunications service requested by the user; the use of these cookies does not require the user's prior consent;
- functional cookies, allowing the settings selected by the user (e.g. language version of the Website) to be remembered and the interface to be personalized;
- analytical / statistical cookies, allowing analysis of how the Website is used in order to optimize it (counting visits, traffic sources, time spent on the Website);
- marketing / advertising cookies, enabling personalized marketing content to be displayed on and outside the Website and the effectiveness of marketing campaigns to be measured.
4.2. The use of functional, analytical, marketing and third-party cookies (to the extent they are not strictly necessary for the operation of the Website) requires the user's prior consent in accordance with Article 399(1) of the Act of 12 July 2024, Electronic Communications Law.
5. Legal basis for using cookies
5.1. The use of cookies on the Website is governed by the provisions of the Act of 12 July 2024, Electronic Communications Law (Journal of Laws of 2024, item 1221) ("PKE"), which, as of 10 November 2024, replaced the provisions of the Act of 16 July 2004, Telecommunications Law, in this respect.
5.2. Pursuant to Article 399(1) PKE, storing information in the telecommunications terminal equipment of an end user and obtaining access to information already stored therein is permissible provided that the end user has given consent.
5.3. Pursuant to Article 399(4) PKE, the requirement to obtain the consent referred to in section 5.2 above does not apply if storing or accessing information is necessary for:
- transmission of a communication over a public telecommunications network; or
- provision of a telecommunications service or electronically supplied service requested by the end user.
5.4. Pursuant to Article 400 PKE, the provisions on personal data protection apply accordingly to obtaining the consent referred to in section 5.2 above. Consent should be, in particular, freely given, specific, informed and unambiguous, and expressed by a statement or clear affirmative action, in accordance with Article 4(11) and Article 7 GDPR.
5.5. To the extent that the use of cookies involves the processing of personal data, the legal basis for processing is:
- Article 6(1)(a) GDPR (consent of the data subject), with respect to optional cookies (functional, analytical, marketing) and third-party cookies requiring consent;
- Article 6(1)(f) GDPR (the Controller's legitimate interest), with respect to strictly necessary cookies, where the legitimate interest is to ensure the proper and secure operation of the Website.
5.6. If cookies requiring the User's consent are implemented on the Website, consent to such optional cookies will be collected through the consent management banner described in section 9 of the Policy. The User may withdraw consent or change the scope of consent at any time in accordance with the rules set out in section 9 of the Policy. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal (Article 7(3), second sentence, GDPR).
6. Cookies used on the Website
6.1. The table below identifies the cookies and similar technologies actively used on the Website as at the effective date of the Policy, together with their detailed characteristics.
| Name / identifier | Provider | Category | Purpose | Storage period |
|---|---|---|---|---|
| Hosting server logs (GoDaddy), automatic tagging of clicks and timestamps on Website subpages | GoDaddy.com, LLC (United States), the Website hosting provider with whom the Controller has entered into a data processing agreement (DPA) | Strictly necessary | A technical mechanism integral to GoDaddy's hosting service, involving the automatic server-side recording of information about the User's clicks on individual subpages of the Website and the timestamps of those clicks. The mechanism is used for basic technical operation of the Website, diagnostics, traffic statistics and security (protection against DDoS attacks, scraping and brute-force attacks). The mechanism does not involve storing cookies or other identifiers on the User's terminal equipment. This information is recorded exclusively on the infrastructure of the hosting provider. | Logs are stored on GoDaddy's infrastructure in accordance with the configuration of the provider's hosting service. |
6.2. The cookies listed in section 6.1 are classified as strictly necessary and are used on the basis of:
- Article 399(4)(2) PKE, as technologies necessary to provide an electronically supplied service requested by the User;
- Article 6(1)(f) GDPR, the Controller's legitimate interest consisting in ensuring the proper and secure operation of the Website.
6.3. The use of cookies listed in section 6.1 does not require the User's prior consent.
7. Third-party cookies and external components
7.1. The Website uses components provided by third parties that may result in the transfer of Users' personal data (in particular IP addresses) to those entities and, in some cases, in the setting of cookies by those entities. These components are identified in the table below.
| Component / tool | Provider | Purpose and characteristics | Status | Transfer outside EEA |
|---|---|---|---|---|
| Cloudflare (contact form handling) | Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) | Technical handling of the contact form available on the Website, including forwarding submissions sent by the User to the Controller and protecting the form against abuse (including automated attacks and spam). As part of handling the form, the User's IP address, browser technical data and the content of the form are transferred to Cloudflare. In the current configuration, the use of Cloudflare does not involve storing cookies on the User's terminal equipment. | ACTIVE | YES — possible transfer outside the EEA, including to the USA. Safeguards in accordance with section 8 of the Policy. |
7.2. The privacy policies of the providers of the components listed in the table in section 7.1 are available at the following addresses:
- Cloudflare (contact form): cloudflare.com/privacypolicy
7.3. The use of the components listed in the table in section 7.1, to the extent they require the User's consent, takes place only after the User's prior consent has been obtained through the consent management banner described in section 9 of the Policy.
8. Transfer of data outside the European Economic Area
8.1. Some components used on the Website are provided by entities from corporate groups established outside the European Economic Area or using infrastructure located outside the EEA, which may result in the transfer of Users' personal data to third countries, in particular to the United States of America.
8.2. Personal data are transferred to a third country in accordance with the rules set out in Chapter V GDPR.
8.3. With respect to countries for which the European Commission has issued an adequacy decision pursuant to Article 45 GDPR, transfers are made on the basis of that decision. In particular, with respect to the United States of America, in relation to entities certified under the EU-U.S. Data Privacy Framework (DPF), transfers are made on the basis of Commission Implementing Decision (EU) 2023/1795 of 10 July 2023.
8.4. Where personal data are transferred to third countries for which no adequacy decision applies, or where the recipient of the data is not covered by such a decision, the Controller ensures appropriate safeguards within the meaning of Article 46 GDPR, in particular by:
- applying standard contractual clauses adopted by the European Commission on the basis of Commission Implementing Decision (EU) 2021/914 of 4 June 2021;
- implementing, where necessary, additional technical and organizational measures in accordance with the guidelines of the European Data Protection Board (including EDPB Recommendations 01/2020 on supplementary measures).
8.5. The User may obtain a copy of the safeguards applied or information on where such safeguards have been made available by submitting a request using the contact details indicated in section 2.1 of the Policy, subject to limitations arising from business confidentiality.
9. Managing consents on the Website, cookies banner
9.1. In the current configuration of the Website, no cookies or similar technologies requiring the User's consent are used. Therefore, the Controller does not actively display a consent management banner. If cookies or similar technologies requiring consent are introduced on the Website (e.g. analytical cookies, marketing cookies, mechanisms for embedding videos or maps), a consent management banner will be displayed during the User's first visit to the Website, enabling the User to make a choice regarding optional cookies. The banner will include in particular:
- brief information about the use of cookies on the Website;
- a reference to this Policy;
- buttons enabling consent to be given or refused.
9.2. In the banner, the User may:
- accept all cookies ("Accept all" option), granting consent to the use of all categories of optional cookies indicated in the Policy;
- accept only strictly necessary cookies ("Necessary only" option), refusing consent to optional cookies and using the Website only with cookies necessary for its proper operation.
9.3. If the banner is implemented, the choice made by the User in the banner will be saved in the User's browser local storage (localStorage) under a key dedicated to the Website, making it possible to avoid displaying the banner again during subsequent visits by the User to the Website. The Policy will be updated with details of this functionality when it is implemented.
9.4. The User may change their choice or withdraw previously granted consent at any time:
- using the consent management panel available on the Website ("Cookie settings" link in the Website footer), if the panel functionality has been implemented;
- by clearing local storage (localStorage) and site data for the bergopay.com domain in the User's browser, which will cause the banner to be displayed again on the next visit;
- by changing the browser settings for cookies in accordance with section 10 of the Policy.
9.5. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal (Article 7(3), second sentence, GDPR).
10. Managing cookies in the browser
10.1. Regardless of the settings made in the banner referred to in section 9 of the Policy, the User may manage cookies at any time in the settings of the browser used to access the Website. In particular, the User may in the browser:
- block all cookies;
- block only third-party cookies;
- delete cookies already stored on the terminal equipment;
- set notifications for each attempt to store a cookie.
10.2. Detailed information on managing cookies in popular browsers is available from Google Chrome, Mozilla Firefox, Microsoft Edge, Apple Safari and Opera support pages.
11. Consequences of disabling cookies
11.1. Refusing consent to optional cookies or withdrawing such consent does not affect the basic functioning of the Website. The User may fully access the informational content of the Website and use the contact form.
11.2. Disabling all cookies (including strictly necessary cookies) or blocking them in the browser settings may cause certain Website functions to operate incorrectly, in particular:
- repeated display of the consent management banner each time the User visits the Website (without the ability to remember the User's preferences);
- failure to remember the settings selected by the User (e.g. the language version of the Website);
- limited functionality of selected Website elements, in particular components requiring external resources to be loaded.
12. Changes to the Policy
12.1. The Policy may be updated periodically, in particular in the event of:
- introduction of new cookie tools or similar technologies on the Website (e.g. analytics tools, marketing tools, mechanisms for embedding videos or maps);
- changes to the providers of components used on the Website;
- changes to generally applicable legal provisions or guidelines of supervisory authorities (UODO, EDPB) in the field of personal data protection or the use of cookies;
- changes in the organization of data processing processes on the Controller's side.
12.2. The current version of the Policy is published on the Website in a manner enabling the User to read its content. The date of the last material update is indicated in section 13 of the Policy.
12.3. In the event of material changes concerning the manner in which cookies are used, in particular the introduction of new tracking tools or changes to the scope of consents required from the User, the Controller will inform Users in a manner appropriate to the nature of the change, including by displaying an updated consent management banner enabling consent to be given again.
13. Effective date
13.1. This Policy in its present wording applies from 29 May 2026.
13.2. Matters not regulated in this Policy are governed by the GDPR, the Act of 10 May 2018 on the Protection of Personal Data, the Act of 12 July 2024, Electronic Communications Law, the Act of 18 July 2002 on the Provision of Electronic Services and the Controller's Privacy Policy available on the Website.