Skip to content
DGDOMUS GLOBALReal estate
BuySell
Rent
Find a property to rentLet my propertyManage a rental propertyResolve a rental deposit
FinancingForeign buyersKnowledge
More
How we workExpertsAll services
Describe your situation
PLRUUKEN
DGDOMUS GLOBALReal estate

Property, financing and transaction support in one coordinated process.

Office

al. Jerzego Waszyngtona 40A, lok. 3
03-910 Warszawa

+48 785 956 750biuro@domusglobal.pl

Directions

I am buying a propertyI am selling a propertyRental and managementI am financing a purchaseI am buying as an international clientMore

About and contact

How we workExpertsAll servicesKnowledgeDescribe your situationPrivacy information
© 2026 DOMUS GLOBAL
Home/Privacy information

Privacy on this website

DOMUS GLOBAL contact-form privacy policy

This policy describes the processing of personal data in the English version of the DOMUS GLOBAL contact form.

This policy applies to the EN contact formVersion: privacy-2026-08-02-en · Date: 2 August 2026
Privacy policy
  1. 01Overview
  2. 021. Controller and personal-data contact
  3. 032. Form scope and purposes
  4. 043. Data we process
  5. 054. Purposes and legal bases
  6. 065. Voluntary provision of data
  7. 076. Recipients, providers, and transfers outside the EEA
  8. 087. Retention period
  9. 098. Data-subject rights
  10. 109. Automated decisions, marketing, and cookies
  11. 1110. Security
  12. 1211. Version and changes

1. Controller and personal-data contact

The controller of personal data submitted through the form is Jacek Stefański, conducting a sole proprietorship under the name DOMUS NOVA Nieruchomości JS, NIP 7581814764, REGON 141960860, address: al. Jerzego Waszyngtona 40A, unit 3, 03-910 Warsaw, hereinafter the “Controller”.

  • For questions about the processing of personal data: biuro@domusglobal.pl ↗

You may also write to the Controller’s postal address.

2. Form scope and purposes

The English version of the form is used to receive and handle one of four types of enquiry:

  • an enquiry about a specified property;
  • a description of an advisory need;
  • notification of an intention to sell a property;
  • an enquiry about possible financing scenarios.

The form is not used to create an account, send documents, or subscribe to marketing. The first EN release does not make WhatsApp or Telegram available. Enabling a messenger later requires a separate assessment, information notice, and release of this policy.

3. Data we process

Depending on the selected response method, the form processes:

  • your name or preferred form of address;
  • your e-mail address or telephone number;
  • the enquiry type and message content;
  • the language, source page, and public identifier or slug of a property or project if the enquiry started on such a page;
  • the policy version, acknowledgement that it has been read, selected contact method, form start time, and a technical identifier for safe retry;
  • the minimum technical data needed to protect the form, such as a hash of the IP address, browser information, request time and source address, and the result of the anti-spam mechanism.

In the first message, we do not ask for document scans, PESEL, identity-document numbers, banking data, complete financial documentation, or special-category data. If such information becomes necessary later, the Controller will indicate an appropriate channel and provide the required processing information.

4. Purposes and legal bases

  • receiving the enquiry, replying, identifying needs, and taking steps at the person’s request before a possible contract is concluded — Article 6(1)(b) GDPR;
  • protecting the form, limiting spam and abuse, preventing duplicates, ensuring service continuity, and establishing, pursuing, or defending claims — Article 6(1)(f) GDPR; the legitimate interest is service security and the ability to demonstrate that an enquiry was received correctly;
  • compliance with a legal obligation imposed on the Controller if such an obligation arises during further handling of the matter — Article 6(1)(c) GDPR, to the extent resulting from the applicable provision.

Acknowledging that the policy has been read records that the information was provided and is not marketing consent. The form records the absence of marketing consent. The data is not used for a newsletter, behavioural advertising, or marketing profiling.

5. Voluntary provision of data

Providing data is voluntary, but without a message and the data required for the selected response method, the enquiry cannot be handled. Fields not marked as required remain optional. Instead of the form, you may use the telephone number or e-mail address published on the website.

6. Recipients, providers, and transfers outside the EEA

Data may be accessed by authorised DOMUS personnel handling the matter and by the following providers acting on the Controller’s instructions:

  • OpenAI Ireland Ltd. — hosting, maintaining and supporting the published ChatGPT Site and processing Hosted Data required to provide that service;
  • Supabase Pte. Ltd — the enquiry-intake function and PostgreSQL database of the DOMUS service system; the database is located in the eu-central-1 region, while functions, support, and subprocessors may involve global processing;
  • Google Cloud Poland Sp. z o.o. — Google Workspace Gmail used to send an operational notification to the team about a new enquiry.

Providers and their subprocessors may process data outside the European Economic Area. In such a case, the Controller relies on a transfer mechanism provided for by the GDPR, in particular an adequacy decision or Standard Contractual Clauses (SCCs) forming part of the relevant data-processing agreement. Information about the safeguard used, or a copy of it, may be requested through biuro@domusglobal.pl, subject to protected commercial and security information.

Data may be disclosed to a mortgage adviser, lawyer, notary, or another partner only where required by the specific matter, an appropriate legal basis exists, and the person receives the required information.

  • Supabase — DPA ↗
  • Supabase — subprocessor list ↗
  • Google — Cloud Data Processing Addendum ↗
  • Google Workspace — subprocessor list ↗

7. Retention period

  • the raw form-submission record and its technical identifier: up to 365 days after receipt, followed by a mandatory review, archiving, or deletion;
  • the lead, conversation, and messages connected with the matter: for the duration of handling and, after closure, up to 730 days before a mandatory review;
  • evidence that the policy version and selected channel were communicated: up to 1,095 days after the matter is closed or channel consent is withdrawn, if such consent is used later;
  • security logs: for the period necessary to prevent abuse, detect and explain an incident, and demonstrate protection of the service, taking account of providers’ technical retention periods.

Data required by law or needed to establish, pursue, or defend claims may be retained longer — for the period resulting from the applicable provision, a legal hold, or until the limitation period expires. The periods above are mandatory review thresholds; automated destruction remains disabled until a deletion or anonymisation procedure has been approved and tested.

8. Data-subject rights

Within the limits set by the GDPR, a person may request access to their data, rectification, erasure, restriction of processing, and portability, and may object to processing based on Article 6(1)(f) GDPR. If particular processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

A request may be sent to biuro@domusglobal.pl or by post to the Controller’s address. The Controller may request information necessary to verify identity securely. The person also has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).

  • UODO — rights under the GDPR ↗

9. Automated decisions, marketing, and cookies

Form data is not used to make decisions about a person that produce legal effects solely by automated means. The anti-spam mechanism may reject a technical request; in that case, telephone or e-mail contact remains available.

The first EN launch does not include analytics, advertising, marketing pixels, a newsletter, or marketing cookies. The form does not request marketing consent. Optional functions require a separate review and a new version of the policy before they are enabled.

10. Security

The form sends data over an encrypted connection to the protected DOMUS service system. The browser does not store draft form content in persistent storage or create a user account. Access to records is restricted according to role, and repeated requests are controlled by a technical identifier.

No technical measure eliminates risk completely. Documents, banking data, identifiers, and other sensitive information should be provided only after an appropriate secure channel has been agreed.

11. Version and changes

Version privacy-2026-08-02-en takes effect on 2 August 2026 for the English version of the form. A change to the purpose, data scope, provider, retention, messenger, or language requires an assessment and a new version. The PL, RU, UK, and EN editions apply as corresponding language versions of this package.

Direct contact

Choose the form or contact the office directly

In the first message, state only the purpose of the conversation. Share documents, bank details, and identifiers after a contact channel has been agreed.

Go to contactHome