Privacy Policy
1. Introduction
This Privacy Policy explains how Starbien Sp. z.o.o. (“Startbien”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you visit our website or use our online services. We are committed to safeguarding your privacy and processing your information lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Polish Data Protection Act.
This Policy should be read together with our Terms & Conditions, Cookies Policy, and AML/CFT Policy.
2. Data Controller
Starbien Sp. z o.o.
Plac Bankowy 2/1309, 00-095 Warsaw, Poland
Email: support@startbien.com
We determine the purposes and means of processing your personal data and act as the Data Controller under GDPR.
3. Personal Data We Collect
Depending on your relationship with Starbien and the services you use, we may collect the following categories of data:
- Identification Data: full name, date of birth, nationality, government ID numbers.
- Contact Details: residential address, email address, telephone number.
- Verification Data: copies of ID documents, and where applicable source-of-funds information.
- Transaction Data: payment information, wallet addresses, account activity and order history.
- Technical Data: IP address, browser type, device information, and cookie identifiers (see Cookies Policy).
- Communication Records: emails, support requests, and complaint submissions.
4. Purposes and Legal Bases for Processing
Your personal data are processed only where lawful bases apply under Article 6 of the GDPR:
| Purpose of Processing | Legal Basis |
|---|---|
| Account registration and customer onboarding (KYC) | Legal obligation (AML Act, GDPR Art. 6 (1)(c)) |
| Transaction execution and service delivery | Contract performance (GDPR Art. 6 (1)(b)) |
| Risk management and AML/CFT monitoring | Legal obligation and legitimate interest |
| Communication and support responses | Contract performance and legitimate interest |
| Marketing or service updates (optional) | Consent (GDPR Art. 6 (1)(a)) |
| Website analytics and security | Legitimate interest (GDPR Art. 6 (1)(f)) |
We do not use personal data for automated decision-making that produces legal effects without human review.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described above or as required by law.
- AML/KYC records – at least 5 years after the end of the business relationship.
- Transaction and financial records – for statutory accounting periods.
- Marketing data – until consent is withdrawn.
When retention periods expire, data are securely deleted or anonymized.
6. Disclosure of Data
We may share data with:
- Regulatory and law enforcement authorities (e.g., GIIf, KNF) where required by law.
- Financial and payment institutions to process transactions and verify funds.
- Third-party service providers (KYC, hosting, analytics) under strict data processing agreements.
- Legal advisors and auditors for compliance purposes.
We do not sell or rent personal data to third parties.
7. International Data Transfers
Where data are transferred outside the European Economic Area (EEA), we ensure adequate protection through:
- EU Commission adequacy decisions; or
- Standard Contractual Clauses (SCCs) approved by the European Commission.
You may request further information on these safeguards via support@startbien.com.
8. Data Security
Starbien applies robust technical and organizational measures to protect data from loss, misuse, unauthorized access, or disclosure.
Measures include encryption, access controls, multi-factor authentication, firewalls, secure storage systems, and staff training.
Despite these safeguards, no online system can be guaranteed 100% secure, and Users share responsibility for protecting their own login credentials.
9. Your Data Protection Rights
Under the GDPR you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data (subject to legal retention obligations).
- Right to Restriction: Limit processing in certain circumstances.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time (without affecting prior lawful processing).
To exercise any of these rights, contact us at support@startbien.com. We will respond within one month (extendable by two months in complex cases).
10. Complaints
If you believe your data has been mishandled, you have the right to lodge a complaint with the Polish supervisory authority:
President of the Personal Data Protection Office (PUODO)
ul. Stawki 2, 00-193 Warsaw, Poland
Website: https://uodo.gov.pl
11. Changes to This Policy
Starbien may update this Privacy Policy from time to time to reflect legal, operational, or technological changes. Updates will be posted on this page with a revised “Last Updated” date.
Significant changes may be communicated via email or Platform notification.
12. Contact Us
For questions or concerns about this Privacy Policy or data processing practices, contact:
Starbien Sp. z.o.o.
Email: support@startbien.com
Address: Plac Bankowy 2/1309, 00-095 Warsaw, Poland