Legal

Privacy notice

Last updated: 2026-09-08

This notice explains how Momentum AI sp. z o.o., ul. Olsztyńska 58, 11-500 Wilkasy, Poland (KRS 0001171902, NIP 8452007341, REGON 541679702), the operator of Momentum Terminal (“we”), processes personal data. It has two parts: Part I is our public notice under Article 14 GDPR for people who appear in Polish public registers whose records the product displays; Part II covers holders of Momentum Terminal accounts and visitors to this site (Article 13 GDPR). Privacy contact: hello@momentumterminal.pl. Polska wersja poniżej.

Part I. People who appear in public registers (Article 14 GDPR)

1. What we process, and what we do not. In the company records the product displays, we process the following about individuals connected with registered entities: first and last name; role or function in the entity (for example management board member, supervisory board member, proxy, shareholder); the affiliation itself (entity name and KRS number); dates of entry into and removal from the register; shareholding information as disclosed in filings; and country of citizenship where the register discloses it. For companies whose ultimate owners are filed in the Central Register of Beneficial Owners (Centralny Rejestr Beneficjentów Rzeczywistych, CRBR), we also process the beneficial owner’s name, the size and nature of their holding, the year of birth as filed, and the date the register states that entry as of. The year of birth is neither shown nor used: no screen, filter or export in the product reads it. If that ever changes, this notice changes first. We do not process PESEL numbers, residential addresses, or any special categories of personal data (Article 9 GDPR) of people appearing in registers.

2. Where the data comes from. Exclusively from publicly accessible official sources: the National Court Register (Krajowy Rejestr Sądowy, KRS) and its public filings, including the repository of financial documents (ekrs.ms.gov.pl); the Central Register of Beneficial Owners (CRBR); and public company websites. We do not obtain this data from the persons concerned and we do not enrich it from non-public sources. Separately, for investment firms and advisory practices we keep business contact details of the people who handle enquiries there, taken from those firms’ own websites and public professional profiles, so that a user can reach the firm; these are professional contact details, used for no other purpose, and the person may have them removed by writing to hello@momentumterminal.pl.

3. Purpose and legal basis. We provide professional users (private equity funds, M&A advisors, valuation and corporate finance teams) with business information that supports the certainty, transparency and safety of economic transactions: due diligence, valuation and market analysis. The legal basis is legitimate interest under Article 6(1)(f) GDPR, ours and our clients’. We also rely on Article 6(1)(f) for establishing or defending legal claims, and on Article 6(1)(c) where the law imposes obligations on us. A summary of our legitimate interest assessment is available on request.

4. Why we inform publicly rather than individually. The public registers do not disclose to us any contact details of these persons, and we deliberately collect none. Individual notification is therefore impossible or would require disproportionate effort within the meaning of Article 14(5)(b) GDPR. This public notice, kept permanently available, together with the objection route below, is the measure we take to protect your rights.

5. Who receives the data. Categories of recipients: authenticated users of the product, bound by our Terms of Service; and IT infrastructure and hosting providers acting as our processors within the European Economic Area (our server is in Frankfurt). We do not transfer register-person data outside the EEA: the AI features available in the product today send only the user’s own question and company-level figures to our AI provider, never register-person records. Should a future feature need to pass such records to an AI provider outside the EEA, this notice will say so before it ships. We do not sell personal data, we do not share it with advertisers, and we do not use it to train machine-learning models.

6. How long we keep it. For as long as the underlying information remains disclosed in public registers and we have a continuing legitimate interest in providing it, including historical entries where the register itself preserves history. Where we honour an objection, we keep a minimal suppression record for as long as necessary for the objection to remain effective, so the data is not re-imported on a later register refresh.

7. Your rights. You may object to the processing at any time, on grounds relating to your particular situation (Article 21 GDPR). You also have the rights of access, rectification, erasure and restriction. Use the data subject request form or write to hello@momentumterminal.pl; we respond within one month (extendable by two further months in complex cases, with notice). You may lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

8. No automated decisions. We do not make automated decisions producing legal effects concerning individuals and we do not profile them. The figures in the product describe companies, not people.

Part II. Account holders and website visitors (Article 13 GDPR)

1. What we collect. The account data you give us: name, email address, password (stored only as a hash) and optional two-factor authentication secrets. The content you create in the product: lists, notes, saved screens, and the questions you type into the plain-language search together with their answers. Your sign-in sessions: the IP address and browser each was opened from, so that you can see and end them in the account settings. When you subscribe: your billing name and address, a tax identification number if you buy as a business, and the invoices we issue; your card details are entered directly with our payment processor and never reach us. The technical logs needed to run and secure the service. If you choose to sign in with Google, we receive your name and email address from Google. If you asked for access before signing up, that request: email, name, company, and the IP address and browser it was sent from. Problem reports and data requests you send from the product: the text you write, any screenshots you attach, the company or page you sent it from, your browser and language, and the product version.

2. Purposes and legal bases. Providing the service you signed up for, including handling the problem reports and data requests you send, Article 6(1)(b) GDPR. Keeping the service secure, preventing abuse and sending transactional email, Article 6(1)(f). Invoicing and tax obligations, Article 6(1)(c).

3. Recipients and transfers. Categories of recipients: hosting in the EEA (a server in Frankfurt); transactional email delivery; our payment processor, which receives your billing details and your card, and the invoicing software in which we issue your invoice; and, when you use the plain-language search, the text of your query is processed by an AI provider in the United States solely to compile it into filters. Problem reports and data requests, with the name and email address of the account that sent them, and the notice that a payment arrived, with the buyer’s name, address and tax identification number, reach our team through a team messaging service in the United States. Transfers outside the EEA are safeguarded by the EU-US Data Privacy Framework where the provider is certified under it, and otherwise by EU Standard Contractual Clauses. The current list of providers is on the Data Processing Addendum page. No figure shown in the product is generated by AI.

4. Cookies. The session cookie that keeps you signed in, for seven days at most, and preference cookies that remember the language, theme and layout you chose. The sign-in flow briefly sets the framework’s own security cookies. No analytics cookies, no tracking cookies, no third-party cookies. These cookies are needed to provide what you asked for or to keep a choice you made, so no consent banner is shown for them.

5. Retention. For the life of your account, then deletion, except records we must keep by law (five years after the end of the tax year for accounting records in Poland, invoices included). Problem reports, data requests and their screenshots, and any access request you sent before signing up, are deleted with the account. Expired sign-in links are deleted after a day and expired sessions after 30 days. You can export your data and delete your account in the account settings, or via a data subject request.

6. Your rights. The same rights as in Part I, plus data portability. Complaints go to Prezes UODO, as above. Providing account data is a condition of having an account; you are not otherwise required to provide it.

We will post any material change to this notice on this page, with the date of the last update shown above.

Informacja o przetwarzaniu danych osobowych (wersja polska)

Niniejsza informacja wyjaśnia, jak Momentum AI sp. z o.o., ul. Olsztyńska 58, 11-500 Wilkasy, Poland (KRS 0001171902, NIP 8452007341, REGON 541679702), operator produktu Momentum Terminal („my”), przetwarza dane osobowe. Część I to publiczna informacja na podstawie art. 14 RODO dla osób ujawnionych w polskich rejestrach publicznych, których akta produkt prezentuje; część II dotyczy posiadaczy kont i odwiedzających tę stronę (art. 13 RODO). Kontakt w sprawach prywatności: hello@momentumterminal.pl.

Część I. Osoby ujawnione w rejestrach publicznych (art. 14 RODO)

1. Co przetwarzamy, a czego nie. W aktach spółek prezentowanych w produkcie przetwarzamy następujące dane osób powiązanych z zarejestrowanymi podmiotami: imię i nazwisko; funkcję w podmiocie (np. członek zarządu, członek rady nadzorczej, prokurent, wspólnik); samo powiązanie (nazwa podmiotu i numer KRS); daty wpisu i wykreślenia z rejestru; informacje o udziałach w zakresie ujawnionym w aktach; oraz obywatelstwo, jeżeli rejestr je ujawnia. W przypadku spółek, których beneficjenci rzeczywiści są ujawnieni w Centralnym Rejestrze Beneficjentów Rzeczywistych (CRBR), przetwarzamy dodatkowo imię i nazwisko beneficjenta, wielkość i charakter jego udziału, rok urodzenia w brzmieniu ujawnionym w rejestrze oraz datę, na którą rejestr podaje stan. Rok urodzenia nie jest ani prezentowany, ani wykorzystywany: żaden ekran, filtr ani eksport w produkcie go nie odczytuje. Gdyby miało się to zmienić, najpierw zmieni się niniejsza informacja. Nie przetwarzamy numerów PESEL, adresów zamieszkania ani żadnych szczególnych kategorii danych osobowych (art. 9 RODO) osób ujawnionych w rejestrach.

2. Skąd pochodzą dane. Wyłącznie z powszechnie dostępnych źródeł urzędowych: z Krajowego Rejestru Sądowego (KRS) i jego jawnych akt, w tym z repozytorium dokumentów finansowych (ekrs.ms.gov.pl); z Centralnego Rejestru Beneficjentów Rzeczywistych (CRBR); oraz z publicznych stron internetowych spółek. Nie pozyskujemy danych od samych osób, których dotyczą, i nie wzbogacamy ich ze źródeł niepublicznych. Odrębnie, dla funduszy i praktyk doradczych przechowujemy służbowe dane kontaktowe osób, które obsługują tam zapytania, pochodzące ze stron internetowych tych firm i publicznych profili zawodowych, aby użytkownik mógł się z firmą skontaktować; są to dane służbowe, wykorzystywane wyłącznie w tym celu, a osoba może żądać ich usunięcia, pisząc na hello@momentumterminal.pl.

3. Cel i podstawa prawna. Dostarczamy profesjonalnym użytkownikom (fundusze private equity, doradcy M&A, zespoły wycen i corporate finance) informacje gospodarcze wspierające pewność, jawność i bezpieczeństwo obrotu gospodarczego: due diligence, wyceny i analizy rynkowe. Podstawą prawną jest prawnie uzasadniony interes, art. 6 ust. 1 lit. f) RODO, nasz i naszych klientów. Na art. 6 ust. 1 lit. f) opieramy się także w zakresie ustalania i obrony roszczeń, a na art. 6 ust. 1 lit. c), gdy prawo nakłada na nas obowiązki. Streszczenie testu równowagi udostępniamy na żądanie.

4. Dlaczego informujemy publicznie, a nie indywidualnie. Rejestry publiczne nie ujawniają nam żadnych danych kontaktowych tych osób, a my celowo ich nie zbieramy. Indywidualne powiadomienie każdej osoby jest więc niemożliwe lub wymagałoby niewspółmiernie dużego wysiłku w rozumieniu art. 14 ust. 5 lit. b) RODO. Niniejsza publicznie i stale dostępna informacja, wraz z opisaną niżej ścieżką sprzeciwu, jest środkiem, którym chronimy Państwa prawa.

5. Odbiorcy danych. Kategorie odbiorców: uwierzytelnieni użytkownicy produktu, związani naszym Regulaminem, oraz dostawcy infrastruktury IT i hostingu działający jako nasze podmioty przetwarzające na terenie Europejskiego Obszaru Gospodarczego (nasz serwer znajduje się we Frankfurcie). Danych osób z rejestrów nie przekazujemy poza EOG: dostępne dziś w produkcie funkcje AI przesyłają do naszego dostawcy AI wyłącznie pytanie użytkownika i dane na poziomie spółki, nigdy rekordy osób z rejestrów. Gdyby przyszła funkcja wymagała przekazania takich rekordów dostawcy AI spoza EOG, niniejsza informacja powie o tym, zanim ta funkcja zostanie udostępniona. Nie sprzedajemy danych osobowych, nie udostępniamy ich reklamodawcom i nie używamy ich do trenowania modeli uczenia maszynowego.

6. Okres przechowywania. Tak długo, jak dane pozostają ujawnione w rejestrach publicznych i mamy dalszy prawnie uzasadniony interes w ich udostępnianiu, w tym jako wpisy historyczne tam, gdzie sam rejestr zachowuje historię. Po uwzględnieniu sprzeciwu zachowujemy minimalny wpis blokujący tak długo, jak to konieczne, aby sprzeciw pozostał skuteczny i dane nie zostały ponownie zaimportowane przy kolejnej synchronizacji rejestru.

7. Państwa prawa. Mogą Państwo w każdej chwili wnieść sprzeciw wobec przetwarzania, z przyczyn związanych ze swoją szczególną sytuacją (art. 21 RODO). Przysługują Państwu także prawa dostępu, sprostowania, usunięcia i ograniczenia przetwarzania. Prosimy skorzystać z formularza wniosku lub napisać na adres hello@momentumterminal.pl; odpowiadamy w ciągu miesiąca (w sprawach złożonych z możliwością przedłużenia o dwa miesiące, za powiadomieniem). Mogą Państwo wnieść skargę do Prezesa Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

8. Brak zautomatyzowanych decyzji. Nie podejmujemy wobec osób fizycznych zautomatyzowanych decyzji wywołujących skutki prawne i nie profilujemy ich. Liczby w produkcie opisują spółki, nie osoby.

Część II. Posiadacze kont i odwiedzający (art. 13 RODO)

1. Jakie dane zbieramy. Dane konta, które Państwo podają: imię i nazwisko, adres e-mail, hasło (przechowywane wyłącznie jako skrót kryptograficzny) oraz opcjonalne sekrety uwierzytelniania dwuskładnikowego. Treści tworzone w produkcie: listy, notatki, zapisane screeningi oraz pytania wpisywane w wyszukiwanie zwykłym językiem wraz z odpowiedziami. Sesje logowania: adres IP i przeglądarka, z których każdą otwarto, aby mogli Państwo je przeglądać i kończyć w ustawieniach konta. Przy zakupie subskrypcji: nazwa i adres do faktury, numer identyfikacji podatkowej przy zakupie firmowym oraz wystawione przez nas faktury; dane karty wpisują Państwo bezpośrednio u naszego operatora płatności i nigdy do nas nie trafiają. Logi techniczne niezbędne do utrzymania i zabezpieczenia usługi. Przy logowaniu przez Google otrzymujemy od Google imię, nazwisko i adres e-mail. Jeżeli przed założeniem konta poprosili Państwo o dostęp, także tę prośbę: e-mail, imię i nazwisko, firmę oraz adres IP i przeglądarkę, z których ją wysłano. Zgłoszenia problemów i prośby o dane wysyłane z produktu: treść zgłoszenia, dołączone zrzuty ekranu, spółka lub strona, z której je wysłano, przeglądarka i język oraz wersja produktu.

2. Cele i podstawy prawne. Świadczenie usługi, na którą Państwo się zapisali, w tym obsługa wysyłanych przez Państwa zgłoszeń problemów i próśb o dane, art. 6 ust. 1 lit. b) RODO. Bezpieczeństwo usługi, zapobieganie nadużyciom i e-maile transakcyjne, art. 6 ust. 1 lit. f). Fakturowanie i obowiązki podatkowe, art. 6 ust. 1 lit. c).

3. Odbiorcy i przekazywanie danych. Kategorie odbiorców: hosting w EOG (serwer we Frankfurcie); dostawca poczty transakcyjnej; nasz operator płatności, który otrzymuje dane do faktury i dane karty, oraz program do fakturowania, w którym wystawiamy fakturę; a przy wyszukiwaniu zwykłym językiem treść zapytania jest przetwarzana przez dostawcę AI w Stanach Zjednoczonych wyłącznie w celu przełożenia jej na filtry. Zgłoszenia problemów i prośby o dane, wraz z imieniem, nazwiskiem i adresem e-mail konta, z którego je wysłano, oraz powiadomienie o wpłacie z nazwą, adresem i numerem identyfikacji podatkowej kupującego, trafiają do naszego zespołu przez komunikator zespołowy w Stanach Zjednoczonych. Przekazywanie poza EOG zabezpiecza ramowa umowa UE-USA o ochronie danych (Data Privacy Framework), gdy dostawca posiada certyfikację, a w pozostałych przypadkach Standardowe Klauzule Umowne UE. Aktualna lista dostawców znajduje się na stronie Data Processing Addendum. Żadna liczba w produkcie nie jest generowana przez AI.

4. Pliki cookie. Cookie sesyjne utrzymujące zalogowanie, najwyżej przez siedem dni, oraz cookies preferencji zapamiętujące wybrany język, motyw i układ. Proces logowania na krótko ustawia własne cookies zabezpieczające używanego frameworka. Bez cookies analitycznych, śledzących i cookies podmiotów trzecich. Te cookies są niezbędne do świadczenia usługi, o którą Państwo poprosili, albo utrwalają dokonany przez Państwa wybór, dlatego nie wyświetlamy dla nich baneru zgody.

5. Okres przechowywania. Przez czas istnienia konta, następnie usunięcie, z wyjątkiem danych, które musimy przechowywać z mocy prawa (pięć lat od końca roku podatkowego dla dokumentów księgowych w Polsce, w tym faktur). Zgłoszenia problemów, prośby o dane i dołączone do nich zrzuty ekranu oraz prośba o dostęp wysłana przed założeniem konta są usuwane razem z kontem. Wygasłe linki logowania usuwamy po jednym dniu, a wygasłe sesje po 30 dniach. Eksport danych i usunięcie konta są dostępne w ustawieniach konta oraz przez wniosek o realizację praw.

6. Państwa prawa. Te same prawa co w części I, a dodatkowo prawo do przenoszenia danych. Skarga do Prezesa UODO, jak wyżej. Podanie danych konta jest warunkiem jego posiadania; poza tym nie mają Państwo obowiązku ich podawania.

Każdą istotną zmianę tej informacji opublikujemy na tej stronie, z datą ostatniej aktualizacji widoczną powyżej.

See also the Data Processing Addendum, Privacy and Data requests.