Skip to content
LTF Advisers Group
About Our approach Services Team Contact PL EN
Legal

Privacy policy.

Version: 1.0 Effective date: 25 May 2018 Last updated: 5 May 2026 Controller: Kancelaria LTF Sp. z o.o.
Contents
  1. General provisions
  2. Data controller
  3. Purposes, legal bases and categories of data
  4. Professional secrecy
  5. Recipients of data
  6. Transfers outside the EEA
  7. Retention period
  8. Rights of the data subject
  9. Automated decision-making
  10. Data security
  11. Cookies
  12. Changes to the policy

§ 1. General provisions

This Privacy Policy (the "Policy") sets out the rules for the processing of personal data in connection with the activities of Kancelaria LTF Sp. z o.o. Advisers Group and the use of the website available at https://ltfadvisers.com (the "Site").

The Policy fulfils the information obligation arising from Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (the "GDPR"), as well as the obligations arising from the Polish Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2019 item 1781, as amended) and other applicable provisions of law.

Use of the Site does not require providing personal data beyond the technical information related to the browser and device used (see § 11 — Cookies).

§ 2. Data controller

The controller of personal data within the meaning of Article 4(7) of the GDPR is:

Kancelaria LTF Spółka z ograniczoną odpowiedzialnością Advisers Group
ul. Belwederska 10/17, 00-762 Warsaw, Poland
KRS: 0000370589 · NIP (Tax ID): 5252495446 · REGON: 142672212
District Court for the Capital City of Warsaw, 12th Commercial Division of the National Court Register
share capital: PLN 5,000.00

The Controller may be contacted on all matters relating to the processing of personal data:

  • by e-mail: biuro@ltfadvisers.com
  • by post: to the registered office address, marked "Personal data"
  • by telephone: +48 535 643 601

Data Protection Officer

The Controller has not appointed a Data Protection Officer. All matters concerning the processing of personal data may be addressed to the Controller using the contact details indicated above, in particular by writing to biuro@ltfadvisers.com.

§ 3. Purposes, legal bases and categories of data processed

The Controller processes personal data for the purposes and on the legal bases set out below.

Purpose of processing Legal basis Categories of data
Provision of legal advice, tax advisory and other services to the Client — conclusion and performance of the contract Article 6(1)(b) GDPR; for special categories — Article 9(2)(f) GDPR (establishment, exercise or defence of legal claims) identification and contact data, financial and family data, data contained in documents provided by the Client
Client verification and fulfilment of obligations under anti-money-laundering (AML) and counter-terrorism-financing legislation Article 6(1)(c) GDPR in connection with the Polish Act of 1 March 2018 on counteracting money laundering and the financing of terrorism identification data, ID document data, beneficial ownership data, source-of-wealth data
Issuing and storing invoices, keeping accounting records Article 6(1)(c) GDPR in connection with the Accounting Act and tax legislation identification data, invoicing data, settlement data
Handling incoming correspondence (e-mail, contact form, telephone, postal mail) Article 6(1)(f) GDPR — legitimate interest of the Controller in responding and conducting communication identification and contact data, content of correspondence
Marketing of the Controller's own services to existing Clients and professional recipients Article 6(1)(f) GDPR — legitimate interest in informing about services offered identification and contact data, data on prior cooperation
Newsletter, invitations to training and conferences, expert materials Article 6(1)(a) GDPR — consent of the data subject first name, e-mail address, optionally company name and position
Recruitment of candidates for employment or cooperation Article 6(1)(b) GDPR (steps taken prior to entering into a contract), Article 6(1)(c) GDPR (Polish Labour Code), and for additional data — Article 6(1)(a) GDPR (consent) data from the CV and cover letter, data required by law
Establishment, exercise or defence of legal claims Article 6(1)(f) GDPR; Article 9(2)(f) GDPR data necessary for defending claims arising from the legal relationship
Ensuring security of the Site and IT infrastructure Article 6(1)(f) GDPR — legitimate interest in ensuring system security IP address, device and browser data, system logs

Nature of the provision of data. Providing data is voluntary; however, in certain cases (e.g. concluding a legal services agreement, issuing an invoice, fulfilling AML obligations) failure to provide data prevents the commencement or continuation of cooperation.

§ 4. Professional secrecy

Independently of the obligations arising from the GDPR, the personal data of the firm's Clients and of persons whose data are processed in matters handled by the firm are protected by the rules on professional secrecy, in particular:

  • professional secrecy of an attorney-at-law (radca prawny) — Article 3 of the Polish Act of 6 July 1982 on Attorneys-at-Law (Journal of Laws 2022 item 1166, as amended) and the Code of Ethics of Attorneys-at-Law;
  • professional secrecy of a tax adviser — Article 37 of the Polish Act of 5 July 1996 on Tax Advisory (Journal of Laws 2021 item 2117, as amended).

This protection applies indefinitely and is absolute — save for cases set out in statute (including obligations under the AML Act and waivers of professional secrecy granted by a court under Article 180 § 2 of the Polish Code of Criminal Procedure).

To the extent covered by professional secrecy, the Controller is entitled to limit the exercise of certain rights of data subjects — where their exercise would result in a breach of professional secrecy (see Article 14(5)(d) and Article 23 of the GDPR in connection with Article 5 of the Polish Act of 10 May 2018 on the Protection of Personal Data).

§ 5. Recipients of data

The Controller may disclose personal data to the following categories of recipients — solely to the extent and for the purpose for which it is necessary:

  • substantive partners of the firm — attorneys-at-law (radcowie prawni), advocates (adwokaci), tax advisers, mediators, psychologists, trainers — solely to the extent necessary to perform the contract with the Client and subject to professional secrecy;
  • processors processing data on the Controller's behalf — in particular providers of IT services, hosting, e-mail, law firm management tools, and the accounting office — under data processing agreements meeting the requirements of Article 28 of the GDPR;
  • couriers and postal operators — to the extent necessary to deliver correspondence;
  • banks — to the extent necessary to settle payments;
  • state authorities and other entities authorised to access data under statute — to the extent and in the manner provided by those statutes, with respect for professional secrecy;
  • courts, bailiffs and other justice authorities — within the framework of pending proceedings.

§ 6. Transfers of data outside the European Economic Area

As a rule, the Controller does not transfer personal data outside the European Economic Area (EEA). Where the use of IT tools provided by global suppliers (e.g. e-mail, hosting, video-conferencing, office software) involves a transfer of data to a third country, this takes place on the basis of:

  • a European Commission adequacy decision (Article 45 of the GDPR), or
  • standard contractual clauses adopted by the European Commission (Article 46(2)(c) of the GDPR), with additional safeguards where required.

A copy of the relevant safeguards may be obtained by contacting the Controller.

§ 7. Retention period

The Controller stores personal data for the period necessary to fulfil the purpose for which they were collected:

  • data processed to perform a legal services or other services agreement — for the duration of the agreement and the limitation period for claims (as a rule, 6 years from the end of the calendar year in which the claim became due — Article 118 of the Polish Civil Code);
  • data contained in accounting and tax records — for 5 years from the end of the calendar year in which the tax payment deadline expired (Article 70 § 1 of the Polish Tax Ordinance Act);
  • data processed for AML purposes — for 5 years from the end of the business relationship with the client (Article 49(1) of the AML Act), with the possibility of extension by another 5 years at the request of the General Inspector of Financial Information;
  • data processed for handling correspondence — until the matter is concluded and the relevant limitation periods have expired;
  • data processed on the basis of consent (newsletter) — until consent is withdrawn;
  • data processed for own marketing purposes — until an effective objection is raised;
  • recruitment data — until the recruitment process ends, and where consent has been given for future recruitment processes — for the period indicated in the consent, no longer than 24 months.

§ 8. Rights of the data subject

Each person whose data are processed by the Controller is entitled to the following rights under the GDPR:

  • right of access to data and to obtain a copy thereof (Article 15 of the GDPR);
  • right to rectification (Article 16 of the GDPR);
  • right to erasure ("right to be forgotten" — Article 17 of the GDPR);
  • right to restriction of processing (Article 18 of the GDPR);
  • right to data portability (Article 20 of the GDPR) — for data processed on the basis of consent or contract, in an automated manner;
  • right to object to processing carried out under Article 6(1)(f) of the GDPR (Article 21 of the GDPR) — including objection to direct marketing;
  • right to withdraw consent at any time (Article 7(3) of the GDPR) — without affecting the lawfulness of processing carried out before its withdrawal;
  • right to lodge a complaint with the supervisory authority, which in Poland is the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).

To exercise any of the above rights, please contact the Controller using the details set out in § 2. The Controller responds without undue delay, and in any event within one month of receiving the request (extendable by a further two months in complex cases — with information on the reasons for extension).

The exercise of certain rights may be limited to the extent that the data are covered by professional secrecy or where their disclosure would infringe the rights of third parties (see § 4).

§ 9. Automated decision-making and profiling

Personal data are not used for automated decision-making producing legal effects or similarly significantly affecting data subjects. The Controller does not carry out profiling within the meaning of Article 4(4) of the GDPR.

§ 10. Data security

The Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk of infringement of natural persons' rights or freedoms, including in particular:

  • access control — only for authorised persons, to the extent necessary for the work performed;
  • encryption of data in transit (SSL/TLS) and, where justified, at rest;
  • regular backups;
  • organisational safeguards — including written authorisations to process data, regular training and internal policies;
  • data processing agreements with service providers, meeting the requirements of Article 28 of the GDPR.

§ 11. Cookies

The Site uses cookies and similar technologies in accordance with the Polish Act of 12 July 2024 — Electronic Communications Law (Prawo komunikacji elektronicznej) and the GDPR. Detailed rules on the use of cookies — including the list of cookies used, their retention periods and information on how to manage them — are set out in the Cookies policy, which forms an integral part of this Policy.

§ 12. Changes to the policy

The Controller reserves the right to amend this Policy — in particular in the event of changes in legislation, in the scope of the Controller's activities, or in the technologies used in the Site. The current version of the Policy is available at all times in the Site at https://ltfadvisers.com/en/privacy-policy.html.

This Policy is the intellectual property of Kancelaria LTF Sp. z o.o. Advisers Group and has been prepared on the basis of the law in force as at the date of its adoption. In the event of any discrepancies between the Polish-language and English-language versions, the Polish version shall prevail.

LTF Advisers Group

Kancelaria LTF Sp. z o.o. — since 2010 we have designed and implemented succession plans for families, entrepreneurs and companies across Poland.

Site
  • About
  • Our approach
  • Services
  • Team
  • Contact
Legal
  • Privacy policy
  • Cookies policy
  • Terms of electronic services
Contact
  • biuro@ltfadvisers.com
  • +48 535 643 601
  • ul. Belwederska 10/17
    00-762 Warsaw, Poland
© 2026 Kancelaria LTF Sp. z o.o. Advisers Group. All rights reserved. Wersja polska