PeselCheck PESEL Check
Services About Help Contact
Legal

Data Processing Agreement (summary)

This page summarises how PeselCheck processes personal data on behalf of landlords who use the platform to manage tenants. The full DPA is available on request from legal@peselcheck.pl.

1. Roles

For personal data of tenants that a landlord uploads or collects via the platform (e.g. invited tenants), the landlord is the controller and PeselCheck is the processor. For data PeselCheck collects for its own account management, security and billing, PeselCheck is the controller.

2. Scope and purpose

Processing is limited to providing the PeselCheck platform: account management, identity verification, consent-managed data sharing, rating aggregation, invitations, rental-portfolio management and related operational features.

3. Sub-processors

PeselCheck engages the following sub-processors: (a) Veriff OÜ (Estonia) β€” identity verification (KYC); (b) hosting provider in the EU (to be disclosed); (c) transactional e-mail provider in the EU (to be disclosed). Each sub-processor is bound by a data-processing contract and appropriate safeguards.

4. Security measures

PESEL numbers are encrypted at rest with AES-256 and looked up via keyed HMAC-SHA256. Passwords are hashed with bcrypt. Access is role-based and audited. All data in transit is transmitted over TLS. Admin impersonation is logged. Sub-processors are vetted for equivalent security.

5. Data-subject rights support

PeselCheck provides a self-service data export (Art. 15 GDPR) and deletion (Art. 17 GDPR) in the account settings. On written request PeselCheck assists landlords with their data-subject obligations.

6. Breach notification

In case of a personal data breach, PeselCheck notifies affected controllers without undue delay and within 48 hours of becoming aware of the breach.

7. Audit

Landlords may audit compliance upon reasonable written notice, no more than once per year, during business hours and subject to confidentiality.

8. Termination

Upon termination, personal data is deleted or returned within 30 days, save where retention is required by law.

Last updated: 2026-04-24 Β· Back to home