Privacy Policy
1. Data controller
The controller of skanfirmy.pl is Bartosz Kuć (sole proprietorship), tax ID (NIP) 7393933151. Contact: [email protected].
2. What data we process
The site processes identification numbers you enter yourself: tax ID (NIP) and KRS number (company verification) and tax ID (NIP) or PESEL (tax micro-account generator). Tax ID and KRS number are company identifiers. PESEL is personal data, but in the micro-account generator it is processed entirely locally in your browser — it is never sent or stored anywhere. We do not collect browsing history, location, login data, or any information identifying the user.
3. How queries work
In six of the interactive tools (VAT White List, KRS, account check, tax micro-account, PKD, interest calculator), the number you enter is sent directly from your browser to the official, public APIs of government registers:
wl-api.mf.gov.pl— VAT Payers Register (Ministry of Finance),api-krs.ms.gov.pl— National Court Register (Ministry of Justice).
For these tools we have no proxy server of our own — we do not intercept or store your queries. The tax micro-account generator sends no queries at all — the number is computed entirely in your browser.
The exception is two public endpoints: skanfirmy.pl/nip/{number} and
skanfirmy.pl/vies/{country}/{number} (EU VAT verification in the European Commission's
VIES system), meant to be read by search engines and AI agents and as the
backend for the VIES tool — here the query to the registers is made by our
server function (Netlify Functions), not your browser. The response is temporarily
cached on Netlify's CDN (max. 24 hours) to avoid overloading the daily query limits shared
by all visitors. We do not keep our own, persistent database or query log — beyond
Netlify's standard infrastructure logs. For sole proprietorships, the "name" field
from the VAT Register may be a natural person's first and last name; processing here
happens under the same legal basis as in section 6 (legitimate interest — verifying a
business counterparty), for no longer than the cache period noted above.
skanfirmy.pl/mcp works the same way — an MCP (Model Context Protocol) server
letting AI agents call our tools directly. Same server function, same source registers,
same lack of persistent query logging — the only difference is
technical: responses to POST requests are not cached on the CDN (standard
behavior for this kind of request), so every call reaches the relevant
register directly.
4. Local storage (cache)
We save query results only locally in your browser
(localStorage) for up to 24 hours, to reduce the number of
queries to the registers. This data is never sent anywhere; you can delete it at any time
by clearing the site's data in your browser.
5. No tracking
We do not use tracking cookies, analytics, or advertising tools. We do not share any data with third parties.
6. Legal basis (GDPR)
The site makes it easier to access public government registers and performs calculations locally in the browser. We do not collect users' personal data on any server — for company verification, processing identifiers (tax ID/KRS number) is based on legitimate interest (Article 6(1)(f) GDPR): verifying a business counterparty.
7. Changes
We may update this policy. The current version is always available at this address.