Regulations for the Provision of Electronic Services by PKO Bank Polski S.A. in the area of Open Banking by PKO Bank Polski S.A.
§1 Preliminary provisions
These Rules for the provision of services by electronic means by PKO Bank Polski S.A. on the Internet site maintained on the developers.pkobp.pl domain (hereinafter referred to as „Rules”), constitute the rules for the provision of services by electronic means within the meaning of the Act of 18 July 2002 on the provision of services by electronic means.
§2 Definitions
The terms used in the Rules shall mean:
- PKO Bank Polski API, PKO BP API, API - application programming interface maintained by the Bank.
- eIDAS - Regulation (EU) No. 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC.
- User Account - a unique profile of a User registered in the Developer Portal, enabling him/her to access the Portal resources made available to him/her.
- PKO Bank Polski, Bank - Powszechna Kasa Oszczędności Bank Polski Spółka Akcyjna with its registered office in Warsaw at Świętokrzyska 36, 00-827, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Department of the National Court Register, under the number KRS 0000026438, NIP: 525-000-77-38, REGON: 016298263; Share capital (paid-up capital): 1 250 000 000 PLN.
- Developer Portal, Portal - a website intended for professional entities, available at www.developers.pkobp.pl, allowing the use of services provided electronically listed in §3 sections 1 and 2, provided by the Bank, available through the Portal.
- Product - a solution that allows access to some of the Bank's IT resources, including through the API of PKO Bank Polski. Information about available Products and terms of use are available on the Portal.
- PSD2 - Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC, 2013/36/EU and Regulation (EU) No. 1093/2010 and repealing Directive 2007/64/EC.
- Rules- these Rules for the provision of services electronically by PKO Bank Polski through the Developer Portal.
- GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons in relation to the processing of personal data and on the free flow of such data and repealing Directive 95/46/EC.
- RTS - Commission Delegated Regulation (EU) 2018/389 of November 27, 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open communication standards.
- Test environment or sandbox - a dedicated IT environment enabling testing of selected functionalities based on the API of PKO Bank Polski.
- Service provided electronically - services provided through the Developer Portal of PKO Bank Polski listed in par. 3 sec. 1 and 2.
- User - a natural person, a legal person or an organizational unit without legal personality that uses the resources and services of the Portal, including an unregistered User.
- Registered User - User who has registered and activated a User Account on the Portal.
§3 Services provided electronically by the Portal
The Bank, via the Developer Portal, allows the User, without registration, access to:
a. Information about Products.
b. Interface availability reports under PSD2 services.
c. Abbreviated technical documentation of PSD2 services.
d. Educational content regarding the Products.
The Bank requires registration of a User Account and login to the Portal to access:
a. Contact with the Bank related to the operation of the PKO BP API.
b. Additional information about selected Products offered through the Portal.
c. Full technical documentation of PSD2 services.
d. Test environments (sandboxes).
e. Educational content on the Products for Registered Users.
Access to test environments (sandboxes) of services resulting from the RTS and their full documentation requires the presentation of a certificate confirming the authorization to provide payment services or confirmation of submission of an application to the competent supervisory authority for their granting.
The Portal is not intended for use by consumers.
§4 Terms of the Portal use
By using the Portal, the User acknowledges that the Portal is intended for entrepreneurs in connection with their business activities.
a. Registration of a User Account in any other capacity may result in limited access to the content presented on the Portal.
b. Access to Payment Services Products, including PSD2 Products, is limited to entrepreneurs with the appropriate authorization from the supervisory authority.
Access to services listed in §3 section 1 and section 2 letters a., b. and e. is also allowed to natural persons, in direct connection with the professional activity performed by these entities.
The content available on the Portal does not constitute an offer within the meaning of the Civil Code, unless expressly stipulated otherwise.
Upon the commencement of the use of the Portal, an agreement is concluded for the provision of services in the form of access to the Developer Portal for Users other than Registered Users, under the rules specified in the Rules.
At the moment of registration and activation of the User Account, an agreement for the provision of services in the form of access to the Developer Portal for Registered Users is concluded, on the Rules specified in these Regulations.
Access to the data made available through the API of PKO Bank Polski may involve the need to meet the requirements set forth in separate regulations, including in particular the provisions of the eIDAS Regulation and the RTS.
Access to the PSD2 test environment involves the need to present a valid qualified seal certificate compliant with ETSI TS 119 495.
The Bank shall be entitled to unilaterally amend the Rules at any time. Any changes to the Rules are effective from the date of their publication on the Portal's website in the form of a consolidated text. Changes to the Rules will be communicated by e-mail to all Users who have an active User Account.
The Bank reserves the right to restrict, replace, remove or change at any time the function, structure or any other aspect of the Portal, software, PKO BP APIs or the content of the Portal without prior notice to the Users, unless otherwise specified by law. The User is obliged to stop using the Portal and delete his/her User Account if he/she does not accept the changes, as further use implies acceptance of the changes. The changes introduced by the Bank, referred to in the preceding sentence, will not cause the shutdown of the Portal and the Services to the extent that their operation is required by universally applicable regulations.
Both the Portal as a whole and the individual elements of its content are subject to the protection provided by law, in particular, the Acts: Act of February 4, 1994 on Copyright and Related Rights; Act of July 27, 2001 on Protection of Databases; Act of April 16, 1993 on Combating Unfair Competition; and Act of June 30, 2000 on Industrial Property Law.
The Users have the right to use the Portal solely for the purpose of contacting the Bank in the area of services, and to use the services, only within the functionalities provided by the Bank, in accordance with the technical specifications published and updated by the Bank within the Portal. The User undertakes to use the Portal in accordance with the specifications current as of the date of the User's use of the Portal. Any other use of the Portal is prohibited and constitutes a material violation of these Rules by the User, in particular:
a. an attempt to use real payment service user data in test environments,
b. an attempt to use eIDAS certificates to which the Participant does not have authorization,
c. an attempt to access the PKO sandbox or API using elements to which the Participant is not authorized
d. an attempt to generate traffic that threatens the stability of the test environment.
The technical condition for the use of the Portal is the possession of Internet access and an e-mail account by the entity requesting access to the services available after registration.
The use of the Portal is possible through the web browser Microsoft Edge, Chrome 70, FireFox 60.3 (or higher versions) and when JavaScript and cookies are enabled in the user's web browser and through the mobile application.
The Portal may use the following technologies: JavaScript, XML, DHTML, cookies, HTML, CSS, SSL. All sub-pages of the Portal may require login or use of encrypted SSL transmission protocol.
The Bank reserves the right to introduce technical interruptions in the operation of the Portal, during which some or all of the functionalities will not be available, without notifying you each time. Technical interruptions do not constitute grounds for complaint.
It is forbidden to access the Portal and its content in an automated manner, consisting, in particular, in the use of bots, indexing robots and other automated tools that allow the use of the Portal without the User's intervention. Automated access is allowed only if the Bank gives its written (under pain of invalidity) consent.
The User is prohibited from engaging in activities to the detriment of the Portal, the Bank or other Portal Users.
If third parties are allowed to use the Portal in accordance with the provisions of the Rules, the User shall be liable for the acts and omissions of such persons as for his/her own acts and omissions.
Introduction of unlawful content in the Portal by the User is not permitted.
The User may use within the Portal only the data and content to which he/she is entitled, unencumbered by the rights of third parties.
§5 Access to the Products
- Product selection is possible from the User's Account at any time after registration.
- The User may select more than one Product.
- If the User selects a Product for which the User does not have contractual or legal rights, the Bank may deny access.
- Failure to select Products results in access limited to basic information and to the area dedicated to contacting the Bank. The same effect is carried by the Bank's denial of access to Products.
§6 Registration process and login
Use of all services requires prior acceptance of the content of the Rules and registration on the Developer Portal. The User is obliged to use current and complete data to which he/she has full rights.
The use of false, outdated, incorrect or incomplete data or data of other persons shall be grounds for refusal to conclude or immediate termination of the agreement concluded between the User and the Bank.
Within the framework of registration, the User shall provide the Bank with his/her basic data:
a. First and last name
b. Contact telephone number
c. Company e-mail address or private address, if the registration of the User Account is not related to the User's business duties
d. Name of the company/organization to which the User belongs and its address
After registering on the Portal, the User will receive an e-mail to the e-mail address he/she indicated in the registration process confirming the establishment of the User's account, together with an activation code allowing activation of the account.
In the event of a change in registration or contact data, the User agrees to immediately inform the Bank by updating them.
Any notices sent by the Bank under the Rules shall be deemed effectively delivered if sent to the last mailing address (including e-mail address) known to the Bank and provided by the User in the registration process or in the User panel.
The Bank reserves the right to send messages related to the functioning of the Portal to the e-mail address provided, in particular regarding changes made to the Rules, Services and Products, as well as notifications related to the User's Account, including, but not limited to, responses to requests or notifying of the need to take action.
§7 Test environments
- Test environments, fictional data, tools and other content are provided and available as shown on the Developer Portal. The Bank makes every effort to make them work properly, but does not assure that they will meet the User's specific requirements.
- The User agrees that the Portal must be used for its intended purpose and without violation of the law. The User is not authorized to trade or share user identification elements (APIKEY, logins, passwords, certificates, etc.). and shall be independently liable therefor.
- The test environment is available to Users who are authorized by the competent regulator to provide payment services under PSD2 or Users who have applied for such authorization. Access to this environment is granted upon positive verification by the Bank that it has the required authorizations.
- An application for access to the test environment submitted by an entity other than those specified in paragraph (3) shall be considered by the Bank on an individual basis. In such a case, the use of services may take place under separate, individually presented rules.
§8 Changes in documentation
- Bank zastrzega sobie prawo do dokonywania zmian w dokumentacji technicznej, która jest dostępna za pośrednictwem Portalu Developera.
- Zmiany w dokumentacji produktów wynikających z PSD2 dokonywane są w sposób i terminach wynikających z obowiązujących przepisów prawa.
§9 Refusal and blocking of access
- The Bank reserves the right to deny or block access to the Portal in whole or in part for legitimate reasons related to security of access to these services or due to suspected unauthorized use of access to the Portal and/or the Service.
- The Bank, via e-mail, shall inform the User of the blocking of access to the Portal and/or the Service immediately after this action, unless the communication of such information would be unreasonable for security reasons or prohibited by law.
- The blocking shall be maintained until the reason for which it was performed ceases to exist and shall be removed at the request of the User.
§10 Termination of the Agreement for use of the Portal
The provision of Services by the Bank within the Portal is perpetual, with the User having the right to terminate the Agreement at any time by deleting the User's Account, which results in loss of access to the part of the Portal for Registered Users, including settings, Products and existing communication with the Bank.
Subject to the other provisions of the Rules, the Agreement may be terminated by the Bank immediately for reasons that are important to the Bank, including, in particular, when:
a. The User violates the provisions of the Rules, in particular § 4 section 10, § 6 section 2 or § 7 section 2,
b. the User is found to have provided false, outdated, incorrect or incomplete data or statements, or data of other persons,
c. The User undertakes actions aimed at changing the content of the service or other modifications that may disrupt its operation,
d. the User's actions or omissions adversely affect the Bank's good name or otherwise materially harm the Bank.
Termination of the Agreement by the Bank shall result in the blocking of access to the User's Account.
The Bank reserves the right to discontinue the Portal at any time, without any compensation to the Users.
§11 Final provisions and disclaimers
- These Rules are available at https://developers.pkobp.pl/en/terms, in a manner that allows Users to obtain, reproduce and record their content by printing or saving on a carrier at any time.
- All information and content presented on the Portal is for informational purposes only. The contents found on the Portal and the manner of their transmission do not constitute an offer within the meaning of the Civil Code, as well as activities in the field of providing legal assistance, tax advice, investment advice or any other advice. The Bank does not guarantee or make any representations as to the functionality of the Portal, the absence of any errors within the Portal or the existence of any deficiencies within the Portal. Any liability of the Bank in this regard is excluded to the extent permitted by applicable regulations.
- Making any decisions, including business or investment decisions, on the basis of the content on the Portal is done at the User's own risk, and any liability of the Bank (including contractual and tort liability) for the consequences of such decisions is hereby excluded. Under no circumstances should the content on the Portal be considered an express or implied statement or assurance of any kind made by the Bank or persons acting on behalf of the Bank.
- To the extent permitted by applicable law, the Bank's liability for any damage that has occurred and may occur in connection with the content presented on the Portal and in connection with the User's use of the Portal is hereby excluded, regardless of the direct or indirect cause of such damage, as well as regardless of the contractual or tortious regime of liability.
- The Bank's liability for temporary or permanent unavailability of the Portal for any reason is hereby excluded.
- The User declares that he/she is aware of the limitations of the above provisions, as well as that he/she is aware of his/her sole responsibility for decisions made on the basis of data, including test data received through the Portal.
- In all matters not covered by these Rules, the provisions of generally applicable Polish law shall apply, in particular the provisions of the Civil Code, the RODO Ordinance and the Act of 18 July 2002 on the provision of electronic services.
- The supervisory authority overseeing the Bank's activities is the Financial Supervision Commission. A user may file a complaint with the Financial Supervision Commission against the Bank's activities if the activity violates the provisions of the law.
- The language used in the Bank's relations with the User shall be Polish and English, while Polish shall remain the leading language.
- The law applicable to the settlement of disputes arising in connection with the provision of services by the Bank shall be Polish law.
- Written correspondence regarding the Portal, Products and services should be addressed to the Bank's address, i.e.: Formacja Otwartej Bankowości, Powszechna Kasa Oszczędności Bank Polski Spółka Akcyjna, 89 Chmielna Street, 00-805 Warsaw.
- The court having exclusive jurisdiction to hear disputes arising from the application of the Rules and agreements concluded on the basis thereof shall be the common court with jurisdiction over the registered office of the Bank.
- The User may file complaints regarding the use of the Portal.
- Via the Portal, the Bank does not accept complaints related to the provision of payment services.
- Complaints may be filed by sending a message through the contact form or in writing to the Bank's mailing address. If it is not possible to register a User Account and use the contact form, the complaint should be reported to the email address: kontakt.api@pkobp.pl. The email address mentioned in the preceding sentence is also an electronic address within the meaning of Article 5 Section 2 item 1 of the Act of July 18, 2002 on electronic service provision.
- The complaint should contain data enabling identification of the User making the complaint and a description of the event giving rise to the complaint. If the data or information provided in the complaint needs to be supplemented, the Bank shall request the User to supplement it in the indicated scope before the complaint is considered.
- Complaints will be considered within 30 days from the date of receipt by the Bank of a properly submitted complaint (containing the required elements and not requiring supplementation).
- The User will receive information on the manner of processing the complaint by electronic correspondence to the e-mail address provided in the complaint.
- These rules have been drafted in Polish and English version. In case of any discrepancy or conflict Polish version shall prevail.
§12. Personal data processing
- If personal data is processed by the Bank in connection with the use of the Developer Portal, the provisions of the GDPR shall apply. The Bank hereby informs that it is the administrator of Users' personal data. The personal data is processed in order to realize the legitimate interest of the administrator, i.e. to test by the Users the interoperability of their software and applications with the Bank's systems, and to enable the Users to use the technical support referred to in §3.2.a. Provision of personal data is voluntary, but necessary in order to use the Portal.
- Detailed information on the rights related to the processing of personal data by the Bank is available at https://www.pkobp.pl/rodo/.