Safety information
Information
on specific risks associated with the use of electronically supplied services
Effective as of: 9 February 2026
| Service Provider: | Rafcom sp. z o.o., with its registered office in Reguły (05-816), at ul. Stanisława Bodycha 97, Tax Identification Number (NIP): 5342663114, whose company records are kept by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under KRS number 0001029234, with a share capital of PLN 500,000 |
| Service Recipient: | A person or entity using the Rafcom B2B Platform |
| Service: | Rafcom B2B Platform |
| Document version: | 1.0 |
| Legal basis: | Article 6(1) of the Polish Act on the Provision of Electronic Services of 18 July 2002 |
| Security contact: | alert@rafcom.waw.pl |
Legal basis and purpose of this information
This information is provided in order to fulfil the obligation to give the Service Recipient access to current information about specific risks associated with the use of electronically supplied services pursuant to Article 6 of the Polish Act on the Provision of Electronic Services of 18 July 2002 (consolidated text: Journal of Laws of 2024, item 1513).
Specific risks
The use of online services involves, in particular, the following risks:
• Malware, including viruses, trojans, spyware and adware, which may result in data theft, unauthorised control of the device or disruption of the service.
• Phishing and other forms of social engineering involving attempts to obtain login credentials or payment information fraudulently or to induce a User to perform an undesired action, such as clicking a link or installing an application.
• Impersonation of the Service Provider or a User (spoofing), including fraudulent emails or text messages, fake login pages and fake social media profiles.
• Interception of communications or session data, including Man-in-the-Middle attacks, particularly when using public or unsecured Wi-Fi networks.
• Unauthorised access to an account, for example as a result of using a weak password, passwords leaked from other services, credential-stuffing or brute-force attacks, or leaving a device unlocked.
• Attacks involving the takeover of a telephone number or authentication channel, such as SIM swapping or email account takeover, which may allow account security measures to be bypassed.
• Ransomware, involving data encryption and a ransom demand, and other incidents resulting in loss of access to data or systems.
• Loss of data confidentiality resulting from User errors, such as sharing a screen, sending data to the wrong recipient or storing passwords in unsecured locations.
• Exploitation of security vulnerabilities in the User’s operating system, browser, plug-ins, applications or device, particularly when software is not kept up to date.
• Attacks affecting data integrity, such as modifying the content of submitted forms, replacing bank account numbers or manipulating transactions, including payment redirection.
• Attacks affecting service availability, including network overload or DDoS attacks, which may result in interruptions or restricted functionality.
• Malicious browser extensions, plug-ins or applications obtained from untrusted sources, which may track activity and capture data.
• Service disruptions caused by factors attributable to the User, such as device failures, Internet access interruptions, incorrect configuration or software conflicts.
Security recommendations for the Service Recipient
To reduce these risks, the following measures are recommended in particular:
• Use an up-to-date operating system, browser and applications, and install updates and security patches regularly.
• Use strong, unique passwords and, where available, multi-factor authentication (MFA).
• Do not click links or open attachments from untrusted sources. Verify the website domain and HTTPS certificate in your browser.
• Be cautious about requests for login credentials, SMS codes, payment information or bank transfers. As a general rule, the Service Provider does not request such information in messages.
• Use trusted networks and avoid logging in through public Wi-Fi without additional protection, such as a VPN.
• Log out after completing a session, secure your device with a password or biometric authentication and do not allow unauthorised persons to use it.
• Use up-to-date security software, such as antivirus or EDR software, and a firewall, and make backup copies of important data.
• Review application, extension and plug-in permissions and install software only from official sources.
• Regularly monitor account activity, including login history and notifications. If you suspect an incident, change your password immediately and contact the Service Provider.
Reporting suspected misuse and security incidents
If you suspect unauthorised access to your account, a data leak, a phishing attempt impersonating the service or another security incident, contact Rafcom immediately using the channel specified under “Security contact”.
You should also change your password immediately and enable MFA where available.