Privacy policy
Effective from:
The binding version of this document is the Slovak one at /sk/ochrana-osobnych-udajov/. This English text is a courtesy translation; in case of any discrepancy the Slovak version prevails.
This document describes what personal data we process while running Faktura365, why, on what legal basis, and who we share it with. It is written to be read, not to put you off.
Who we are
The controller is Volodin s. r. o., Račianska 1579/88B, 831 02 Bratislava, Slovakia, company ID (IČO) 57105961, entered in the Commercial Register of the Municipal Court Bratislava III, section Sro, insert no. 190122/B.
For anything about personal data, write to info@faktura365.sk. We have not appointed a Data Protection Officer — the obligation does not apply to us.
Two different roles — and the difference matters
For your account data we are the controller: we decide why we need it.
For the data you type into invoices — your customers, their addresses and the amounts — YOU are the controller and we are the processor. We only store it and show it back to you; we do not use it for anything of our own and we do not pass it on. The terms of that processing are in article 9 of the Terms of Service.
Account data we process
- Email — signing in, verifying the address, resetting the password and service messages. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- Password, only as an irreversible hash (PBKDF2) — signing in. Performance of a contract.
- First name, last name, phone, interface language — prefilling documents and setting up the interface. Performance of a contract.
- Profile picture — only if you sign in with Google, and it comes from Google. Performance of a contract.
- Number of visits, the date and time of the last visit, and the account creation date — security, support and abuse prevention. Legitimate interest, Art. 6(1)(f) GDPR.
- The date you accepted the terms of service and this policy, together with the identifier of the wording you accepted — performance of a contract, and proof that we informed you.
- Your IP address when signing in, registering or resetting a password — limiting the number of attempts, that is, protection against password guessing and against mail being sent to addresses that are not yours. All we keep is a counter of attempts tied to the address; it is valid for at most an hour, and its row is deleted the next time the table is swept. The same kind of counter, this time without being written to the database, limits company lookups in the registers. Legitimate interest, Art. 6(1)(f) GDPR.
Data you enter yourself
Your companies, customers, price-list items, bank accounts, invoices and the payments against them. We keep them for as long as your account exists. We do not use them for advertising or profiling and we do not pass them to third parties.
Email we send you
Service messages — a welcome message or address verification when you sign up, password reset, notices about your account and about material changes to these documents — go to every user. They are part of the service; the legal basis is performance of a contract, Art. 6(1)(b) GDPR, and the only way out of them is to delete the account.
A one-off offer of help — if your email address is confirmed, we send you at most one such email: on a weekday morning, two to six days after you sign up if your account holds no document yet, not even a draft, or seven to twelve days after you sign up if it holds exactly one. In it we ask whether something is missing or not working. All we check is how many documents there are, never what they contain. The legal basis is our legitimate interest in the service being usable, Art. 6(1)(f) GDPR; if you would rather not receive it, write to info@faktura365.sk.
The newsletter — invoicing tips, changes to the rules and product news, roughly once a month — goes only to people who explicitly ask for it by turning the switch on during sign-up or in the account settings. The legal basis is your consent, Art. 6(1)(a) GDPR together with § 116 of Act No. 452/2021 Coll. on electronic communications. Consent is not a condition of using the service.
You can withdraw that consent at any time — with the switch in your account settings or the link at the bottom of every such email. Withdrawal works for the future and does not affect the lawfulness of what we sent before it.
We keep a record of your answer: what you answered, when, where from (sign-up, settings, the unsubscribe link), in which language, and which version of the wording you were shown. Without it we could not demonstrate that we had consent, which is what Art. 7(1) GDPR requires of us. We do not store your IP address or details of your browser alongside it. The record lives for as long as your account does and is deleted with it.
Documents you send to your own customers — if you choose to email a document, Resend delivers it to the address you enter. The email carries either the document as a PDF or a link to it, plus your short note if you add one. It is sent in your company's name, and the customer's reply goes to the email address on the document or, where there is none, to your account's email address — so the customer will see that address. We do not store the customer's address beyond what is already on the document itself; all we keep in your account is a count of the emails sent this way. In this relationship you are the controller and we are the processor — the same role the "Two different roles" section above describes.
A link to a document is signed and has no expiry: anyone holding it can open it without an account with us, so that the document is still there a year later when your customer's accountant needs it. That is why you can cancel it at any time with "Cancel the link" on the document; cancelling stops every link to that document you have handed out so far.
The invoice generator without an account
The finished invoice is produced inside your own browser. Neither the document nor its contents is sent to our server, and we do not store it.
The invoice you are still working on is kept in your browser's local storage, so that closing the page does not lose it. It stays on your device and is not sent anywhere. After 30 days we stop using it — the next time the generator is opened it is deleted; sooner than that, the button that clears the form removes it, as does clearing the site's data in your browser. Until you open the page again, it stays in your browser.
There is one exception: company lookup. If you have the details filled in from a register, the query (a name or an IČO) passes through our server — see the next section.
If you decide to create an account from the generator, we carry the draft into the sign-up form in the part of the address that is never sent to a server, and store it only once the account exists — at which point it becomes ordinary account data. Without that step of yours, no data of yours and nothing from the document reaches us.
When you download the finished invoice, we add one to a count of our own — all we follow is how many documents the generator has produced. We store no name, no cookie and nothing else that could tie that counter to you or to what the document says. Your IP address — as with any request to a website — is seen by our server and used only to limit abuse; it is not written to the database.
Company lookups in the registers
When you have a company or a customer filled in from a register, we send your query to public sources of Slovak company data: the Register of Legal Entities (RPO) of the Statistical Office, the Commercial Register, and the OpenData service of the Financial Administration for checking VAT-payer status.
Searching by name is served by ORSF (orsf.sk) — a private project, its server in Germany, which republishes those same state registers as a search index. It is not a state register and we would rather say so plainly; we use it because it answers a name in a fraction of a second instead of several. The address and the register entry that get printed on the invoice we ask RPO for directly in the first place; when RPO does not answer, we fill them in from ORSF — otherwise the document would go out missing a mandatory particular. So do check the prefilled details before you issue a document: they are your responsibility.
Only what you typed leaves (a name or an IČO), and it leaves from our server — those sources receive neither your IP address nor anything about your account. We use the answer to prefill the form and we do not store the queries against your account.
Suggestions for improvement
If you send us a suggestion from inside the application, it reaches us by email together with your email address and your account identifier — otherwise we could not reply to you. Resend delivers that email to us and the message then stays in our mailbox, which is operated by Google, for as long as the subject is open. Legitimate interest in improving the service and in answering you, Art. 6(1)(f) GDPR.
When something in the application breaks
So that we learn about a fault before you have to tell us, we send a report about it to Sentry. It carries a technical description of the error and the place in our code, the address of the page it happened on, the version of the application, the type of your browser and operating system, and the identifier of your account if you are signed in.
We do not put your name, your email address or the contents of your invoices into the report, and links that open something by themselves — address verification, password reset, signing in with Google, and a link to a document shared with a customer — are stripped out of the address before it is sent. Storing IP addresses is switched off in Sentry. Reports are kept for 30 days and then disappear.
Legitimate interest in keeping the service working and in being able to fix a fault, Art. 6(1)(f) GDPR.
Who we share data with
Our processors, and nobody else. We do not sell data and we do not hand it to advertising networks.
- Cloudflare, Inc. — hosting of the site, the application and the database. EU/US, Standard Contractual Clauses.
- Resend (Plus Five Five, Inc.) — sending service email (the welcome message, address verification, password reset, the one-off offer of help), delivering your suggestion for improvement to us, and delivering the documents you send to your own customers. US, Standard Contractual Clauses.
- Google Ireland Ltd. — signing in with Google, if you use it, the Google sign-in button shown on the pages of this site, audience measurement, measuring how well our advertising works, and the mailbox your suggestions for improvement arrive in. EU/US, EU-US Data Privacy Framework.
- Functional Software, Inc. (Sentry) — reports about errors in the application. Processed in the EU (Germany).
Cookies and local storage
Strictly necessary, without which the service does not work: f365_session (you are signed in), f365_google_state (CSRF protection for Google sign-in), f365_google_widget (the same for the Google sign-in card on this site; it is created only after you press its button and lasts 5 minutes), f365_active_company, f365_locale, f365_theme (your interface settings) and f365_consent (your answer to the cookie bar, kept for 6 months).
Besides cookies we use your browser's local storage (localStorage and sessionStorage) for small things that need not travel to a server: the language and theme you picked, the units of measure you used last (f365_units), the constant symbol you used last (f365_constant_symbol), whether the optional parts of a form are unfolded, the details prefilled into your next invoice (f365_invoice_issuer_details, f365_invoice_client_details), the countdown before a verification email can be sent again (f365_verify_resend_until), the fact that you dismissed the Google sign-in card (f365_google_widget_closed, until you close the browser tab), a one-off marker that stops a page reloading in a loop after an error (f365_skew_reload), and the draft invoice in the generator. All of it stays on your device, none of it is sent to us, and clearing the site's data in your browser removes it.
Measurement of visits and of advertising: Google Analytics 4 and Google Ads in Consent Mode v2. Until you answer the bar, consent is not granted: in that state no cookie is stored, you are not identified, and Google receives only anonymous signals about the visit. If you do grant it, Google Analytics stores its own cookie and joins your visits into one session, and Google Ads stores the identifier of the ad click (the _gcl_* cookies) so that we can tell which campaign brought a new sign-up.
From advertising we measure a single event — that a new account was created. We do not send Google your email, your name or anything else that could identify you (enhanced conversions are switched off), and we do not track what you do inside the application. We do not use personalised advertising: the ad_personalization signal is always denied, so your data does not become advertising audiences or remarketing lists.
Signing in with Google on the page itself: under the header we show a small card with a button for signing in with your Google account. For that button to be drawn, your browser requests a script from Google (accounts.google.com), and Google may store cookies of its own in the process. This is neither measurement nor advertising, it serves sign-in alone, and that is why we do not make it conditional on your answer to the cookie bar: § 109 of Act 452/2021 Coll. requires consent for storage that is not necessary for a service you asked for yourself. Data from your Google account (email, name and profile picture) reaches us only when you press the button — until then we receive nothing about you from Google. You can dismiss the card at any time with its ✕.
Your answer covers both this site and the application (the cookie is set on the .faktura365.sk domain). You can change it at any time by clearing cookies in your browser settings — the bar will then ask again.
Where you came from is worked out WITHOUT a cookie and without storing anything in your browser. If you arrive from a link carrying campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content, or a click identifier such as gclid, msclkid or fbclid) or from another site, we pass that along in the addresses of our own links (the src parameter) and store it only if you create an account — as a detail of that account. It describes the visit, not you: no name, no email, nothing that identifies you. If you do not create an account, nothing is stored at all. It answers one question for us — which of our pages and campaigns bring new users.
After a sign-in or a sign-up we set a technical cookie, f365_ga_event, for one minute. It carries a single fact to the browser — that the sign-in succeeded — because the sign-in itself is completed on the server and the page would otherwise never learn of it. It contains no personal data and is deleted once it has been read.
How long we keep it
Account data and everything you created in it, for as long as the account exists. When you delete the account, all of it goes at once — invoices, customers and numbering counters included; we keep no "just in case" backups.
One-time tokens (email verification, password reset) live for hours and are deleted once they expire.
Counters of failed sign-in attempts — tied to an IP address and to a hash of the email that was typed — are valid for at most an hour and are swept away as later attempts come in.
The counter of documents you have emailed — tied to your account identifier — is valid for 24 hours and exists only so that the daily sending limit can be kept. It is deleted with your account.
The record of your newsletter answer, for as long as the account exists; it is deleted with it.
A link to a document shared with a customer, until you cancel it or delete the document or the account.
Your rights
You have the right of access to your data, and rights to rectification, erasure, restriction of processing, portability, and to object to processing based on legitimate interest. Write to info@faktura365.sk — we answer within one month.
Where processing rests on consent (the newsletter, measurement of visits and advertising), you have the right to withdraw that consent at any time, without affecting the lawfulness of the processing that took place before you did.
If you believe we are processing your data unlawfully, you may lodge a complaint with the Slovak Data Protection Authority (dataprotection.gov.sk).
Automated decision-making
We make no automated decisions about you and we do not profile you.
Changes
The effective date of this version is shown above. We will tell you about material changes by email at the address in your account.