Notice for counterparties — Ksefly
Version 1.0 · in force from ⟨TO CONFIRM: publication date⟩
Who publishes this: developNET Maciej Matysiewski (brand: develop.NET), ul. Nowowiejska 6/6, 00-649 Warszawa, Poland. NIP 1182238190, REGON 521446646 — the maker of the Ksefly app. Data protection contact: privacy@ksefly.app ⟨TO CONFIRM: that the privacy@ksefly.app mailbox exists and receives mail. This entire document sends people to that address; publishing it with a bouncing mailbox is worse than giving no address at all.⟩
The Polish version at ksefly.app/kontrahenci is the authoritative text; where the two differ, the Polish version controls.
You are reading this because a business you traded with uses Ksefly
Ksefly is an app for Polish businesses that issue and receive invoices through the National e-Invoicing System (Krajowy System e-Faktur, KSeF). We are not a government body and we are not affiliated with the Polish Ministry of Finance.
If you issued an invoice to someone, or someone issued one to you, and that other party uses Ksefly, then your invoice data — name, address, tax number (NIP) — reached our system. You never gave it to us and you have most likely never heard of us. That is exactly why this notice exists: GDPR art. 14 requires it.
We did not create an account for you. We do not send you marketing. We do not sell your data.
What to do about it — right now
| Your question | Who to write to |
|---|---|
| You want data corrected or erased, you want to object, or you want to know what exactly was recorded about you on an invoice | The business you traded with. They decide about that data — we only run the tool for them. See §3. |
| You want to know what we ourselves do with it — the AI-written invoice description, the payment record, our technical logs | privacy@ksefly.app. For those we are the controller (§3 and §4). |
| You have no idea who to ask | Write to us. We will point you to the right party, and where the matter belongs to your trading partner, we will pass it on. |
To find anything on our side we need your NIP — we can look up an exact match on it. We do not search by name or address.
1. Where we got your data
Not from you. It reached us in three ways:
- From the invoice itself. Either your trading partner issued you an invoice in Ksefly and typed (or pasted from their own address book) your details, or we downloaded the invoice from KSeF — the Ministry of Finance’s system — because that is where the document you issued to them ended up. In the second case the data is exactly what you wrote on the invoice yourself.
- From public registers. When your trading partner checks you in the app, we send your NIP to GUS (the REGON register), to the VAT white list or to VIES. The reply carries your registered details — name, address, REGON, legal form, VAT status, the bank accounts on the white list, and sometimes an e-mail address that GUS holds for you. These are publicly accessible sources (GDPR art. 14(2)(f)).
- From Stripe — only if you paid an invoice through Ksefly (by card on your partner’s phone, or through a payment link). The payment provider then sends us the settlement confirmation.
2. Exactly what we hold about you
2.1. Invoice data
Name (of the business, or your own name if you are a sole trader), address, NIP, invoice number, dates (issue and payment due), net, VAT and gross amounts, currency, the document’s KSeF number, and for a correction also the number and date of the corrected invoice and the reason for the correction.
Plus two things that do not come from the document:
- your trading partner’s note — a field where they can write, in their own words, why they accepted or rejected your invoice;
- a one-line AI-written description of the invoice (“what this invoice is for”) — generated automatically, which we describe honestly in §5.
A fuller copy sits on your trading partner’s device: it additionally holds the invoice line items, the bank account number and the rest of the document’s detail.
What is encrypted and what is not. We store your NIP encrypted. Your name and your address sit in the database as plain text — we do not want this notice to imply more protection than actually exists.
2.2. The contractor book
If your trading partner saved you in their address book, we keep a backup copy of it: name, NIP, country, address, REGON, legal form, VAT status, the private name they gave you, bank account numbers from the white list and e-mail addresses. That book is encrypted on our side.
2.3. The payment record — if you paid through Ksefly
Amount, currency, payment method, wallet type (e.g. Apple Pay), card brand and last four digits, a link to the Stripe receipt, the settlement time and our technical identifiers. This record is not encrypted and — today — is never deleted (§6).
We do not hold your card number, expiry date or CVC. Card data is read on the device by Stripe’s own software and goes straight to Stripe; it never passes through our servers.
2.4. What we do not hold
We hold no password of yours, no location of yours, and no profile of you in any marketing sense. We run no advertising, and we do not track you across other apps or sites — the app contains no third-party analytics SDK and no advertising identifier.
3. Who is responsible for what — and why that matters to you
This is the most important paragraph here, because it decides who you should approach.
For most of this data your trading partner is responsible, not us. They decided to issue or receive an invoice and to use Ksefly to handle it. We store the data and act on it on their instructions — we are their processor under GDPR. In that part they are the controller, and they are the ones who handle your requests (access, rectification, erasure, objection). This covers: storing the invoice and its data, the contractor book, sending the document to KSeF, checks in public registers, and the notifications on their phone.
But some things we decide ourselves — they do not follow from your trading partner’s instruction, and they cannot turn them off. In that part we are the controller:
- the one-line AI-written invoice description — our own product decision; today it is generated automatically for every invoice and there is no switch anywhere that turns it off (§5);
- the payment record in §2.3 — we keep it to settle our commission and to document the transaction;
- our server’s technical logs, needed to keep the service running and to detect abuse.
If any of those three concerns you, write to us directly.
4. Why we process this, and on what legal basis
References are to GDPR art. 6(1).
| What we do | Who is the controller | Basis |
|---|---|---|
| Store the invoice and its data so your trading partner can issue, receive, read and settle it | Your trading partner | They state it. In the nature of things it is usually a legal obligation (point c) — Polish VAT law requires the invoice to name you — and performance of a contract between the two of you (point b). |
| Send the document to KSeF | Your trading partner | As above — the statutory obligation to use KSeF. |
| Check your NIP against GUS, the VAT white list and VIES | Your trading partner | Their tax obligations (point c) and due diligence (point f). |
| Keep the payment record and collect our commission | Us | point f — our legitimate interest in documenting and settling a payment taken through our platform, and in establishing and defending claims. |
| Keep technical logs, detect faults and abuse | Us | point f — keeping the service running and preventing abuse (GDPR recital 49). |
| Have an AI model write the one-line invoice description | Us | ⟨TO CONFIRM: the legal basis. Today the feature runs automatically and without anyone’s consent. To be decided together with §4.1 of the privacy policy: consent (point a) once a switch exists, or legitimate interest (point f) with a documented balancing test. The same gap is recorded in the privacy policy — one decision must close both.⟩ |
Our balancing test, in one sentence: we process business register data that has to appear on the invoice anyway, purely so that the invoice works and the service does not break — we build no profile from it, use it for no marketing, and sell it to nobody.
We make no automated decisions about you that produce legal effects, and we do not profile you within the meaning of GDPR art. 22. The AI writes only a label describing the goods or services; it decides nothing.
5. Who we pass your data to, and where it travels
There is an uncomfortable thing to say here, and we say it plainly.
Your business name goes to an AI model in the United States. To write that one-line invoice description we send Anthropic PBC (USA): the seller’s name, the buyer’s name, the gross amount, the currency and the names of the invoice line items — that is, what was actually bought or sold. This happens automatically for every invoice, and nobody — neither you nor your trading partner — can switch it off today. If the invoice carries a buyer NIP, we also attach up to eight earlier descriptions written for the same pair of businesses, so that similar goods keep the same label. We do not send tax numbers or addresses there. ⟨TO CONFIRM: the contracting entity (Anthropic PBC or an EU entity), the data processing agreement, any zero-retention terms, and the transfer mechanism outside the EEA — standard contractual clauses or another chapter V mechanism. Until that is established we assert nothing here about Anthropic’s own retention.⟩
The other recipients:
| Who | What reaches them | Where | Transfer basis outside the EEA |
|---|---|---|---|
| Microsoft Azure — hosting and database | everything described in §2 | Poland Central (Poland) ⟨TO CONFIRM: the production environment’s region⟩ | no transfer outside the EEA ⟨TO CONFIRM: terms of Microsoft support access from outside the EEA⟩ |
| Anthropic PBC — language model | as above | USA | ⟨TO CONFIRM⟩ |
| Apple (APNs) — push notifications | your name and the invoice amount inside the notification your trading partner receives when you invoice them (when several arrive at once, only their number and total). Their device can turn this off, but it is on by default | USA | ⟨TO CONFIRM⟩ |
| Stripe — payments | only if you paid an invoice through Ksefly: amount, currency, method, the invoice number as the line description, card data read on the device | ⟨TO CONFIRM: which Stripe entity (Irish or US) and the transfer basis⟩ | ⟨TO CONFIRM⟩ |
| KSeF / Ministry of Finance | the complete invoice document; the Ministry is an independent controller under its own statutory mandate | Poland | — |
| GUS BIR, VAT white list (MF), VIES (European Commission) | your NIP (and for a bank account check: NIP + account number) | Poland / EU | — |
6. How long we keep it
- Invoice data and the contractor book — for as long as your trading partner uses Ksefly. When they delete their account, or remove their company from the app, we erase their invoices, scheduled sends and their whole data vault — and with it the data about you that was in there.
- We delete nothing “after X years”. There is no time-based retention mechanism in the system today. ⟨TO CONFIRM: decide and write in the intended retention periods — separately for invoice data and for the payment record — or state plainly that we keep them until the trading partner deletes their account.⟩
- One exception we will not keep quiet about: the payment record described in §2.3 is not deleted even after your trading partner deletes their account. It stays in the database with the amount, the card brand and the last four digits. ⟨TO CONFIRM: decide whether this is a deliberate retention decision (e.g. an obligation to document settlements) or a defect. If a decision — state the basis and the period. If a defect — fix the code and delete this paragraph.⟩
- Invoices in KSeF are a different matter. Neither we nor your trading partner can remove a document that has already reached KSeF — that system is run by the Ministry of Finance on statutory terms.
7. Your rights
You have the right to access your data, to have it rectified, erased or its processing restricted, to object to processing based on legitimate interest (GDPR art. 21), and — to the extent processing rests on a contract or consent and is carried out by automated means — to data portability.
Where to take it:
- Invoice data and address-book data — to your trading partner. They are the controller (§3) and it is their duty to answer you. If you write to us, we will pass the matter on and help carry it out technically, but we will not change or delete their data without their instruction — that is what being a processor means.
- The AI-written description, the payment record, the technical logs — to us, at privacy@ksefly.app. There we answer ourselves.
We reply without undue delay and within one month at the latest. Include your NIP — without it we cannot find your data. We may ask for information confirming that you are writing about your own affairs.
What we cannot do, and we say so up front: we cannot remove an invoice from KSeF, we cannot make it disappear from your trading partner’s records if the law requires them to keep it, and we cannot erase data that is necessary to settle a payment already made.
Complaint. You may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland).
Data protection officer: ⟨TO CONFIRM: whether a DPO has been appointed. If not, write: “We have not appointed a data protection officer; for data protection matters write to privacy@ksefly.app.”⟩
8. Why this is a published notice and not a letter to you
GDPR requires us to inform you when data was obtained from someone other than you (art. 14). Sending each such person an individual message would take disproportionate effort within the meaning of art. 14(5)(b) — and, more importantly, would mean processing more data about you than we hold today:
- an invoice does not say whether the other party is a natural person (whom GDPR protects) or a company (whom it does not);
- in most cases we have no way to contact you at all, and if a trading partner’s address book happens to hold your e-mail, that is their book and their data — using that address for a mailing of our own would be new, unexpected processing;
- there are very many such records, and every invoice adds more.
So, as art. 14(5)(b) allows, we make this information publicly available — at a permanent address, indefinitely, linked from the privacy policy. Independently of this, your trading partner has their own duty to inform you.
9. A note on scope
GDPR protects natural persons. This notice concerns you if you are a sole trader, a partner in a civil-law partnership, or a private individual who received an invoice. The data of a company with legal personality is not personal data — although data about the people who represent it may be.
10. Changes
We will update this notice as the app develops. Every version carries a number and a date.
Change log
- Version 1.0 — ⟨TO CONFIRM: date⟩. First publication, produced during the compliance audit alongside version 2.0 of the privacy policy. It discloses: exactly what we hold about a counterparty on our servers and which fields are not encrypted; that the business name and the invoice line-item names go to an AI model in the USA with no way to turn it off; that the name and the amount travel inside a push notification through Apple; that the payment record is not deleted today when an account is deleted; and the split of roles between the trading partner (controller) and Ksefly (processor — with the exceptions listed in §3).