Právne info

Privacy Policy

Default clickwrap terms for ePošťák SMB programs and web interface.

Účinné od: Effective from 11 July 2026

01

Controller and privacy contact

For activities where we determine the purposes and means of processing, the controller is:

Kaja Solutions s.r.o.

IČO: 57369186

DIČ: 2122701339

Sídlo: Lermontovova 3, 811 05 Bratislava

Email: info@epostak.sk

Company registered in the Commercial Register of the Bratislava III Municipal Court.

02

Roles by processing activity

Kaja is an independent controller to the necessary extent for account and authentication, contract formation and evidence, billing and tax, its own support, security, audit, legal claims and mandatory operational records.

For customer document content, Kaja generally acts as the customer's processor in direct Enterprise API mode and as a sub-processor in the chain end company → integrator → Kaja in integrator or white_label mode. Those activities are governed by the applicable signed DPA and controller instructions, not by this information page.

03

Purposes, roles and legal bases

Account, login and authentication — identity, contact, permissions, OAuth identifier, IP and security records; GDPR Article 6(1)(b) applies only where the data subject is personally a party, in particular a sole trader or natural-person entrepreneur. For directors, employees and other representatives of a legal entity, the basis is the necessary administration and secure provision of the company account under Article 6(1)(f) GDPR.

Contract, Order, signature evidence, billing and tax — company, contact, signature, payment and tax data; GDPR Article 6(1)(b) applies only where the data subject is personally a party, in particular a sole trader or natural-person entrepreneur. Data of directors, employees and other representatives of a legal entity is processed for statutory accounting and tax duties under Article 6(1)(c) and for contract administration and legal claims under Article 6(1)(f) GDPR.

Support, service communications and required price, contract, security or supplier notices — contact data, request content and delivery history; GDPR Article 6(1)(b) applies only where the data subject is personally a party, in particular a sole trader or natural-person entrepreneur. For directors, employees and other representatives of a legal entity, the basis is a statutory duty under Article 6(1)(c) or relationship administration and reliable delivery under Article 6(1)(f) GDPR. Optional marketing is used only with consent under Article 6(1)(a), which may be withdrawn at any time.

Security, abuse prevention, audit and incident handling — IP, user agent, identifiers, events, logs and appropriately minimized diagnostic data; Kaja as independent controller under Article 6(1)(c) and (f) GDPR. A diagnostics purpose does not authorize intentional copying of invoice content into monitoring.

E-invoice, UBL/XML, PDF and attachment content, delivery receipts and related metadata — Kaja as processor or sub-processor on documented instructions. The relevant controller determines the legal basis; a data subject should primarily exercise content-related rights with the company or integrator that determined the purpose, and Kaja will route the request securely.

Peppol, SMP/PFS and statutory network flows — Participant ID, Tax ID, routing, registration, authorization, delivery and status metadata; GDPR Article 6(1)(b) applies only where the data subject is personally a party, in particular a sole trader or natural-person entrepreneur. For directors, employees and other representatives of a legal entity, the specific flow relies on a statutory duty under Article 6(1)(c) or necessary service provision and network security under Article 6(1)(f) GDPR; Kaja's role is assessed for each purpose.

Optional AI/OCR — a document or minimized extract, image, extracted text and structured data only on the explicit instruction of the user or authorized integrator. In a processor chain the controller determines the legal basis; Kaja must not describe the function as Enterprise-ready until the specific supplier, DPA, transfer and DPIA/TIA gate is closed.

Our legitimate interests are service security and resilience, preventing and investigating fraud and abuse, reliable delivery of contractual notices, maintaining an appropriate audit trail, and establishing, exercising or defending legal claims. We assess necessity and proportionality against data-subject rights.

04

Categories of personal data

Depending on the activated service, we process the following categories:

  • Identity and contact data: name, title, email, phone, business name, Company ID, Tax ID, VAT ID, address and billing contact.
  • Account and authentication data: user account, OAuth/Google ID, authorization status, token identifiers, roles and login history.
  • Company and network data: Peppol Participant ID, PFS/SMP verification, registration, migration, routing and status metadata.
  • Service content and operations: documents and attachments, UBL/XML and PDF, transaction and delivery metadata, payment and tax data, IP, user agent, logs, support communications and, when expressly used, AI/OCR input and extracted data.
05

Data sources and indirect collection

We collect data directly from you during registration, ordering, signing, communications, account configuration, document upload or use of an optional function.

We may receive data indirectly from your employer or contracting company, accountant, integrator or white-label partner, a document sender or recipient, PFS or the Slovak Financial Administration, SMP/SML/Peppol and access points, an OAuth provider, a public register or technical security events.

Where Kaja acts as controller for indirectly obtained data and no exception applies, it provides this information by an appropriate link or directly within one month at the latest, at the first communication with the person or before the first disclosure to another recipient — whichever occurs first. An Article 14(5) exception is used only where evidenced for the specific flow; where Kaja acts only as processor, the relevant controller is responsible for the notice.

06

Purposes and legal bases

Each purpose and legal basis is stated for the relevant activity; consent is not used as a substitute for a contract or statutory duty. If we as controller intend an incompatible new purpose, we provide information about that purpose and the relevant conditions before further processing begins.

  • Providing and securing the ordered service.
  • Support, service communications and audited mandatory notices.
  • Accounting, tax, network and other legal duties and protection of legal claims.
07

Recipients and external parties

To the necessary extent, data may be received by authorized Kaja personnel, the contracting customer or integrator, verified processors listed at /sub-spracovatelia, payment and professional advisory parties for the specific purpose, and public authorities where required by law. A supplier with an open activation gate is not described as an approved active sub-processor.

OpenPeppol AISBL, SML/Directory, the Slovak Financial Administration or PFS, the SMP operator, Peppol Authority, counterparty access points, senders, recipients and their systems may be network recipients, authorities, or independent or joint controllers for a specific activity; they are not Kaja sub-processors merely because they route or receive data.

08

Transfers outside the EU/EEA

An adequacy decision may be used only where the specific flow falls within its material and territorial scope and meets its conditions; for a flow covered in that way, Standard Contractual Clauses (SCCs) and a TIA are not used merely because data goes to a third country. Where SCCs are used, the applicable module is selected and a TIA is performed and recorded before activating the specific flow, with supplementary technical, organisational or contractual measures adopted where the assessment requires them. This wording and the public register does not claim that a TIA or another open activation gate has been completed for any specific supplier; production use requires account-specific evidence. Current entity, location, mechanism and gate status is shown at /sub-spracovatelia. Information about the safeguard or an available copy may be requested at info@epostak.sk, subject to appropriate protection of confidential information.

09

Your rights

Subject to GDPR conditions, you have rights of access, rectification, erasure, restriction, portability and objection; where processing relies on consent, you may withdraw it at any time without affecting prior lawfulness. You may also complain to a supervisory authority and not be subject to prohibited solely automated decision-making.

  • 01Right to access data
  • 02Right to rectification
  • 03Right to erasure
  • 04Right to data portability
  • 05Right to restrict processing
  • 06Right to object
  • 07Right to withdraw consent
  • 08Right to complain to a supervisory authority
  • 09Right not to be subject to prohibited automated decision-making

Right to object under GDPR Article 21

Where processing relies on Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation; we will stop unless we demonstrate compelling legitimate grounds or the need for legal claims. You may object to processing for direct marketing at any time and without further conditions, after which we will no longer process the data for that purpose.

10

Retention and deletion

Free-program content for no more than 90 days remains in the visible working layer; older content may be hidden or removed, and this does not replace the customer's statutory archive. Paid or individually contracted service content is retained during the active contractual relationship and for no more than 30 days after it ends for export; it is then deleted from the active layer and expires from backups through their documented rotation. Webhook delivery-attempt telemetry is retained for no more than 90 days and acknowledged webhook events for no more than 30 days. The administrative audit trail (AuditLog) and the integrator partner audit are retained for 730 days; security events (AuditEvent) are retained for 1825 days. IP address and user agent in both security and partner audit records are removed after no more than 30 days. Closed support tickets are retained for no more than 730 days. Signed AS4 envelopes are retained in WORM mode for 10 years as Access Point infrastructure evidence, not as a substitute for the customer's accounting archive. Mandatory law or a documented legal hold may extend retention only for specifically identified records; its reason, scope and closure are recorded.

11

Mandatory and optional data

Fields marked as mandatory for an account, PFS/SMP authorization, Order, billing or statutory routing are contractual or legal requirements; without them we cannot create or secure the account, verify authority, conclude the Order, issue an invoice or deliver the document. Phone, OAuth instead of another login method, marketing, AI/OCR and other optional functions are voluntary unless the specific activated process expressly says otherwise.

12

Automated decision-making

Kaja does not carry out solely automated decision-making or profiling that produces legal or similarly significant effects for a data subject. Automated validation, risk detection, routing or technical holding may flag a request for manual review but does not itself determine a person's legal position; if this changes, we will explain the logic, significance and expected consequences before deployment.

13

Contact and complaint

Send a request to info@epostak.sk. If it concerns content processed on a customer or integrator's instructions, identify the relevant company; Kaja will route it securely to the controller. We may reasonably verify identity before responding.

Email: info@epostak.sk

Supervisory authority: Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, https://dataprotection.gov.sk/