Právne info

General Terms and Conditions

These GTC are the default clickwrap terms for SMB programs and the web interface; they do not constitute the Enterprise/Integrator MSA. For enterprise, integrator or white-label scope, the signed Order, MSA, DPA and applicable schedules prevail by subject matter; the GTC apply only where an Order expressly incorporates them and only to the non-conflicting extent. The privacy and cookie notices are informational and do not replace a DPA. Slovak wording is binding. English wording is an informative translation unless a specific Order expressly provides otherwise. This wording is effective for new acceptances from 11 July 2026; older acceptances and their evidence artifacts remain unchanged.

Účinné od: Effective from 11 July 2026

00

Service Provider

Kaja Solutions s.r.o.

Company No.: 57369186

Tax ID: 2122701339

Registered Office: Lermontovova 3, 811 05 Bratislava

Contact email: info@epostak.sk

Company registered in the Commercial Register of the Municipal Court Bratislava III.

01

Article 1 — Definitions and Interpretation

For the purposes of these General Terms and Conditions:

Provider — Kaja Solutions s.r.o., Company No.: 57369186, operator of the ePošťák platform and a certified Peppol Access Point.

User — a legal entity or sole trader who has entered into a Contract with the Provider and uses the Service to send or receive electronic invoices.

Integrator — an Enterprise API customer acting for authorized client companies; its production relationship is governed by a signed Order, MSA, DPA and applicable schedules, not by the SMB clickwrap alone.

Peppol Network — the international interoperable infrastructure for exchanging electronic business documents operated under the supervision of OpenPeppol AISBL, governed by the Peppol Interoperability Framework (PIF) and Peppol Service Provider Agreement (SPA).

SMP (Service Metadata Publisher) — the register of Peppol participants, endpoints and capabilities used for Slovak Peppol flows. The exact legal entity of the production operator, its role, DPA, hosting and transfers are a activation condition and must not be inferred only from a network address or the role of the Slovak Financial Administration/PFS.

Access Point (AP) — a certified technical node of the Peppol network that sends and receives documents on behalf of Users. The Provider operates an AP certified by OpenPeppol.

Digital Postman — a certified delivery service provider under Act No. 222/2004 Coll. on Value Added Tax, as amended by Act No. 385/2025 Coll., authorized to mediate the transfer of tax data documents between taxpayers and the Financial Administration of the Slovak Republic.

E-Invoice — an electronic invoice in a structured format corresponding to the European standard EN 16931 and UBL 2.1 format, sent via the Peppol network.

Tax Data Document — an electronic invoice or other document in the format required by Act No. 222/2004 Coll. on Value Added Tax, as amended, including by Act No. 385/2025 Coll.

FR SR — the Financial Directorate of the Slovak Republic, acting as the national Peppol Authority in Slovakia.

Identifier 0245:[TAX ID] — the standard Peppol participant identifier for Slovakia, where 0245 is the scheme code for the Slovak Tax ID.

GTC — default SMB terms for the web interface, including the processing agreement in Annex No. 1; they are not the Enterprise or Integrator framework agreement.

Service — for these GTC, primarily the SMB web interface at epostak.sk. Enterprise API, integrator and white-label scope is governed by the signed package and by these GTC only where expressly incorporated.

Web interface — the user interface of the Service intended for manual or ordinary accounting use, especially receiving, viewing, checking, manually downloading, exporting and sending e-Invoices without programmatic API access.

SMB programs — the Free, Standard and Business programs intended for sole traders, small and medium-sized businesses or accountants who use the Service through the web interface without programmatic API access.

Document — an e-Invoice, corrective invoice, tax data document or other supported electronic business document processed through the Service.

Free program monthly limit — a fixed limit of 500 received Documents and 5 sent e-Invoices per month per one company or Tax ID. After the limit is reached, additional received Documents are archived in the background but are not shown in the interface, and sending additional e-Invoices is suspended until switching to a paid program or until the start of the next monthly period under these GTC.

Contract — for the SMB web product, the relationship created by registration and acceptance of these GTC; an enterprise, integrator or white-label contract is formed as stated in the signed Order and MSA.

Provider-controlled infrastructure — application, web, authentication, API and Access Point components operated or configured under the Provider's direct technical control.

External systems — Peppol network components, SML/SMP or public systems outside the Provider's control, counterparty Access Points, recipient and sender systems, customer ERP, internet, DNS, email, payment, analytics and other third-party services.

ePošťák Box — a staging function for upload, temporary storage, preparation, validation or holding of a Document before a separate sending instruction.

White-label mode — a separate enterprise mode under a signed Order and white-label schedule; this SMB clickwrap does not itself activate it or determine its price, SLA, role chain or term.

Professional services — assisted onboarding, integration consulting, custom mapping, migration, non-standard export, training, security or legal review, custom reports or extended support ordered separately.

02

Article 2 — Subject of Contract and Service Description

The Provider undertakes to provide the User with access to the ePošťák platform, which is a certified Peppol Access Point connected to the Peppol network in accordance with the Peppol Interoperability Framework.

Within the Service, the Provider ensures: (a) registration of the User in a verified production SMP under identifier 0245:[TAX ID] only after the operator/role/DPA gate is closed; (b) sending and receiving e-Invoices via the Peppol network; (c) transfer of tax data documents to the FR SR AP in accordance with Act No. 222/2004 Coll. as amended by Act No. 385/2025 Coll.; (d) technical validation of documents according to Peppol BIS Billing 3.0 before sending.

The Provider acts as a technical intermediary — a Digital Postman. This operational label does not determine the GDPR role, which is assessed by activity and the DPA. The Provider is not responsible for the tax accuracy, completeness or substantive correctness of invoices; responsibility for tax-law compliance of content remains with the User to the extent it cannot be allocated to the Provider.

Enterprise API, integrator and white-label services are not ordered merely by accepting these GTC. Their scope, price, retention, SLA, termination, GDPR role chain and switching are governed by the signed Order, MSA, DPA and applicable schedules, which prevail for the relevant subject matter.

Peppol functionality must follow binding technical and network rules to the extent applicable to the specific service. This wording does not claim execution or content of a specific agreement; a signed SPA and current controller/joint-controller allocation are a activation condition. Network rules prevail only for technical requirements and cannot reduce mandatory law or DPA/GDPR protection.

The Provider reserves the right to extend, modify, or change Service functionalities while preserving its core purpose, with notification according to Article 11.

A legally required data-output function is provided only while the relevant obligation is effective, the public interface is available, and the Provider is objectively enabled to perform it by the competent authority or network.

03

Article 3 — Registration and Verification Data

The Contract between the Provider and the User is concluded upon completion of registration via the web form at epostak.sk, authentication via Google OAuth, or acceptance of an invite link within the PFS (Partner Flow System), and simultaneously confirming the relevant checkbox expressing consent to these GTC and requesting activation of the Service.

By confirming the checkbox, the User confirms that they have familiarized themselves with the GTC, understood their content, and agree to them within the meaning of Section 273 of Act No. 513/1991 Coll. Commercial Code, as amended. Electronic consent has the same legal effect as a written signature.

In PFS registration, the Financial Administration verifies the existence of the tax subject and provides the Provider with the Verification Data required for the subsequent SMP registration. In the standard activation flow, the Provider relies on the PFS authorization, the Verification Data, confirmation of the relevant checkbox, and the audit trail. The Provider may refuse or suspend registration if the PFS authorization is invalid, duplicate, revoked, or technically conflicting.

By registering, the User requests registration of its Peppol identifier 0245:[TAX ID] in a verified production SMP based on Verification Data obtained through the Slovak Financial Administration process. The exact SMP operator and its role are determined separately; the identifier and capabilities are public within Peppol discovery and visible to authorized network participants.

The User is responsible for the confidentiality of their account access credentials. In case of suspected unauthorized access, the User must immediately contact the Provider at info@epostak.sk.

Registration may only be performed by representatives of legal age authorized to act on behalf of the User. The individual completing the registration declares that they are authorized to legally bind the User.

04

Article 4 — User Obligations

The User is solely responsible for the content of sent e-Invoices and tax data documents, including their tax accuracy, compliance with applicable accounting and tax regulations, and identification of correct tax rates.

The User is obliged to keep their registration and contact details (name, address, Company ID, Tax ID, email address) current and truthful. Changes must be reported to the Provider without undue delay, no later than 5 business days.

The Service must not be used to send fraudulent invoices, unsolicited commercial communications (spam), to commit criminal offences, or to circumvent tax obligations. Violation of this prohibition entitles the Provider to immediately block the account and deregister it from the SMP without any right to compensation.

The User acknowledges that ePošťák is not an archiving service. The User is obliged to ensure archiving of e-Invoices and tax documents in their own system in accordance with Section 76 of Act No. 222/2004 Coll. on VAT and Section 35 of Act No. 431/2002 Coll. on Accounting, which set a 10-year retention period. If a special regulation requires a longer period, the User is responsible for complying with it.

The User must refrain from conduct that could disrupt the availability, security, or integrity of the Peppol network or the Service, including attempts at unauthorized access, attacks on infrastructure, or circumvention of security mechanisms.

Where an Order expressly incorporates these GTC into an enterprise or integrator relationship, they apply only supplementally; the signed MSA, Order and DPA set the specific duties for API keys, client companies, downstream information and support.

A Document held in ePošťák Box or another staging queue is not sent or delivered until an authorized sending instruction or an expressly configured automatic rule is executed.

The User remains responsible for timely sending instructions and deadlines where a Document is only prepared or held in staging.

05

Article 5 — Free Program Monthly Limits

5.1 The Provider provides the Free Program free of charge subject to these GTC.

5.2 The monthly limits of the Free Program are: (a) receipt of max. 500 electronic invoices and (b) sending of max. 5 electronic invoices per calendar month per one company or Tax ID.

5.3 After either limit is reached, additional received invoices are archived but are not shown in the interface; sending a new invoice is refused with the notice “limit exhausted”; the User receives email notifications at 80% and 100% of limit usage.

5.4 Data is retained for at least 90 days and becomes fully available again after switching to a Paid Program. Peppol receipt continues in the background after the Free Program monthly limit is reached.

5.5 The Provider may reasonably change the limits; it will notify the User of the change at least 30 days in advance.

06

Article 6 — Archiving and Data Retention

The Archive is a supplementary operational function of the Service intended for technical retention of Documents, UBL/XML files, PDF visualizations, transport metadata, statuses, confirmations, audit records and related data for the period defined by the selected plan, Price List or Contract.

Free Program: documents are available and exportable in the web interface for 90 days from the date of sending or receipt. After this period, they may be hidden from the application interface or removed; the User's statutory archiving obligations remain unaffected.

Standard and Business Plans: SMB documents remain available in production during the active subscription and for 30 days after termination for export. They are then deleted from production use; copies in technical backups remain isolated and expire through the documented rotation. Separate billing, contract, security or audit records are retained only for an applicable legal duty, legitimate claim or legal hold.

Enterprise API: retention, export, switching, return, deletion, backup lifecycle and any legal hold are determined by the signed Order, DPA and Data Act schedule. These SMB GTC cannot be used to shorten or expand the agreed enterprise regime.

The Archive is not a qualified electronic archiving service, guaranteed legal custody of documents, accounting archive or replacement for the statutory duty of the User, Integrator or end customer to retain accounting, tax or other legally significant documents.

The Provider will send the User an email notification 7 days before planned data deletion to allow the User to export their data.

Delivery logs, activity logs, and audit records are kept for at least 6 months unless legal or security reasons require a longer period. Records related to security incidents may be retained longer.

Data export is available in UBL 2.1 (XML), PDF, and CSV formats via the web interface or API.

Backups are used for technical recovery of the Service after an incident, failure, data loss, cyberattack or another technical problem. Backups are not a user archive, and the User or Integrator has no automatic right to restore an individual document, message or record from a backup unless the Provider decides to provide such restoration technically or it is agreed as a paid Professional Service.

07

Article 7 — Availability Target

The Provider uses reasonable efforts, applying appropriate professional and commercial measures, to achieve monthly availability of the ePošťák platform's Provider-controlled infrastructure of 99.5%, measured monthly, 24 hours a day, 7 days a week. This is a reasonable-efforts obligation, not an absolute guarantee of a result, uninterrupted Service availability or availability of external delivery layers. The availability target does not create any right to a contractual penalty, service credit, or automatic damages.

The availability target applies exclusively to the Provider-controlled infrastructure. It does not apply to External Systems, including the Peppol network as such, OpenPeppol components, SML, SMP or ACL services outside the Provider's direct control, systems of the Slovak Financial Administration, access points of other providers, sender or recipient systems, User or Integrator ERP and integration solutions, internet connection, DNS, email, SMS, payment, analytics or other third-party services.

Planned maintenance, emergency maintenance, force majeure, a cyberattack that could not reasonably have been prevented, incorrect User or Integrator configuration or integration, invalid or incomplete input data, blocked API keys, exceeded request-rate limits, legislative or technical changes by third parties, and security measures taken to protect the Service are not included in the availability calculation.

For the SMB web flow, after a temporary sending failure the Provider makes 3 retry attempts at 2-hour intervals where technically possible and not blocked by Peppol, FR SR or the receiving Access Point. Enterprise retry, idempotency and delivery rules are governed by the signed SLA/API lifecycle schedule and technical documentation without changing contractual rights.

In the event of an incident affecting availability of the ePošťák platform under the Provider's direct control, the Provider will use reasonable efforts to diagnose the incident, restore the service, and provide ongoing updates through an appropriate channel.

The status page at epostak.sk/status displays availability solely for the Provider's Controlled Infrastructure. Outages, maintenance, or unavailability of External Systems are not included in the displayed ePošťák platform status or availability percentage.

The platform availability target does not apply to the Free plan. Free plan Users acknowledge that platform availability, supplementary web interface features, notifications, exports and user comfort are provided as-is without availability guarantees. This sentence does not apply to the Provider's obligations as a digital postman to receive and make Documents available through the Peppol network to the extent arising from mandatory legal regulations, Peppol network rules and these GTC.

08

Article 8 — Limitation of Liability

The Provider is liable for damage caused to the User only to the extent set out in these GTC and applicable legal regulations.

Free Plan: The Free plan is provided free of charge and supplementary web interface features, notifications, exports, user comfort and support are provided as-is, without any warranty of quality or availability. The Provider is not liable for damage arising in connection with use of these free supplementary features, except for liability that cannot be excluded under mandatory legal regulations and except for failure of the Provider's obligation as a digital postman to receive or make available a tax data document where that obligation is on the Provider's side and under its direct control.

Paid Plans: The Provider's total liability for damage incurred by the User during one contractual year is limited to the amount of fees actually paid to the Provider in the last 12 months prior to the damage event.

Liability for Enterprise API is governed by the signed Order and MSA; these SMB GTC do not by themselves reduce, expand or replace agreed carve-outs or mandatory rights.

White-label liability, commitment and termination economics are governed by the signed Order, MSA and white-label schedule; these SMB GTC do not alter or replace them.

The Provider is not liable for non-delivery, delayed delivery or rejection of a Document where the cause does not arise exclusively within the Provider-controlled infrastructure.

Under no circumstances shall the Provider be liable for indirect damages, lost profits, loss of revenue, data loss, loss of business opportunities, or any other consequential or unforeseeable damages, even if the Provider was previously advised of the possibility of such damages.

Claims for damages must be asserted in writing within 12 months of the damage event, otherwise they expire.

The Provider is not liable for damages caused by force majeure or events outside the Provider's direct control, including but not limited to: cyberattacks and information security incidents beyond the Provider's control, outages of telecommunications, hosting, storage, database, email, or payment infrastructure of third parties, pandemic, decisions of state authorities, natural disasters, changes to or outages of Peppol network rules or infrastructure, FR SR, SMP/SML, Peppol Authority, OpenPeppol AISBL, access points of other providers, or recipients' receiving systems.

If a failure in the transfer of a tax data document occurs on the side of the Provider's certified AP, the Peppol network, FR SR, SMP/SML, Peppol Authority, OpenPeppol AISBL, a third-party access point, the recipient's receiving system, or other infrastructure outside the Provider's direct control, the Provider will provide the User, upon request, with reasonable technical cooperation, in particular available confirmation, an error log, an audit trail, or other technical evidence. The Provider is not liable for penalties, tax, accounting, or legal consequences caused by failure of infrastructure outside its direct control.

The Provider is not liable for tax, accounting, or legal consequences of the content of invoices sent by the User.

09

Article 9 — Contract Termination and Deregistration

An SMB web-plan User may terminate the Contract or request a change of digital postman through account settings or in writing to info@epostak.sk; termination of a paid SMB subscription takes effect at the end of the current period unless agreed otherwise. Enterprise API, integrator and white-label termination and switching are governed by the signed Order, MSA and Data Act schedule, which prevail and cannot be silently changed by these GTC.

The Provider may terminate the Contract without stating a reason with 30 days' notice. Notice is sent by email to the User's address.

The Provider is entitled to terminate the Contract immediately in the event of: (a) material breach of the GTC by the User; (b) proven fraud or criminal activity; (c) payment delay exceeding 30 days; (d) request of a competent public authority; (e) violation of Peppol network rules that could jeopardize the Provider's AP certification.

When the User requests a change of digital postman, the Provider will issue an SMP migration code. The Service remains active with the Provider and the SMP record remains in transfer state until the new digital postman takes over the Peppol ID using the migration code or until the User cancels the request. The Provider does not perform immediate deletion of the SMP record for a digital postman change; the migration code must be handed to the new digital postman.

After termination of the SMB Contract, the User has 30 days to export customer content. Subsequent production deletion, rotational expiry of backups and separate statutory or legal retention of billing, security and contract evidence are governed by Article 6 and the SMB DPA; this does not claim immediate deletion of every copy regardless of legal basis.

Termination of the Contract does not affect obligations and claims that arose prior to the effective date of termination.

10

Article 10 — Intellectual Property

The ePošťák platform, its code, design, documentation, trademarks, and all related intellectual property rights are the exclusive property of Kaja Solutions s.r.o.

The Provider grants the User a limited, non-exclusive, non-transferable, and revocable license to use the Service solely for the User's internal business purposes during the term of the Contract.

The User shall not: (a) copy, modify, or distribute any parts of the platform; (b) reverse engineer, decompile, or disassemble it; (c) create derivative works; (d) sublicense access to third parties without the Provider's prior written consent.

User data (invoices, transaction records, and other documents) is the exclusive property of the User. The Provider does not acquire any ownership rights to the content of User data and processes it solely in accordance with Annex No. 1 (DPA) and for the purpose of providing the Service.

The User grants the Provider a non-exclusive right to process User data to the extent necessary for providing the Service.

11

Article 11 — Changes to GTC

The Provider may propose a change to these SMB GTC and will give an auditable notice at least 30 days before it takes effect. A GTC change does not itself amend a signed enterprise/integrator Order, MSA, DPA, pricing or other schedule; their own notice, objection, exit or reacceptance mechanism applies.

If the User continues to use the Service after the amended GTC take effect, they are deemed to have accepted the changes.

In the case of material changes to the GTC (changes in the scope of liability, changes in fees, or changes in termination conditions), the User has the right to terminate the Contract without penalties before the changes take effect, by written notice to the Provider within the 30-day period.

The following are not considered material changes: addition of new functionalities, change of technical documentation, clarification of definitions, or legislatively required changes (i.e., changes resulting from amendments to applicable regulations).

The current wording of the GTC is always available at epostak.sk/podmienky. The date of the last update is stated in the document header.

12

Article 12 — Final Provisions

These GTC and the Contract are governed by the laws of the Slovak Republic. Any disputes arising from these GTC shall be resolved by the courts of the Slovak Republic with jurisdiction in Bratislava.

The contracting parties undertake to maintain confidentiality of confidential information of the other party obtained in connection with the performance of the Contract.

If any provision of these GTC is found to be invalid, ineffective, or unenforceable, this shall not affect the validity and enforceability of the remaining provisions (severability clause). The parties agree to replace such provision with a valid and enforceable provision that most closely approximates the economic purpose of the original provision.

This wording applies to new acceptances from its effective date. It does not retroactively amend older acceptances or signed contracts.

Annex No. 1 is the processing agreement for direct web processing. Enterprise API, integrator and white-label use the processing agreement captured in the signed contract package; that signed agreement prevails for personal-data protection and is not replaced by the privacy notice.

A1

Annex No. 1 — SMB DPA for the web interface

Processing agreement under GDPR Article 28.

This Annex applies only to direct SMB/web processing: the Controller is the registered SMB user and the Processor is Kaja Solutions s.r.o. Enterprise API, integrator and white-label scope is governed by a separate signed DPA v2 with an activity-specific role chain; this Annex does not replace it.

Purpose of Processing: The subject is receipt, validation, transformation, staging, sending, delivery, storage, export, support and deletion of e-Invoices, tax data documents, attachments and metadata. The nature includes automated and necessary authorized manual operations for the purpose of providing the SMB web service. Processing has a duration covering the effective SMB contract and subsequent retrieval, return/deletion or statutory-retention phase. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation. Where Union or Member State law to which the Processor is subject requires processing, the Processor informs the Controller before processing of that legal requirement, unless that law prohibits such information on important grounds of public interest.

Categories of Personal Data: names, job contacts and addresses, Company ID, Tax ID, VAT ID, IBAN and payment data, document line items and amounts, email, phone, transaction, delivery and technical metadata, and other personal data the Controller includes in a document or attachment. The Controller must minimize data and send Article 9 special-category data only where demonstrably necessary under a valid legal basis, the Controller's documented instructions and appropriate safeguards; Kaja does not make a blanket assumption that such data is absent.

Data Subjects: customers of the Controller, suppliers of the Controller, contact persons of contractual partners, and employees appearing on invoices.

Legal Basis: the Controller determines the legal basis and information duties toward data subjects. Kaja processes only on documented instructions; Kaja's separate controller purposes — account, billing, security and legal evidence — are outside this DPA and described in the privacy notice.

Hosting and Security: Kaja uses appropriate technical and organisational measures including transport encryption, access control, logging and technical backups for service recovery. Each supplier's specific account, contracting entity, location, support access and transfer mechanism must be account-specific verified and published in the register; a public vendor page or IP location is not evidence for Kaja's specific account.

Sub-processors: General authorization covers only the exact legal entity and activity marked as a verified active sub-processor at https://epostak.sk/sub-spracovatelia. A conditional, inactive, unverified or blocked supplier is not authorized and must close its activation gate before engagement. Kaja gives at least 30 days' notice of an intended change, allows a reasoned objection, and imposes equivalent duties on the further processor.

Personal Data Breach: When Kaja becomes aware of a personal data breach affecting data under this DPA (awareness), it informs the Controller without undue delay and not only after internal confirmation. The first notice may be incomplete and is supplemented progressively so the Controller can assess its duties; a general security incident without personal data is tracked separately, but classification must not delay privacy triage.

Audit and Security Evidence: Kaja makes available information needed to demonstrate Article 28 GDPR compliance and allows an appropriate audit by the Controller or an independent auditor. A routine audit is performed preferably remotely through documentation, security evidence and explanations under Art. 28(3)(h) GDPR; this does not affect the right to a legally required or reasonably necessary inspection under secure and confidential conditions. Persons with access are bound by confidentiality and need-to-know access. If Kaja considers a documented instruction to be an unlawful instruction, it informs the Controller without undue delay and suspends it only to the necessary extent while it is clarified.

Rights of Data Subjects: The Controller decides requests under GDPR Articles 12 to 23. Kaja securely routes them, does not answer substantively without instructions, and provides appropriate assistance with duties under Articles 32 to 36.

AI/OCR Functions: AI/OCR is disabled by default and may process a document only on the Controller's explicit instruction after the specific supplier, DPA, transfer, retention and DPIA/TIA activation gate is closed. Content is not used to train, fine-tune or evaluate a third-party model without a separate explicit legal basis and instruction.

Backups: Personal data may be present in encrypted technical backups, which are not a user archive. After production deletion they remain isolated from ordinary processing and expire through the documented rotation unless law or a legal hold requires retention; a restore must not silently return deleted data to active use.

Return and Deletion of Data: After processing ends, Kaja returns or deletes personal data according to the Controller's choice and deletes existing copies unless law requires retention. Standard export remains available for the notified retrieval period; backups are isolated until rotational expiry and Kaja provides appropriate confirmation of completed deletion on request.