Invoisync Privacy Policy

Effective Date: 16th April 2026

Invoisync Spółka z ograniczoną odpowiedzialnością (KRS 0000934373), with registered address at ul. Złota 59, floor 14, 00-120 Warszawa, Poland, is the company operating the Invoisync website and application ("Invoisync", "we" or "us"). We are the data controller for personal data collected through the Invoisync website (https://invoisync.io). This Privacy Policy explains how we collect, use, and protect your personal data when you use our website, in compliance with the EU General Data Protection Regulation (GDPR). Our services are primarily intended for users in the European Union, and we adhere strictly to EU GDPR requirements.

1. Purpose and Main Functionality of the Invoisync Website

The Invoisync website is designed to attract users to our product and provide information and access to the Invoisync mobile application, an all-in-one mobile solution for businesses to manage payments, send invoices, and get paid. In particular, through the website, users can:

  • Download the App: Find links to download the Invoisync application on the Apple App Store and Google Play.
  • Learn About Invoisync: Read about Invoisync's features, functionality, and stay informed about product updates or new services.
  • Contact Us: Obtain our contact information (email) to ask questions about the product, request support, or suggest partnerships and collaborations.
  • Access Content: View educational or promotional materials related to Invoisync (such as blog posts, guides, or FAQs) to help understand how the product can benefit their business.

We use personal data collected via the website only to operate and improve the site, provide information or services you request, and communicate with you about Invoisync's offerings, as described below.

2. Personal Data We Collect

We limit our collection of personal information to what is relevant and necessary for the purposes outlined. The categories of personal data we may collect through the website include:

  • Contact Information: First name, last name, phone number, email address, company name, and country of residence.
  • Technical Identifiers: IP address, browser type and version, device type, operating system, and other details automatically collected when you visit our site. This information is typically captured through cookies or analytics tools to understand usage patterns.
  • Usage Data: Pages visited, date and time of access, clicks and navigation actions on our site. This data helps us analyse how users interact with the website. Usually collected via analytics cookies as described in the Cookies section below.

Note: In general, you provide personal data voluntarily. You can choose not to provide specific contact details, but then we may not be able to respond to your inquiries or provide certain information. Other data (like IP address and device info) is collected automatically by our website and analytics systems when you browse our site.

3. Sensitive or Special Category Data

We do not collect any sensitive personal data or special category data through our website. This means we do not seek to collect information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health information, or information about sexual orientation. Invoisync is oriented around business services, and none of our website features require this type of sensitive data. We ask that you do not send or submit any sensitive personal information to us. If we discover we have inadvertently received sensitive data, we will delete it promptly.

We only use your personal data for specified and legitimate purposes, and we ensure we have a legal basis under GDPR for each use. The primary purposes for which Invoisync processes personal data collected via the website include:

  • Providing Information or Services: If you contact us with questions about Invoisync or request a partnership, we will use your provided contact details (like email or phone) to communicate with you and respond to your requests. This may include answering your questions, discussing partnership opportunities, or sending you materials you asked for. Legal basis: our legitimate interest in responding to inquiries and potential customer requests, or to take steps at your request prior to possibly entering a contract (Art. 6(1)(f) or Art. 6(1)(b) GDPR).
  • Website Analytics and Improvements: We analyse usage data (such as site traffic, page views, and click patterns) to understand how our website is used and to improve its design, content, and performance. For instance, we use Google Analytics to gather aggregated information about which pages are most visited and how users navigate the site. Wherever possible, we use this data in an anonymised or aggregated form. Legal basis: your consent, obtained via our cookie banner for any analytics cookies (see Cookies below), or our legitimate interest in understanding and improving our services (when analytics cookies are strictly anonymised or exempt from consent requirements).
  • Operational and Security Purposes: We may use technical information like IP addresses or browser information to maintain the security of our website, debug and troubleshoot issues, and prevent fraud or misuse. For example, IP addresses may be used to detect and mitigate potential denial-of-service (DoS) attacks or other malicious activities. Legal basis: our legitimate interests in protecting our website and service integrity (Art. 6(1)(f) GDPR). This may involve processing that is strictly necessary for security, which is allowed without consent under applicable law.

We do not use the data we collect to make any automated decisions about you that produce legal or similarly significant effects. In other words, we do not conduct automated profiling or scoring of individuals based on website-collected data.

5. Third-Party Tools and Services

Invoisync uses a few trusted third-party services to operate our website and communicate with users. We choose vendors who adhere to high data protection standards, and we have agreements in place to safeguard your information. The external tools we may use include:

  • Google Analytics (Google LLC): We utilise Google Analytics to track and report on website traffic and user interactions. Google Analytics uses cookies to collect information such as your IP address, device identifiers, and browsing actions on our site. This helps us generate reports on website usage and improve the user experience. Google may process this data on servers located outside the EU. However, we have configured Google Analytics to respect privacy, and we rely on Google LLC being an active participant in the Data Privacy Framework (see Data Transfers below). You can opt out of Google Analytics as described in the Cookies section.
  • Marketing & CRM Tools (HubSpot, Mailchimp, or similar): We may use customer relationship management (CRM) and email marketing platforms such as HubSpot (HubSpot, Inc.) or Mailchimp (The Rocket Science Group LLC, an Intuit company) to manage contact information and send out newsletters or updates. If you fill out a form on our website, your data might be stored in one of these systems. These platforms help us organise user inquiries, send emails in bulk to subscribers, and track email open rates or website clicks from emails. Any such tool will process your data only on our instructions and for our purposes – for instance, Mailchimp would use your email address to send you an Invoisync newsletter you signed up for. These providers operate servers outside the EU, and both are active participants in the Data Privacy Framework.
  • Website Hosting and IT Providers: Our website is hosted by an external hosting company, and we use standard infrastructure and cloud service providers. Those providers could incidentally process technical data (like log files containing IP addresses) to ensure the site runs smoothly. We contractually require any such processor to handle data securely and in accordance with GDPR.

We do not sell or rent your personal information to any third parties. We also do not share your data with third parties for their own independent marketing purposes without your consent. Data processing agreements bind any third-party service providers we use and can only use the data for the specified services they provide to us, under our instructions.

6. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance user experience and to collect usage analytics. Cookies are small text files placed on your device when you visit a website. Before we set any non-essential cookies, we will obtain your consent through a cookie banner, following EU law. Below, we explain the types of cookies we use:

  • Essential Cookies: These cookies are necessary for the website to function properly. They enable core features such as security, network management, and accessibility. For example, if our site had a login or user session feature, an essential cookie might keep you logged in or remember your selections as you navigate pages. We do not need your consent to use these strictly necessary cookies, but we still want to inform you of their presence and why they are needed. Without these cookies, certain basic functions of the site may not work.
  • Analytics Cookies: We use analytics or performance cookies to collect information about how visitors use our site. For instance, Google Analytics cookies may track which pages you visit, how long you stay, and which links you click. The information collected is aggregated and not used to identify you personally; it helps us understand user behaviour generally and improve our website's content and layout. We will only set analytics cookies if you opt in via the cookie consent banner. If you decline, your browsing will not be tracked by these analytics tools and you will still have full access to the site.
  • Marketing Cookies (Optional): These cookies, sometimes called targeting or advertising cookies, are used to personalise marketing and advertising to you. If we run advertising campaigns or retargeting, such cookies could remember that you visited our site and allow us or our advertising partners to show you relevant ads on other platforms. As of now, Invoisync's website is primarily informational, and we do not heavily use advertising cookies. However, if we do implement any marketing cookies, we will ask for your explicit consent before enabling them. You can choose not to accept these cookies and still use our site without any loss of core functionality.
  • Cookie Consent Banner & Preferences: When you first visit our website, you will see a cookie consent banner. This banner informs you about the types of cookies we use and asks for your preferences. You can accept all cookies, reject non-essential cookies, or customise your choices. We will not set any analytics or marketing cookies until you have given consent by clicking "Accept" or selecting your preferences and confirming. We also provide a way for you to manage your consent later, via a "Cookie Settings" link on our site where you can change your preferences or withdraw consent. Additionally, most web browsers allow you to control cookies through the browser settings. You can delete or block cookies, but be aware that doing so might affect some features of the site.
  • Do Not Track: Some browsers offer a "Do Not Track" (DNT) signal. Currently, our site does not respond to DNT signals, because there is no industry standard for DNT. We instead rely on the explicit consent choices you make with our cookie banner.

For more detailed information about our use of cookies, you can refer to our Cookies Policy or contact us. By adjusting your cookie settings and preferences, you have full control over whether optional cookies are used during your visit.

7. Data Retention Period

We keep personal data only for as long as necessary for the purposes described above, and following legal requirements. Retention periods vary depending on the type of data and the purpose of processing:

  • Contact and Inquiry Data: If you contact us, we will retain the personal data you provide for as long as needed to respond to and resolve your inquiry. After we have fully addressed your request or question, we may keep the correspondence for a period of time in case you follow up or to establish a history of communications. Typically, such communications are kept for no longer than 24 months, unless further retention is justified, e.g. if you become a customer or for legal record-keeping obligations.
  • Marketing Data: Personal data that we process for email newsletters or other marketing communications, based on your consent, is retained until you unsubscribe or withdraw your consent. If you have given consent to receive marketing emails, we will generally retain your contact information for up to 24 months after your last interaction with us or until you opt out, whichever comes first. If you withdraw consent or ask to unsubscribe, we will promptly remove you from our mailing list and stop sending you communications.
  • Analytics Data: Data collected via Google Analytics and similar tools is stored as aggregated reports. Raw analytics data may be retained by Google Analytics on their systems, typically for 12 months or as configured in our Google Analytics settings. We have set our analytics tools not to retain personal data longer than necessary. Additionally, analytics data is mostly aggregated and doesn't directly identify individuals; we use it for trend analysis over time.
  • Cookies: Cookies themselves have their own retention durations. Some cookies (especially essential cookies) last only for the browsing session (session cookies) and are erased when you close your browser. Others are persistent cookies that remain on your device until they expire or you delete them. We configure our cookies to expire within a reasonable time frame. For example, analytics cookies may persist for a few months (Google Analytics cookies often last 6 to 12 months unless refreshed) and marketing cookies (if used) may last up to 12 months. We follow best practice by not setting any non-essential cookie with a lifespan longer than 12 months. You can also clear cookies manually from your browser at any time.
  • Legal Obligations and Disputes: In some cases, we might need to retain certain data for a longer period if required by law or to resolve any legal issues. For instance, if a law requires us to keep records of transactions or communications, we will retain that information as mandated. Similarly, if any complaint or dispute is ongoing, we will retain relevant data until it is resolved.

After the applicable retention period ends, we will either securely delete or anonymize your personal data. "Anonymise" means we remove personally identifying details so that the data can no longer be linked to any individual, and then we may use such anonymized data for statistical or analytical purposes without further notice.

8. Data Transfers Outside the EU

Invoisync primarily stores and processes personal data within the European Union. However, some of our third-party service providers (mentioned above) are based outside the European Economic Area (EEA). In particular, if we use services like Google Analytics or Mailchimp, your data might be transferred to servers in the United States or other non-EU jurisdictions for processing. The GDPR imposes strict requirements on such international data transfers, to ensure your data receives a adequate level of protection even outside Europe.

Whenever we transfer personal data to a country that is not deemed to have "adequate" data protection laws (as determined by the EU Commission), we implement appropriate safeguards as required by GDPR. These safeguards may include:

  • Standard Contractual Clauses (SCCs): These are template data protection clauses approved by the European Commission, which contractually bind the recipient of the data to protect it according to EU privacy standards. For example, our agreements with U.S.-based service providers like Google, HubSpot, or Mailchimp include Standard Contractual Clauses, committing them to safeguard your data.
  • EU-U.S. Data Privacy Framework Certification: We utilize vendors who are certified under this recognized framework. Such certification indicates that the provider complies with EU data protection principles for transferred data.
  • Data Processing Agreements: We have contracts in place with all external processors which include obligations to protect your information, grant you EU-equivalent data subject rights, and require immediate notification of any data breaches, etc. These contracts reflect GDPR standards no matter where the data is processed.
  • Technical Measures: In addition to legal safeguards, we apply encryption and other technical measures to personal data before it is transmitted internationally, adding an extra layer of security.

If you would like more information about the specific safeguards for a particular transfer of your data, please contact us (see How to Contact Us below). We will be happy to provide additional details about our data transfer protections. Our goal is to ensure that your personal information remains protected to the standards required by EU law, even when processed in a different country.

9. Your Rights Under GDPR

As an individual using our website, and if you are in the EU or otherwise subject to GDPR protections, you have certain data protection rights regarding the personal data we hold about you. Invoisync is committed to respecting your rights and facilitating your exercise of them. Under the GDPR, you are entitled to the following:

  • Right of Access: You have the right to request confirmation if we are processing your personal data, and if so, to obtain a copy of the data we hold about you, as well as information about how we use it. This is commonly known as a Data Subject Access Request. Note: If you request additional copies beyond the first, we may charge a reasonable fee as permitted by law.
  • Right to Rectification: If any personal data we have about you is incorrect or incomplete, you have the right to request that we correct or update it. We encourage you to notify us if your contact details change so we can keep our information accurate.
  • Right to Erasure: You have the right to request deletion of your personal data in certain circumstances – for example, if the data is no longer necessary for the purposes it was collected, or if you withdraw consent and we have no other legal basis to continue processing. This is sometimes called the "right to be forgotten." We will honor valid erasure requests and also notify any third-party processors to delete your data, unless an exemption applies.
  • Right to Restrict Processing: You can ask us to restrict (temporarily halt) the processing of your personal data under certain conditions. For example, if you contest the accuracy of the data or have objected to our processing (see below), you can request restriction until the issue is resolved. When processing is restricted, we will store your data securely but not actively use it.
  • Right to Object: You have the right to object to our processing of your personal data when we are doing so on a legal basis of legitimate interests or for direct marketing. If you object to direct marketing, we will stop using your data for that purpose immediately. If you object to processing based on our legitimate interests, we will evaluate your request and will cease processing unless we demonstrate compelling legitimate grounds that override your rights, or if the processing is needed for legal claims.
  • Right to Data Portability: Where we process your data based on consent or a contract, and the processing is carried out by automated means, you have the right to obtain the personal data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller (if technically feasible). In simpler terms, you can ask for an electronic copy of the data you have given us, so you can reuse it elsewhere, or ask us to transfer it to a third party of your choice.
  • Right to Withdraw Consent: If we are processing any of your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing we conducted prior to withdrawal, and it won't affect processing that is not based on consent. If you withdraw consent for marketing emails, we will stop sending them. If you withdraw consent for cookies, we will stop using those cookies on your browser.
  • Right to Lodge a Complaint: We sincerely hope to address any concerns you have directly, but we must inform you that you have the right to file a complaint with a Data Protection Supervisory Authority. In particular, you can contact the supervisory authority in the EU country where you live, work, or where you believe a violation of data protection law has occurred. For example, if you are in Poland, the relevant authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - PUODO). We welcome you to contact us first, and we will do our best to resolve your issue, but you always have the right to seek assistance from the authorities.

To exercise any of your rights, please see the How to Contact Us section below. We will respond to your request as soon as possible and no later than one month from receiving it, as required by GDPR. In certain cases, we may request additional information to confirm your identity to ensure we don't disclose data to the wrong person. If your request is complex or if you have made multiple requests, we are allowed to extend the response time by up to two further months, but we will inform you if that is the case. Exercising your rights is free of charge. However, if requests are manifestly unfounded or excessive, we might either refuse to act or charge a reasonable fee as permitted by law.

10. Technical and Organisational Security Measures

We take the security of your personal data very seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction. While no website or electronic transmission can be 100% secure, we follow industry best practices to safeguard information. Our key security measures include:

  • Encryption (TLS/SSL): All data transmitted between your browser and our website is encrypted using HTTPS with TLS (Transport Layer Security). This means that when you submit information on our site (for example, by filling a form), it is encoded to prevent eavesdropping by third parties. You can verify that our site is using HTTPS by the padlock icon in your browser's address bar. We also encourage you to ensure you are using an up-to-date browser that supports the latest security protocols.
  • Access Controls: Internally, we limit access to personal data to only those employees or contractors who need it to perform their duties (principle of least privilege). Access to user data is protected by authentication steps, and our staff are trained on confidentiality and data protection practices. Administrative accounts and data systems are protected with strong passwords (and multi-factor authentication where possible) to prevent unauthorized access.
  • Role-Based Permissions: We employ role-based access control in our systems, so that, for example, a team member handling customer support can only see the data necessary for that task and nothing more. We regularly review user privileges and remove or adjust access when people's roles change or if they leave our organization.
  • Data Minimization: We strive to collect only the personal data we truly need and to keep it only for as long as necessary (as detailed in the Data Retention section). By minimizing the data we hold, we reduce the risk associated with storing large amounts of personal information.
  • Secure Hosting and Network Security: Our website is hosted on secure servers that are protected by firewalls and monitoring systems. We ensure the hosting provider maintains up-to-date security patches and anti-malware protections. We also utilize measures to detect and prevent malicious traffic or attacks, such as Distributed Denial of Service (DDoS) mitigation services. Regular backups are performed to prevent data loss, and backups are encrypted and stored securely.
  • Vendor Vetting and Agreements: Before we engage any third-party service providers (processors) to handle personal data, we vet their security practices. We choose reputable companies with strong security track records. We also sign Data Processing Agreements with them that require them to take adequate security measures and notify us promptly in the event of any data breach on their side. This ensures that any personal data handled by our partners is given a comparable level of protection.
  • Monitoring and Testing: We monitor our systems for potential vulnerabilities and attacks. Security logs are reviewed for unusual activities. Where appropriate, we employ intrusion detection/prevention systems. We also conduct periodic testing (and/or use third-party audits) of our websites and apps to find and fix security weaknesses. For example, we may perform penetration testing or vulnerability scans on our web services.
  • Incident Response Plan: In the unlikely event of a data breach or security incident, we have an internal procedure (incident response plan) to respond quickly and effectively. This includes identifying and containing the issue, notifying affected users and authorities as required by law, and taking steps to prevent a recurrence. We are aware of the GDPR's breach notification requirements and will comply with them, including informing the supervisory authority and users when necessary.

While we are dedicated to protecting your information, it's also important for you as a user to take precautions. Ensure that any device you use to contact us or access our site is secure. Be cautious about the information you share and never send sensitive personal data through unencrypted channels. If you have any reason to believe your interaction with us is no longer secure, please contact us immediately.

11. Children's Privacy

Invoisync's website and services are not directed to children, and we do not knowingly collect personal data from individuals under the age of 16 (or the equivalent minimum age in the relevant jurisdiction) without verifiable parental consent. Our product is intended for businesses and professionals. If you are under 16, please do not submit any personal information on our site. If we learn that we have inadvertently collected personal data from a child under 16 without proper consent, we will delete that information as soon as possible. Parents or guardians who discover that a minor under their care has provided personal data to us should contact us, and we will promptly remove the data and cease any related processing.

12. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make changes, we will modify the "Effective Date" at the top of this policy. For significant changes, we may also provide a more prominent notice such as a banner on our website or an email notification, if appropriate. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. If we plan to use your personal data for a new purpose not originally outlined in this policy, we will notify you (and where required by law, seek your consent) before starting that new processing.

Your continued use of the Invoisync website after any modifications to this Privacy Policy will constitute your acknowledgment of the changes and agreement to be bound by the updated policy. However, if the changes are substantial, we will seek your explicit acknowledgment as needed.

13. How to Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please do not hesitate to contact us. We have appointed a compliance manager to oversee data protection matters, and our support team is also equipped to handle your inquiries or exercises of rights.

You can reach us by email at support@invoisync.io (general support and privacy inquiries) or call our complaints hotline +48 534 344 667. Alternatively, you may send correspondence to our postal address:

Invoisync Sp. z o.o.
ul. Złota 59, floor 14
00-120 Warszawa
Poland

Please specify that your request is related to privacy/data protection. For example, in the subject line of your email, you might write "GDPR Data Inquiry" or "Privacy Request". This will help us route your inquiry to the right personnel. We will reply as soon as possible, and in any event within the timeframes required by law.