Privacy Policy
Privacy Policy of the "Fast KSeF" Service
1. Data Administrator​
The administrator of personal data is Sci Software Sławomir Cichy (hereinafter: "Administrator" or "Operator").
2. Scope of Collected Data​
As part of using the Service, the following data is processed:
| Category | Data Examples |
|---|---|
| Identification data | First and last name, email address, Tax ID (NIP) |
| Login data | Google / Microsoft account identifiers (The Operator does not store passwords) |
| Company data | Company name, registered office address, REGON, KRS, bank account number |
| Invoice data | Content of invoices created and sent to KSeF |
| Technical data | IP address, browser type, session data, activity logs |
| Certificates | Qualified certificates / seals used for authorization in KSeF |
3. Purposes of Data Processing​
Personal data is processed for the following purposes:
- Service Provision — enabling logging in, creating, and sending invoices to KSeF (basis: Art. 6(1)(b) GDPR — performance of a contract).
- Security — account protection, fraud detection, maintaining logs (basis: Art. 6(1)(f) GDPR — legitimate interest).
- Marketing — sending commercial information and ad personalization, only with the User's explicit consent (basis: Art. 6(1)(a) GDPR — consent).
- Legal Obligations — fulfillment of accounting and tax requirements (basis: Art. 6(1)(c) GDPR — legal obligation).
4. Data Retention Period​
- Account data — stored for the entire duration of using the service.
- Invoice data — not applicable. Invoice data is stored in the National e-Invoice System (KSeF).
- Technical logs — stored for up to 12 months.
- Marketing data — until consent is withdrawn.
5. Data Sharing​
Data may be shared with:
- National e-Invoice System (KSeF) — for the purpose of transmitting structured invoices.
- IT Service Providers — hosting, databases, authentication systems (Google, Microsoft) — only to the extent necessary to provide the service.
- State Authorities — based on applicable legal regulations.
The Operator does not sell personal data to third parties.
6. User Rights​
Users are entitled to the following rights under the GDPR:
- Right of access to their data (Art. 15).
- Right to rectification of incorrect data (Art. 16).
- Right to erasure — the "right to be forgotten" (Art. 17). Exercised via the account deletion function in the Service.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20).
- Right to object to processing (Art. 21).
- Right to withdraw consent for marketing data processing at any time — in the account settings, "Consents" section.
7. Data Security​
- Communication with the Service takes place via an encrypted connection (TLS/SSL).
- Certificates and private keys are stored in encrypted form.
- Access to data is restricted by Row Level Security mechanisms — each user sees only their own data.
- The Operator performs regular database backups.
8. Cookies​
The Service uses cookies exclusively for:
- Essential purposes — maintaining login sessions and CSRF tokens.
- Analytical purposes — anonymous traffic analysis (only with the User's consent).
Users can manage cookies in their browser settings.
9. Changes to the Privacy Policy​
The Operator reserves the right to change this Privacy Policy. Users will be informed of any changes 14 days in advance via email.
10. Contact​
For matters concerning personal data protection, please contact us at:
- Email: [kontakt@fast-ksef.pl]
- Address: Sci Software Sławomir Cichy, ul. Bolesława Chrobrego 4, 84-207 Bojano, Poland, NIP: PL9570429696, REGON: 222009584