Privacy Policy for the Faktio Service

Controller: VisionEdge s. r. o., 29. augusta 1503/1A, 958 01 Partizánske, Slovak Republic Company ID (IČO): 51962161, Tax ID (DIČ): 2120848521 (not a VAT payer) Registration: Commercial Register of the District Court Trenčín, Section Sro, Insert No. 37109/R Data protection contact: info@visionedge.sk

Version: 1.0 · Effective date: 21 June 2026


1. Introduction

This policy explains how VisionEdge s. r. o. ("we") process personal data in connection with Faktio — an electronic invoicing solution (conversion, validation and delivery of invoices over the Peppol network, and preparation for reporting to IS EFA). Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll.

2. Dual role in processing

2.1 Controller: With respect to data about user accounts, billing and operation of the Service, we are the controller. This is governed by this policy.

2.2 Processor: With respect to personal data contained in invoices and the rest of the Customer Content (including data transferred via connectors), we are a processor. The controller of that data is the customer; where the customer processes data on behalf of its own clients, it acts as a processor and we as a sub-processor. The processing is governed by the Data Processing Agreement (DPA). If you are a person whose data is processed in an invoice, please address your rights to the relevant customer.

2.3 Invoices may contain personal data (e.g. names and addresses of customers/suppliers, contact details, identifiers, payment data). Special categories of data under Art. 9 GDPR are not to be entered into the Service beyond what is necessary for the invoice content.

3. What data we process (as controller)

  • Account and user data: first name and surname, email, organisation name, role, sign-in identifiers.
  • Billing and identification data: business name, registered office, Company ID, Tax ID, VAT ID and data needed to issue documents and manage the subscription.
  • Technical and operational data: IP address, device and browser data, logs, audit records of actions, cookies (see the separate Cookie Policy).
  • Communication: the content of communications during support and handling of requests.

4. Purposes and legal bases (as controller)

PurposeLegal basis (GDPR)
Provision and administration of the Service, account managementArt. 6(1)(b) — performance of a contract
Billing and bookkeepingArt. 6(1)(c) — legal obligation
Security, abuse prevention, logs and auditArt. 6(1)(f) — legitimate interest
Improving and supporting the ServiceArt. 6(1)(f) — legitimate interest

We do not carry out marketing communications without a legal basis.

5. Retention period

  • Account data and Customer Content: for the duration of the agreement and a reasonable period after its termination (see Terms, Art. 11.4 — export available for 30 days after termination).
  • Accounting and tax documents on the Provider's side: for the period required by law (usually 10 years).
  • Logs and audit records: usually 12 months, unless needed longer for security or evidentiary purposes.

6. Recipients and processors

To provide the Service we use processors with whom we have concluded processing agreements:

ProcessorPurposeLocation
Storecove B.V.delivery of invoices over the Peppol network (Access Point)European Union (NL)
Hetzner Online GmbHinfrastructure hosting (servers)European Union
Clerk, Inc.authentication and user managementUSA
Resend, Inc.sending transactional emailsUSA
MinIO (self-hosted)storage of invoices and documents (within our infrastructure)European Union

Connectors to accounting/ERP systems (e.g. Pohoda mServer, KROS Onix) are activated and managed by the customer; data transfer through them takes place under the customer's control. We may also disclose data to the competent authorities where required by law.

Operational note: Storecove (Peppol) and Clerk are confirmed from Faktio's actual configuration. Hetzner, Resend and MinIO are taken from the VisionEdge standard — verify and adjust to reality before publishing.

7. Transfers to third countries

The processors Clerk and Resend are based in the USA. We safeguard transfers with appropriate safeguards under the GDPR, in particular standard contractual clauses (SCC). Peppol delivery and hosting take place within the EU.

8. Rights of data subjects

You have the right to access, rectification, erasure, restriction of processing, portability, to object to processing based on a legitimate interest, and to withdraw consent. Exercise them at info@visionedge.sk. If your data is processed in a customer's invoices, please exercise your rights with the relevant customer (the controller). You have the right to lodge a complaint with the supervisory authority:

Office for Personal Data Protection of the Slovak Republic
Hraničná 12, 820 07 Bratislava 27
https://dataprotection.gov.sk

9. Cookies

We use only strictly necessary cookies. Details are set out in the separate Cookie Policy.

10. Security of processing

We apply appropriate technical and organisational measures, in particular: encrypted transmission (HTTPS/TLS), security HTTP headers (HSTS), logical row-level isolation of individual customers' data (RLS), access and permission management, audit logging, regular encrypted backups, and monitoring. Delivery over the Peppol network takes place over secure protocols (TLS/AS4) at the Access Point.

11. Changes to this policy

We may update this policy when the Service, processors or legislation change. We will inform you of material changes in an appropriate manner. The current version is always available on the Service's website.

12. Contact

VisionEdge s. r. o., 29. augusta 1503/1A, 958 01 Partizánske, info@visionedge.sk, https://visionedge.sk