Privacy policy
Last updated: 30 July 2026.
1. Controller and contact
The controller of the data tied to your account in KSeF Kit is Ernest Bursa, ul. Dąbrowskiego 96/5b, 60-576 Poznań, Poland, NIP 7831677335. Data contact: [email protected].
2. Roles: controller and processor
- For your account data (email, company details, billing data) we are the controller.
- For the personal data contained in your invoices (e.g. NIP, names and addresses of your counterparties) you are the controller, and we act as a processor on your documented instructions under a data processing agreement (DPA).
3. What data we process
- Account data: email, company details (including NIP), settings.
- Invoice data pulled from Stripe and converted to FA(3) (including counterparty data).
- KSeF authentication (token or certificate) — stored encrypted.
- UPO receipts and KSeF numbers returned by the system.
4. Purposes and legal bases
We process data to perform the contract — file your invoices to KSeF and give you the proof (Art. 6(1)(b) GDPR), to meet legal obligations (Art. 6(1)(c)), and in our legitimate interest (Art. 6(1)(f)), e.g. service security.
5. Recipients and processors
We use trusted providers acting on our instructions: Stripe (the source of invoices and payments), a hosting provider, and KSeF — the Polish tax authority we file to on your behalf. The current list of sub-processors is provided as part of the DPA.
6. Analytics and session recordings
The KSeF Kit website runs Microsoft Clarity. It records session recordings (a replay of cursor movement, clicks, scrolling and page-to-page navigation), click heatmaps, and basic browser technical data. The recipient of that data is Microsoft; the processing is described in the Microsoft Privacy Statement.
We use it for one purpose: to see where signing up and setting up an account gets stuck. The basis is our legitimate interest in removing those blockages (Art. 6(1)(f) GDPR).
Financial data is masked in the recordings. Every page behind sign-in is marked as masked in its entirety, and we additionally mark the individual elements that render NIPs, company names and addresses, amounts, KSeF numbers, UPO contents and the KSeF token. According to Microsoft's documentation, masked content is not sent to Microsoft.
Masking covers the content of page elements. It does not cover HTML attribute values or the contents of style sheets, so we do not place any of the data listed above there. Clarity does not run in the KSeF Kit panel embedded in Stripe.
How to limit this collection:
- Clarity honours the browser's Global Privacy Control (GPC) signal. It does not respond to the older Do Not Track (DNT) header.
- You can opt out via the Digital Advertising Alliance opt-out page, selecting Microsoft from the list.
- You can object to this processing by writing to [email protected].
We do not use a cookie consent banner.
7. A phone number, if you ask us to call
Our onboarding emails offer a short phone call. If you use that form, the number you give us (and any note) is passed on in a single email to the KSeF Kit owner's mailbox and used once — to arrange and hold that call. We do not store the number in the application database: there is no field for it, so it will never appear in a data export or on your account. We delete the message carrying the number from the mailbox once the call is over.
Giving us a number is entirely voluntary — the basis is your consent (Art. 6(1)(a) GDPR), given by submitting the form. Simply replying to our email is an equally good route.
8. Retention
We keep UPOs as your proof of compliance for as long as you use the service. Your KSeF authentication (token or certificate) and invoice data are deleted after you disconnect your account, unless the law requires longer retention. KSeF stores invoices for 10 years; our storage does not relieve you of your own record-keeping duties (generally until the tax liability is time-barred).
9. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection. You can export your data and UPOs at any time. You may also lodge a complaint with the President of the Personal Data Protection Office (UODO).
10. Transfers outside the EEA
We process data primarily in the EU/EEA. If a provider processes data outside the EEA, we rely on an adequacy decision or standard contractual clauses (SCCs) with additional safeguards.
11. Security
We use encryption of sensitive data (including the KSeF token), isolation, and restricted access. We use your KSeF token solely to file your invoices.
12. Contact
Privacy questions: [email protected].
Questions? Email [email protected].