Privacy policy
Last updated: 10 September 2026.
1. Controller and contact
The controller of the data tied to your account in KSeF Kit is Ernest Bursa, ul. Dąbrowskiego 96/5b, 60-576 Poznań, Poland, NIP 7831677335. Data contact: [email protected].
2. Roles: controller and processor
- For your account data (email, company details, billing data) we are the controller.
- For the personal data contained in your invoices (e.g. NIP, names and addresses of your counterparties) you are the controller, and we act as a processor on your documented instructions under the Data Processing Agreement (DPA).
3. What data we process
- Account data: contact email, company details (including NIP), and settings. You can provide the email yourself; when you install the Stripe App we may also read the email associated with the Stripe account or, if absent, the public support email in its business profile. We do not treat an address obtained from Stripe as marketing consent.
- Invoice data pulled from Stripe and converted to FA(3) (including counterparty data).
- KSeF authentication (token or certificate) — stored encrypted.
- UPO receipts and KSeF numbers returned by the system.
4. Purposes and legal bases
We process data for which we are the controller to perform our contract with you, including operating your account (Art. 6(1)(b) GDPR), to meet our own legal obligations (Art. 6(1)(c)), and in our legitimate interest (Art. 6(1)(f)), such as service security and contact with customer representatives. You determine the legal basis for entrusted invoice data as its controller; we process that data on your instructions and under the DPA.
We may use the contact email for messages necessary to operate the service: an invoice rejection or hold, a payment problem, or an interruption in filing to KSeF. These are service messages, not advertising; they help us perform the service and protect your filing workflow. You can disable the optional service notifications in settings.
We send onboarding tips, product updates, offers, and occasional requests for feedback or a short research call by email only after separate, voluntary consent. Consent is not required to use KSeF Kit. You can withdraw it at any time in settings or through the link in a message, without affecting earlier lawful processing. Withdrawing marketing consent does not disable service messages that are necessary to operate your account.
5. Automation, profiling and decisions
The core invoice filing process is automated. Once you configure the integration and a Stripe invoice is finalised, we retrieve its data, convert it to FA(3), submit the document to KSeF, collect its status, KSeF number and UPO, and write the result back to Stripe. Entrusted personal data is therefore subject to automated processing to the extent necessary to provide the service.
We do not use entrusted data for profiling. We do not create profiles of individuals, perform scoring, or analyse or predict their behaviour, preferences, reliability or personal circumstances. We do not use AI or statistical models in this process. We apply predetermined rules to the data of the individual document to check its completeness, determine how to map the transaction to FA(3), and carry out the filing instruction. If required data is missing or a case is unsupported, the document is held rather than submitted using assumptions of our own. The conditions and outcome of each rule are described in How filing works.
In our assessment, this process is not automated individual decision-making within the meaning of Article 22 GDPR. We do not make a decision about an individual that produces legal effects concerning that person or similarly significantly affects them. We perform technical operations on the customer's documented instructions. The customer decides to finalise an invoice, create a correction and enable the integration, while acceptance or rejection of the document is the result returned by KSeF. If you use Stripe or invoice data for other automated decisions about individuals, as controller you are responsible for assessing those activities separately.
6. Recipients and processors
For entrusted data, we use the infrastructure and service providers listed in section 5 of the DPA. Stripe is also the source of your invoices, the recipient of filing updates and a payment provider. KSeF (the Ministry of Finance), to which we submit invoices on your behalf, is a separate statutory recipient, not our sub-processor.
Sentry (Functional Software, Inc.) provides error diagnostics. Before sending reports, we filter invoice and UPO content, buyer data and secrets. Reports may retain account and document identifiers and the part of a KSeF number that excludes the tax ID. This is data minimisation and pseudonymisation; the identifiers can let us locate the document in our database. The DPA describes the processing terms.
7. Analytics, session recordings and advertising
With your consent, the KSeF Kit website may run Microsoft Clarity. It records session recordings (a replay of cursor movement, clicks, scrolling and page-to-page navigation), click heatmaps, and basic browser technical data. The recipient is Microsoft Ireland Operations Limited, acting as an independent controller under the Clarity terms. The processing is described in the Microsoft Privacy Statement.
We use it for one purpose: to see where signing up and setting up an account gets stuck. Clarity does not connect or place its cookies until you enable Product analytics and save the choice. The basis for accessing or storing information on your device and the related processing is your consent (Art. 6(1)(a) GDPR).
Financial data is masked in the recordings. Every page behind sign-in is marked as masked in its entirety, and we additionally mark the individual elements that render NIPs, company names and addresses, amounts, KSeF numbers, UPO contents and the KSeF token. According to Microsoft's documentation, masked content is not sent to Microsoft.
Masking covers the content of page elements. It does not cover HTML attribute values or the contents of style sheets, so we do not place any of the data listed above there. Clarity does not run in the KSeF Kit panel embedded in Stripe.
If you leave Product analytics disabled, the Clarity script is not downloaded. You can change your choice through Privacy settings in the footer. When you withdraw consent, we send Clarity a denied signal and remove the tool's cookies that our site can access; cookies belonging to Microsoft domains remain under Microsoft's and your browser's control.
Google Ads, when we are running ads
When a search campaign is live, with your consent this site loads the Google Ads conversion tag, without Google Analytics or Tag Manager. The tag reports signup to attribute it to an ad click. The event also includes your KSeF Kit account identifier for deduplication, the conversion identifier and the PLN currency; it does not contain invoice content or buyer data. For this measurement Google acts as an independent controller under the Google Ads Controller-Controller Data Protection Terms.
The Google Ads tag is not downloaded until you enable Ad measurement. The banner may also appear for Product analytics alone. Leave Ad measurement disabled and the Google advertising script is not requested. You can change your answer at any time through Privacy settings in the footer. The answer, and the moment you gave it, are stored in your own browser, not on our servers.
Separately, we record the click identifier Google appends to an ad link (gclid, or
gbraid/wbraid on iOS) on the account you create, along with the campaign name and the time of
the click. Once linked to an account, that identifier is pseudonymous personal data. We keep it so we can tell which
campaigns bring in customers who stay, and the basis is our legitimate interest in not wasting
an advertising budget (Art. 6(1)(f) GDPR). It stays in our database; if we ever report a paid
subscription back to Google Ads as an offline conversion, that identifier is what we would send.
8. A phone number, if you ask us to call
Our onboarding emails offer a short phone call. If you use that form, the number you give us (and any note) is passed on in a single email to the KSeF Kit owner's mailbox and used once — to arrange and hold that call. We do not store the number in the application database: there is no field for it, so it will never appear in a data export or on your account. We delete the message carrying the number from the mailbox once the call is over.
Giving us a number is entirely voluntary — the basis is your consent (Art. 6(1)(a) GDPR), given by submitting the form. Simply replying to our email is an equally good route.
9. Retention
When an integration is disconnected, we immediately remove access to its authentication material in KSeF Kit and request deletion from the storage provider. If provider access has already been revoked, that provider's own retention and deletion controls apply. We delete locally stored tokens or certificates, Stripe keys, and webhook signing secrets. Disconnection does not automatically delete filing history. Continuing to store invoice data, KSeF numbers and UPOs on your behalf requires your documented instruction and an agreed period. After services involving processing end, we return or delete entrusted data at your choice and delete copies, unless the law requires us to retain it. Section 7 of the DPA describes the procedure and how to submit instructions.
We retain account and contact data while providing the service and afterwards only as needed to close the account, handle requests, or defend claims. Withdrawing marketing consent stops future marketing; we may retain the suppression record so that we do not start sending it again. KSeF retains documents independently of us, and our archive does not replace your own record-keeping duties.
10. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection. You can export your data and UPOs at any time. You may also lodge a complaint with the President of the Personal Data Protection Office (UODO).
11. Transfers outside the EEA
Providers operating globally, including Cloudflare, Stripe, cloud-hosted Sentry, Microsoft and Google, may process data outside the EEA, including in the US. This concerns data within the scope described above; it does not mean that invoice content goes to every provider. For such transfers we use an applicable adequacy decision (including the DPF for covered US transfers) or standard contractual clauses (SCCs) with supplementary safeguards where needed. You can request information about locations and transfer grounds using the contact below.
12. Security
We use encryption of sensitive data (including the KSeF token), isolation, and restricted access. We use your KSeF token solely to file your invoices.
13. Contact
Privacy questions: [email protected].
Questions? Email [email protected].