1. Controller and contact
Controller: R. Redivo, dynafis / General Informatics, Fijewo 58a, 14-260 Lubawa, Poland. German office: Am Sandfeld 11, 76149 Karlsruhe, Germany.
Email: support@dynafis.com · Website: dynafis.com · REGON: 384103047 · VAT ID: PL7441822686.
Privacy requests may be sent to support@dynafis.com. No data protection officer is currently appointed unless a statutory appointment obligation applies.
2. Scope and privacy roles
This policy applies to public websites, demos and contact functions, user accounts, contract and billing processes and use of the dynafis platform.
dynafis is controller for website, account, contract, payment, security and its own communication data. For invoices, receipts, banking, client, employee and business-partner data processed by customers, dynafis normally acts as processor under Article 28 GDPR. The customer is then controller and the primary contact for data subject requests.
3. Sources and categories of data
We receive data from users, workspace administrators, customers and their agents, connected authorities and providers, and automatically from devices and system logs.
Depending on use, we process identity, contact, login and role data, company and tax identifiers, contract and billing data, payment status, support communications, device and log data, IP addresses, consent data, document content, bank transactions, e-invoice metadata, audit and security events and configured integration data.
4. Website, server logs and security
When the website is accessed, we process IP address, date and time, requested URL, referrer, browser and device information, response status and transferred data volume. This is necessary for delivery, diagnostics, misuse prevention and system security.
The legal basis is Article 6(1)(f) GDPR. Security logs are generally retained only as long as required for analysis and defence; records relating to a concrete incident may be kept until investigation and claims are completed.
5. Registration, contract, billing and business verification
For registration and contracts we process names, business contact data, organisation, role, legal entity, billing address, tax identifiers, plan, orders, invoices, payment status and contractual communications.
Legal bases are Article 6(1)(b) GDPR, Article 6(1)(c) for tax and accounting obligations and Article 6(1)(f) for fraud prevention, business verification, receivables and secure account administration.
6. Customer content and processing on behalf
Customers may process invoices, receipts, finance, banking, employee, supplier, customer and client data. The data processing agreement and the customer's configuration determine subject matter, purpose, data subjects and duration.
dynafis processes such data only on documented instructions unless law requires otherwise. Customers must ensure that upload, retrieval, linking, storage, disclosure and deletion are lawful and that required privacy information is provided.
7. OCR, AI and automated assistance
OCR, rules and AI services may analyse documents, extract fields, flag risks, suggest matches, generate text or prioritise workflows. Content may be transferred to contracted providers where required for the selected feature.
Customer data is not used to train generally available AI models unless the customer separately and expressly agrees. dynafis does not make solely automated decisions under Article 22 GDPR with legal or similarly significant effects on individuals. Professional decisions and approvals remain with the customer.
8. E-invoicing, authority, banking and import connectors
When KSeF, Peppol, EBICS, bank import, SFTP, import mailbox, webhooks or similar services are used, we process participant, sender, bank, transaction, document, status and log data for authentication, transfer, receipt, matching, error handling and evidence.
Depending on the connector, authorities, banks, access points or technical providers act as independent controllers or processors and their notices also apply. Credentials and certificates are processed only as required for the connection and protected by secrets and access controls.
9. Payment processing
For paid services, payment and billing data is sent to the selected payment provider, especially Mollie or PayPal. Payment providers generally act as independent controllers for authorisation, fraud checks and legal obligations.
dynafis generally does not store full card or online-banking credentials, but stores payment references, status, amount, currency, invoice linkage and necessary evidence. Legal bases are Article 6(1)(b) and (c) GDPR.
10. Sign-in with Google or Apple
For optional Google or Apple sign-in, we receive a provider identifier, name, email address and authentication status depending on the user's release. The provider learns that its service is used for dynafis.
The legal basis is Article 6(1)(b) GDPR. The link may be removed in the account or with the provider; data already required for performance or evidence is unaffected.
11. Support, forms and B2B communication
For enquiries we process contact data, company, subject, message, attachments, technical diagnostics and handling history. Processing is for pre-contractual or contractual purposes and our legitimate interest in support and documentation.
We may inform business customers about similar services, security and product information where legally permitted. Direct marketing may be objected to at any time. Newsletters and other marketing requiring consent are based on Article 6(1)(a) GDPR.
12. Cookies, local storage and Turnstile
Necessary cookies and local storage support language, login, session, security, load balancing, consent status and core functions. The basis is Article 6(1)(b) or (f) GDPR and applicable ePrivacy law.
Optional analytics or convenience technologies activate only after consent. Cloudflare Turnstile may process device, network and interaction signals to detect bots and protect forms. Consent can be changed at any time in cookie settings for the future.
13. Legal bases
We rely on Article 6(1)(a) GDPR (consent), (b) (contract and pre-contractual steps), (c) (legal obligations) and (f) (legitimate interests). Legitimate interests include operation and security, misuse and fraud prevention, support, product improvement using aggregated data, B2B communication and legal enforcement.
For customer-controlled processing, the customer determines the legal basis and dynafis processes under Article 28 GDPR and documented instructions.
14. Recipients and subprocessors
Recipients may include hosting, database, object and backup storage providers, email and support services, monitoring and security providers, OCR and AI providers, payment services, authentication providers, Peppol and e-invoicing providers, banks and authorities.
We select providers carefully, limit access and enter into appropriate contracts. A current list of key subprocessors is available in the Trust Center or on request. Authorities receive data only on a legal basis or valid order.
15. International transfers
We prefer processing in the EU or EEA. Where providers process data in or can access it from third countries, transfers rely on an adequacy decision, EU Standard Contractual Clauses or another permitted safeguard, together with additional measures where required.
For certified US providers, the EU-US Data Privacy Framework may be used. Information on applicable safeguards can be requested from support@dynafis.com, subject to security and trade-secret limitations.
16. Retention and deletion
We keep data only as long as required by purpose, contract, security or law, then delete or anonymise it. Unless contract or law requires otherwise, current operational guidelines include:
• anonymous invoice checks: usually up to 24 hours; checks linked to an email: up to 14 days; paid reports: up to 365 days;
• raw bank import files: usually up to 90 days; bank webhook data: up to 30 days;
• support and contact requests: usually up to 180 days; forms classified as spam: up to 30 days;
• Peppol transport and evidence data: where required, up to 10 years;
• contract, invoice and tax records: statutory retention periods;
• account data and customer content: contract term, subsequent export window and then deletion policy. Backups are overwritten on a rolling basis and used only for restoration.
17. Technical and organisational measures
Measures include, as appropriate to risk, tenant separation, roles and permissions, two-factor authentication, transport encryption, secrets management, audit logs, backup and recovery, monitoring, vulnerability and dependency checks, access restriction and incident response.
No system can guarantee absolute security. Incidents are assessed, documented and notified to customers, authorities or data subjects as required by law.
18. Data subject rights
Subject to legal conditions, individuals have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. Withdrawal does not affect processing lawfully carried out before withdrawal.
For data processed on behalf of a customer, requests should normally be directed to that customer. dynafis supports the customer under the processing agreement. Identity verification may be required to prevent unauthorised disclosure.
19. Right to complain
Individuals may complain to a supervisory authority. The relevant Polish authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.
A complaint may also be lodged with another authority competent under Article 77 GDPR at the individual's habitual residence, workplace or place of the alleged infringement.
20. Required data, minors and profiling
Contract and account fields marked as required are needed to conclude and perform the contract. Without them, some services cannot be provided. Optional information is marked or apparent from context.
dynafis is intended for businesses, not minors. We do not conduct advertising profiling or solely automated decision-making under Article 22 GDPR. Risk and priority indicators in the software assist authorised users.
21. Changes to this policy
We update this policy when features, providers, law or processing changes. The update date appears above. Material changes affecting registered users are communicated in the application, by email or another suitable channel.
This version describes the intended production operation. Enabled providers, subprocessors, retention periods and country features must remain aligned with the Trust Center and data processing agreement.
