Product
Dynafis
Dynafis Trust Center
Dynafis processes sensitive finance and invoice data with clear security measures, controlled access rights and traceable processes.
Last content review: July 30, 2026
01
Dynafis
General Informatics
European Union · Poland
support@dynafis.com
support@dynafis.comService provider: R. Redivo, dynafis / General Informatics
Registered business address: Fijewo 58a, 14-260 Lubawa, Poland
German office: Am Sandfeld 11, 76149 Karlsruhe, Germany
Email: support@dynafis.com
Website: dynafis.com
REGON: 384103047
VAT ID: PL7441822686
VAT-5E: PL7441822686
D-U-N-S® Number: 850940431
The listed registration and identification numbers are provided for clear allocation of the service provider. Changes or corrections are updated here after professional review.
For support, sales, privacy and contract requests, please use the contact channels stated on dynafis. Legally binding notices should be sent to the registered business address in Poland unless another receiving office has been expressly confirmed in an individual case.
dynafis is aimed primarily at businesses and professional users in the EU. VAT, reverse-charge notes and invoice details are shown depending on customer type, place of supply, registration status and checkout configuration.
Registration and identification details: REGON 384103047, VAT-5E / VAT ID PL7441822686, D-U-N-S® Number 850940431.
The website provides information about AI-assisted finance automation, invoice data processing, export packages and compliance workflows. Content is general product information and not tax, legal, audit or accounting advice. Professional outputs must be reviewed by qualified persons before use.
External links are checked carefully when added. The operators of external pages are solely responsible for their content. If we become aware of unlawful content, affected links will be removed promptly.
dynafis is intended exclusively for businesses and professional users. We are neither obliged nor willing to participate in consumer dispute resolution proceedings unless mandatory law requires this.
The former EU online dispute resolution platform was discontinued on 20 July 2025. Previous references or links to that platform no longer apply.
02
Dynafis processes data for defined purposes, with role-based controls and according to enabled features and contracts.
Depending on the use case, the customer acts as controller and Dynafis as processor. Dynafis processes its own contract, security and billing data as controller.
Only data required for the selected invoice, review, export or integration workflow is processed.
Retention periods are separated by data type and use. Anonymous short-check artefacts are scheduled for deletion after 24 hours by default.
Reviewed invoice data and approved artefacts can be exported through supported formats and API flows.
International transfers are described and safeguarded only according to the providers and contracts actually enabled.
A DPA is available as a central legal document and is not replaced by marketing claims.
| Provider | Purpose | Data category | Processing region | Safeguard | Status | Last review |
|---|---|---|---|---|---|---|
| Contractually named hosting/storage provider | Application operation and object storage | Application data and documents | Region stated in the DPA | Contract, access controls and documented operational measures | Active | Jul 30, 2026 |
| Configured AI provider | Optional extraction and assistance | Only content required for the enabled flow | According to provider and contract configuration | Production approval, minimised data flow and provider training disabled | Provider-specific | Jul 30, 2026 |
| Mollie / PayPal | Optional payment processing | Billing and transaction data | According to the selected provider and contract documentation | Only for the enabled payment method; Dynafis does not store complete card details | Provider-specific | Jul 30, 2026 |
| Brevo or configured SMTP provider | Transactional and support email | Email address and required message content | According to provider and contract configuration | Minimised message content, restricted access and retention rules | Provider-specific | Jul 30, 2026 |
03
Status labels distinguish active, planned and provider-specific measures.
Public web and API connections are provided over TLS.
Passwords are not stored in plain text; authentication and tokens are protected server-side.
Every account can optionally be protected with an authenticator app, QR code and one-time recovery keys.
Roles, object access and API actions are checked server-side.
Workspace, organisation, client and legal entity are treated as separate access contexts.
Security-relevant changes, approvals and processing steps are logged traceably.
Credentials are not exposed in the interface or public logs and are separated by purpose.
Backups, recovery and objectives are documented as operational evidence; commitments are based on documented tests.
Service health, queues and security-relevant errors are monitored and communicated without sensitive internals.
Development, test, sandbox and production use separate configurations and release rules.
04
Dynafis Secure Processing combines technical and organisational safeguards for controlled, traceable finance and invoice workflows.
File type, size, origin and permitted processing paths are checked before further processing.
Original, extraction, rule finding, AI suggestion, human decision and export remain separately traceable.
Data and connectors are processed in the correct organisation, client and legal-entity context.
Approvals and sensitive actions are tied to roles, permissions and, where configured, four-eyes review.
Versions, changes, decisions and exports can be traced through audit and activity data.
Exports follow permissions and format boundaries; deletion respects retention and audit rules.
05
Connectors are labelled transparently by availability and dependency. Provider or authority logos are not presented as Dynafis certification.
Client- and legal-entity-specific connection with test and production context.
Peppol services are provided through a connected Peppol service provider.
CAMT.053, MT940 and CSV import with traceable allocation and manual review.
Automatic key- or password-protected retrieval from configured directories.
Automatic retrieval of approved statement attachments through a configured mailbox.
Read-only retrieval as a premium connector; activation and bank keys require approval by the bank.
06
Operational information is provided through defined status and support channels.
Last content review: July 30, 2026
07
Report a potential security issue through the protected form. Submissions are validated server-side, protected against abuse and stored as traceable support cases.
08
Only evidence that actually exists is shown as active.
Policies, risks, controls and operational evidence are maintained with versioning.
Privacy notice, DPA and cookie documentation are linked centrally.
Will only be shown as completed after a real test and approved evidence.
Readiness and ISMS structures are being prepared. Dynafis currently claims neither certification nor formal conformity.
09
Optional AI features are described separately, purpose-bound and transparently.
The active provider, model, purpose and data flow must be documented and approved before production use.
Customer documents and invoice content are not used to train Dynafis models.
AI outputs are treated as labelled suggestions with provenance and confidence; acceptance, modification or rejection remains traceable.
10
No. Readiness and ISMS structures are being prepared; certification will only be published after it is actually granted.
Peppol services are provided through a connected Peppol service provider. Dynafis does not claim its own Access Point certification.
Privacy notice, DPA, terms and imprint are linked centrally in the footer and in the company section of this Trust Center.
Use the protected form in this Trust Center. Do not send passwords, API keys or complete customer documents.