vite

PRIVACY POLICY OF THE ACCONTI PEPPOL PLATFORM

Draft for internal review and adaptation before publication

FieldValue
CompanyACCONTI PLUS s. r. o.
Domainacconti.sk
Contactsupport@upkz.sk
DocumentPrivacy Policy
LanguageEnglish
Prepared on13 April 2026
StatusInitial draft

Introduction

Thank you for your interest in using the ACCONTI Peppol e-invoicing platform. To provide the Platform and related services properly, it is necessary for us to process personal data. We take the protection of personal data seriously and use appropriate technical, security and organisational measures to prevent unauthorised access, loss, destruction or misuse.

This Privacy Policy explains how ACCONTI PLUS s. r. o. processes personal data, for what purposes, on what legal bases, for how long, with whom the data may be shared, and what rights data subjects have. This document is intended as an initial draft for internal review.

1. Controller

The controller of personal data for the processing described in this Privacy Policy is ACCONTI PLUS s. r. o., Líščie údolie 12, 841 04 Bratislava – mestská časť Karlova Ves, Slovak Republic, Company ID No. 50547232, Tax ID No. 2120375796, VAT ID No. SK2120375796 (the “Controller”, “we”, “us”).

Contact email for privacy, support and data protection requests: support@upkz.sk.

The Platform is operated in connection with the domain acconti.sk and related systems.

2. Our role: controller and processor

Depending on the type of processing, we act either as an independent controller or as a processor acting on behalf of our business customers.

  • We act as a controller mainly for data relating to contract conclusion, account administration, invoicing, communication, support, security, internal records, legal compliance and the operation of our own website and business.
  • We act as a processor where we process personal data included in invoices, attachments, recipient data, supplier data, metadata, integrations and other customer content processed through the Platform on behalf of a customer who determines the purposes and means of that processing.

Where we act as a processor, the relevant customer is typically the controller and our processing is governed by the applicable contract and Data Processing Agreement.

3. Categories of personal data

  • Identification and registration data, such as name, company affiliation, role, user identifier, Peppol participant identifier and account information.
  • Contact data, such as email address, telephone number, billing address and communication details.
  • Contract, billing and payment data, such as invoicing details, VAT identification, order information and payment status.
  • Document and transaction data, including data contained in e-invoices, credit notes, attachments, routing data, timestamps, message identifiers and delivery statuses.
  • Technical and security data, such as IP addresses, device and browser metadata, API and audit logs, authentication records and system events.
  • Support and communication data, such as requests, tickets, feedback, call notes and implementation correspondence.
  • Any other personal data that a customer intentionally uploads, transmits or imports through integrations into the Platform.

4. Sources of personal data

  • directly from the data subject, for example during registration, onboarding, communication or support;
  • from our customer or its authorised users;
  • from customer systems and enabled integrations or connectors;
  • from recipients, suppliers or other parties involved in document exchange through the Peppol Network;
  • from publicly available registers or compliance sources where reasonably necessary for business verification or legal compliance.

5. Purposes of processing, legal bases and retention when we act as controller

PurposeTypical dataLegal basisRetention
Contracting, account setup and service administrationIdentification, contact, account and implementation dataPerformance of a contract and pre-contractual measuresFor the term of the relationship and ordinarily up to 10 years after its end where needed for claims or records
Billing, accounting, tax and statutory complianceInvoicing, identification and payment dataCompliance with legal obligationsFor the periods required by applicable law, ordinarily up to 10 years
Service security, fraud prevention, access management and incident handlingAuthentication, audit and technical logsLegitimate interest in securing the Platform and protecting our rightsFor a proportionate period, typically up to 10 years where linked to business records; shorter operational log cycles may apply
Customer communication and supportContact data, ticket content, call notes, correspondencePerformance of a contract and legitimate interest in providing supportFor the duration of support and subsequently as needed for evidence, quality control and claims, ordinarily no longer than 10 years
Defence, exercise and establishment of legal claimsRelevant contractual, communication and log dataLegitimate interest and, where applicable, legal obligationFor the duration of the relevant claim, limitation period or legal proceeding
Website operation and strictly necessary cookiesTechnical identifiers and browser/session dataLegitimate interest or consent where requiredAccording to the relevant cookie setting and the necessity of the specific tool

We do not intentionally process special categories of personal data unless such data is included by the customer in business documents or otherwise made available through the Platform. In such case, the customer remains responsible for the legality of the underlying processing unless mandatory law provides otherwise.

6. Processing when we act as processor

When we process personal data on behalf of a customer, we do so only on documented instructions, within the scope of the relevant service and Data Processing Agreement, and only for the duration necessary to provide the Platform and fulfil legal retention or security obligations.

In this context, the customer determines what personal data is uploaded or transmitted through the Platform. This may include names, contact details, tax identifiers, bank details, document content, invoice line items and other personal data embedded in business documents.

If a data subject wishes to exercise rights in relation to data processed on behalf of a customer, the request should primarily be addressed to the relevant customer as controller. We will provide reasonable assistance where required by law or contract.

7. Recipients and categories of recipients

  • our employees and authorised contractors on a need-to-know basis;
  • hosting, cloud, email and IT service providers, in particular services within Microsoft Azure and Microsoft email infrastructure;
  • Peppol Network participants, access points and technical operators strictly as required for document routing and delivery;
  • enabled connectors and integration partners, including eKODigital Slovensko, merk.sk and merk.cz, where relevant to the customer’s implementation;
  • professional advisers, auditors, insurers, banks and payment service providers where reasonably necessary;
  • public authorities, courts, regulators and other third parties where required by law or to protect legal rights.

We maintain and update the list of authorised subprocessors and service providers in accordance with contractual and legal requirements.

8. International transfers

Our primary hosting environment is Microsoft Azure in the West Europe region. We aim to keep personal data within the European Economic Area whenever reasonably possible.

If personal data is transferred outside the European Economic Area, we will do so only where an appropriate transfer mechanism exists, such as an adequacy decision, standard contractual clauses or another lawful safeguard, unless the transfer is otherwise permitted by applicable law or is necessary to carry out the customer’s documented instructions.

9. Retention and deletion

Business documents, related metadata and backups processed through the Platform may be retained for up to ten (10) years and subsequently deleted or anonymised, unless a longer period is required by law, by a valid instruction of the customer, or for the establishment, exercise or defence of legal claims.

Different retention periods may apply to certain technical logs, cookies or isolated support records where a shorter or longer period is objectively justified by the purpose of processing, security requirements or applicable law.

At the end of the relevant retention period, personal data is deleted, anonymised, archived in accordance with law, or further retained only in a restricted form where necessary for legal claims or mandatory compliance.

10. Security measures

  • encrypted transmission channels, including HTTPS/TLS and security controls aligned with Peppol requirements;
  • role-based access management and confidentiality obligations for personnel;
  • logical separation, backup and recovery procedures;
  • logging, monitoring and incident response processes;
  • regular maintenance and reasonable technical and organisational safeguards appropriate to the risk.

11. Rights of data subjects

Subject to the conditions laid down by applicable law, a data subject has the right to request access to personal data, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interests, and the right not to be subject solely to automated individual decision-making where the law provides such protection.

Where processing is based on consent, the data subject also has the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Requests may be sent to support@upkz.sk. We may need to verify identity before handling a request.

12. Complaints and supervisory authority

If a data subject believes that personal data is being processed unlawfully, the person may contact us first so that we can attempt to resolve the matter.

A data subject also has the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic. Current contact details of the authority are published on its official website.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law, our services, our technical infrastructure or our processing practices. The current version should always be published in the relevant customer-facing location.