Privacy policy
What we do with personal data, on what legal basis, for how long, and what you can demand from us. Written under Articles 13 and 14 GDPR.
In force since
Who you are contracting with
- Company
- IRUKA DIGITAL spółka z ograniczoną odpowiedzialnością
- Registered office
- ul. Szczęsna 26, 02-454 Warszawa, Poland
- Registry court
- Sąd Rejonowy dla m.st. Warszawy w Warszawie, Wydział Gospodarczy Krajowego Rejestru Sądowego
- KRS
- 0000980870
- NIP
- 5223230254
- REGON
- 522516722
- EU VAT
- PL5223230254
- Share capital
- 5 000,00 PLN
- [email protected]
- Phone
- +48 690 164 776
In one page
We are IRUKA DIGITAL sp. z o.o., a Polish company. We build and run our own applications — InvoiceMatch (sold in Poland as RozliczTo), e-Sprawozdanie, AduanaLink and CarPanel — and we sell them ourselves, taking payment through Tpay.
Three things are worth knowing before the detail:
- We wear two different hats. For our websites, your account and your invoices we are the controller — we decide what happens and we answer for it. For the documents you upload into the applications we are only the processor — you decide, and we act on your instructions under the data processing agreement.
- We do not sell personal data, and we do not run advertising trackers. There is no advertising network, no data broker and no ad pixel on our sites. The one measurement tool we use — Google Analytics on the marketing site — does not load at all unless you say yes. See the cookie policy.
- You can make us act. Access, correction, deletion, portability, objection — Article 15 to 22 GDPR — and a complaint to the Polish supervisory authority if we get it wrong. Section 9 tells you how.
1. Who is the controller
The controller of personal data is the company identified at the top of this page: IRUKA DIGITAL sp. z o.o., ul. Szczęsna 26, 02-454 Warszawa, Poland, KRS 0000980870, NIP 5223230254.
Write to [email protected] for anything in this policy. It reaches a person, not a queue.
We have not appointed a data protection officer. None of the conditions in Article 37(1) GDPR applies to us: we are not a public authority, and neither large-scale monitoring nor large-scale special-category processing is a core activity. Data protection matters go to the address above and are handled by the management board.
2. What this policy covers
This policy covers personal data we process as controller when you:
- visit irukadigital.com or a product site — invoicematch.app (rozliczto.app in Poland), e-sprawozdanie.com, aduanalink.com, carpanel.app;
- create an account, start a trial or subscribe to one of those products;
- pay us, or ask us for an invoice;
- write to us — support, sales, a legal request, a job enquiry;
- receive a message from us because we think our product solves a problem your business has.
It does not cover what you put inside the applications. If you upload invoices, bank statements, customs declarations or customer records, the people named in those documents are your data subjects and you are their controller. We handle that material strictly on your instructions; the terms are in the data processing agreement, and the security measures and the sub-processor list come with it.
3. Controller or processor — why the distinction matters to you
| Controller (us) | Processor (us, on your instructions) | |
|---|---|---|
| Typical data | Your name, work email, company and NIP, login and session records, subscription and payment history, support correspondence, server logs | Invoices, bank statements, trial balances, customs declarations, vehicle and customer records — whatever you upload or connect |
| Who decides the purpose | We do | You do |
| Governing document | This policy | The data processing agreement |
| Who answers a data subject | We do | You do; we help you within the deadline |
If a person named in a document you uploaded asks us to delete their data, we cannot decide that on our own. We will tell them to contact you and let you know the request arrived.
4. What we process, why, and on what legal basis
Everything below is a separate processing activity with its own legal basis, as Article 13(1)(c) GDPR requires. Where the basis is a legitimate interest we say what that interest is; you can object to any of those under Article 21.
4.1 Running your account and delivering the service
Data: name, work email, password hash (or the identifier from your sign-in provider), company name, address and NIP, role, product and plan, configuration, login timestamps and IP, feature and usage events.
Why: to create the account, provision the product, keep it available, apply the plan limits, and show you your own history.
Basis: Article 6(1)(b) GDPR — performance of the contract you entered into by accepting the terms of service. For a company customer, the individual users’ data is processed on Article 6(1)(f) — our legitimate interest in delivering the service the company bought.
Kept: for as long as the account exists, then for 30 days so you can still export (see section 8).
4.2 Payments and billing
Data: billing name and address, NIP or VAT number, the products and amounts, currency, transaction and order identifiers, payment method type, payment status, refunds and chargebacks, invoice numbers.
We do not receive or store your card number. Card and bank credentials are entered inside Tpay’s own environment and are never exposed to us. What comes back to us is a status and a token — enough to know the payment succeeded, not enough to charge a card ourselves.
Why: to take payment, issue the invoice, keep our tax and accounting records, handle refunds, and pursue or defend a claim if it comes to that.
Basis: Article 6(1)(b) for taking the payment; Article 6(1)(c) for the invoice and the records — the Polish VAT Act, the Accounting Act and the Tax Ordinance leave us no choice; Article 6(1)(f) for fraud prevention and for defending claims.
Kept: accounting and tax documents for 5 years counted from the end of the calendar year in which the tax payment deadline fell (art. 86 § 1 of the Tax Ordinance, art. 74 of the Accounting Act). This period is not shortened by a deletion request — see section 9.
More on Tpay — section 5.
4.3 The AI features
Several products use a large language model: InvoiceMatch explains why an invoice and a bank line match, e-Sprawozdanie reviews a filing against the Accounting Act, AduanaLink cross-checks a commercial invoice against its declaration.
Data: the content you submit to that feature, plus the prompt and the model’s output. It may contain personal data if your documents do.
Why: to produce the result you asked for.
Basis: Article 6(1)(b) where you are the customer; where the content is yours as controller, we act as processor under the DPA and your instruction is the basis.
How it is constrained:
- The model provider acts as our sub-processor, on contract terms that prohibit using your inputs or outputs to train its models.
- The model does not decide anything about you on its own. Every output is a suggestion a human accepts or rejects. This is deliberate: it keeps the feature outside Article 22 GDPR (see section 10).
- Where you interact with an AI feature directly, we tell you so in the interface, as Article 50 of Regulation (EU) 2024/1689 (the AI Act) requires since 2 August 2026.
You can ask us not to run AI features on your data; for some products that means the feature is unavailable rather than degraded, and we will say so plainly.
4.4 Support and correspondence
Data: your message and our reply, your email address and any attachments, plus the account it relates to.
Why: to answer you, to reproduce and fix a problem, and to keep a record of what was agreed.
Basis: Article 6(1)(b) for a customer; Article 6(1)(f) otherwise — our legitimate interest in answering the person who wrote to us and in having a record of it.
Kept: 3 years from the close of the matter, which is the general limitation period for claims connected with business activity under art. 118 of the Civil Code.
4.5 Security, abuse and availability
Data: IP address, user agent, request and error logs, authentication attempts, rate-limit and abuse signals.
Why: to keep the service up, to investigate an incident, to stop credential stuffing and scraping, and to prove what happened if it is disputed.
Basis: Article 6(1)(f) — our legitimate interest, and yours, in a service that is not broken into. Recital 49 GDPR treats this as a legitimate interest expressly.
Kept: 12 months, longer only for a specific log preserved as evidence of an incident.
4.6 Business development — how we may have got your address
If we contacted you and you never gave us your details, this section is your Article 14 notice.
Data: name, business role, employer, business email address, business phone, public company identifiers (KRS, NIP), and the public source we took them from.
Source: public registers and public business directories, your employer’s website, public professional profiles, or a business-contact list we compiled or bought. On request we will tell you exactly which one.
Why: to contact your organisation about a product we believe fits a problem it has.
Basis: Article 6(1)(f) — our legitimate interest in direct B2B marketing, expressly recognised in Recital 47 GDPR. We do this only with business contact data, never with private addresses, and never for special-category or sensitive purposes.
Kept: 12 months from the last contact, or immediately deleted (bar a suppression record) if you object.
Your controls: object under Article 21(2) and we stop — no balancing test, no argument, no “are you sure”. One line to [email protected] is enough. Separately, Polish law (art. 398 of the Electronic Communications Act) requires your prior consent before we send commercial electronic communications to you, and we treat an objection as covering both.
4.7 The marketing website and its statistics
Visiting irukadigital.com puts your IP address and request headers in front of our hosting provider. That is unavoidable for any website and rests on Article 6(1)(f) — we cannot serve you a page without receiving a request.
Analytics. The marketing site can measure which pages are read, using Google Analytics 4. It is off by default and stays off:
- Data: a randomly generated device identifier stored in a cookie, pages viewed, referrer, approximate location derived from a truncated IP address, device and browser type.
- Basis: Article 6(1)(a) — your consent, obtained through the banner before anything loads. Under art. 399 of the Polish Electronic Communications Act consent must come first, so the analytics tag is not present in the page at all until you accept it. Rejecting takes one click on a button the same size as the accept button, and the site works identically either way.
- Withdrawing: the cookie policy has a button that reopens the choice. Withdrawal stops future collection.
- Not in the products. Analytics runs on the marketing site only. There is no analytics tag inside InvoiceMatch/RozliczTo, e-Sprawozdanie, AduanaLink or CarPanel, so your working documents are never in scope.
- Kept: by us, nothing — we see aggregate reports. By Google, per its own retention setting, no longer than 14 months.
Google acts as our processor for this, and the data can reach the United States; see section 7. We have turned off Google signals and advertising features, so the measurement is not fed into ad profiles.
Fonts. The typeface is served from our own domain. Loading it from a third-party font service would expose your IP address to that service on every page load, so we do not do that.
5. Payments through Tpay
All our products take payment through Tpay, the payment system operated by Krajowy Integrator Płatności S.A., plac Władysława Andersa 3, 61-894 Poznań, KRS 0000412357, NIP 7773061579, REGON 300878437 — a Polish national payment institution supervised by the Polish Financial Supervision Authority (KNF), entered in the register of payment services under number IP27/2014 and holding acquirer status. Tpay has its own data protection officer, reachable at [email protected].
Two points that most privacy policies get wrong, and that matter for your rights:
Tpay is not our processor. For executing and settling your payment, and for meeting its own obligations under payment-services law, anti-money-laundering law, accounting law and the card-scheme rules, Tpay decides the purposes itself and is a separate controller. We cannot instruct it on that processing and we cannot answer for it. Tpay publishes its own privacy notice and you have the full set of GDPR rights against Tpay directly, in addition to your rights against us.
We are the seller. Tpay collects the money; the contract is with us. That means the invoice, the VAT, the refund and the complaint are all ours to deal with — see the terms of service.
What passes between us and Tpay: the order identifier, the amount and currency, the payment method type, your billing name and email, the payment status, and — where a payment is disputed or looks fraudulent — the information needed to resolve it. Card numbers and bank credentials go to Tpay, not to us.
6. Who else receives personal data
We keep the list of providers short on purpose and publish it in full. The complete, current register — what each provider does, where it is, and whether it is our processor or a controller in its own right — is at sub-processors and other recipients.
Beyond that register, personal data may go to:
- our accountant and tax adviser, and our bank, for statutory bookkeeping and settlement;
- Google, as our processor for site statistics, but only if you consented;
- lawyers, auditors, debt-recovery or insurers, where we need to establish, exercise or defend a legal claim;
- public authorities — the tax administration, KSeF, a court, the police, the President of the Personal Data Protection Office — where a legal provision obliges us to hand something over. We do not treat an informal request as an obligation, and we check the legal basis before we answer one;
- an acquirer or successor, if the business or a product is ever sold or reorganised, in which case we will tell you before your data changes hands.
We do not sell personal data. We do not share it for anyone else’s advertising.
7. Transfers outside the EEA
Some of our providers are established in, or transfer to, the United States: Cloudflare, Supabase, Anthropic, Resend and — if you consented to analytics — Google. Using them means personal data can be transferred to or accessed from a third country.
The transfer tool we rely on is Article 46(2)(c) GDPR — the European Commission’s Standard Contractual Clauses, entered into as part of each provider’s data processing agreement, together with a transfer impact assessment and the technical measures in Annex 2 of the DPA (encryption in transit and at rest, access control, minimisation). Where a provider is also certified under the EU–US Data Privacy Framework, that decision applies in addition; we do not rely on it alone.
AduanaLink and CarPanel serve customers in Colombia and elsewhere in Latin America. Colombia is not covered by a European Commission adequacy decision. Where our support staff or a customer’s own users access data from outside the EEA, that access is likewise a transfer and is covered by the Standard Contractual Clauses in our customer agreement. Colombian users additionally have the rights given by Ley 1581 de 2012; nothing in this policy takes those away.
You can ask us for a copy of the clauses we rely on for a specific provider. Write to [email protected] and we will send the relevant one.
Where each product’s database actually sits. We would rather give you the region than a vague assurance:
| Product | Database region |
|---|---|
| InvoiceMatch / RozliczTo | Stockholm, Sweden (EU) |
| e-Sprawozdanie | Paris, France (EU) |
| AduanaLink | London, United Kingdom — a third country, covered by the Commission’s adequacy decision of 19 December 2025, so no Standard Contractual Clauses are needed |
| CarPanel | N. Virginia, United States — a genuine third-country transfer, covered by the Standard Contractual Clauses |
| Our own account and billing records | Paris, France (EU) |
If you use CarPanel, note that the data you hold about your own customers is stored in the United States. That is lawful on the clauses above, and if it does not suit your risk assessment, tell us — moving a project between regions is a migration we can plan with you.
8. How long we keep things
| What | How long | Why that long |
|---|---|---|
| Account and configuration | The life of the account, then 30 days | The 30 days are your export window under the terms — Article 25 of the Data Act |
| Documents uploaded to InvoiceMatch | Deleted 30 minutes after processing | The product does not need them afterwards, so it does not keep them |
| Other customer content in the apps | As set in the DPA and your product settings | You decide; we execute |
| Invoices and accounting records | 5 years from the end of the calendar year in which the tax was payable | art. 86 § 1 Tax Ordinance; art. 74 Accounting Act |
| Support correspondence | 3 years from closure | Limitation period, art. 118 Civil Code |
| Server and security logs | 12 months | Long enough to investigate, short enough not to hoard |
| Marketing consent and objections | Until withdrawn, plus a suppression record kept indefinitely | So that “stop” stays stopped |
| Analytics consent choice | On your device until you clear it or change it | It records your decision, so it has to outlast the visit |
| Analytics data at Google | 14 months maximum | Google’s retention setting, configured to the shortest useful period |
| Prospect business contact data | 12 months from last contact | Beyond that the interest no longer outweighs the intrusion |
When a period ends we delete or irreversibly anonymise. Backups age out on their own cycle, within 30 days of the deletion.
9. Your rights
Under the GDPR you can require us to do the following. All of it is free, and we answer within one month of the request; if it is genuinely complex we may extend by two months and will tell you why inside the first month.
- Access — Article 15. A copy of your data and the information in this policy applied to you specifically.
- Rectification — Article 16. Correct what is wrong; complete what is missing.
- Erasure — Article 17. We must delete, unless we still need the data for a legal obligation (invoices are the usual case) or for a legal claim. If we refuse in part, we will tell you exactly which part and which provision.
- Restriction — Article 18. Freeze the processing while a dispute about accuracy or legitimate interest is resolved.
- Portability — Article 20. Data you gave us, in a structured, commonly used, machine-readable format. In practice: an export, not a screenshot.
- Objection — Article 21. Against anything we do on a legitimate-interest basis. For direct marketing the objection is absolute — we must stop, and we do.
- Withdraw consent — Article 7(3). At any time, as easily as it was given. Withdrawal does not undo what was lawful before it.
To exercise any of these, write to [email protected]. We may ask you to confirm who you are, but only where we genuinely cannot tell — we will not use identity checks as an obstacle.
Complaints. If you think we have handled your data unlawfully, tell us first if you are willing — it is usually the fastest fix. You do not have to. You can complain directly to the supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office) ul. Stawki 2, 00-193 Warszawa, Poland uodo.gov.pl
You can also bring a claim before a court. If you live in another EU or EEA country, you may complain to your own national supervisory authority instead.
10. Automated decisions and profiling
We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you. Article 22 GDPR is therefore not engaged.
Concretely: our matching scores, AI reviews and health signals are suggestions with the arithmetic attached. A person decides. No one is refused an account, charged differently, or reported to an authority because a model said so.
Two nuances we would rather state than hide:
- Tpay and the card schemes do run automated fraud and risk checks on payments, and a check can result in a payment being declined. That processing is Tpay’s, on its own legal basis, and Tpay’s privacy notice explains the logic and your rights against it. If a payment is declined we will help you find another way to pay.
- Inside our own operations we score account health to decide who to email about a stalled trial. It changes which message you get, not what you pay or whether you are served, and you can object under Article 21 at any time.
11. Security
We are a small team, so our security posture is built on things that hold up without a security department: encryption in transit (TLS) and at rest; least-privilege access with individual accounts and multi-factor authentication; separation between production and everything else; secrets held in a managed secret store, never in the repository; deny-by-default authorisation on the database; and retention limits short enough that a breach cannot spill what we no longer hold.
The measures are described in full in Annex 2 of the data processing agreement, which is the document we are contractually bound to.
If something happens, we will notify the President of the Personal Data Protection Office within 72 hours where Article 33 requires it, and we will tell affected people without undue delay where Article 34 requires it. If you are our customer and the incident concerns data we process for you, you get told without undue delay whether or not it meets the notification threshold — you need to make your own Article 33 assessment, and you cannot do that if we sit on it.
Found a vulnerability? Write to [email protected]. Report it to us before you publish it and we will not treat you as an attacker.
12. Children
Our products are business tools. They are not directed at children and we do not knowingly collect data from anyone under 16. If a child’s data reaches us anyway — for instance inside a document a customer uploaded — it is handled under the DPA and, if you tell us, we delete it.
13. Cookies and device storage
Handled separately and honestly in the cookie policy, including why there is no consent banner on this site.
14. Changes to this policy
The date at the top of this page is the version in force. When we change something that affects you materially — a new purpose, a new legal basis, a new category of recipient — we will notify account holders by email before it takes effect, not quietly swap the page. Previous versions are available on request.
15. Contact
[email protected] — for exercising a right, for a question about this policy, or for telling us we have got something wrong.
Postal address, registry data and phone: at the top of this page.