Skip to content
C
Citofact

Privacy Policy

Last updated: June 25, 2026

Draft template. Before launching publicly, have this reviewed by qualified Latvian counsel.

This notice explains how Citofact processes personal data when you use our invoicing service and visit our website. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and, for users in Switzerland, the Swiss Federal Act on Data Protection (FADP).

1. Who is responsible

The controller for the processing described here is:

SIA "Gulbis Solutions"
Mezciema iela 44 - 41
Riga, LV-1079, Latvia
E-mail: privacy@citofact.com

We have not appointed a Data Protection Officer: our processing does not consist of large-scale processing of special categories of data or large-scale regular monitoring, so the appointment thresholds in Art. 37 GDPR are not met. You can reach us on any data-protection matter at the address above.

2. Controller and processor roles

For your account data — your profile, workspace, branding, billing and tax identity — Citofact is the controller and this notice applies.

For the client and invoice data you enter about your own customers, you are the controller and Citofact acts only as your processor, on your instructions. That relationship is governed by our Data Processing Agreement, not by this notice. You remain responsible for informing your customers about that processing.

3. What data we collect

When you sign up, we store the email address and profile information provided by your identity provider (Google), and the company name, currency and branding assets (logo, accent color) you enter during onboarding. To produce compliant invoices, we store your workspace's legal and tax identity (address, VAT ID, tax number, legal form, register details) and bank details (IBAN, BIC) that you choose to show on invoices.

When you create invoices, we store the invoice contents you author — line items, your clients' contact details, totals, due dates, and payment status. If you invite team members, we store their email address and role.

4. What we don't collect

We do not see or store your clients' payment card details. Payments are processed by Stripe directly; Citofact only receives event notifications confirming payment status. We do not use advertising or tracking technologies and we do not profile you.

5. Why we process it, and our legal basis

  • To provide the service — creating your account, generating and sending invoices, processing payment events: performance of our contract with you,Art. 6(1)(b) GDPR.
  • To meet legal obligations — retaining our own invoices and accounting records: compliance with a legal obligation, Art. 6(1)(c) GDPR (e.g. retention required by Latvian accounting law).
  • To keep the service secure — preventing fraud and abuse, ensuring availability and integrity: our legitimate interest in a secure service,Art. 6(1)(f) GDPR.

6. Recipients and sub-processors

We use the following sub-processors to operate the service: Supabase (database and authentication), Stripe (payments), Resend (transactional email), Cloudflare (DNS, edge hosting and cookieless web analytics), and Render (API hosting). Each acts under a data-processing agreement and only to the extent needed to provide its part of the service. The current list is maintained in our Data Processing Agreement.

7. International transfers

Some sub-processors (in particular Stripe, Cloudflare and Resend) may process data in the United States. Where a recipient is certified under the EU–US Data Privacy Framework, transfers rely on that adequacy decision; otherwise they are safeguarded by the European Commission's Standard Contractual Clauses. For data of users in Switzerland, transfers rely on the Swiss–US Data Privacy Framework or the Swiss-recognised Standard Contractual Clauses.

8. How long we keep your data

We keep your account data for as long as your account is active. Our own business records (for example your subscription and billing history) we retain as required by Latvian accounting law — generally 5 years.

While your account is open we keep the invoices you generate, as your processor, so that you can meet your own statutory retention obligations — for German businesses that means 8 years for invoices and 10 years for books and accounts (§ 147 AO / GoBD); 7 years in Austria; 10 years in Switzerland.

Closing your account ends that arrangement. You can export everything — your clients, your invoices and every invoice PDF we issued — at any time from Settings → Profile, and you should do so before you close. When you close your account we delete our copy; from then on, keeping those records for the remainder of your statutory retention period is your responsibility, not ours. Our own business records described above are the exception, because the law requires us to keep them.

Deletion is immediate and cannot be undone. Backups are the one exception we cannot make instant: residual copies persist in encrypted backups for a short rolling window and are overwritten on their normal cycle; they are never used to restore a deleted account.

9. Your rights

You have the right to access your data and to its rectification, erasure, restriction of processing, and portability, as well as the right to object to processing based on our legitimate interests and to withdraw any consent you have given (without affecting prior processing). You can exercise erasure and portability yourself at any time — Settings → Profile in the app lets you export all your data and permanently delete your account. For anything else, or to have us do it for you, email privacy@citofact.com; we respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority — for us, the lead authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija, DVI). You may also complain to the authority in your own country. Users in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC).

10. Automated decisions

We do not use automated decision-making, including profiling, that produces legal or similarly significant effects on you.

11. Users in Switzerland

If you are in Switzerland, the FADP applies alongside this notice. The controller and the purposes, categories of recipients and countries of transfer are as set out above. You have the FADP rights of access, rectification and erasure, and may contact the FDPIC. Where required under Art. 14 FADP, our representative in Switzerland is [Swiss representative — if applicable].

12. Cookies and measurement

We use only strictly necessary cookies — one to remember your language choice and one to keep you signed in. These are required to provide the service, so no consent banner is needed. We set no analytics, advertising or tracking cookies.

To see how the site and app are used we run Cloudflare Web Analytics. It is cookieless: it stores nothing on your device and reads nothing from it, sets no identifier, and does not fingerprint you or track you across other sites. It records aggregate page views, referrers and coarse technical data such as country and device type. Because nothing is stored on or read from your terminal equipment, § 25 TDDDG requires no consent for it, and we rely on our legitimate interest in understanding and improving the service (Art. 6 (1) (f) GDPR).

13. Changes and contact

We may update this notice as the service evolves; we will post the new version here and update the date above. Questions? Email privacy@citofact.com.