Privacy Policy
Last updated: June 25, 2026
Draft template. Before launching publicly, have this reviewed by qualified Latvian counsel.
This notice explains how Citofact processes personal data when you use our invoicing service and visit our website. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and, for users in Switzerland, the Swiss Federal Act on Data Protection (FADP).
1. Who is responsible
The controller for the processing described here is:
SIA "Gulbis Solutions"
Mezciema iela 44 - 41
Riga, LV-1079, Latvia
E-mail: privacy@citofact.com
We have not appointed a Data Protection Officer: our processing does not consist of large-scale processing of special categories of data or large-scale regular monitoring, so the appointment thresholds in Art. 37 GDPR are not met. You can reach us on any data-protection matter at the address above.
2. Controller and processor roles
For your account data — your profile, workspace, branding, billing and tax identity — Citofact is the controller and this notice applies.
For the client and invoice data you enter about your own customers, you are the controller and Citofact acts only as your processor, on your instructions. That relationship is governed by our Data Processing Agreement, not by this notice. You remain responsible for informing your customers about that processing.
3. What data we collect
When you sign up, we store the email address and profile information provided by your identity provider (Google), and the company name, currency and branding assets (logo, accent color) you enter during onboarding. To produce compliant invoices, we store your workspace's legal and tax identity (address, VAT ID, tax number, legal form, register details) and bank details (IBAN, BIC) that you choose to show on invoices.
When you create invoices, we store the invoice contents you author — line items, your clients' contact details, totals, due dates, and payment status. If you invite team members, we store their email address and role.
4. What we don't collect
We do not see or store your clients' payment card details. Payments are processed by Stripe directly; Citofact only receives event notifications confirming payment status. We do not use advertising or tracking technologies and we do not profile you.
5. Why we process it, and our legal basis
- To provide the service — creating your account, generating and sending invoices, processing payment events: performance of our contract with you,Art. 6(1)(b) GDPR.
- To meet legal obligations — retaining our own invoices and accounting records: compliance with a legal obligation, Art. 6(1)(c) GDPR (e.g. retention required by Latvian accounting law).
- To keep the service secure — preventing fraud and abuse, ensuring availability and integrity: our legitimate interest in a secure service,Art. 6(1)(f) GDPR.
6. Recipients and sub-processors
We use the following sub-processors to operate the service: Supabase (database and authentication), Stripe (payments), Resend (transactional email), Cloudflare (DNS and edge hosting), and Render (API hosting). Each acts under a data-processing agreement and only to the extent needed to provide its part of the service. The current list is maintained in our Data Processing Agreement.
7. International transfers
Some sub-processors (in particular Stripe, Cloudflare and Resend) may process data in the United States. Where a recipient is certified under the EU–US Data Privacy Framework, transfers rely on that adequacy decision; otherwise they are safeguarded by the European Commission's Standard Contractual Clauses. For data of users in Switzerland, transfers rely on the Swiss–US Data Privacy Framework or the Swiss-recognised Standard Contractual Clauses.
8. How long we keep your data
We keep your account data for as long as your account is active. Our own business records (for example your subscription and billing history) we retain as required by Latvian accounting law — generally 5 years.
The invoices you generate we keep, as your processor, so that you can meet your own statutory retention obligations — for German businesses that means 8 years for invoices and 10 years for books and accounts (§ 147 AO / GoBD); 7 years in Austria; 10 years in Switzerland. When you close your account, your data is exported on request and deleted within 30 days, except records that we or you are legally required to retain.
9. Your rights
You have the right to access your data and to its rectification, erasure, restriction of processing, and portability, as well as the right to object to processing based on our legitimate interests and to withdraw any consent you have given (without affecting prior processing). To exercise any of these, email privacy@citofact.com; we respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority — for us, the lead authority is the Data State Inspectorate of Latvia (Datu valsts inspekcija, DVI). You may also complain to the authority in your own country. Users in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC).
10. Automated decisions
We do not use automated decision-making, including profiling, that produces legal or similarly significant effects on you.
11. Users in Switzerland
If you are in Switzerland, the FADP applies alongside this notice. The controller and the purposes, categories of recipients and countries of transfer are as set out above. You have the FADP rights of access, rectification and erasure, and may contact the FDPIC. Where required under Art. 14 FADP, our representative in Switzerland is [Swiss representative — if applicable].
12. Cookies
We use only strictly necessary cookies — one to remember your language choice and one to keep you signed in. These are required to provide the service, so no consent banner is needed. We set no analytics, advertising or tracking cookies.
13. Changes and contact
We may update this notice as the service evolves; we will post the new version here and update the date above. Questions? Email privacy@citofact.com.