Privacy policy
Version dated 6 September 2026.
Who is responsible for the data
For account data, service security, billing and contact, the operator is Michał Mietliński SLUG IT. Contact: michal@mietlinski.pl, Pałucka 29, 60-604 Poznań.
For invoice and contractor data processed on behalf of a company using the platform, the parties' roles may depend on their legal relationship. The organisation using the Service remains responsible for having a lawful basis to process its contractors' and users' data.
Data we process
This mainly includes a user's email address, company membership and roles, company and contractor data, invoices and line items, categories, technical KSeF integration data, sharing information, an audit log, assigned plan and start date, and security data such as IP address and browser information.
If paid plans are introduced, the system may also store billing data such as a payment or customer identifier at the payment provider, payment status, billing period, amount and currency. fv.converts.ninja does not intend to store full card details; the exact scope will depend on the chosen payment provider.
When notifications are enabled, we also process the supplied phone number or email address, monitoring conditions, technical delivery history and monthly SMS allowance usage.
Purposes
Data is used to provide the Service, authenticate users, operate KSeF, maintain operational history, record plan usage, prevent abuse, handle reports, maintain security, establish or defend claims and meet legal duties. Billing data will be processed only when a paid plan or another real payment requiring it is enabled.
Data minimisation
Each feature uses only the data needed for its task. Category suggestions receive neither KSeF secrets nor direct access to the full database.
Cookies and similar mechanisms
The service uses cookies required for secure sign-in, form protection and remembering privacy settings. They are necessary to provide the service and are not used for advertising or cross-site tracking.
| Name/type | Purpose | Lifetime | Basis |
|---|---|---|---|
fv_session | Keeps the user signed in and protects access to company data. | Up to 8 hours or until sign-out | Essential |
fv_cookie_preferences | Remembers the optional-cookie choice. | Up to 180 days | Essential to retain the choice |
This version uses no advertising or third-party analytics cookies. If optional usage measurement is introduced, it will remain off until explicit consent is given. Consent can be refused or withdrawn through “Cookie settings” in the footer without losing access to the service.
Identifying a bank from an account
After a Polish bank account is entered, the application may retrieve the bank name and SWIFT/BIC from the NBP register of payment-instrument issuers. Only the eight-digit bank clearing number extracted from the account is sent to NBP; this feature does not send the full account number.
GUS REGON register
When a user selects “Retrieve from GUS”, fv.converts.ninja sends the supplied Polish tax number (NIP) to the official GUS REGON API and retrieves public identification data such as name, REGON and address. Communication originates from fv.converts.ninja infrastructure; the GUS API key is never sent to the browser.
The REGON service may log technical request information, including the connecting system's IP address, date, time and query content, under its rules. The feature runs only at the user's request.
External AI and LLMs
Invoice content is not sent to public generative-AI services or external language models for classification or interpretation. Category suggestions are prepared in a controlled environment.
Retention
Unverified companies that have never confirmed KSeF access may be scheduled for deletion after 90 days, with an additional grace period. Data is retained for as long as needed to operate the account and documents, preserve security, comply with law and defend claims. Periods may vary by data type and relationship; data should be deleted or anonymised when there is no further basis or purpose.
After a user deletes their account, the email address is removed from the active profile and access and sessions are revoked. A limited technical audit trace without an active email address may remain where needed for integrity, security, a legal duty or claims.
Recipients and infrastructure
Infrastructure, email and other technical providers required to operate the platform may process data under the terms applicable to their services. Data sent to KSeF is transferred to the public-administration system as instructed by the user.
For an SMS, the gateway receives the recipient number, completed message and technical message identifier. The standard message may contain an amount and shortened contractor name; the discreet option does not. The email provider processes the email address and message body.
Your rights and contact
For access, rectification, erasure, restriction, objection or other rights under applicable law, contact michal@mietlinski.pl. The precise right depends on the basis and nature of processing.
Security
The main safeguards are described on the Security page.