Kontly
← Back

Privacy Policy

Last updated: 6 July 2026

1. Who We Are

Kontly ("we", "us", "our") operates the financial document management platform available at this domain. We are the data controller for all personal data processed through the Service.

Contact: ondrusfilip20@gmail.com

2. Data We Collect

We collect and process the following categories of personal data:

Account data

Your email address, collected when you sign in via email link. We also store a unique user identifier, account creation timestamp, and your record of having accepted these terms.

Workspace data

The name of your business or workspace, provided when you first set up your account.

Financial documents

Documents you upload to the Service (invoices, receipts, contracts, and similar files). We extract and store structured information from these documents including vendor names, client names, amounts, VAT, dates, and document summaries. We also generate and store AI vector embeddings of document content to enable search functionality. Original files are stored in encrypted cloud storage.

Bank transaction data

If you voluntarily connect a bank account, we retrieve and store transaction data including amounts, dates, descriptions, and AI-assigned categories. Bank connection tokens are stored encrypted. We do not store your banking credentials.

Payment records

Records of payments you manually log against documents, including amounts, dates, and notes.

Billing data

If you subscribe to a paid plan, we store your Stripe customer identifier and subscription status. Full payment card details are held exclusively by Stripe and are never transmitted to or stored by us.

Technical logs

Server logs necessary for security monitoring, error diagnosis, and service operation, retained for up to 30 days.

3. How We Use Your Data

We process your data to:

  • Provide, maintain, and improve the Service
  • Extract structured information from your uploaded documents using AI
  • Generate monthly financial summary reports sent to your email
  • Process subscription billing and manage your account
  • Respond to your support requests
  • Detect, investigate, and prevent fraud or misuse
  • Comply with applicable legal obligations

4. Legal Basis (GDPR)

We process your personal data under the following legal bases as defined in the EU General Data Protection Regulation (GDPR):

  • Contract performance (Art. 6(1)(b)): Processing your account data, documents, and bank data is necessary to provide the Service you have contracted with us for.
  • Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, technical log retention, and service improvement, where our interests are not overridden by your rights.
  • Legal obligation (Art. 6(1)(c)): Retention of billing and financial records as required by applicable tax and accounting law.

5. Third-Party Processors

We share data with the following sub-processors solely to provide the Service. All processors are bound by data processing agreements.

ServiceProviderPurposeLocation
Database & AuthSupabase Inc.Data storage, authenticationEU (Frankfurt)
File storageSupabase StorageEncrypted document storageEU (Frankfurt)
AI extractionOpenAI, LLCDocument extraction & embeddingsUSA (SCCs)
PaymentsStripe, Inc.Subscription billingUSA (SCCs)
Bank connectionsEnable Banking OyOpen banking data accessFinland / EU
Email deliveryResend, Inc.Transactional & report emailsUSA (SCCs)

For transfers outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) or equivalent adequacy safeguards approved by the European Commission.

6. Data Retention

  • Account data: Retained for the duration of your account, plus 90 days after account deletion to allow for recovery.
  • Financial documents and payment records: Retained for 7 years from the document date to comply with accounting record-keeping requirements, unless you request earlier deletion and no legal retention obligation applies.
  • Bank transaction data: Retained for 2 years from the transaction date.
  • Billing data: Retained as required by Stripe and applicable tax law (typically 7 years).
  • Technical logs: Retained for up to 30 days.

7. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights. To exercise any of these, contact us at ondrusfilip20@gmail.com. We will respond within 30 days.

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate personal data.
  • Right to erasure: Request deletion of your personal data, subject to legal retention obligations.
  • Right to data portability: Receive your data in a structured, machine-readable format (JSON).
  • Right to restriction: Request that we restrict processing of your data in certain circumstances.
  • Right to object: Object to processing based on legitimate interests.

8. Cookies

The Service uses only strictly necessary cookies. No advertising, analytics, or tracking cookies are used.

  • Authentication session — Maintains your logged-in state. Set by Supabase Auth. Expires when you sign out or the session expires.
  • Workspace cache (ws_ok) — A short-lived flag that avoids a database lookup on every page load. Expires after 1 hour.
  • Consent record (consent_v1) — Records that you have accepted these legal agreements. Expires after 1 year.

As these cookies are strictly necessary for the Service to function, they do not require separate consent under the ePrivacy Directive.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include encryption of data at rest and in transit, access controls, and regular security reviews.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours, and affected individuals without undue delay where required.

10. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. In the Netherlands, this is:

Autoriteit Persoonsgegevens
Bezuidenhoutseweg 30, 2594 AV Den Haag, Netherlands
autoriteitpersoonsgegevens.nl

If you are located in another EU member state, you may also lodge a complaint with the supervisory authority in your country of residence.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email at least 14 days before they take effect. The current version is always available at /legal/privacy.

12. Contact

For any privacy-related queries or to exercise your rights, contact us at: ondrusfilip20@gmail.com