Privacy Policy
1. Introduction
This Privacy Policy explains how Accordix processes personal data in connection with the Accordix website and service. Accordix is a document collection and shared inbox workflow for accountants and their clients. It is not an accounting system, tax filing system, payroll system, certified legal archive, or replacement for statutory accounting records retention.
This policy describes processing for which Accordix acts as a controller, primarily account administration, authentication, communications, support, service security, and limited operational records. For personal data within customer documents and workflow content, Accordix generally acts as a processor on the customer's documented instructions. That processing is governed by the Data Processing Agreement.
2. Who we are
The controller for the processing described in this policy is:
- Anton Desiatnykov
- Legal form: sole trader operating under a Slovak trade licence (živnostenské oprávnenie)
- Registered address: Agátová 3460/7F, 841 01 Bratislava-Dúbravka, Slovak Republic
- Company ID (IČO): 57 025 991
- Trade register: č. živnostenského registra 110-355749
- Tax ID (DIČ): 3122289764
- VAT ID (IČ DPH): Not registered for VAT (not a VAT payer)
- Privacy contact: privacy@accordix.sk
We have not appointed a Data Protection Officer at this stage. We review whether appointment becomes necessary as the service, customer base, and risk profile develop.
3. Scope
This policy applies to website visitors, registered users, customer administrators, accountants, people who contact support, and people whose contact details Accordix processes for service communications. Customers determine why customer documents are collected and who may upload or review them.
4. Data we process as controller
Account and workspace administration data. Name, email address where provided, optional phone number, organization name, role, interface language, verification status, and records of acceptance of contractual documents.
Authentication and security data. Password hashes, authentication cookies, sign-in attempts, timestamps, IP address and user-agent information where captured for security or acceptance records, and limited technical logs.
Communications and support. Messages sent to Accordix, contact details, support history, and related operational records.
Service usage metadata. Workflow statuses, timestamps, feature settings, and technical events needed to operate, secure, troubleshoot, and improve reliability. Customer document content is treated as processor data as described below.
Billing data. Paid plans are not currently generally offered. Before payment processing is introduced, this policy and the Subprocessors page will be updated.
Analytics and advertising. Accordix currently uses no third-party advertising trackers or third-party website analytics. See the Cookie Policy.
5. Customer content and uploaded documents
Customers and their clients may upload invoices, receipts, delivery notes, contracts, bank statements, payroll-support documents, and similar files. These may contain names, contact details, company and tax identifiers, bank account numbers, transaction information, document references, and other personal data.
For personal data within Customer Content, Accordix generally acts as a processor. The Customer determines the purposes, legal basis, categories of documents, authorised users, and applicable retention obligations. Accordix does not own Customer Content and does not replace the Customer's accounting, tax, payroll, or statutory record-retention responsibilities.
Customers should not intentionally upload health data, biometric data, criminal-offence data, or other highly sensitive information unless the use has been agreed with Accordix in writing and the Customer has assessed the legal basis and risks.
6. Optional AI-assisted processing through Google Cloud Vertex AI
Where enabled for a Customer workspace or selected by an authorised user, Accordix may send a document file to Google Cloud Vertex AI (Gemini) for one or more of the following purposes:
- extracting structured information from invoices;
- extracting structured information and transactions from bank statements;
- suggesting documents that may still be required based on a linked document.
The document sent may be the complete uploaded file and may contain personal and financial information, including names, identifiers, addresses, account numbers, IBANs, transaction descriptions, amounts, dates, references, and document contents. The resulting structured fields or suggestions may be stored in Accordix as part of Customer Content.
Vertex AI requests are configured to use the Google Cloud eu multi-region. Google Cloud acts as a subprocessor. Google states in its applicable cloud terms that Customer Data is not used to train or fine-tune models without permission or instruction. Limited technical retention, caching, abuse-monitoring processing, or global support access may nevertheless apply depending on the selected service, model, configuration, and contractual terms. Accordix does not promise zero retention by Google unless that configuration has been separately verified.
AI output is assistive and must be reviewed by an authorised person. It may be incomplete or incorrect. Accordix does not use AI output to make decisions producing legal or similarly significant effects about an individual, and a failed analysis does not prevent the underlying document from being uploaded.
Use of an AI feature, together with the Customer's workspace configuration and instructions, constitutes the Customer's documented instruction to carry out that processing. A Customer that does not want document contents sent to Vertex AI must keep the relevant AI features disabled and must not initiate AI analysis.
7. WhatsApp document intake
Where WhatsApp intake is enabled for a Customer, messages and attachments sent through the configured WhatsApp Business channel are processed by Meta Platforms Ireland Limited and the WhatsApp Business Platform before they reach Accordix. This may include the sender's telephone number, profile or message metadata made available by the platform, message content, timestamps, and attachments.
WhatsApp processing is subject to Meta's applicable terms and infrastructure. Meta may process data outside the EU/EEA under its applicable transfer safeguards. The Customer is responsible for deciding whether WhatsApp is an appropriate collection channel, informing its own clients and contacts, and avoiding requests for unsuitable sensitive documents through that channel.
The technical deployment may have the WhatsApp integration available globally, but Customer Content is processed through it only when a Customer has been assigned or uses an enabled intake channel. Customers that do not want WhatsApp processing should use the web or email intake channels instead.
8. Purposes and legal bases where Accordix acts as controller
Accordix processes controller data to create and secure accounts, provide the service, communicate about service activity, respond to support, prevent abuse, maintain records of contractual acceptance, comply with law, and establish or defend legal claims.
Depending on the activity, the legal basis is performance of a contract, legitimate interests in operating and securing a business service, compliance with legal obligations, or consent where consent is specifically requested. For Customer Content, the Customer determines the applicable legal basis.
9. Sharing and subprocessors
We do not sell personal data. We use providers needed to host the service, deliver and receive email, provide WhatsApp intake where used, and perform optional AI processing. The current list, purposes, data categories, locations, and transfer safeguards is maintained on the Subprocessors page.
We may disclose data where required by law, to protect rights and security, or in connection with a business transfer subject to appropriate safeguards.
10. International transfers
The Accordix application is intended to be hosted in the EU, currently Frankfurt, Germany. Some providers are headquartered outside the EU/EEA or may provide support or processing from other countries. Where required, the provider's data processing terms, the European Commission's Standard Contractual Clauses, an applicable adequacy decision, or another lawful safeguard is used. Data residency does not by itself mean that every support, security, telemetry, or corporate access activity is confined to the EU.
11. Retention
Controller data is retained only for as long as reasonably needed for the relevant purpose, contractual administration, security, legal obligations, or legal claims.
- Active account and workspace administration data is generally retained while the account is active.
- Following termination, Accordix normally allows up to 30 days for an assisted export before deleting or anonymising active workspace data, unless a shorter or longer period is agreed or required by law.
- Technical and security records are generally retained for up to 90 days, but may be kept longer where required to investigate an incident or protect legal claims.
- Support communications may be retained for up to 24 months after resolution.
- Customer Content retention is determined by Customer instructions and the DPA.
- Deleted data may remain in provider-managed backups until those backups expire or are overwritten under the provider's then-current backup lifecycle. Accordix does not guarantee a fixed 35-day maximum unless confirmed for the applicable service and plan.
Further details are available on the Data Export & Deletion page.
12. Security
Accordix uses measures including HTTPS/TLS, password hashing, permission checks, role-based access, logical organization separation, secrets stored in environment configuration, and login throttling. Important limitations, including the absence of MFA and a complete end-user audit trail, are stated on the Security page.
13. Rights of individuals
Subject to GDPR conditions, individuals may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Where Accordix acts as processor, the request should normally be made to the relevant Customer. Accordix will reasonably assist the Customer under the DPA.
Requests concerning data for which Accordix acts as controller may be sent to privacy@accordix.sk. Accordix may verify identity and authority before responding.
14. Cookies and local storage
Accordix uses authentication and preference storage needed to operate the service. It may also use browser local storage for onboarding state and similar product preferences. No third-party advertising or analytics storage is currently used. See the Cookie Policy.
15. Children
Accordix is a business-to-business service and is not directed to children. We do not knowingly offer accounts to children.
16. Changes
We may update this policy. Material changes that expand processing or reduce protections will be communicated to Customer administrators through email, the service, or another durable method where reasonably practicable. Contractual acceptance and privacy acknowledgement are not treated as interchangeable where the law distinguishes them.
17. Contact and complaints
Privacy questions: privacy@accordix.sk.
Individuals may lodge a complaint with the Úrad na ochranu osobných údajov Slovenskej republiky, or with the competent supervisory authority in another EU/EEA country.