Security and GDPR
Your firm is responsible for its clients' data. We understand that.
By giving us your clients' NIPs (Polish tax IDs), contact details and invoice content, you become a controller of personal data within the meaning of Art. 4 GDPR, and we become a processor (Art. 28). That is why the data processing agreement (DPA), the place of processing and encryption are not marketing for us. They are the foundation.

Your data stays in Europe
We process the database, invoice content and KSeF tokens in a data centre in London. The United Kingdom is covered by a European Commission adequacy decision, which confirms an adequate level of personal data protection.
AES-256 disk encryption
The database disks (clients' NIPs, invoice content, KSeF tokens) are encrypted with AES-256 by the infrastructure provider, Supabase. The connection between the browser and the server is protected by TLS 1.3.
Write-only KSeF token
Once saved, a KSeF token or a certificate's private key cannot be read back by the browser, because the database does not release those fields to any signed-in user. Only server functions use them, at the moment they call the KSeF API.
Role-based access
The account owner and administrators manage clients, the team, payments and integrations. Invited team members upload, fix and send invoices. Every user of the account sees all of the firm's clients, and other firms' data is separated at database level.
Submission history and UPO
The History tab shows submissions to KSeF, uploaded files and errors, with date and time. For every sent invoice we save the KSeF number and the UPO, the official receipt signed by the Ministry of Finance.
No tracking, no marketing cookies
We use cookie-free analytics (Umami). No Google Analytics, no Facebook Pixel, no remarketing. Your clients are not profiled.
Art. 28 GDPR
A data processing agreement, ready to sign.
Every accounting firm that uses FakturaFlow signs a data processing agreement with us that complies with Art. 28 GDPR. Standard wording, no hidden clauses, with an open list of subprocessors and places of processing.
What the agreement covers
- Scope of data: identification data of the firm's clients (NIP, name, address), invoice content, contact details.
- Purpose of processing: only sending invoices to KSeF, archiving UPOs, providing the SaaS service.
- Duration of processing: for the term of the agreement plus the period needed for legal retention.
- Subprocessors: Supabase (database hosting, London), Stripe (payments), Resend (transactional email). Full list in the agreement.
- Place of processing: database, invoices and KSeF tokens in London. The United Kingdom is covered by a European Commission adequacy decision. Supporting providers (payments, email, DNS, analytics) are US companies operating under standard contractual clauses.
- Right to audit and a duty to notify of a breach within 24 hours.
Need a template of the agreement before signing up?
Write to kontakt@fakturaflow.pl mentioning “DPA”. Within 24 hours we will send back a template of the processing agreement (PDF) for your lawyer or data protection officer to approve.
Request the DPA templateSubprocessors
You know who touches your data.
Your clients' data, meaning the database, invoice content and KSeF tokens, sits in one place: a data centre in London. The United Kingdom is covered by a European Commission adequacy decision confirming an adequate level of personal data protection. Supporting providers that have no access to invoice content (payments, transactional email, DNS, cookie-free analytics) are US companies operating under standard contractual clauses. The full list of providers and the scope of their processing is in the data processing agreement (DPA), which we make available on request before you sign up for a subscription.
What FakturaFlow is not
We are not an official integrator of the Ministry of Finance, nor a certifying body. We use the public KSeF API on the same terms as any other tool. Responsibility for the substantive correctness of invoices lies with the firm. We take care of the technical correctness of sending, FA(3) schema validation and archiving UPOs.
Questions about GDPR or security?
We answer every question from an accounting firm: from specific clauses of the processing agreement, through the retention policy, to the encryption architecture.