Skip to content

Version 1.0

Privacy policy

This sets out what data Kolektro processes, why, where it physically lives, who else can reach it and how long we keep it. Every factual claim here was checked against the running code — what we could not verify is not in this document.

Last updated:

1. Who we are and in which role we process data

Kolektro is provided by MCODE, obrt za računalno programiranje, vl. Matko Setnik (“MCODE”), a sole proprietorship registered in Croatia. Full provider details are at the bottom of this page.

Kolektro handles two groups of data and our role differs between them:

  • Data about the accounting firm and its users: sign-in details, firm settings and subscription data. For these, MCODE is the controller.
  • Data about the firm’s clients and the documents those clients send. For these, the accounting firm is the controller and MCODE is the processor, processing them only on the firm’s documented instructions.

If you are a client of an accounting firm and received a link to send documents, that firm is your controller. You exercise your rights with them, and we act on their instructions.

2. What data we process

  • Firm users: email address and account identifier; for Google sign-in also the name and profile picture link that Google returns.
  • The firm: name, OIB (tax number), time zone, language, reminder settings, and the addresses used for client replies and the daily digest.
  • The firm’s clients: name, email address, mobile number, language, and the internal note the firm writes.
  • Document requests: the period, the list of requested items, due dates, the status of each item, and the note the firm leaves to explain what is missing.
  • Documents: the files a client uploads (images and PDFs), with the original file name, size and type.
  • Send and usage records: when a reminder went out and over which channel, when an upload link was last opened and how many times, when a document arrived, and who at the firm accepted or rejected it.
  • Email deliverability status: a mark that a client’s address permanently rejected a message or reported it as spam, with the time and a short reason. Our email provider reports it back to us and it stops further sending to that address.
  • WhatsApp consent record: whether the client opted in, when, and which firm user recorded it.
  • Subscription: the firm name and OIB we pass to Stripe, plus the details Stripe collects directly from you at checkout (billing address, tax number, payment method).

We never see, receive or store card details — payment happens entirely on Stripe’s own page.

Our code does not record a visitor’s IP address or browser details. Our hosting provider’s infrastructure logs contain the usual HTTP request data, including the IP address, and are deleted on that provider’s default schedule (30 days).

We do not buy data, do not enrich it from outside sources, do not sell it, and do not use it for advertising or for developing or training artificial-intelligence models.

3. Cookies and tracking

Kolektro’s public pages set no cookies and load no analytics, pixels, maps or third-party scripts — not even web fonts from someone else’s server. That is also why there is no consent banner: there is nothing to consent to.

The page a firm’s client reaches through an upload link likewise sets no cookies and carries no analytics.

Inside the firm console, after sign-in, the browser stores locally what sign-in needs to work: the signed-in session, the email address typed during link sign-in, and which firm was last opened. None of it is used for tracking or shared with anyone.

4. Why we process data and on what legal basis

  • To enter into and perform the contract for the service, including account creation and subscription billing — Article 6(1)(b) GDPR.
  • To meet legal obligations, primarily tax and accounting ones — Article 6(1)(c) GDPR.
  • For the security of the service and the prevention of abuse: send and link-opening records, and sending limits — our legitimate interest, Article 6(1)(f) GDPR.
  • The firm’s client data and their documents are processed solely on the firm’s instructions, to send a reminder and receive a document. The legal basis towards those clients is determined by the firm as controller.

Reminders are sent by email. The WhatsApp channel is not active and currently sends no messages at all. A firm can already record a WhatsApp opt-in in Kolektro, with the time and the person who recorded it; without that record no message will go out even once the channel works.

5. Where the data lives

  • The application, background jobs and the website run in the Google Cloud region europe-west1 (Belgium).
  • The database is in the EU multi-region eur3.
  • Documents sent by clients are stored in a Google Cloud Storage bucket in the europe-west1 region (Belgium).
  • Firm user sign-in is not region-bound and Google processes it on its global infrastructure.
  • Outbound email is sent through Amazon SES in the eu-west-1 region (Ireland).
  • Billing is processed by Stripe, in the European Union and the United States.

For processing outside the European Economic Area the transfer basis is the European Commission’s Standard Contractual Clauses, contained in those providers’ data processing terms, which form part of our contract with them.

6. Sub-processors

We use the following sub-processors to run the service:

  • Google (Firebase and Google Cloud): application hosting, database, document storage, user sign-in, secret management and infrastructure logs. Processing and storage in the EU; sign-in data is processed on global infrastructure under Standard Contractual Clauses.
  • Amazon Web Services (Amazon SES): outbound email delivery and the bounce and complaint notifications it reports back, region eu-west-1 (Ireland). A message carries the client’s name and email address, the firm name, the list of requested documents and the upload link.
  • Stripe: subscription billing and invoicing, processing in the EU and the United States under Standard Contractual Clauses. We pass Stripe the firm name, OIB and internal account identifiers; payment details are collected by Stripe directly from you, and Stripe also processes them as an independent controller to meet its own legal obligations. No client data and no documents are sent to Stripe.

Bird (WhatsApp) exists in the system but is switched off: it sends no messages and has never received any data. If we switch it on, we will change this list before the first message is sent.

We notify firms by email at least 30 days before any change to this list. A firm may object within that period and, if it does not accept the change, may cancel its subscription at no cost.

7. How long we keep data

  • Documents sent by clients, the firm’s client records and request records: while the firm’s account is active. We delete them after the contract ends, on the timeline in the next section, or earlier at the firm’s request.
  • Upload-link records (the cryptographic hash of the link, the client and period it points at, when it was last opened): while the account is active, deleted together with the firm’s other data. The link itself stops working 14 days after it is issued.
  • Firm user account data: while the account is active. When a firm is deleted its members’ sign-in accounts are deleted with it — unless that person also belongs to another firm in Kolektro, since deleting one firm must not lock them out of the other.
  • Invoices and accounting records: 11 years from the end of the business year they relate to, as accounting law requires. These records contain no client data.
  • The hosting provider’s infrastructure logs: deleted automatically on that provider’s default schedule (30 days).

Kolektro is a tool for collecting paperwork, not an archive. Download anything you are required to retain into your own system — we do not keep it longer than the subscription lasts.

8. Deletion after the contract ends

After the contract ends we keep data and documents for a further 30 days, so an export is still possible after the last day of the subscription. We then delete them — no later than 60 days after the contract ends.

If you ask for earlier deletion we carry it out within 30 days of a request sent from the firm’s contact address. The same applies to a request to delete a single client or a single document while the account is active.

Deletion is performed manually, on request or when the period above expires: the console does not yet have a button with which a firm permanently deletes a document or a client itself. A request to the contact address at the bottom of this page is the only route, and it is sufficient — including when the request reaches us from a firm’s client through the firm.

9. Security

  • All access to the application goes over HTTPS, and outbound email over a TLS connection.
  • Data and documents are encrypted at rest at the infrastructure provider’s level. We apply no additional application-level encryption and do not claim to.
  • Only users of a firm can reach that firm’s data. Database rules and server-side checks enforce this on every read and write, not only in the interface.
  • A firm’s clients have no account and no database access. Through the link they see only the firm’s name, their own name and the list of documents that firm is asking them for.
  • An upload link is bound to one client and one period, expires after 14 days, can be revoked, and is limited by number of opens and by uploads per day. The link record stores only its cryptographic hash (SHA-256).
  • Only file types on an explicit allow-list are accepted: PDF, images, office documents (xlsx, xls, docx), CSV and ZIP archives, up to 20 MB per file. The type is verified on the server, not merely from the filename extension.
  • Administrative access to the production environment is held by the owner of the business alone.

If a personal data breach affects a firm’s data, we will notify that firm without undue delay and no later than 48 hours after we become aware of it, and give them what they need to report it to the supervisory authority.

10. Your rights

You have the right of access, rectification, erasure, restriction of processing, portability, and objection to processing based on legitimate interest. Send your request to the contact address at the bottom of this page; we answer within one month.

If you are a client of an accounting firm, address your request to that firm — it is the controller of your data. If a request reaches us directly, we forward it to the firm and tell you we have done so.

You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP) or with the supervisory authority in the country where you habitually reside.

11. Data processing agreement

The Article 28 GDPR data processing agreement forms part of these terms and is concluded when a firm is opened. Article 28(9) GDPR expressly permits electronic form, so no separate signature is required; we record which version of the terms the firm accepted and when. A firm that needs a separately signed copy for its own records gets one on request to the contact address.

The agreement carries over the obligations in this document and adds what a controller needs in writing: a description of the processing, the categories of data and data subjects, the list of sub-processors with their processing locations, the security measures, the deletion timelines and method, and what happens in the event of a data breach.

The full text is published here: Data processing agreement. The sub-processor list in its Annex III must match the “Sub-processors” section of this policy.

12. Changes to this policy

We change this policy when the way the service works changes, when the sub-processor list changes, or when the law does. The version and the date of the last change are at the top of this page.

We notify firms by email to the account address at least 30 days before any change that materially affects the processing of the firm’s data or that of its clients.

Provider details and contact

MCODE, obrt za računalno programiranje, vl. Matko Setnik

Registered seat
D. Cesarića 67, 31550 Valpovo, Hrvatska
OIB (tax number)
58358056658
Register
Obrtni registar, MBO 98583441
Web
kolektro.com

Questions about this document, data requests and requests for a signed copy of the data processing agreement go to the address above.

Privacy policy — Kolektro