Privacy policy
How Perfect Light processes personal data in connection with FiskalMe, on what legal basis, and what rights you have.
In force from
The controller is PERFECT LIGHT, obrt za usluge, proizvodnju, trgovinu i prijevoz, vl. Filip Curkić, Zagreb, Croatia, OIB 40797811615, e-mail support@fiskalme.com.
This policy describes processing under the General Data Protection Regulation (EU 2016/679) and the Croatian act implementing it.
1. Two different roles — read this first
There are two kinds of personal data in FiskalMe and we stand differently towards each.
- Your data as a customer — name, e-mail, business details, subscription. For these we are the controller: we decide why and how they are processed. This policy is about them.
- The data you enter about your own customers — their names, tax numbers, addresses, invoice lines. For these we are only a processor: we act on your instructions and you are the controller. They are governed by the Data Processing Agreement, not by this policy.
The practical difference: we decide nothing about your customers’ data. We do not use it for our own purposes, do not analyse it, and share it with no one except those you name or the law requires.
2. What we process and why
As controller we process the following, each with the lawful basis stated:
- Registration and account — name, e-mail, password (stored as a cryptographic hash by Firebase Authentication). Basis: performance of a contract (art. 6(1)(b)). Without it we cannot open an account.
- Business details — name, tax number, address, IBAN, contact. Basis: performance of a contract and, in part, legal obligation (art. 6(1)(c)), since these appear on the invoices we issue.
- Subscription and billing — plan, payments and the invoices we issue you. Basis: performance of a contract and the statutory duty to keep accounting records.
- Service e-mail — notices about your account, certificate expiry, failed fiscalisation. Basis: performance of a contract. This is not marketing, and we send no promotional messages without your consent.
- Operational and error logs — technical logs and error reports (Sentry, EU region). Basis: legitimate interest (art. 6(1)(f)) in keeping the service secure and correct. Sending personal data in error reports is deliberately switched off.
- Preferences and consent record — your theme choice and your answer to the cookie notice, stored in your browser. See clause 8.
3. Fiscalisation and the tax authority
When you issue an invoice, the application signs its elements with your certificate and submits them to the tax authority’s fiscalisation system. Those data — including the buyer’s tax number on a B2B invoice — are submitted because the Fiscalisation Act requires it.
That legal obligation is yours, not ours: you are the taxpayer subject to fiscalisation, and we carry out the submission on your behalf. The lawful basis therefore rests on your side (art. 6(1)(c)) and we act as processor for this part.
The tax authority is an independent controller for the data it receives and handles it under its own rules.
4. Who we entrust data to
We do not sell data and do not share it for anyone else’s purposes. We use the following processors, each bound by an art. 28 contract:
- Google (Firebase / Google Cloud) — sign-in, database, file storage, server-side execution and secret storage. Data is held in the EU: the database in region eur3, storage and execution in europe-west1 (Belgium).
- Sentry — error reporting, EU region (de.sentry.io), with personal data sending disabled.
- An e-mail provider — delivery of service messages and of the documents you send to your customers.
- Stripe — payment processing, once billing is introduced. We neither receive nor store card details.
- The tax authority — as described in clause 3.
We may also disclose data to a competent authority where the law obliges us to.
5. Transfers outside the European Economic Area
All services are deliberately configured to European regions and data is stored in the EU.
Google, Sentry and Stripe are US-headquartered companies, so access from a third country — for technical support, say — cannot be entirely ruled out. For such cases we rely on the EU–US Data Privacy Framework or on the standard contractual clauses approved by the European Commission.
If either mechanism changes, we will update this policy and, where necessary, look for another processor.
6. How long we keep data
- Account and business data — for the term of the agreement, then a further 60 days for export.
- Invoices we issued you and our accounting records — for the periods required by Croatian accounting and tax law.
- The fiscal archive — fiscal messages sent and received are kept for the periods in the accounting rules, to which the Fiscalisation Act refers. These records are not deleted on request, because the law requires them to be kept.
- Technical logs and error reports — at most 90 days.
Your customers’ data is deleted on your instruction, within statutory retention limits — see the Data Processing Agreement.
7. Your rights
In respect of data for which we are controller you have the right to:
- request access to your data and a copy of it,
- request rectification of inaccurate data,
- request erasure, where no legal basis for further retention exists,
- request restriction of processing,
- portability — you can export your data yourself from the application at any time,
- object to processing based on legitimate interest.
Send requests to support@fiskalme.com. We respond without delay and at the latest within one month.
If your request concerns your customers’ data, contact us only if you are that customer; otherwise the controller is the business that entered the data.
8. Cookies and browser storage
The public site fiskalme.com uses no tracking cookies and no analytics. Your browser stores only your light or dark theme choice and your answer to the cookie notice, so we do not ask again.
The application app.fiskalme.com uses storage strictly necessary to work — keeping you signed in, and your settings. Without it you cannot stay signed in.
If we introduce visitor measurement or other optional tools, they will not load without your consent, and we will update this policy first.
9. Security
Traffic is encrypted (HTTPS). Access to data is enforced by database rules rather than by the interface alone, and every business sees only its own data.
Your FINA certificate and its passphrase are stored in Google Secret Manager and used solely to sign your fiscal messages.
In the event of a personal data breach likely to result in a risk to individuals’ rights and freedoms, we will notify the Croatian supervisory authority within 72 hours of becoming aware, and you without delay where the risk is high.
10. Data protection officer and complaints
We are not required to appoint a data protection officer: we do not carry out regular and systematic monitoring of individuals on a large scale, nor process special categories of data on a large scale (art. 37). For any data-protection question write to support@fiskalme.com.
If you believe your rights have not been respected, you may lodge a complaint with the supervisory authority:
- Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, Croatia
- e-mail: azop@azop.hr · telephone: +385 1 4609-000 · azop.hr
11. Changes to this policy
We may amend this policy. The date of the last change is shown at the top.
We will notify you by e-mail or in the application before a material change takes effect — a new purpose, a new processor, or a change of legal basis.