GANADO FAKTURA · PRIVACY
What happens to invoice data.
This notice supplements Ganado’s general privacy policy and describes the actual data flow of the Czech invoice tool.
1. Controller and roles
Ganado International s.r.o. is the controller for account identity, service operation, security, support and minimal usage records. Contact: Ganado International s.r.o., IČO 19322119, Příčná 1892/4, Nové Město, 110 00 Praha 1, [email protected].
For personal data that a user enters about an invoice recipient, the invoice issuer normally determines why the data is used and acts as controller. Ganado processes that content on the issuer’s instructions only to provide Faktura. The processing terms in the Faktura Terms apply to that relationship.
2. Data, purpose and legal basis
Using the tool without an account keeps drafts and issued documents in this browser. After a new document is successfully issued, Faktura may prepare one vector PDF in the background and cache it only in browser memory; opening an archived document does not do this. A hosted link is created only on request. Signing in additionally enables the durable account archive and cross-device sync.
| Activity | Data | Purpose and legal basis | Application retention |
|---|---|---|---|
| Account and sign-in | Supabase user ID; e-mail, name and avatar supplied by Google when Google sign-in is chosen. | Authentication, account continuity and sync: performance of the service under Article 6(1)(b) GDPR. | Until account closure; authentication-provider records follow that provider’s own policy. |
| Invoice content and archive | Supplier and customer identity, address, IČO/DIČ, contact and bank details, line items, dates, amounts, status, relations and activity history. | Create, preserve, sync and restore documents requested by the user: Article 6(1)(b) for the user’s data; processing on the issuer’s instructions for recipient data. | Signed-in archive: until account closure or 31 December of the tenth calendar year after the year of issue, whichever comes first. |
| PDF generation | Validated invoice HTML needed to render the requested PDF. | Prepare one vector file after successful issuance, or generate it when the user later requests a download: Article 6(1)(b). | Processed in the Vercel function for that render and cached only in browser memory for the immutable snapshot; Faktura does not write the PDF or its HTML to an application database. |
| Hosted invoice link | A signed copy of the invoice snapshot, invoice ID, ownership/fingerprint metadata and read-security counters. | Show the invoice to people chosen by the user: Article 6(1)(b). | Maximum 30 days. A managed signed-in link is denied when the durable document is voided, removed or no longer matches. An anonymous capability link ends after successful revocation or expiry. |
| Reliability and abuse prevention | Pseudonymous document ID/type/timestamps; request metadata and rate-limit identifiers derived from IP address. | Idempotency, service capacity, incident diagnosis and abuse prevention: legitimate interests under Article 6(1)(f). | Minimal usage records until account closure; short-lived rate-limit keys and technical logs only for the relevant operational window. |
3. Local storage, sync, PDF and sharing
- Browser storage belongs to the device profile. Clearing site data, using private browsing or losing the device can remove it.
- The signed-in archive is stored server-side in Supabase and is available only through a session verified for the same account. Browser roles have no direct table access.
- A hosted link is a possession capability: anyone who receives it can view the invoice. Managed signed-in links are checked against the durable non-voided snapshot on every read. Anonymous links remain readable until revocation succeeds or they expire. Do not send a link to unintended recipients.
- Older transitional device-sync copies may remain in Upstash for their existing maximum 90-day TTL; new signed-in document truth is kept in Supabase.
- Voiding a document preserves its accounting history; it is not a privacy deletion request.
4. Providers and international transfers
Ganado gives providers only the data needed for their role. The production Supabase database is configured in the EU region eu-west-1. Other providers or their subprocessors may process data outside the EEA under the safeguards in their applicable agreements.
| Provider | Role in Faktura | Relevant data |
|---|---|---|
| Supabase | Authentication and PostgreSQL archive | Account identity, immutable invoice snapshots, lifecycle and numbering metadata. |
| Vercel | Hosting, API execution and transient PDF rendering | Web requests, validated PDF input during rendering and technical metadata. |
| Upstash | Hosted-link storage, short-lived counters and transitional sync storage | 30-day signed invoice snapshots for hosted links; short-lived security keys; legacy sync copy with a maximum 90-day TTL. |
| Google (optional) | Sign-in identity provider | The account identity Google returns after the user chooses Google sign-in. |
5. Retention, deletion and account closure
- A daily database job deletes signed-in invoice content after the service retention above. For example, a document issued in 2026 is eligible for deletion on 1 January 2037.
- Technical numbering counters contain no document or customer content and remain while the account exists so an old number is not reused.
- To close the account, e-mail the privacy contact from the sign-in address. After identity verification, deletion of the Auth account cascades to the Faktura archive, numbering records and minimal usage records.
- Export every document you must retain before closing the account. Ganado Faktura is a creation and convenience archive, not a replacement for the issuer’s statutory accounting archive or backup.
- Deleted database rows can remain temporarily in isolated provider backup or recovery copies for that provider’s configured recovery window. They are not available in ordinary Faktura operation and expire under the provider’s backup cycle.
Privacy or account-closure request: [email protected]
6. Rights and requests
Subject to the GDPR, you may request access, correction, erasure, restriction, portability or object to processing based on legitimate interests. Erasure is not absolute where continued processing is required by law or for legal claims. We respond without undue delay and normally within one month.
If you are named on an invoice created by another user, contact the invoice issuer first because the issuer normally controls that invoice content. You may also contact Ganado; we will not disclose another user’s account information and will assist with a valid request.
You may complain to the Czech Office for Personal Data Protection (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7.
7. Security and user responsibility
- Server tables are deny-by-default for browser roles; server operations verify the signed-in account and immutable invoice snapshot.
- PDF responses are marked no-store, hosted links expire and can be revoked, managed links fail closed against the durable ledger, and public endpoints have bounded rate limits.
- The user must secure their device and sign-in session, enter only data needed for invoicing, avoid special-category data, and keep an independent statutory archive.