Privacy Policy
Effective from 18 August 2026
1. Data controller
The data controller is The Invisible Company OÜ (Estonian registry code 17424017, Nooda tee 8, 13516 Tallinn).
Privacy contact: tere@klaariks.ee
2. What data we collect
Klaariks processes the following categories:
| Category | Examples | Source |
|---|---|---|
| Account data | Email, name, company name, registry code, VAT number | Your input / Google sign-in / RIK Äriregister |
| Accounting documents | Invoices (PDF/images), bank transactions, contacts, chart of accounts | Your upload / bank import / e-invoice channel |
| Technical data | IP address, browser type, cookies, login timestamps | Automatically from your use of the service |
| Diagnostic logs | Error and operation records | Automatically during service operation |
3. Purposes of processing
We process personal data for these purposes:
- Service delivery — account management, document processing, bookkeeping.
- Text recognition (OCR) — AI-based extraction of data from uploaded document images (invoices, expense documents, trial-balance reports).
- Customer support — answering questions, resolving issues.
- Service improvement — analysis of anonymised usage data, evaluating AI accuracy.
- Legal compliance — retaining accounting documents, responding to lawful requests from authorities (e.g. EMTA, AKI).
4. Legal basis
Processing is based on Regulation (EU) 2016/679 (GDPR):
- Performance of a contract (Art 6(1)(b)) — service delivery, account management, document processing.
- Legitimate interest (Art 6(1)(f)) — service improvement, security, fraud prevention.
- Legal obligation (Art 6(1)(c)) — accounting retention requirements, responses to authority requests.
5. Retention
| Category | Retention |
|---|---|
| Account data | While the account is active + 30 days after closure |
| Accounting documents (invoices, bank transactions, annual report data) | 7 years per Estonian Accounting Act § 12(1) |
| Technical and diagnostic logs | Up to 30 days |
After the retention period, data is securely deleted.
6. Subprocessors
Klaariks engages categories of subprocessors (data processors under GDPR Art 28) under appropriate contractual safeguards:
| Category | Role | Data location |
|---|---|---|
| Cloud hosting providers | Application and database hosting | European Union |
| Document storage | Storage of uploaded files | European Union |
| PSD2 account-information aggregator (Enable Banking Oy) | Licensed account-information service provider (AISP) — retrieves bank account and transaction data with the User's consent | European Union (Finland) |
| AI text-extraction service | OCR — extracts text from invoice images | Outside the EU, with appropriate GDPR safeguards (see § 7) |
| Diagnostic logging | Technical diagnostics | European Union |
| Product usage analytics | Usage statistics, only where consent is given | European Union |
| Internal team notifications | Operational alerts to our team, and contact requests left on the marketing page (name, e-mail, phone, company name). No accounting content is sent. | Outside the EU, with appropriate GDPR safeguards |
A current list of named subprocessors is available on request at tere@klaariks.ee.
User-initiated external services are not our subprocessors — the User establishes the relationship directly if they choose to use the feature:
- e-invoice ingestion services,
- public registries (e.g. RIK Äriregister),
- the tax authority (EMTA) for VAT return submission.
6a. Bank connections (PSD2)
Bank connections rely on PSD2 consent and operate through a licensed account-information service provider (AISP) acting as our subprocessor (see the § 6 table). When linking an account:
- The User grants read-only access to account information — account and transaction data. We cannot initiate payments through this connection.
- Login and consent happen in the bank's own secure environment — Klaariks never sees or stores the User's bank password or PIN.
- Consent is time-limited — the period is set by your bank (up to 180 days under PSD2 rules). After it expires, the connection must be renewed.
- The User can revoke consent at any time — either at their bank or by disconnecting in Klaariks.
A bank connection is an optional convenience. The User can always upload bank transactions manually (e.g. as a CSV file) instead.
7. International data transfers
Some subprocessors are located outside the European Economic Area (primarily in the United States). For those transfers we rely on:
- the European Commission's approved Standard Contractual Clauses (SCCs), and
- supplementary technical and organisational safeguards where necessary.
For OCR, invoice images are sent to the AI text-extraction provider; under our contract with that provider, the data is not used to train AI models.
8. Your rights
Under GDPR Articles 15–22, you have the following rights:
- Access (Art 15) — information about what data we process.
- Rectification (Art 16) — correction of inaccurate data.
- Erasure (Art 17) — deletion of your data (except where mandatory retention applies).
- Restriction of processing (Art 18).
- Data portability (Art 20) — receive your data in a machine-readable format.
- Objection (Art 21) — object to processing based on legitimate interest.
- Withdraw consent (where processing is based on consent).
To exercise your rights, contact us: tere@klaariks.ee.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (AKI): aki.ee.
9. Cookies and visit measurement
Without your consent, Klaariks uses only essential cookies required for the service to function:
- Session cookie — login state (secure, HttpOnly).
- CSRF cookie — form-submission security.
- Language cookie — remembers whether you use Klaariks in Estonian or English.
- Analytics entry — only with your consent; holds a random identifier used for measurement. Removed when consent is withdrawn.
We do not use advertising cookies, and we do not track you across other websites. Analytics is used only inside the signed-in application and only with your consent — see below.
On the public marketing page we count visits without cookies: nothing is written to your device, and you are neither identified nor tracked across other websites. We collect aggregate figures only — page viewed, referring page, country, device type and browser.
Inside the signed-in application we ask for consent for detailed usage measurement. We ask for it in the application, and without it nothing analytics-related is written to your device. You can withdraw at any time in settings — withdrawing is as easy as agreeing.
Where consent is given, we collect which views you open and which controls you use. Button and link text is masked, we do not record your screen, and we do not collect the contents of your invoices, transactions or documents.
Regardless of consent, we record a small number of technical events about the service's own behaviour — for example whether a suggested link between an invoice and a bank transaction was confirmed or dismissed. These are necessary to operate and improve the service, stay on our own servers, contain only identifiers and counts, and write nothing to your device.
10. Security
Our security measures include:
- Encryption in transit (TLS).
- Data hosted within the European Union.
- Access controls and audit logs for internal administrative actions.
- Regular software updates and security patches.
- Passwords stored as secure hashes; sign-in via a third-party identity provider (e.g. Google) is also supported.
To report a security vulnerability: tere@klaariks.ee.
11. Children
Klaariks is a service for businesses. We do not knowingly collect data from persons under 18. If we become aware of such data, we will delete it without delay.
12. Changes to this policy
We may update this policy to reflect changes in subprocessors, new features, or legal requirements. Material changes will be communicated by email or in-app notice at least 30 days in advance.
13. Contact
Privacy questions: tere@klaariks.ee Postal address: The Invisible Company OÜ, Nooda tee 8, 13516 Tallinn, Estonia Supervisory authority: Estonian Data Protection Inspectorate (AKI)