Klaariks

Privacy Policy

Effective from 18 August 2026

Eesti keeles

1. Data controller

The data controller is The Invisible Company OÜ (Estonian registry code 17424017, Nooda tee 8, 13516 Tallinn).

Privacy contact: tere@klaariks.ee

2. What data we collect

Klaariks processes the following categories:

CategoryExamplesSource
Account dataEmail, name, company name, registry code, VAT numberYour input / Google sign-in / RIK Äriregister
Accounting documentsInvoices (PDF/images), bank transactions, contacts, chart of accountsYour upload / bank import / e-invoice channel
Technical dataIP address, browser type, cookies, login timestampsAutomatically from your use of the service
Diagnostic logsError and operation recordsAutomatically during service operation

3. Purposes of processing

We process personal data for these purposes:

  1. Service delivery — account management, document processing, bookkeeping.
  2. Text recognition (OCR) — AI-based extraction of data from uploaded document images (invoices, expense documents, trial-balance reports).
  3. Customer support — answering questions, resolving issues.
  4. Service improvement — analysis of anonymised usage data, evaluating AI accuracy.
  5. Legal compliance — retaining accounting documents, responding to lawful requests from authorities (e.g. EMTA, AKI).

4. Legal basis

Processing is based on Regulation (EU) 2016/679 (GDPR):

  • Performance of a contract (Art 6(1)(b)) — service delivery, account management, document processing.
  • Legitimate interest (Art 6(1)(f)) — service improvement, security, fraud prevention.
  • Legal obligation (Art 6(1)(c)) — accounting retention requirements, responses to authority requests.

5. Retention

CategoryRetention
Account dataWhile the account is active + 30 days after closure
Accounting documents (invoices, bank transactions, annual report data)7 years per Estonian Accounting Act § 12(1)
Technical and diagnostic logsUp to 30 days

After the retention period, data is securely deleted.

6. Subprocessors

Klaariks engages categories of subprocessors (data processors under GDPR Art 28) under appropriate contractual safeguards:

CategoryRoleData location
Cloud hosting providersApplication and database hostingEuropean Union
Document storageStorage of uploaded filesEuropean Union
PSD2 account-information aggregator (Enable Banking Oy)Licensed account-information service provider (AISP) — retrieves bank account and transaction data with the User's consentEuropean Union (Finland)
AI text-extraction serviceOCR — extracts text from invoice imagesOutside the EU, with appropriate GDPR safeguards (see § 7)
Diagnostic loggingTechnical diagnosticsEuropean Union
Product usage analyticsUsage statistics, only where consent is givenEuropean Union
Internal team notificationsOperational alerts to our team, and contact requests left on the marketing page (name, e-mail, phone, company name). No accounting content is sent.Outside the EU, with appropriate GDPR safeguards

A current list of named subprocessors is available on request at tere@klaariks.ee.

User-initiated external services are not our subprocessors — the User establishes the relationship directly if they choose to use the feature:

  • e-invoice ingestion services,
  • public registries (e.g. RIK Äriregister),
  • the tax authority (EMTA) for VAT return submission.

6a. Bank connections (PSD2)

Bank connections rely on PSD2 consent and operate through a licensed account-information service provider (AISP) acting as our subprocessor (see the § 6 table). When linking an account:

  • The User grants read-only access to account information — account and transaction data. We cannot initiate payments through this connection.
  • Login and consent happen in the bank's own secure environment — Klaariks never sees or stores the User's bank password or PIN.
  • Consent is time-limited — the period is set by your bank (up to 180 days under PSD2 rules). After it expires, the connection must be renewed.
  • The User can revoke consent at any time — either at their bank or by disconnecting in Klaariks.

A bank connection is an optional convenience. The User can always upload bank transactions manually (e.g. as a CSV file) instead.

7. International data transfers

Some subprocessors are located outside the European Economic Area (primarily in the United States). For those transfers we rely on:

  • the European Commission's approved Standard Contractual Clauses (SCCs), and
  • supplementary technical and organisational safeguards where necessary.

For OCR, invoice images are sent to the AI text-extraction provider; under our contract with that provider, the data is not used to train AI models.

8. Your rights

Under GDPR Articles 15–22, you have the following rights:

  • Access (Art 15) — information about what data we process.
  • Rectification (Art 16) — correction of inaccurate data.
  • Erasure (Art 17) — deletion of your data (except where mandatory retention applies).
  • Restriction of processing (Art 18).
  • Data portability (Art 20) — receive your data in a machine-readable format.
  • Objection (Art 21) — object to processing based on legitimate interest.
  • Withdraw consent (where processing is based on consent).

To exercise your rights, contact us: tere@klaariks.ee.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (AKI): aki.ee.

9. Cookies and visit measurement

Without your consent, Klaariks uses only essential cookies required for the service to function:

  • Session cookie — login state (secure, HttpOnly).
  • CSRF cookie — form-submission security.
  • Language cookie — remembers whether you use Klaariks in Estonian or English.
  • Analytics entry — only with your consent; holds a random identifier used for measurement. Removed when consent is withdrawn.

We do not use advertising cookies, and we do not track you across other websites. Analytics is used only inside the signed-in application and only with your consent — see below.

On the public marketing page we count visits without cookies: nothing is written to your device, and you are neither identified nor tracked across other websites. We collect aggregate figures only — page viewed, referring page, country, device type and browser.

Inside the signed-in application we ask for consent for detailed usage measurement. We ask for it in the application, and without it nothing analytics-related is written to your device. You can withdraw at any time in settings — withdrawing is as easy as agreeing.

Where consent is given, we collect which views you open and which controls you use. Button and link text is masked, we do not record your screen, and we do not collect the contents of your invoices, transactions or documents.

Regardless of consent, we record a small number of technical events about the service's own behaviour — for example whether a suggested link between an invoice and a bank transaction was confirmed or dismissed. These are necessary to operate and improve the service, stay on our own servers, contain only identifiers and counts, and write nothing to your device.

10. Security

Our security measures include:

  • Encryption in transit (TLS).
  • Data hosted within the European Union.
  • Access controls and audit logs for internal administrative actions.
  • Regular software updates and security patches.
  • Passwords stored as secure hashes; sign-in via a third-party identity provider (e.g. Google) is also supported.

To report a security vulnerability: tere@klaariks.ee.

11. Children

Klaariks is a service for businesses. We do not knowingly collect data from persons under 18. If we become aware of such data, we will delete it without delay.

12. Changes to this policy

We may update this policy to reflect changes in subprocessors, new features, or legal requirements. Material changes will be communicated by email or in-app notice at least 30 days in advance.

13. Contact

Privacy questions: tere@klaariks.ee Postal address: The Invisible Company OÜ, Nooda tee 8, 13516 Tallinn, Estonia Supervisory authority: Estonian Data Protection Inspectorate (AKI)