Skip to main content

Privacy Policy

How Nephworx Ltd collects, uses and protects personal data in connection with the smetni.app platform, and the rights you have under the EU General Data Protection Regulation (GDPR).

LegalIn force from:

1. Controller

This policy describes how we process personal data when you visit smetni.app, sign up, or use the smetni.app invoicing platform and the client portal. We process personal data in line with Regulation (EU) 2016/679 (GDPR) and the Bulgarian Personal Data Protection Act. The controller is:

Nephworx Ltd (Нефуъркс ЕООД) · UIC 207138187 · VAT BG207138187 · 51 Cherni Vrah Blvd, Hladilnika Industrial Zone, Lozenets, Sofia 1407, Bulgaria

For questions about personal data write to info@smetni.app.

2. What data we process

Account and identity data

Name, email address, workspace and role within an organization, and authentication metadata such as sign-in timestamps and IP addresses. Sign-in and passwords are managed by our authentication provider WorkOS; we do not store your password.

Customer Data (data you enter)

Your company details (name, EIK, VAT number, address, bank details, logo), client records (name, address, EIK/VAT, email, contacts), invoice and document content, and documents or attachments you upload (for example expense receipts). For personal data of your clients contained in Customer Data, you or your organization are the controller and we act as a processor on your instructions; controller obligations toward your clients, including informing them, are your responsibility. Our processor obligations are set out in the Data Processing Agreement.

Subscription and payment data

Payments are processed by Stripe. We do not store card numbers or full card details on our servers; we receive and keep only billing metadata such as plan, amount, invoice number, card brand and the last 4 digits of the card.

Usage and device data

Server logs (IP address, user agent, requested URL, timestamp, response code) kept for security and debugging. With your consent, product analytics (PostHog) and performance and error telemetry (Grafana Faro) in the application and the client portal, and web analytics (Google Analytics, PostHog) on the website.

Support communications

If you contact us, we keep the message and any attachments to answer your question and improve the service.

3. Purposes and legal bases

We process personal data on the following bases under Article 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)): to provide the Service, manage your account, process payments and respond to support requests.
  • Legal obligation (Art. 6(1)(c)): to comply with Bulgarian and EU law, including accounting, tax and anti-money-laundering rules.
  • Legitimate interests (Art. 6(1)(f)): to keep the Service secure, prevent fraud and abuse, and defend our legal rights. We balance these interests against your rights and freedoms.
  • Consent (Art. 6(1)(a)): for analytics and telemetry cookies and similar technologies, and for any direct marketing. You can withdraw consent at any time without affecting prior processing.

4. AI processing of uploaded documents

The platform offers optional AI-assisted features: automatic extraction of structured data from documents you upload, for example expense receipts and imported sales documents. These features run only when you use them.

When you use an AI-assisted feature, the content of the uploaded file is transmitted through our gateway hosted in the EU (AWS Frankfurt) to our AI model provider, Google LLC (Gemini API, United States, certified under the EU-U.S. Data Privacy Framework), solely to generate an extraction proposal. The content is not used by us or, under the applicable API terms, by the provider to train AI models.

The proposal is shown to you for review; nothing is saved to your records without your confirmation. No decision producing legal effects concerning you is made solely by automated means (Art. 22 GDPR).

Where uploaded documents contain personal data of your clients or other third parties, this processing is part of the processor relationship described in section 2: you decide whether to use the feature, and we process the content only to return the proposal to you.

5. Recipients

We share personal data only with service providers that help us deliver the Service, bound by data-processing agreements:

  • Amazon Web Services (EU).
  • WorkOS (United States).
  • Stripe (EU and United States).
  • Resend (Plus Five Five, Inc., United States).
  • Google LLC (United States).
  • PostHog (EU and United States).
  • Grafana Labs (EU and United States).
  • OpenAI, L.L.C. (United States).

The providers that process Customer Data on your behalf, with the purpose, processing location and transfer mechanism for each, are listed in Annex C of the Data Processing Agreement.

We may also disclose personal data when required by law, court order, or to defend our legal rights, and to professional advisers, accountants and auditors bound by confidentiality. We do not sell personal data.

6. International transfers

Customer Data and account data are hosted in the European Union (AWS Frankfurt, eu-central-1).

Some providers process limited data outside the EU, primarily in the United States. Where personal data leaves the EU, we rely on the EU-U.S. Data Privacy Framework where the recipient is certified, or on Standard Contractual Clauses approved by the European Commission, supplemented with appropriate technical and organizational measures.

7. Retention

We keep personal data only for as long as necessary for the purposes described in this policy:

  • Account and Customer Data: for as long as your account exists. After your subscription ends, the account remains in read-only mode and the data stays available to you for as long as we operate the Service.
  • Server and security logs: for a limited period appropriate to security and diagnostics, longer where needed to investigate an incident.
  • Analytics data: aggregated or pseudonymous metrics, up to 26 months in Google Analytics and up to 12 months in PostHog.

After the applicable period, data is deleted or irreversibly anonymized.

8. Security

We apply industry-standard technical and organizational measures to protect data, including TLS 1.2+ encryption in transit and AES-256 encryption at rest, EU data residency for the production database (AWS Frankfurt), least-privilege and role-based access controls, automated daily backups with point-in-time recovery, and logging and monitoring of administrative access.

9. Cookies

We use a small number of cookies and similar technologies to keep you signed in, remember preferences and, with your consent, measure usage. Full details are in the Cookie Policy.

10. Changes

We may update this policy as the service or the law evolves; the effective date at the top reflects the latest revision. For material changes we will notify you by email (for registered users) or by a notice on the website at least 14 days before the change takes effect.

Create a smetni.app account

Free for up to 5 clients, paid plans from €19/⁠mo.

Start now