Kontabilisti im Contact

Privacy policy

Last updated: 1 September 2026.

To complete before publishing: the privacy contact address ([EMAIL]).

Who processes your data

Kontabilisti im is a service of Sun Dream Devs L.L.C. (business no. 812294560), at Velani, Prishtinë 10000, Kosovo. For questions about data, write to [EMAIL].

Two different roles, and why it matters

For your account data — email, name, password, company — we are the controller.

For the data you enter into the software — employees, salaries, national ID numbers, bank accounts, invoices, bank statements — the controller is your company. We process it only on your behalf and on your instruction, as a processor. That means we do not look at it, analyse it, or use it for any other purpose. Obligations towards your employees — informing them, statutory retention, handling their requests — remain with the company.

What is collected

From your account

  • The email and name you enter at registration.
  • Your password, stored only as an Argon2 hash. The plain text is never stored and cannot be read by us.
  • Company name and business number (NUI).

From usage

  • Device sessions: creation time, last use, IP address, and a description of the browser or app. These exist to show you where you are signed in and to let you revoke sessions — particularly when a phone is lost.
  • An audit log of actions inside your company (who saved what, when), so a mistaken change can be found.

From you, for the work

  • Employees: name, national ID, bank account, bank, salary.
  • Expense invoices and their photographs.
  • Bank statements you upload (CSV or PDF).
  • Customers and outgoing invoices.

The contact form

When you write through the contact form, we collect your name, email and message — plus company, phone and how many users will log in, if you fill those in. The legal basis is the legitimate interest in answering a request you started.

Messages are stored on the same server as the application, do not pass through any third-party service, and are not added to any mailing list. They are kept for up to a year after the last reply, then deleted. Ask if you want yours deleted sooner.

Invoice photographs

Invoice reading (OCR) happens on our own server, using a locally installed Tesseract. The photograph is not sent to Google, Amazon, OpenAI or any external OCR service. This has a cost — the reading is simpler than a large provider's — and the choice is deliberate: an invoice carries the supplier's name, the amounts, and often other details that have no business reaching a third party.

The mobile app strips EXIF metadata — including location — before the photograph is sent. When stripping fails, the app says so on screen rather than uploading silently.

Where it is stored

On a rented server in the European Union, with Hetzner Online GmbH. There is one database, with each company's data separated and filtered by company on every request. Connections are HTTPS only.

Trackers

This website has no trackers, no advertising cookies, no Google Analytics, no Facebook pixel and no external fonts. That is why there is no cookie consent banner — there is nothing to consent to.

The application uses a session cookie (in the browser) or a token stored in Keychain/Keystore (on a phone). They keep you signed in; they do not track behaviour.

Who receives it

Your data is not sold, not traded, and not sent to third parties for advertising. The only exceptions:

  • Hetzner — as the server host. It does not look at the data; it holds the disk the data lives on.
  • Where required by law by a competent authority, on a legal basis.

How long it is kept

As long as you keep the account, plus any period required by law. Payroll data in Kosovo carries statutory retention periods that belong to your company; deleting an account therefore does not always immediately delete payroll records.

Your rights

You may request access, correction, export or deletion. Export needs no request: CSV for payroll, invoices, expenses and the ATK list is inside the software and always works.

Account deletion: for now this is done by request to [EMAIL], and completed within 30 days. Deletion directly inside the app is being built. Where an account is the sole owner of a company, ownership must first be transferred or deletion of the whole company chosen — otherwise the company's data would be left with no owner.

Security

  • Passwords: Argon2 hashes, never readable text.
  • Integration credentials: encrypted in the database.
  • HTTPS only; session cookies marked Secure.
  • Device sessions visible and revocable by the user.
  • Every query filtered by company; roles separate reading from writing.

No system is unbreakable, and this page does not promise perfection. If a breach occurs that puts data at risk, you will be notified.

Children

The service is for companies. It is not directed at children and does not knowingly collect their data.

Changes

When this policy changes materially, you are notified by email before the change takes effect. The update date is at the top of this page.