Privacy Policy
This Privacy Policy was last updated on January 3rd 2022.
1. Controller
The controller for personal data processed through https://www.simple-tasks.com and the related application is Kvadrati, Aleksandar Hajduković s.p., Celovška cesta 95a, 1000 Ljubljana, Slovenija. Privacy questions or requests can be sent through the contact page. This Policy should be read together with our Terms of Use.
2. Personal Data We Process
- Account, identity and contact data, such as name, email, phone, company, address, language and login information.
- Company, employee, customer, supplier, invoice, expense, project, task, message, attachment and document data entered by users.
- Billing and payment metadata, such as plan, payment status, invoice data and payment-provider references. We do not intentionally store full card numbers.
- Technical and security data, such as IP address, device, browser, logs, authentication events, error reports and usage events.
- Support and contact data that you send to us through forms, email or other support channels.
- Cookie and similar technology data, depending on your settings and the tools enabled on the website.
3. Why We Process Data
- To create accounts, provide the Service, store documents, process workflows and enable collaboration, based on contract performance.
- To process payments, invoices, accounting records, tax records and legal obligations, based on contract and legal obligations.
- To secure the Service, prevent abuse, troubleshoot, improve performance and support users, based on legitimate interests.
- To send service messages, security notices, billing information and important product changes, based on contract or legitimate interests.
- To send optional marketing or use non-essential analytics/cookies where consent is required, based on consent.
- To comply with law, court orders, public authority requests and dispute handling, based on legal obligations or legitimate interests.
4. Data Entered By Your Organization
When an organization uses the Service for employees, customers, suppliers or project participants, that organization is responsible for ensuring a valid legal basis and providing any required notices to those people. We process that data to provide the Service to the account owner and according to the product functionality.
5. Recipients And Processors
We share personal data only when needed to operate the Service, comply with law or protect our rights. Recipients may include hosting and database providers, email providers, payment providers, analytics or captcha providers, OCR/document processing providers, support tools, professional advisers, public authorities and integrations that you enable or use. Processors may only process data under our instructions and appropriate contractual safeguards.
6. International Transfers
We aim to use providers in the European Economic Area where practical. If personal data is transferred outside the EEA, we rely on an adequacy decision, Standard Contractual Clauses or another transfer mechanism permitted by GDPR.
7. Retention
We keep personal data for as long as needed to provide the Service, maintain the account, comply with accounting, tax, legal and security obligations, resolve disputes and enforce agreements. After account termination or service discontinuation, content may be deleted after 30 days unless a longer retention period is required by law or backup/deletion cycles. Accounting and tax documents may need to be retained for statutory periods.
8. Your Rights
Subject to GDPR conditions and limits, you may request access, rectification, erasure, restriction, portability and objection to processing. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing. You may also lodge a complaint with the Slovenian Information Commissioner or another competent supervisory authority.
9. Cookies And Similar Technologies
We use essential cookies and similar technologies for login, security, language, preferences and core application functions. Analytics, advertising or other non-essential cookies are used only where enabled and where a valid legal basis exists, including consent where required. You can manage cookies in your browser and, where provided, through our consent controls.
10. Security
We use technical and organizational measures intended to protect personal data, including access controls, authentication, backups, monitoring and secure communication where applicable. No internet service can be guaranteed as completely secure. You must also protect your devices, passwords and user permissions.
11. Children
The Service is intended for business users and is not directed to children under 16. If we learn that a child has provided personal data without appropriate authorization, we will take reasonable steps to delete it.
12. Changes
We may update this Policy to reflect product, legal or operational changes. Material changes will be communicated by email, in-app notice or publication on the website.
13. Contact
For privacy requests, use the contact page and include the email address connected with your account so we can identify the request.