Deal2Invoice for inFakt: Privacy Policy
Version 1.0, effective 1 October 2026.
1. Who is responsible
1.1. Deal2Invoice for inFakt (the App) is provided by Vinit Kumbharkar, ul. Złota 75A/7, 00-819 Warszawa, Poland, NIP 5273188850, trading as The Integration Desk (we, us).
1.2. Contact for privacy matters: support@deal2invoice.com.
2. Two roles
2.1. Processor. Most data in the App belongs to our customers: deals, buyers, contacts and invoice drafts. We process it on the customer's behalf, under the Data Processing Agreement in Annex 1 of our Terms. If your data is in a customer's Pipedrive or inFakt account, that customer is the controller. Please contact them first.
2.2. Controller. This policy covers the data we decide about ourselves: data needed to run customer accounts, billing and support.
3. What we process as controller, why, and for how long
Installation data. Kept until the last user of the company removes the App; a user's own tokens are deleted when that user removes it.
- Data: Pipedrive company ID and domain; for each user who authorizes the App, their Pipedrive user ID, language, granted scopes and access tokens (encrypted).
- Why: to provide the App that the customer ordered.
- Legal basis: users are usually employees or representatives of the customer, so the basis is our and the customer's legitimate interest in providing and securing the App (art. 6(1)(f) GDPR). For the data of a customer who is itself a natural person (e.g. a sole trader), the basis is the contract (art. 6(1)(b)). Its employees remain covered by legitimate interest.
Audit log. Deleted when the App is removed from the company.
- Data: which user did what in the App, and when.
- Why: security, and to resolve disputes about what was sent to inFakt. The legal basis is our legitimate interest (art. 6(1)(f)).
Free-draft counter. Kept after the App is removed, for as long as we offer the App.
- Data: Pipedrive company ID and the number of free drafts used.
- Why: so that the free allowance applies once per company and does not reset when the App is reinstalled.
- Legal basis: our legitimate interest (art. 6(1)(f)).
Subscription records. Kept while the subscription exists, then until the limitation period for claims under the subscription ends. Under Polish law this is normally 3 years for business claims, ending on the last day of a calendar year (art. 118 of the Civil Code). It can be longer when a claim becomes due later or the period is interrupted. If a dispute is pending, or the law requires us to keep a record longer, we keep only the records concerned, until the dispute ends or the legal duty expires.
- Data: Paddle customer and subscription IDs, subscription status, plan and dates.
- Why: to manage the subscription and to handle payment disputes.
- Legal basis: the contract with the customer (art. 6(1)(b)) and our legitimate interest in establishing or defending claims (art. 6(1)(f)).
Support emails. Kept up to 2 years after the case is closed.
- Data: your name, email address and the content of your message.
- Why: to answer you. The legal basis is our legitimate interest (art. 6(1)(f)).
Server logs. Kept for 30 days.
- Data: time, request path, Pipedrive company and user IDs, and technical errors. The logs contain no IP addresses, no credentials and no invoice contents.
- Why: to operate the App and keep it secure. The legal basis is our legitimate interest (art. 6(1)(f)).
4. Payments
4.1. Paddle sells subscriptions as our merchant of record. The Paddle entity depends on your location; for customers outside the US and Canada it is Paddle.com Market Ltd. Paddle is an independent controller for the payment, billing and tax data you give it at checkout, under Paddle's privacy policy. That policy describes how Paddle may process data outside the European Economic Area.
4.2. We send Paddle the Pipedrive company ID, so that a payment can be matched to the company. We receive from Paddle only what we need to know whether a company has an active subscription. We never see card details.
5. Who receives data
5.1. Hetzner Online GmbH hosts the App, in Germany.
5.2. Namecheap, Inc. (forwarding) and Google LLC (Gmail) handles support emails.
5.3. Paddle handles payments; see section 4.
5.4. Pipedrive and inFakt receive data only as the customer instructs: the App reads from and writes to the customer's own accounts.
5.5. We do not sell data, and we do not use it for advertising.
5.6. We host the App and its data in the European Economic Area. Paddle may process the data it receives outside it, under its own policy (section 4). Support emails are processed in the USA: by Namecheap under the Standard Contractual Clauses, and by Google under the EU–US Data Privacy Framework.
6. Deletion when the App is removed
6.1. When the last user of a company removes the App, we immediately delete the company's operational data:
- the company's installation data;
- the inFakt connection;
- settings, invoices and the audit log.
6.2. Some data is kept after that, for the periods stated in section 3:
- the free-draft counter;
- subscription records;
- server logs;
- support emails.
6.3. Deleted data disappears from our backups within 30 days.
7. Cookies
7.1. The App sets no cookies of its own and uses no analytics or advertising trackers.
7.2. The checkout page loads Paddle's checkout, which may set cookies needed for the payment, under Paddle's policy.
8. Your rights
8.1. You have the right to:
- access your data;
- have it corrected;
- have it deleted;
- restrict its processing;
- data portability;
- object to processing based on legitimate interest.
8.2. Write to support@deal2invoice.com.
8.3. You can also complain to the Polish supervisory authority, the Prezes Urzędu Ochrony Danych Osobowych (PUODO), ul. Moniuszki 1A, 00-014 Warszawa, uodo.gov.pl. You can also complain to the authority in your own country.
9. Security
9.1. The App is hosted in the EU.
9.2. All connections are encrypted.
9.3. Credentials are stored encrypted.
9.4. Requests from the App's screens in Pipedrive are checked with a signed Pipedrive token. Pipedrive's installation and removal callbacks are authenticated with our app credentials.
9.5. Each company's data is accessible only to that company.
10. Changes
We will announce material changes to this policy in the App or by email before they take effect.