Skip to content
S.P.jček
Features Reliability Getting started FAQ
SL Sign in

Legal

Privacy policy

Effective 14 September 2026

In short: we process personal data only to make S.P.jček work. We don’t sell it, we don’t use advertising or analytics tools, and we don’t track your browsing. Our servers and database are in Germany, in the EU.

Contents

  1. Who we are
  2. Controller and processor
  3. Data we control
  4. Data we process for you
  5. What we don’t do
  6. Cookies and local storage
  7. Who else processes data
  8. How long we keep data
  9. Security
  10. Your rights
  11. Changes to this policy

See also

Terms of service →

Questions? info@intralab.si

1Who we are

The controller of the personal data processed to run S.P.jček (the website www.spjcek.si and the app app.spjcek.si) is:

Company
IntraLab, Miha Meglič s. p.
Address
Stegne 21C, 1000 Ljubljana, Slovenia
Registration no.
7333315000
Tax no.
21449155
E-mail
info@intralab.si

We have not appointed a data protection officer, as we are not required to. For any privacy question, write to the e-mail address above.

2Controller and processor

S.P.jček is invoicing software, so it holds two kinds of data, for which we are responsible in different ways:

  • Data about you as a user — your account, sign-in, memberships and the like. We are the controller of this data, and this policy applies to it.
  • Data you enter to run your business — your company’s details, clients and invoices. The company using S.P.jček is the controller of this data and we are its processor. The relationship is governed by the data processing agreement that forms part of the Terms of service.

If you received an invoice issued with S.P.jček and have a question about your data on it, contact the company that issued it. If such a request reaches us, we will forward it to them.

3Data we control

DataPurposeLegal basis
User account: name, e-mail, interface language, creation timeCreating and managing your accountPerformance of a contract (Article 6(1)(b) GDPR)
Sign-in link: e-mail, a hash of the one-time link, its expiry (24 hours)Password-less sign-inPerformance of a contract
Google or Microsoft sign-in: account identifier at the provider, name, e-mail, profile picture, tokens the provider issues at sign-inSigning in and linking several sign-in methods to one accountPerformance of a contract
Sessions: session identifier and expiryKeeping you signed inPerformance of a contract
Memberships and invitations: role in a company; for an invitation, the invitee’s e-mail and who invited them and whenSeveral people working in one companyPerformance of a contract; for the invitee, the legitimate interest of the inviting company (Article 6(1)(f))
API access tokens: token name, prefix and hash, permissions, last useAccess to the APIPerformance of a contract
Correspondence with us: e-mail address and message contentAnswering questions and requestsLegitimate interest; for rights requests, a legal obligation (Article 6(1)(c))
Server logs: IP address, time, requested URL, browser detailsSecurity and troubleshootingLegitimate interest (Article 6(1)(f))

4Data we process for you

As a processor for the companies that use S.P.jček, we store:

  • company details: name, address, tax and registration numbers, VAT ID, IBAN, BIC, bank, e-mail, phone, website and logo — for a sole trader these are their personal data;
  • the history of those details: a copy on every change, with who made it and when, so that an issued invoice always reads as it did on the day it was issued;
  • clients: name, address, tax and registration numbers, VAT ID, e-mail, phone and notes;
  • invoices: buyer details, items, references, notes and who created the invoice;
  • invoice templates.

We use this data only to show it in the app, to produce invoices (PDF, print, e-SLOG) and to serve the API. We don’t use it for any other purpose and don’t look at it, unless that is necessary to fix a fault or you ask us to.

5What we don’t do

  • We use no analytics, advertising or tracking tools — neither on the website nor in the app.
  • We don’t sell data or share it with third parties for their own purposes.
  • We don’t profile you or make automated decisions about you.
  • We serve our own fonts, so your browser doesn’t contact Google or anyone else when you visit.
  • S.P.jček doesn’t e-mail your invoices to your clients; you send them yourself.

6Cookies and local storage

We use only cookies that are strictly necessary for the service and cookies that remember a setting you chose yourself. Under the Slovenian Electronic Communications Act (ZEKom-2) these need no consent, so we don’t ask for it.

NameWherePurposeLifetime
authjs.session-tokenAppKeeps you signed in30 days, extended as you use it
authjs.csrf-tokenAppProtection against forged requests (CSRF)Until the browser closes
authjs.callback-urlAppThe page to return to after signing inUntil the browser closes
authjs.pkce.code_verifier, authjs.state, authjs.nonceAppSecure Google or Microsoft sign-in15 minutes
spjcek_tenantAppThe company you selected1 year
spjcek_localeAppInterface language1 year
theme (local storage)App and websiteLight or dark themeUntil you clear it
langWebsiteSite language; set only when you pick a language yourself1 year

Over HTTPS, the sign-in cookies carry a __Secure- or __Host- prefix.

7Who else processes data

We rely on the following providers (sub-processors) to run the service. We have a data processing agreement with each of them.

ProviderWhat it doesLocation
Hetzner Online GmbHHosts the servers and database; all S.P.jček data is stored hereFalkenstein, Germany (EU)
ResendSends sign-in link and company invitation e-mails: the recipient’s e-mail, and the names of the company and the inviting personUSA

Using Resend involves a transfer of data to the USA, based on the European Commission’s standard contractual clauses included in our data processing agreement with that provider. We send only sign-in and invitation e-mails through Resend — never invoices or data about your clients.

Signing in with Google or Microsoft

If you choose to sign in with Google or Microsoft, that provider processes your sign-in data as an independent controller under its own privacy policy. We receive your name, e-mail and profile picture; with Microsoft we read the profile picture through Microsoft Graph. We have no access to your mail, files, calendar or any other data in those accounts.

PDF generation

PDFs are generated on our own server, so the data never leaves our environment in the process.

Public authorities

We disclose data to public authorities only when the law requires us to, and only to the extent it requires.

8How long we keep data

  • User account — for as long as it exists.
  • Company details, their history, clients and invoices — for as long as the company exists in S.P.jček.
  • After a deletion request — we delete the data within 30 days. It disappears from backups within a further 30 days, as they are overwritten.
  • Server logs — at most 30 days.
  • Correspondence with us — as long as needed to deal with the matter, then at most two years.

Note: the Slovenian VAT Act (ZDDV-1) requires invoices to be kept for 10 years after the end of the year they relate to. That obligation lies with the company issuing them. Before asking for deletion, export your invoices (PDF or e-SLOG) and keep them.

9Security

  • All traffic to the website and the app is encrypted (HTTPS).
  • We use no passwords: you sign in with an e-mailed link or through Google or Microsoft.
  • Sign-in links and API access tokens are stored only as hashes.
  • On every request we check again that you are a member of the company you are accessing.
  • Only IntraLab has access to the servers and database.

In the event of a personal data breach we will act as the GDPR requires: we will notify the Slovenian Information Commissioner and, where necessary, you.

10Your rights

For the data we control, you have the right to:

  • access the data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • erasure;
  • restriction of processing;
  • data portability;
  • object to processing based on legitimate interest.

You can change most of your data yourself in the app’s settings. To delete a user account or a company, export your data, or make any other request, write to info@intralab.si from the e-mail address you sign in to S.P.jček with. We will reply within one month at the latest.

If you believe we process your data unlawfully, you can lodge a complaint with the supervisory authority: the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si.

11Changes to this policy

We update this policy when the way we process data or the law changes. The current version is always published on this page. We will notify you of material changes by e-mail or in the app at least 14 days in advance.

This policy is published in Slovenian and English. If the two differ, the Slovenian version prevails.

S.P.jček

Invoicing for small Slovenian businesses. Made by IntraLab.

Sign in Privacy Terms Slovenščina