1Who we are
The controller of the personal data processed to run S.P.jček (the website www.spjcek.si and the app app.spjcek.si) is:
- Company
- IntraLab, Miha Meglič s. p.
- Address
- Stegne 21C, 1000 Ljubljana, Slovenia
- Registration no.
- 7333315000
- Tax no.
- 21449155
- info@intralab.si
We have not appointed a data protection officer, as we are not required to. For any privacy question, write to the e-mail address above.
2Controller and processor
S.P.jček is invoicing software, so it holds two kinds of data, for which we are responsible in different ways:
- Data about you as a user — your account, sign-in, memberships and the like. We are the controller of this data, and this policy applies to it.
- Data you enter to run your business — your company’s details, clients and invoices. The company using S.P.jček is the controller of this data and we are its processor. The relationship is governed by the data processing agreement that forms part of the Terms of service.
If you received an invoice issued with S.P.jček and have a question about your data on it, contact the company that issued it. If such a request reaches us, we will forward it to them.
3Data we control
| Data | Purpose | Legal basis |
|---|---|---|
| User account: name, e-mail, interface language, creation time | Creating and managing your account | Performance of a contract (Article 6(1)(b) GDPR) |
| Sign-in link: e-mail, a hash of the one-time link, its expiry (24 hours) | Password-less sign-in | Performance of a contract |
| Google or Microsoft sign-in: account identifier at the provider, name, e-mail, profile picture, tokens the provider issues at sign-in | Signing in and linking several sign-in methods to one account | Performance of a contract |
| Sessions: session identifier and expiry | Keeping you signed in | Performance of a contract |
| Memberships and invitations: role in a company; for an invitation, the invitee’s e-mail and who invited them and when | Several people working in one company | Performance of a contract; for the invitee, the legitimate interest of the inviting company (Article 6(1)(f)) |
| API access tokens: token name, prefix and hash, permissions, last use | Access to the API | Performance of a contract |
| Correspondence with us: e-mail address and message content | Answering questions and requests | Legitimate interest; for rights requests, a legal obligation (Article 6(1)(c)) |
| Server logs: IP address, time, requested URL, browser details | Security and troubleshooting | Legitimate interest (Article 6(1)(f)) |
4Data we process for you
As a processor for the companies that use S.P.jček, we store:
- company details: name, address, tax and registration numbers, VAT ID, IBAN, BIC, bank, e-mail, phone, website and logo — for a sole trader these are their personal data;
- the history of those details: a copy on every change, with who made it and when, so that an issued invoice always reads as it did on the day it was issued;
- clients: name, address, tax and registration numbers, VAT ID, e-mail, phone and notes;
- invoices: buyer details, items, references, notes and who created the invoice;
- invoice templates.
We use this data only to show it in the app, to produce invoices (PDF, print, e-SLOG) and to serve the API. We don’t use it for any other purpose and don’t look at it, unless that is necessary to fix a fault or you ask us to.
5What we don’t do
- We use no analytics, advertising or tracking tools — neither on the website nor in the app.
- We don’t sell data or share it with third parties for their own purposes.
- We don’t profile you or make automated decisions about you.
- We serve our own fonts, so your browser doesn’t contact Google or anyone else when you visit.
- S.P.jček doesn’t e-mail your invoices to your clients; you send them yourself.
6Cookies and local storage
We use only cookies that are strictly necessary for the service and cookies that remember a setting you chose yourself. Under the Slovenian Electronic Communications Act (ZEKom-2) these need no consent, so we don’t ask for it.
| Name | Where | Purpose | Lifetime |
|---|---|---|---|
authjs.session-token | App | Keeps you signed in | 30 days, extended as you use it |
authjs.csrf-token | App | Protection against forged requests (CSRF) | Until the browser closes |
authjs.callback-url | App | The page to return to after signing in | Until the browser closes |
authjs.pkce.code_verifier, authjs.state, authjs.nonce | App | Secure Google or Microsoft sign-in | 15 minutes |
spjcek_tenant | App | The company you selected | 1 year |
spjcek_locale | App | Interface language | 1 year |
theme (local storage) | App and website | Light or dark theme | Until you clear it |
lang | Website | Site language; set only when you pick a language yourself | 1 year |
Over HTTPS, the sign-in cookies carry a __Secure- or __Host- prefix.
7Who else processes data
We rely on the following providers (sub-processors) to run the service. We have a data processing agreement with each of them.
| Provider | What it does | Location |
|---|---|---|
| Hetzner Online GmbH | Hosts the servers and database; all S.P.jček data is stored here | Falkenstein, Germany (EU) |
| Resend | Sends sign-in link and company invitation e-mails: the recipient’s e-mail, and the names of the company and the inviting person | USA |
Using Resend involves a transfer of data to the USA, based on the European Commission’s standard contractual clauses included in our data processing agreement with that provider. We send only sign-in and invitation e-mails through Resend — never invoices or data about your clients.
Signing in with Google or Microsoft
If you choose to sign in with Google or Microsoft, that provider processes your sign-in data as an independent controller under its own privacy policy. We receive your name, e-mail and profile picture; with Microsoft we read the profile picture through Microsoft Graph. We have no access to your mail, files, calendar or any other data in those accounts.
PDF generation
PDFs are generated on our own server, so the data never leaves our environment in the process.
Public authorities
We disclose data to public authorities only when the law requires us to, and only to the extent it requires.
8How long we keep data
- User account — for as long as it exists.
- Company details, their history, clients and invoices — for as long as the company exists in S.P.jček.
- After a deletion request — we delete the data within 30 days. It disappears from backups within a further 30 days, as they are overwritten.
- Server logs — at most 30 days.
- Correspondence with us — as long as needed to deal with the matter, then at most two years.
Note: the Slovenian VAT Act (ZDDV-1) requires invoices to be kept for 10 years after the end of the year they relate to. That obligation lies with the company issuing them. Before asking for deletion, export your invoices (PDF or e-SLOG) and keep them.
9Security
- All traffic to the website and the app is encrypted (HTTPS).
- We use no passwords: you sign in with an e-mailed link or through Google or Microsoft.
- Sign-in links and API access tokens are stored only as hashes.
- On every request we check again that you are a member of the company you are accessing.
- Only IntraLab has access to the servers and database.
In the event of a personal data breach we will act as the GDPR requires: we will notify the Slovenian Information Commissioner and, where necessary, you.
10Your rights
For the data we control, you have the right to:
- access the data we hold about you and receive a copy;
- have inaccurate data corrected;
- erasure;
- restriction of processing;
- data portability;
- object to processing based on legitimate interest.
You can change most of your data yourself in the app’s settings. To delete a user account or a company, export your data, or make any other request, write to info@intralab.si from the e-mail address you sign in to S.P.jček with. We will reply within one month at the latest.
If you believe we process your data unlawfully, you can lodge a complaint with the supervisory authority: the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si.
11Changes to this policy
We update this policy when the way we process data or the law changes. The current version is always published on this page. We will notify you of material changes by e-mail or in the app at least 14 days in advance.
This policy is published in Slovenian and English. If the two differ, the Slovenian version prevails.