Legal
Privacy policy
Updated: May 2, 2026
1. Data controller
The data controller is N.S., VAT ID PL7773183644. Contact for data matters: support@fulbill.pl.
2. What we collect
Operator company data: company name, VAT ID, address, contact details of the decision maker. Technical data: login email, IP address, panel event log. Operational data from Base: products, stock, orders, returns, deliveries.
3. What we do NOT collect
We do not collect end-consumer data. We work with order numbers, SKU codes, quantities, locations. Names, addresses and phone numbers of your clients' consumers do not enter our database. For that reason we do not sign DPAs with consumers.
4. Purposes and legal basis
Service provision (Art. 6(1)(b) GDPR). Settlements, invoices, accounting (Art. 6(1)(c) GDPR). Security and logs (Art. 6(1)(f) GDPR). Direct marketing to clients (Art. 6(1)(f) GDPR, right to object).
5. Hosting and processors
Infrastructure: Hetzner Online GmbH (Germany). Database and auth: Supabase (Frankfurt). Payments: Stripe Payments Europe (Ireland). Analytics: Plausible (EU, cookieless). All processors in the EU or under GDPR-compliant DPAs.
6. Retention
Account data: contract term + 12 months. Settlement and invoice data: 5 years under Polish accounting law. Technical logs: 12 months.
7. Your rights
Access, rectification, erasure, restriction, portability, objection, complaint to the Polish DPA. Requests: support@fulbill.pl. Reply within 30 days.
8. Policy changes
We publish updates on this page with the effective date. Material changes are communicated by email to the account administrator with 14 days notice.