Privacy Policy
This Privacy Policy explains how Mark Kucler s.p., a sole proprietor registered in Slovenia, doing business as SimplNorm (“SimplNorm”, “we”, “us”, or “our”), collects, uses, stores, and protects personal data when you visit our website, join the waitlist, or use the SimplNorm application.
1. Controller
For personal data that we process for our own purposes, the controller is:
- Legal name: Mark Kucler s.p.
- Business form: samostojni podjetnik / sole proprietor, Slovenia
- Business address: Podsmreka 5V, 1356 Dobrova, Slovenia
- Registration number / maticna stevilka: 7472099000
- Tax number / davcna stevilka: 52888746
- VAT ID, if applicable: not VAT registered
- Privacy and data-protection email: info@simplnorm.com
- Support email: support@simplnorm.com
If you use SimplNorm to store personal data about your own clients, customers, suppliers, collaborators, or invoice recipients, you are normally the controller for that data and we process it on your behalf as a processor. That processing is also governed by the Data Processing Addendum.
2. What SimplNorm Does
SimplNorm is a SaaS invoicing workspace primarily designed for Slovenian sole proprietors and small businesses, including normirani s.p. users. The service can help users manage company profile data, clients, invoices, invoice PDFs, payment status, VAT and income-tax summaries, contribution summaries, exports, templates, and related account settings.
SimplNorm is not an accounting, tax, legal, or financial advisory service. The data you enter may be used to produce documents, estimates, summaries, and exports, but you remain responsible for checking whether your invoices, records, tax filings, and business decisions are correct for your situation.
3. Personal Data We Collect
We collect personal data that you provide directly, data generated through your use of the service, data received from service providers, and limited data from public or official business-register sources when you use company lookup features.
The categories may include:
- Account data: name, email address, password hash, login method, email verification state, profile image if provided by an identity provider, account settings, and account status.
- Authentication and security data: session identifiers, login timestamps, authentication provider IDs, password reset events, account linking data, the date and version of accepted Terms and the Privacy Policy version, device/browser metadata, IP address, and security logs.
- Business and organization data: workspace name, legal name, business address, tax number, VAT ID, registration number, contact email, phone number, bank account details, VAT registration status, Article 94 eligibility, invoicing defaults, invoice numbering settings, business premises/device codes where configured, logo files, and Slovenia year-end tax profile data.
- Client and invoice data: client names, legal names, addresses, countries, tax numbers, VAT IDs, email addresses, contact details, invoice numbers, issue/supply/due dates, document types, line items, prices, discounts, VAT rates, payment methods, payment status, notes, credit-note references, public-sector flags, real-estate flags, and generated invoice PDFs.
- Imported and exported data: invoice import files or extracted invoice data, CSV exports, account archives, generated PDFs, and related metadata.
- Agent and integration data: SimplNorm agent access tokens, token scopes, device-login approval state, MCP/API activity, and tool usage metadata where agent access is enabled.
- Email data: email addresses, message metadata, transactional email content, delivery events, and support communications.
- Technical data: server logs, request metadata, error logs, browser type, device information, timestamps, and diagnostics needed to operate and secure the service.
- Waitlist data: email address, submission timestamp, source, Cloudflare country code, landing-page language, page origin, referrer host where available, and a capped user-agent string. Waitlist contacts are stored in Resend. We do not send raw IP addresses to Resend.
- Landing-page analytics and abuse-prevention data: limited interaction events such as CTA clicks, product-preview selections, waitlist submission status, request path, country code, browser language, origin host, referrer host where available, event label/target where relevant, timestamps, and short-lived hashed rate-limit keys.
We ask you not to enter special categories of personal data, criminal-offence data, or health data unless they are strictly necessary for your business records and lawful for you to process.
4. Sources Of Personal Data
We collect data from:
- you, when you create an account, configure a workspace, enter clients, create invoices, upload files, contact support, or join the waitlist;
- your authorized users or agents, when they act in your workspace;
- identity providers such as Google or GitHub, if you choose social sign-in;
- service providers that help operate SimplNorm;
- public or official Slovenian company-register sources, such as AJPES/open-data sources, when you use company lookup features.
5. Purposes And Legal Bases
For users in the EU/EEA, we process personal data under the GDPR legal bases below.
Provide the service
- Examples: account creation, login, workspaces, invoices, PDFs, exports, reports, templates, client records, and agent access.
- Legal basis: contract performance or steps before entering a contract.
Operate and secure the service
- Examples: sessions, abuse prevention, fraud prevention, troubleshooting, rate limits, logs, and account safety.
- Legal basis: legitimate interests in operating and securing the service; legal obligation where applicable.
Send transactional emails
- Examples: account verification, password reset, account safety, deletion or export notices, and service messages.
- Legal basis: contract performance; legitimate interests; legal obligation where applicable.
Support users
- Examples: responding to questions, diagnosing issues, and handling complaints.
- Legal basis: contract performance; legitimate interests.
Improve SimplNorm
- Examples: debugging, product quality, feature planning, and internal analytics if enabled.
- Legal basis: legitimate interests, unless consent is required for a specific technology.
Comply with law
- Examples: tax, accounting, regulatory matters, legal claims, and court or authority requests.
- Legal basis: legal obligation; legitimate interests in establishing or defending claims.
Waitlist
- Examples: collecting beta access requests, managing invite priority, preventing duplicate or abusive submissions, and sending relevant product access or onboarding messages.
- Legal basis: steps before entering a contract; legitimate interests in operating the beta and preventing abuse; consent where required for optional marketing.
Marketing
- Examples: optional product updates or marketing emails, if enabled.
- Legal basis: consent or legitimate interests where permitted, with opt-out rights.
Where we rely on legitimate interests, we consider whether our interests are overridden by your rights and freedoms. You may object to processing based on legitimate interests where GDPR gives you that right.
6. Whether You Must Provide Data
Some data is necessary to enter into or perform the contract and provide SimplNorm. If you do not provide basic account, authentication, workspace, company, client, or invoice data, you may not be able to use the relevant features.
Data for optional marketing messages, additional profile details, logos, imports, integrations, and agents is voluntary, but some features will not work without it.
Data that you must keep or process for tax, accounting, or other legal duties is your business data. SimplNorm may help you process that data, but it does not decide for you which data you are legally required to keep.
7. Service Providers And Recipients
We share personal data only where needed to provide, secure, improve, or legally operate SimplNorm.
Current recipients and providers include:
- Application hosting/infrastructure: Hetzner Online GmbH as the contractual provider and Hetzner Finland Oy as the data-center operator for the production VPS in Helsinki, Finland, covering the application frontend, backend, and PDF service.
- Database: Neon Postgres in the Frankfurt, EU region.
- File storage: Cloudflare R2, configured for EU storage where enabled, for app files such as uploaded logos, generated PDFs, and exports.
- Email delivery and waitlist contact storage: Resend for transactional emails and beta waitlist contacts.
- Landing-page hosting, security, rate limiting, and internal analytics: Cloudflare Pages, Cloudflare Workers, Cloudflare KV, and Cloudflare Analytics Engine.
- Error monitoring and diagnostics: Sentry to detect errors and protect frontend and backend service stability.
- External sign-in providers: Google and GitHub if you choose social sign-in through those providers.
- Professional advisers and authorities: accountants, lawyers, auditors, courts, tax authorities, regulators, or law enforcement where required or appropriate.
More detailed information is available in the Subprocessor List, which we may update from time to time.
If we introduce paid plans later, we may use Stripe as a payment processor and will update this policy before charging users.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
8. International Transfers
We try to keep core production hosting and storage in the EU where practical, including EU VPS application hosting and EU Cloudflare R2 storage. Some providers may still process account, support, security, email, or operational data outside Slovenia or the EU/EEA.
Where personal data is transferred internationally, we rely on appropriate safeguards required by GDPR, such as adequacy decisions, the EU Standard Contractual Clauses, data processing agreements, and supplementary safeguards where needed.
Provider-specific notes:
- Resend may process certain data in the United States and uses EU Standard Contractual Clauses for certain ex-EEA transfers.
- Cloudflare uses a global network and includes EU Standard Contractual Clauses in its data processing terms for restricted transfers.
- Sentry, Google, GitHub, and Stripe may process data internationally under their own legal, privacy, and data processing terms.
9. Cookies And Similar Technologies
SimplNorm uses essential cookies and similar technologies to provide login, authentication, session security, and core application functionality. We may also store local application state, such as selected workspace data, UI preferences, and cached query data, in browser storage. Cached query data expires 24 hours after its last refresh and is removed after a successful sign-out or account-deletion request. Always sign out explicitly on a shared device.
On the landing page, we may use browser local storage to remember that a visitor has already joined the beta waitlist, so the page can show a confirmation state instead of asking again. This flag does not store the email address.
We currently do not use analytics, advertising, or tracking cookies on the landing page. We may collect limited first-party landing-page events through our own Cloudflare Worker and Cloudflare Analytics Engine to understand aggregate interest in the beta, measure CTA clicks and waitlist form status, and protect the form from abuse. These events do not rely on cookies, do not include raw IP addresses in the analytics dataset, and are not used for behavioral advertising.
If analytics or marketing cookies are introduced later, we will update this policy and, where required, request consent before using them.
10. Retention
We keep personal data only as long as needed for the purposes described in this policy, unless a longer retention period is required or permitted by law.
Current retention rules and intended criteria include:
- Active account and workspace data is kept while your account or workspace remains active.
- Account deletion removes active access immediately and schedules certain sole-member workspace data for permanent deletion after a 30-day retention window.
- Shared-workspace data may be retained if other users remain members of the workspace.
- Invoices, invoice PDFs, exports, audit records, and bookkeeping-related records may be retained where required for tax, accounting, legal, or dispute purposes. Slovenian bookkeeping and tax rules may require invoice and accounting records to be retained for long periods, commonly 10 years and, for certain real-estate VAT records, 20 years.
- Security and application logs are kept for a limited period needed for security, troubleshooting, and event evidence. Where practical, we truncate or anonymize them.
- Transactional email records are retained by us and our email provider as needed for delivery, security, troubleshooting, and compliance.
- Waitlist data is kept until the beta access process is complete, you ask us to delete it, or we no longer need it for product access, onboarding, or related communications.
- Landing-page analytics are kept in aggregate or event form only as long as useful for internal product and launch analysis. Rate-limit keys in Cloudflare KV are short-lived and expire automatically according to the configured rate-limit window.
You should export your records before deleting your account if you need them for accounting, tax, legal, or business purposes.
11. Security
We use reasonable technical and organizational measures to protect personal data, including access controls, authenticated sessions, scoped agent tokens, secure transport, environment-secret management, provider security controls, error monitoring, and operational logging. A separate SimplNorm-managed backup system is not yet active as of this policy date, so you should regularly export and separately retain important business records.
No online service can guarantee complete security. You are responsible for using strong credentials, protecting your devices, limiting access to your workspace, reviewing agent/API access, and promptly telling us about suspected unauthorized access.
12. Automated Decision-Making And Profiling
SimplNorm does not currently make solely automated decisions that produce legal effects concerning individuals or similarly significantly affect them within the meaning of GDPR Article 22.
Reporting, tax-summary, reminder, template, agent, and other automation features may prepare drafts, calculations, estimates, or suggestions. These outputs are intended for user review and do not by themselves represent our automated legal decision about an individual.
13. Your GDPR Rights
Depending on your location and the context of processing, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion of personal data;
- restrict processing;
- object to processing based on legitimate interests;
- receive a portable copy of data you provided;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority.
In Slovenia, the supervisory authority is the Information Commissioner of the Republic of Slovenia (Informacijski pooblascenec): https://www.ip-rs.si/
You can exercise rights by using available in-product export/deletion tools or by contacting info@simplnorm.com. We may need to verify your identity before acting on a request.
If you ask us to delete data that your business must keep for accounting, tax, legal, or regulatory reasons, we may restrict or retain the relevant data as required or permitted by law.
14. Data You Process About Your Clients
When you enter client, invoice recipient, supplier, or collaborator data into SimplNorm, you are responsible for ensuring that you have a lawful basis to process that data and to provide it to us for processing. You are also responsible for giving any required notices to those individuals and for responding to their rights requests, unless the law requires us to respond directly.
We process this customer data only to provide and secure SimplNorm, according to your instructions, the Data Processing Addendum, and applicable law, unless we are legally required to do otherwise.
15. Children’s Data
SimplNorm is intended for business users and is not directed to children. You must be at least 18 years old, or the age of legal capacity in your country if higher, to use SimplNorm. We do not knowingly collect personal data from children.
16. Changes To This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify users, such as through the website, the app, or email. The updated version applies from the effective date shown above unless stated otherwise.
17. Contact
Questions, requests, or complaints about privacy can be sent to:
