This policy explains how personal data is handled in connection with craftedbills.com, email contact and the local-first CraftedBills App.
Effective from 21 July 2026
1. Scope and local app data
This policy covers visits to craftedbills.com, messages sent to the published email address and personal data that may be processed during support or controlled product tests.
The current app stores its working data locally on the user’s device. Crafted Solutions does not receive bank statements, invoices, matching decisions or local backups merely because the app processes them. Such data reaches the controller only if the user deliberately sends it in correspondence, support material or through a separately described online service.
2. Data categories
Depending on how you use the website or contact us, the following categories may be processed:
technical connection data, such as IP address, request time, requested URL, referrer, browser or device headers and security events;
contact data and correspondence, including name, email address, message content and attachments you choose to send;
information supplied for test access, support or feedback, including professional role, device information and product observations;
data required to document requests, defend claims or comply with legal obligations.
3. Purposes and legal bases
We process data only for defined purposes and on an applicable basis under Article 6 GDPR:
to deliver and secure the website, prevent abuse and diagnose errors — legitimate interests under Article 6(1)(f) GDPR;
to answer enquiries and take steps requested before possible test access or another agreement — Article 6(1)(b) or, where appropriate, Article 6(1)(f) GDPR;
to comply with legal obligations — Article 6(1)(c) GDPR;
to establish, pursue or defend claims — legitimate interests under Article 6(1)(f) GDPR;
for optional communications based on consent, if introduced — Article 6(1)(a) GDPR; consent may be withdrawn at any time.
4. Hosting, recipients and international transfers
The website is delivered through Cloudflare Pages and Cloudflare’s network. Cloudflare may process limited connection and security data, including IP addresses and traffic metadata, to deliver, cache and protect the website.
Data may also be disclosed to email and IT providers, professional advisers or public authorities when required by law. Providers receive only data necessary for their tasks and act under appropriate agreements.
Where a provider processes data outside the European Economic Area, the transfer is based on a mechanism permitted by Chapter V GDPR, such as an adequacy decision or the European Commission’s standard contractual clauses, with supplementary safeguards where required.
5. Retention
Technical data is kept for the period required to deliver and secure the service, according to the configuration and retention rules of the hosting and security provider.
Correspondence and test enquiries are kept until the matter is closed and afterwards only for the period necessary to document the communication, meet legal duties or until relevant claims expire. Data processed solely on consent is kept until consent is withdrawn or the stated purpose ends.
6. Your rights
Subject to the conditions in GDPR, you may request access, rectification, erasure, restriction, portability, object to processing based on legitimate interests and withdraw consent without affecting earlier lawful processing. You may also lodge a complaint with the President of the Polish Personal Data Protection Office (UODO). Requests can be sent to [email protected].
7. Cookies, analytics and automated decisions
CraftedBills currently does not use advertising cookies, marketing trackers or client-side analytics tags on craftedbills.com. Strictly necessary security mechanisms may be applied by the infrastructure provider when required to protect the service.
The website does not make automated decisions about visitors and does not profile them. Local matching suggestions in the app support the user’s review and are not decisions made by Crafted Solutions about an individual.
8. Security, contact and changes
We use measures proportionate to the scope and risk of processing. Please do not send real accounting documents, bank statements, credentials or special-category data by ordinary email unless a secure support method has been agreed. Questions and privacy requests should be sent to [email protected]. Material updates will be published on this page with a new effective date.