1. What data we process
Account data (contact name, email, phone, encrypted password, role in the firm); company data (business name, address, company number, PIB, activity code, bank account, premises and tills); subscription and billing data; technical data and logs (IP address, access time, device and browser, the activity log of who did what, technical errors); support correspondence; and proof of consent (accepted version, date, time and IP).
2. Basis and purpose
Processing rests on contract performance (opening and running the account, providing the Service, support, billing), legal obligation (issuing and keeping receipts and the records required by tax and accounting rules), legitimate interest (system security, abuse prevention, the activity log, basic visit statistics, and legal claims), and consent, which is asked only where expressly needed and can be withdrawn at any time.
3. How long we keep data
Account data and User Content are kept while the contract lasts and at least 30 days afterwards for download, then deleted or anonymized. Receipts and accounting records are kept for the statutory periods. Technical and activity logs are kept up to 12 months, and proof of consent for the contract term and the limitation period after it.
4. To whom we share data
Data is not sold or handed to third parties for their own purposes. Processors acting on Go Simple's instructions under contract are Vercel Inc. (application hosting, European Frankfurt region), Neon Inc. (database), Cloudflare, Inc. (DNS and traffic protection) and Resend (email). Card payment data is handled only by the authorized payment operator and is never seen or stored by Go Simple; data goes to authorities only when the law requires it.
5. Security
Traffic is protected by HTTPS and passwords are stored only in encrypted form. Access is limited by role and by firm, so each firm sees only its own data. Staff have no insight into a firm's business data; only technical data is processed for support and monitoring, and access to business content happens only when the firm expressly requests and enables it. High-risk breaches are reported to affected persons and to the Commissioner within statutory deadlines.
6. Cookies and visit statistics
Necessary cookies are used for login and session security, without which the Service cannot run. Public-page visits are measured with Go Simple's own measurement, without profiling, and, only with your consent given in the banner, with Google Analytics. Details are in the Cookie Policy.
7. Your rights
You have the rights of access, rectification of inaccurate data, erasure, restriction of processing, portability, and objection to processing based on legitimate interest. Send requests to podrska@tezgafiskal.com; we reply within 30 days, extendable with notice for a complex request. You may also complain to the Commissioner for Information of Public Importance and Personal Data Protection, or go to court.
8. Data of our users' customers
Firms that use Tezga enter data about their own customers and staff; for that data the firm is the controller and Go Simple is only a processor acting on its instructions. Some processes need more data, for example a refund, where the regulation requires identifying the customer. If you are a firm's customer, address your rights to that firm; this processing is governed by the Data Processing Agreement.
9. Tezga eKasa mobile app
The Android app is part of the same Service, so everything above applies to it too. Issued receipts (the journal), the item catalogue, customers, cashiers and device settings stay on the device until sent to the Service; only issued receipts and, when connected, company-data requests are sent, over HTTPS. The app asks only for internet access (no location, contacts, camera, microphone or files), has no ads or tracking and no advertising identifier, and deleting it removes the on-device data.
10. Children
The Service is intended only for businesses and is not aimed at minors. Go Simple does not knowingly collect data about minors.
11. Changes to the Policy
The Policy may change, and each version carries a version mark and effective date. Changes that materially alter how data is processed are announced by email or in the Service at least 15 days before they take effect.
