Security and privacy
Your data is yours. Here is where it lives and who sees it.
Short and without marketing: where the data lives, who can see it, how it is protected and what happens when you leave. The binding text is in the Privacy Policy, the Data Processing Agreement and the Terms of Use; here it is the same, in plain language.
- Frankfurt
- the app and the database, in the European Union
- HTTPS
- all traffic between you and Tezga
- 30 days
- at least, to download your data after the contract ends
- 48 hours
- at the latest, to notify you of a data breach
The Tezga team does not see
- your turnover
- your receipts
- your customers
- your products and prices
- your bank statements
- the content of your documents
For support we see only the technical status
- whether fiscalization is working
- the status of the links with the Tax Administration and SEF
- the number of documents by type
- the time of the last activity
- technical errors
- your subscription and payments to Go Simple
The only exception: when you explicitly ask for help and grant access yourself, for example by sharing your screen, to solve a specific problem. Such access is limited to that problem, lasts as long as the problem lasts and is recorded in the activity log.
Where the data lives
Tezga works through processors that handle data on our instructions and under a contract. We store data in European regions whenever that is available. We announce a new processor at least 30 days in advance, with your right to object.
| Processor | For what |
|---|---|
| Vercel Inc. | app hosting, European region Frankfurt |
| Neon Inc. | database |
| Cloudflare, Inc. | DNS and traffic protection |
| Resend | sending email |
- Vercel Inc.
- app hosting, European region Frankfurt
- Neon Inc.
- database
- Cloudflare, Inc.
- DNS and traffic protection
- Resend
- sending email
We do not sell your data and do not pass it to third parties for their own purposes. We provide it to the authorities only when the law requires us to.
How the data is protected
Traffic goes over HTTPS, passwords are stored only encrypted and even we cannot read them, and each company sees only its own data. The rest is on the list, with the plan it is available from.
Security and compliance, the full list- A fiscal record is never changed or deleted after it is issuedAll plans
- Your security element is stored encrypted and never shown backAll plans
- All integration secrets are stored encrypted in the databaseBiznis
- Several users per company, each with their own accountPosao
- Roles: administrator, manager and cashierBiznis
- An audit log of every administrative actionBiznis
- Access restriction by IP address or rangeBiznis
- A request-rate limit per company, protection against floodingBiznis
- Screen protection against over-the-shoulder viewingAll plans
- Password sign-in with reset by emailAll plans
Backups and how long each thing is kept
We make regular backups and check that data can be restored from them. A backup protects the system; it does not replace your archive, so download the exports Tezga offers you from time to time.
- Your account and the data you enter
- While the contract lasts, and after it ends at least 30 days for download. Then it is deleted or anonymised.
- Receipts and accounting records
- For the periods required by tax and accounting regulations.
- Technical logs and the activity log
- Up to 12 months, unless needed to investigate a security incident or for a legal claim.
- Proof of consent to the Terms
- While the contract lasts and within the limitation period for claims after it ends.
The Personal Data Protection Act: who is responsible for what
Data about your account
For account, contact and billing data, Go Simple is the controller. How we process it, on what basis and for how long, is set out in the Privacy Policy.
Data about your customers
For the data you enter about your customers and employees, you are the controller and we are the processor. The Data Processing Agreement is part of the Terms and needs no separate signature; we send a signed copy on request.
Your rights
Access, correction, erasure, restriction of processing, portability and objection. You send your request to podrska@tezgafiskal.com, and we reply within 30 days at the latest. You may also lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection, Bulevar kralja Aleksandra 15, 11120 Belgrade. If a data breach that may cause a high risk occurs, we will notify the affected individuals and the Commissioner within the statutory deadlines.
On the public pages we use only necessary cookies and our own visit measurement, with no third-party tools and no profiling.
Frequently asked questions
Where is Tezga's data stored?
The app and the database are in the European Union, in Frankfurt. The processors are Vercel Inc. (app hosting, European region Frankfurt), Neon Inc. (database), Cloudflare, Inc. (DNS and traffic protection) and Resend (sending email). We do not sell your data or pass it to third parties for their purposes.
Do Tezga employees see my turnover and receipts?
No. Go Simple and the people who work on the platform have no access to your turnover, receipts, customers, products, prices or bank statements. For support we see only the technical status: whether fiscalization works, the status of the links with the Tax Administration and SEF, the number of documents by type and technical errors. Access to content is possible only when you explicitly request it and grant access yourself, and it lasts as long as the problem lasts.
What happens to my data when I stop using Tezga?
The data stays available for download at least 30 days after the contract ends, in a format Tezga supports for export. After that it is deleted or anonymised, except for what must be kept longer by law.
Does Tezga ask for the PIN of my security element?
Never. You enter the security element yourself in Settings, it is stored encrypted and is never shown back. If anyone asks you for the PIN on Tezga's behalf, it is an attempt at fraud.
Who do I contact about my rights under the Personal Data Protection Act?
You send a request for access, correction, erasure, restriction of processing, portability or objection to podrska@tezgafiskal.com. We reply without delay and within 30 days at the latest. You may also lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection.
A question about your data? Write to us before you register.
We answer at podrska@tezgafiskal.com and on 060 0919 029, on working days. When you are ready, an account opens in two minutes.
