Skip to content

Privacy policy

Last updated: 28 September 2026
On this page

1. Introduction

This Privacy Policy explains how NumWise ("we", "our", "us", or the "Service") collects, uses, discloses, and safeguards your information when you use our accounting software service at numwise.eu.

The NumWise service is operated by BuildFlow Angelika Kotarba, a sole proprietorship registered in Poland (NIP: 6711821792, REGON: 364919712, registered address: ul. 1 Maja 13/1, 78-100 Kołobrzeg, Poland), which acts as the data controller for the purposes of the General Data Protection Regulation (GDPR).

We comply with the GDPR and applicable EU data protection laws. By using our Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you register for NumWise, we collect:

  • Your name and email address
  • Business name and VAT registration number (if applicable)
  • Business address and contact details
  • Password credentials managed and cryptographically hashed by our authentication provider
  • If you sign in with Google: the name, email address and profile picture your Google account shares with us. We never receive your Google password

2.2 Business Data

To provide our accounting services, we collect and store:

  • Customer and supplier information (names, addresses, contact details)
  • Invoices, expenses, and financial transactions
  • Bank transaction data (when you import a bank statement)
  • Receipt images and documents you upload
  • Supplier invoices and receipts emailed to your workspace's inbox address (see 2.5)

2.3 Gmail Integration

If you choose to connect your Gmail account, we ask Google for two permissions: gmail.send, to send email from your address, and your email address, to show which account is connected. NumWise uses them only to:

  • Send the invoices and quotes you choose to send to your customers
  • Send the payment reminders and repeat invoices you have switched on, on the schedule you set

Important: the permission only allows sending. NumWise cannot read, search, change or delete the emails in your mailbox. We never receive your Google password: we keep the tokens Google issues, encrypted. You can disconnect Gmail at any time in Settings, Email sending, or remove NumWise's access in your Google Account.

Google API Services User Data Policy. NumWise's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data or use it for advertising, and nobody at NumWise reads it unless you ask us to, it is needed for security, or the law requires it. We do not use data obtained through Google Workspace APIs (including Gmail) to develop, improve or train generalised AI or machine-learning models.

2.4 Usage Data

We process limited technical data such as IP address, browser details, request timestamps, and application errors to secure and operate the Service. With your consent, analytics may also record page views and usage events so we can improve the Service.

2.5 Invoices Sent to Your Inbox Address

Each workspace has its own address at in.numwise.eu for supplier invoices and receipts. When an email arrives there, we keep the sender's address, the subject, the date, the email's technical identifier and the attached PDF, JPG, PNG or WebP files; we do not keep the text of the email. Files are accepted only from the email addresses of team members who can add expenses and from senders your workspace allows. Accepted files are sent to Anthropic to be read while your workspace's document reading allowance lasts, and wait in your workspace until someone records them as an expense or discards them. From any other sender we keep only the sender's address, the subject, the date and the identifier, so you can see what was not accepted, and none of its files.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our accounting services
  • Process your transactions and send invoices on your behalf
  • Generate financial reports and draft VAT calculations for your review
  • Communicate with you about your account and our services
  • Provide customer support
  • Comply with legal obligations (e.g., Irish tax record-keeping requirements)
  • Detect and prevent fraud or abuse

4. Data Retention and Deletion

4.1 While your account exists

We keep your account and the data in your workspaces while your account exists, so that we can provide the Service. When a trial or a plan ends, the workspace becomes read-only: you can still view and export your data and contact support. Ending a plan does not by itself delete the workspace.

Every 6 months we review whether the data of inactive accounts still needs to be kept, following the review described in our procedures, and we contact the account owner. We delete an inactive account only at its owner's request. Nothing is deleted automatically, and the end of a trial or a plan is not by itself a reason to delete.

Irish law requires businesses to keep their financial records, generally for at least 6 years. That duty is yours as the business. NumWise lets you keep and export your records while your account exists, but it is not an archive service: after your account is deleted we keep only what is listed in 4.3. Before you ask for deletion, export your records in Settings, Organisation, "Export all data (Excel)", and download the receipt files you uploaded from their records.

4.2 Deleting your account

You can ask us to delete your account in two ways:

  • in NumWise, in Settings, Profile, "Delete account"; or
  • by email to support@numwise.eu from the email address of your account. We then ask you to confirm the request from that address.

We answer without undue delay and at the latest within one calendar month of receiving your request. Only where it is necessary because of the complexity or the number of requests, we may take up to two further months; if so, we tell you within the first month, with the reasons. If we do not act on your request, or on part of it, we tell you without delay, and at the latest within one month, why, and that you can complain to a supervisory authority (4.5) and seek a judicial remedy.

Your request covers every organization you belong to:

  • You are its only member: the organization is deleted with all its records and files.
  • You are its last owner and other people use it: it is not deleted without your written confirmation. We ask you to either transfer ownership to a member who accepts it, or confirm in writing that the organization is to be deleted for everyone; its members are then told at least 14 days before the deletion so they can export. If you do not choose, the organization stays as it is and we delete everything else we can.
  • You are a member, not the last owner: your membership is removed. The records you created stay with the organization, because they are part of its books.

API keys you created are deleted, so they stop working: those in each organization your request removes you from, and, when your account is deleted, those in organizations you left earlier. An integration that uses one of them needs a new key, created by an owner or admin of the organization. The organization's records stay.

Your sign-in account and profile are deleted last, once you no longer belong to any organization. Public invoice and quote links sent from a deleted organization stop working. Deleted means removed from our systems, not hidden; we do not restore deleted data.

If a deleted organization has a paid plan, we cancel its subscription at once, so no further payments are taken, and delete its customer record at our payment provider, Stripe. The rest of the period already paid for is lost and is not refunded, except where the law requires a refund (Terms of Service, section 4.4). This never stops us from accepting your request: you do not need to cancel first or wait for the end of the period.

4.3 What we keep after deletion

  • Our billing records of your subscription (the invoices and payments for your NumWise plan), which Stripe keeps and which are part of the accounts of the seller of the plan, BuildFlow Angelika Kotarba: for 5 years from the end of the year in which the related tax fell due, as Polish tax law requires (Ordynacja podatkowa, art. 70 and 86). Stripe also keeps its own records, as an independent controller.
  • Technical copies of Stripe's event messages. When Stripe tells us about a payment or a subscription, we store a technical copy of its message so that we process each message only once. When the copy is stored, it is reduced to identifiers, the type of the message, its processing status and dates and, if processing failed, a short technical error message; the names, email addresses and postal addresses in Stripe's message are not kept. A copy is deleted 90 days after we received it once it has been processed, or 180 days after we received it if it was never processed. When an organization is deleted, the copies that concern its customer record at Stripe are deleted with it; a copy that arrives later is stored in the same reduced form and deleted on the same schedule. These copies are not billing documents: the invoices and payments for your plan are kept by Stripe and in BuildFlow's accounting records, as described in the first point.
  • Backups. An encrypted copy of all stored files is made every day; each copy is kept for 30 days and then deleted automatically. It is encrypted with a key that only we hold and is stored with GitHub. Our database provider, Supabase, keeps a daily backup of the database for 7 days, in the EU (Stockholm). Data you deleted stays in these backups until they expire. If we ever restore a backup, we delete again everything that was deleted after it was made, using the register in 4.4.
  • Error reports (Sentry), which can contain your user id and email address: kept for 30 days, in the United States (see section 5).
  • Analytics, only if you consented: Google Analytics event data for 2 months and user data for 14 months (the 14 months restart when the same browser visits again); Vercel Web Analytics data for 1 month.
  • Emails you already sent to your customers through NumWise are in their mailboxes and outside our control.
  • Our correspondence with you about the request (your request, your confirmation and our answers): deleted together with the register entry, 24 months after the request is closed. It passes through ImprovMX, which forwards support@numwise.eu, and is stored in the Google (Gmail) mailbox that address forwards to.
  • The deletion register entry described in 4.4.

4.4 Deletion register

When we handle a deletion request, we keep a record of it: the deletion register. It is personal data, and we treat it as such.

  • Why we keep it and our legal basis: we keep the information necessary to handle your request, demonstrate our response and prevent deleted data from being brought back into use when a backup is restored. This processing is necessary to comply with our obligations under Articles 5(2), 12, 17 and 24 GDPR, on the basis of Article 6(1)(c) GDPR. We also retain a limited record to answer later questions or complaints and establish, exercise or defend legal claims, based on our legitimate interests under Article 6(1)(f) GDPR. You may object to processing based on legitimate interests by contacting us (section 8). We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
  • What it contains: a reference number; a keyed hash of your email address (not the address itself); how and when the request was received; the deadlines; the status; the type and date of each formal message we sent you (not their text); the actions we carried out (their type and date, and the ids of the organizations, users and provider records they concerned); the owner confirmations for a shared organization (dates and the email's technical identifier); our assessment of any part we did not act on; and the ids and roles of the organizations you belonged to. No names, no email address and no content of your data. Your user id stays in it only while your sign-in account still exists.
  • The keyed hash: made with a secret key that is never stored in the database. To match a later question to a request, we compute the hash of the asker's address with the same key.
  • Who can see it: only NumWise's operator, through the server; the app gives no access to it.
  • How long: 24 months after the request is closed, then a scheduled job deletes it. This is our retention period for the limited record of the request, not a fixed period prescribed by the GDPR. It allows us to address follow-up questions and complaints and exceeds the lifetime of our backups. We keep open requests while they are being handled and review any objection individually.
  • Encrypted copy outside the database: because a database restore would also roll back the register, we keep an encrypted copy of the same entries outside our database, with Cloudflare (R2 storage, EU jurisdiction). It is used only to re-apply deletions after a restore, and its entries are deleted when their register entry is deleted.

4.5 If you are not satisfied

You can complain to a supervisory authority: the Polish President of the Personal Data Protection Office (UODO), which is the lead authority because we are established in Poland, or the authority where you live, which in Ireland is the Data Protection Commission. You can also seek a judicial remedy before the courts.

The steps to ask for deletion are also described on numwise.eu/delete-account.

5. Third-Party Services

We use the following third-party services to operate NumWise:

  • Supabase - Database and authentication services (data stored in EU region)
  • Stripe - Payment processing for subscriptions. Stripe handles all payment card data; we do not store your card details.
  • Google - Sign-in with Google (when you choose it) and Gmail integration for sending invoices (when you choose to connect your Gmail account). If you connect another mailbox by SMTP instead, your own email provider sends those messages. Google also hosts the mailbox that receives the messages sent to support@numwise.eu.
  • ImprovMX - Sending NumWise's own emails: sign-in emails (address confirmation and password reset), invitations, trial and account notices, support replies and, only if you opt in, the getting-started lessons; forwarding messages you send to numwise.eu addresses to the people who answer them; and receiving the emails sent to your workspace's inbox address (see 2.5)
  • Vercel - Web application hosting and delivery, and page speed measurement (Speed Insights: load times per page, without cookies and without the query part of the address)
  • GitHub - Runs our daily file backup and stores the encrypted copies for 30 days. The copies are encrypted with a key only we hold, so GitHub cannot read them. GitHub may store them in the United States; for data leaving the EU it relies on the EU-U.S. Data Privacy Framework and the European Commission's standard contractual clauses.
  • Cloudflare - Stores an encrypted copy of our deletion register (R2 storage, EU jurisdiction), used only to re-apply deletions after a restore from a backup (see section 4.4).
  • Anthropic - AI-assisted extraction for receipt, invoice and statement content you submit to those features, including invoices sent to your workspace's inbox address
  • Sentry - Application error monitoring. Error reports can contain your user id and email address; they are stored in the United States and kept for 30 days. Session Replay is disabled and we do not intentionally send financial document contents as error metadata. Sentry (Functional Software, Inc.) is certified under the EU-U.S. Data Privacy Framework, which covers this transfer.
  • Google Analytics and Vercel Web Analytics - Optional website analytics, activated only after you consent

These providers act under their own terms and, where applicable, data-processing agreements. International transfers are protected using applicable transfer mechanisms such as Standard Contractual Clauses.

6. Cookies and Tracking

We use cookies and similar technologies to:

  • Keep you signed in to your account
  • Remember your preferences
  • Understand how you use our Service, only when analytics consent is granted

You can accept or reject optional analytics in the consent banner. Essential authentication and security storage remains available because it is required to provide the Service.

7. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, secure authentication, and regular security assessments. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

8. Your Rights Under GDPR

As a data subject in the EU, you have the following rights:

  • Right of Access - Request a copy of your personal data
  • Right to Rectification - Request correction of inaccurate data
  • Right to Erasure - Request deletion of your data (subject to legal retention requirements)
  • Right to Restrict Processing - Request limitation of how we use your data
  • Right to Data Portability - Receive your data in a machine-readable format
  • Right to Object - Object to processing based on legitimate interests
  • Right to Withdraw Consent - Withdraw consent at any time for processing based on consent

To exercise any of these rights, please contact us at hello@numwise.eu.

9. International Data Transfers

Your data is primarily stored and processed within the European Union. Where we use service providers outside the EU (such as for certain infrastructure services), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

10. Children's Privacy

NumWise is designed for business use and is not intended for children under 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we will provide notice via email or through the Service.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: hello@numwise.eu

Data Controller (postal address):
BuildFlow Angelika Kotarba
ul. 1 Maja 13/1
78-100 Kołobrzeg, Poland
NIP: 6711821792 · REGON: 364919712

You also have the right to lodge a complaint with your local EU data protection authority (for EU residents) or with the Polish President of the Personal Data Protection Office (UODO), which is the supervisory authority for the data controller.