Privacy
Kvitta is run by Ple Consulting AB, org. no. 559262-1212, Viktoriavägen 20, 434 93 Vallda, referred to below as "we". You can reach us at hello@usekvitta.com.
We hold personal data in two different roles
The distinction matters, because different rules apply to each.
As controller, for this website and for the accounts of the people who sign in to Kvitta. We decide what to collect and why, and this policy governs it.
As processor, for the payment files and ledger extracts our customers put into Kvitta. Those may contain the names of people who paid our customer. We do not decide what is in them and we do not use them for our own purposes. The customer is the controller and the data processing agreement governs that relationship.
Cookies and similar technologies on this website
Fonts are served from this domain rather than a font CDN. Page views and button clicks are counted by our host, Vercel, without cookies or any identifier that persists between visits.
If you accept cookies, we load the Meta Pixel (Meta Platforms Ireland Limited) so we
can measure visits and advertising performance. That Pixel sets cookies and may process your IP address
and device identifiers. You can reject non-essential cookies; the Pixel then does not load. Your choice
is stored in local storage on this device as kvitta_cookie_consent.
Our host records standard server logs, including IP addresses, for delivery and security. Those are kept for a short period and are not used to build a profile of you.
When you request early access we collect the details you submit (name, email, company and optional notes) so we can reply and onboard you. That request is emailed to hello@usekvitta.com and may be recorded in our early-access waitlist.
What we collect when you use Kvitta
- Account details. Your name, email address and profile picture, passed to us by Microsoft when you sign in. We never see or store a password.
- Your organisation and companies. Names, membership and who may do what.
- What was done. An audit trail of the acts that matter: a file imported, a rule added, a journal taken, a batch marked posted. Each entry records who and when. This exists because a tool that produces accounting entries has to be able to answer an auditor.
- Uploaded files and match results. Handled under the processing agreement, not this policy.
- What you write to us. Email you send, and anything in it.
Why, and on what basis
- To provide the service under our contract with you (GDPR Art 6(1)(b)).
- To keep it secure and working, and to keep the audit trail, on legitimate interests (Art 6(1)(f)). Our interest is running a reliable service that can be audited; we think this is what a user of an accounting tool expects.
- To meet legal obligations such as bookkeeping (Art 6(1)(c)).
We do not sell personal data, we do not advertise, and we do not use your data or your customers' data to train any model.
Who else processes it
We use a small number of service providers, each listed with its purpose and location on the sub-processors page. We do not share personal data with anyone else unless the law requires it.
Where it is held
Kvitta runs on infrastructure in the European Union. Some components are hosted in the United States at the time of writing and are being moved to European regions; the sub-processors page states the current location of each, and we keep it accurate. Where data is transferred outside the EEA we rely on the European Commission's standard contractual clauses.
How long we keep it
- Account and organisation records: while the account is open, then 90 days.
- Audit trail: seven years, because it evidences accounting activity.
- Uploaded files and match results: as agreed in the processing agreement, and deleted on request.
- Email: 24 months.
Your rights
You may ask for a copy of your data, ask us to correct or delete it, ask us to restrict or stop a particular use, and ask for it in a portable format. Write to hello@usekvitta.com and we will answer within a month.
If you think we have handled your data badly, you can complain to the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy.se. We would rather you told us first.
Changes
If we change this policy in a way that affects you, we will say so by email before it takes effect rather than quietly changing the date at the top.