Legal
Privacy policy.
What we collect, why we collect it, who else sees it, how long we hold it, and what you can make us do about it.
This page is placeholder text written for a design mockup. It has not been reviewed by a lawyer and must be replaced by counsel before publication.
Who is responsible for your data.
Dicopay AB, Göteborg, Sweden, company registration number 559108-7787, is the controller of the personal data described on this page. The registered address is [to confirm]. Our data protection contact is [to confirm]. If a data protection officer has been appointed, the name and contact details are [to confirm].
This policy covers the Dicopay app, this website, and the invoices and reminders we send on your behalf. Cookies and similar technologies are handled separately in the cookie policy.
What we collect.
Account and identity data
Your name, email address, phone number, login credentials, and the outcome of the identity check we run when the account opens. In Sweden that check uses BankID, and we record that it passed along with the identifiers it returns.
Business data
The business name, registration number, address, tax and VAT details, bank account details, and the people who own or control the business. We collect owner information because anti-money-laundering law requires us to know who is behind an account.
Invoice data
Line items, amounts, tax, dates, payment terms, attachments, contracts, e-signatures, time reports, reminder history, and payment status.
Your customer's contact data
The name, email address, phone number, and billing address of the business or person you invoice. You give us this so we can deliver the invoice and chase it. Where your customer is an individual rather than a company, that is their personal data, and this policy applies to it.
Device and usage data
IP address, device type, operating system, app version, language setting, crash reports, and how you move through the app. This is how we find bugs and stop abuse.
Messages you send us
Emails, chat messages, support tickets, and anything attached to them.
Why we use it, and the legal basis.
GDPR requires a legal basis for every use of personal data. These are ours.
- Running the service. We open your account, send your invoices, chase payment, and export to the accounting software you connect. The basis is performance of our contract with you.
- Checking what an invoice is worth, and passing on an application. When you ask to see an offer, we send a funding partner what it needs to price the invoice. The basis is performance of our contract with you, acting on your request.
- Verifying identity and preventing fraud and money laundering. We run the checks the law requires of us, and the checks that keep bad accounts out. The basis is a legal obligation, together with our legitimate interest in a service that is not abused.
- Keeping accounting records. We record the transactions we have been part of. The basis is a legal obligation under Swedish accounting law.
- Supporting you. We read your messages and answer them. The basis is performance of our contract with you, together with our legitimate interest in answering questions properly.
- Improving the product and keeping it secure. We look at how the product is used and where it fails. The basis is our legitimate interest in a product that works.
- Sending marketing, and setting non-essential cookies. We send you email and set optional cookies. The basis is your consent, which you can withdraw at any time.
Where we rely on a legitimate interest, we weigh that interest against your rights before we act on it, and you can object. Your rights are listed further down this page.
Decisions about financing.
Dicopay is not a lender and does not make the credit decision. The funding partner decides whether to make an offer, what it costs, and on what terms, and it does that under its own privacy notice as a controller in its own right. If a partner uses automated processing to reach that decision, you can ask for a human to look at it, put your side of the case, and contest the outcome. Ask us and we will tell you which partner handled your application and how to reach them.
Who we share it with.
- Funding partners. When you ask to see an offer or apply for one, we pass on the invoice, the business details, and the customer details the partner needs to price it. Partners are independent regulated lending partners and are controllers of what we send them. We do not name our partners on this site, and we will tell you who the partner is before you accept an offer.
- Identity, sanctions, and fraud providers. The checks the law requires when an account opens, and the checks that keep fraudulent invoices out afterward.
- Accounting software you connect. Exports go only where you point them. In Sweden that is Visma, Bokio, Hogia, or SpeedLedger.
- Service providers working for us. Hosting, email and text message delivery, error monitoring, analytics, and support tools. They act on our written instructions and cannot use your data for their own purposes.
- Authorities, courts, and professional advisers. Where the law requires it, or where we need to establish, exercise, or defend a legal claim.
- A buyer. If the business is sold or merged, data moves with it, and you will be told before it does.
We do not sell your personal data, and we do not sell your customers' personal data.
Text messages and mobile information.
If you agree to receive text messages from us, we use your mobile number to send them and we keep a record of the consent. Mobile information is not shared with third parties or affiliates for marketing or promotional purposes. The sharing described in the section above is limited to running the service, meeting a legal obligation, or acting on a request you made. You can stop text messages at any time by replying STOP. See the SMS terms and the SMS consent page.
How long we keep it.
We keep personal data for as long as we need it for the purpose we collected it, and then we delete it or make it anonymous.
- We keep account and invoice records while the account is open, and then for the period Swedish accounting law requires, which is [to confirm].
- We keep identity and anti-money-laundering records for the period anti-money-laundering law requires, which is [to confirm].
- We keep support messages for [to confirm].
- We keep device and analytics data for [to confirm].
- We keep marketing consents until you withdraw them, and then for [to confirm] as proof of what was agreed.
The account deletion page explains what survives a deletion request and why.
Where your data is held.
Our systems are hosted in the European Economic Area. Some providers we work with process data outside it. When that happens, we rely on the transfer mechanisms GDPR allows, usually the European Commission's standard contractual clauses, with additional technical measures where they are needed. Write to us and we will send you the safeguard that covers a specific transfer. The current list of providers and countries is [to confirm].
How we protect it.
Data is encrypted in transit. Access inside Dicopay is limited to the people whose job needs it and is logged. We verify who you are before we discuss an account. No system is perfect. If a breach is likely to put your rights at risk, we tell you and we tell the regulator within the time the law allows.
Your rights.
GDPR gives you all of the following rights.
- You can be told how your data is used, which is what this page is for.
- You can get access to the personal data we hold about you, and a copy of it.
- You can have inaccurate data corrected and incomplete data completed.
- You can have your data erased, a right sometimes called the right to be forgotten, where we have no remaining reason to keep it.
- You can restrict how we use your data while a dispute about its accuracy, or about our basis for holding it, is open.
- You can receive the data you gave us in a portable, machine-readable format, and have it sent to another provider where that is technically possible.
- You can object to processing that we base on a legitimate interest, and you can object to direct marketing at any time.
- You can withdraw consent at any time where consent is the basis we rely on, and that withdrawal does not affect anything we did before it.
- You can insist that a decision with a legal effect on you, or a similarly significant effect, is not taken solely by automated processing, including profiling.
- You can complain to a data protection supervisory authority.
To use any of these, write to [to confirm]. We answer within one month and will tell you if we need longer and why. We may ask you to confirm who you are first, because handing your data to the wrong person is the outcome we are guarding against.
In Sweden the supervisory authority is Integritetsskyddsmyndigheten (IMY). You can also complain to the authority in the country where you live or work.
Children.
Dicopay is a service for businesses and is not meant for children. We do not knowingly collect data from a child. If you think a child has given us data, write to [to confirm] and we will delete it.
Changes to this policy.
We update this policy as the product, our providers, and the law change. Where a change matters to you, we will tell you before it takes effect. The date at the bottom of this page tells you which version you are reading.
How to reach us.
Dicopay AB, Göteborg, Sweden. Company registration number 559108-7787. Privacy questions go to [to confirm], or through contact.
Last updated: [to confirm]