Skip to content
Documentation
English
Open the app

GDPR and personal data

The roles of the firm and of NovaFisko under the GDPR, the personal data processed, the rights of data subjects and the tools of the software to respond to them.

Accounting records contain personal data: contact details of customers and suppliers who are natural persons, bank account numbers, identity of team members. This page describes how NovaFisko fits into the General Data Protection Regulation (GDPR) and what the software gives you to fulfil your own obligations.

Note

This page describes how the software works. It replaces neither your record of processing activities, nor the data processing agreement concluded with NovaFisko, nor legal advice. The points marked "to be confirmed" depend on contractual and organisational commitments that cannot be verified in the software itself.

Who is responsible for what

Party Role within the meaning of the GDPR For which data
The client company Controller Its own accounting: its customers, its suppliers, its staff.
The accounting firm Controller for its engagement, or processor of its client depending on the nature of the engagement The company files it keeps. The qualification depends on your engagement letter.
NovaFisko Processor The data that the firm and its clients record in the platform.
NovaFisko Controller User accounts, billing of the subscription, audience measurement of the public website.

The personal data present in a company file

Category Examples Where
Identity and contact details of third parties Name, address, email, phone number, VAT number of a self-employed person Third parties tab
Bank data IBAN, BIC, name of the counterparty, communication of a transfer Third parties and Bank tabs
Supporting documents Invoices and credit notes, which may contain any data printed on them Documents tab
Tax forms Beneficiaries of 281.50 forms Third-party sheet
Team members and users Name, email, role, language, log of actions, IP address, name of the device Team, History, audit trail

NovaFisko is not intended to receive special categories of data (health, opinions, etc.). Avoid entering any in the free notes fields.

The technical processors called by the platform

Some functions call on external services. They only receive the data needed for the requested operation.

Service Function Data transmitted
B2Brouter Peppol registration and directory Identity, enterprise number, address and contact of the registered company file
CompanySearch Company detection The name or number searched for
VIES (European Commission) Validation of a VAT number The VAT number checked
Document analysis engine Reading of the invoices uploaded to the importer The content of the analysed document
Novadesko Synchronisation of linked company files Reading of the company's data; sending of only the documents created by the accountant
Warning

The document importer sends the content of the supporting documents to an artificial intelligence analysis engine. If a document contains data that you do not wish to submit to this processing, enter it manually. The contractual list of sub-processors and their location are to be confirmed in your data processing agreement.

Responding to the rights of data subjects

Right of access and portability

  • For a third party: the Third-party history export, filtered on the person, gives all the movements that concern them. The Third-party file export gives their sheet.
  • For a whole company file: the complete accounting file provides the data in an open format (CSV) together with the PDFs.

Right to rectification

Correct the third-party sheet. The change is recorded in the history with the old and the new value.

Right to erasure

The right to erasure comes up against the legal obligation to retain accounting books and supporting documents.

  1. The third party has no entries: delete it, then delete it permanently from the trash. As long as it is in the trash, its data still exists.
  2. The third party is linked to entries: the deletion is refused by the software. The data must be retained for the legal period. You can reply to the person that erasure is limited by a legal obligation (Article 17(3) of the GDPR).

Right to object to emails

Each user can set their notification preferences by email category. Messages that are essential to the security of the account are always sent.

Minimisation and partitioning

  • Access per company file: a team member only sees the company files assigned to them. Only the administrators and managers of the firm see all the company files of the firm. A company file to which a user has no access is presented to them as non-existent.
  • Roles: encoder, reviewer, lead, read-only auditor with a possible expiry date.
  • Read-only towards Novadesko: NovaFisko reads the company's data without changing it.
  • Temporary links: the preview of a document or an export goes through a signed, time-limited link.

Traceability

The GDPR requires being able to demonstrate who accessed the data and changed it. NovaFisko records:

  • each data change, with its author, its date, its device and the values before and after;
  • each successful or failed sign-in;
  • each export generated, with its fingerprint.

These logs themselves contain personal data relating to your team members. Inform them of their existence.

The public website

The novafisko.com website measures its audience without any third-party tool. IP addresses in clear text are truncated after 30 days and visit data is deleted after 13 months. The details are given in the privacy policy of the website.

Data breach

If you notice abnormal access to a company file, for example an unknown sign-in in the activity log:

  1. immediately change the password of the account concerned;
  2. remove the access of the team member from Team if necessary;
  3. export the activity log of the period;
  4. contact NovaFisko support;
  5. assess with your data protection officer whether a notification to the Data Protection Authority is required within 72 hours.

See also