GDPR and personal data
The roles of the firm and of NovaFisko under the GDPR, the personal data processed, the rights of data subjects and the tools of the software to respond to them.
Accounting records contain personal data: contact details of customers and suppliers who are natural persons, bank account numbers, identity of team members. This page describes how NovaFisko fits into the General Data Protection Regulation (GDPR) and what the software gives you to fulfil your own obligations.
This page describes how the software works. It replaces neither your record of processing activities, nor the data processing agreement concluded with NovaFisko, nor legal advice. The points marked "to be confirmed" depend on contractual and organisational commitments that cannot be verified in the software itself.
Who is responsible for what
| Party | Role within the meaning of the GDPR | For which data |
|---|---|---|
| The client company | Controller | Its own accounting: its customers, its suppliers, its staff. |
| The accounting firm | Controller for its engagement, or processor of its client depending on the nature of the engagement | The company files it keeps. The qualification depends on your engagement letter. |
| NovaFisko | Processor | The data that the firm and its clients record in the platform. |
| NovaFisko | Controller | User accounts, billing of the subscription, audience measurement of the public website. |
The personal data present in a company file
| Category | Examples | Where |
|---|---|---|
| Identity and contact details of third parties | Name, address, email, phone number, VAT number of a self-employed person | Third parties tab |
| Bank data | IBAN, BIC, name of the counterparty, communication of a transfer | Third parties and Bank tabs |
| Supporting documents | Invoices and credit notes, which may contain any data printed on them | Documents tab |
| Tax forms | Beneficiaries of 281.50 forms | Third-party sheet |
| Team members and users | Name, email, role, language, log of actions, IP address, name of the device | Team, History, audit trail |
NovaFisko is not intended to receive special categories of data (health, opinions, etc.). Avoid entering any in the free notes fields.
The technical processors called by the platform
Some functions call on external services. They only receive the data needed for the requested operation.
| Service | Function | Data transmitted |
|---|---|---|
| B2Brouter | Peppol registration and directory | Identity, enterprise number, address and contact of the registered company file |
| CompanySearch | Company detection | The name or number searched for |
| VIES (European Commission) | Validation of a VAT number | The VAT number checked |
| Document analysis engine | Reading of the invoices uploaded to the importer | The content of the analysed document |
| Novadesko | Synchronisation of linked company files | Reading of the company's data; sending of only the documents created by the accountant |
The document importer sends the content of the supporting documents to an artificial intelligence analysis engine. If a document contains data that you do not wish to submit to this processing, enter it manually. The contractual list of sub-processors and their location are to be confirmed in your data processing agreement.
Responding to the rights of data subjects
Right of access and portability
- For a third party: the Third-party history export, filtered on the person, gives all the movements that concern them. The Third-party file export gives their sheet.
- For a whole company file: the complete accounting file provides the data in an open format (CSV) together with the PDFs.
Right to rectification
Correct the third-party sheet. The change is recorded in the history with the old and the new value.
Right to erasure
The right to erasure comes up against the legal obligation to retain accounting books and supporting documents.
- The third party has no entries: delete it, then delete it permanently from the trash. As long as it is in the trash, its data still exists.
- The third party is linked to entries: the deletion is refused by the software. The data must be retained for the legal period. You can reply to the person that erasure is limited by a legal obligation (Article 17(3) of the GDPR).
Right to object to emails
Each user can set their notification preferences by email category. Messages that are essential to the security of the account are always sent.
Minimisation and partitioning
- Access per company file: a team member only sees the company files assigned to them. Only the administrators and managers of the firm see all the company files of the firm. A company file to which a user has no access is presented to them as non-existent.
- Roles: encoder, reviewer, lead, read-only auditor with a possible expiry date.
- Read-only towards Novadesko: NovaFisko reads the company's data without changing it.
- Temporary links: the preview of a document or an export goes through a signed, time-limited link.
Traceability
The GDPR requires being able to demonstrate who accessed the data and changed it. NovaFisko records:
- each data change, with its author, its date, its device and the values before and after;
- each successful or failed sign-in;
- each export generated, with its fingerprint.
These logs themselves contain personal data relating to your team members. Inform them of their existence.
The public website
The novafisko.com website measures its audience without any third-party tool. IP addresses in clear text are truncated after 30 days and visit data is deleted after 13 months. The details are given in the privacy policy of the website.
Data breach
If you notice abnormal access to a company file, for example an unknown sign-in in the activity log:
- immediately change the password of the account concerned;
- remove the access of the team member from Team if necessary;
- export the activity log of the period;
- contact NovaFisko support;
- assess with your data protection officer whether a notification to the Data Protection Authority is required within 72 hours.