Skip to content

Privacy policy

Last updated 26 September 2026

Who processes your data

KontoLink (kontolink.si) is operated by RamaPrint SH.P.K.. RamaPrint SH.P.K. is the controller for account data — the details you give us to have an account and be billed.

For the documents you upload, RamaPrint SH.P.K. is a processor: those files stay under the control of the company that uploaded them, and we act only on that company's instructions. We do not routinely access, review, mine or use document contents for our own purposes, and the application gives KontoLink administrators no way to open or download them. Limited infrastructure-level access by authorised staff may be technically possible where it is necessary for security, maintenance, incident response or a legal obligation.

Controller
RamaPrint SH.P.K.
Address
UÇK, p.n, 21000 Rahovec, Kosovo
Data protection contact
info@ramaprint.com

What we collect

  • Account data: name, e-mail address, phone, company or office name, tax and registration numbers, address, and your chosen language.
  • Documents: the files you upload and any note attached to them.
  • Technical data: browser user agent, sign-in times and an audit record of significant actions. The audit record does not keep an IP address.
  • Billing data: handled by Paddle, which sells the subscription as merchant of record. Card details never reach KontoLink's servers.
  • Visit statistics: the page visited, the referring website, and whether the device is a phone or a computer.

How we count visitors

We keep our own basic visit statistics instead of using an external analytics service, so no data about you is sent to a third party. No IP address is stored. To count how many different people visited on a given day, we store a one-way hash of the IP address and browser combined with a secret value that changes every day. It is not kept in a form intended to identify the original IP address, and the same visitor cannot be recognised from one day to the next. No tracking cookie is set.

Why we process it

To operate the service and perform the contract with you, to secure accounts and investigate abuse, to send transactional messages such as verification codes, and to meet accounting and tax obligations for payments received. Where the GDPR applies, we rely on performance of a contract to provide KontoLink, compliance with legal obligations for accounting and billing records, and our legitimate interests in securing the service, preventing abuse and keeping it running reliably.

Who can see your documents

Only the company that uploaded a document and the accounting office it is linked with. Documents are stored outside the public web root and every download passes an individual authorisation check. The application gives KontoLink administrators no way to open or download document contents — they see only that a document exists, with its name, size and status, for support, billing and abuse handling. Document contents are never used for KontoLink's own purposes.

Virus scanning

Every uploaded file is checked for malware on our own server, before anyone can open it. The file is never sent to an external scanning service. If malware is found, the file is moved out of reach and both the company and its accounting office are told what was found.

Where your data is

The application, the documents you upload and the backups are hosted on servers in the European Union, with hosting provided by Hetzner. RamaPrint SH.P.K. is established in Kosovo and operates KontoLink from there. Where processing involves an international transfer of personal data under the GDPR, the applicable requirements of Chapter V of the GDPR are followed. Personal data may also be processed by the service providers listed below, subject to the data-protection safeguards applicable to those providers.

Service providers and recipients

  • Hetzner — hosting. Servers in the European Union.
  • Paddle.com Market Ltd — merchant of record for subscriptions: card payments, VAT and the tax invoice issued in its own name.
  • Cloudflare — Turnstile, the check that keeps bots off the public forms. It sees the request, not the form contents.
  • Google (Firebase Cloud Messaging) — delivery of push notifications to the mobile app. It receives the device token and the notification text, which names the company and the file. It never receives the file.
  • The mail server at kontolink.si, for outgoing e-mail.

We use no advertising networks and no third-party analytics. Visit statistics are counted by us, on our own server, as described above.

How long we keep it

Documents are kept while the account is active. After an account is closed, personal data is kept only as long as needed to complete the closure, to work through the backup cycle it already sits in, to meet a legal obligation, or where retention rules relating to the accounting relationship apply. Documents already sent to an accounting office may remain available to that office on the same basis. Audit records are kept for security purposes. Invoicing records are kept for the statutory retention period.

Your rights

Under the GDPR you may request access to your personal data, correction, deletion, restriction of processing, portability, and you may object to processing. Write to the address above. You also have the right to lodge a complaint with the Slovenian Information Commissioner (Informacijski pooblaščenec).

To have your account and the data belonging to it deleted, there is a page for exactly that: Delete your account.

Cookies

KontoLink sets only the cookies needed to keep you signed in, to remember your chosen language, and to protect forms against cross-site request forgery. Your light or dark theme preference is stored locally in your browser, not in a cookie. Our visit statistics use no cookie at all. There is no advertising and no third-party tracking.

Questions? Write to support@kontolink.si