Privacy Policy for the Monitor KSeF Application

Version: 1.1
Effective date: 23.02.2026
Last updated: 25.02.2026
TL;DR: The application does not have its own servers for storing invoices. It connects directly to the KSeF API and displays data on your device. No ads, no trackers.

1. Introduction and scope

This policy describes the principles of data processing in the Monitor KSeF application for iOS.

The KSeF system and its infrastructure are operated by the Polish Ministry of Finance. With regard to data processing within KSeF, the Ministry of Finance acts as a separate data controller.

2. Information required under Art. 13 GDPR (summary)

  1. Data controller: mDesign Michal Lotocki (brand: KrzewiLabs).
  2. Purposes and legal bases: described in section 4.
  3. Recipients: described in section 8.
  4. Transfers outside the EEA: described in section 9.
  5. Retention period: described in section 7.
  6. Rights: section 11.
  7. Complaint to the supervisory authority: section 12.
  8. Obligation to provide data: section 6.
  9. Profiling: none (section 10).

3. Definitions

4. What data we process, for what purposes and on what legal basis

The Application has been designed following the "privacy by design" principle – as a rule, we do not store invoice content on the Controller's servers and strive to keep data on the user's device.

4.1 Categories of data

4.2 Purposes and legal bases

  1. Providing application functionality (connecting to KSeF, displaying data, export): Art. 6(1)(b) GDPR.
  2. Security (PIN, lockouts, connection integrity): Art. 6(1)(f) GDPR.
  3. Technical support (when the user provides data, e.g. logs): Art. 6(1)(b) and/or (f) GDPR.
  4. Biometrics (Face ID/Touch ID, optional): Art. 6(1)(a) GDPR – consent expressed by enabling the feature.
  5. Purchases (IAP/subscriptions): Art. 6(1)(b) GDPR; billing is handled by Apple.

5. Sources of data

6. Is providing data mandatory

Providing a NIP and KSeF token is a prerequisite for using the invoice retrieval and display functionality. Without this data, the application cannot authenticate the connection to KSeF.

Biometrics are optional. A PIN is required for using the PIN lock feature.

7. How long we retain data (retention)

8. Disclosure and data recipients

The Controller does not sell data and does not share invoice content for marketing purposes.

9. Transfers of data outside the EEA

The Controller does not transfer invoice content to its own servers outside the EEA. Apple may process purchase data outside the EEA in accordance with its own policies.

10. Profiling and automated decision-making

The Application does not engage in profiling or automated decision-making within the meaning of Art. 22 GDPR.

11. User rights

The User has the right of access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent (where consent is the legal basis).

12. Complaints to the supervisory authority

The User has the right to lodge a complaint with the President of the Polish Data Protection Authority (UODO).

13. Children's data

The Application is not directed at children.

14. In-App Purchases

The Application may offer subscriptions. Billing is handled by Apple (App Store / StoreKit). The Controller receives only the minimum information necessary to verify subscription status.

15. How we store data on the device (local architecture)

16. Network connections and external APIs

17. Data security

18. Changes to this policy

This policy may be amended. The current version will be published within the application or on the Controller's website together with the update date.

19. Contact

Data controller (GDPR): mDesign Michal Lotocki (brand: KrzewiLabs)

Address: Osiedlowa 5/9, 65-268 Zielona Gora

E-mail: kontakt@krzewilabs.pl

Website: krzewilabs.pl

Back to homepage