Last updated: 6 July 2026
Privacy Policy
This policy explains what personal data we process when you use ContaCerta, for what purposes, on what legal basis, and what your rights are under the General Data Protection Regulation (GDPR).
1. Data controller
The data controller is Miguel Dias Tech Labs Ltd, a company incorporated in Cyprus with tax identification number 60345642E, registered at Tulip Residences, Kopeghagis 4, Apartment 201, 3050 Limassol, Cyprus. For any question about personal data, contact [email protected].
2. Data we process
- Account data: name, email and password (stored encrypted), and organisation data (for example, company name and tax number).
- Documents: the invoices and documents you upload, photograph or send to your account's dedicated email address, and the data extracted from them (supplier, tax number, dates, amounts, line items).
- Subscription and payment data: plan, subscription status and billing history. Card data is handled directly by Stripe — it never touches our servers.
- Technical data: IP address, access and error logs, needed for security and for operating the service.
- Preferences: your chosen language (stored in a cookie — see the Cookie Policy).
Note: documents you upload may contain personal data of third parties (for example, names on invoices). For that data we act as a processor on your behalf; it is your responsibility to ensure you have a lawful basis to process it.
3. Purposes and legal bases
- Providing the service (account creation, document processing, data export, support) — performance of a contract.
- Billing and compliance with tax and accounting obligations — legal obligation.
- Security, fraud and abuse prevention, and service improvement — legitimate interest.
- Marketing communications (for example, waitlist or product news) — consent, which you can withdraw at any time.
4. AI document processing
Data extraction from your documents is performed by artificial intelligence models provided by Google (Gemini), exclusively for that purpose. Your documents are not used to train AI models — neither by us nor, under the applicable contract, by the model provider.
5. Processors and recipients
We use providers that process data on our behalf under data processing agreements:
- application hosting and database (infrastructure in the European Union);
- asynchronous task processing (Trigger.dev);
- email sending and receiving (Resend);
- payments and billing (Stripe);
- AI data extraction (Google).
If you connect an integration (for example, Moloni), the data you choose to export is sent to that service, which processes it as an independent controller under its own policies. We do not sell personal data to third parties.
6. International transfers
Some providers may process data outside the European Economic Area (for example, in the United States). In those cases, transfers rely on European Commission adequacy decisions (such as the EU-US Data Privacy Framework) or on standard contractual clauses.
7. Retention
We keep your data for as long as your account exists. When you delete your account (or individual documents), data is removed from active systems within a reasonable period and may persist in backups for a limited time before being permanently deleted.
Billing data is retained for the periods required by applicable tax legislation.
8. Your rights
You have the right to access your data, rectify it, erase it, restrict or object to its processing, and to receive it in a structured format (portability). Where processing is based on consent, you can withdraw it at any time.
To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with a supervisory authority — the lead authority is the Commissioner for Personal Data Protection of Cyprus (dataprotection.gov.cy); in Portugal you can contact the CNPD (cnpd.pt).
9. Security
Data is encrypted in transit and at rest. We apply access controls, activity logging and other technical and organisational measures appropriate to the risk. No system is completely secure; in the event of a data breach posing a risk to your rights, we will notify you as required by the GDPR.
10. Children
The service is intended for professional use and is not directed at anyone under 18. We do not knowingly collect data from minors.
11. Changes to this policy
We may update this policy by publishing the new version here with its update date. If a change is material, we will give notice by email or within the service.
This policy is made available in several languages; in case of inconsistency, the Portuguese version prevails.