Podmioty przetwarzające
Wersja rejestru 1.0 · Pobrano 04 września 2026 · Kanał RSS · JSON
Clozo (Andrei Diachenko, jednoosobowa działalność gospodarcza pod nazwą Clozo) korzysta z następujących podmiotów przetwarzających, aby świadczyć usługę. Ten rejestr jest publikowany na podstawie art. 28(2) RODO. Powiadamiamy z 30-dniowym wyprzedzeniem przed dodaniem nowego podmiotu przetwarzającego — zasubskrybuj poniżej, aby otrzymywać powiadomienia.
Pełen opis, jak wykorzystujemy Twoje dane osobowe, znajdziesz w naszej Polityce prywatności §6.
| Podmiot przetwarzający | Kraj | Usługa | Kategorie danych | Mechanizm przekazywania | Polityka prywatności | Umowa powierzenia |
|---|---|---|---|---|---|---|
| Stripe Payments Europe Ltd. | Ireland (EU) | Payment processing for Pro/Unlimited subscriptions and customer-paid invoices via Stripe Connect. | Email, name, IP, payment method metadata (last4, brand), billing address, transaction amount and currency. | EU/EEA only — no third-country transfer Data processed in EU (Ireland). Stripe Connect routes between Stripe legal entities transparent to user. | Link ↗ | Link ↗ |
| Cloudflare, Inc. | USA (with EU edge) | CDN, DDoS protection, Workers runtime hosting the frontend, R2 object storage for PDFs + uploaded logos. | IP addresses (truncated at edge, hashed daily-rotated salt for click logging), user agent (browser family only), file uploads (logos, PDF invoices). | USA — Standard Contractual Clauses (Commission 2021/914) Standard Contractual Clauses signed (Cloudflare 2024 DPA). EU edge enabled — content delivery happens from EU PoPs. | Link ↗ | Link ↗ |
| Functional Software, Inc. (Sentry) | USA | Error monitoring and performance tracing for backend (Django) and frontend (Next.js). | Stack traces, request paths, user-agent strings. PII scrubbing enabled via Sentry data-scrubbing rules. NO email or full request bodies sent. | USA — Standard Contractual Clauses (Commission 2021/914) Standard Contractual Clauses signed. Sentry-EU region used where available. | Link ↗ | Link ↗ |
| PostHog Inc. | USA | Product analytics, session replay (Pro+ only, opt-in), feature flags. Consent-gated — no events sent without explicit acceptance. | Anonymous distinct_id, event names, properties (page paths, button clicks). User-linked only after authentication. Session replay PII-masked. | USA — Standard Contractual Clauses (Commission 2021/914) Standard Contractual Clauses signed. EU region in roadmap; current routing via US. | Link ↗ | Link ↗ |
| Microsoft Corporation (Clarity) | USA | Consent-gated, marketing-only session analytics and heatmaps (Microsoft Clarity) on the public marketing pages. Loaded only after 'analytics' consent and NEVER on authenticated/app pages (dashboard, proposals, invoices, settings) — client and financial data are never recorded. | Pages visited on the public marketing site, clicks/taps, scroll and pointer movement, referrer, UTM parameters, browser/device and OS family, approximate region (from IP at Microsoft's edge), and a pseudonymous Clarity session/user identifier. Financial and client PII is out of scope by design (Clarity is never loaded on app pages, and financial elements carry data-clarity-mask as defence-in-depth). | USA — EU-US Data Privacy Framework (DPF) Transfer to the USA under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795; Microsoft Corporation is DPF-certified — verifiable at dataprivacyframework.gov), supplemented by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) under the Microsoft Products and Services DPA. Microsoft may process Clarity data for its own purposes per the Microsoft Clarity terms and the Microsoft Privacy Statement; Clozo's integration is consent-gated, marketing-only, and masks financial fields. | Link ↗ | Link ↗ |
| Resend, Inc. | USA | Transactional email delivery (welcome, OTP, password reset, invoice delivery, DSR confirmations, sub-processor change notices). | Email address, subject line, HTML body. We do not store delivery logs beyond 30 days. | USA — Standard Contractual Clauses (Commission 2021/914) Standard Contractual Clauses signed. | Link ↗ | Link ↗ |
| BRBX BV (Recommand) | Belgium | Certified Peppol Access Point and SMP. Transmits the B2B org's outgoing invoices over the Peppol e-invoicing network and receives their suppliers' invoices from it. Also publishes the participant's address in the network directory when receiving is enabled. | The full structured invoice, unscrubbed, because the document is the payload: legal name, postal address, VAT-ID, national registration number, seller contact name / telephone / e-mail (mandatory for German sellers under DE-R-005/006/007), bank IBAN and BIC, invoice number, dates, line-item descriptions and monetary amounts. | EU/EEA only — no third-country transfer BRBX BV is established in Belgium; the transmission itself involves no transfer outside the EEA. ONWARD, a Peppol document is delivered to whichever Access Point the RECIPIENT has chosen, which may be outside the EEA — that is a transmission to the controller's own trading partner over the network's own routing, not a Clozo sub-processing arrangement. The provider retains a copy for approximately 365 days; Clozo keeps the legal original for the statutory 5-10 years. | Link ↗ | Link ↗ |
| Didit | Spain | Identity verification of the authorised representative of a legal entity, required by the Peppol Access Point before that entity's address may be registered and published in the network directory. Invoked once per entity at onboarding, not per invoice. | Identity-document data of the authorised representative: name, date of birth, document number and type, issuing country, document image and a liveness selfie. No invoice content and no client financial data. | EU/EEA only — no third-country transfer EU-established; no transfer outside the EEA for the check itself. Reached through the Access Point's verification flow rather than directly by Clozo, which is why it is disclosed here even though we hold no contract of our own with it — the data subject is entitled to know who sees their identity document. | Link ↗ | — |
| Crisp IM SAS | France (EU) | Live-chat support widget on every page of useclozo.com. For an authenticated session the widget is initialised with the user's identity (see data categories) — not only with what the user types into the chat. | Email address and full name, pushed programmatically on every authenticated session (crisp.ts `user:email` / `user:nickname`) regardless of whether the chat is opened; plan, country, Stripe-connected flag, user id and UI language as session metadata; conversation transcript; IP; browser. | EU/EEA only — no third-country transfer EU-based provider, data hosted in EU (Nantes, France). | Link ↗ | Link ↗ |
| Geoapify GmbH | Germany (EU) | Address autocomplete in account settings (street, postal code, city, country normalisation for e-invoice fields). | Partial address strings typed into autocomplete. Not stored on Clozo side beyond live session. | EU/EEA only — no third-country transfer EU-based provider, processing in Germany (Linz HQ). No third-country transfer. | Link ↗ | Link ↗ |
| Google LLC (Gemini API) | USA | AI text expansion, translation, and service-agreement drafting in the proposal editor (Pro+ feature). | (1) B2C proposal editor: proposal description text + line-item names, with PII (client name, email, IBAN, currency amounts) scrubbed before transmission. For AI-generated service agreements ONLY, the identifying details of both contracting parties (names, addresses, VAT numbers, emails) ARE transmitted unscrubbed — a contract is void without them. (2) B2B AP invoice extraction (PDF/scan): the FULL incoming supplier-invoice document and its extracted content — supplier name, address, VAT-ID, IBAN/BIC, invoice number, dates, line items, and amounts — sent UNSCRUBBED (the supplier data is the extraction target). Per-org opt-out available. We do not send the B2C client list, billing data, or invoice totals. | USA — EU-US Data Privacy Framework (DPF) Google LLC is an ACTIVE participant in the EU-US Data Privacy Framework (certified 2016-09-22; participant record 5780), which covers its wholly-owned US subsidiaries. Transfer rests on the Commission's DPF adequacy decision, with the Google Cloud/Gemini API DPA as the contractual layer. Google does not use paid-tier API prompts or outputs to train its models. | Link ↗ | Link ↗ |
| Gotenberg (self-hosted) | EU (Railway hosting) | PDF rendering service for invoices and proposals. Runs as Clozo's own Railway service — open-source software (gotenberg/gotenberg). | Proposal/invoice HTML payload passed in for PDF conversion. Stateless — no logs retained. | EU/EEA only — no third-country transfer Self-hosted in Clozo's own Railway environment (EU region). Not a third-party processor in the legal sense — listed for transparency only. | Link ↗ | — |
Ostatnie zmiany
- 22 sie 2026 · Updated · Crisp IM SAS[SEC-31] Corrected: identity (email + full name) is pushed to Crisp on every authenticated session, not 'only if the user types it into chat'. No change to what is sent — only to what the register says is sent.
- 30 lip 2026 · Added · DiditAdded: Didit (ES) — identity verification of a legal entity's authorised representative, required before that entity's Peppol address may be published. Once per entity, not per invoice.
- 30 lip 2026 · Added · BRBX BV (Recommand)Added: BRBX BV (Recommand, BE) — certified Peppol Access Point and SMP. Carries the full structured invoice, including bank IBAN, to the recipient's own Access Point.
- 20 lip 2026 · Updated · Google LLC (Gemini API)Updated: Google LLC (Gemini API) data categories — added B2B AP invoice extraction (PDF/scan), migrated from Anthropic [D-198]. Full incoming supplier-invoice documents (supplier PII, IBAN/BIC, amounts) are sent unscrubbed for OCR/extraction under the EU-US DPF + Google DPA. Per-org opt-out (ai_extraction_enabled) + human-review gate unchanged.
- 20 lip 2026 · Updated · Anthropic PBCUpdated: Anthropic PBC data categories — added B2B AP invoice extraction (PDF/scan). Full incoming supplier-invoice documents (supplier PII, IBAN/BIC, amounts) are sent unscrubbed for OCR/extraction under SCCs. Per-org opt-out (ai_extraction_enabled) + human-review gate. Prod dark at disclosure time.
- 18 lip 2026 · Removed · Anthropic PBCRemoved: Anthropic PBC (USA) — Clozo no longer sends any data to Anthropic. Replaced by Google LLC (Gemini API).
- 18 lip 2026 · Added · Google LLC (Gemini API)Added: Google LLC (Gemini API) (US-DPF) — AI text expansion, translation and agreement drafting in the proposal editor.
- 05 cze 2026 · Added · Microsoft Corporation (Clarity)Added: Microsoft Corporation (Clarity, US-DPF) — consent-gated, marketing-only session analytics / heatmaps. Never loaded on authenticated/app pages.
- 16 maj 2026 · Updated · Anthropic PBCUpdated: Anthropic PBC service description — removed the incorrect 'opt-in via Settings → AI' clause; aligned with /tia page (Schrems II summary) which correctly states no per-user opt-in is required (Art. 6(1)(b) core service).
- 16 maj 2026 · Updated · Anthropic PBCUpdated: Anthropic PBC service description — removed the incorrect 'opt-in via Settings → AI' clause; aligned with /tia page (Schrems II summary) which correctly states no per-user opt-in is required (Art. 6(1)(b) core service).
- 13 maj 2026 · Added · Stripe Payments Europe Ltd.Initial sub-processor register published — 9 sub-processors disclosed (Stripe, Cloudflare, Sentry, PostHog, Resend, Crisp, Geoapify, Anthropic, Gotenberg).
Otrzymuj 30-dniowe wyprzedzenie o zmianach
Wyślemy e-mail 30 dni przed dodaniem, usunięciem lub zmianą podmiotu przetwarzającego. Podwójna weryfikacja — najpierw otrzymasz e-mail potwierdzający.
Powrót do logowania·Polityka prywatności·Umowa powierzenia przetwarzania danych·Warunki świadczenia usług·Nota prawna