Privacy policy

    Last updated: 22 September 2026.

    1. Who processes the data

    SmartAccount is a service of Pametno računovodstvo d.o.o., OIB 23618229102, Ulica Ivana Rendića 13, 10000 Zagreb, Croatia. For privacy questions and requests concerning personal data, write to info@smartaccount.hr.

    This policy covers the smartaccount.hr website, the app.smartaccount.hr web application, the SmartAccount mobile app for iOS and Android, and related accounting services. The company is the controller for its own business relationships, user accounts and service security. When we process employee, customer or supplier data according to a client's instructions, we act as a processor within the contracted services; the client determines the purposes of that processing.

    2. What data we process and where it comes from

    • User and business entity data: name, email, contact details, user identifier, permissions, business name, OIB and address.
    • Business and financial data: invoices, documents and their attachments, customer and supplier data, bank accounts, balances, transactions, portfolio, and data needed for the contracted bookkeeping and reporting.
    • Login and security data: data required for the selected authentication method, sessions, access tokens, and technical access and error logs, which may contain the IP address and request time.
    • The content of inquiries and communications with support or an accountant, and application settings.

    We receive data from you, your business entity and its authorized users, through use of the service, and from connected systems to which you grant us access. The scope of processing depends on the services and features you use. Without data required for login or processing a specific document, we cannot provide the relevant feature.

    3. Purposes and legal bases

    We process data to provide contracted services, manage accounts, process documentation and answer inquiries. The legal basis is performance of a contract or steps before entering into it when you are a contracting party, or legitimate interest in business communication and providing services to the business entity you represent. Legal obligations provide the basis for required accounting, tax reporting and retention of documentation.

    To protect accounts, prevent misuse and ensure reliable service operation, we rely on legitimate interest while respecting your rights. Where processing is based on consent, you may withdraw it without affecting the lawfulness of prior processing. We process data on behalf of a client according to their documented instructions.

    4. Mobile app and device permissions

    The camera is used to scan incoming invoices when you start that feature. The scanned document is sent to the SmartAccount server when you choose to send it. You can change camera permission in your device settings; without it, camera scanning is unavailable.

    Data needed to restore login is stored in the device's secure storage. Signing out removes the saved data for restoring login; it does not delete your account or documentation on the server. Android widgets may display financial data on the home screen, so add them only if you want that information visible there.

    If you choose to add a company card to Apple Wallet or Google Wallet, the card contains the company's name, OIB and address. Use of the wallet is also subject to its provider's privacy policy. Sharing a PDF transfers the document to the app or recipient you select. Bluetooth permission on Android is used to connect to a printer when printing invoices.

    5. AI-assisted document processing

    SmartAccount uses the Anthropic API to automatically recognize invoice data. In this process, the document's content and the recipient company's name and OIB are sent to the provider to identify the issuer, date, amounts and other invoice fields. The document may contain personal data of people named in it.

    The result is used to prepare invoice data for review and confirmation. Recognized data may contain errors and must be checked before further use. This process is not intended to make decisions about individuals' rights.

    6. Who may receive data

    Data is accessed by authorized people who need it to provide the service and by users with appropriate permissions within your business entity. Infrastructure, storage, email delivery and document processing providers take part in processing. We use Amazon SES for email delivery and Anthropic for the AI processing described above.

    Depending on the features selected, we exchange data with the login provider Certilia, Apple and Google wallets, and connected business systems. We provide data to competent authorities where this is a legal obligation or part of a service we are authorized to perform.

    If processing involves a transfer outside the European Economic Area, that transfer requires an appropriate basis under the GDPR, such as an adequacy decision or standard contractual clauses and any necessary supplementary measures. You can request information about recipients, processing locations and applicable safeguards at info@smartaccount.hr.

    7. Cookies, local storage and external content

    The web application uses sessions and storage required for login, security and settings. The mobile app stores data required for login and selected settings on the device. Deleting that storage may require signing in or configuring settings again.

    The contact page includes a Google Maps map. Loading it connects the browser to Google and sends technical data required for display, including the IP address. Google's privacy policy applies to processing it carries out for its own purposes.

    8. Data retention and protection

    Retention periods depend on the type of data, purpose of processing, contractual relationship, mandatory retention periods for accounting and tax documentation, and the need to establish or defend legal claims. We retain account data for as long as needed to provide the service and meet the stated obligations, and security logs for as long as needed for protection and incident resolution. For data we process on behalf of a client, their instructions and contractual obligations to return or delete data also apply.

    Once the basis for retention ends, data must be deleted or irreversibly anonymized. Mandatory retention of business records may continue after a user account is closed. We protect data through access controls, encrypted transmission and secure storage of login data on mobile devices.

    9. Your rights and deletion requests

    Under the conditions of the GDPR, you may request access, rectification, erasure, restriction of processing and data portability, and object to processing based on legitimate interest. You may withdraw consent by contacting info@smartaccount.hr.

    Send a request to delete your user account and associated personal data to info@smartaccount.hr. Specify the account to which the request relates; do not send your password. To protect data, we may request identity verification. If we must retain some data, we will explain the reason and applicable retention period or criterion. If your employer or another client is the controller, we will direct the request to the appropriate controller.

    We respond to requests without undue delay, normally within one month. We will notify you of any legally permitted extension and its reasons. You have the right to lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).

    10. Policy changes

    We publish the current policy at smartaccount.hr/privacy with its update date. We will notify users appropriately of material changes to processing. For additional information, contact info@smartaccount.hr.