Privacy Policy
Last updated: 28 May 2026
This Privacy Policy explains how Genetic codes, razvoj informacijskih rešitev, d.o.o. (“Genetic codes”, “we”, “us”) processes personal data when you use Pretvori račun at https://pretvori-racun.si (the “Demo”).
This document is provided for transparency. It is not legal advice. You should consult your own adviser where needed.
1. Who is responsible for your data?
Controller: Genetic codes, razvoj informacijskih rešitev, d.o.o. (Genetic codes d.o.o.)
Address: Kunaverjeva ulica 4, 1000 Ljubljana, Slovenia
Registration number (matična številka): 7337060000
Tax number (davčna številka): 44386583
Contact: [email protected]
We have not appointed a data protection officer. For privacy requests, contact us at the email above.
2. What is the Demo?
The Demo lets you upload a single invoice file (PDF, JPEG, or PNG) and receive a parsed result you can review and correct in your browser. After a successful parse, you may optionally submit a feature access request to ask about production capabilities (for example export formats). There is no user account and no searchable history of past parses in the interface. A run link works for up to 24 hours from when the run is created (see section 5).
3. What data do we process?
Depending on how you use the Demo, we may process:
- Invoice files and content you upload, including personal data that appears on invoices (e.g. names, addresses, tax identifiers, amounts). On our servers, each file is stored until our parser consumes it for processing — typically while it waits in the processing queue — then removed. We do not use uploads for model training.
- Parsed results and other data generated through use of the Demo (see section 5).
- Contact form data — if you use the contact form on the mission page: your email address and message content.
- Feature access request data — if you use the form on a completed parse run page: your email address, optional note, the parse run correlation ID, which feature you selected (e.g. eSlog export or e-računi.com import), and your IP address as included in the notification email we receive.
- IP address used for abuse prevention and rate limiting (see section 5).
- reCAPTCHA data processed by Google after you make a cookie choice in our banner (see sections 7 and 8).
- Theme preference stored in your browser’s local storage (`invoice-parser-theme`) if you change light/dark mode.
- Cookie consent choice stored in local storage (`invoice-parser-cookie-consent`).
- Language preference, reflected in the URL path (`/en` or `/sl`).
On your device only (we do not receive this unless you upload or submit a form as described above):
- A copy of your uploaded file in IndexedDB (database `invoice-parser-demo`) so you can preview the document on the parse run page.
- Corrected parse fields you edit in sessionStorage (key `correctedExtract:` followed by the run ID).
We do not require you to create an account. Invoice parsing and related storage use our own self-hosted AI model on infrastructure we control in Slovenia. We do not send invoice file content to publicly available third-party AI services (such as OpenAI, Anthropic, or similar cloud APIs) for parsing.
4. Why do we process data and what is our legal basis?
- Operate the Demo and show you a parse result — Data: invoice file and parsed output, including temporary storage of the file on our servers until the parser consumes it. Legal basis: legitimate interests (providing and securing a public product demo).
- Prevent abuse and enforce rate limits — Data: IP address and reCAPTCHA signals. Legal basis: legitimate interests (security and fraud prevention).
- Respond to contact and feature-access inquiries — Data: email address; message or note; for feature access, also correlation ID, intent, and IP address in our notification. Legal basis: consent (required checkbox when you submit the form).
- Store theme and cookie preferences — Data: localStorage. Legal basis: legitimate interests (remembering your UI and cookie choices).
Where we rely on legitimate interests, you may object under Art. 21 GDPR (see section 10). Where we rely on consent, you may withdraw consent as described in section 10.
5. Retention
- Invoice files on our servers: when you upload, the file is persisted on our Slovenian infrastructure until our parser consumes it — i.e. for as long as it is waiting to be parsed in the processing queue, and no longer after the parser has taken it. We do not keep uploads for model training or unrelated purposes.
- Parsed results: kept on our servers in memory for up to 24 hours from when they are created, then deleted. Results and any other data generated through use of the Demo are not stored in a database.
- Uploaded file and corrected fields on your device: in IndexedDB and sessionStorage until you close the tab, clear site data, or we clean up when you leave the run page; we do not sync corrected fields to our servers.
- IP addresses for rate limiting: held in memory only, in a rolling window of up to 1 hour. Default limits: 5 parse requests per IP per hour; 3 contact form submissions per IP per hour; 3 feature-access form submissions per IP per hour. They are not stored in a persistent database for this purpose.
- Server logs: we aim to log only operational metadata (e.g. correlation identifiers, status codes), not invoice file content or parsed payload. If verbose logging is enabled, IP addresses may appear in logs for troubleshooting; avoid uploading sensitive data if this concerns you.
- Theme and cookie consent preferences: until you clear site data in your browser.
- Contact and feature-access messages: delivered to our Gmail inbox and retained there until manually deleted. They are not stored in the application database. Feature-access notifications include metadata only (no invoice file or corrected extract).
- reCAPTCHA: governed by Google’s retention practices; see Google’s privacy information.
6. Where is data processed?
Invoice files are received and stored on infrastructure we control in Slovenia until our parser consumes them, then removed. Parsing uses our own self-hosted model — invoice file content is not sent to publicly available third-party AI services (such as OpenAI or Anthropic) for parsing.
7. Who do we share data with?
We do not sell your personal data.
We use the following processors:
- Google Ireland Limited / Google LLC — reCAPTCHA Enterprise (token and related signals; no invoice file content). Google may process data in countries outside the EEA. Google provides appropriate safeguards as described in its documentation and terms.
- Google LLC (Gmail SMTP) — used to deliver contact form and feature-access request messages to our inbox. Contact: email address and message content only. Feature access: email, note, correlation ID, intent, timestamp, locale, and client IP in the notification body. Invoice file content and corrected extract are never sent via this channel.
We may disclose data if required by law or to protect our rights, users, or security.
8. Cookies and similar technologies
- Strictly necessary: none beyond what your browser sends to load the site.
- After you choose in our cookie banner: Google reCAPTCHA may set or read cookies or similar identifiers. We load reCAPTCHA only after you dismiss the banner by clicking Accept all or Refuse unnecessary (both choices allow reCAPTCHA; we do not use analytics or advertising cookies). reCAPTCHA is used for invoice upload abuse prevention, contact form submission, and feature-access form submission.
- localStorage (not cookies): theme preference (`invoice-parser-theme`) and cookie consent choice (`invoice-parser-cookie-consent`), stored only on your device.
- sessionStorage and IndexedDB (not cookies): corrected parse fields and upload preview on your device only (see section 3).
See Google’s privacy information: https://policies.google.com/privacy
You can reset your cookie choice by clearing site data; the banner will appear again on your next visit.
9. Automated decision-making
We use automated checks (rate limiting, reCAPTCHA scoring) to reduce abuse. These do not produce legal or similarly significant effects on you in the sense of Art. 22 GDPR.
10. Your rights
If GDPR applies, you may have the right to: access, rectification, erasure, restriction, portability (where applicable), object to processing based on legitimate interests, and withdraw consent where processing is based on consent.
To exercise rights, email [email protected]. We may need to verify your request. We respond within the time limits set by law.
11. Children
The Demo is not directed at children under 16. You must be at least 16 years old to use it.
12. International visitors
If you access the Demo from outside the EEA, you understand that data may be processed in Slovenia and the EU/EEA as described above, and that reCAPTCHA may involve transfers to Google as described in section 7.
13. Changes
We may update this Privacy Policy. The “Last updated” date at the top will change. Material changes may be highlighted on the Demo where appropriate.
14. Contact
Genetic codes d.o.o. — [email protected]