Autonify
Български · English

Privacy Policy

Autonify — accounting and compliance software Last updated: 2 August 2026 · Version 1.1

1. Who we are

Autonify is operated by APEX SYSTEMS EOOD (ЕЙПЕКС СИСТЪМС ЕООД), a company registered in Bulgaria under UIC 208560191, with registered address at 4 Yuriy Venelin St., entrance B, office 2, Varna 9028, Bulgaria (ул. „Юрий Венелин“ № 4, вх. Б, ап. Офис 2, гр. Варна 9028) ("Autonify", "we", "us").

We are the data controller for the personal data described in this policy.

For any question about this policy or your data, contact our data protection contact at dpo@autonify.bg.

2. What this policy covers

Autonify helps Bulgarian businesses automate bookkeeping, categorise invoices and transactions, and prepare for tax and regulatory compliance. This policy explains what personal data we process when you use Autonify, why, and what rights you have.

It covers, in particular, the data we receive when you connect your business bank account to Autonify, and the data we process when you switch on payment initiation from that account.

3. Bank account data (open banking)

3.1 How the connection works

When you connect a bank account, you authenticate directly with your bank, on your bank's own website or mobile app. Autonify never sees, receives, or stores your online banking credentials, PIN, or one-time codes.

Account access is provided through Iris Solutions AD (Айрис Солюшънс АД), a licensed Account Information Service Provider (AISP) authorised under PSD2 and supervised by the Bulgarian National Bank. Iris Solutions connects to your bank on our behalf, under your explicit consent, and passes the resulting data to Autonify. Iris Solutions acts as our processor for this purpose, and separately as a regulated AISP in its own right.

This connection is read-only: over it Autonify receives data, but submits no payment orders and changes nothing in your account. Payment initiation is a separate, opt-in service, off until you switch it on yourself; what data it involves and on what basis we process it is set out in section 3a.

3.2 What bank data we receive

Category Examples
Account details IBAN, account name, product type, currency, account holder name
Balances Current and booked balances
Transactions Date, amount, currency, credit/debit indicator, payment reference and remittance text, transaction status
Counterparty information Names and IBANs of the parties you pay and are paid by — this may include personal data about third parties

We request access for the period your bank permits (typically up to 90–180 days per consent), and we may retrieve historical transactions from up to 24 months before the connection date.

3.3 Legal basis

We process bank account data on the basis of your explicit consent (Art. 6(1)(a) GDPR), given when you authorise the connection at your bank, and to perform our contract with you (Art. 6(1)(b) GDPR).

Counterparty personal data appearing in your transactions is processed on the basis of our legitimate interest and yours in maintaining accurate accounting records, and to meet the statutory bookkeeping obligations that apply to you (Art. 6(1)(c) and (f) GDPR).

3.4 Withdrawing consent

You can disconnect a bank account at any time from Settings → Bank connections → Disconnect. We immediately revoke the access consent with your bank and stop retrieving new data.

Transactions already imported are retained, because they form part of your accounting records and are subject to statutory retention (see §6). You may request their deletion, subject to those obligations.

3a. Payment initiation

If you switch on bank payments (Terms, section 5a), Autonify prepares payment orders from the data in your account and submits them to your bank through a licensed payment initiation service provider (PISP). You give the authorisation yourself, with your bank, using strong customer authentication (SCA). This processing is separate from the read-only access in section 3.

3a.1 What data is processed

Category Examples
Payer details IBAN and account holder of the account being paid from
Beneficiary details Name and IBAN of the payee — a supplier, НАП, or an employee where wages are being paid. This is personal data about third parties
Order details Amount, currency, reference, date, payment status, and the identifier returned by the bank or provider
Authorisation details The single-use identifier of the authorisation (SCA) session, and the scope of the consent you gave your bank
Who instructed it The user in your account who initiated the payment, or a note that it was made automatically, with a timestamp

We do not receive or store your banking credentials. Authorisation happens entirely on your bank's systems. Autonify does not hold your money.

3a.2 Legal basis

  • Preparing and submitting the payment order is performance of our contract with you (Art. 6(1)(b) GDPR). Separately from the GDPR, Article 94(2) of Directive (EU) 2015/2366 (PSD2) requires your explicit consent to the processing of the data necessary for the payment service — you give it when you authorise the payment with your bank.
  • Beneficiary personal data — including employee names and IBANs where wages are paid — is processed to meet the statutory obligations that apply to you, and on the basis of our legitimate interest and yours in the payment being made and documented (Art. 6(1)(c) and (f) GDPR).
  • Keeping the payment record after execution is to meet a legal obligation to keep and retain accounting information (Art. 6(1)(c) GDPR).

3a.3 Switching off and withdrawing

You can switch automatic payments off at any time from Settings → Autopilot → Automatic payments, and withdraw the consent given to your bank directly with the bank. Switching off stops future orders. Records of payments already made are retained: they form part of your accounting records and are subject to statutory retention (see §6).

4. Other data we process

Category What Why
Account data Name, email, password hash, company details To create and secure your account
Invoices & documents Invoices and receipts you upload, and text extracted from them To categorise expenses and prepare reports. Document text recognition (OCR) runs locally on our own infrastructure — your documents are not sent to any third-party cloud OCR service.
Public registry data Company information from public Bulgarian registers To identify counterparties and validate company details
Usage & technical data Log data, IP address, device/browser information Security, fraud prevention, and diagnosing faults
Billing data Subscription and payment records To bill you and meet tax obligations

4a. Automated processing

Autonify processes your documents automatically: it reads scanned invoices (OCR), classifies income and expenses, matches bank transactions to documents, and prepares draft declarations.

  • This is not automated decision-making within the meaning of Article 22 GDPR. The outputs listed above are proposals. They have no legal effect and do not significantly affect you until you have reviewed and confirmed them; you can always change or reject them.
  • Automatic payments are the exception to that, and are dealt with separately. They do not propose, they execute. That is why they are off by default, are switched on by you alone, and are made only within the authorisation you gave your bank — which remains the party that authenticates you and executes the transfer. You can stop them at any time from Settings, or withdraw the consent with your bank (section 3a).
  • Your corrections stay with your company; a supplier's vocabulary does not. When you correct a classification we remember it for your company only, and that record is deleted along with the company. When you correct a field read from a supplier's invoice, we may also learn where that supplier prints the field (for example, the label in front of the invoice number) so it is read correctly for every customer who receives that supplier's invoices. What is learned is the position of the label - never the values from your document, and nothing that identifies your company.
  • Processing takes place within the European Union.
  • If you believe an automated result is wrong, correct it directly in the application; we keep both the original result and your correction.

5. Who we share data with

Recipient Role Purpose
Iris Solutions AD (Bulgaria) Processor / licensed AISP Bank connectivity
Iris Solutions AD (Bulgaria) Processor / licensed payment initiation service provider (PISP) Submitting payment orders where you have switched payments on. The provider is identified in the application before you switch the feature on
Your bank Recipient Authenticates you, receives the authorisation, and executes the transfer
Zume Hosting (Amsterdam datacentre, the Netherlands) Processor Application hosting and data storage
Stripe Processor Subscription billing
Your accountant, if you invite them Recipient Only where you explicitly grant access
Public authorities Recipient Only where legally required

We do not sell your data. We do not use your bank transaction data to train machine learning models for other customers, and we do not share it for advertising or profiling.

5.1 International transfers

Your data is stored and processed within the European Economic Area. Where any processor operates outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses.

6. How long we keep data

Data Retention
Accounting records (transactions, invoices, reports, vault documents) Retained for at least the statutory period required by Bulgarian accounting and tax law — generally 10 years (Закон за счетоводството; ДОПК art. 38). The periods are minima, and nothing is deleted automatically once they pass: the records stay until you ask for their deletion (or delete the company), and we tell you when records are past their minimum period
Raw bank API responses 18 months from receipt, for reconciliation and audit, then erased automatically. The transaction itself is kept — only the bank's original response is erased
Bank access consents and session identifiers Deleted on disconnection or consent expiry
Initiated payment records (beneficiary, IBAN, amount, reference, status) Kept alongside the accounting records they evidence — the first row of this table. The authorisation (SCA) session identifier is single-use and is spent as soon as the payment concludes
Account data For as long as your subscription is active. After it ends we keep it only for as long as we are obliged to retain the accounting records it gives access to (the first row of this table). You may request deletion at any time — we then restrict processing to the statutory minimum rather than erasing
Application logs (diagnostics) 14 days
Audit trail (who changed what on your records) Kept alongside the accounting records it relates to. It is protected against modification and deletion at the database level — it is the evidence that the records have not been altered, which is why it is not held for a shorter period

Statutory retention obligations may require us to keep accounting records even after you ask for deletion. Where that applies, we restrict processing rather than deleting.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased, where no statutory retention obligation applies;
  • restrict or object to processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing carried out before withdrawal.

To exercise any of these, contact dpo@autonify.bg. We respond within one month.

You also have the right to lodge a complaint with the Bulgarian supervisory authority, the Commission for Personal Data Protection (Комисия за защита на личните данни) — cpdp.bg.

8. Security

  • All data is encrypted in transit (TLS) and at rest.
  • Bank session identifiers are encrypted with restricted access.
  • We never store your banking credentials — authentication happens entirely on your bank's systems. The same is true of authorising a payment.
  • Autonify does not hold your money: it never passes through an account of ours.
  • Access to production data is limited to authorised personnel and logged.
  • Document text recognition runs on our own infrastructure, not a third-party cloud service.

9. Changes to this policy

We will notify you of material changes by email and in the application before they take effect.

10. Contact

APEX SYSTEMS EOOD (ЕЙПЕКС СИСТЪМС ЕООД) 4 Yuriy Venelin St., entrance B, office 2, Varna 9028, Bulgaria (ул. „Юрий Венелин“ № 4, вх. Б, ап. Офис 2, гр. Варна 9028) Data protection contact: dpo@autonify.bg

Autonify is accounting and compliance software.

Privacy Terms