Privacy Policy
Autonify — accounting and compliance software Last updated: 2 August 2026 · Version 1.1
1. Who we are
Autonify is operated by APEX SYSTEMS EOOD (ЕЙПЕКС СИСТЪМС ЕООД), a company registered in Bulgaria under UIC 208560191, with registered address at 4 Yuriy Venelin St., entrance B, office 2, Varna 9028, Bulgaria (ул. „Юрий Венелин“ № 4, вх. Б, ап. Офис 2, гр. Варна 9028) ("Autonify", "we", "us").
We are the data controller for the personal data described in this policy.
For any question about this policy or your data, contact our data protection contact at dpo@autonify.bg.
2. What this policy covers
Autonify helps Bulgarian businesses automate bookkeeping, categorise invoices and transactions, and prepare for tax and regulatory compliance. This policy explains what personal data we process when you use Autonify, why, and what rights you have.
It covers, in particular, the data we receive when you connect your business bank account to Autonify, and the data we process when you switch on payment initiation from that account.
3. Bank account data (open banking)
3.1 How the connection works
When you connect a bank account, you authenticate directly with your bank, on your bank's own website or mobile app. Autonify never sees, receives, or stores your online banking credentials, PIN, or one-time codes.
Account access is provided through Iris Solutions AD (Айрис Солюшънс АД), a licensed Account Information Service Provider (AISP) authorised under PSD2 and supervised by the Bulgarian National Bank. Iris Solutions connects to your bank on our behalf, under your explicit consent, and passes the resulting data to Autonify. Iris Solutions acts as our processor for this purpose, and separately as a regulated AISP in its own right.
This connection is read-only: over it Autonify receives data, but submits no payment orders and changes nothing in your account. Payment initiation is a separate, opt-in service, off until you switch it on yourself; what data it involves and on what basis we process it is set out in section 3a.
3.2 What bank data we receive
| Category | Examples |
|---|---|
| Account details | IBAN, account name, product type, currency, account holder name |
| Balances | Current and booked balances |
| Transactions | Date, amount, currency, credit/debit indicator, payment reference and remittance text, transaction status |
| Counterparty information | Names and IBANs of the parties you pay and are paid by — this may include personal data about third parties |
We request access for the period your bank permits (typically up to 90–180 days per consent), and we may retrieve historical transactions from up to 24 months before the connection date.
3.3 Legal basis
We process bank account data on the basis of your explicit consent (Art. 6(1)(a) GDPR), given when you authorise the connection at your bank, and to perform our contract with you (Art. 6(1)(b) GDPR).
Counterparty personal data appearing in your transactions is processed on the basis of our legitimate interest and yours in maintaining accurate accounting records, and to meet the statutory bookkeeping obligations that apply to you (Art. 6(1)(c) and (f) GDPR).
3.4 Withdrawing consent
You can disconnect a bank account at any time from Settings → Bank connections → Disconnect. We immediately revoke the access consent with your bank and stop retrieving new data.
Transactions already imported are retained, because they form part of your accounting records and are subject to statutory retention (see §6). You may request their deletion, subject to those obligations.
3a. Payment initiation
If you switch on bank payments (Terms, section 5a), Autonify prepares payment orders from the data in your account and submits them to your bank through a licensed payment initiation service provider (PISP). You give the authorisation yourself, with your bank, using strong customer authentication (SCA). This processing is separate from the read-only access in section 3.
3a.1 What data is processed
| Category | Examples |
|---|---|
| Payer details | IBAN and account holder of the account being paid from |
| Beneficiary details | Name and IBAN of the payee — a supplier, НАП, or an employee where wages are being paid. This is personal data about third parties |
| Order details | Amount, currency, reference, date, payment status, and the identifier returned by the bank or provider |
| Authorisation details | The single-use identifier of the authorisation (SCA) session, and the scope of the consent you gave your bank |
| Who instructed it | The user in your account who initiated the payment, or a note that it was made automatically, with a timestamp |
We do not receive or store your banking credentials. Authorisation happens entirely on your bank's systems. Autonify does not hold your money.
3a.2 Legal basis
- Preparing and submitting the payment order is performance of our contract with you (Art. 6(1)(b) GDPR). Separately from the GDPR, Article 94(2) of Directive (EU) 2015/2366 (PSD2) requires your explicit consent to the processing of the data necessary for the payment service — you give it when you authorise the payment with your bank.
- Beneficiary personal data — including employee names and IBANs where wages are paid — is processed to meet the statutory obligations that apply to you, and on the basis of our legitimate interest and yours in the payment being made and documented (Art. 6(1)(c) and (f) GDPR).
- Keeping the payment record after execution is to meet a legal obligation to keep and retain accounting information (Art. 6(1)(c) GDPR).
3a.3 Switching off and withdrawing
You can switch automatic payments off at any time from Settings → Autopilot → Automatic payments, and withdraw the consent given to your bank directly with the bank. Switching off stops future orders. Records of payments already made are retained: they form part of your accounting records and are subject to statutory retention (see §6).
4. Other data we process
| Category | What | Why |
|---|---|---|
| Account data | Name, email, password hash, company details | To create and secure your account |
| Invoices & documents | Invoices and receipts you upload, and text extracted from them | To categorise expenses and prepare reports. Document text recognition (OCR) runs locally on our own infrastructure — your documents are not sent to any third-party cloud OCR service. |
| Public registry data | Company information from public Bulgarian registers | To identify counterparties and validate company details |
| Usage & technical data | Log data, IP address, device/browser information | Security, fraud prevention, and diagnosing faults |
| Billing data | Subscription and payment records | To bill you and meet tax obligations |
4a. Automated processing
Autonify processes your documents automatically: it reads scanned invoices (OCR), classifies income and expenses, matches bank transactions to documents, and prepares draft declarations.
- This is not automated decision-making within the meaning of Article 22 GDPR. The outputs listed above are proposals. They have no legal effect and do not significantly affect you until you have reviewed and confirmed them; you can always change or reject them.
- Automatic payments are the exception to that, and are dealt with separately. They do not propose, they execute. That is why they are off by default, are switched on by you alone, and are made only within the authorisation you gave your bank — which remains the party that authenticates you and executes the transfer. You can stop them at any time from Settings, or withdraw the consent with your bank (section 3a).
- Your corrections stay with your company; a supplier's vocabulary does not. When you correct a classification we remember it for your company only, and that record is deleted along with the company. When you correct a field read from a supplier's invoice, we may also learn where that supplier prints the field (for example, the label in front of the invoice number) so it is read correctly for every customer who receives that supplier's invoices. What is learned is the position of the label - never the values from your document, and nothing that identifies your company.
- Processing takes place within the European Union.
- If you believe an automated result is wrong, correct it directly in the application; we keep both the original result and your correction.
5. Who we share data with
| Recipient | Role | Purpose |
|---|---|---|
| Iris Solutions AD (Bulgaria) | Processor / licensed AISP | Bank connectivity |
| Iris Solutions AD (Bulgaria) | Processor / licensed payment initiation service provider (PISP) | Submitting payment orders where you have switched payments on. The provider is identified in the application before you switch the feature on |
| Your bank | Recipient | Authenticates you, receives the authorisation, and executes the transfer |
| Zume Hosting (Amsterdam datacentre, the Netherlands) | Processor | Application hosting and data storage |
| Stripe | Processor | Subscription billing |
| Your accountant, if you invite them | Recipient | Only where you explicitly grant access |
| Public authorities | Recipient | Only where legally required |
We do not sell your data. We do not use your bank transaction data to train machine learning models for other customers, and we do not share it for advertising or profiling.
5.1 International transfers
Your data is stored and processed within the European Economic Area. Where any processor operates outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses.
6. How long we keep data
| Data | Retention |
|---|---|
| Accounting records (transactions, invoices, reports, vault documents) | Retained for at least the statutory period required by Bulgarian accounting and tax law — generally 10 years (Закон за счетоводството; ДОПК art. 38). The periods are minima, and nothing is deleted automatically once they pass: the records stay until you ask for their deletion (or delete the company), and we tell you when records are past their minimum period |
| Raw bank API responses | 18 months from receipt, for reconciliation and audit, then erased automatically. The transaction itself is kept — only the bank's original response is erased |
| Bank access consents and session identifiers | Deleted on disconnection or consent expiry |
| Initiated payment records (beneficiary, IBAN, amount, reference, status) | Kept alongside the accounting records they evidence — the first row of this table. The authorisation (SCA) session identifier is single-use and is spent as soon as the payment concludes |
| Account data | For as long as your subscription is active. After it ends we keep it only for as long as we are obliged to retain the accounting records it gives access to (the first row of this table). You may request deletion at any time — we then restrict processing to the statutory minimum rather than erasing |
| Application logs (diagnostics) | 14 days |
| Audit trail (who changed what on your records) | Kept alongside the accounting records it relates to. It is protected against modification and deletion at the database level — it is the evidence that the records have not been altered, which is why it is not held for a shorter period |
Statutory retention obligations may require us to keep accounting records even after you ask for deletion. Where that applies, we restrict processing rather than deleting.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where no statutory retention obligation applies;
- restrict or object to processing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing carried out before withdrawal.
To exercise any of these, contact dpo@autonify.bg. We respond within one month.
You also have the right to lodge a complaint with the Bulgarian supervisory authority, the Commission for Personal Data Protection (Комисия за защита на личните данни) — cpdp.bg.
8. Security
- All data is encrypted in transit (TLS) and at rest.
- Bank session identifiers are encrypted with restricted access.
- We never store your banking credentials — authentication happens entirely on your bank's systems. The same is true of authorising a payment.
- Autonify does not hold your money: it never passes through an account of ours.
- Access to production data is limited to authorised personnel and logged.
- Document text recognition runs on our own infrastructure, not a third-party cloud service.
9. Changes to this policy
We will notify you of material changes by email and in the application before they take effect.
10. Contact
APEX SYSTEMS EOOD (ЕЙПЕКС СИСТЪМС ЕООД) 4 Yuriy Venelin St., entrance B, office 2, Varna 9028, Bulgaria (ул. „Юрий Венелин“ № 4, вх. Б, ап. Офис 2, гр. Варна 9028) Data protection contact: dpo@autonify.bg