Privacy summary
Invoice Studio does not use private workspace records or uploaded documents to train generalized artificial-intelligence models. Automated extraction and matching may suggest values, but an authorized user remains responsible for review and approval.
1. Scope and contact
This policy applies to the Invoice Studio web dashboard and the Invoice Studio mobile apps for iOS and Android. Invoice Studio is provided by Coetic X L.L.C., registered in Kosovo.
Questions and privacy requests can be sent to info@coetic-x.com. The public deletion process is described at Account and data deletion.
2. Our role and your organization's role
For account identity, product security, service operation, support, and our own legal obligations, Coetic X acts as the organization responsible for deciding how that information is processed.
When a customer organization uses Invoice Studio to manage its clients, employees, invoices, bank records, tax work, or uploaded documents, that customer generally decides why and how the information is used. Coetic X processes it to provide Invoice Studio under the customer's instructions. The customer is responsible for giving its clients, employees, and contacts any notice required by law and for assigning access only to authorized people.
External business-portal users receive a separate, limited view selected by the accounting organization. They do not receive access to staff-only banking, payroll, QuickBooks, extraction, or audit records.
3. Information we process
Account and identity information
- Name, email address, role, organization membership, business assignments, invitations, authentication identifiers, security settings, and multi-factor-authentication status.
- Profile preferences, language, time zone, navigation choices, and notification preferences.
Organization and contact information
- Organization and issuing-business names, logos, addresses, countries, currencies, business, tax, and VAT identifiers, and billing settings.
- Client, supplier, employee, and business-contact names, email addresses, phone numbers, addresses, identifiers, preferred communication channels, and access relationships.
Financial and accounting information
- Invoices, credit notes, purchases, receipts, services, line items, amounts, currencies, payment status, due dates, and settlement records.
- Bank statement records and transactions, reconciliation decisions, accounting categories, ledger entries, fixed assets, reports, tax and declaration workspaces, payroll inputs, and export history.
- Tasks, reminders, checklist progress, notifications, internal notes, review decisions, and activity history.
Files and extraction evidence
- Documents that an authorized user uploads or synchronizes, including invoices, receipts, spreadsheets, bank statements, reports, business records, and brand images.
- Filename, file type, size, cryptographic hash, upload source, parser version, extracted text or fields, review status, evidence anchors, and retention state.
Technical and security information
- Session, device, browser, network, request, error, rate-limit, security-event, and audit information needed to authenticate users, prevent abuse, investigate failures, and operate the service.
- Support messages and privacy-safe diagnostic information that a user chooses to provide.
We receive this information from users, their organization administrators, files and systems they connect or upload from, and normal operation of the service. We do not request access to a device's contacts, location, microphone, camera, or photo library unless a future feature clearly asks for it and this policy and the store disclosures are updated first.
4. Optional local workspace
A user may choose a local workspace that does not sign in or synchronize with the cloud service. Its records remain in that app installation or browser unless the user deliberately exports, shares, or submits them. Coetic X cannot recover a local workspace that was never sent to the service.
Opening a public legal page, the Coetic X website, or an email application still creates the ordinary network request associated with that destination. Fictional preview workspaces are separate from customer account data.
5. How and why we use information
- Authenticate users, maintain sessions, accept invitations, and enforce organization, business, and role permissions.
- Create, store, calculate, review, reconcile, search, export, and share records according to authorized user actions.
- Parse and preview selected documents, suggest mappings or matches, detect unsupported or unsafe files, and retain review evidence.
- Deliver reminders, account notices, document requests, and business-portal notifications when enabled.
- Protect accounts and tenants, limit abuse and storage usage, maintain audit trails, troubleshoot failures, and recover the service.
- Provide support, comply with law, enforce our terms, and improve reliability and usability using appropriately limited information.
Depending on the relationship and location, processing may be necessary to provide the contracted service, comply with legal obligations, pursue legitimate security and service interests, or act on consent for optional communications or integrations. A customer organization is responsible for establishing the appropriate basis for the personal data it places in its workspace.
6. Automated assistance
Invoice Studio may extract fields from documents, suggest accounting categories, flag possible matches, or calculate draft outputs from user-provided rules. These features support review; they do not independently file a tax declaration, make a payment, determine a person's legal rights, or replace professional judgment.
Users should verify source documents, names, identifiers, dates, currencies, totals, tax treatment, and exports before approval or external submission.
8. Security
Invoice Studio uses safeguards appropriate to private accounting work, including encrypted transport, scoped authentication, tenant and business authorization, row-level database controls, private object storage, short-lived file access, audit history, idempotent financial commands, upload quotas, file verification, malware scanning, restricted workers, and backup and recovery controls.
No system can guarantee absolute security. Customers should use strong unique passwords, enable multi-factor authentication where available, review member access, protect exported files, and promptly report suspicious activity.
9. Retention and deletion
Account and workspace information is retained while the account or customer relationship is active and afterward only as needed for the purposes described here, contractual commitments, security, dispute resolution, and applicable accounting or legal obligations.
Customer administrators can choose supported source-document retention classes. A temporary processing source may be scheduled for deletion after processing and human acceptance; retained workspace evidence remains until an authorized deletion or the organization's retention schedule applies; legal-hold material is not deleted until the hold is released. Deletion removes the private object while preserving only the limited audit or deletion evidence needed to prove what occurred.
Account deletion requests are normally completed within 30 days after identity and ownership checks. Some financial, audit, fraud-prevention, or legal records may be retained when required or permitted by law. Deleted information may remain in encrypted disaster-recovery backups until normal backup rotation, where it is isolated from ordinary product use.
See Account and data deletion for the available controls and the difference between deleting a personal account, an organization workspace, and a local workspace.
10. Your privacy choices and rights
Depending on applicable law, a person may request access, correction, export, restriction, objection, or deletion of personal information, and may withdraw consent where consent is the basis for processing. Account settings provide direct controls for some information.
If the information belongs to a customer organization's workspace, contact that organization first because it controls the record and its legal retention. We will assist the organization with a valid request. Requests about a Coetic X account, support conversation, or service operation can be sent directly to us.
We may ask for information needed to verify identity and authority. You may also raise a concern with the competent data-protection authority, including the Information and Privacy Agency of Kosovo where applicable.
11. Children
Invoice Studio is a business and professional product intended for adults. It is not directed to children, and we do not knowingly create accounts for children.
12. Government and regulated services
Invoice Studio is a private product. It is not a government app, bank, payment service, licensed fiscalization platform, or tax authority, and it is not endorsed by the Kosovo Tax Administration or another government body. Any future official integration will be identified separately with its authorization and source.
13. Changes to this policy
We will update this policy and the relevant App Store and Google Play disclosures before materially changing collection or use. The effective date and version above identify the current text. When required, material changes will be communicated in the product or by account notice.