Privacy Policy

At Contabilista, we prioritize your privacy and comply with the EU General Data Protection Regulation (GDPR) and Portuguese data protection laws to ensure your personal data is handled lawfully and securely. This Privacy Policy outlines what data we collect, how we use and protect it, and your rights regarding your data.

1. Who We Are

Contabilista is operated by Rising Formula - Unipessoal Lda, a company registered in Portugal (NIF: 517240912). We are the "data controller" of your personal data. For inquiries about this policy or your data, contact us at support@contabilista.io.

2. Information We Collect

We collect only the data necessary to provide our AI accounting assistant service, including:

2.1 Telegram Username

Collected when you use our Telegram bot to identify your account and deliver responses.

2.2 Payment Information

Includes name, email, and card details for purchases, processed securely by Stripe.

We do not store full credit card numbers; Stripe manages payment data.

2.3 Service Usage Data

Queries and interactions with our AI (questions and answers) are processed to provide and improve the service.

Treated as confidential; may include personal data if you share it in queries.

2.4 Contact Information

Collected when you contact us (e.g., name, email, message content) to respond to your inquiries or support requests.

3. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to function and enhance your experience, with consent required for non-essential uses.

3.1 Essential Cookies

Necessary for site operation (e.g., loading pages, maintaining sessions); no consent needed.

3.2 Analytics and Preferences Cookies

Used for preferences (e.g., language) or anonymous analytics (e.g., page visits); set only with your consent.

Not used for advertising or profiling.

3.3 Your Choices

Accept or reject non-essential cookies on your first visit.

Manage cookies via browser settings; disabling some may affect site functionality.

4. Legal Bases for Processing

We process your data under GDPR-approved legal bases:

4.1 Performance of a Contract

Processing Telegram username, queries, and payment data to deliver the service (Article 6(1)(b) GDPR).

4.2 Legal Obligation

Retaining payment records for tax/accounting compliance (e.g., 10 years) (Article 6(1)(c) GDPR).

4.3 Legitimate Interests

Improving the AI or sending service updates, balanced against your rights (Article 6(1)(f) GDPR).

You may object to this processing (see Your Rights).

4.4 Consent

Used for optional activities (e.g., marketing emails); withdrawable at any time (Article 6(1)(a) GDPR).

5. How We Use Your Information

We use your data solely for these purposes:

5.1 Providing the Service

Telegram username and query content used to deliver AI responses; may be reviewed internally for accuracy.

5.2 Processing Payments

Payment details processed via Stripe for subscriptions or one-time purchases; records kept for compliance.

5.3 Customer Support

Contact info and account details used to assist with inquiries or troubleshoot issues.

5.4 Service Communications

Non-promotional updates (e.g., purchase confirmations, policy changes, service alerts).

5.5 Improvement and Development

Usage analysis (preferably anonymized) to enhance AI and features; consent sought if beyond service delivery.

6. How We Protect Your Information

We employ robust security measures:

6.1 Encryption

Data encrypted in transit (HTTPS for website, Telegram's secure channels, Stripe's protocols).

6.2 Secure Storage

Stored on secure servers with industry-standard safeguards (firewalls, access controls).

6.3 Access Control and Confidentiality

Limited to authorized personnel under confidentiality agreements; access logged.

6.4 Payment Security

Stripe secures card data (PCI-DSS Level 1); we store only transaction references.

6.5 Data Minimization

Collect and retain minimal data for minimal time (see Data Retention).

6.6 Regular Reviews

Security practices updated; breaches reported to you and authorities if required.

7. Information Sharing and Disclosure

We do not sell or rent your data, sharing it only as necessary:

7.1 Service Providers (Processors)

  • Telegram: Transmits bot messages; subject to their privacy terms.
  • Stripe: Processes payments securely under GDPR compliance.
  • Hosting/IT: Cloud providers store data, bound by EU protection standards.
  • Email Service: Sends communications via secure providers.

7.2 Legal Compliance and Protection

Disclosed if legally required or to enforce rights/safety; you're informed if permitted.

7.3 Business Transfers

Data may transfer in mergers/acquisitions with confidentiality ensured; you'd be notified.

8. International Data Transfers

Data is preferably kept in the EEA, but some providers may transfer it outside:

8.1 Telegram

Global infrastructure; data may route beyond EEA (e.g., U.S.); review their terms.

8.2 Stripe

Primarily EEA-processed; may transfer to U.S. with GDPR safeguards (e.g., SCCs).

8.3 Other Providers

Non-EEA transfers use adequacy decisions or SCCs for protection.

9. Data Retention

We retain data only as needed or required:

9.1 Telegram Username and Account Data

Kept while active; retained briefly post-use unless deleted upon request.

9.2 Query Content

Stored briefly (e.g., months) for quality; anonymized later unless deletion requested.

9.3 Payment Records

Kept 10 years for legal compliance; deleted/anonymized afterward.

9.4 Communications

Retained for account duration plus a period; deletable upon request unless legally needed.

9.5 Analytics Data

Short-term retention; anonymized quickly; identifiers removed.

10. Children's Privacy

Our service is not for children:

10.1 No Use by Under-13

We do not collect data from those under 13; contact us if detected.

10.2 Minors Over 13

13-18 users need parental consent for purchases; age verification possible.

10.3 No Targeting of Children

Service not designed for or marketed to minors.

11. Your Rights

Under GDPR, you have these rights:

11.1 Right of Access

Request a copy of your data and details on its use, free of charge.

11.2 Right to Rectification

Correct inaccurate or incomplete data.

11.3 Right to Erasure

Delete data unless legally required to retain (e.g., payment records).

11.4 Right to Restrict Processing

Pause processing in specific cases (e.g., accuracy disputes).

11.5 Right to Object

Oppose processing for legitimate interests or marketing.

11.6 Right to Data Portability

Receive or transfer your data in a machine-readable format.

11.7 Right to Withdraw Consent

Revoke consent anytime for applicable processing.

11.8 Rights re: Automated Decision-Making

No solely automated decisions with legal effects apply; human oversight exists.

11.9 Right to Complain

Contact Portugal's CNPD or us directly with concerns.

11.10 Exercising Your Rights

Email support@contabilista.io; response within one month (extendable if complex).

12. Automated Decision-Making and AI

Our AI usage is informational, not decisional:

12.1 No Legal Effect

AI answers queries without affecting your rights.

12.2 Human Oversight

Experts oversee AI knowledge and outputs.

12.3 Transparency

AI uses pattern matching on trained data; no personal profiling.

12.4 Future Developments

Any automated decisions would comply with GDPR, with notice and contest rights.

13. Changes to This Privacy Policy

Updates posted with notice (e.g., website, Telegram, email).

Effective upon posting; consent sought for material changes.

14. Contact Us

Email: support@contabilista.io

Hours: Monday–Friday, 9:00–18:00 WET

Mail: Request address via email if needed.

Last Updated: March 27, 2025