Privacy policy
Effective from: 4 October 2026 · Last updated: 4 October 2026
This policy explains how personal data is processed when you use the Dosszi service – the dosszi.app website, the platform.dosszi.app web platform, the api.dosszi.app interface and the Dosszi mobile app (iOS, Android) – under Regulation (EU) 2016/679 (GDPR) and the Hungarian Act CXII of 2011 on informational self-determination and freedom of information (Infotv.). The Hungarian version is authoritative.
1. Who we are
Dosszi is operated by DRB Services Kft. (the Provider). For any data protection question or request, contact us at [email protected].
- Name
- DRB Services Kft.
- Registered seat
- 2000 Szentendre, Sellő u. 6.
- Company registration number
- Cg. 13-09-195642 (Company Registry Court of the Budapest Environs Regional Court)
- Tax number
- 26536424-2-13
- [email protected]
- Hosting provider
- DigitalOcean, LLC, 101 6th Ave, New York, NY 10013, USA, www.digitalocean.com – Frankfurt (Germany, EU), FRA1 data centre
2. On whose behalf we process data
Dosszi is a business service: companies (each a Customer) use it so that their staff can capture and upload invoices and other documents. We therefore act in two roles:
- As a processor for the documents uploaded by the Customer (through its staff) and the data in them (for example names, addresses, tax numbers and line items on invoices). The Customer is the controller of this data: it decides what is uploaded, how long it is kept and who may access it. We process it only on the Customer's instructions under a data processing agreement (Article 28 GDPR). Please send requests about this data to your employer (the Customer) first; if they reach us, we forward them to the Customer.
- As a controller for user account data, sign-in and security logs, device data, crash diagnostics and app usage analytics. The sections below mainly cover this processing.
3. What we process, why, and on what legal basis
There is no public sign-up: users are invited by their company administrator or by the Provider. The data needed for the invitation therefore comes from the Customer.
3.1. Account data
- Data
- First and last name, email address, role (company admin or company user), the company the account belongs to, preferred language, document visibility setting, last used category, account status, creation and last sign-in time. We never store your password, only a salted one-way hash of it (scrypt).
- Purpose
- Creating and managing the account, signing in, enforcing permissions, sending notifications (e.g. a document's status changed).
- Legal basis
- Article 6(1)(b) GDPR (performance of the contract with the Customer) and Article 6(1)(f) (the legitimate interest of the Provider and the Customer in letting the Customer's staff use the service).
- Retention
- While the account exists, then 30 days after it is deleted or closed.
3.2. Sign-in and security data
- Data
- IP address, browser or app identifier (user agent), times of sign-ins, failed attempts and sign-outs; the six-digit sign-in codes sent by email (stored only as a keyed hash, HMAC-SHA256, valid for 10 minutes, at most 5 attempts); session and device tokens (hashes only); and the audit log: who did what and when (e.g. sign-in, upload, view, download, status change, deletion). Passwords, codes and tokens never enter the log.
- Purpose
- Two-step verification, protecting accounts and documents, preventing and detecting abuse (e.g. password guessing), accountability.
- Legal basis
- Article 6(1)(f) GDPR (legitimate interest in the security of the system and the data), in line with Article 32 GDPR.
- Retention
- Audit log: 1 year. Sign-in codes: valid for 10 minutes, then deleted. Web sessions expire after 30 minutes of inactivity or 12 hours at most. App: the refresh token expires after 7 days without use; signing out invalidates the device's tokens immediately.
3.3. Uploaded documents and their metadata
- Data
- The uploaded file (PDF, JPEG, PNG, XML) and the data in it, plus metadata: document name, original file name, type, size, page count, checksum, category, uploader, capture and upload time, status (new, processed, rejected) and the rejection reason.
- Role
- We process this data as a processor, on the instructions of the Customer as controller (see section 2).
- Purpose
- Storing, displaying and searching the documents and tracking their processing status for the Customer.
- Retention
- As instructed by the Customer: until the Customer permanently deletes the document or the contract ends. The duty to keep accounting records for at least 8 years (Hungarian Accounting Act C of 2000, section 169) lies with the Customer; Dosszi supports it with a warning before permanent deletion.
3.4. Device data (mobile app)
- Data
- A random identifier of the app installation, platform (iOS or Android), device name, app version, last use and – if you allowed notifications – the push notification token.
- Purpose
- Signing the device in and out, blocking outdated app versions, sending push notifications about your documents' status.
- Legal basis
- Article 6(1)(f) GDPR (legitimate interest in providing the service securely).
- Retention
- While the device is signed in; the push token is removed on sign-out or when the device is revoked. Device data is deleted with the account.
3.5. Crash diagnostics (Sentry)
- Data
- Technical reports about app crashes and errors: error message, stack trace, app version, operating system and device model. We do not send personal data in these reports (no name, email address, IP address or document content).
- Purpose
- Finding and fixing errors in the app.
- Legal basis
- Article 6(1)(f) GDPR (legitimate interest in reliable, secure operation).
- Retention
- up to 90 days
3.6. Product analytics (PostHog, EU)
- Data
- Events about how the app is used (e.g. screens opened, scans started, uploads succeeded or failed, settings changed) with time, app version and device model, linked to your user id; your email address and name as person properties. Document content is never sent.
- Purpose
- Understanding how Dosszi is used, where users get stuck and which features to improve; customer support.
- Legal basis
- Article 6(1)(f) GDPR (legitimate interest in improving the service). You can object at any time (see section 7); we then delete the analytics data linked to your account and stop collecting it.
- Retention
- up to 12 months; the person profile is deleted when the account is deleted
3.7. Contacting us
- Data
- If you email us: your name, email address and the content of your message.
- Purpose
- Answering questions, customer support, handling data protection requests.
- Legal basis
- Article 6(1)(f) GDPR; for data protection requests Article 6(1)(c) (legal obligation).
- Retention
- 1 year after the matter is closed; 5 years for data protection requests (accountability).
The Customer's company admin can see the account data of the company's users, the uploaded documents and the company's audit log. A company user sees either their own or all of the company's documents, depending on their setting. We do not make automated decisions or profile you in a way that has legal effects on you, we do not sell your data and we do not use it for advertising.
4. Processors and recipients
We use the following processors to run the service. We have a data processing agreement with each of them.
- DigitalOcean, LLC (USA) – hosting, application server, database and file storage. Data is stored in Frankfurt (Germany, EU).
- Resend (USA) – delivery of system emails (invitations, sign-in codes, password resets, notifications): recipient name, email address and message content.
- Google (Firebase Cloud Messaging) – delivery of push notifications to the mobile app: push token and notification text (document name, status). On iOS devices delivery goes through the Apple Push Notification service.
- Functional Software, Inc. (Sentry) (USA) – receiving and analysing app crash reports, without personal data.
- PostHog – product analytics in its EU cloud (Frankfurt).
- Cloudflare, Inc. (Turnstile) (USA) – bot protection on the web sign-in and password forms: IP address and browser characteristics.
International transfers. Resend, Sentry's ingest service, Cloudflare and Google may process data in the United States; the US parent companies of DigitalOcean and PostHog may access EU-stored data for operational purposes. Such transfers rely on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR, Decision (EU) 2021/914) or, where the provider is certified, the EU–US Data Privacy Framework adequacy decision (Article 45 GDPR). You can request a copy of these safeguards at [email protected].
We disclose data to authorities only where and to the extent required by law.
5. Retention at a glance
- Account data: while the account exists, plus 30 days.
- Audit log: 1 year.
- Sign-in codes: 10 minutes; sessions: 30 minutes of inactivity or 12 hours; app refresh token: 7 days without use.
- Push token: until sign-out or device revocation.
- Documents: as instructed by the Customer; keeping accounting records for 8 years (Accounting Act, section 169) is the Customer's obligation.
- Crash reports: up to 90 days; product analytics: up to 12 months; the person profile is deleted when the account is deleted.
6. Security
- All connections are encrypted (HTTPS/TLS); the web platform uses strict security headers.
- Every sign-in requires your password and a one-time code sent by email (two-step verification).
- Passwords and codes are stored only as one-way hashes; the account is locked temporarily after repeated failed attempts.
- Files are kept in private storage with no public links; they open only after sign-in, through links valid for 60 seconds.
- The mobile app's local database is encrypted, and after one minute of inactivity the app unlocks only with biometrics or the device passcode.
- The audit log cannot be changed or deleted.
7. Your rights
Under the GDPR you have the right to:
- access (Article 15): information about and a copy of your personal data;
- rectification (Article 16): you can change your name on the Settings page yourself; ask your company admin or us to change your email address;
- erasure (Article 17): ask us to delete your account and personal data;
- restriction of processing (Article 18);
- data portability (Article 20): receive your account data in a machine-readable format (JSON);
- object (Article 21) at any time to processing based on legitimate interest, including product analytics.
How to make a request
- Account deletion in the app or on the web: in the mobile app's Settings, or on the Settings page of platform.dosszi.app, choose "Request account deletion". We notify your company admin and the Provider, then delete the account and confirm it by email.
- By email: send any other request to [email protected], preferably from the email address of your account. If we have doubts about your identity, we may ask for additional verification.
We respond without undue delay and within one month at the latest; this may be extended by two further months where necessary, in which case we let you know. Requests are free of charge. Deleting your account does not delete the documents uploaded for your company: they are the Customer's data and the Customer decides how long to keep them (see sections 2 and 3.3); we forward requests about them to the Customer.
8. Complaints and remedies
If you believe that your personal data is processed unlawfully, please contact us first at [email protected] so that we can fix the problem. You may also lodge a complaint with the Hungarian supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH – Hungarian National Authority for Data Protection and Freedom of Information)
- Address
- Falk Miksa utca 9–11., 1055 Budapest, Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- Phone
- +36 1 391 1400
- [email protected]
- Website
- www.naih.hu
You may also go to court (Article 79 GDPR, section 23 Infotv.); at your choice, the proceedings can be brought before the regional court of your place of residence. If you live in another EU country, you may also complain to the supervisory authority there.
9. Cookies
The dosszi.app website uses no cookies, analytics or third-party tracking; even the fonts are served from our own server.
The platform.dosszi.app web platform uses only strictly necessary cookies:
__Host-dosszi_session– the signed-in session cookie (readable only by the server; expires after 30 minutes of inactivity and after 12 hours at most);- a short-lived cookie for the email sign-in code step (10 minutes);
dosszi_sidebar– remembers whether the sidebar is collapsed (no personal data, 1 year).
These do not require consent (Article 5(3) of the ePrivacy Directive; section 155(4) of the Hungarian Electronic Communications Act). The web platform uses no analytics or advertising cookies.
10. Changes and effective date
We may update this policy when the service or the law changes. We notify users of material changes by email or in the service before they take effect. The current version is always available on this page (dosszi.app/en/privacy/).