This Privacy Policy informs you about how Rolak Automation (hereinafter "RolakInvoice", "we") collects, processes, and protects personal data. We comply with the revised Swiss Federal Act on Data Protection (revised FADP) and the EU General Data Protection Regulation (GDPR), where applicable. Our offering is directed at business customers domiciled in Switzerland. The GDPR only applies insofar as we specifically offer services to individuals in the EU or EEA in a given case (market-location principle, Art. 3(2) GDPR).
1. Data Controller
Responsible for data processing is:
Rolak Automation (sole proprietorship)
Owner: Jan Rolak
Ahornweg 24, 8630 Rüti ZH, Switzerland
Email: [email protected]
2. Purpose of Data Processing
We process your data for the following purposes:
- Provision and operation of RolakInvoice (invoice automation, OCR, and AI analysis)
- Contract execution, billing, and support
- Improvement of our services and security (technical logs, error analysis)
- Fulfillment of legal retention and documentation obligations
- Communication with you (email, support requests)
3. Categories of Processed Data
- Master data: Name, company, address, email, phone number, payment details.
- Invoice contents: Invoices imported by you (PDF, images, QR invoices) including all information contained therein such as sender, amounts, VAT, line items.
- Email contents: If email monitoring (IMAP/POP3) is enabled, invoice attachments and related metadata are retrieved and processed.
- Usage and log data: IP address, timestamp, browser, operating system, error messages – exclusively for security and operational purposes.
4. Legal Basis
Processing is based on the following legal grounds (Art. 6 GDPR as well as Art. 6 and Art. 31 revised FADP):
- Contract fulfillment (Art. 6(1)(b) GDPR) – for the provision of our software and services.
- Legitimate interest (Art. 6(1)(f) GDPR) – to secure our systems, prevent abuse, and improve quality.
- Legal obligation (Art. 6(1)(c) GDPR) – especially for tax and commercial retention obligations.
- Consent (Art. 6(1)(a) GDPR) – e.g., for optional analysis and marketing cookies.
5. Retention Periods
We store personal data only as long as necessary for the stated purposes or as required by statutory retention periods. Invoice data is stored in the local SQLite database on your device; you retain full control at all times. Log data is generally deleted after 30 days. Billing-related documents are kept for 10 years in accordance with the Swiss Code of Obligations.
6. Transfer to Third Parties (Processors)
We use carefully selected processors with whom corresponding Data Processing Agreements (DPA) are in place. A complete, continuously updated list can be found in our Data Processing Agreement, Section 8.
- Google Ireland Ltd. (Google Gemini) – primary AI-supported extraction of invoice data. Invoice contents (PDFs, extracted text, metadata) are transmitted to the Google Gemini API; processing may also take place on Google infrastructure outside Switzerland/the EU (basis: EU Standard Contractual Clauses under the Google Data Processing Addendum). Under the Gemini API Additional Terms, Google commits: (a) content is not used to train or improve models, (b) API logs are deleted by default after at most 55 days, (c) human review only takes place in individual cases for abuse detection by authorised Google personnel.
- OpenAI, OpCo, LLC (gpt-4o-mini) – cross-provider fallback for AI extraction. Used exclusively when Google Gemini is unavailable (outage, rate limit). Only the extracted invoice text or an image of the PDF pages is transmitted to OpenAI, OpCo, LLC, San Francisco (USA). Safeguards: SCCs (EU) 2021/914 Module 2 with Swiss amendments, incorporated in the OpenAI Data Processing Addendum. Under the OpenAI API Terms, API content is not used to train the models; retention max. 30 days for abuse prevention.
- Infomaniak Network SA, Geneva (Switzerland) – hosting of cloud backend infrastructure (VPS, database) in the Swiss data centre. Infomaniak is ISO 27001 certified and revised FADP-compliant.
- Stripe Payments Europe Ltd., Dublin (Ireland) – processing of subscription payments (credit card, SEPA). PCI-DSS Level 1.
- Apple Inc. (iCloud+ mail alias) – sending of transactional emails (registration confirmation, password reset) via
[email protected]as an alias on an iCloud mailbox. - Google LLC (Gmail SMTP, Google Analytics 4) – sending of contact-form replies as well as, exclusively upon your consent, web analytics via Google Analytics 4 (cookies, anonymised IP address; details in the Cookie Policy).
7. Data Transfer Abroad
Where personal data is transferred to countries outside Switzerland or the EU/EEA — in particular to Google Gemini (contracting party is Ireland-based Google Ireland Ltd.; processing may also take place on infrastructure of the parent company Google LLC in the USA or other countries), OpenAI, OpCo, LLC (USA) as cross-provider fallback, Apple Inc. and Google LLC — we rely on:
- EU Standard Contractual Clauses (SCCs, Module 2 "Controller-to-Processor", Implementing Decision (EU) 2021/914 of 4 June 2021),
- the supplementary revised FADP provisions (Annex II of the SCCs for Switzerland),
- additional technical measures such as TLS transport encryption and (where feasible) pseudonymisation.
Transfers to the USA only take place where the recipient is certified under the Swiss-U.S. or EU-U.S. Data Privacy Framework or has entered into appropriate SCCs.
In accordance with Art. 19 para. 4 revised FADP, we inform you that the aforementioned recipients are located in the USA and Ireland respectively. The disclosure abroad is based on appropriate safeguards within the meaning of Art. 16 para. 2 let. b revised FADP (Standard Contractual Clauses with Swiss amendments).
7a. Specific Rights Related to AI Processing
In addition to the general data subject rights (see Section 8), the following applies to AI processing by Google Gemini and OpenAI:
- Deletion pass-through: If you request deletion of your data, we delete the orchestration metadata stored in our cloud database as well as all extracted invoice contents within 30 days. Google deletes Gemini API logs by default after at most 55 days; OpenAI by default retains API content for a maximum of 30 days for abuse prevention. A separate deletion request to the providers is generally not required, as no persistent storage takes place.
- No automated decision with legal effect: The AI providers only deliver structured-data suggestions; all accounting steps remain with the customer. There is no automated individual decision within the meaning of Art. 21 revised FADP or Art. 22 GDPR.
8. Rights of Data Subjects
You have the right at any time to:
- Information about your stored data (Art. 15 GDPR / Art. 25 revised FADP)
- Correction of inaccurate data (Art. 16 GDPR)
- Deletion "Right to be forgotten" (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
- Revocation of a given consent with effect for the future
- Lodge a complaint with the competent supervisory authority (in Switzerland: FDPIC)
To exercise your rights, an informal message to [email protected] is sufficient.
9. Data Security
We take appropriate technical and organizational measures to protect your data against unauthorized access, loss, or manipulation, including:
- TLS transport encryption (HTTPS) for all connections,
- JWT-based authentication, role-based access control, Argon2id/bcrypt password hashing,
- Swiss hosting infrastructure (Infomaniak Network SA, Geneva) for orchestration, OCR pre-processing and persistence of results. The AI extraction step primarily calls the Google Gemini API (processing may also take place outside the EU); if unavailable, OpenAI (USA) is used as a cross-provider fallback.
- Local SQLite database in the Windows client — invoice data primarily remains on the customer's device; the cloud stores account, plan and licence data as well as processing jobs with their extraction results; documents uploaded for processing are automatically deleted after at most 7 days
- Regular security updates of the website and client, Stripe-webhook idempotency, rate-limiting on critical endpoints.
- Daily automated database backups with 7 days' retention on Swiss infrastructure.
Contact
For questions regarding data protection, you can reach us at [email protected]. Processing details are set out in our Data Processing Agreement (DPA).