Privacy Policy

Last updated: July 14, 2026

1. Who We Are

Kassy ("we", "us", "the Service") is a scheduling and invoicing platform for private practitioners and small teams, operated by KVSoft EOOD, UIC 206613460, with registered seat and address at Sofia, zhk. Strelbishte, ul. Mila Rodina 11, vh. E, Bulgaria. For any questions about this policy or your data, contact us at support@kassy.app.

This policy explains what personal data we process, why we process it, and what rights you have. It covers practitioners and team members who use the platform, and the clients whose data practitioners manage in it - including people who receive invoices or visit payment, booking or schedule pages generated by the platform.

2. Data We Process

We process only what is needed to run the Service:

  • Account data: name, email address and profile picture provided by Google when you sign in, plus your workspace settings (organisation name, working hours, preferences).
  • Client data: client names, email addresses, phone numbers, billing details, prices, packages and credit balances, and notes that practitioners enter into the platform.
  • Session data: session titles, dates, times, durations, attendance status and notes.
  • Invoice and payment data: invoice amounts, statuses, payment links and payment references received from our payment provider. We never see, process or store card numbers - card payments run entirely on the provider's hosted checkout.
  • Payment setup (verification) data: if you enable card payments, we collect in our interface - and transmit directly to our payment provider Paypercut - the details the provider requires by law: business representative details (name, date of birth, address), payout IBAN and account holder name, and identity documents. This data is not stored on our servers; we keep only the status of your payment account (e.g. outstanding verification steps, whether charges are enabled).
  • Payment and booking page visitors: public pages display data entered by your practitioner (your name, session details, amounts owed). We do not collect further personal data from you on these pages beyond standard technical logs.
  • Usage and diagnostics data: product analytics (page views, feature usage), which is linked to your account while you are signed in (PostHog), and error and performance diagnostics (Sentry, server logs), which may include your IP address and browser information.
  • Contact data: your name, email and message when you use our contact form.

3. Purposes and Legal Bases

We process personal data on the following legal bases under the GDPR:

  • Performance of a contract (Art. 6(1)(b)) - operating the scheduling, client, invoicing and payment features; sending invoices and reminders on your instruction; transactional emails; enabling payment onboarding with our provider.
  • Legitimate interests (Art. 6(1)(f)) - understanding product usage to improve the Service, securing the Service, preventing fraud and abuse, and diagnosing errors.
  • Legal obligation (Art. 6(1)(c)) - accounting and tax records, and responding to lawful requests from authorities.
  • Consent (Art. 6(1)(a)) - where we ask for it, for example for optional communications. You can withdraw consent at any time.

We do not sell or rent your personal data or your clients' data, and we do not share it with third parties for their marketing.

4. Service Providers

We use the following providers to operate Kassy. They process data on our behalf under data processing agreements, except where noted:

  • Supabase - database hosting and authentication (EU region).
  • Vercel - application hosting and content delivery.
  • Google - sign-in (Google acts as an independent controller for your Google account).
  • Resend - transactional email delivery (invoices, reminders, notifications).
  • Paypercut - payment processing and merchant verification. For identity verification (KYC), anti-money-laundering compliance and payment execution, Paypercut acts as an independent controller under its own terms and privacy policy.
  • PostHog - product analytics.
  • Sentry - error and performance monitoring.

5. International Transfers

Data is stored primarily in the European Union. Some providers (for example Vercel, Resend, Sentry and Google) may process limited data in the United States or other countries outside the EEA. Where that happens, transfers are protected by the EU Standard Contractual Clauses and/or the provider's certification under the EU–U.S. Data Privacy Framework.

6. Security

Data is encrypted in transit (TLS) and at rest, and access is restricted with row-level isolation so each workspace can only reach its own records. No method of electronic storage is completely secure and we cannot guarantee absolute security, but we protect your data with appropriate technical and organisational measures.

7. Controller and Processor Roles

For the account, usage and contact data of practitioners and team members, we are the controller.

For the client data practitioners enter into the platform, the practitioner is the controller and Kassy is a processor acting on their instructions, under the data processing terms in our Terms of Service. Practitioners are responsible for having a lawful basis to process their clients' data.

8. Information for Clients of Practitioners

If you receive a Kassy-generated invoice or visit a payment or booking page, please note:

  • Your data was entered by your practitioner, who is the controller of it. Questions about why your data is processed, and requests to correct or delete it, are best directed to your practitioner.
  • We display and transmit this data only as instructed by the practitioner and do not use it for any other purpose.
  • Payments are executed by the payment provider on its own hosted checkout - your card details never pass through Kassy.
  • Kassy is not a party to your relationship with the practitioner and does not provide the underlying services.
  • We do not create an account for you. If you believe your data is processed unlawfully, you can also contact us at support@kassy.app or the supervisory authority.

9. Retention and Deletion

We keep your data for as long as your account is active. If you delete your account, we delete personal data and client data within 30 days, except where the law requires longer retention (for example accounting records). Diagnostic logs and error reports are kept for short periods (up to about 90 days). Payment account status records are kept for as long as payments are enabled.

10. Your Rights

Under the GDPR you have the right to:

  • access, correct or delete your personal data;
  • receive your data in a portable format;
  • object to, or ask us to restrict, certain processing;
  • withdraw consent at any time, where processing is based on consent;
  • lodge a complaint with the Bulgarian Commission for Personal Data Protection (cpdp.bg) or your local supervisory authority.

To exercise your rights, email support@kassy.app. We respond within one month.

11. Cookies

Kassy uses cookies that are necessary for signing in, keeping your session and remembering your language. Our analytics tool (PostHog) stores identifiers that help us understand how the product is used. We do not use advertising cookies or tracking pixels.

12. Changes to This Policy

We may update this policy as the Service evolves. We will notify registered users of material changes by email or in the app; the date at the top shows the latest revision.

13. Contact

For questions about this policy or your data, contact us at support@kassy.app.