← Back to home

Personal data policy

Version of 27 August 2026

This document describes what information about a person the safzir service collects, why, how long it is kept, and how to obtain or delete it.

1. Who processes the data

The controller is the owner of the safzir service, operating on the domains safzir.com and safzir.online. Enquiries about data processing are accepted at support@safzir.online.

2. What is collected at signup

When the registration form is filled in, the following is stored: e-mail address, first and last name, company name, country, phone number, expected number of employees, selected modules, and a comment if one is left.

Alongside the application, technical details are stored automatically: the IP address of the request, the browser string (User-Agent), the page the visitor came from, campaign tags (UTM), and the country and city derived from the IP address.

The password itself is not stored. Only an irreversible hash is kept, from which the original password cannot be recovered.

The record of acceptance of the terms and of this policy is stored together with the date, time and document version.

3. What appears during use

Data the customer enters into the system — about their employees, buyers, suppliers and documents — is processed by the operator on the customer instruction and solely to run the service.

For that data the controller is the customer: they determine purposes and retention, while the service acts as a processor.

Actions in the system are written to an audit log: who changed which record and when. The log is used to investigate disputes and is protected against backdating.

4. Why it is needed

Contact details — to review the application, get in touch about the account and send notices about the end of the grace period.

Technical details — to tell genuine applications from automated ones, limit the rate of requests, and understand which channel the customer came from.

Company details — to select a plan and a set of modules.

5. How long it is kept

An application whose e-mail address has not been confirmed is deleted after 14 days, together with the IP address, geodata and password hash.

A rejected application is deleted 30 days after rejection.

An approved application is kept for as long as the organization created from it exists.

After an organization is closed its data is kept for 90 days so that the customer can take an export, and may then be permanently deleted.

Audit log records are kept separately and for longer — they are needed as evidence of actions in disputes.

6. Who it is shared with

Data is not sold and is not passed to third parties for advertising.

Mail is delivered through the operator own mail server; messages travel through the networks of the recipient mail provider.

Data is processed and stored on servers rented by the operator. Traffic between browser and server is encrypted.

7. Rights of the person concerned

You may request what information about you is stored, ask for it to be corrected or deleted, and withdraw your consent to processing.

Withdrawing consent means the application is deleted and, if an organization has already been created, that the service stops — it cannot operate without this information.

Requests are sent to support@safzir.online and answered within 30 days.

8. How data is protected

Passwords are stored as an irreversible hash, connections are encrypted, and operator staff access to customer data is limited and logged.

Different customers data is separated: one customer queries cannot return another customer records.

9. Cookies and browser storage

The site uses no third-party advertising or analytics trackers.

Campaign tags (UTM) and the referring address are kept in browser session storage for the duration of the visit, so that they are not lost when moving between pages and reach the application. They are removed when the tab is closed.

The application at safzir.online uses cookies that are necessary for signing in and keeping the session.

10. Changes to this policy

A new version is published on this page with its date. The version accepted by the customer is stored with their application.