MT940 Toolkit
Privacy policy
MT940 Toolkit privacy policy for the mt940toolkit.com and wyciag.com domains.MT940 Toolkit Privacy Policy
Last updated: June 8, 2026
1. Data controller
- The personal data controller is Smartbusiness sp. z o.o., Oginskiego 2/10, 85-236 Bydgoszcz, Poland, NIP 5542964866, REGON 380078217, KRS 0000730289.
- The Controller can be contacted by e-mail at kontakt@smartbusiness.pl or support@mt940toolkit.com.
- This Policy describes data processing in MT940 Toolkit available at mt940toolkit.com and wyciag.com.
2. Main rule: the MT940 file stays in the browser
- In the standard app flow, MT940 file content is read, decoded, parsed, filtered, split, and exported locally in the User's browser.
- The Controller does not receive or store MT940 file content to perform the tool's basic functions.
- In particular, in the standard flow we do not send to our backend the content of :61: or :86: sections, account numbers, amounts, contractors, transfer titles, or raw statement text.
- If the User sends an MT940 file to the Controller in support correspondence, a complaint, or a bug report, data from that file will be processed only to handle that correspondence. Users should not send bank files unless necessary.
3. Data stored locally in the browser
- The app may store locally in the User's browser data needed for convenient use, especially active document, file history, table settings, column visibility and widths, active filters, document hashes, and the Free Plan limit counter.
- This data may be stored in localStorage, IndexedDB, or similar browser storage mechanisms.
- Local data remains on the User's device. The Controller has no access to it unless the User sends it, for example in support correspondence.
- The User may delete local data from the app interface if the feature allows it or by clearing browser storage.
- Using public, shared, or work devices may increase the risk that other people access data stored locally in the browser.
4. Categories of personal data
- When using the Service, we may process technical data necessary for operation and security, such as IP address, browser type, operating system, session identifiers, technical logs, and error information.
- In connection with a Pro Plan purchase, we may process order data such as name, e-mail address, purchased service name, amount, currency, payment status, access period, order ID, and technical transaction identifiers.
- When contacting the Controller, we may process e-mail address, name, message content, and data needed to handle a request, complaint, or withdrawal.
- The automated purchase path is intended for Consumers and does not allow entering a buyer tax ID or business invoice data. We do not process the Customer's tax ID as buyer data in this path.
- We do not require special categories of personal data such as health, political views, religion, or sexual orientation data.
5. Purposes and legal bases of processing
- Providing the Service and its functions: Article 6(1)(b) GDPR if processing is needed to provide an electronic service, or Article 6(1)(f) GDPR, our legitimate interest in ensuring Service operation.
- Handling Pro Plan purchases, payments, and access: Article 6(1)(b) GDPR.
- Accounting, tax, and consumer obligations: Article 6(1)(c) GDPR.
- Handling complaints, withdrawals, and inquiries: Article 6(1)(b), (c), or (f) GDPR depending on the matter.
- Security, technical diagnostics, and abuse prevention: Article 6(1)(f) GDPR.
- Own marketing, if implemented: Article 6(1)(f) GDPR or Article 6(1)(a) GDPR if consent is required.
- Establishing claims and defending against claims: Article 6(1)(f) GDPR.
6. EasyCart, Easytools, and Stripe
- We use Easytools tools, especially EasyCart, to handle orders, payments, purchase confirmations, customer panel, and Pro access.
- EasyCart may use Stripe or other payment methods available in the order form.
- In connection with an order, Customer data may be transferred to Easytools and Stripe as necessary to handle the order, payment, refund, complaint, abuse prevention, and Pro access maintenance.
- Transferred data may include name, e-mail address, order ID, service name, amount, currency, payment status, and technical transaction identifiers.
- EasyCart, Easytools, and Stripe do not receive MT940 file content from us in the standard app flow.
7. Hosting, security, and technical logs
- The Service may be hosted using infrastructure, CDN, and security providers, in particular Cloudflare or equivalent providers.
- Infrastructure providers may process technical data such as IP address, request headers, browser information, request time, and security logs.
- Technical logs are used to ensure Service operation, protect against abuse, diagnose failures, and secure infrastructure.
- Technical logs should not contain MT940 file content because files are not sent to the server in the standard app flow.
8. Analytics, diagnostics, and marketing
- The product assumption is no analytics over bank document content.
- If we implement analytics or diagnostics, they should not include MT940 file content, :61: or :86: sections, account numbers, amounts, contractors, or transfer titles.
- Analytics may include only technical and product metadata, such as visited subpage, CTA click, plan type, error information without statement content, or general feature usage statistics.
- If law requires consent for analytics or marketing cookies, we will use them according to the User's consent settings.
9. Cookies and similar technologies
- The Service may use cookies, localStorage, IndexedDB, and similar technologies.
- Necessary technologies are used for Service operation, Pro access protection, remembering settings, payment handling, and security.
- EasyCart may use cookies or similar technologies to handle checkout, login, customer panel, and active access verification.
- The User can manage cookies in browser settings. Disabling necessary cookies, JavaScript, or local storage may make some Service functions difficult or impossible to use.
10. Data recipients
- Personal data may be transferred to entities supporting us in operating the Service and providing Digital Services, especially hosting, CDN, IT infrastructure, sales system, payment, e-mail, customer support, accounting, legal, and advisory providers.
- Data may also be disclosed to public authorities if required by law.
- We do not transfer data to couriers for physical product delivery because the Service sells only Digital Services.
11. Transfers outside the EEA
- Some providers, especially infrastructure, payment, checkout, e-mail, or analytics providers, may process data outside the European Economic Area.
- In that case, mechanisms required by data protection law apply, especially European Commission adequacy decisions, standard contractual clauses, or other legally permitted safeguards.
12. Data retention period
- Technical data related to Service use is stored for the time necessary to ensure operation, security, diagnostics, and request handling.
- Data related to orders, payments, and Pro access is stored for the agreement performance period and then for the period required by law or the limitation period for claims.
- Accounting and tax document data is stored for periods required by accounting and tax law.
- Correspondence, complaint, and withdrawal data is stored for the handling period and then for the limitation period for claims.
- Data processed based on consent is stored until consent is withdrawn unless another legal basis for further processing exists.
- Data stored locally in the browser is kept on the User's device until removed by the User, the app, or the browser.
13. User rights
- The User has the right to access data, obtain a copy, rectify data, delete data, restrict processing, transfer data, object to processing based on legitimate interest, object to marketing, withdraw consent, and lodge a complaint with the President of the Personal Data Protection Office.
- To exercise rights, contact kontakt@smartbusiness.pl or support@mt940toolkit.com.
- Some rights may be limited by law, especially when processing is needed to establish, pursue, or defend claims or meet legal obligations.
14. Voluntary provision of data
- Providing data required to use the Service, place an order, pay, or contact us is voluntary but may be necessary to perform those activities.
- Failure to provide required data may prevent using some Service functions, purchasing Pro, receiving access, or handling a request.
15. Automated decisions and profiling
- We do not make decisions producing legal effects for the User or similarly significantly affecting the User based solely on automated processing of MT940 file content.
- EasyCart, Stripe, or other payment providers may use automated anti-fraud and risk mechanisms under their own rules.
- If marketing or product profiling is implemented, it should not include bank document content.
16. Security
- We apply organisational and technical measures appropriate to Service type and processing risk.
- Local browser processing limits exposure of MT940 files but does not remove risks related to the User's device, browser extensions, malware, or shared access.
- The User should use an up-to-date browser, trusted device, and secure network, and should remove local data after work where needed.
17. Changes to the Privacy Policy
- We may update this Policy, especially after legal, technical, provider, payment, analytics, or Service-function changes.
- The current version of the Policy is available in the Service.