Privacy Policy / PersĂłnuvernarstefna

Last updated: 19 March 2025

This statement explains how FREE‑Iceland ehf. ("FreelancePay", "we", "us") collects, uses, shares, and protects your personal data when you use our invoicing and payout platform. It meets the requirements of the EU General Data Protection Regulation (GDPR), Icelandic Data Protection Act No 90/2018 and relevant e‑Privacy rules.


1. Who We Are (Controller)

Legal entityFREE‑Iceland ehf., kt. 530323‑0130, vsk nr. 148836
Registered officeLaugavegur 13, 101 ReykjavĂ­k, Iceland
Emailinfo@freelancepay.is
Data‑protection officerMaarit Kaipainen – maarit@freelancepay.is
Phone+354 (weekdays 09‑16)
Supervisory authorityPersónuvernd – Icelandic Data Protection Authority
Skipholti 37, 105 ReykjavĂ­k
+354 510 9600
www.personuvernd.is

2. What Personal Data We Collect

2.1 Data you provide

  • Account details – name, email, phone, address.
  • Identity – kennitala (personal ID), electronic‑ID assertions.
  • Payout & tax – bank IBAN, pension‑fund choice, union membership (optional).
  • Invoicing & financial – client names, invoice amounts, expense receipts.

2.2 Data we generate or log

  • Usage logs (Q4 2025 launch) – IP address, device/browser, pages visited, time‑stamps.
  • Cookies – see our Cookie Policy banner for full list.
    • Essential cookies keep the site secure and let you log in.
    • Analytics (opt‑in) cookies help us improve UX. Disabled by default until you consent.

3. Why & How We Use Your Data

PurposeExamplesGDPR legal basis
Provide the ServiceAccount setup, invoicing Wolt, paying salary, supportArt 6 (1)(b) – contract
Legal complianceTax & accounting records, AML checksArt 6 (1)(c) – legal duty
Security & fraudLogin monitoring, incident logsArt 6 (1)(f) – legitimate interest
Product analytics (future)Aggregate traffic statsArt 6 (1)(a) – consent
Direct marketingNewsletters about new featuresArt 6 (1)(a) – consent (opt‑in)
Data sharing/sale to third partiesLead‑generation listsOnly after explicit opt‑in consent (Art 6 (1)(a))
Automated decision‑making (future)Fraud‑risk scoringArt 6 (1)(f) + Art 22 safeguards & human review

Right to object: You can opt out of any processing based on legitimate interest or withdraw marketing consent at any time in Account › Privacy Settings or by emailing us.


4. Who Receives Your Data

  • Payment & infrastructure partners – Supabase (hosting), Rapyd (payout rails), Authentise (e‑ID). All under GDPR‑compliant Data‑Processing Agreements.
  • Professional advisors & auditors – for statutory accounting.
  • Public authorities – RSK, police or courts when legally obliged.
  • Third‑party marketers / research firms – only if you have opted in.

5. International Transfers

All primary storage is in the EEA. If we need to move data outside the EEA (e.g., US analytics vendor) we will use Standard Contractual Clauses and list the vendor under Who Receives Your Data.


6. Retention Periods

Data categoryRetention
Financial & accounting records7 years after the end of the fiscal year (Accounting Act 3/2006)
User account profileUntil you delete your account or 2 years of inactivity
Marketing consent logs5 years (accountability requirement)
Support tickets & chat3 years from closure
Usage logs12 months (or shorter if you disable analytics)

We may keep backups for up to 30 days beyond these periods for disaster‑recovery.


7. Your Rights

You may access, rectify, erase, restrict, port, or object to our processing of your personal data. To exercise rights, email maarit@freelancepay.is. We will respond within 1 month (extendable by 2 months for complex requests). You can lodge complaints with PersĂłnuvernd.

We do not knowingly offer services to persons under 18. If we learn that we hold data about a minor, we will delete it promptly.


8. Data Security

  • AES‑256 encryption at rest, TLS 1.2+ in transit.
  • Per‑row access controls (Supabase RLS).
  • Annual external penetration test & planned ISO‑27001 certification.

If a breach likely affects your rights, we will notify you and PersĂłnuvernd without undue delay.


9. Changes

Material updates will be announced via email and an in‑app banner at least 14 days before taking effect. Older versions are archived here.


10. Contact

Questions or requests?

đź“§ info@freelancepay.is

📞 +354 XXX XXXX

📮 FREE‑Iceland ehf., Laugavegur 13, 101 Reykjavík, Iceland


© 2025 FREE‑Iceland ehf. All rights reserved.