Privacy Policy / PersĂłnuvernarstefna
Last updated: 19 March 2025
This statement explains how FREE‑Iceland ehf. ("FreelancePay", "we", "us") collects, uses, shares, and protects your personal data when you use our invoicing and payout platform. It meets the requirements of the EU General Data Protection Regulation (GDPR), Icelandic Data Protection Act No 90/2018 and relevant e‑Privacy rules.
1. Who We Are (Controller)
Legal entity | FREE‑Iceland ehf., kt. 530323‑0130, vsk nr. 148836 |
Registered office | Laugavegur 13, 101 ReykjavĂk, Iceland |
info@freelancepay.is | |
Data‑protection officer | Maarit Kaipainen – maarit@freelancepay.is |
Phone | +354 (weekdays 09‑16) |
Supervisory authority | Persónuvernd – Icelandic Data Protection Authority |
Skipholti 37, 105 ReykjavĂk +354 510 9600 www.personuvernd.is |
2. What Personal Data We Collect
2.1 Data you provide
- Account details – name, email, phone, address.
- Identity – kennitala (personal ID), electronic‑ID assertions.
- Payout & tax – bank IBAN, pension‑fund choice, union membership (optional).
- Invoicing & financial – client names, invoice amounts, expense receipts.
2.2 Data we generate or log
- Usage logs (Q4 2025 launch) – IP address, device/browser, pages visited, time‑stamps.
- Cookies – see our Cookie Policy banner for full list.
- Essential cookies keep the site secure and let you log in.
- Analytics (opt‑in) cookies help us improve UX. Disabled by default until you consent.
3. Why & How We Use Your Data
Purpose | Examples | GDPR legal basis |
---|---|---|
Provide the Service | Account setup, invoicing Wolt, paying salary, support | Art 6 (1)(b) – contract |
Legal compliance | Tax & accounting records, AML checks | Art 6 (1)(c) – legal duty |
Security & fraud | Login monitoring, incident logs | Art 6 (1)(f) – legitimate interest |
Product analytics (future) | Aggregate traffic stats | Art 6 (1)(a) – consent |
Direct marketing | Newsletters about new features | Art 6 (1)(a) – consent (opt‑in) |
Data sharing/sale to third parties | Lead‑generation lists | Only after explicit opt‑in consent (Art 6 (1)(a)) |
Automated decision‑making (future) | Fraud‑risk scoring | Art 6 (1)(f) + Art 22 safeguards & human review |
Right to object: You can opt out of any processing based on legitimate interest or withdraw marketing consent at any time in Account › Privacy Settings or by emailing us.
4. Who Receives Your Data
- Payment & infrastructure partners – Supabase (hosting), Rapyd (payout rails), Authentise (e‑ID). All under GDPR‑compliant Data‑Processing Agreements.
- Professional advisors & auditors – for statutory accounting.
- Public authorities – RSK, police or courts when legally obliged.
- Third‑party marketers / research firms – only if you have opted in.
5. International Transfers
All primary storage is in the EEA. If we need to move data outside the EEA (e.g., US analytics vendor) we will use Standard Contractual Clauses and list the vendor under Who Receives Your Data.
6. Retention Periods
Data category | Retention |
---|---|
Financial & accounting records | 7 years after the end of the fiscal year (Accounting Act 3/2006) |
User account profile | Until you delete your account or 2 years of inactivity |
Marketing consent logs | 5 years (accountability requirement) |
Support tickets & chat | 3 years from closure |
Usage logs | 12 months (or shorter if you disable analytics) |
We may keep backups for up to 30 days beyond these periods for disaster‑recovery.
7. Your Rights
You may access, rectify, erase, restrict, port, or object to our processing of your personal data. To exercise rights, email maarit@freelancepay.is. We will respond within 1 month (extendable by 2 months for complex requests). You can lodge complaints with PersĂłnuvernd.
We do not knowingly offer services to persons under 18. If we learn that we hold data about a minor, we will delete it promptly.
8. Data Security
- AES‑256 encryption at rest, TLS 1.2+ in transit.
- Per‑row access controls (Supabase RLS).
- Annual external penetration test & planned ISO‑27001 certification.
If a breach likely affects your rights, we will notify you and PersĂłnuvernd without undue delay.
9. Changes
Material updates will be announced via email and an in‑app banner at least 14 days before taking effect. Older versions are archived here.
10. Contact
Questions or requests?
đź“§ info@freelancepay.is
📞 +354 XXX XXXX
đź“® FREE‑Iceland ehf., Laugavegur 13, 101 ReykjavĂk, Iceland
© 2025 FREE‑Iceland ehf. All rights reserved.