Privacy policy
This policy explains how we process personal data on the Torevo website and in Shopify apps, including Torevo • KROS Fakturácia.
Last updated: 29 July 20261. Who processes data
The controller of the website, business contacts and Torevo’s own accounts is mespi s.r.o., registered office Východná 4, 949 01 Nitra, Slovenská republika, company ID 52004040, tax ID 2120859554, VAT ID SK2120859554, EORI SK2120859554, Obchodný register Okresného súdu Nitra, oddiel Sro, vložka 46751/N. Contact: torevo@torevo.tech, +421 948 856 685. For customer data processed by an app under a merchant’s instructions, the merchant generally acts as controller and mespi s.r.o. as processor under the DPA.
2. Website and business-contact data
When you visit the website, we may process essential request and security data. If you contact us, we process your name, work email, company or store, URL, selected topic and message. Do not send passwords, API keys or customer data.
3. Data in Shopify apps
Depending on the enabled product, we may process Shopify store and administrator identity, permissions and subscription state, order and transaction data, customer or recipient name, address, email and telephone, company and billing details, Shopify and connected-provider identifiers, document state, PDFs, encrypted credentials and technical, security and audit records. Scope is limited to data required for the enabled workflow.
4. Purposes and legal bases
We use contact data to respond and take pre-contract steps. Merchant account data is processed to perform the contract, bill, support and secure the service. Customer data in an app is processed under the merchant’s documented instructions and the DPA. Essential security and audit records support our legitimate interest in protecting the service, preventing duplicates and evidencing operations. We retain data where required by law.
5. KROS Fakturácia
After the merchant connects its KROS account, the app transfers to KROS only the data required to create or reconcile a document, payment and PDF under the merchant’s settings. The merchant controls the KROS account, API access and accounting content. Torevo does not use this data for its own marketing or disclose it to another merchant.
6. Recipients and transfers
Hosting, email delivery and operations use only providers listed on the Subprocessors page. Shopify, KROS or a carrier may be a separate platform or merchant-selected recipient rather than a Torevo subprocessor. A transfer outside the EEA takes place only under an adequacy decision, the Data Privacy Framework, Standard Contractual Clauses or another valid mechanism.
7. Retention periods
Default technical maximums are: webhooks and jobs 30 days, provider callbacks 90 days, security audit records 365 days, refund-review records 365 days, backups 30 days, and document metadata or encrypted PDFs up to 2,555 days unless the merchant removes them earlier and law or a legal claim does not require retention. Contact correspondence is kept while handled and for a reasonable follow-up period, normally no longer than 24 months without an active contract.
8. Uninstall and Shopify requests
After uninstall, we block further routine processing and start the applicable retention or deletion process. Mandatory Shopify customers/data_request, customers/redact and shop/redact webhooks are used to export, anonymise or delete data for the relevant store. Data retained for a legal obligation or claim is isolated from routine processing.
9. Sale, advertising and automated decisions
We do not sell or rent personal data, use it for behavioural advertising or use it to train general-purpose artificial-intelligence models. The app does not make solely automated decisions producing legal or similarly significant effects for a customer. We do not knowingly collect children’s data.
10. Your rights
Subject to GDPR conditions, you may request access, correction, erasure, restriction or portability, or object to processing based on legitimate interests. If a request concerns customer data in a Shopify app, contact the relevant merchant first. Torevo will provide the merchant with appropriate assistance. We may reasonably verify the requester’s identity.
11. Supervisory authority
You may lodge a complaint with Úrad na ochranu osobných údajov Slovenskej republiky, Galvaniho 7/B, 821 04 Bratislava. This does not affect your right to contact another competent authority under GDPR.
12. Cookies and analytics
The website uses only technical elements required to deliver and secure it. Optional analytics and marketing tools are not enabled. Before any such tool is enabled, we will update this policy and implement the required consent controls.
13. Security and incidents
We use encrypted communications, encryption of sensitive secrets and documents, tenant separation, access controls, audit records, production/test separation, limited backup retention and an incident-response procedure. As processor, we notify the affected merchant of a confirmed personal-data breach without undue delay.
14. Contact and changes
Send requests to torevo@torevo.tech. Identify the store and provide enough context, but do not send passwords or API keys. Material changes are published with a new effective date and, for an active contract, notified through an appropriate channel.