Privacy Policy
This notice explains what personal data InvoiceEU collects, why, who else sees it, how long it is kept, and what you can require us to do about it. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679.
Last updated 2026-09-09
Draft — company details pending
The structure and substance of this document are in place, but the operating company’s identity, address and contact details have not been filled in yet. Every outstanding item is marked below. This document is not yet binding and has not been reviewed by a lawyer.
Fill in LEGAL_ENTITY in src/data/legal.ts and this notice disappears.
1. Who is responsible for your data
The controller of the personal data described in this notice is:
Registered in Company register under number Registration number. VAT identification number VAT number.
For any question about this notice or to exercise the rights in section 8, contact privacy@ address.
Data protection officer: DPO name, or none appointed. Whether one is required is assessed under Article 37; where none is appointed, requests go to the address above.
2. Two different roles, and why the difference matters
InvoiceEU handles personal data in two distinct capacities, and your rights differ between them.
As controller, for data about you as our customer: your account, your organization, your billing relationship, and how you use the service. This notice governs that data.
As processor, for data you put into the service about other people — most importantly the contact details of the clients you invoice. There, you are the controller and we act on your instructions. You decide what to enter, how long it stays, and on what lawful basis. Section 10 describes the terms of that arrangement.
3. What we collect
Account data. Your name, email address and a hashed password. If you sign in with Google, we receive your name, email address and Google profile identifier instead of a password. We record when a sign-in attempt fails and when an account is temporarily locked after repeated failures.
Organization data. Your business name, legal name, tax and registration numbers, address, invoice numbering preferences, logo and default currency. Bank details you enter for display on invoices — IBAN and BIC — are encrypted before they are written to the database.
Content you create. Clients, products, invoices, credit notes, and the generated XML and PDF documents. Where a client is a sole trader or a natural person, their name, address and tax number are personal data that you have entrusted to us as processor.
Billing data. Your subscription tier, status, trial and renewal dates, and the identifiers Stripe assigns you. Card numbers are entered on Stripe’s systems and never reach ours.
Technical data. Your IP address, used to apply rate limits and to detect abuse; a session cookie; and server logs of requests and errors.
We do not use tracking or advertising cookies, we do not build advertising profiles, and we do not sell personal data.
4. Why we use it, and on what legal basis
- To provide the service — creating your account, storing your invoices, generating documents, sending them. Article 6(1)(b), performance of a contract.
- To take payment — subscriptions, invoices for the service itself, dunning. Article 6(1)(b), performance of a contract.
- To keep the service secure — rate limiting, account lockout after repeated failed sign-ins, abuse investigation. Article 6(1)(f), our legitimate interest in a service that is not abused, balanced against the limited data involved.
- To send service messages — password resets, invitations, trial and billing notices. Article 6(1)(b), and Article 6(1)(f) for notices about your own account.
- To meet our own legal obligations — accounting and tax records relating to what you pay us. Article 6(1)(c), legal obligation.
We do not currently send marketing email. If that changes, it will be on the basis of your consent under Article 6(1)(a), with an unsubscribe link in every message.
5. Who else sees it
We use the service providers below. Each processes personal data only on our instructions under a data processing agreement, and this list is derived from the integrations actually present in the product.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Vercel | Application hosting and content delivery | Everything submitted to the service, plus request metadata such as IP address | EU / United States |
| Database hosting (Supabase or Neon) | Primary PostgreSQL database | Account, organization, client, product and invoice records | EU region as configured |
| Stripe | Subscription billing and payment processing | Billing name, email, payment method held by Stripe, subscription state | EU / United States |
| Resend | Transactional email (account, invoice and billing notifications) | Recipient email address, message content, delivery metadata | EU / United States |
| Cloudflare R2 | Storage of uploaded logos and generated invoice documents | Uploaded files and generated invoice PDFs and XML | As configured on the bucket |
| Upstash | Shared rate-limit counters and VAT-number lookup cache | Hashed request keys, IP-derived identifiers, VAT numbers looked up | EU region as configured |
| Optional sign-in provider | Name, email address and profile identifier, only if you choose Google sign-in | EU / United States | |
| European Commission VIES | Validation of the VAT numbers you enter | The VAT number being checked | European Union |
| Qvalia | Delivery of invoices over the Peppol network, when you use it | The invoice document and the identifiers of both parties | European Union |
| Anthropic | Tax-rate research assistant, used on public government sources only | No customer or personal data is sent | United States |
We also disclose data where a law or a court requires it, and to professional advisers bound by confidentiality. If the business is ever sold or merged, data may transfer to the acquirer; you would be told before that happened.
6. Transfers outside the EEA
Some providers above process data in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, and where applicable on the provider’s certification under the EU–US Data Privacy Framework. You can request a copy of the safeguards in place by writing to privacy@ address.
7. How long we keep it
- Account and organization data — for as long as your account exists, then deleted within 90 days of closure.
- Invoices and the documents generated from them — for as long as your account exists. Note that tax law in your own country will usually require you to retain invoices for six to eleven years; exporting them before you close your account is your responsibility, and the service provides export for exactly that reason.
- Billing records — for the period our own tax and accounting obligations require, which outlasts your account.
- Password reset and invitation tokens — short-lived by design; reset links expire after one hour, invitations after seven days.
- Security and rate-limit records — retained briefly and only as long as needed to make the limit work.
8. Your rights
Under the GDPR you may:
- ask what personal data we hold about you and receive a copy (Article 15);
- have inaccurate data corrected (Article 16);
- have data erased where we no longer have grounds to keep it (Article 17);
- ask us to restrict processing while a dispute is resolved (Article 18);
- receive the data you gave us in a portable, machine-readable form (Article 20) — the client, product and invoice export in the application does this directly;
- object to processing based on our legitimate interests (Article 21);
- withdraw any consent you have given, without affecting what was done before you withdrew it.
Write to privacy@ address and we will respond within one month, as Article 12(3) requires. If you are not satisfied, you may complain to your local data protection authority, or to ours: Supervisory authority.
9. Security
Traffic is encrypted in transit. Passwords are stored hashed, never in plain text. Bank details are encrypted at rest with AES-256-GCM. Every database query for business records is scoped to your organization at the data-access layer rather than by convention, so one customer’s records are not reachable from another’s session. Access to production systems is limited to people who need it.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours as Article 33 requires, and notify you directly where Article 34 requires it.
10. Data you enter about other people
When you add a client, you decide what to record about them. For that data you are the controller and we are your processor, acting only on your documented instructions. In that capacity we undertake to:
- process the data only to provide the service to you;
- keep it confidential and require the same of our staff;
- apply the security measures described in section 9;
- engage the sub-processors listed in section 5, and tell you before adding another;
- help you respond to a data subject who contacts you, and to a supervisory authority;
- delete or return the data when your account closes.
What you may lawfully enter, and on what basis, is your decision as controller. Invoicing normally rests on contract or legal obligation, but that assessment is yours to make.
11. Children
The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
12. Changes to this notice
We may update this notice as the service changes. The date at the top always reflects the last substantive change. If a change materially affects your rights, we will tell you by email before it takes effect.