IEInvoiceEU

Privacy Policy

This notice explains what personal data InvoiceEU collects, why, who else sees it, how long it is kept, and what you can require us to do about it. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679.

Last updated 2026-09-09

Draft — company details pending

The structure and substance of this document are in place, but the operating company’s identity, address and contact details have not been filled in yet. Every outstanding item is marked below. This document is not yet binding and has not been reviewed by a lawyer.

Fill in LEGAL_ENTITY in src/data/legal.ts and this notice disappears.

1. Who is responsible for your data

The controller of the personal data described in this notice is:

Legal entity name
Street and number
Postal code City
Country

Registered in Company register under number Registration number. VAT identification number VAT number.

For any question about this notice or to exercise the rights in section 8, contact privacy@ address.

Data protection officer: DPO name, or none appointed. Whether one is required is assessed under Article 37; where none is appointed, requests go to the address above.

2. Two different roles, and why the difference matters

InvoiceEU handles personal data in two distinct capacities, and your rights differ between them.

As controller, for data about you as our customer: your account, your organization, your billing relationship, and how you use the service. This notice governs that data.

As processor, for data you put into the service about other people — most importantly the contact details of the clients you invoice. There, you are the controller and we act on your instructions. You decide what to enter, how long it stays, and on what lawful basis. Section 10 describes the terms of that arrangement.

3. What we collect

Account data. Your name, email address and a hashed password. If you sign in with Google, we receive your name, email address and Google profile identifier instead of a password. We record when a sign-in attempt fails and when an account is temporarily locked after repeated failures.

Organization data. Your business name, legal name, tax and registration numbers, address, invoice numbering preferences, logo and default currency. Bank details you enter for display on invoices — IBAN and BIC — are encrypted before they are written to the database.

Content you create. Clients, products, invoices, credit notes, and the generated XML and PDF documents. Where a client is a sole trader or a natural person, their name, address and tax number are personal data that you have entrusted to us as processor.

Billing data. Your subscription tier, status, trial and renewal dates, and the identifiers Stripe assigns you. Card numbers are entered on Stripe’s systems and never reach ours.

Technical data. Your IP address, used to apply rate limits and to detect abuse; a session cookie; and server logs of requests and errors.

We do not use tracking or advertising cookies, we do not build advertising profiles, and we do not sell personal data.

4. Why we use it, and on what legal basis

  • To provide the service — creating your account, storing your invoices, generating documents, sending them. Article 6(1)(b), performance of a contract.
  • To take payment — subscriptions, invoices for the service itself, dunning. Article 6(1)(b), performance of a contract.
  • To keep the service secure — rate limiting, account lockout after repeated failed sign-ins, abuse investigation. Article 6(1)(f), our legitimate interest in a service that is not abused, balanced against the limited data involved.
  • To send service messages — password resets, invitations, trial and billing notices. Article 6(1)(b), and Article 6(1)(f) for notices about your own account.
  • To meet our own legal obligations — accounting and tax records relating to what you pay us. Article 6(1)(c), legal obligation.

We do not currently send marketing email. If that changes, it will be on the basis of your consent under Article 6(1)(a), with an unsubscribe link in every message.

5. Who else sees it

We use the service providers below. Each processes personal data only on our instructions under a data processing agreement, and this list is derived from the integrations actually present in the product.

ProviderPurposeDataLocation
VercelApplication hosting and content deliveryEverything submitted to the service, plus request metadata such as IP addressEU / United States
Database hosting (Supabase or Neon)Primary PostgreSQL databaseAccount, organization, client, product and invoice recordsEU region as configured
StripeSubscription billing and payment processingBilling name, email, payment method held by Stripe, subscription stateEU / United States
ResendTransactional email (account, invoice and billing notifications)Recipient email address, message content, delivery metadataEU / United States
Cloudflare R2Storage of uploaded logos and generated invoice documentsUploaded files and generated invoice PDFs and XMLAs configured on the bucket
UpstashShared rate-limit counters and VAT-number lookup cacheHashed request keys, IP-derived identifiers, VAT numbers looked upEU region as configured
GoogleOptional sign-in providerName, email address and profile identifier, only if you choose Google sign-inEU / United States
European Commission VIESValidation of the VAT numbers you enterThe VAT number being checkedEuropean Union
QvaliaDelivery of invoices over the Peppol network, when you use itThe invoice document and the identifiers of both partiesEuropean Union
AnthropicTax-rate research assistant, used on public government sources onlyNo customer or personal data is sentUnited States

We also disclose data where a law or a court requires it, and to professional advisers bound by confidentiality. If the business is ever sold or merged, data may transfer to the acquirer; you would be told before that happened.

6. Transfers outside the EEA

Some providers above process data in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, and where applicable on the provider’s certification under the EU–US Data Privacy Framework. You can request a copy of the safeguards in place by writing to privacy@ address.

7. How long we keep it

  • Account and organization data — for as long as your account exists, then deleted within 90 days of closure.
  • Invoices and the documents generated from them — for as long as your account exists. Note that tax law in your own country will usually require you to retain invoices for six to eleven years; exporting them before you close your account is your responsibility, and the service provides export for exactly that reason.
  • Billing records — for the period our own tax and accounting obligations require, which outlasts your account.
  • Password reset and invitation tokens — short-lived by design; reset links expire after one hour, invitations after seven days.
  • Security and rate-limit records — retained briefly and only as long as needed to make the limit work.

8. Your rights

Under the GDPR you may:

  • ask what personal data we hold about you and receive a copy (Article 15);
  • have inaccurate data corrected (Article 16);
  • have data erased where we no longer have grounds to keep it (Article 17);
  • ask us to restrict processing while a dispute is resolved (Article 18);
  • receive the data you gave us in a portable, machine-readable form (Article 20) — the client, product and invoice export in the application does this directly;
  • object to processing based on our legitimate interests (Article 21);
  • withdraw any consent you have given, without affecting what was done before you withdrew it.

Write to privacy@ address and we will respond within one month, as Article 12(3) requires. If you are not satisfied, you may complain to your local data protection authority, or to ours: Supervisory authority.

9. Security

Traffic is encrypted in transit. Passwords are stored hashed, never in plain text. Bank details are encrypted at rest with AES-256-GCM. Every database query for business records is scoped to your organization at the data-access layer rather than by convention, so one customer’s records are not reachable from another’s session. Access to production systems is limited to people who need it.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours as Article 33 requires, and notify you directly where Article 34 requires it.

10. Data you enter about other people

When you add a client, you decide what to record about them. For that data you are the controller and we are your processor, acting only on your documented instructions. In that capacity we undertake to:

  • process the data only to provide the service to you;
  • keep it confidential and require the same of our staff;
  • apply the security measures described in section 9;
  • engage the sub-processors listed in section 5, and tell you before adding another;
  • help you respond to a data subject who contacts you, and to a supervisory authority;
  • delete or return the data when your account closes.

What you may lawfully enter, and on what basis, is your decision as controller. Invoicing normally rests on contract or legal obligation, but that assessment is yours to make.

11. Children

The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16.

12. Changes to this notice

We may update this notice as the service changes. The date at the top always reflects the last substantive change. If a change materially affects your rights, we will tell you by email before it takes effect.