Privacy Policy
Version: 1.0 · Effective date: __[set on publication]__
This Privacy Policy explains how AIS TECH LIMITED handles personal data in connection with the Bizalma e-invoicing service.
1. Controller
AIS TECH LIMITED, registration number HE 494533, Ifigeneias 14, Limassol 3036, Cyprus, is the controller for the processing described in this Policy.
Data protection contact: privacy@bizalma.com.
2. Two distinct roles
The distinction below determines which document applies to which data, and it matters.
We are controller for personal data in account and administrative records: the people who register, sign in, and administer an Organisation, and the records of what they did. This Policy describes that processing.
We are processor for personal data contained in the documents our customers upload — the names, addresses, contact details, and identifiers of suppliers, buyers, and their representatives that appear on an invoice. For that data the customer is the controller, we act on the customer’s instructions, and the terms of processing are set out in the Data Processing Agreement. This Policy does not govern that processing, and we do not decide the purposes of it.
3. What we process as controller
| Category | Data |
|---|---|
| Identity and contact | Username, email address, first and last name |
| Authentication | Credentials managed by our identity provider (passwords are stored only as cryptographic hashes), email verification state, sign-in and sign-out events, password reset and email change events |
| Account configuration | Role, account status, interface language, Organisation membership and ownership |
| Organisation and billing records | Organisation name, jurisdiction, registration identifier, value added tax identification number and the result of its verification, legal name, billing contact and address, usage counts, and issued invoices |
| Payment and transaction records | Name of the cardholder, billing address, the card brand and last four digits, transaction, refund and chargeback identifiers, and the history of top-ups, deductions, and balance. We do not receive or store full card numbers — card details are entered directly with our payment provider |
| Activity records | An audit log of actions taken in the Service, recording the acting user, the object acted on, the action, and the time |
| Support correspondence | Messages you send us and our replies |
| Technical records | Server and application logs, including network address and request metadata, generated when you use the Platform |
We do not ask for and do not require special categories of personal data about our users.
4. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and administering your account and Organisation; providing the Service | Performance of a contract, Article 6(1)(b) GDPR |
| Sending transactional messages: email verification, password reset, notifications about your documents | Performance of a contract, Article 6(1)(b) |
| Metering usage, maintaining the prepaid balance, taking card payments, issuing invoices, making refunds | Performance of a contract, Article 6(1)(b) |
| Keeping accounting and tax records, verifying value added tax identification numbers in order to determine the tax treatment of a payment | Legal obligation, Article 6(1)(c) |
| Preventing and investigating payment fraud and reversed payments | Legitimate interests, Article 6(1)(f), and legal obligation where it applies to our payment provider |
| Security, abuse prevention, and keeping an audit trail of actions in the Service | Legitimate interests, Article 6(1)(f) — our interest in operating a secure and accountable service, and our customers’ interest in being able to establish who did what |
| Establishing, exercising, and defending legal claims | Legitimate interests, Article 6(1)(f) |
We do not use your personal data for advertising, and we do not sell it.
5. Automated decision-making
The Service applies machine learning models to the content of uploaded documents in order to extract data from them. It does not use them to take decisions about individuals, and there is no automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.
6. Who receives the data
We share personal data only with the processors we engage to run the Service.
| Recipient | Role | Location |
|---|---|---|
| netcup GmbH | Hosting and infrastructure; all data is stored on servers we operate at this provider | Germany |
| Sendinblue SAS, trading as Brevo | Transactional email delivery; receives email addresses and names, and never the content of documents | France |
| Stripe Payments Europe, Limited | Card payment processing, refunds, and payment fraud prevention; receives payment and billing data, and never the content of documents. Stripe also acts as a controller in its own right for fraud prevention and for its own regulatory obligations | Ireland, with onward transfers under Stripe’s own safeguards |
| OpenAI | Extraction from document content; relevant to the processing described in the Data Processing Agreement, not to account data | European Union and United States |
Account data described in this Policy is stored within the European Union and is not transferred to OpenAI. Payment and billing data is shared with our payment provider in Ireland; where that provider transfers it outside the European Economic Area, it does so under its own transfer safeguards.
We may disclose data to a competent authority where we are legally required to do so, and to professional advisers under a duty of confidentiality. Where our business is reorganised, merged, or sold, data may be transferred to the successor, which remains bound by this Policy or an equivalent one.
7. Cookies and local storage
We use no analytics, advertising, or tracking technologies, and we embed no third-party trackers. For that reason the Platform does not present a cookie consent banner.
Our identity provider sets cookies on the authentication domain that are strictly necessary to establish and maintain your signed-in session, and the administrative interface sets a session cookie that is discarded when you sign out. Your browser’s local storage holds interface preferences only — panel layout, sort order, page size, and default export formats — which we do not read for any other purpose.
8. How long we keep it
Account data is kept for as long as the account exists. When an account or an Organisation is deleted, the record is first placed in a deleted state and is then irreversibly deleted, together with the associated documents and files, on expiry of the retention period for deleted data, which is one year.
Audit log entries are retained after that deletion. They are the record of who acted in the Service and when, they are what allows us and our customers to reconstruct the handling of a document, and they are retained for the duration of the relationship and thereafter for as long as necessary for the establishment, exercise, or defence of legal claims.
Accounting, invoicing, and payment records, including the history of top-ups and deductions from the prepaid balance, are retained for the period required by applicable tax and accounting law, irrespective of the deletion of an Organisation.
9. Your rights
Subject to the conditions in the GDPR, you have the right to obtain access to your personal data, to have inaccurate data rectified, to have data erased, to have processing restricted, to receive data in a portable form, and to object to processing carried out on the basis of legitimate interests.
Exercise these rights by writing to privacy@bizalma.com. We respond within one month and may extend that period where the request is complex, in which case we will tell you.
Where you are an employee or representative of a customer and your request concerns data contained in that customer’s documents, we will refer you to that customer, who is the controller for it. We do so because we may not act on such data other than on the customer’s instructions.
You may lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or with the supervisory authority of the member state in which you live or work.
10. Security
We restrict access to personal data to personnel who need it in order to deliver and support the Service, each bound by confidentiality obligations. Access to customer documents by our personnel is recorded in the audit log. All data is encrypted in transit. Administrative access to our infrastructure requires individual accounts, and administrative actions in our artificial intelligence provider’s environment are logged.
The measures we apply to document content are described in the Data Processing Agreement.
11. Changes to this Policy
We may amend this Policy. We will publish the amended version with a new version number and effective date and, where the change is material, notify account holders in advance.
12. Language
The English version of this Policy is the authoritative version. Any translation is provided for convenience only; in the event of any discrepancy, the English version prevails.