Account data
We are controller
Names, email addresses, sign-in events, and audit records of people who use the service. That processing is described in the Privacy Policy.
Trust
Accounting firms send us documents that belong to their clients. For that content we act as processor. The Data Processing Agreement forms part of the Terms of Service and is published on this site.
Account data
Names, email addresses, sign-in events, and audit records of people who use the service. That processing is described in the Privacy Policy.
Document content
Personal data in the invoices you upload: names, addresses, and identifiers of suppliers, buyers, and their representatives. You determine the purposes. We process only on your instructions, under the DPA.
Account processing is in the Privacy Policy . Document processing is in the DPA .
The subprocessors engaged for personal data in documents are listed here and on a dedicated page. We will notify you at least 30 days before adding or replacing one.
| Subprocessor | Purpose | Data processed | Location | Transfer basis |
|---|---|---|---|---|
| netcup GmbH, Germany | Hosting and infrastructure for all services, the database, and object storage | All personal data processed under the DPA, at rest | Germany | Not applicable — within the EU |
| OpenAI | Extraction of data from documents by machine learning models | Content of uploaded documents, including any personal data it contains | European Union and United States | Standard Contractual Clauses under the subprocessor's data processing addendum |
| Sendinblue SAS, trading as Brevo, France | Transactional email delivery | Email addresses and names of your users. No document content. | France | Not applicable — within the EU |
The English DPA Annex III is the binding list.
The object storage, database, identity provider, and observability tooling run on our infrastructure. They are not separate subprocessors. The payment provider is not a subprocessor under the DPA; billing is described in the Privacy Policy.
Documents at rest are stored in the European Union, on infrastructure in Germany.
The only processing that leaves the EEA is inference: document content is sent to our AI subprocessor to extract data.
We do not use your documents, extracted data, or output files to train machine learning models. Logging of prompts and model outputs at the AI provider is disabled.
Boundary
The organisation is the isolation boundary. A user of one organisation cannot address the documents, results, or exports of another.
Our personnel
Personnel acting as supervisors may view documents in your organisation and may correct extracted data. Review is part of the service, not an exception to it.
Our personnel
Personnel acting in support have read access only. They cannot change extracted values.
Uploads, corrections, exports, deletions, and support access are recorded in an append-only audit log.
Deleting a document or an organisation removes it from the interface immediately. Irreversible deletion from our databases and object storage follows one year later. Audit-log entries that record actions on a document are retained after that deletion.
You may export extracted data and output files during the term and for 30 days after termination.