Privacy Policy

Last updated: 22 July 2026

Template — have this reviewed by a lawyer before launch. This describes how Invoiz processes personal data under the EU GDPR. It is a starting point, not legal advice.

1. Who we are (data controller)

Invoiz is operated by Fidei BV ("Invoiz", "we"), a company established in Belgium. For questions about this policy or your data, contact us at privacy@invoiz.eu.

When you use Invoiz to send invoices to your own customers, you are the controller of your customers' data and we act as your processor for that content.

2. What data we process

3. Why we process it (purposes & legal bases)

PurposeLegal basis (GDPR Art. 6)
Provide the invoicing service & deliver invoices over Peppol/emailPerformance of a contract
KYB/verification & fraud preventionLegal obligation / legitimate interest
Billing and subscription managementPerformance of a contract
Keeping legally required invoice recordsLegal obligation (VAT/accounting law)
Security, debugging, product improvementLegitimate interest

4. Processors we use

We share data only with providers that process it on our behalf under data-processing agreements:

ProviderPurpose
SupabaseDatabase, authentication and file storage (EU region)
ScradaPeppol access point — sending/receiving e-invoices
StripeSubscription billing and card processing
ResendTransactional email delivery
VercelWeb application hosting

5. International transfers

We aim to keep data within the EU. Where a processor transfers data outside the EEA, it is covered by EU Standard Contractual Clauses or an equivalent safeguard.

6. How long we keep it

Invoices, credit notes and related accounting records are retained for the period required by Belgian law (currently up to 10 years). Other personal data is kept for as long as your account is active and deleted or anonymised afterwards, subject to those legal retention obligations.

7. Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing. You can export your data and request account deletion from within the app (Settings). Legally required invoice records may be retained even after account deletion. To exercise a right, contact privacy@invoiz.eu. You may also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit).

8. Security

Access is protected by authentication and row-level security; secrets are stored server-side only; sensitive records (issued invoices, the cashbook) are immutable. No system is perfectly secure, but we take appropriate technical and organisational measures.

9. Changes

We may update this policy; material changes will be notified in-app or by email. Continued use after an update constitutes acceptance.