Privacy Policy
Last updated: 22 July 2026
1. Who we are (data controller)
Invoiz is operated by Fidei BV ("Invoiz", "we"), a company established in Belgium. For questions about this policy or your data, contact us at privacy@invoiz.eu.
When you use Invoiz to send invoices to your own customers, you are the controller of your customers' data and we act as your processor for that content.
2. What data we process
- Account & identity: your name, email, password (hashed), and the companies you manage.
- Company & KYB data: company name, VAT/enterprise number, address, IBAN/BIC, and verification evidence used to confirm you may act for a company.
- Invoicing content: invoices, credit notes, contacts (your customers/suppliers), line items and amounts, and documents received over Peppol.
- Billing data: your subscription and payment status. Card details are handled by Stripe; we do not store card numbers.
- Technical data: log and error events needed to operate and secure the service.
3. Why we process it (purposes & legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the invoicing service & deliver invoices over Peppol/email | Performance of a contract |
| KYB/verification & fraud prevention | Legal obligation / legitimate interest |
| Billing and subscription management | Performance of a contract |
| Keeping legally required invoice records | Legal obligation (VAT/accounting law) |
| Security, debugging, product improvement | Legitimate interest |
4. Processors we use
We share data only with providers that process it on our behalf under data-processing agreements:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file storage (EU region) |
| Scrada | Peppol access point — sending/receiving e-invoices |
| Stripe | Subscription billing and card processing |
| Resend | Transactional email delivery |
| Vercel | Web application hosting |
5. International transfers
We aim to keep data within the EU. Where a processor transfers data outside the EEA, it is covered by EU Standard Contractual Clauses or an equivalent safeguard.
6. How long we keep it
Invoices, credit notes and related accounting records are retained for the period required by Belgian law (currently up to 10 years). Other personal data is kept for as long as your account is active and deleted or anonymised afterwards, subject to those legal retention obligations.
7. Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing. You can export your data and request account deletion from within the app (Settings). Legally required invoice records may be retained even after account deletion. To exercise a right, contact privacy@invoiz.eu. You may also lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit).
8. Security
Access is protected by authentication and row-level security; secrets are stored server-side only; sensitive records (issued invoices, the cashbook) are immutable. No system is perfectly secure, but we take appropriate technical and organisational measures.
9. Changes
We may update this policy; material changes will be notified in-app or by email. Continued use after an update constitutes acceptance.