einvoicecheck
Menu

Privacy Policy

Document version 2026-07-16-v2 · effective 2026-07-16.

Who we are

The einvoicecheck.eu service (einvoicecheck) is the data controller for account and operational data described here. Contact: privacy@einvoicecheck.eu. Registered business details are published on /legal/impressum before paid checkout opens.

Summary

We do not store your invoice XML. Payloads are processed in memory for validation and discarded. We do store account data, usage metadata, and limited operational logs as described below.

Data we process

DataPurposeLegal basisRetention
Email addressAccount, magic-link sign-in, transactional noticesContract (Art. 6(1)(b) GDPR)Until account deletion + short backup window
Session cookie (__Host-eiv_session)Dashboard authenticationContract / legitimate interestUp to 30 days; see Cookies
API key hashes & masked prefixesAuthenticationContractUntil revoked or account deleted
Usage counters (validations, VAT checks)Quota enforcement, billing fairnessContractWhile account active; period keys roll monthly
Subscription statePlan entitlementsContractWhile account active; billing records longer if required by tax law
Validation request metadata (request id, key id, format, sizes, timings, failed rule ids)Operations, abuse preventionLegitimate interest (Art. 6(1)(f))Server logs — typically days to weeks on the host
Invoice XML contentValidationContract (processor role for business customers)Not persisted — processed in memory only
VIES query results (VAT number, name, address when returned)VAT check API + cacheContract / legitimate interestCache up to ~8 days after expiry; stale fallback up to ~30 days during outages
Magic-link tokensPasswordless sign-inContractUntil expiry + 24 h
Email delivery log (quota warnings, etc.)Idempotent lifecycle emailsContractUp to 180 days
Webhook idempotency keysBilling correctnessContractUp to 90 days

Processors and recipients

We do not sell personal data. We do not use advertising or analytics cookies.

International transfers

Primary processing is in the EU. If a subprocessor transfers data outside the EEA, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) where required.

Your rights

Depending on applicable law you may have rights to access, rectify, erase, restrict, object, and port your data, and to withdraw consent where processing is consent-based. Use privacy@einvoicecheck.eu or the account tools in the dashboard. We respond within one month where GDPR applies.

You may lodge a complaint with the Slovenian Information Commissioner (ip-rs.si).

Security and breaches

We use TLS, hashed API keys, rate limits, and EU-region hosting. No system is perfectly secure. If a personal-data breach likely affects your rights, we will notify you and regulators as required by law.

Automated decisions

We do not make solely automated decisions with legal or similarly significant effects on you.

Children

The Service is not directed at children under 16.

Changes

We will post updates here with a new version date. Material changes may require renewed acceptance.