Endpoints
GenerateJSON in, wire-ready XML or Factur-X outValidateXSD, EN 16931 and country CIUS in one passParseExtract embedded XML from a PDFConvertCII to UBL within the EN 16931 familySendSoonRoute each invoice over the right national networkRulesets↗The authority rulesets we run, pinned by version and hash
Explore
CoverageFormats and authority-verified datesDeliveryComing soon: managed routingPlaygroundRun it live, no signupPricingPlans and document quotas
Integration paths
REST APIPOST /v1/generate, cURL-readySDKs & developer toolsNode, Python, MCP and CLINo-code & automationn8n, Activepieces and moreE-commerceShopware · WooCommerce pluginsAccounting & ERPValidate and convert, e.g. sevDesk
Explore
All integrations →The full connector list on docsPlaygroundLive generate and validate, no signupOpenAPI 3.0 · PostmanSoonDownloadable spec and collection
Try it first
Run a live generate or validate in the no-signup Playground.
Open Playground →
Docs↗Guides and conceptsQuickstart↗First call in five minutesFAQCommon questions, answeredChangelogWhat shipped, and whenStatus↗Live uptime and incidentsBlogStandards, deep dives, notesTrustHosting, subprocessors, provenance
Pricing
eli
Log inGet API key
Product▾
Endpoints
GenerateJSON in, wire-ready XML or Factur-X outValidateXSD, EN 16931 and country CIUS in one passParseExtract embedded XML from a PDFConvertCII to UBL within the EN 16931 familySendSoonRoute each invoice over the right national networkRulesets↗The authority rulesets we run, pinned by version and hash
Explore
CoverageFormats and authority-verified datesDeliveryComing soon: managed routingPlaygroundRun it live, no signupPricingPlans and document quotas
Integrations▾
Integration paths
REST APIPOST /v1/generate, cURL-readySDKs & developer toolsNode, Python, MCP and CLINo-code & automationn8n, Activepieces and moreE-commerceShopware · WooCommerce pluginsAccounting & ERPValidate and convert, e.g. sevDesk
Explore
All integrations →The full connector list on docsPlaygroundLive generate and validate, no signupOpenAPI 3.0 · PostmanSoonDownloadable spec and collection
Resources▾
Docs↗Guides and conceptsQuickstart↗First call in five minutesFAQCommon questions, answeredChangelogWhat shipped, and whenStatus↗Live uptime and incidentsBlogStandards, deep dives, notesTrustHosting, subprocessors, provenance
PricingLog in

Legal documents

  • Overview
  • Imprint
  • Privacy policy
  • Terms of service
  • Data Processing Agreement
  • Cookie policy
  • Acceptable use
  • Right of withdrawal
Last updated · July 24, 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller", "Customer") and Tobias Satzger, operating as Beliq ("Processor", "we", "us"). This DPA applies when we process personal data on your behalf in the course of providing the Beliq service ("Service").

This DPA is established in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

1. Definitions

Unless otherwise defined, terms used in this DPA have the same meaning as in the GDPR and the Terms of Service.

  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by us on your behalf through the Service.
  • "Processing" means any operation performed on Personal Data, including collection, recording, storage, adaptation, retrieval, use, disclosure, or erasure.
  • "Sub-Processor" means any third party engaged by us to assist in processing Personal Data on behalf of the Controller.

2. Scope and Applicability

This DPA applies when you, as the Controller, submit content containing Personal Data to the Service for invoice processing (for example, JSON, XML, or PDF containing customer names, addresses, VAT identifiers, or other personal information in invoices). You determine the purposes and means of processing; we process the data solely on your instructions and for the purpose of providing the Service.

This DPA does not apply to data we process as an independent controller (for example, your account data and billing information), which is covered by our Privacy Policy.

3. Subject Matter and Duration

3.1 Subject Matter

The subject matter of this DPA is the processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of e-invoice generation, validation, parsing, and conversion services via the Beliq API.

3.2 Duration

This DPA remains in effect for the duration of the Controller's use of the Service. Upon termination, the provisions of this DPA continue to apply to any Personal Data still in the Processor's possession until it is deleted.

4. Nature and Purpose of Processing

The Processor processes Personal Data for the following purposes:

  • Generating e-invoices from structured JSON data submitted by the Controller (including party names, addresses, and financial details)
  • Validating e-invoice XML or PDF documents against EN 16931 and CIUS rules
  • Parsing e-invoice documents into normalized JSON for the Controller
  • Converting e-invoices between supported formats for the Controller
  • Delivering processing results to the Controller via API response or webhook

5. Types of Personal Data

The types of Personal Data processed depend on the content the Controller submits. This may include but is not limited to:

  • Names and contact details (addresses, email, phone numbers)
  • Business and financial data (invoice amounts, account numbers, IBAN, VAT identifiers)
  • Any other Personal Data contained in the invoice data submitted by the Controller

6. Categories of Data Subjects

Data Subjects may include the Controller's customers, employees, suppliers, partners, or any other individuals whose Personal Data is contained in the invoice content submitted for processing.

7. Processor Obligations

In accordance with Art. 28(3) GDPR, the Processor shall:

  1. Documented instructions: Process Personal Data only on documented instructions from the Controller. The Controller's instructions are defined by the API request parameters.
  2. Confidentiality: Ensure that persons authorized to process Personal Data have committed themselves to confidentiality.
  3. Security measures: Implement appropriate technical and organizational measures as described in Section 10.
  4. Sub-processors: Not engage another processor without prior general written authorization from the Controller, as described in Section 8.
  5. Data Subject rights: Assist the Controller in responding to Data Subject requests.
  6. Security and breach assistance: Assist the Controller, taking into account the nature of processing and the information available, with its obligations under Art. 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation).
  7. Deletion: At the Controller's choice, delete or return all Personal Data after the end of the provision of services.
  8. Audits: Make available all information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits.

8. Sub-Processors

8.1 General Authorization

The Controller grants general written authorization for the Processor to engage Sub-Processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors, giving the Controller the opportunity to object within 14 days. If the Controller objects on reasonable data-protection grounds, the Controller may terminate the affected part of the Service. The Processor imposes on each Sub-Processor, by contract, data-protection obligations equivalent to those in this DPA (Art. 28(4) GDPR).

8.2 Current Sub-Processors

The following Sub-Processor may process Personal Data submitted via the API (invoice content). Invoice content is processed in memory and is not persistently stored:

Sub-ProcessorPurposeLocationData Processed
Hetzner Online GmbHCloud infrastructure (servers, Kubernetes, database)Germany (EU)Invoice content transiting our infrastructure (in memory only, not stored)

The following services process the Controller's account, support, or operational data but do not process invoice content (the Personal Data submitted via the API):

ServicePurposeLocation
Scaleway SASTransactional email, static-site object storage, and encrypted off-site backup copyFrance (EU)
OVH SASHosting for our self-managed logs and metrics monitoring (operational metadata only). Error tracking is self-hosted on Hetzner (EU).France (EU)
BunnyWay d.o.o.Content delivery network for static sites (website request metadata only; invoice data does not transit the CDN)Slovenia (EU)
Mistral AI SASAI assistant in our self-hosted support chat (drafts replies from support messages; no invoice content)France (EU)
Armitage Labs OÜ (Creem)Subscription checkout, customer billing portal, payment processing, and subscription webhooks (account and billing data only)Estonia (EU)

9. International Transfers

All processing of invoice content occurs within the European Union. The Processor does not transfer Personal Data submitted via the API to countries outside the EU/EEA.

10. Technical and Organizational Measures

The Processor implements the following technical and organizational measures (TOMs) in accordance with Art. 32 GDPR:

10.1 Encryption

  • All data in transit is encrypted using TLS 1.3 / HTTPS
  • Sensitive fields at rest (email addresses, secrets, invoice templates) are encrypted using AES-256-GCM
  • Database backups are stored in encrypted object storage, held on-site (EU) and off-site (France)

10.2 Access Controls

  • Row-level security in the database, isolating each organization's data
  • Least-privilege database roles; the application role does not own the schema
  • Network policies in Kubernetes for strict service isolation
  • Signed, short-lived session tokens with immediate revocation on password change or account lock

10.3 Data Minimization

  • Invoice content is processed in memory and not persistently stored
  • Personal data submitted via the API is not included in job metadata or logs
  • Temporary files used during document processing are deleted after each request

10.4 Availability and Resilience

  • Kubernetes-based infrastructure across two data centers with auto-scaling
  • Regular automated database backups, on-site and off-site (both in the EU)
  • Rate limiting and abuse protection to preserve availability

10.5 Monitoring

  • Self-managed error tracking (self-hosted in the EU), plus logging and metrics (self-hosted in France); this telemetry excludes invoice content and secrets. Client-side error reports from the interactive tools on our public website also exclude the content entered into the invoice form.

11. Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Personal Data processed on behalf of the Controller. The notification shall include a description of the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences, and the measures taken to address the breach.

12. Return and Deletion of Data

Invoice content is processed in memory and not persistently stored. After each API request, the content is discarded. The job metadata we retain (described in our Privacy Policy) contains no invoice content and none of the personal data submitted via the API.

Upon termination of the Service agreement, the Processor shall delete all Personal Data processed on behalf of the Controller (to the extent it is still in the Processor's possession), unless EU or member state law requires storage.

13. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR. Audits shall be conducted with reasonable prior notice (at least 30 days), limited to once per year, conducted during normal business hours, and at the Controller's expense.

14. Governing Law

This DPA is governed by the laws of the Federal Republic of Germany. The provisions of the GDPR apply directly.

15. Contact

For questions about this Data Processing Agreement or to exercise audit rights, please contact us at:

Email: hello@beliq.eu

The mandate digest

What changes across European e-invoicing mandates, plus the occasional big Beliq update. A few times a year, no noise.

We use your email only for this newsletter, handled per our privacy policy

eli

The platform for European e-invoicing. Generate and validate against authority-pinned rulesets today, with managed delivery next.

hello@beliq.eu
Platform
  • Generate
  • Validate
  • Parse
  • Convert
  • Delivery (soon)
  • Playground
  • Webhooks
Coverage
  • EN 16931
  • Country CIUS
  • Peppol BIS
  • Authorities
Integrations
  • REST API
  • n8n
  • SDKs
  • MCP server
  • All integrations →
Resources
  • Documentation ↗
  • Quickstart
  • FAQ
  • Status ↗
  • Changelog
  • Security
  • Blog
  • Newsletter
  • Free generator
Company
  • Contact
  • Imprint
  • Privacy
  • DPA
  • Legal overview
© 2026 Beliq · made with care in EuropeEU-resident · Hetzner · status + changelog public