Privacy Policy
This Privacy Policy explains how Beliq ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our website (beliq.eu), dashboard (dashboard.beliq.eu), API (api.beliq.eu), documentation (docs.beliq.eu), and related services (collectively, the "Service"). We are committed to processing your data in compliance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG, formerly TTDSG).
1. Controller
The controller responsible for data processing is:
Tobias Satzger
c/o IP-Management #10800
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: hello@beliq.eu
2. Overview of Data Processing
Beliq is an API-first platform for generating, validating, parsing, and converting EU-compliant electronic invoices (EN 16931). We process personal data in the following contexts:
- Account registration and authentication
- Providing and operating the e-invoicing API and dashboard
- Billing and subscription management
- Transactional emails
- Marketing communications: our opt-in newsletter (only if you subscribe)
- Delivery of our static websites and documentation
- Error monitoring and operational logging
- Customer support through our self-hosted live chat, including an AI assistant
- Privacy-friendly, self-hosted website analytics
We do not use any third-party analytics, advertising networks, or cross-site tracking. The only usage analytics we run is a privacy-focused, cookieless tool that we self-host on our own infrastructure. See Section 10 (Analytics).
3. Account Data
3.1 Registration with Email and Password
When you register, we collect your email address and a password. Your email address is stored encrypted at rest (AES-256-GCM); a keyed hash (HMAC) of the address is used only to look it up without decrypting the whole table. Your password is stored as an Argon2id hash and cannot be read by us. We also record the timestamp of your acceptance of our Terms of Service and Privacy Policy.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
3.2 Sign-in with a Third-Party Provider (OAuth)
Instead of a password, you may choose to register or log in using a third-party sign-in provider: Google, GitHub, or (where enabled) Microsoft. This is optional. If you use it, you authenticate directly with that provider, which acts as an independent controller under its own privacy policy, and (with your consent) returns your email address and basic profile information (name, avatar URL) to us. We store the provider account link to enable future logins. We do not receive or store a password from these providers.
These providers are based in the United States. Because the sign-in is initiated by your own choice and runs against your existing account with the provider, this is not a transfer we make on your behalf. If you prefer not to use a US provider, register with email and password instead, which is always available. See Section 16 (International Data Transfers).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
3.3 Email Verification
We send a verification code to your email address upon registration and when changing your email. These codes are stored encrypted and are deleted after use or expiration.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
4. API and Service Usage Data
4.1 Invoice Processing Requests
When you use our API to generate, validate, parse, or convert e-invoices, we process the content you submit (JSON invoice data, XML documents, or PDF files). This content may contain personal data of third parties, such as buyer and seller names, addresses, tax identifiers, and payment details.
Invoice content is processed in memory by our validation engine and is not persistently stored. It is discarded once the request completes; any temporary files created during processing are deleted immediately after.
We do store metadata about each processing job (operation type, standard and profile, input and output format, status, validation findings, and processing time) for quota tracking, abuse prevention, and to give you a history of your requests in the dashboard. The invoice content itself, and the party data inside it, are not included in this metadata or in our logs. Where you submit personal data of third parties for processing, you act as the controller and we act as your processor under our Data Processing Agreement.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for retaining job metadata after a request completes, Art. 6(1)(f) GDPR (legitimate interest in quota and billing reconciliation, abuse prevention, and service-integrity records).
4.2 API Keys
We store API key secrets as SHA-256 hashes. Only a short prefix is kept in readable form so you can identify a key in the dashboard. The full secret is shown once at creation and cannot be retrieved afterwards.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
4.3 Invoice Templates
If you create custom PDF invoice templates in the dashboard, they are stored encrypted at rest (AES-256-GCM), scoped to your organization, and decrypted only to render your documents. Template contents are not logged or used for any other purpose.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
5. Payment and Billing
Paid subscriptions are processed through Creem (Armitage Labs OÜ, Estonia), which acts as our merchant of record. When you subscribe, Creem processes your payment information (card or other payment method) on its hosted checkout and billing portal. We do not receive or store your full payment details. From Creem we receive and store:
- A subscription and customer identifier
- Your plan tier
- Billing period start and end dates
- Subscription status (active, cancelled, past due, etc.)
Receipts, invoices, and the applicable tax treatment for your purchase are issued by Creem. See Creem's privacy notice at creem.io/privacy.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
6. Transactional Emails
We use Scaleway Transactional Email (Scaleway SAS, France) to send service emails such as:
- Email verification codes
- API key creation and security notifications
- Quota usage warnings
- Password reset links
- Organization invitations and billing notifications
Scaleway receives the recipient email address and the email content for delivery purposes. It does not receive invoice content. Scaleway processes this data within the EU (France).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract); Art. 6(1)(f) GDPR (legitimate interest in operational and security notifications).
7. Static Hosting and Content Delivery
Our static websites (landing page and documentation) are stored in Scaleway Object Storage (Scaleway SAS, Paris, France) and delivered through bunny.net (BunnyWay d.o.o., Slovenia), a content delivery network with European infrastructure. When you visit these sites, bunny.net processes your IP address and standard HTTP request data (browser type, requested URL) to deliver the content. Invoice data does not transit the CDN.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient and secure content delivery).
8. Error Monitoring and Logging
To keep the Service reliable and secure, we operate our own self-hosted monitoring stack. Server-side logs and metrics run on a dedicated server we host at OVH (OVH SAS, Gravelines, France); error tracking runs on our self-hosted GlitchTip instance on Hetzner, in the EU. This captures technical information such as request metadata (method, path, response status, processing time), rate-limit and abuse signals, and, when an error occurs, exception details and stack traces. It does not capture invoice content, API key secrets, or the personal data inside your invoices. This telemetry is not shared with any third-party analytics provider.
On the interactive pages of our public website (the free invoice generator and the API playground), we also report client-side JavaScript errors from your browser to that same self-hosted GlitchTip instance, so we can detect and fix problems with those tools. This sends only the error and its technical context (stack trace, browser type, the page address); it sets no cookies, records no browsing session, and the content you type into the invoice form is stripped before any error report is sent. It is not used for analytics or tracking.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure and reliable service).
9. Cookies and Local Storage
For a detailed explanation of the cookies and storage we use, please see our Cookie Policy. In short: the dashboard sets an essential authentication cookie, the landing page stores your language preference in your browser's local storage, the support chat stores a conversation identifier if you open it, and we set no advertising or tracking cookies.
| Cookie / Storage | Purpose | Type | Legal Basis |
|---|---|---|---|
| NextAuth session | Authentication (signed JWT) | Essential | Art. 6(1)(b) / TDDDG Section 25(2) |
beliq:lang (local storage) | Remembers your language preference | Functional | TDDDG Section 25(2) |
10. Analytics
To understand how our public website and documentation are used, we run Umami, a privacy-focused, open-source analytics tool that we self-host on our own server in the EU (Hetzner). There is no third-party analytics provider: your usage data is not shared with Google Analytics, an advertising network, or any other external service, and it is not used for advertising or profiling.
Umami is cookieless. It does not set cookies, does not store any identifier on your device, and does not track you across websites or over time. It records only aggregated, anonymized statistics such as page views, the referring site, browser type, and country (derived from your IP address, which is not stored). Because no information is stored on or read from your device, no consent banner is required. Umami runs only on our public marketing site and documentation; it is not loaded in the dashboard or the API.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding and improving how our website is used).
11. Customer Support Chat and AI Assistant
Our website and documentation offer a live support chat. It runs on Chatwoot, an open-source customer-support tool that we self-host on our own server in the EU (Hetzner). The chat widget loads only when you open it, not on page view. When you start a conversation, we process the messages you send, together with any name or email address you choose to provide, to answer your request and follow up with you.
To respond faster, the chat uses an AI assistant that generates and sends replies to you directly. For this, the text of your support messages is sent to Mistral AI (Mistral AI SAS, Paris, France), whose API processes the request on EU infrastructure. Mistral acts as our processor: it may retain the message text for a short period (up to 30 days) for abuse monitoring and then deletes it, and it does not use it to train its models. The chat tells you that you are talking to an AI assistant, and a human agent can take over at any time; the AI does not make any decision that produces legal or similarly significant effects for you.
Invoice content is never part of the support chat. Please do not paste invoice data into the chat; use the API for any invoice processing, and share no more personal data in the chat than your request needs.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual and contractual support communication); Art. 6(1)(f) GDPR (legitimate interest in providing efficient customer support).
12. Hosting and Infrastructure
All of our infrastructure is hosted within the European Union:
- Application servers, API, and validation engine: Hetzner Online GmbH, across multiple EU data centers
- Database: PostgreSQL, operated within our Hetzner Kubernetes cluster in the EU
- Dashboard: Hetzner server in the EU
- Cache: Redis, used solely for rate-limit counters (no personal data stored)
- Database backups: primary copy in Hetzner Object Storage (EU), with an encrypted off-site copy in Scaleway Object Storage (France)
- Static websites and documentation: Scaleway Object Storage (France) delivered via bunny.net CDN (EU)
- Monitoring: logs and metrics self-hosted on our own server at OVH (Gravelines, France); error tracking self-hosted on Hetzner (EU)
- Support chat: self-hosted Chatwoot on our own server at Hetzner (EU)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable service operation).
13. Data Retention
- Account data: Retained for the duration of your account. Upon account deletion, your personal data is deleted or anonymized, subject to statutory retention obligations.
- Invoice job metadata: Retained under our legitimate interest (Section 4.1) for only as long as needed for quota and billing reconciliation, abuse prevention, and service-integrity records, then removed by a scheduled purge. This metadata holds no invoice content and none of the personal data inside your invoices.
- Invoice content: Processed in memory only; not persistently stored.
- Verification codes: Deleted after use or expiration.
- Support chat conversations: Retained while an inquiry is open and for a reasonable period afterwards to handle follow-ups, then deleted. Message text sent to our AI assistant is held by Mistral for up to 30 days for abuse monitoring and then deleted.
- Authentication and abuse audit logs: Retained for up to 90 days for security purposes.
- Webhook delivery logs and billing-event records: Retained for up to 30 days.
- Inactive accounts: Accounts inactive for 24 months receive a warning email. If the account remains inactive, it may be deleted in accordance with our data minimization obligations.
14. Data Subject Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR): You may request information about the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR): You may request deletion of your personal data, subject to statutory retention requirements.
- Right to restriction of processing (Art. 18 GDPR): You may request restriction of processing in certain circumstances.
- Right to data portability (Art. 20 GDPR): You may request your personal data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR): You may object to processing based on legitimate interests at any time.
- Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at hello@beliq.eu. We will respond within one month, as required by Art. 12(3) GDPR. Please note that where we must keep limited records to meet a statutory obligation, or retain job metadata for the legitimate-interest purposes described in Section 13, we may restrict rather than delete that specific data until it is purged.
15. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). You may address the supervisory authority of your habitual residence or place of work, or the state (Land) supervisory authority responsible for us as a private-sector controller. If you would like the contact details of the authority responsible for us, email hello@beliq.eu.
16. International Data Transfers
We keep all data processing within the European Union. Our primary infrastructure is located in the EU, and every sub-processor we engage on your behalf is based in the EU/EEA:
- Hetzner Online GmbH, Germany (EU)
- Scaleway SAS, France (EU)
- BunnyWay d.o.o., Slovenia (EU)
- OVH SAS, France (EU)
- Mistral AI SAS, France (EU)
- Armitage Labs OÜ (Creem), Estonia (EU)
The only case in which your data may reach a provider outside the EU is if you choose to sign in with Google, GitHub, or Microsoft (Section 3.2). Those providers are based in the United States and act as independent controllers under their own privacy policies and safeguards. This is optional, and email-and-password sign-in is always available as an EU-only alternative.
17. Sub-Processors
We engage the following sub-processors to deliver the Service:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting, servers, Kubernetes, database, backups, error tracking, self-hosted support chat | Germany (EU) |
| Scaleway SAS | Transactional email, static-site object storage, off-site backup copy | France (EU) |
| BunnyWay d.o.o. | Content delivery network (CDN) for static sites | Slovenia (EU) |
| OVH SAS | Hosting for our self-managed logs and metrics monitoring | France (EU) |
| Mistral AI SAS | AI assistant in our support chat (drafts replies from support messages; no invoice content) | France (EU) |
| Armitage Labs OÜ (Creem) | Subscription checkout, billing portal, payment processing, and related webhooks for paid plans (merchant of record) | Estonia (EU) |
| Brevo (Sendinblue SAS) | Newsletter delivery and subscriber list management (email address and opt-in metadata only; no invoice content). Only engaged if you subscribe (Section 22) | France (EU) |
Google, GitHub, and Microsoft sign-in providers are independent controllers, not sub-processors, and are only engaged when you explicitly choose to log in via those services (Section 3.2).
18. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS 1.3 / HTTPS for all communications)
- Encryption at rest of sensitive fields (email addresses, secrets, and invoice templates) using AES-256-GCM
- Passwords hashed with Argon2id; API key secrets stored as SHA-256 hashes
- Row-level security in the database, isolating each organization's data, and least-privilege database roles
- Signed, short-lived session tokens (7-day maximum) with immediate revocation on password change or account lock
- Network policies in our Kubernetes cluster to isolate services
- Invoice content processed in memory only, never persisted
- Rate limiting and abuse protection to prevent misuse
- Regular, encrypted database backups held on-site and off-site (both in the EU)
19. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects as defined by Art. 22 GDPR. The AI assistant in our support chat (Section 11) only drafts replies for a human agent and makes no such decision.
20. Children's Privacy
Our Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify registered users of material changes via email or through the dashboard. The "Last updated" date at the top of this page indicates when this policy was last revised.
22. Marketing Communications (Newsletter)
If you subscribe to our newsletter, we process your email address and the opt-in metadata (the time and the page the signup came from) to send you a periodic digest about changes to European e-invoicing mandates, plus occasional updates about beliq. This is separate from the transactional emails in Section 6 and is entirely optional.
Double opt-in. After you enter your address, we send a confirmation email; we only add you to the list and send the newsletter once you click the confirmation link. If you never confirm, your address is not added to the list.
Unsubscribe. Every newsletter includes a one-click unsubscribe link. You can withdraw your consent at any time with no effect on the lawfulness of processing before withdrawal.
We use Brevo (Sendinblue SAS, France) as our processor for newsletter delivery and list management (Section 17). Brevo processes your email address and opt-in metadata in the EU; no invoice content is ever involved, and there is no US data transfer.
Legal basis: Art. 6(1)(a) GDPR (consent).
23. Contact
If you have any questions about this Privacy Policy or our data processing practices, please contact us at:
Email: hello@beliq.eu