Privacy Policy
This policy describes what personal data we process when providing Beliq, for what purpose, on what legal basis, and for how long. It covers our website (beliq.eu), the dashboard (dashboard.beliq.eu), the API (api.beliq.eu) and the documentation (docs.beliq.eu). This is a translation of the German Datenschutzerklärung, which is the original.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Tobias Satzger
c/o IP-Management #10800
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany
Email: hello@beliq.eu
2. Our two roles
Beliq is an API for generating, validating, parsing and converting electronic invoices under EN 16931. Two areas have to be distinguished:
- For the content you submit through the API (invoice data naming issuers, recipients and their contact persons), you are the controller. We process it strictly on your instructions as a processor under Art. 28 GDPR. What governs there is our Data Processing Agreement, not this policy.
- For everything else (account, billing, support, usage measurement, newsletter, operating and securing the service), we are the controller. Those processing operations are described below.
We use no third-party analytics services, no advertising networks and no cross-site tracking.
3. Delivering the websites
Our website and documentation are static files stored with Scaleway SAS (France) and delivered through the content delivery network of BunnyWay d.o.o. (Slovenia). The same network sits in front of the dashboard at dashboard.beliq.eu. On each request the network processes your IP address and the usual HTTP details (requested address, time, browser type, bytes transferred), because delivery is not technically possible without them. Where you use the dashboard, invoice content passes through this network too; it is only carried through and is neither cached nor stored at the edge. Delivery happens exclusively from locations in EU member states. For invoice content you submit as a controller, the Data Processing Agreement applies in addition; BunnyWay is listed there as a sub-processor.
Purpose: delivery, stability, and defence against attacks.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and performant operation of our web presence.
Retention: connection data is deleted or truncated after seven days at the latest.
4. Storage on your device
Simply visiting our website stores nothing on your device and reads nothing from it, so no consent banner is required. Something is stored only once you actively use a feature, such as opening the support chat or signing in to the dashboard, and then only what that feature strictly needs. Our Cookie Policy lists each item, its purpose and its duration.
Legal basis for access to your device: Section 25(2) no. 2 TDDDG, because each item is strictly necessary for us to provide a service you explicitly requested. The subsequent processing of any personal data obtained rests on the legal basis stated in the relevant section below.
5. Account
5.1 Registration with email address and password
On registration we process your email address and your password. The email address is stored encrypted (AES-256-GCM); we additionally keep a keyed hash (HMAC) of it so we can look it up without decrypting the table. The password is stored only as an Argon2id hash and is not accessible to us in clear text. We also record when you accepted our contract terms and confirmed your status as a business.
Purpose: creating and running the account.
Legal basis: Art. 6(1)(b) GDPR. The record of acceptance additionally rests on Art. 6(1)(c) in conjunction with Art. 5(2) GDPR.
Retention: for the life of the account, then deletion or anonymization unless a statutory retention obligation applies.
5.2 Signing in with a third-party provider
Instead of a password you may sign in with an existing Google, GitHub or (where enabled) Microsoft account. This is optional. You authenticate directly with that provider, which then sends us your email address, basic profile data (name, avatar URL) and an identifier we use to match future sign-ins. We do not receive a password.
The provider is an independent controller for its own processing and is not our processor; its own privacy notice applies. These providers are based in the United States. If you would rather avoid that, register with email address and password, which is always available.
Purpose: authentication and account creation.
Legal basis: Art. 6(1)(b) GDPR.
Retention: as in 5.1.
5.3 Confirming your email address
On registration and when you change your address, we send a confirmation code to it. We do not store the code in clear text; we store a keyed one-way hash (HMAC) of it and compare that against your input.
Purpose: proving the address is yours and preventing abusive registrations.
Legal basis: Art. 6(1)(b) GDPR.
Retention: deleted once redeemed or expired.
6. Using the API and the dashboard
6.1 Invoice content
When you use the API to generate, validate, parse or convert invoices, we process the content you submit (JSON data, XML documents or PDF files). It may contain personal data of third parties, such as names and addresses of issuers and recipients, tax identifiers, bank details and contact persons.
Invoice content is processed in memory only and is not persistently stored. It is discarded once the request completes; temporary files created during processing are deleted immediately afterwards.
For this processing you are the controller and we are the processor (see Section 2). The details are in the Data Processing Agreement.
6.2 Job metadata
For each request we store metadata: operation type, standard and profile, input and output format, status, validation findings, processing time and the owning organization. Invoice content, and the personal data of third parties inside it, are not included; submitted values are stripped out of validation findings before they are stored.
Purpose: quota and billing reconciliation, abuse prevention, service-integrity records, and your job history in the dashboard.
Legal basis: Art. 6(1)(b) GDPR for providing the history; Art. 6(1)(f) GDPR for keeping it thereafter. Our legitimate interest is reconciling quota and billing, preventing abusive use, and evidencing correct operation.
Retention: we delete job metadata twelve months after it is created. Because deletion happens by partition, actual retention is twelve to at most twenty-four months depending on when the record was written.
6.3 API keys
An API key secret is stored only as a SHA-256 hash. Only a short prefix stays readable so you can recognize the key in the dashboard. The full key is shown once on creation; afterwards not even we can reconstruct it.
Purpose: authenticating your API requests.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you revoke the key or the account is deleted.
6.4 PDF templates
Custom PDF templates you create in the dashboard are stored encrypted (AES-256-GCM), separated by organization. They are decrypted only to render your documents. Their contents are not logged and are not used for any other purpose.
Purpose: rendering the documents you designed.
Legal basis: Art. 6(1)(b) GDPR.
Retention: until you delete the template or the account is deleted.
7. Payment and subscription management
Paid subscriptions run through Armitage Labs OÜ (Creem), Estonia, which sells in its own name as merchant of record. You enter your payment details directly with Creem; we neither receive nor store them. From Creem we receive a subscription and customer identifier, the plan booked, the start and end of the billing period, and the subscription status.
Receipt, invoice and VAT treatment come from Creem. Its own privacy notice applies to that processing (creem.io/privacy).
Purpose: activating and managing your plan.
Legal basis: Art. 6(1)(b) GDPR.
Retention: for the term of the subscription; records of our own business transactions are kept as required by Section 147 AO and Section 257 HGB.
8. Transactional emails
For confirmation codes, API key security notices, quota warnings, password reset links, invitations and billing notices we use Scaleway Transactional Email (Scaleway SAS, France). Scaleway receives the recipient address and the content of the message, never invoice content.
Purpose: performing the contract and notifying you of security-relevant events.
Legal basis: Art. 6(1)(b) GDPR; for security notices additionally Art. 6(1)(f) GDPR. Our legitimate interest is informing you about security-relevant events in your account.
Retention: delivery logs are deleted at Scaleway under its own schedule; we do not store message content persistently.
9. Support chat and AI assistant
Our website and documentation offer a support chat. It runs on Chatwoot, which we host on our own server in the European Union. The chat loads only when you click it, not on page view. We process the messages you send, plus any name and email address you choose to provide.
In the chat an AI assistant generates replies itself and sends them to you directly. We disclose that you are talking to an AI system in the chat window before your first input (Art. 50(1) AI Act). A person can take over at any time. To generate the replies we send the text of your messages to Mistral AI SAS (France) as our processor. Where that processing takes place, and which two layers at the provider reach beyond the Union, is set out in Section 14.3. Mistral retains the text for up to 30 days for abuse monitoring and then deletes it; it is not used to train models.
Please do not paste invoice content into the chat. Use the API for invoice processing, and share no more personal data in the chat than your request needs.
Purpose: answering your enquiry.
Legal basis: Art. 6(1)(b) GDPR where the enquiry concerns a contract or its initiation, otherwise Art. 6(1)(f) GDPR. Our legitimate interest is handling enquiries promptly.
Retention: for the duration of handling and a reasonable period for follow-up questions, then deleted.
10. Error tracking and operational logs
To run the service reliably and securely we operate our own monitoring. Logs and metrics run on a server we operate at OVH SAS (France); error tracking runs on a GlitchTip installation we operate at Hetzner Online GmbH (Germany). Captured are technical details such as method, path, response status and processing time, overload and abuse signals, and, when an error occurs, the error message and stack trace. Invoice content, API key secrets and the personal data inside your invoices are not captured. Nothing is passed to third-party analytics services.
For sign-in events we additionally record the time and type of the event, the IP address and the browser's user agent. Where the event happens before a session exists, such as a registration or a failed sign-in attempt, we store a keyed fingerprint of the address entered instead of the address. The sign-in log does not contain the address itself. If you delete your account, we also delete the entries in that log belonging to your account and to your address.
On the interactive pages of our website, the free invoice generator and the API playground, we additionally report errors occurring in your browser to that same installation. Only the error and its technical context are transmitted. No cookies are set, no session is tracked and no data is collected for analytics; the content you type into the form is stripped before sending.
Purpose: finding and fixing errors, maintaining security.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the stability and security of the service and error diagnosis.
Retention: sign-in and abuse-prevention logs 90 days, error reports at most 90 days.
11. Usage measurement
To understand how our website and documentation are used we run Umami, an open-source tool, on our own server in the European Union. No analytics provider is involved.
Umami works without cookies. No identifier is stored on your device, and there is no recognition across websites or sessions. It records page views, the referring page, browser type and screen size, and the country derived from your IP address; the IP address itself is not stored. No device fingerprint is formed.
Access to your device: nothing is stored on your device, and what is read is limited to what your browser sends with the request anyway and does not serve recognition. Consent under Section 25(1) TDDDG is therefore not required.
Legal basis for the subsequent processing: Art. 6(1)(f) GDPR. Our legitimate interest is designing our web presence to fit actual use.
Retention: the statistics are aggregated and permit no reference to an identified person.
12. Newsletter
If you subscribe to our newsletter we process your email address and the signup metadata (time and page of signup) to send you periodic notes on European e-invoicing mandates and occasional product updates. The newsletter is separate from the transactional emails in Section 8 and entirely optional.
Double opt-in. After you enter your address we send a confirmation email. Only when you click the link in it do we add you to the list. If you do not confirm, the address is not added.
Unsubscribing. Every newsletter carries an unsubscribe link. You may withdraw your consent at any time with effect for the future; the lawfulness of processing up to that point is unaffected.
For sending and list management we use Brevo (Sendinblue SAS, France) as our processor. Where that processing takes place is set out in Section 14.5.
Legal basis: Art. 6(1)(a) GDPR (consent).
Retention: until withdrawal; the signup metadata is kept beyond that as evidence of consent.
13. Recipients and processors
We engage the following processors. All are established in a member state of the European Union. Where the processing takes place is set out per processing in Section 14; for the AI support chat, the newsletter and the status page the statement does not reach as far as it does for the other rows of this table.
| Processor | Task | Location |
|---|---|---|
| Hetzner Online GmbH | Servers, Kubernetes cluster, database, backups, error tracking, support chat | Germany |
| Scaleway SAS | Transactional email, object storage for the static websites, encrypted off-site backup copy | France |
| BunnyWay d.o.o. | Content delivery network in front of the websites and the dashboard; carried through only, EU locations exclusively | Slovenia |
| OVH SAS | Server for our self-operated logs and metrics | France |
| Mistral AI SAS | Generating replies in the AI support chat; no invoice content; processing location in Section 14.3 | France |
| Armitage Labs OÜ (Creem) | Checkout, customer portal and subscription management for paid plans | Estonia |
| Brevo (Sendinblue SAS) | Newsletter delivery and list management; only if you subscribe; processing location in Section 14.5 | France |
| Lightkeeper OÜ (Phare) | Operation of the status page at status.beliq.eu; only when you open that page; no invoice content; processing location in Section 14.6 | Estonia |
For third-party sign-in, Google, GitHub and Microsoft are independent controllers, not processors. They are involved only if you explicitly choose that route (Section 5.2).
14. Processing in third countries
The statement about where processing takes place is split per processing, because it does not reach equally far. A single blanket sentence would be too weak for the commissioned data and too strong for the AI support chat.
14.1 Invoice content and job metadata
Content you submit through the API or the dashboard for validation, generation or conversion, and the associated metadata (Sections 6.1 and 6.2), is processed exclusively in member states of the European Union. No transfer to a third country takes place. This also covers access for maintenance and error analysis. Section 11.1 of the Data Processing Agreement puts that under contract.
14.2 Delivery of the websites and the dashboard
Delivery through the content delivery network of BunnyWay d.o.o. (Section 3) runs exclusively through locations in member states of the European Union. All three zones (homepage, documentation, dashboard at dashboard.beliq.eu) have the provider's "European Union (EU) only" routing filter set. That routes every request to a location in the Union, including requests from outside it; while the filter is set, a location outside the Union cannot serve.
14.3 AI assistant in the support chat
For the AI assistant (Section 9) we cannot promise processing exclusively in the Union. According to the sub-processor list the provider publishes, generation of the reply and its time-limited retention sit in the European Union or the European Economic Area. The provider's data processing agreement gives no undertaking to that effect, however: it permits transfers to countries with an adequacy decision and beyond that on the basis of the standard contractual clauses (Art. 46(2)(c) GDPR).
Two layers in the provider's infrastructure reach beyond the Union: a worldwide security and routing layer (Cloudflare), which is entered at the caller's location, and a security provider with locations in the European Economic Area and the United States (CrowdStrike). Both concern the operation and protection of the provider's platform rather than the generation of the reply. We therefore cannot rule out third-country access at that level.
The provider's further features that draw in non-European services (web search, image generation, connectors) are not enabled in our assistant; it knows exactly three functions of its own (search our own body of text, hand over to a person, query our status endpoint). That is our configuration, not a technical impossibility.
So please do not paste invoice content into the chat, and no personal data your request does not need. Use the API for invoice processing; Section 14.1 applies there.
14.4 Signing in with a third-party provider
A further exception arises if you choose to sign in via Google, GitHub or Microsoft (Section 5.2). Those providers are based in the United States and act as independent controllers under their own safeguards. Signing in with email address and password is always available as an alternative with no third-country element.
14.5 Newsletter dispatch
For the newsletter (Section 12) we cannot promise processing exclusively in the Union either. Brevo (Sendinblue SAS) is established in France, and according to the sub-processor list the provider publishes, the hosting sits with OVH (France, servers in France) and Google Cloud Platform (France, servers in Belgium). The provider's data processing agreement gives no undertaking to that effect, however: it reserves processing outside the European Economic Area where the provider, its affiliates or its sub-processors operate, on the basis of the standard contractual clauses (Art. 46(2)(c) GDPR) and, for the United States, the EU-US Data Privacy Framework.
One layer in the provider's infrastructure reaches beyond the Union: a worldwide content delivery and security layer (Cloudflare), with locations in the United States and in the Union. As in Section 14.3, that concerns the operation and protection of the provider's platform rather than the dispatch of the newsletter itself. We therefore cannot rule out third-country access at that level.
What is processed there is your email address, the signup metadata and the delivery data of the mails themselves. No invoice content reaches the newsletter; Section 14.1 governs that separately. Subscribing is voluntary and revocable at any time (Section 12), so not subscribing is always available as an alternative with no third-country element.
14.6 Opening the status page
The status page at status.beliq.eu is not served by us but by Lightkeeper OÜ (Phare), Tallinn, Estonia. When you open it, your browser connects directly to that provider's servers ( phare.io and cdn.phare.io), which transmits your IP address and the usual connection data to them. This happens only when you open the status page, for example through the link in the footer. No connection to this provider is made on any other page.
For this processing we cannot promise processing exclusively in the Union. Per the provider's published sub-processor list, its application and database run at Hetzner (Germany), but its delivery, DNS and security layer is operated by BunnyWay d.o.o. from locations worldwide, and unlike our own zones (Section 14.2) the "European Union (EU) only" routing filter there is not set by us. The provider also names sub-processors in the United States and the United Kingdom; those concern its billing, its error tracking and its notification delivery, not the serving of the page. We therefore cannot rule out access from a third country. For transfers outside the European Economic Area the provider commits to the standard contractual clauses (Art. 46(2)(c) GDPR).
The page sets no cookies and stores nothing in your browser; it embeds no analytics and no tracking services (as at 6 September 2026, checked by us in the browser). No invoice content reaches the status page: the monitoring calls two health endpoints only and never sees processed data. The provider is therefore not a sub-processor under the Data Processing Agreement.
15. Retention and deletion
Retention for each processing operation is stated in Sections 3 to 12. Across all of them:
- We delete personal data once its purpose has ceased and no statutory retention obligation applies.
- If you delete your account, the associated data is deleted or anonymized. Data we must keep under a statutory retention obligation is restricted in its processing (Art. 18 GDPR) and deleted once the period expires.
- Database backups are overwritten by rotation after 30 days. Until then, an already-deleted record may still be present in a backup.
- Sign-in and abuse-prevention logs are deleted after 90 days; webhook delivery logs and billing events after 30 days.
16. Whether you have to provide the data
The data in Section 5 is necessary for the account. You are under no statutory obligation to provide it, but without it we cannot create an account or perform the contract. Giving a name and email address in the support chat, and subscribing to the newsletter, are entirely voluntary; if you do not, you incur no disadvantage beyond not receiving that particular service.
17. No automated decision-making
Automated individual decision-making including profiling under Art. 22 GDPR does not take place. The AI assistant in the support chat (Section 9) answers enquiries; it makes no decision producing legal effects concerning you or similarly significantly affecting you.
18. Data security
We take technical and organizational measures under Art. 32 GDPR, including:
- Encryption in transit (TLS 1.3)
- Encryption at rest of particularly sensitive fields (email addresses, secrets, PDF templates) with AES-256-GCM
- Passwords as Argon2id hashes, API key secrets as SHA-256 hashes
- Tenant separation in the database through row-level security, and database roles with least privilege
- Signed session tokens valid for at most seven days, revoked immediately on password change or account lock
- Network policies separating services in the cluster
- Invoice content processed in memory only
- Rate limiting and abuse detection
- Regular encrypted backups in two locations, both in the European Union
19. Your rights
You have the following rights against us:
- Access to the data we process about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
A message to hello@beliq.eu is enough. We reply within one month (Art. 12(3) GDPR). Where we must keep data under a statutory obligation or for the legitimate interests in Section 6.2, we restrict its processing rather than delete it.
20. Right to object
You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you which is based on Art. 6(1)(f) GDPR (Art. 21(1) GDPR). We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
An informal message to hello@beliq.eu suffices.
21. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). You may address the authority of your habitual residence, your place of work, or the place of the alleged infringement.
22. Data protection officer
We are not required to designate a data protection officer under Art. 37 GDPR in conjunction with Section 38 BDSG, and have not designated one. Data protection questions go to hello@beliq.eu.
23. Changes to this policy
We adapt this policy when the processing described here or the legal requirements change. We notify registered users of material changes by email or in the dashboard. The date at the top of this page shows when it was last revised.