NordInvoice
Prüfung
AnmeldenAPI-Schlüssel holen
Legal

Privacy Policy

Last updated: 21 August 2026

Kurzfassung (nicht bindend)
  • Rechnungsinhalte speichern wir nicht: Dokumente werden im Speicher verarbeitet und verworfen; es bleiben nur Metadaten.
  • Wir verarbeiten Kontodaten (E-Mail, Name), Nutzungs-Metadaten, Zustelldaten und Support-Nachrichten.
  • Keine Werbe-Cookies, kein Tracking; localStorage nur für Theme, Sprache und Sitzung.
  • Zahlungen wickelt unser Zahlungsdienstleister ab; vollständige Zahlungsdaten sehen wir nie.
  • Verarbeitung in der EU/EWR. Ihre DSGVO-Rechte üben Sie per E-Mail aus; Beschwerde bei der Autoriteit Persoonsgegevens möglich.
  • Verantwortlicher ist Nordreg (KvK 42137606, USt-IdNr. NL005526020B24) aus der Region Utrecht.

This policy explains what NordInvoice processes when you use nordinvoice.com and the NordInvoice API, why, and what your rights are. The short version: we run the service on as little personal data as possible, and we do not store the content of your invoices.

1. Who is responsible

The controller is Nordreg (KvK 42137606, btw-id NL005526020B24), the company operating NordInvoice from the Utrecht region, the Netherlands. For anything in this policy, write to [email protected].

2. What we process

We process the following categories of data:

  • Account data: email address, name (when you sign in with Google, we receive your name and email from Google), a password hash if you register with a password, and your language preference.
  • Usage metadata: for each processed document a cryptographic fingerprint, the profile used, verdict and issue counts, file size and timestamp; delivery records (receiver identifier, status); an audit log of account events; API key prefixes and labels; never the full key, which we store only as a hash.
  • Invoice documents: processed in memory to answer your request, then discarded. Invoice content is never written to storage. Browser tools such as the invoice viewer run entirely on your machine; those files are never uploaded.
  • VAT checks: the VAT number you submit is forwarded to the European Commission’s VIES service to answer the query; we keep the outcome as metadata.
  • Billing data: your plan, orders, subscription status and payment status from our payment provider. Full payment details (card or bank data) go directly to the provider; we never see them.
  • Support messages you send us.

3. Why we process it

We process account, usage and billing data to provide the service you signed up for (Art. 6(1)(b) GDPR), to keep the platform secure and prevent abuse through rate limiting and audit logs (Art. 6(1)(f)), and to meet legal obligations such as tax record-keeping (Art. 6(1)(c)).

We do not use your data for advertising and we do not sell it. We currently send only transactional email (verification, delivery results, billing notices).

4. No tracking

The site sets no advertising or analytics cookies. Your browser’s localStorage holds your theme, language, session and, if you save one in the docs console, an API key; all of it stays on your machine and is sent only to the NordInvoice API.

5. Who receives data

We use a small number of processors, under data processing agreements, to run the service:

  • An EU hosting provider that runs our servers and database.
  • Our payment provider, for subscriptions and charges.
  • Certified Peppol access point partners, to deliver the invoices you send.
  • The European Commission’s VIES system, to answer VAT number checks.
  • A transactional email service, to deliver the emails described above.

6. Where data is processed

Data is processed in the EU/EEA. We do not transfer personal data to third countries; if that ever changes, we will put the required safeguards in place and update this policy first.

7. How long we keep it

Account data and usage metadata are kept while your account exists. You can delete your account yourself under Billing; personal data is then removed immediately and disappears from our nightly backups within seven days. Invoices and the payments behind them are kept for the statutory Dutch retention period (currently seven years), without login or personal data beyond what an invoice must show. Audit logs are kept up to 24 months.

Invoice content is not kept at all; there is nothing to delete.

8. Your rights

Under the GDPR you can request access to, correction of, deletion of, or a portable copy of your personal data, restrict or object to processing, and withdraw consent where processing is based on it. Deletion you can do yourself in the dashboard; for everything else write to [email protected] and we answer within a month.

You can also complain to a supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.

9. Security

All traffic is encrypted in transit (TLS). API keys and passwords are stored only as hashes. Access to production systems is restricted, and documents are processed without being written to disk.

10. Changes and contact

When this policy changes materially, we notify account holders by email before the change takes effect. The current version is always published on this page.

Contact: [email protected].

NordInvoice

Kostenlose europäische E-Rechnungsprüfung

Produkt

PrüfungPeppol-CheckKontoPreiseDokuGuidesFAQ

Unterstützte Standards

Peppol BIS Billing 3.0XRechnung (DE)NLCIUS / SI-UBL (NL)EN 16931 (EU)

Rechtliches

DatenschutzNutzungsbedingungenAuftragsverarbeitung (AVV)

Immer aktuell

Die Regelwerke werden laufend an die europäische Gesetzgebung angepasst. Die aktive Version steht immer neben dem Ergebnis.

© 2026 NORDINVOICE · KvK 42137606 · USt-IdNr. NL005526020B24iDEALVISASEPAMADE IN THE NETHERLANDS