Privacy Policy

Who is responsible for your data

Name
Not provided yet
Address
Not provided yet
Data protection contact
Not provided yet

This document hasn't been published yet

It is being finalised and will appear here once it is approved.

Service providers that receive personal data

Generated from the integrations Payzio actually uses. The same list is published on the subprocessors page.

ProviderPurposePersonal dataWhenLocationTransfer safeguard
Google CloudHosting of the application, its database and stored files (receipts, uploaded contracts and other uploads kept on the service volume).All account, client, invoice, contract, expense, time-tracking and bank-feed data held in Payzio.On every useTo be confirmedTo be confirmed
Amazon Web Services (S3)File storage for logos, signatures, profile photos and attachments, in deployments configured to store uploads in S3.Uploaded images and files, which can include a handwritten signature.Only when file storage is configured to use S3.To be confirmedTo be confirmed
OpenAIAI features: reading receipts an account holder scans into expenses, drafting payment reminders for AI collections, and answering the Co-Pilot assistant.Receipt images; for reminder drafts, the overdue invoice's number, amounts and dates, the client's name and payment-reliability figures and the sender's business name; for the Co-Pilot, the conversation and whatever business data it looks up to answer, which can include client names, email and postal addresses, VAT and Peppol IDs, and invoice, contract, expense, bank-transaction and time-tracking records.Only when an account holder uses receipt scanning, AI collections or the Co-Pilot.To be confirmedTo be confirmed
StripeSubscription billing for account holders, and online card payment of invoices when an account holder connects Stripe.Account holder's name, email, billing address and subscription; for invoice payments, the invoice amount and reference and the payer's payment details entered at Stripe checkout.On every useTo be confirmedTo be confirmed
PayPalOnline payment of invoices when an account holder connects PayPal.The invoice amount and reference, and the payer's details entered at PayPal checkout.Only when an account holder connects PayPal.To be confirmedTo be confirmed
Enable BankingBank feed: connecting an account holder's bank account and reading its transactions to match incoming payments to invoices.Bank account details and transactions, including counterparty names and payment references.Only when an account holder connects a bank account.To be confirmedTo be confirmed
RecommandDelivery of e-invoices over the Peppol network.The e-invoice, including the seller's and buyer's names, addresses, VAT and Peppol identifiers.Only when an account holder sends an invoice via Peppol.To be confirmedTo be confirmed
ip-api.comApproximate location (country, region, city) for the login history and unusual-sign-in alerts.The IP address of each sign-in.On every useTo be confirmedTo be confirmed
PostHogProduct analytics.Page views and product events with a pseudonymous identifier.Only after a visitor opts in to analytics in the cookie banner or settings.To be confirmedTo be confirmed
Email delivery providerDelivery of transactional email: invoices, reminders, contracts and account notices.Recipient email addresses and names, and the message content.On every useTo be confirmedTo be confirmed

Retention periods

These are the periods the system enforces automatically.

DataKept for
Deleted accounts: the grace period during which a deleted account can be reactivated, after which its data is erased.30 days
Login history (IP address, browser, device and approximate location).548 days
In-app notifications.365 days
Signed-out and revoked sessions.30 days
Email-verification and password-reset links, after they expire.30 days
Records of AI operations and the credits they used.730 days
Plan usage alerts.365 days
Invoice delivery and view logs (including the viewer IP address and browser).730 days
Issued invoices of an erased account, kept in anonymized form to meet tax record-keeping law.10 years
Bank-feed transactions that were never matched to a payment.730 days
Co-Pilot conversations, counted from their last message.90 days
Uploaded files nothing uses any more, such as an abandoned receipt scan or a replaced logo.24 hours