Security and GDPR are the base layer, not an upsell.
EU (Estonian) controller. Lawful bases, data-subject rights, and a full DPA for business customers.
TLS in transit, row-level security, and private signed-URL file storage.
Registration and VAT fields, plus an optional identity-verification flow.
Download invoices as PDFs anytime, request a full account export, and delete your account whenever you choose.
Invoicing records kept per the Estonian Accounting Act (Raamatupidamise seadus); the rest deleted after closure.
A short, transparent list under DPAs with EU SCC / UK IDTA safeguards.
Straight answers
The application runs on DigitalOcean; the database and files live in Supabase, EU region. Invoices, documents and personal data stay in the EU by default.
Yes — automated daily database backups on our hosting stack, with files stored redundantly. Losing your data is not an acceptable failure mode for us.
TLS 1.2+ for everything in transit, AES-256 at rest. Documents are served through signed, expiring URLs — never public links.
GDPR-first by design: a DPA is available, subprocessors are listed publicly, hosting is EU-based, and data-protection requests are answered within one month.
Your invoices are downloadable as PDFs at any time, and you can request a full data export at [email protected] — self-serve export is on the roadmap.
From Settings → Privacy, or by email. Personal data is removed within 30 days, except records the law requires to keep (e.g. issued invoices).
Team plans add seats with roles — admin, member, viewer — so your accountant can read the numbers without touching the settings.
Read the Privacy Policy, DPA and Terms.