Privacy Policy
Last updated: 2026-07-21
InvoiceAlert, Sofia, Bulgaria ("we", "us") operates InvoiceAlert. This Privacy Policy explains what personal data we process, why, and your rights under the GDPR.
1. Two roles: controller and processor
We act as data controller for the account data of the person who registers and logs into InvoiceAlert (name, email, login activity). We act as data processor for the data our business Customers upload about their own clients (names, emails, invoice amounts, VAT numbers) — that processing is governed by the Data Processing Agreement, and the Customer remains the controller of that data.
2. What we collect
Account data (you, as a registered user)
- Name, email address, password (stored hashed, never in plain text), role (admin/viewer), login timestamps and IP address (for security/audit logging).
Data you upload about your own clients (processed on your behalf)
- Client name, email address(es), nationality/company details, invoice numbers, amounts, due dates, payment status.
- Email delivery logs (recipient, timestamp, content summary) for audit and rate-limiting purposes.
3. Legal basis
- Contract (Art. 6(1)(b) GDPR) — to provide the Service you subscribed to.
- Legitimate interest (Art. 6(1)(f)) — security logging, fraud/abuse prevention, service improvement.
- Legal obligation (Art. 6(1)(c)) — accounting/tax records where applicable.
4. How data flows — sub-processors
We use the following categories of sub-processor. A current, named list is available on request (see Contact).
- Hosting — the application and database run on a cloud server located in the EU (Frankfurt, Germany).
- Outbound email delivery — reminder emails are sent via the SMTP provider you configure in your own account settings (e.g. your own Microsoft 365/Google Workspace mailbox, or a transactional email provider). Where your configured provider cannot be reached directly from our primary hosting region, the message is relayed through an intermediary relay server we operate, solely to complete delivery — it does not store your message content beyond what's needed to relay it.
- Backups — encrypted daily database backups are kept on our primary server and, if offsite backup is enabled in your account, additionally uploaded to a separate storage location under our control.
5. Retention
- Account/client/invoice data: retained for the duration of your subscription plus 30 days after termination, then deleted, unless a longer period is required by law.
- Local backups: rotated on a 7-day cycle. Offsite backups (if enabled): currently kept without automatic rotation until an offsite retention policy is configured.
- Security/audit logs: 90 days.
6. Security measures
We apply technical and organizational measures appropriate to the risk, including: encryption of stored credentials (database passwords are encrypted at rest, not stored in plain text), TLS-encrypted connections for the application and for outbound email relay, password hashing (bcrypt), rate limiting on authentication and bulk-email endpoints, restricted server access, and regular internal security review.
7. International transfers
Our primary hosting is within the EU/EEA. Where a sub-processor is located outside the EU/EEA, we rely on Standard Contractual Clauses as adopted by the European Commission.
8. Your rights
Under the GDPR you have the right to: access your data, request correction or erasure, restrict or object to processing, and data portability. If your data was uploaded by a business you're a client of (not you directly), please first contact that business — they are the data controller for that data. To exercise rights over your own account data, contact us (see below). You may also lodge a complaint with the Bulgarian Commission for Personal Data Protection (КЗЛД, cpdp.bg) or your local supervisory authority.
9. Cookies
We use only strictly necessary session cookies required for login and security (CSRF protection) — no third-party tracking or advertising cookies.
10. Changes to this Policy
We may update this Policy from time to time; material changes will be notified by email.
11. Contact
Privacy / DPO email: [email protected]
InvoiceAlert, Sofia, Bulgaria