Legal · updated 2026-09-25

Privacy policy

How Invoreg collects, uses and protects personal data on this website and in the Invoreg service, under the GDPR.

Effective 25 September 2026. This policy explains how Invoreg (“we”, “us”) handles personal data when you visit invoreg.com, contact us, book a demo, or use the Invoreg service. It is written for the EU General Data Protection Regulation (GDPR) and Malta’s Data Protection Act. It will be reviewed by counsel before public launch; the operating company’s legal name, registration number and registered address will be inserted here.

Who is responsible

The data controller for this website and for our marketing is Invoreg, [legal entity name, company number, registered address, Malta/EU]. Contact: hello@invoreg.com.

For documents that accounting firms and their clients upload to the Invoreg service, the firm is the data controller and Invoreg is a data processor acting on the firm’s instructions under a data processing agreement (DPA). A DPA is available on request.

What we collect and why

| Situation | Data | Purpose | Legal basis | Kept for | | --- | --- | --- | --- | --- | | You visit the site | IP address, browser and device type, pages viewed, referrer (server logs and, once enabled, privacy-respecting analytics) | Run and secure the site; understand which pages are useful | Legitimate interest (Art. 6(1)(f)) | Logs 30 days; aggregated analytics indefinitely | | You book a demo or contact us | Name, work email, company, country, accounting software, invoice volume, preferred time, your message | Reply to you, arrange the demo, follow up about Invoreg | Steps prior to a contract at your request (Art. 6(1)(b)); consent for follow-up marketing where you tick the box (Art. 6(1)(a)) | Until the enquiry is closed, then up to 24 months unless you become a customer | | You use the Invoreg service | Account details (name, email, role), organisation settings, activity logs | Provide the service, secure accounts, support | Contract (Art. 6(1)(b)) | Life of the account plus 12 months | | Documents you upload to the service | Supplier invoices and other documents, which may contain names, addresses, bank details and VAT numbers of third parties | Read, classify and register documents as instructed by your firm | Processed on the firm’s behalf under the DPA; the firm holds the legal basis | As set by the firm; deleted documents are recoverable for the retention period the firm sets, then removed |

We do not sell personal data, and we do not use your documents to train AI models.

Where data is processed

Documents and account data are processed on Invoreg infrastructure located in the European Union. Invoice content is processed and stored in EU regions only. If a sub-processor outside the EU is ever used (for example for email delivery), transfers rely on the European Commission’s Standard Contractual Clauses and are listed in the sub-processor list available on request.

Sub-processors

We use a small number of service providers to run the site and service: hosting and content delivery (Vercel), transactional email (Resend), and the accounting integrations you connect (via OAuth with the minimum scopes needed to read master data and post bills). A current list with locations is available on request and will be published here before launch.

Cookies

The website sets no advertising or tracking cookies. Strictly necessary cookies may be set by the hosting platform for security. If we add analytics or embedded video (YouTube, using the privacy-enhanced no-cookie domain), this section and a consent banner will be updated first.

Your rights

Under the GDPR you can ask us to access, correct, delete or restrict your personal data, object to processing based on legitimate interest, and receive a copy in a portable format. Where processing relies on consent, you can withdraw it at any time. Write to hello@invoreg.com; we respond within one month. If you are unhappy with our answer you can complain to the Information and Data Protection Commissioner in Malta (idpc.org.mt) or your local supervisory authority.

For documents processed on behalf of an accounting firm, please contact that firm first; we will assist them in meeting your request.

Security

Access to the service is role-based and every action on a document is logged. Data is encrypted in transit and at rest. Integration tokens are stored encrypted and can be revoked from the connected accounting system at any time. We notify affected firms of a personal data breach without undue delay, as the DPA requires.

Marketing email

We send marketing email only with prior consent, which is required in Malta for unsolicited email to businesses as well as individuals. Every email includes an unsubscribe link, and we keep a suppression list so you are not contacted again.

Changes

We will post changes here with a new effective date. Material changes affecting customers are notified by email.