Short version: We collect only the data needed to run your invoicing account. We never sell your data. You can delete your account and all data at any time. We comply with EU GDPR.
1 Controller (Data Owner)
The data controller responsible for your personal data is:
2 What data we collect
We collect the following categories of personal data:
- Account data: name, email address, password (hashed).
- Company data: company name, registration number, VAT number, address, IBAN — entered by you.
- Invoice data: invoices you create, client names, client emails, amounts.
- Technical data: IP address, browser type, session data — for security only.
We do not collect payment card data. We do not use advertising trackers.
3 Why we process your data (legal basis)
- Contract performance (Art. 6(1)(b) GDPR): to provide you with the invoicing service you registered for.
- Legitimate interest (Art. 6(1)(f) GDPR): security, fraud prevention, service improvement.
- Legal obligation (Art. 6(1)(c) GDPR): complying with Estonian accounting and tax law.
4 How long we keep your data
- Account and invoice data: as long as your account is active.
- After account deletion: data is permanently deleted within 30 days.
- Invoice records may be retained for 7 years if required by Estonian accounting law (Raamatupidamise seadus §12).
5 Who we share data with
We do not sell or rent your data. We may share data with:
- Email service provider (for sending invoice emails) — data processor under contract.
- Hosting provider — servers located in EU.
- Authorities — only if required by Estonian or EU law.
Your invoice emails are sent to your clients on your behalf — this is the core function of the service.
6 Your rights (GDPR)
As an EU resident, you have the following rights regarding your personal data:
- Right of access — request a copy of all data we hold about you.
- Right to rectification — correct inaccurate data via your profile settings.
- Right to erasure — delete your account and all associated data.
- Right to data portability — export your invoices as PDF or XML at any time.
- Right to object — object to processing based on legitimate interest.
To exercise any right, email us at: tallinn@milard.ee (subject: ARVE1.EE Privacy Request). We respond within 30 days.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): www.aki.ee.
7 Cookies
We use only essential cookies required for the service to function:
- PHPSESSID — session cookie, keeps you logged in. Deleted when you close the browser.
- lang — saves your language preference.
No advertising or tracking cookies. No third-party analytics (Google Analytics, Facebook Pixel, etc.).
8 Data security
- Passwords stored as bcrypt hashes — never in plain text.
- All connections secured via HTTPS / TLS.
- Database access restricted to the application only.
- Daily automated backups stored in EU.
9 Changes to this policy
We may update this policy. When we do, we will update the date at the top and notify registered users by email if changes are significant.
10 Contact
For any privacy-related questions: