Privacy policy

What we process, why, for how long — and what expressly does not happen. Two roles appear in this, and they are not the same: on this site we are the controller, for the data in your account you are.

As at: 2026-09-08

01Controller

MR²Consulting Ruediger & Rheinlaender Ltd, Evagora Pallikaridi 38, 8010 Paphos, Cyprus (HE 449045). Questions about data protection and the exercise of your rights: datenschutz@mr2consulting.com. There is no designated data protection officer — the conditions of Article 37 GDPR are not met.

02The two roles

For visiting this site, the contact form and your user account we are the controller within the meaning of Article 4(7) GDPR.

For the data you keep in Invobookz — your customers, suppliers, invoices, receipts and bank movements — YOU are the controller and we are your processor under Article 28 GDPR. What we may do with it is not set out here but in the data processing agreement you conclude with us. Data subjects turn to you in that case, not to us; if a request nevertheless reaches us, we forward it to you and do not answer it ourselves.

03Visiting this site

The site runs on Vercel Inc. in region `fra1` (Frankfurt am Main). Technical access data arises in the process — IP address, time, address requested, browser identification. It serves operation and defence against attacks and is not combined with other data. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a service that stays reachable.

There is NO audience measurement. We use no analytics tool, no tracking pixels, no advertising networks, and we load no third-party fonts at runtime — the fonts sit on the same server as the page. That is also why this site has no consent banner: there is nothing to consent to.

04Cookies

We set exactly one cookie, and only after you sign in: it holds your session. It is bound to the host name you signed in under — a session on scan.invobookz.com does not apply on app.invobookz.com and vice versa. It is technically necessary (Article 6(1)(b) GDPR) and expires with the session.

05Contact form

We process name, company, e-mail address and your message in order to answer the enquiry (Article 6(1)(b) or (f) GDPR). Dispatch runs through Resend Inc. We keep the enquiry for as long as the matter lasts, and beyond that only where commercial or tax law periods require it.

Before submission, Cloudflare Turnstile checks whether the request comes from a human. Your IP address is transmitted to Cloudflare Inc. in the process. Turnstile sets no advertising identifiers and builds no profile across sites. The legal basis is Article 6(1)(f) GDPR — without that check the form would be a bulk-mail tool within days.

06User account and sign-in

For your account we process e-mail address, name and a password check value. We do not store the password itself: it is turned into a bcrypt check value from which it cannot be computed back. The legal basis is Article 6(1)(b) GDPR.

We count failed sign-in attempts in order to slow down password guessing. Your IP address is NOT stored in the process, only a SHA-256 check value derived from it — enough to recognise two attempts of the same origin, too little to name that origin. These entries are deleted after 24 hours at the latest, by an hourly run rather than only on the next failed attempt.

07Receipt reading by a language model

Invobookz can read receipts instead of having them typed in. For that, the image or PDF is transmitted to Anthropic PBC in the USA. This happens ONLY if you have switched it on in the settings; the default is off, and you can withdraw it at any time with immediate effect (Article 6(1)(a) GDPR).

  • Anthropic does NOT use the content to train models.
  • Retention at the provider is limited to 30 days.
  • The result is a PROPOSAL. It takes effect only once a human confirms it — there is no automated decision within the meaning of Article 22 GDPR.

08Recipients

We use five processors. Article 28 GDPR agreements are in place with all of them. There are no others — in particular no provider for error monitoring, audience measurement or advertising.

RecipientFor whatLocation
Neon Inc.Database including receipt filesAWS eu-central-1, Frankfurt
Vercel Inc.Hosting and deliveryRuntime fra1, Frankfurt
Resend Inc.Dispatch of invoice and system e-mailsDispatched from eu-west-1 (Ireland), stored in the USA
Cloudflare Inc.Turnstile — protection of sign-in and formglobal
Anthropic PBCReceipt reading, only with consentUSA

Your own cloud storage and your bank are NOT recipients in this sense: they are your systems. Invobookz accesses them only because you stored the credentials, and in the case of the bank read-only.

09Transfers to third countries

Your receipts, invoices and bank data reside in Frankfurt. Three recipients go beyond this: Resend stores the data arising from mail dispatch (recipient, subject, delivery log) in the USA, Cloudflare checks at whichever location is closest to you, and Anthropic processes in the USA.

The basis is the adequacy decision on the EU-US Data Privacy Framework and, in addition, the standard contractual clauses under Implementing Decision (EU) 2021/914.

10How long we store

WhatHow long
Receipts, invoices, bank movementsas long as your account exists; for tax purposes they must be kept for six years in Cyprus
User accountuntil the account is deleted
Sign-in attemptsat most 24 hours, and only as a check value
Contact enquiriesuntil the matter is settled
Server access datashort term, for operation and defence

11Your rights

You have the right of access (Article 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21). Any consent given — for instance to receipt reading — can be withdrawn at any time; processing carried out until then remains lawful.

Write to datenschutz@mr2consulting.com. We answer within one month. Access and data portability are provided on request today and delivered within 14 days; a self-service route for this is being built.

You may also lodge a complaint with a supervisory authority. The authority responsible for us is the Office of the Commissioner for Personal Data Protection in Nicosia, Cyprus; you may equally turn to the authority of your place of residence or work (Article 77 GDPR).

12Changes

If who processes on our behalf changes, we announce it here before it takes effect. The date above says which version you are reading.