Privacy policy
What we process, why, for how long — and what expressly does not happen. Two roles appear in this, and they are not the same: on this site we are the controller, for the data in your account you are.
As at: 2026-09-08
01Controller
MR²Consulting Ruediger & Rheinlaender Ltd, Evagora Pallikaridi 38, 8010 Paphos, Cyprus (HE 449045). Questions about data protection and the exercise of your rights: datenschutz@mr2consulting.com. There is no designated data protection officer — the conditions of Article 37 GDPR are not met.
02The two roles
For visiting this site, the contact form and your user account we are the controller within the meaning of Article 4(7) GDPR.
For the data you keep in Invobookz — your customers, suppliers, invoices, receipts and bank movements — YOU are the controller and we are your processor under Article 28 GDPR. What we may do with it is not set out here but in the data processing agreement you conclude with us. Data subjects turn to you in that case, not to us; if a request nevertheless reaches us, we forward it to you and do not answer it ourselves.
03Visiting this site
The site runs on Vercel Inc. in region `fra1` (Frankfurt am Main). Technical access data arises in the process — IP address, time, address requested, browser identification. It serves operation and defence against attacks and is not combined with other data. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a service that stays reachable.
There is NO audience measurement. We use no analytics tool, no tracking pixels, no advertising networks, and we load no third-party fonts at runtime — the fonts sit on the same server as the page. That is also why this site has no consent banner: there is nothing to consent to.
04Cookies
We set exactly one cookie, and only after you sign in: it holds your session. It is bound to the host name you signed in under — a session on scan.invobookz.com does not apply on app.invobookz.com and vice versa. It is technically necessary (Article 6(1)(b) GDPR) and expires with the session.
05Contact form
We process name, company, e-mail address and your message in order to answer the enquiry (Article 6(1)(b) or (f) GDPR). Dispatch runs through Resend Inc. We keep the enquiry for as long as the matter lasts, and beyond that only where commercial or tax law periods require it.
Before submission, Cloudflare Turnstile checks whether the request comes from a human. Your IP address is transmitted to Cloudflare Inc. in the process. Turnstile sets no advertising identifiers and builds no profile across sites. The legal basis is Article 6(1)(f) GDPR — without that check the form would be a bulk-mail tool within days.
06User account and sign-in
For your account we process e-mail address, name and a password check value. We do not store the password itself: it is turned into a bcrypt check value from which it cannot be computed back. The legal basis is Article 6(1)(b) GDPR.
We count failed sign-in attempts in order to slow down password guessing. Your IP address is NOT stored in the process, only a SHA-256 check value derived from it — enough to recognise two attempts of the same origin, too little to name that origin. These entries are deleted after 24 hours at the latest, by an hourly run rather than only on the next failed attempt.
07Receipt reading by a language model
Invobookz can read receipts instead of having them typed in. For that, the image or PDF is transmitted to Anthropic PBC in the USA. This happens ONLY if you have switched it on in the settings; the default is off, and you can withdraw it at any time with immediate effect (Article 6(1)(a) GDPR).
- Anthropic does NOT use the content to train models.
- Retention at the provider is limited to 30 days.
- The result is a PROPOSAL. It takes effect only once a human confirms it — there is no automated decision within the meaning of Article 22 GDPR.
08Recipients
We use five processors. Article 28 GDPR agreements are in place with all of them. There are no others — in particular no provider for error monitoring, audience measurement or advertising.
| Recipient | For what | Location |
|---|---|---|
| Neon Inc. | Database including receipt files | AWS eu-central-1, Frankfurt |
| Vercel Inc. | Hosting and delivery | Runtime fra1, Frankfurt |
| Resend Inc. | Dispatch of invoice and system e-mails | Dispatched from eu-west-1 (Ireland), stored in the USA |
| Cloudflare Inc. | Turnstile — protection of sign-in and form | global |
| Anthropic PBC | Receipt reading, only with consent | USA |
Your own cloud storage and your bank are NOT recipients in this sense: they are your systems. Invobookz accesses them only because you stored the credentials, and in the case of the bank read-only.
09Transfers to third countries
Your receipts, invoices and bank data reside in Frankfurt. Three recipients go beyond this: Resend stores the data arising from mail dispatch (recipient, subject, delivery log) in the USA, Cloudflare checks at whichever location is closest to you, and Anthropic processes in the USA.
The basis is the adequacy decision on the EU-US Data Privacy Framework and, in addition, the standard contractual clauses under Implementing Decision (EU) 2021/914.
10How long we store
| What | How long |
|---|---|
| Receipts, invoices, bank movements | as long as your account exists; for tax purposes they must be kept for six years in Cyprus |
| User account | until the account is deleted |
| Sign-in attempts | at most 24 hours, and only as a check value |
| Contact enquiries | until the matter is settled |
| Server access data | short term, for operation and defence |
11Your rights
You have the right of access (Article 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21). Any consent given — for instance to receipt reading — can be withdrawn at any time; processing carried out until then remains lawful.
Write to datenschutz@mr2consulting.com. We answer within one month. Access and data portability are provided on request today and delivered within 14 days; a self-service route for this is being built.
You may also lodge a complaint with a supervisory authority. The authority responsible for us is the Office of the Commissioner for Personal Data Protection in Nicosia, Cyprus; you may equally turn to the authority of your place of residence or work (Article 77 GDPR).
12Changes
If who processes on our behalf changes, we announce it here before it takes effect. The date above says which version you are reading.