This is a translation of the Dutch original. If the two differ, the Dutch text prevails.
This statement is about the personal data we process when you use factuurmaken or visit our website. We have tried to write down what the app really does, not what reads well. Do you see something that does not match what you see in the app? Let us know and we will correct it.
Who is responsible for your data
The controller is the company named at the top of this page, with the Chamber of Commerce number, the address and the privacy e-mail address listed there. factuurmaken is the trade name the service is offered under.
No data protection officer has been appointed: the organisation is too small for that and the processing is not large-scale enough. So your questions come straight to us.
Which data we process and why
If you make an invoice without an account
While you build an invoice, it lives in your own browser. We see nothing. Only when you check out do we store the invoice: your own company details, your client’s details, the lines and the amounts. That is needed to produce the PDF and let you download or e-mail it.
An anonymous invoice like that has a short retention period and disappears automatically afterwards. You have no account, so we cannot find it for you after that either.
If you have an account
Then we process:
- your account details: your name, your e-mail address and whatever you fill in on your company profile, including your address, your Chamber of Commerce number, your VAT number, your IBAN and your logo. These end up on your invoices verbatim, so they are needed to deliver the service.
- your clients: name, contact person, address, e-mail address, Chamber of Commerce and VAT number. If you save a private individual, those are personal data of a natural person.
- your documents: invoices, quotes, lines, notes and the amounts. On creation we freeze the sender and recipient details, so a later change to your profile does not rewrite your old invoices.
- your payments to us: which amount, which plan, when, and whether it succeeded.
- when you were here: the moment of your last visit and the last page you looked at. We use that to see whether an account is still in use and to help you when you ask a question.
A limited number of administrators on our side can view those account details. That is needed for support and for managing trial and complimentary accounts.
If your administration sits still for a while, we may send you one e-mail about it per period. We do that on the basis of our legitimate interest in keeping the service useful, and you can switch it off in your preferences in the app.
If you give an accountant access
If you give an accountant access to your administration, they can view and download your issued invoices. Drafts stay out of their reach. If you withdraw access, that stops immediately, but copies already delivered to them are beyond our reach.
If you arrive through a partner
If you arrive through a link from a partner in our partner programme, we remember for 60 days which partner that was, so we can reward them if you become a customer. That partner is shown no name, e-mail address or company name: they see only the date, the plan, whether payment was made and what they earn from it. Who invoices with us is not something we pass on, not even to the party who referred you.
If you are a partner yourself, we process your company’s details (company name, contact person, e-mail address, phone number, website, Chamber of Commerce number, VAT number and bank account) in order to assess the application and pay out the fee. We do that on the basis of the agreement that the partner programme is.
If your client receives an invoice from you
Your clients’ data are your data, not ours. For those you are the controller and we are the processor: we do with them what you instruct us to and nothing else. If you want that recorded in writing, a processor agreement is available, see article 11 of the terms and conditions.
If you send an invoice by e-mail, we record which address it went to, when, and whether it was delivered or refused. If your client opens the view link, we see that it was viewed. There is no invisible tracking pixel in our e-mails: they are inaccurate and intrusive, so we do not use them. We measure a click, not an opening.
If you use the contact form
Then we process your name, your e-mail address and your message, in order to answer your question. The form is protected against abuse by bots, and that check sees your IP address.
If you visit the website
Then technical data are processed that come with any visit to any website, such as your IP address and your browser. Our hosting party uses those to deliver the site and to spot outages and abuse. For visitor statistics we use a cookieless service, see Cookies below.
On which legal basis
- Performance of the contract. Everything needed to make your invoice, run your account, send your documents and process your payment.
- Legal obligation. Our own records of the payments you make to us, because a statutory retention obligation applies to those.
- Legitimate interest. The security of the service, keeping abuse out, anonymised visitor statistics, and the e-mail you get when your administration sits still for a long time.
- Consent. The integrations you switch on yourself, such as your bank and your cloud storage. If you do not switch them on, nothing happens. If you withdraw them, it stops.
Parties that process data on our behalf
These parties are always involved, because the service does not work without them. A processor agreement is in place with each of them.
- Hosting. Runs the website and the app. Therefore sees all traffic, including your IP address and what you submit.
- Database. Stores what is listed above.
- Sign-in. Manages your e-mail address, your name and your session. If you choose to sign in with Apple or LinkedIn, that runs through that party.
- Payments. We deliberately send as little as possible: no name, no e-mail address and no address. Only the country, our order number, the amount and a short description, plus an internal customer number if you set up a recurring mandate. You enter your bank or card details with the payment service itself and they never pass through us.
- E-mail. Sends all e-mail from the app, including the invoice PDF and the e-invoice as attachments. So it sees your client’s e-mail address and the content of the message.
- Scheduled tasks. Triggers the recurring jobs, such as reminders and clean-up. This party receives no personal data, only the signal that a job should start.
- Logo storage. Your logo sits on a content network under a random filename, so your invoice loads quickly. The link contains no account detail.
- Bot check. Only on the contact form, and only that one check. Sees your IP address.
- Statistics. Cookieless and without personal data, in production only. No Google Analytics, no advertising pixels.
Services you switch on yourself
These are off until you switch them on. If you do not, nothing goes to them.
- Dutch trade register (KVK). If you look up a company to fill in a form, your search term goes to the register. We keep the answer briefly, so a second search for the same company costs nothing extra.
- Bank integration. If you connect your bank to tick off payments automatically, we fetch your transactions at the moment of checking and do not store them. We do store your IBAN, a reference to your account and an encrypted key allowing us to look again.
- Cloud storage. If you connect Dropbox, Google Drive or Microsoft OneDrive, we put a copy of your issued invoices in your own folder. For that we store the e-mail address of that account and an encrypted key.
Transfers outside the European Economic Area
Some of the parties above are established in the EU, among them the payment service, the bank integration, the logo storage, the statistics service and the trade register. For those there is no transfer outside the EEA.
Other parties are established outside the EEA or have a parent company there. For those cases the transfer is covered in the processor agreement, through the EU-US Data Privacy Framework or through the European Commission’s standard contractual clauses.
Do you want to know per party who it is, where the data sit and which safeguard applies? Ask for it through the privacy e-mail address at the top of this page and we will send the current list.
Cookies
We only use cookies that are needed to make the service work or to remember a choice of yours:
- sign-in cookies, so you stay signed in. These are set by our sign-in party.
- a hint that you are probably signed in (30 days), so a public page can show the right menu straight away without having to fetch your session.
- your last used sign-in method (a year) and the method of an attempt in progress (10 minutes), so the sign-in screen offers you the right button first.
- a referral code (60 days), if you arrive through an invitation from an existing user or through a partner link.
- a short security cookie (10 minutes) while connecting your bank or your cloud storage, to complete the connection.
- your language choice, so the site stays in the language you pick.
Why you see no cookie banner
Because there is nothing to ask. All the cookies above are strictly necessary or a preference you set yourself, and those need no consent. Our visitor statistics work without cookies and without personal data, and we do not follow you across other websites. There is no advertising cookie on this site and no party watching along here to build you a profile.
How we secure your data
- All traffic to the site and the app runs over an encrypted connection.
- Three kinds of keys are kept additionally encrypted: the key to your bank integration, the one to your cloud storage and the one to your own payment integration.
- We do not manage your bank or card details ourselves. You enter those with the payment service.
- Access to the database is limited to those who need it to run the service.
No measure is watertight. Do you suspect a leak or see something odd? Report it through the privacy e-mail address at the top of this page and we will look at it right away.
How long we keep data
Two rules, and the rest follows from them:
- We keep nothing longer than is needed for the purpose we have it for.
- What we are legally required to keep, we keep for as long as required. For the records of the payments you make to us that is seven years.
The concrete periods the app itself keeps to are at the bottom of this page, under Retention periods in the app.
Important: what we keep is not your archive. Your own bookkeeping is subject to a seven-year statutory retention obligation, and that is your responsibility. Download your invoices as a PDF or an e-invoice, or switch on the cloud integration, so you always have your own copy.
Your rights
You have the right to:
- see which personal data we hold about you
- have them corrected if they are wrong
- have them deleted, insofar as we are not legally required to keep them
- have the processing restricted or object to it
- take your data to another party
- withdraw consent you have given, for an integration for example
How to exercise them
Part of it you can do yourself: you edit your profile and your clients in the app, and you delete a client, product, draft invoice or integration there yourself too.
There is no button yet to delete your whole account or export it in one go. We are going to build that, but until it exists we do it by hand: send your request to the privacy e-mail address at the top of this page. We respond within a month, and usually a good deal sooner. To avoid sending someone else’s data, we ask you to send the request from the e-mail address of your account.
Complaint with the supervisory authority
If you disagree with how we handle your data, tell us first. If we cannot resolve it together, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You always have that right, also without coming to us first.
Changes to this privacy statement
If the service changes, this statement changes with it. The top of the page says when we last updated it. For a change that genuinely matters to you, we will let you know by e-mail or in the app.