Privacy Policy
Last updated: 28 June 2026
This Policy explains what personal data Invoister collects, why, and your rights under the EU General Data Protection Regulation (GDPR). We aim to keep it short and clear.
1. Who is responsible
The data controller is Mykyta Ryzhov ("Invoister"). For any privacy question or to exercise your rights, contact [email protected].
2. What we collect and why
We collect only what we need to run the Service. The table below sets out each category, why we use it, and the legal basis under GDPR Article 6.
| Data | Purpose | Legal basis |
|---|---|---|
| Account data (email, name) | Create and secure your account | Performance of a contract |
| Business profile, clients, invoices | Provide the core invoicing features | Performance of a contract |
| AI assistant content you send | Answer your requests in the assistant | Performance of a contract |
| Analytics cookies (PostHog, in your browser) | Understand and improve the product | Consent |
| First-party product-usage events (server-side) | Operate, secure, and improve the Service | Legitimate interest |
| Essential cookies | Keep you signed in, remember settings | Necessary for the Service |
| Payment details | Billing — handled by our Merchant of Record; we never store card data | Performance of a contract |
| Support emails | Respond to your enquiries | Legitimate interest |
3. How we use your data
We use your data to provide and secure the Service, to bill you (via our Merchant of Record), to improve the product (using analytics cookies only with your consent, and limited first-party usage events under our legitimate interest), and to comply with our legal obligations. We do not sell your personal data.
5. International transfers
We host data in the EU where possible (our database and analytics run in EU regions). Where a processor is outside the EU/EEA, the transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
We retain invoice and tax-related records for a minimum of 4 years, as required by Spanish tax law (Ley General Tributaria, Art. 66). Other account and personal data is deleted within 30 days of a deletion request, and removed from backups within 90 days. Analytics data is retained according to our analytics provider's defaults.
7. Your rights
Under GDPR (Articles 15–22) you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent at any time. You can export your data and request deletion directly from Settings → Privacy, or email [email protected].
You also have the right to lodge a complaint with your data-protection authority. In Spain this is the AEPD (aepd.es).
9. Security
Data is encrypted in transit and at rest, access is restricted, and our database enforces row-level security so each account can only access its own data. No system is perfectly secure, but we apply industry-standard measures.
10. Children
The Service is not directed at people under 18, and we do not knowingly collect their data.
11. Changes to this Policy
We may update this Policy. We will notify you of material changes by email or in-app.
12. Contact
Privacy questions: [email protected].