SmartInvoice
DemoFeaturesPricingContact
Sign InStart Free Trial
Data Protection

GDPR Compliance

We're committed to protecting your privacy rights under the General Data Protection Regulation.

SmartInvoice is fully GDPR compliant and registered with the UK Information Commissioner's Office (ICO)

Our Commitment to GDPR

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that gives EU/EEA residents control over their personal data. Even though we're based in the UK, we apply GDPR standards to all users globally.

As a data processor handling sensitive financial documents, we take our responsibilities seriously. This page explains how we comply with GDPR and how you can exercise your rights.

Data Controller: SmartInvoice Ltd
DPO Contact: dpo@smartinvoice.finance

Your Data Rights

Under GDPR, you have specific rights regarding your personal data. Here's how to exercise them.

Article 15

Right to Access

You can request a copy of all personal data we hold about you, including uploaded documents, extracted data, account information, and usage logs.

Request Data Export →
Article 16

Right to Rectification

You can correct any inaccurate personal data we hold. Update your profile information directly in your account settings or contact us for assistance.

Update Profile →
Article 17

Right to Erasure

You can request deletion of your personal data. This includes your account, all uploaded documents, extracted data, and associated records.

Delete My Data →
Article 18

Right to Restrict Processing

You can request that we limit how we process your data while we verify accuracy or assess our legitimate interests.

Restrict Processing →
Article 20

Right to Data Portability

You can receive your data in a structured, commonly used format (JSON, CSV) to transfer to another service provider.

Export Data →
Article 21

Right to Object

You can object to processing based on legitimate interests, direct marketing, or research/statistical purposes.

Submit Objection →

Data We Collect & Process

Transparency about what data we collect, why, and how long we keep it.

CategoryData CollectedPurposeRetention
Account InformationEmail address, Name, Password (hashed), Profile settingsAccount management and authenticationUntil account deletion + 30 days
Financial DocumentsUploaded bank statements, Invoices, ReceiptsDocument processing and data extraction30 days after processing (configurable)
Extracted DataTransactions, Account balances, Vendor informationProviding core service functionalityUntil account deletion
Payment InformationBilling address, Payment method (via Stripe)Processing payments and subscriptions7 years (legal requirement)
Usage DataFeatures used, Pages viewed, Processing historyService improvement and analytics90 days

Legal Bases for Processing

Contract Performance (Article 6(1)(b))

Processing your documents and providing our services requires handling your data as part of our contractual obligations to you.

Legitimate Interests (Article 6(1)(f))

We use anonymized analytics to improve our service, detect fraud, and ensure security. We've conducted legitimate interest assessments for these activities.

Consent (Article 6(1)(a))

For optional features like marketing emails and analytics cookies, we obtain your explicit consent. You can withdraw consent at any time.

Legal Obligation (Article 6(1)(c))

We retain certain records (like payment history) to comply with tax, accounting, and anti-money laundering regulations.

Response Times

Data Subject Requests

We respond to all GDPR requests within 30 days. Complex requests may take up to 60 days, and we'll notify you of any extension.

Data Breach Notification

In case of a data breach affecting your rights, we'll notify you and the relevant supervisory authority within 72 hours.

Submit a GDPR Request

To exercise any of your rights, please contact our Data Protection Officer. We may need to verify your identity before processing your request.

Email DPORead Privacy Policy

You also have the right to lodge a complaint with a supervisory authority (e.g., ICO in the UK, your local DPA in the EU).

Platform developed by AI Makers • 10-12 Snipweg, Willemstad, Curaçao

SmartInvoice

AI-Powered Bank Statement Processing. Automate your financial workflows with AI-powered document processing and real-time insights.

twitter
linkedin

Product

  • Features
  • Pricing
  • Changelog
  • Roadmap

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Security
  • GDPR

© 2025 SmartInvoice Ltd. All rights reserved.

|

Built by AI Makers

All systems operational