Legal

Privacy Policy

We take your privacy seriously. This policy explains what data we collect, how we use it, and what rights you have. Last updated: August 2026.

1. Overview

TaxItEasy® ("we", "us", "our") operates the TaxItEasy platform for invoice processing and document management. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services.

We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.

2. Data Controller

The data controller responsible for processing your personal data is:

THE GROVVEST AI LTD
Evangelou Floraki 10, Villa 4
8220 Paphos, Cyprus

Email: [email protected]
Website: taxiteasy.org

3. What Data We Collect

3.1 Account Data

When you create an account, we collect:

  • Name — Your first and last name
  • Email address — Used for login, verification, and communication
  • Phone number — Optional, for account recovery and communication
  • Password — Stored only as an Argon2 hash (we never see your actual password)
  • Language preference — Your preferred language for emails and notifications (German or English)
  • Notification preferences — Your custom notification settings
  • Two-factor authentication — If enabled, we store an encrypted TOTP secret for generating verification codes

3.2 Company Data

When you create a company on our platform, we collect:

  • Company name and legal form
  • Business address — Street, city, postal code, state/province, country
  • Tax identification number — Tax ID, VAT number, or EIN (optional)
  • Company registration number — e.g. Handelsregister (optional)
  • Banking information — IBAN, routing number, and SWIFT/BIC code (optional, stored from invoice data)
  • Billing details — Billing email, billing address, and billing VAT ID for invoice generation

3.3 Document Data

When you upload documents, we process:

  • Uploaded files — Invoices, receipts, bank statements, and other documents you upload
  • Extracted data — Invoice numbers, amounts, dates, VAT rates, sender/recipient details, line items, and other data extracted by our AI
  • Metadata — Upload timestamps, file sizes, file types, processing status, and file hashes
  • OCR data — Full text extracted from documents via optical character recognition, including confidence scores
  • Version history — Previous versions of re-uploaded documents

3.4 Banking & Transaction Data

If you import a bank statement (via statement-file upload, e.g. PDF; automated bank connections are planned), we collect:

  • Bank account details — IBAN, BIC, account holder name, bank name, account type, and current balance
  • Transactions — Transaction date, amount, currency, description, counterparty name/IBAN, merchant information, and categorization
  • Bank statements — Statement periods, opening/closing balances, and transaction summaries
  • OAuth tokens — Encrypted access and refresh tokens for API connections (you can revoke access at any time)

3.5 Email Integration Data

If you set up automatic email invoice forwarding, we collect:

  • Email credentials — Your email address and app password, stored encrypted (AES) on our servers
  • IMAP settings — Server address, port, and folder to monitor
  • Processing logs — Email subject, sender address, received date, and number of attachments processed

3.6 Sharing Data

When you share documents with others (e.g. tax advisors), we collect:

  • Recipient information — Name and email address of the person you share with
  • Access logs — IP address, browser information, and timestamps of each access to shared documents
  • Share settings — Access level, expiry date, password protection status, and access limits

3.7 Usage Data

When you use our platform, we automatically collect:

  • IP address — For security, rate limiting, and audit logging
  • User agent — Browser and device information
  • Action logs — Records of actions taken within the platform (uploads, shares, logins, downloads)
  • Timestamps — When actions were performed
  • Login security data — Failed login attempts, account lockout timestamps

3.8 Payment Data

Payment processing is handled by Stripe (PCI-DSS Level 1 compliant). We do not store or have access to your full credit card numbers. We store:

  • Stripe customer and subscription IDs
  • Subscription status, plan, and billing interval
  • Payment confirmation and invoice records (amount, status, dates)
  • Last 4 digits of your payment method (for display purposes only)
  • Usage records per billing period (invoices processed, storage used)

3.9 Website Assistant (Chat) Data

Our public website carries an AI assistant that answers questions about the product. You do not need an account to use it, and it has no access to any account, document, banking or tax data — it can only read our published website content. When you type a message into it, we collect:

  • The message text you type — stored as you wrote it, so please do not type tax IDs, IBANs, card numbers or other sensitive details into it
  • The assistant's reply, and whether you rated it helpful
  • The page you were on when you opened the chat, and the language of that page
  • A random session identifier — generated in your browser tab so the assistant can follow the conversation. It is not linked to any account, and it is not an identifier we can trace back to you

We do not store your IP address or a browser fingerprint against the conversation. See section 11 for who processes these messages and section 6 for how long we keep them.

4. How We Use Your Data

We process your personal data for the following purposes:

Purpose Legal Basis (GDPR)
Providing the TaxItEasy service Contract performance (Art. 6(1)(b))
AI invoice processing and OCR Contract performance (Art. 6(1)(b))
Account verification and security Legitimate interest (Art. 6(1)(f))
Audit logging and access tracking Legitimate interest (Art. 6(1)(f))
Payment processing via Stripe Contract performance (Art. 6(1)(b))
Email notifications about your account Contract performance (Art. 6(1)(b))
Responding to support requests Contract performance (Art. 6(1)(b))
Bank account integration and transaction matching Contract performance (Art. 6(1)(b))
Automatic email invoice processing Contract performance (Art. 6(1)(b))
Document sharing with tax advisors Contract performance (Art. 6(1)(b))
Newsletter (only if you subscribe, double opt-in) Consent (Art. 6(1)(a))
Answering questions in the website assistant, and improving its answers Legitimate interest (Art. 6(1)(f))
We do not

We do not sell your data. We do not share your data with advertisers. We do not use your data for profiling or targeted advertising. We do not train AI models on your documents.

4a. Newsletter & Direct Marketing

If you sign up for our newsletter on taxiteasy.org, we send you a weekly email about EU tax and compliance topics and TaxItEasy product news. Subscribing is entirely optional and separate from having a TaxItEasy account.

Legal basis and double opt-in

The legal basis is your consent (Art. 6(1)(a) GDPR). We use double opt-in: after you submit your email address, we send you a confirmation email, and only after you click the confirmation link do you become a subscriber. Without confirmation, no newsletter is ever sent to your address.

What we store

  • Email address — the address you subscribe with
  • Consent proof — timestamp and IP address of the signup request and of the confirmation, plus the version of the consent text you agreed to (required to demonstrate consent under Art. 7(1) GDPR)
  • Signup source — the page you signed up on and, if your visit came from a campaign link, its UTM parameters

No tracking in newsletter emails

Our newsletter emails contain no open tracking (no tracking pixels) and no per-recipient click tracking — this is a deliberate decision, not a technical limitation. Links in the newsletter lead directly to their destination. We measure how newsletter content performs only in aggregate, first-party, on our own website (see Section 10 on cookies and analytics consent).

Sending and storage

Newsletter emails are delivered through Resend, Inc. (United States), under Standard Contractual Clauses — see our Sub-processors page. Unconfirmed signups are deleted after 30 days. Confirmed subscriptions are kept until you unsubscribe.

Unsubscribing and withdrawal of consent

You can withdraw your consent at any time: every newsletter email contains an unsubscribe link that works without logging in. Withdrawal stops all further newsletter emails immediately and does not affect the lawfulness of processing before the withdrawal. You can also contact us at [email protected].

5. Where We Store Your Data

Your primary data — documents, invoices, account records, bank transactions — is stored on servers physically located in Frankfurt, Germany (EU), operated by DigitalOcean (DOKS Kubernetes cluster, managed PostgreSQL, Spaces object storage). Your data does not leave the European Union for storage.

Documents are stored in encrypted object storage. Database records are stored in encrypted PostgreSQL databases. All connections between services use TLS encryption.

AI extraction (OCR / document reading) uses the Anthropic API. Anthropic, PBC is located in the United States. Transfers to Anthropic for AI processing are made under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs). Retention of API request content follows Anthropic's commercial default (up to 30 days for safety monitoring); a contractual zero-retention addendum is in active negotiation. Messages typed into the AI assistant on our public website are sent to Anthropic in the United States on the same terms — see section 11a. See our Sub-processors page for the full list and transfer mechanisms.

6. How Long We Keep Your Data

Data Type Retention Period
Account data Until account deletion
Documents and invoices Until deleted by you, or 30 days after account deletion
Deleted documents (recycle bin) 30 days after deletion, then permanently removed
Audit logs — tax-relevant entries (documents, invoices, transactions, banking, billing) 10 years (legal retention duty for tax-relevant records)
Audit logs — security events (logins, account changes, shares incl. share access logs) 2 years
Audit logs — other operational events 6 months
IP addresses in audit logs Anonymized after 90 days
Payment records 10 years (legal requirement for financial records)
Bank transactions Until deleted by you, or 30 days after account deletion
Email integration credentials Until you disconnect the email account
Bank connection tokens (OAuth) Until you revoke the connection
Website assistant conversations (messages and replies) 90 days, then permanently deleted

7. Who We Share Your Data With

We share your data only with the following recipients (sub-processors and authorized third parties), and only to the extent necessary. The complete current list with locations and transfer mechanisms is on our Sub-processors page.

  • DigitalOcean, LLC (cloud infrastructure) — Hosts our Kubernetes cluster, managed PostgreSQL database, and Spaces object storage in Frankfurt, Germany (EU). DigitalOcean is a US-incorporated company; data residency in Frankfurt is contractually guaranteed. DigitalOcean Privacy Policy
  • Anthropic, PBC (AI provider) — Processes document content (invoices, receipts) for field extraction via the Claude API, and generates the answers of our public website assistant from the messages typed into it. Located in the United States. Transfers under EU-U.S. Data Privacy Framework and SCCs. Retention follows Anthropic's commercial default (up to 30 days for safety monitoring); a contractual zero-retention addendum is in active negotiation. Anthropic Privacy Policy
  • Stripe, Inc. (payment processor) — Receives payment-related data only. Located in the United States. Transfers under EU-U.S. Data Privacy Framework and SCCs. Stripe Privacy Policy
  • Resend (outbound transactional + newsletter email) — Sends transactional emails (verification, notifications, receipts) and, if you subscribe, newsletter emails on our behalf. Resend Privacy Policy
  • MailPace (OhMySMTP Ltd) (inbound email receiving) — Receives emails forwarded to your private @in.taxiteasy.org address and delivers them to our systems for processing. UK company; email data is hosted in France (EU) with backups in Germany (EU). Transfers covered by the UK adequacy decision. MailPace Privacy Policy
  • Mistral AI SAS (website assistant) — Generates text embeddings for the public website assistant (chatbot). Receives only messages typed into the website assistant — no account, document, banking, or tax data. EU provider located in France; we configure processing within the EU.
  • Sentry (error monitoring) — Receives application error events with limited PII (user ID, IP). Used to detect and fix bugs. Sentry Privacy Policy
  • Cloudflare, Inc. (CDN & network security) — Web traffic to our public website (taxiteasy.org) passes through Cloudflare for DDoS protection, WAF, and CDN. Processes IP addresses and request metadata but has no access to documents or account content. Cloudflare Privacy Policy
  • Your tax advisor (if you invite one) — Receives access only to invoices and transactions for the company you invite them to. Permissions and revocation are managed in your settings.
  • Google (Gmail) / Microsoft (Outlook) (email integration, optional) — If you connect Gmail or Outlook via OAuth, we read invoice emails (read-only scope). OAuth tokens are encrypted at rest.

We do not sell, rent, or otherwise share your personal data with any other third parties.

7a. Google API Services — Limited Use Disclosure

TaxItEasy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We request the gmail.readonly scope only to identify and parse invoice / receipt emails on your behalf. We never modify, send, or delete email on your account.
  • Data obtained via Google APIs is used only to provide and improve user-facing features within TaxItEasy — specifically: detecting invoice emails, extracting attachments, and surfacing them in your document inbox.
  • We do not use Gmail data to develop, improve, or train generalized AI / machine-learning models. Per-account OCR / classification runs on the attachments you choose to ingest, never as training input for shared models.
  • We do not transfer Gmail data to third parties except as necessary to provide or improve user-facing features (e.g. our OCR sub-processor) or to comply with applicable law.
  • We do not allow humans to read Gmail data unless we have your explicit consent for specific messages, it is necessary for security purposes (e.g. investigating abuse), to comply with applicable law, or for our internal operations and where the data is aggregated and anonymized.
  • You can revoke our access at any time from the “Email Accounts” settings in TaxItEasy or via your Google Account > Security > Third-party access. On revoke we delete the OAuth token locally and call Google's revocation endpoint to invalidate it server-side.

8. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

Right of Access (Art. 15)

You can request a copy of all personal data we hold about you at any time.

Right to Rectification (Art. 16)

You can request correction of inaccurate or incomplete data. You can also update most data directly in your account settings.

Right to Erasure (Art. 17)

You can request complete deletion of all your data. We will delete your account, documents, invoices, and all associated data within 30 days of your request.

Right to Data Portability (Art. 20)

You can export all your data in JSON (structured, machine-readable) at any time from your account settings. CSV and PDF export are on the 2026 roadmap.

Right to Restrict Processing (Art. 18)

You can request that we limit the processing of your data under certain circumstances.

Right to Object (Art. 21)

You can object to processing based on legitimate interest. We will stop processing unless we demonstrate compelling legitimate grounds.

To exercise any of these rights, contact our data-protection contact at [email protected] (or general support at [email protected]). We will respond to your request within 30 days.

9. Security Measures

We implement the following technical and organizational measures to protect your data:

  • Encryption in transit — All data transfers use TLS encryption
  • Encryption at rest — All stored data is encrypted with AES-256
  • Password hashing — Argon2, a modern memory-hard one-way hash
  • Access control — Role-based access with principle of least privilege
  • Tenant isolation — Complete data separation between companies at the database level
  • Rate limiting — Protection against brute-force and abuse
  • Account lockout — Automatic lockout after 10 failed login attempts (30-minute lock)
  • Audit logging — Complete trail of all user actions
  • File validation — Magic bytes validation to prevent malicious uploads
  • Temporary download links — Presigned URLs expire after 1 hour

10. Cookies & Consent

TaxItEasy uses strictly necessary cookies to run the service, plus — only with your explicit consent — preference storage and anonymous analytics. Our website loads Google Tag Manager (container GTM-MZCTLJZD) and Google Analytics 4 (property G-2XK83JG0B3) with Consent Mode v2: all consent signals default to “denied”, and analytics storage is enabled only after you accept the Analytics category in the cookie banner. Advertising signals (ad_storage, ad_user_data, ad_personalization) are permanently denied, regardless of your banner choice — we do not use advertising, retargeting, or social-media tracking cookies.

Cookie / storage Purpose Duration
Session token (strictly necessary) Keeps you logged in Session / 7 days
CSRF token (strictly necessary) Protects against cross-site request forgery 1 year
Consent record (strictly necessary) Stores your cookie choices as evidence of consent Until revoked
Preferences (opt-in) Stores your UI preferences (sidebar state, theme, recent currencies) Persistent until cleared
_ga, _ga_* (opt-in) Google Analytics 4 — anonymous usage statistics, set only after you consent to Analytics 2 years
ref (opt-in) Partner-referral attribution — remembers the ?ref code from a partner link so your sign-up credits the referring partner; set only after you consent to Attribution 90 days
__cf_bm (strictly necessary) Cloudflare bot detection — distinguishes legitimate users from automated traffic 30 minutes
cf_clearance (strictly necessary) Cloudflare challenge verification — set after passing a DDoS or WAF challenge 24 hours

You can change or revoke your consent at any time via the “Cookie settings” link in the footer. The complete list of every cookie and local-storage entry — including what happens when you revoke — is in our Cookie Policy. The Cloudflare cookies listed above are strictly necessary security cookies set by our CDN provider and cannot be disabled without affecting the security and availability of the service.

11. AI and Automated Processing

When you upload invoices and documents, our AI system automatically processes them to extract structured data (invoice numbers, amounts, dates, etc.). This constitutes automated processing under GDPR.

  • AI extraction is performed via the Anthropic Claude API. Anthropic, PBC is located in the United States. The transfer is governed by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs). Retention of API request content follows Anthropic's commercial default (up to 30 days for safety monitoring); a contractual zero-retention addendum is in active negotiation.
  • Our primary infrastructure (Kubernetes, database, object storage) is EU-hosted in Frankfurt (DigitalOcean DOKS).
  • Your documents are not used to train or improve any AI models — ours or Anthropic's.
  • AI-extracted data is always presented for your review before being finalized
  • You can manually correct any AI-extracted data at any time
  • No automated decisions with legal or similarly significant effects are made

11a. The AI assistant on this website

Separately from document processing, our public website carries an AI assistant that answers questions about the product. It is anonymous, requires no account, and has no access to customer data of any kind — it answers only from our published website content. What you type into it is processed as follows:

  • The answer is generated by the Anthropic Claude API. Anthropic, PBC is located in the United States, under the EU-U.S. Data Privacy Framework and SCCs. The same retention applies as above: up to 30 days for Anthropic's safety monitoring, with a zero-retention addendum in active negotiation.
  • To find the right help article, your message is also turned into a numeric representation by Mistral AI SAS, located in France (EU). We pin their EU endpoint explicitly.
  • We store the conversation for 90 days and then delete it permanently. It is stored unencrypted, which is why the assistant asks you not to type sensitive details into it.
  • Your conversations are not used to train or improve any AI models — ours, Anthropic's, or Mistral's.
  • The assistant does not give tax advice and makes no automated decisions about you.
We cannot identify your chat, and that limits your rights over it

A conversation is keyed only by a random identifier that lives in your browser tab and is gone when you close it. We hold nothing that links it to you — no account, no email, no IP address. That means we genuinely cannot find your conversation if you ask us to, and we therefore cannot act on an access or deletion request for it (Art. 11(2) GDPR). If you can still supply that identifier, contact [email protected] and we will act on it. Otherwise the conversation is deleted automatically after 90 days.

12. Children's Privacy

TaxItEasy is a business tool and is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through a prominent notice on our platform at least 30 days before the changes take effect.

The "Last updated" date at the top of this page indicates when this policy was last revised.

14. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about how we handle your data, please contact us:

You also have the right to lodge a complaint with a supervisory authority in your EU member state if you believe your data protection rights have been violated.

Questions?

If anything in this policy is unclear, don't hesitate to reach out at [email protected]. We're happy to explain how we handle your data.