We take your privacy seriously. This policy explains what data we collect, how we use it, and what rights you have. Last updated: August 2026.
TaxItEasy® ("we", "us", "our") operates the TaxItEasy platform for invoice processing and document management. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services.
We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.
The data controller responsible for processing your personal data is:
THE GROVVEST AI LTD
Evangelou Floraki 10, Villa 4
8220 Paphos, Cyprus
Email: [email protected]
Website: taxiteasy.org
When you create an account, we collect:
When you create a company on our platform, we collect:
When you upload documents, we process:
If you import a bank statement (via statement-file upload, e.g. PDF; automated bank connections are planned), we collect:
If you set up automatic email invoice forwarding, we collect:
When you share documents with others (e.g. tax advisors), we collect:
When you use our platform, we automatically collect:
Payment processing is handled by Stripe (PCI-DSS Level 1 compliant). We do not store or have access to your full credit card numbers. We store:
Our public website carries an AI assistant that answers questions about the product. You do not need an account to use it, and it has no access to any account, document, banking or tax data — it can only read our published website content. When you type a message into it, we collect:
We do not store your IP address or a browser fingerprint against the conversation. See section 11 for who processes these messages and section 6 for how long we keep them.
We process your personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the TaxItEasy service | Contract performance (Art. 6(1)(b)) |
| AI invoice processing and OCR | Contract performance (Art. 6(1)(b)) |
| Account verification and security | Legitimate interest (Art. 6(1)(f)) |
| Audit logging and access tracking | Legitimate interest (Art. 6(1)(f)) |
| Payment processing via Stripe | Contract performance (Art. 6(1)(b)) |
| Email notifications about your account | Contract performance (Art. 6(1)(b)) |
| Responding to support requests | Contract performance (Art. 6(1)(b)) |
| Bank account integration and transaction matching | Contract performance (Art. 6(1)(b)) |
| Automatic email invoice processing | Contract performance (Art. 6(1)(b)) |
| Document sharing with tax advisors | Contract performance (Art. 6(1)(b)) |
| Newsletter (only if you subscribe, double opt-in) | Consent (Art. 6(1)(a)) |
| Answering questions in the website assistant, and improving its answers | Legitimate interest (Art. 6(1)(f)) |
We do not sell your data. We do not share your data with advertisers. We do not use your data for profiling or targeted advertising. We do not train AI models on your documents.
If you sign up for our newsletter on taxiteasy.org, we send you a weekly email about EU tax and compliance topics and TaxItEasy product news. Subscribing is entirely optional and separate from having a TaxItEasy account.
The legal basis is your consent (Art. 6(1)(a) GDPR). We use double opt-in: after you submit your email address, we send you a confirmation email, and only after you click the confirmation link do you become a subscriber. Without confirmation, no newsletter is ever sent to your address.
Our newsletter emails contain no open tracking (no tracking pixels) and no per-recipient click tracking — this is a deliberate decision, not a technical limitation. Links in the newsletter lead directly to their destination. We measure how newsletter content performs only in aggregate, first-party, on our own website (see Section 10 on cookies and analytics consent).
Newsletter emails are delivered through Resend, Inc. (United States), under Standard Contractual Clauses — see our Sub-processors page. Unconfirmed signups are deleted after 30 days. Confirmed subscriptions are kept until you unsubscribe.
You can withdraw your consent at any time: every newsletter email contains an unsubscribe link that works without logging in. Withdrawal stops all further newsletter emails immediately and does not affect the lawfulness of processing before the withdrawal. You can also contact us at [email protected].
Your primary data — documents, invoices, account records, bank transactions — is stored on servers physically located in Frankfurt, Germany (EU), operated by DigitalOcean (DOKS Kubernetes cluster, managed PostgreSQL, Spaces object storage). Your data does not leave the European Union for storage.
Documents are stored in encrypted object storage. Database records are stored in encrypted PostgreSQL databases. All connections between services use TLS encryption.
AI extraction (OCR / document reading) uses the Anthropic API. Anthropic, PBC is located in the United States. Transfers to Anthropic for AI processing are made under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs). Retention of API request content follows Anthropic's commercial default (up to 30 days for safety monitoring); a contractual zero-retention addendum is in active negotiation. Messages typed into the AI assistant on our public website are sent to Anthropic in the United States on the same terms — see section 11a. See our Sub-processors page for the full list and transfer mechanisms.
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Documents and invoices | Until deleted by you, or 30 days after account deletion |
| Deleted documents (recycle bin) | 30 days after deletion, then permanently removed |
| Audit logs — tax-relevant entries (documents, invoices, transactions, banking, billing) | 10 years (legal retention duty for tax-relevant records) |
| Audit logs — security events (logins, account changes, shares incl. share access logs) | 2 years |
| Audit logs — other operational events | 6 months |
| IP addresses in audit logs | Anonymized after 90 days |
| Payment records | 10 years (legal requirement for financial records) |
| Bank transactions | Until deleted by you, or 30 days after account deletion |
| Email integration credentials | Until you disconnect the email account |
| Bank connection tokens (OAuth) | Until you revoke the connection |
| Website assistant conversations (messages and replies) | 90 days, then permanently deleted |
We share your data only with the following recipients (sub-processors and authorized third parties), and only to the extent necessary. The complete current list with locations and transfer mechanisms is on our Sub-processors page.
We do not sell, rent, or otherwise share your personal data with any other third parties.
TaxItEasy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
gmail.readonly scope only to identify and parse invoice / receipt emails on your behalf. We never modify, send, or delete email on your account.
As a data subject under the GDPR, you have the following rights:
You can request a copy of all personal data we hold about you at any time.
You can request correction of inaccurate or incomplete data. You can also update most data directly in your account settings.
You can request complete deletion of all your data. We will delete your account, documents, invoices, and all associated data within 30 days of your request.
You can export all your data in JSON (structured, machine-readable) at any time from your account settings. CSV and PDF export are on the 2026 roadmap.
You can request that we limit the processing of your data under certain circumstances.
You can object to processing based on legitimate interest. We will stop processing unless we demonstrate compelling legitimate grounds.
To exercise any of these rights, contact our data-protection contact at [email protected] (or general support at [email protected]). We will respond to your request within 30 days.
We implement the following technical and organizational measures to protect your data:
TaxItEasy uses strictly necessary cookies to run the service, plus — only
with your explicit consent — preference storage and anonymous analytics. Our website loads
Google Tag Manager (container GTM-MZCTLJZD) and
Google Analytics 4 (property G-2XK83JG0B3) with
Consent Mode v2: all consent signals default to “denied”, and
analytics storage is enabled only after you accept the Analytics category in the cookie banner.
Advertising signals (ad_storage, ad_user_data,
ad_personalization) are permanently denied, regardless of your
banner choice — we do not use advertising, retargeting, or social-media tracking cookies.
| Cookie / storage | Purpose | Duration |
|---|---|---|
| Session token (strictly necessary) | Keeps you logged in | Session / 7 days |
| CSRF token (strictly necessary) | Protects against cross-site request forgery | 1 year |
| Consent record (strictly necessary) | Stores your cookie choices as evidence of consent | Until revoked |
| Preferences (opt-in) | Stores your UI preferences (sidebar state, theme, recent currencies) | Persistent until cleared |
_ga, _ga_* (opt-in) |
Google Analytics 4 — anonymous usage statistics, set only after you consent to Analytics | 2 years |
ref (opt-in) |
Partner-referral attribution — remembers the ?ref code from a partner link so your sign-up credits the referring partner; set only after you consent to Attribution |
90 days |
__cf_bm (strictly necessary) |
Cloudflare bot detection — distinguishes legitimate users from automated traffic | 30 minutes |
cf_clearance (strictly necessary) |
Cloudflare challenge verification — set after passing a DDoS or WAF challenge | 24 hours |
You can change or revoke your consent at any time via the “Cookie settings” link in the footer. The complete list of every cookie and local-storage entry — including what happens when you revoke — is in our Cookie Policy. The Cloudflare cookies listed above are strictly necessary security cookies set by our CDN provider and cannot be disabled without affecting the security and availability of the service.
When you upload invoices and documents, our AI system automatically processes them to extract structured data (invoice numbers, amounts, dates, etc.). This constitutes automated processing under GDPR.
Separately from document processing, our public website carries an AI assistant that answers questions about the product. It is anonymous, requires no account, and has no access to customer data of any kind — it answers only from our published website content. What you type into it is processed as follows:
A conversation is keyed only by a random identifier that lives in your browser tab and is gone when you close it. We hold nothing that links it to you — no account, no email, no IP address. That means we genuinely cannot find your conversation if you ask us to, and we therefore cannot act on an access or deletion request for it (Art. 11(2) GDPR). If you can still supply that identifier, contact [email protected] and we will act on it. Otherwise the conversation is deleted automatically after 90 days.
TaxItEasy is a business tool and is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through a prominent notice on our platform at least 30 days before the changes take effect.
The "Last updated" date at the top of this page indicates when this policy was last revised.
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about how we handle your data, please contact us:

You also have the right to lodge a complaint with a supervisory authority in your EU member state if you believe your data protection rights have been violated.
If anything in this policy is unclear, don't hesitate to reach out at [email protected]. We're happy to explain how we handle your data.