Roles
The invoices, supplier details and connected accounts in a workspace are your company’s data. Your company decides why and how they are used and is the controller; kvitr processes them only to provide the service and is the processor. For account data such as your name, email and sessions, kvitr is the controller, as described in the privacy policy.
What we process on your behalf
- Invoice PDFs and the fields read from them.
- Supplier names, company numbers, addresses, sender addresses and what kvitr learned from your reviews.
- Message metadata and attachments from the mailbox folder and period you chose, and from email forwarded to your workspace address.
- API tokens, app passwords and billing-dashboard sessions, stored encrypted.
The purpose is collecting, storing, reading, organising, reporting on and exporting supplier invoices. Your instructions are the settings, sources and reviews you configure in the app; we do not process this data for our own purposes.
Sub-processors
We rely on the following providers. Each is bound by a data processing agreement, and transfers outside the EU or EEA rest on the EU Standard Contractual Clauses or an adequacy decision.
- Vercel Inc.: hosting, serverless functions and scheduled jobs.
- MongoDB Inc. (MongoDB Atlas): database and encrypted file storage.
- Resend Inc.: account email and receiving forwarded invoice email.
- Cloudflare Inc.: the bot check on the contact form.
Billing-dashboard collection runs on a worker operated by kvitr. We update this list before adding a sub-processor that handles workspace data.
Security measures
- AES-256-GCM encryption at rest for invoice files, invoice fields, supplier details, credentials and company details; TLS in transit.
- Passwords stored as hashes; email verification before an account is used; rate limits on sign-in and account email.
- Workspace isolation checked on every request; owner, member and viewer roles; API keys stored as hashes.
- Credentials decrypted only while collecting; PDF text read in memory and never stored; queued account email encrypted and expiring within an hour.
- Invoices read by software inside kvitr, not by an external AI service.
Data subject requests
If a person asks your company about data held in kvitr, we help you answer. Members can find, download and export invoices themselves; for anything else, write to hello@kvitr.com.
Personal data breaches
If we become aware of a breach affecting your workspace data, we tell the workspace owner without undue delay, with what we know about what happened, what is affected and what we are doing about it.
Deletion and return
You can export PDFs and invoice data from the app at any time. When a workspace ends, or on request, we delete its invoices, files, connections and settings and confirm when it is done. Provider backups expire on their schedules.
Data processing agreement
A signed data processing agreement covering the points on this page is available on request at hello@kvitr.com. Until it is signed, this page and the terms of service describe how we process data for you. We provide the information reasonably needed to demonstrate compliance and, where required, support audits.