Skip to content

Privacy policy

What kvitr stores about you and your invoices, why, who else processes it, how it is protected and what you can ask us to do.

Last updated

Who is responsible

kvitr runs the service at kvitr.com. For your account, we decide how data is used, so we are the controller. For the invoices and supplier details in a workspace, your company decides and we process them on its behalf; the GDPR page describes that relationship. Reach us at hello@kvitr.com.

What we store

  • Account: your name, email address, a hash of your password (never the password itself) and sign-in sessions, which include the IP address and browser used.
  • Workspace: its name, company details such as legal name, company or VAT number, country, address, email domains and time zone, and who is a member with which access.
  • Invoices: the original PDF, the fields read from it (supplier, invoice number, dates, amounts, currency), where it came from (sender, subject, filename or provider record), the supplier’s details and what kvitr learned about that supplier from your reviews.
  • Connections: mailbox app passwords, API tokens and saved billing-dashboard sessions.
  • Operational data: record identifiers, dates, file sizes, collection status and server logs kept for security and troubleshooting.
  • Contact form: the name, email address and message you send us.

Why, and on what basis

We process this data to provide the service you signed up for: collecting invoices from the sources you connect, reading and storing them, and showing them to your workspace. That is performance of our contract with you. Keeping the service secure, preventing abuse and keeping records the law requires rest on our legitimate interest and on legal obligations.

Email is used for account verification, password recovery, invitations and replies to your messages. We do not send marketing email, show ads or sell data.

How invoice data is protected

Stored invoice PDFs, the fields read from them, supplier details, saved connection credentials, company details and workspace choices are encrypted at rest with AES-256-GCM. Traffic between your browser and kvitr, and between kvitr and providers, is encrypted in transit. Our servers decrypt data when they collect invoices, read a PDF, build a report or deliver a document to an authorised member; the text of a PDF is read in memory and is not stored.

Account identity, session records, identifiers, dates, sizes and status are needed to run the service and are not covered by that application-level encryption. The Privacy and security page in the Guide describes this in more detail.

Who else processes your data

We use a small number of providers to run the service, each under a data processing agreement:

  • Vercel hosts the application, its functions and scheduled jobs.
  • MongoDB Atlas stores the database and the encrypted invoice files.
  • Resend delivers account email and receives the email you forward to your workspace address.
  • Cloudflare runs the bot check on the contact form.
  • Billing-dashboard collection runs in a browser on a worker operated by kvitr.

Invoices are read by software running inside kvitr; they are not sent to an external AI service. Where a provider processes data outside the EU or EEA, the transfer relies on the EU Standard Contractual Clauses or an adequacy decision.

Cookies

kvitr sets only the cookies it needs to work: one that keeps you signed in and one that remembers which workspace you opened. There are no analytics or advertising cookies, so there is nothing to consent to.

How long we keep data

Your account and workspace data stay for as long as the account and workspace exist. Disconnecting a source removes its credentials but keeps the invoices it collected. When you ask us to delete a workspace or account, we delete its invoices, files, connections and settings; copies in our providers’ backups expire on their schedules. Queued account emails expire within an hour of being sent, and sign-in sessions expire after seven days without use.

Your rights

You can ask to see the data we hold about you, have it corrected or deleted, restrict or object to how we use it, and receive a copy of it. Invoices can be downloaded and exported from the app at any time. Write to hello@kvitr.com; we answer within a month. If you are unhappy with our answer you can complain to your data protection authority, in Denmark the Danish Data Protection Agency (Datatilsynet).

Changes to this policy

When this policy changes we update the date at the top of the page and tell you about material changes by email or in the app.