Skip to main content
Invoice-Converter.comInvoice-Converter
BlogPricing
Convert InvoiceConvert
ConvertConvert Invoice

This Privacy Policy is available in English and German. In case of any discrepancy, the German version is legally binding.

English|Deutsch

Privacy Policy

Last Updated: February 27, 2025

Welcome to Invoice-Converter.com ("we", "us", or "our"). This Privacy Policy explains how we collect, use, and protect your personal data when you use our services. We are committed to protecting your privacy and complying with all applicable data protection laws, including the EU General Data Protection Regulation (GDPR). By using Invoice-Converter.com, you agree to the practices described in this policy.

1. Identity of Data Controller (Imprint)

Data Controller: Felix Gräber (operating as a registered Gewerbe in Germany).

Business Address: CAYA Postbox 652326, 96035 Bamberg, Germany
Contact Email: contact@invoice-converter.com

(Note: Invoice-Converter.com is not a limited liability company. It is operated by an individual sole proprietor. As such, Felix Gräber is personally responsible for the business. Liability is not limited by corporate status.)

2. Web Hosting and Service Providers

Hosting (Vercel, Koyeb): We use Vercel for frontend delivery and preview environments and Koyeb for backend workloads and related infrastructure. Depending on the request path, technical metadata and uploaded content may be processed through these providers on EU infrastructure or under appropriate transfer safeguards.

Cloudflare (Domain Management & Security):We use Cloudflare for domain, DNS, and security services. Traffic passes through Cloudflare's global network, which may temporarily process your IP address and request data. Cloudflare employs Standard Contractual Clauses (SCCs) for international data transfers.

OpenAI API:We use the OpenAI API (provided by OpenAI in the U.S.) to convert invoice content. Invoice data is sent securely to the API for processing and returned to fulfill your request. We rely on OpenAI's Data Processing Addendum and SCCs to protect your data under GDPR standards.

PostHog: We use PostHog for product analytics and session replay, helping us understand how the site is used. PostHog is hosted on EU servers (Frankfurt, Germany) and data does not leave the EU. Analytics data is only collected with your consent.

Mistral AI: We may use large-language-model APIs from Mistral AI (Paris, France) as an additional processor for invoice data extraction. Processing is intended to take place within the EU.

Google AI Platform (Gemini OCR): For OCR and extraction workflows, we may use Google Ireland Ltd./Google LLC. If Gemini-based OCR is enabled for a workflow, invoice data may be processed under Standard Contractual Clauses (SCCs) and other applicable safeguards.

Stripe: Payments are processed via Stripe Technology Europe (Dublin, Ireland) and Stripe, Inc. (USA). Your billing details (e‑mail, payment method, address) are shared with Stripe under SCCs.

Supabase: We use Supabase (hosted in Frankfurt, Germany) for authentication and the user database. Supabase may access data from the USA for support under SCCs.

Brevo: We use Brevo for transactional and marketing email delivery. Depending on the message, this may include your email address, language preference, unsubscribe status, and message metadata necessary to send or document the email.

3. Personal Data We Collect and Use

a. Visiting Our Website: We collect technical data (IP address, time of access, referrer URL, etc.) in server logs for security and performance analysis. This processing is based on our legitimate interests (Art. 6(1)(f) GDPR).

b. Creating an Account: We collect necessary registration data (email address, hashed password, optionally your name/company). The legal basis is contract performance (Art. 6(1)(b) GDPR).

c. Converting Invoices: When you upload a PDF for conversion, its content may include personal data (names, addresses, line items). We transmit invoice data securely to the AI and infrastructure providers required for the requested workflow, including OpenAI and, where enabled, Google Gemini OCR. Uploaded files and generated artifacts are not kept in a permanent central archive, but may be stored temporarily to complete processing, provide downloads, generate validation proofs, and investigate failures.

d. Cookies and Tracking: We use essential cookies for site functionality and analytics cookies (with your consent) to measure performance. You can opt out of analytics at any time by rejecting cookies in our consent banner.

e. Marketing Communications: When you create an account, we use your email address to send service updates, promotional content, newsletters, and marketing communications about our services and industry-related information. The legal basis for this processing is our legitimate business interest (Art. 6(1)(f) GDPR) in keeping customers informed about relevant services and updates, or your consent where required by applicable law. You can opt out at any time using the unsubscribe link in our emails or by contacting us directly.

4. Data Processing for Invoice Conversion (Processing on Behalf)

When you upload invoices for conversion, we act as a data processor on your behalf. The data within these invoices may contain personal data of third parties (e.g., your customers or suppliers). Your use of the Service for this purpose is governed by our Data Processing Agreement (DPA), which complies with Article 28 GDPR. You can find the DPA here.

We process this invoice data solely for the purpose of providing the conversion service to you. We may disclose it only to contracted sub-processors where necessary for hosting, AI processing, payment processing, email delivery, security, analytics with consent, or where disclosure is required by law. The current sub-processor list is set out in this Policy and in the DPA.

5. Data Retention and Deletion

- Invoices: Source uploads are deleted after processing. Where required for asynchronous processing, download links, validation proofs, or troubleshooting, we may temporarily retain generated artifacts and limited technical metadata for a short period. We do not operate a permanent central archive of uploaded customer documents.

- Account Data: We keep registration info as long as you have an account. You may delete your account anytime, and we will remove your data unless legally required to keep it longer.

- Analytics: PostHog analytics data is retained in accordance with our data retention settings. We use aggregated data to understand traffic patterns.

- Marketing Communications: We retain your email address for marketing communications as long as you have an account and have not opted out. When you opt out or delete your account, we immediately stop sending marketing emails and remove your data from marketing lists. We may retain opt-out records to respect your preferences and for compliance purposes.

- Server Logs: Automatically deleted after a short period unless needed for security investigations.

6. Your Rights

You have the right to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of Processing (Art. 18 GDPR)
  • Data Portability (Art. 20 GDPR)
  • Object (Art. 21 GDPR), especially to direct marketing or certain legitimate-interest processing
  • Withdraw Consent at any time, without affecting prior lawful processing

To exercise these rights, email us at contact@invoice-converter.com. We may ask for identity verification. We typically respond within one month.

7. Right to Lodge a Complaint

If you believe your data protection rights are violated, you can lodge a complaint with your local supervisory authority or the relevant German authority:

Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Website: www.lda.bayern.de
E-Mail: poststelle@lda.bayern.de

8. Data Security Measures

We use HTTPS encryption, secure hosting, and strict access controls. Passwords are hashed. Invoice files are deleted immediately after processing. Though no method is 100% secure, we strive to protect your data against unauthorized access or breach. If a breach occurs, we will notify you and authorities as required by law.

9. Disclaimer and Limitation of Liability

Accuracy of Conversion:We do not guarantee the completeness or accuracy of converted invoices. The output is provided "as is." Users must verify compliance with legal or customer requirements. We are not liable for losses arising from inaccuracies.

Service Availability: We do not guarantee uninterrupted availability; outages can occur. We are not liable for damages from service downtime or third-party failures (OpenAI, Cloudflare, hosting, etc.).

Data Transmission: We employ encryption and best practices, but transmission over the Internet has inherent risks. We are not liable for unauthorized interceptions or hacking beyond our reasonable control.

10. Changes to this Privacy Policy

We may update or modify this Policy to reflect changes in our practices or legal requirements. When we do, we will revise the "Last Updated" date and, for significant changes, notify users via email or prominent notice on our site. Your continued use of Invoice-Converter.com constitutes acceptance of the revised Policy.

11. Contact Information

For questions or requests related to this Privacy Policy, please contact:

Felix Gräber (Owner)
Email: contact@invoice-converter.com
Address: CAYA Postbox 652326, 96035 Bamberg, Germany

Invoice-Converter.com

Empowering businesses across Europe to effortlessly comply with XRechnung regulations. Join hundreds who've automated their invoice conversion process.

Start Converting

Features

Convert PDFs & create

  • PDF to XRechnung
  • PDF to UBL
  • PDF to XRechnung (CII)
  • PDF to ZUGFeRD
  • PDF to Factur-X
  • Create XRechnung
  • XRechnung to PDF

View & validate

  • XRechnung/XML Viewer
  • XRechnung Validator

Quick Links

  • Resources
  • Trust & Security Center
  • Developer API Documentation
  • Blog
  • About
  • Pricing
  • Free trial
  • Climate Contribution

Legal

  • Imprint
  • Privacy Policy
  • Data Processing Agreement
  • Terms & Conditions
  • Money-Back Guarantee

Get in Touch

contact@invoice-converter.com
© 2026 Invoice-Converter.com.Made with in Europe
GDPR Compliant
German Server