Privacy Policy
Regulation (EU) 2016/679 (GDPR) and Act CXII of 2011 (Hungarian Privacy Act).
FakturWire is built privacy-first. The invoices you send to our API are processed in memory to produce a result and are never stored or logged. This policy explains the limited personal data we do process, and your rights over it.
1. Controller
The data controller is Csapó Ádám László E.V. (Individual entrepreneur (egyéni vállalkozó) registered in Hungary), operating FakturWire (https://fakturwire.com). Contact for any privacy matter: hello@fakturwire.com. Full details are in our Legal Notice. We have not appointed a Data Protection Officer as we are not required to; the contact above handles all requests.
2. What we process, why, and on what legal basis
| Data | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Account e-mail; hashed API key; credit balance and ledger | Create and operate your account, authenticate API calls, meter credits | Performance of a contract (6(1)(b)) |
| Usage events — operation type, credit cost, chosen format/profile, timestamp (no invoice content) | Billing accuracy, service metering, troubleshooting | Contract (6(1)(b)); legitimate interest (6(1)(f)) |
| Billing details — name, company, address, VAT ID; payment metadata; issued invoices | Process payments and issue lawful invoices | Contract (6(1)(b)); legal obligation (6(1)(c)) |
| Invoice data you submit to validate/convert/extract | Produce the validation report or converted document, in memory only | Contract (6(1)(b)) — processed transiently, then discarded |
| IP address and request metadata; email-verification and key-reset tokens | Security, rate limiting, abuse prevention, email confirmation and key recovery | Legitimate interest (6(1)(f)); contract (6(1)(b)) |
We do not use advertising or analytics cookies and do not track you across sites. Your API key is stored in your browser's local storage (a functional necessity for the dashboard), not in a cookie, and never leaves your browser except as the Authorization header to our API. Web fonts are self-hosted — no third-party font network receives your IP.
3. Invoice content — our core promise
When you call /v1/validate, /v1/convert or the free validator, the invoice
payload is processed in memory to generate the response and is then discarded. We do not persist,
log, or use it for any other purpose. Usage records contain metadata only.
/v1/extract (PDF-to-data) additionally sends your PDF to our AI sub-processor
(Anthropic) for the single extraction request. The PDF is held only in memory for that call, is
never written to our disks or logs, and Anthropic does not use API data to train its models. The
extracted JSON is returned to you and then discarded on our side.
4. Processors and recipients
We share data only with the processors needed to run the service:
| Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and databases | European Union (Germany) |
| Stripe Payments Europe, Ltd. | Payment processing (we never see full card data) | EU (Ireland), with transfers to the US under SCCs |
| Billingo Technologies Zrt. | Issuing invoices | Hungary (EU) |
| European Commission (VIES) | EU VAT-number validation for reverse charge | European Union |
| Our own mail server | Transactional email (verification, key recovery) | European Union |
| Cloudflare, Inc. (only if the signup captcha is enabled) | Bot protection (Turnstile) | US, under SCCs |
Anthropic PBC (only when you call /v1/extract) | AI extraction of invoice data from your PDF; not used for model training; PDF not retained | US, under SCCs |
5. International transfers
Where a processor transfers data outside the EEA (e.g. Stripe or Cloudflare US infrastructure), the transfer is protected by the European Commission's Standard Contractual Clauses and additional safeguards. The core service and its databases run within the EU.
6. Retention
- Account data: for as long as your account is active, then deleted or anonymised on request.
- Invoices and accounting records: retained for 8 years as required by Hungarian accounting law (Act C of 2000, §169).
- Invoice content you submit: not retained — discarded after the request.
- Verification / key-reset tokens: short-lived (hours) and single-use.
- Server and security logs: kept for a limited period for security and then rotated.
7. Your rights
Under the GDPR you have the right to:
- access your data and obtain a copy;
- rectify inaccurate data;
- erasure ("right to be forgotten"), subject to legal retention duties;
- restrict or object to processing based on legitimate interests;
- data portability; and
- withdraw consent at any time, where processing is based on consent.
To exercise any right, email hello@fakturwire.com. We respond within one month. You also have the right to lodge a complaint with the Hungarian supervisory authority, the National Authority for Data Protection and Freedom of Information (NAIH, naih.hu, 1055 Budapest, Falk Miksa utca 9-11.), or with the supervisory authority of your EU country of residence.
8. Security
We apply appropriate technical and organisational measures: TLS in transit, API keys stored only as SHA-256 hashes (the key itself is never stored), EU-hosted infrastructure, access controls, and the design principle of not storing invoice payloads. No system is perfectly secure, but we work to protect your data and will notify you and the authority of a breach where legally required.
9. Children
The service is intended for businesses and is not directed at children under 16.
10. Changes
We may update this policy; the "last updated" date below reflects the current version, and material changes will be communicated by email or a notice on the site.
Last updated: 20 July 2026. See also our Terms of Service and Legal Notice.