1. Who we are
VektoVAT ("we", "us") provides a SaaS application that lets freelancers and businesses upload receipts and invoices, extract VAT details with AI, store documents securely, export records and manage subscriptions.
For the personal data described in this policy we act as data controller, except for the documents and business data you upload, where you are the controller and we act as processor on your instructions. VektoVAT is established in the Netherlands and processes personal data in line with the EU General Data Protection Regulation (GDPR).
Privacy contact: privacy@vektovat.nl.
2. What personal data we collect and why
- Account information — name, email address and password hash, plus optional business name, VAT number, country and currency. Purpose: creating and securing your account, authenticating you and providing the service. Legal basis: performance of a contract.
- Uploaded documents — receipt and invoice images or PDFs and the values extracted from them (vendor, date, amounts, VAT rate, category, notes). These may contain personal data of you or third parties. Purpose: delivering the core service. Legal basis: performance of a contract; for third-party data in documents, our and your legitimate interest in accurate business administration.
- Billing information — subscription plan, status, billing period, payment status and the customer and subscription identifiers issued by our payment processor. Full card details are never sent to or stored by us; they are handled by Stripe. Purpose: taking payment, managing subscriptions and meeting tax and accounting obligations. Legal basis: contract and legal obligation.
- Usage and technical data — sign-in events, feature usage, document counts against your plan allowance, error logs, IP address, device and browser type. Purpose: keeping the service secure, preventing abuse, enforcing plan limits and improving reliability. Legal basis: legitimate interests.
- Support communications — the content of messages you send us. Purpose: answering your question and improving support. Legal basis: legitimate interests.
We do not sell personal data, do not share it with advertisers and do not use your documents for advertising or profiling.
3. How AI processes your receipts and invoices
When you upload a document, it is stored in your private storage area and then sent, over an encrypted connection, to our AI processing provider for a single extraction request. The model reads the document and returns structured fields such as vendor, date, net amount, VAT amount, VAT rate and a suggested expense category.
Your documents are not used to train AI models. The provider processes the file only to answer that request and does not retain it for its own purposes. No automated decision with legal or similarly significant effects is made about you: the extracted values are suggestions you review, edit and approve before they are saved.
AI extraction is probabilistic and can be wrong. You remain responsible for verifying every value before using it in a VAT return or any accounting record.
4. How your data is stored and protected
- Documents are stored in a private object-storage bucket that is not publicly accessible; files are served only through short-lived signed links to the account that owns them.
- Database records are protected by row-level security rules, so one account can never read or modify another account's profile, records or files.
- All traffic is encrypted in transit with TLS, and data is encrypted at rest by our infrastructure providers.
- Passwords are stored only as salted hashes, and leaked-password protection is enabled. Sign-in is available with email and password or with Google.
- Access to production systems is restricted to authorised personnel on a need-to-know basis, and backups are taken regularly.
5. Third-party services (processors)
- Supabase — authentication, database and file storage hosting for your account, records and uploaded documents.
- Stripe — payment processing, subscription management, invoicing and VAT calculation. Stripe acts as an independent controller for payment data under its own privacy policy.
- AI processing provider — one-off extraction of VAT and expense details from uploaded documents.
- Email delivery provider — transactional emails such as sign-up confirmation, password reset and billing notices.
- Hosting and content delivery — serving the application itself.
Each processor is bound by a data processing agreement and may only process personal data on our documented instructions. A current list of subprocessors is available on request from privacy@vektovat.nl.
6. International data transfers
We aim to keep hosting and storage of your documents and records within the European Union. Some providers, in particular Stripe and our AI processing provider, may process limited data outside the EEA, including in the United States.
Where that happens, the transfer is covered by appropriate safeguards under Chapter V GDPR — normally the European Commission's Standard Contractual Clauses combined with technical measures such as encryption in transit and at rest, or an adequacy decision such as the EU-US Data Privacy Framework where the recipient is certified. You can request a copy of the relevant safeguards from privacy@vektovat.nl.
7. Data retention
- Uploaded documents and extracted records: kept until you delete them or close your account. Deleting a record also deletes the stored file.
- Account and profile data: kept for as long as your account exists, then deleted within 30 days of account closure, except where a longer period is legally required.
- Billing and invoice data: retained for 7 years to satisfy Dutch tax and accounting retention obligations.
- Security and usage logs: retained for up to 12 months, then deleted or aggregated so they no longer identify you.
- Support messages: retained for up to 24 months after the conversation ends.
- Backups: deleted data may persist in encrypted backups for up to 30 days before being overwritten.
Because you are responsible for your own statutory record-keeping (in the Netherlands generally 7 years for business records, 10 years for property-related records), export your records before deleting them or closing your account.
8. Cookies and similar technologies
We use only what the service needs to work. Strictly necessary cookies and local storage keep you signed in, remember your session and protect against cross-site request forgery. Stripe may set cookies during checkout for fraud prevention and payment security.
We do not use advertising cookies or third-party tracking cookies, so no consent banner is required for the categories above. If we ever introduce analytics or marketing cookies, we will ask for your consent first and you will be able to withdraw it at any time. You can also block or delete cookies in your browser, though the app will not function correctly without the necessary ones.
9. Your rights under the GDPR
- Access — obtain confirmation of whether we process your data and receive a copy of it.
- Rectification — have inaccurate or incomplete data corrected; most fields you can edit yourself in Settings and Records.
- Erasure — have your data deleted; you can delete individual records or your entire account from within the app.
- Portability — receive your records in a structured, machine-readable format; the Export page produces a CSV of your data at any time.
- Objection — object to processing based on our legitimate interests, taking into account your particular situation.
- Restriction — ask us to limit processing while a dispute about accuracy or lawfulness is resolved.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise a right, email privacy@vektovat.nl from your account address. We respond within one month, extendable by two months for complex requests, and we do not charge for reasonable requests.
If you believe we have not handled your data correctly, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or the supervisory authority in your country of residence.
10. Data breaches
We monitor for security incidents. If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it and inform affected users without undue delay where the risk is high.
11. Children
VektoVAT is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children; if we learn that we have, we delete it.
12. Changes to this policy
This policy is effective from 6 August 2026. We may update it as the service, our providers or the law change. Material changes are announced by email or in the app at least 30 days before they take effect, and the effective date above is always updated. Continued use after that date means the updated policy applies.
13. Contact
Privacy requests and questions: privacy@vektovat.nl. General support: support@vektovat.nl. You can also reach us through the contact page. We have not appointed a Data Protection Officer, as we are not required to; privacy requests are handled by our privacy contact above.