Privacy policy (Datenschutzerklärung)
As of: 28/09/2026
This is a translation provided for convenience only. The legally binding text is the German version.
OPERATOR_*— see .env.example). The text below contains placeholders, not real company details. Do not publish this page in production until you have filled in the actual registration details.1. Controller
⚠️ NOCH ZU ERGÄNZEN, ⚠️ NOCH ZU ERGÄNZEN, ⚠️ NOCH ZU ERGÄNZEN ⚠️ NOCH ZU ERGÄNZEN, Deutschland
Email for data protection enquiries: ⚠️ NOCH ZU ERGÄNZEN
2. Who we are and what this policy covers
Finanzigo is a SaaS platform for invoicing, quotes, expense management and tax overviews for German sole proprietorships (Gewerbe). This policy covers (a) visits to our website, (b) the use of the application by registered users, and (c) the personal data of our users' clients stored in the application (e.g. invoice recipients) — for these, you as the user are the controller under data protection law and we are the processor (see section 8, data processing agreement).
3. Hosting and server logs
When our website/application is accessed, our hosting provider automatically processes technical connection data (IP address, date/time, requested URL, user agent) in server logs in order to provide and secure the service technically. Legal basis: Art. 6(1)(f) GDPR (DSGVO) (legitimate interest in secure operation).
4. Cookies and local storage
We use only technically necessary cookies/storage — no tracking, no advertising or analytics cookies, which is why no cookie consent banner is required (legal basis: § 25(2) TTDSG or Art. 6(1)(f) GDPR):
- Session cookie (sign-in/authentication, NextAuth)
- Cookie for the active company (which business/view is currently selected)
- Cookie for the selected interface language
- Local storage of the theme preference (light/dark) in the browser
5. Registration and user account
When you register, we process your name, email address and a hashed password (bcrypt — the plain-text password is not stored) in order to give you access to the application. You can also enter personal tax details (federal state, Kirchensteuer, health insurance, marital status, etc.) to enable the tax calculation. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
6. Processing as part of use (invoices, clients, receipts)
As a user, you record in Finanzigo data about your own clients (name, address, USt-IdNr., payment history) as well as receipts/expenses in order to create GoBD-compliant invoices and accounting records. To verify a USt-IdNr., we transmit the country and number to the European Commission's VIES system. Invoice access links for your clients log openings/downloads (time, IP address, browser/device) as the legally required proof of immutability (GoBD) — automated bots/link previews (e.g. Slack, WhatsApp) are filtered out.
7. Payment processing
Card payments for invoices are processed via Stripe Connect — the payment is made directly between your client and your own Stripe account; we only receive status information (paid/failed) and, where applicable, our platform fee. Legal basis: Art. 6(1)(b) GDPR.
8. Data processing on your behalf
Since we process personal data of your clients on your behalf, we conclude a data processing agreement (AVV) with you in accordance with Art. 28 GDPR — available in your company settings. We use the following sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Neon (PostgreSQL database) | Storage of all application data (invoices, clients, user accounts). | EU (eu-central region, Frankfurt) — confirm in the Neon dashboard for your project. |
| S3 object storage (https://3bb6d5c84485754add4ea1e163372610.eu.r2.cloudflarestorage.com) | Storage of attachments (receipts, generated PDF documents). | check the location with the provider (recommended: EU) |
| Resend | Sending transactional emails (invoices, reminders). | USA/EU — check the current Resend DPA |
| European Commission — VIES | Verification of clients' EU VAT numbers (USt-IdNr.) — only the country and VAT number are transmitted. | EU |
9. Retention period
We keep invoices, receipts and related evidence (event logs) for the statutory retention period of 10 years in accordance with § 147 AO / § 257 HGB (GoBD). Other data (e.g. your account profile) is kept for as long as your account exists and deleted when the account is deleted — except for the records mentioned above that must be retained by law, which then remain solely in your own GoBD export archive downloaded beforehand (see section 10).
10. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). In practice, we provide tools for this directly in the application: under Settings → Data export you can download a complete data export archive (documents, structured data, audit trail) at any time; under Settings → Delete account you can irrevocably delete your account together with all data (after the mandatory prior export). For all other requests, please contact ⚠️ NOCH ZU ERGÄNZEN.
11. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement.
12. Data security
Transmission is encrypted (TLS). Receipts/documents are stored content-addressed (SHA-256) and immutably. Passwords are stored only in hashed form (bcrypt).
13. Changes to this policy
We update this policy when our data processing or the legal situation changes. You will always find the current version at this address.
