Privacy Policy
This English version is a convenience translation. Only the German version is legally binding. Deutsche Fassung
As of August 2026 · pursuant to Art. 13, 14 GDPR
Where your data lives
All locations in the EU · no third-country transferHosting (data storage)
Hetzner Falkenstein
Primary data center
All customer data lives here: documents, archive, exports. ISO 27001 certified.
GermanyHetzner Helsinki
Encrypted backup
Daily, client-side encrypted backup for disaster recovery. No direct access.
Finland · EUProcessors (processing on our behalf)
Bunny.net
Security layer
CDN, WAF and DDoS protection. Requests pass through here first, without permanent storage.
Slovenia · EUNebius
AI assistant Kit
Nebius B.V. Generates the assistant's answers from your chat input. No permanent storage, no training. Processed in EU data centers.
Netherlands · EUBrevo
Email delivery
Sendinblue GmbH. Sends confirmation and transactional emails. Processes recipient address and message content.
Germany · EUMollie
Billing of our fees
Mollie B.V. Collects our monthly fees via SEPA direct debit. Independent controller; Mollie's privacy policy additionally applies.
Netherlands · EUYour data is stored only with Hetzner in the EU. The other services are processors (Art. 28 GDPR): they process data only to carry out a specific task and do not store it permanently. All locations are in the EU; we do not transfer data to third countries. Payment services and shop systems that our customers connect themselves (e.g. Stripe, PayPal, Shopify) are contracted by the respective merchant and are not processors of Rechnungskit; see section 5.
1. Controller
Happy Coffee GmbH, Theodor-Heuss-Str. 15, 53562 St. Katharinen, Germany
Email: support@rechnungskit.de
2. What data we process
Waitlist: email address, company name and the details about your setup that you enter in the form, plus the time and proof of your consent (double opt-in, IP address, timestamp). When you use the service, additionally: master data (name, company, contact details), contract and billing data, invoice and transaction data from connected sources (e.g. Stripe, Mollie, shop systems) and technical usage data (log files).
3. Purposes and legal bases
Adding you to the waitlist and contacting you at launch are based on your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future. We process data from your use of the service to perform the contract (Art. 6(1)(b) GDPR), to meet statutory retention obligations, in particular under tax and commercial law (Art. 6(1)(c) GDPR), and on the basis of our legitimate interests in the security and further development of the service (Art. 6(1)(f) GDPR).
4. Processing on behalf of customers, and hosting
Where we process invoice and order data on behalf of our customers, we do so under a data processing agreement pursuant to Art. 28 GDPR. Hosting is provided by Hetzner Online GmbH in the Falkenstein data center (Germany); client-side encrypted backups are stored with Hetzner in Helsinki (Finland), and only encrypted data ever reaches that location. BUNNYWAY d.o.o. (Slovenia) sits in front as the security and delivery layer.
For sending emails (including confirmation and transactional emails) we use Sendinblue GmbH (Brevo), which processes the recipient address and the message content. To collect our own fees by SEPA direct debit we use Mollie B.V. (Amsterdam, Netherlands) as our payment service provider; Mollie processes the payment data in this respect as an independent controller, and Mollie's privacy notice also applies.
All of the locations above are in the EU; we do not transfer data to third countries.
5. Connected payment services and shop systems (processing on behalf of our customers)
As a processor we handle order, invoice and payment data of our customers' end customers (e.g. name, address, email address, purchased items, amounts, payment status). The controller within the meaning of the GDPR is the respective merchant; the information duties under Art. 13, 14 GDPR toward end customers rest with the merchant. If you bought from one of our customers, please direct requests about your data to that shop. We do not process full payment instruments (e.g. card data).
Our customers can connect their own accounts with payment services and shop systems, in particular: Mollie B.V. (Netherlands), Stripe Payments Europe Ltd. (Ireland), PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg), Unzer E-Com GmbH (Germany), Klarna Bank AB (Sweden), GoCardless SAS (France), Shopify International Ltd. (Ireland), as well as Shopware and WooCommerce (which run on the merchant's own infrastructure or hosting). These services are contracted by the merchant, not by us: payment service providers process payment data as independent controllers, shop systems act as the merchant's processors depending on setup. They are not subprocessors of Rechnungskit. We retrieve data there exclusively on the merchant's documented instruction; with Rechnungskit Checkout we additionally transmit the order data required for payment to the merchant's chosen payment service. Our API calls are directed at the providers' European establishments. Any onward transfer to third countries by the providers themselves (for instance to group companies in the US, based on standard contractual clauses, binding corporate rules or the EU-US Data Privacy Framework) is governed by their own privacy policies.
6. Web analytics with Umami
To improve our offering and measure the reach of our website, we use the open-source software Umami, which we run on our own servers in the EU. Umami works entirely without cookies and without fingerprinting. No personal data is collected; in particular, IP addresses are not stored but only used in anonymized form to generate anonymous statistics that cannot be traced back to an individual. The data is not combined with other data sources or passed on to third parties. The legal basis is our legitimate interest in a statistical evaluation of anonymized usage behavior to optimize our offering (Art. 6(1)(f) GDPR). Since no cookies are set and no personal data is processed, consent is not required. You can still object to the anonymous measurement at any time: the "Web analytics" entry in the footer opens a window where you can turn the measurement off with a toggle. The setting is stored only locally in your browser.
7. AI assistant "Kit" (Nebius)
On our website and in the application we offer an AI assistant, "Kit", that answers questions about the product and guides you through setup. Answers are generated automatically by AI and are clearly labeled as such (Art. 50 AI Act); they are not tax advice.
To generate answers, we transmit the content of your chat messages and the knowledge base needed to answer them to our processor, Nebius B.V. (Nebius Token Factory), Schiphol Boulevard 165, 1118 BG Schiphol, Netherlands. Processing takes place under a data processing agreement pursuant to Art. 28 GDPR. The language models we use run in data centers within the EU (Finland and France).
Please do not enter anything in the chat that you do not want processed, in particular no special categories of personal data. Nebius uses the transmitted content solely to provide inference and not to train its own AI models. In the configuration we use, inputs and outputs are not stored permanently (Zero Data Retention).
The legal basis for using the assistant on the website is our legitimate interest in answering inquiries better (Art. 6(1)(f) GDPR); within the application, processing serves the performance of the user agreement (Art. 6(1)(b) GDPR). You are not obliged to use the assistant; you can always contact us directly through the contact form instead.
8. Retention period
We store waitlist data until launch or until you withdraw your consent, and delete it afterwards. We store invoice and accounting data for the statutory retention periods (8 years for accounting records, § 147 AO, § 257 HGB as amended by the Fourth Bureaucracy Relief Act, Bürokratieentlastungsgesetz IV). Other data is deleted as soon as the purpose of processing no longer applies. Backups follow a tiered rotation (daily, weekly, monthly, yearly) and are overwritten after three years at the latest; deleted data may persist in backups until this rotation runs out, but is no longer actively processed there.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15 to 21 GDPR), and the right to withdraw consent you have given at any time. You also have the right to lodge a complaint with the competent supervisory authority, the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz).
10. Cookies
Our website uses only technically necessary cookies. There is no analysis, no tracking and no reach measurement; we set no marketing or statistics cookies and do not embed any third-party services that set cookies. A consent banner is therefore not required.
Website (rechnungskit.de)
Signed-in area (app.rechnungskit.de)
The legal basis for storing and accessing this technically necessary information is § 25(2) no. 2 TDDDG; the associated processing of personal data is based on our legitimate interest in secure and functioning operation (Art. 6(1)(f) GDPR) or on the performance of the contract (Art. 6(1)(b) GDPR).
The version in force at the time the contract is concluded applies. We reserve the right to make changes and will announce them with reasonable notice.