Account, team roles and data security
Updated
Several people can work in the same account with graded permissions, and your data is stored only in the EU. This page shows which role can do what, how to bring in your team, tax advisor, agency or support, how you sign in, and where your data is stored.
Team roles
Under Settings → Team you invite team members by email and give each person a role. Permissions work through roles, not shared logins.
| Role | What it can do | What it cannot do |
|---|---|---|
| Owner (Admin) | everything | no restrictions |
| Accounting | works like an admin: documents, matching, DATEV exports including locking (Festschreibung), all settings (DATEV, VAT matrix, OSS, document rules, template, products), integrations, API keys, team, access grants and plan | appoint admins, edit admin members, delete the account |
| Tax auditor (Betriebsprüfung) | regular app access with read-only rights | download or change anything; auditors have no partner portal access |
| Read only | view dashboards and reports | anything else |
Only the owner (Admin) appoints further admins and can delete the account. You invite auditors as team members with the role Tax auditor, not through external access.
Only owners and Accounting can create, extend, confirm or revoke external access (tax advisor, agency, support). Tax auditor and Read only members can see the page but cannot change anything there. The same goes for agencies and for support with setup access.
Inviting a team member
- YouInviteSettings → Team, email address and role
- EmailLink arrivesvalid for 7 days, tied to the address
- Invited personSign in or create an accountaddress fixed, back to the invitation after confirming it
- DoneOn the teamwith the role from the invitation
- Under Settings → Team, enter the email address and choose the role.
- The invited person gets an email with an invitation link. It is valid for 7 days and tied to their email address.
- They accept the invitation through the link. Anyone without a Rechnungskit login creates an account first, with the email address already fixed. Once they confirm their email address, they go straight back to the invitation.
Anyone who signs up without the link is taken to the open invitation on their first login instead of creating a second, empty company. If they really want a company of their own, they choose "Create my own company instead" there.
While the invitation is open, it shows under Settings → Team with the status "Invited". You can withdraw it there at any time.
If no email arrives, check the spam folder. Otherwise click "Resend" under Settings → Team: the invitation email goes out again and stays valid for another 7 days. The link stays the same.
Signing in with a passkey, email code or password
The sign-in page gives you three ways into your account. You manage passkeys and two-factor authentication under Settings → Account and security.
| Method | How it works |
|---|---|
| Password | email address and password, with "Forgot password" to reset it |
| Email code | "Sign in with an email code": Rechnungskit sends you a 6-digit code that is valid for 5 minutes |
| Passkey | "Sign in with a passkey": Face ID, Touch ID or your device PIN instead of a password, phishing-resistant |
Right after you sign up, Rechnungskit offers to set up a passkey. You can skip this with "Not now, continue to setup" and add or remove a passkey any time under Settings → Account and security.
Two-factor authentication (TOTP)
Two-factor authentication is optional but recommended. When you sign in, Rechnungskit then also asks for a 6-digit code from an authenticator app. Signing in with a passkey needs no extra code.
- Under Settings → Account and security, click "Enable" next to two-factor authentication (TOTP) and enter your current password to confirm.
- Scan the QR code with your authenticator app, such as 1Password, Google Authenticator or Aegis. You can also type in the key by hand.
- Enter the 6-digit code from the app to finish the setup.
- Keep the backup codes somewhere safe. Each code works once, in case you can't get to your app.
When you're asked for the code, you can tick "Trust this device for 60 days". Turning two-factor off needs your password again.
Changing your password
If you change your password or reset it through "Forgot password", you are signed out on all other devices; only the current session stays active. A leaked password stops working as soon as you change it.
Tax advisor access
Your tax advisor is connected through Settings → External access, not as a team member. The access is free for the tax advisor.
- Share accesschoose Tax advisor
- Enter the email addressthen "Invite"
How to invite your tax advisor:
- Under Settings → External access, choose Tax advisor in "Share access".
- Enter the firm's email address and click "Invite".
- If the firm already has an activated partner account with this address, access starts right away. Otherwise we email them an invitation with a link to the free partner sign-up, with their address already filled in.
- If they sign up through this link, their account is activated right away and access starts, with no waiting time.
Until then the invitation shows in the list as "Invited, waiting for sign-up", and you can resend or withdraw it. An invitation is valid for 30 days. In the English app you pick the email language (German or English) before sending; in the German app it always goes out in German.
What your tax advisor can do
Your tax advisor works in their own tax advisor area. They see documents and exports, can maintain the DATEV settings and lock exports. You can revoke the access at any time with one click, and every action is logged so it cannot be altered.
The activity log (who did what, internal and external) is at the bottom of the External access page. The "All entries" button opens the full view with search and a person filter.
Previewing your tax advisor's view
Before you invite anyone, you can see exactly what your tax advisor will get. Under Settings → External access, the "See what your tax advisor sees" button opens their tax advisor area with your real data, right inside the app: client list, overview, the reports from revenue to the document archive, export details, DATEV settings and the log.
It is all read-only. Buttons such as Lock, Create draft, Delete or Save stay visible but are disabled, and the server refuses any change as well. You can still download your own exports and documents, as anywhere else in the app. From the bar at the top you can invite your tax advisor right away or go back.
Owners and Accounting can open the preview, the same roles that can invite. In test mode you see what the tax advisor sees before go-live: your test documents under Reports → Revenue and Payments, and an archive that is still empty.
Agency and support access
For setup and integration work there is a second, time-limited access type. It lasts 30 days from confirmation and then ends automatically.
| Agency | Rechnungskit support | |
|---|---|---|
| Granted | through an invitation link | under Settings → External access with one click, no email address needed |
| Duration | 30 days from confirmation | 30 days from confirmation |
| Reminder | email seven days before it expires | email seven days before it expires |
| Extend | one click, 30 more days each time | one click, 30 more days each time |
Extending helps when, for example, a migration takes longer. There is deliberately no permanent setup access, so your decision about who gets write access stays current. Here too, you can revoke at any time and every action is in the log.
Where your data is stored
Rechnungskit keeps three copies, all in the EU, nothing in US clouds:
- Production system: Germany (Hetzner, Falkenstein), ISO 27001 data center, backups every minute.
- Immutable archive: Germany, WORM object storage for documents, with SHA-256 checksums on every retrieval.
- Encrypted backup: Helsinki (Finland, EU), encrypted on the client side before transfer.
Restore drills are run and logged regularly, and independent monitoring raises an alarm when something fails.
CDN, firewall and DDoS protection (edge)
In front of the production system sits a security and acceleration layer from Bunny.net (headquartered in Slovenia, EU), not Cloudflare. Every request passes through it first: content delivery (CDN), a web application firewall (WAF), DDoS protection and a rate limit against abuse.
This layer stores no customer data permanently; it only checks and speeds up traffic. The origin server is also locked down so that it can only be reached through this edge. Details on data processing are in the privacy policy.
Account and projects
One account is your company (with one VAT ID, USt-IdNr., and one DATEV export). It can hold several projects, for example one per shop, each with its own number range, template and connections. Every project starts in test mode and goes live in place.
Going live
From test mode you move to live operation on the Go live page (button in the yellow test mode banner or in the settings). It checks three things:
| Check | What happens |
|---|---|
| Company details complete | only a notice, it does not block |
| All active payment providers in live mode | a test key blocks going live, because it would create documents for test payments |
| Document start | from when Rechnungskit creates documents: today or a future date, such as the first of the month |
At go-live, the project goes live in place: connections and settings stay, the test documents are hidden and their PDFs are deleted from the archive. Afterwards you see the document start as a compact line in the document rules; it cannot be changed there.
Transferring ownership
You can hand your account over to another person completely, for example when you sell your company:
- Make the new person an admin (by inviting them with the Admin role or by changing their role). The account then has two admins.
- Once there is a second admin, you can downgrade your own role or remove yourself from the account; both ask for explicit confirmation first.
- The account always needs at least one admin. The last admin can neither downgrade nor remove themselves, so the account is never left without a responsible person.
For a handover, also think of the SEPA mandate for the Rechnungskit fees (issue a new one if the bank account changes) and the company details (contact email).
App language (Deutsch or English)
Rechnungskit is available in German and English. You choose the language on the sign-in and sign-up page at the top right (Deutsch / English) or under Settings → Account and security in the "Language" section.
The choice is saved with your user account and applies on every device you sign in on. It does not apply to the whole organization, meaning your company: each person on the team sets their own language, whatever their role, without affecting the others.
Before you sign in (sign-in and sign-up page), the switch only applies to this browser; after sign-in, Rechnungskit shows the language saved in your account. If you have not saved one there yet, Rechnungskit takes your browser's language the first time you sign in.
Invoices and emails to your customers have their own language setting and do not change with it. The rechnungskit.de website is also available in English under rechnungskit.de/en, including most help pages. The legal notice, terms and privacy policy there are translations, and the German version is binding.
Limits
- Rights work through roles instead of shared logins: Admin and Accounting change settings, Tax auditor and Read only can only look. Only an admin can appoint more admins and delete the account.
- Support contact: support@rechnungskit.de, usually answered within a few hours (Monday to Friday).
Where to find it in the app
Recent changes
Rechnungskit is not a tax advisory or law firm. This article explains general principles and does not replace advice from a tax advisor (Steuerberater, § 5 StBerG) or a lawyer (§ 3 RDG). Rechnungskit is built for businesses based in Germany and prepares documents, tax rates and bookings automatically. How your specific case is treated remains your decision, ideally together with your tax advisor or a lawyer.