Ce document a été rédigé séparément pour les utilisateurs belges et néerlandais car les lois nationales et les autorités de contrôle diffèrent. Choisissez la version qui s'applique à votre entreprise.
Last updated: September 12, 2026
This version is for Dutch users. DEMFACT is committed to protecting your privacy and complying with the GDPR (Regulation (EU) 2016/679) and the Dutch Uitvoeringswet Algemene verordening gegevensbescherming (UAVG). Because DEMFACT is a Belgian-established service provider serving Dutch clients under the EU freedom to provide services (Art. 56 TFEU), the Belgian APD/GBA acts as our lead supervisory authority under GDPR Art. 56; Dutch users may nonetheless lodge complaints with the Dutch AP (see Section 14).
1. Introduction
This Privacy Policy explains how DEMFACT ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our invoicing platform at demfact.com (the "Service").
This policy is intended to inform you — reading it does not, on its own, constitute consent to any specific processing. Each purpose for which we process your data has its own legal basis under GDPR Art. 6 (see Section 5). Where a specific processing purpose does require your consent (for example, non-essential analytics or marketing), we ask for it separately and you can withdraw it at any time. Please read this policy alongside our Terms of Service and Data Processing Agreement.
2. Controller and Processor Roles
DEMFACT plays two distinct roles under GDPR depending on the personal data being processed:
- Data Controller — for personal data we collect directly from you as a user of the Service: your account details (email, name, password), your billing information, your subscription usage, technical logs. We decide the purposes and means of processing this data.
- Data Processor — for personal data you upload into DEMFACT about third parties (typically your clients: their names, addresses, VAT numbers, contact details, and any personal data appearing on the invoices you issue to them). For that data, you are the Data Controller and DEMFACT processes it strictly on your instructions, under the terms of our Data Processing Agreement (DPA). If you are a business using DEMFACT to invoice individuals or contacts, you are the Controller for their personal data; DEMFACT is your Processor.
The entity responsible for the controller role above is:
3. Data We Collect
3.1 Account Information
When you register, we collect:
- Email address - for account authentication and communication
- Name - for personalization and account identification
- Password - stored securely using industry-standard hashing (bcrypt)
- Phone number - optional, for account recovery
- Language preference - to provide localized content
3.2 Company Information
When registering a company, we collect:
- Company name and legal form
- BTW number (Dutch VAT-ID) and KVK number (Chamber of Commerce)
- Business address - street, number, postal code, city, country
- Contact details - email, phone, website
- Banking information - IBAN, BIC, bank name (stored encrypted)
- Logo - optional, for invoice branding
- Legal declaration acceptance - date, time, and IP address
3.3 Client Data
You may store information about your clients:
- Business or individual name
- Contact information
- Address details
- VAT numbers
- Payment terms and notes
3.4 Invoice Data
We store all invoices you create, including:
- Invoice numbers, dates, and amounts
- Line items and descriptions
- VAT calculations
- Payment status and history
3.5 Technical Data
We automatically collect:
- IP addresses - for security and fraud prevention
- Browser type and version
- Device information
- Access timestamps
- Error logs - for troubleshooting
4. How We Use Your Data
4.1 Service Provision
- Creating and managing your account
- Processing and storing invoices
- VAT validation through EU VIES
- PEPPOL e-invoicing transmission
- Payment processing through Stripe
4.2 Communication
- Account verification and security notifications
- Service updates and changes
- Invoice and payment notifications
- Support responses
- Legal and compliance notices
4.3 Security and Fraud Prevention
- Detecting unauthorized access
- Preventing fraudulent company registrations
- Logging legal declarations with IP addresses
- Monitoring for suspicious activity
4.4 Legal Compliance
- Tax and accounting record retention
- Responding to legal requests
- Anti-money laundering compliance
5. Legal Basis for Processing
Under GDPR, we process your data based on:
| Purpose |
Legal Basis |
| Account creation and service delivery |
Contract performance (Art. 6(1)(b)) |
| VAT validation and invoice compliance |
Legal obligation (Art. 6(1)(c)) |
| Security and fraud prevention |
Legitimate interests (Art. 6(1)(f)) |
| Marketing communications |
Consent (Art. 6(1)(a)) |
| Tax record retention |
Legal obligation (Art. 6(1)(c)) |
6. Data Sharing
6.1 Third-Party Service Providers
We share data with trusted third parties necessary to provide our Service:
| Provider |
Purpose |
Data Shared |
Location |
| Hetzner Online GmbH |
Hosting infrastructure (servers) |
All platform data (encrypted at rest) |
Germany (EU) |
| EU VIES |
VAT number validation |
VAT numbers, country codes |
European Commission |
| Certified PEPPOL access point provider |
E-invoicing delivery and PEPPOL network access |
Company information, invoice data, VAT numbers, contact details |
EU/EEA |
| Stripe Inc. |
Payment processing |
Billing information, transaction data |
USA/EU (SCC) |
| Brevo (Sendinblue) |
Transactional email delivery |
Email addresses, names |
France (EU) |
| Backblaze Inc. |
Off-site encrypted backups |
All data (AES-256 encrypted) |
USA (SCC) |
| Google LLC (OAuth) |
Login authentication (optional) |
Email, name (from Google account) |
USA/EU (SCC) |
| Microsoft Corp. (OAuth) |
Login authentication (optional) |
Email, name (from Microsoft account) |
USA/EU (SCC) |
| Microsoft Corp. (Clarity) |
Anonymous session recordings & heatmaps (consent-based) |
Anonymous interaction data (no PII) |
USA/EU (SCC) |
| Google LLC (Analytics/Ads) |
Aggregated analytics & ad conversion (consent-based) |
Anonymous visitor metrics |
USA/EU (SCC) |
| Meta Platforms (Pixel) |
Ad attribution (consent-based) |
Anonymous conversion events |
USA/EU (SCC) |
| Anthropic PBC |
AI assistant (DemBot) — invoice scanning, financial insights |
Selected invoice/text data processed on request |
USA (SCC) |
Note on the PEPPOL access point provider:
- Purpose: Sending and receiving e-invoices via the PEPPOL network
- Data processed: Company information, invoice data, VAT numbers, contact details of parties to the invoice
- Location: EU/EEA
- Identity: the specific access point provider is a certified OpenPEPPOL member; its identity, sub-processors and current trust-centre documentation are disclosed upon written request to privacy@demfact.com, and to any Data Controller under our DPA.
- Onward transfers: the provider may use email/SMS notification sub-processors located in the USA under EU Standard Contractual Clauses (SCCs); these are listed in the same trust-centre documentation.
Note on Anthropic (AI processing):
- When it happens: ONLY when you actively use an AI feature — DemBot chat, the invoice scanner (upload a PDF/photo of an incoming invoice), or AI-generated invoice descriptions. Nothing is sent to Anthropic during normal invoicing.
- What is sent: the specific content you submit at that moment — e.g. the image of an invoice you asked to scan, or the text of your DemBot question. This can include personal data such as names, addresses, VAT numbers, IBANs, and amounts appearing on the scanned document.
- Legal basis: For data DEMFACT processes as its own controller (e.g. your DemBot usage metadata, your feature-adoption tracking), DEMFACT relies on Art. 6(1)(a) consent when you activate an AI feature, or Art. 6(1)(b) if the feature is part of a paid plan. For data you upload about third parties (typically your clients' details appearing on an incoming invoice), you are the Data Controller and DEMFACT is your Processor — the applicable legal basis under Art. 6 GDPR for that processing is determined by you, and DEMFACT sends the data to Anthropic strictly on your documented instruction (activating the feature). You are responsible for ensuring an appropriate lawful basis for that third-party data. AI features are opt-in — you can create, edit, and send invoices without ever triggering them.
- Location: USA under EU Standard Contractual Clauses (SCCs).
- Anthropic's role: processor. Anthropic does not train its models on Commercial API data (see Anthropic Commercial Terms) and retains inputs/outputs only as required to provide the service.
- Your control: to avoid any Anthropic processing, use manual invoice entry (available on every plan) and don't use DemBot. All core invoicing features work without AI.
6.2 Legal Disclosure
We may disclose your data when required by:
- Court orders or legal process
- Dutch tax authorities (Belastingdienst)
- Law enforcement with valid legal basis
- Regulatory authorities investigating fraud
6.3 What We Do NOT Do
- We do NOT sell your personal data
- We do NOT share data for third-party marketing
- We do NOT use data for profiling or automated decision-making
7. Data Security
We implement robust security measures:
- Encryption in transit - All connections use TLS 1.3
- Encryption at rest - Database encryption for sensitive data
- Password security - Bcrypt hashing with salt
- Two-factor authentication - Optional TOTP-based 2FA
- Access controls - Role-based permissions
- Audit logging - Security event tracking
- Regular backups - Encrypted, off-site backups
- Server security - Firewall, intrusion detection, regular updates
8. Data Retention
We retain data for the following periods:
| Data Type |
Retention Period |
Reason |
| Account data |
Duration of account + 1 year |
Service provision |
| Invoices and financial records |
7 years (see note below) |
Article 52 Algemene Wet inzake Rijksbelastingen (AWR) — 7-year mandatory retention for tax records |
| Security logs |
2 years |
Fraud prevention (legitimate interest) |
| Legal declarations (KBO/VAT registration, ToS acceptance) |
7 years |
Aligned with fiscal document retention |
| Support communications |
3 years |
Service improvement |
Note on invoice retention: BTW invoices, invoice copies and other tax-related books and records are retained for the periods required by Article 52 of the Algemene Wet inzake Rijksbelastingen (AWR) — the Dutch General Tax Act. The mandatory retention period is seven (7) years, calculated from the end of the calendar year to which the record relates. For records concerning immovable property, article 52(4) AWR extends the retention period to ten (10) years. DEMFACT enforces the seven-year default and retains records longer where a specific legal duty requires it.
9. Your Rights (GDPR)
Under GDPR, you have the following rights:
9.1 Right of Access (Art. 15)
We will respond to data-subject requests without undue delay and, in any event, within one month of receipt. Where permitted by Article 12(3) GDPR, this period may be extended by up to two further months due to the complexity or number of requests. We will inform you of any extension and the reasons for it within the first month.
9.2 Right to Rectification (Art. 16)
You can correct inaccurate data directly in your account settings or by contacting us.
9.3 Right to Erasure (Art. 17)
You can request deletion of your data. Note that we must retain certain data (invoices, tax records) for legal compliance.
9.4 Right to Restriction (Art. 18)
You can request that we limit processing of your data in certain circumstances.
9.5 Right to Data Portability (Art. 20)
You can request your data in a machine-readable format (JSON/CSV) for transfer to another service.
9.6 Right to Object (Art. 21)
You can object to processing based on legitimate interests or for direct marketing.
9.7 Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time without affecting prior processing.
9.8 How to Exercise Your Rights
To exercise any of these rights, contact us at support@demfact.com. We may need to verify your identity before processing your request.
10. International Data Transfers
Your data is primarily stored on servers located in the European Union (Germany - Hetzner). When data is transferred outside the EU:
- We ensure adequate safeguards (Standard Contractual Clauses)
- We only use services that comply with GDPR
- Stripe and Google have valid data protection mechanisms
11. Cookies
DEMFACT uses cookies in three categories:
11.1 Essential cookies (always active)
- Session management - Keeping you logged in
- CSRF protection - Security tokens
- Language preference - Remembering your language choice
- Remember me token - Optional long-lived session (30 days)
11.2 Analytics cookies (with consent)
- Google Analytics 4 (
_ga, _ga_*) - Aggregated visitor statistics, 2 years
- Microsoft Clarity (
_clck, _clsk) - Anonymous session recordings and heatmaps to improve UX, 1 year
11.3 Marketing cookies (with consent)
- Google Ads - Conversion tracking for paid campaigns
- Meta (Facebook) Pixel (
_fbp, _fbc) - Ad attribution, 2-3 months
Analytics and marketing cookies are only activated after you give explicit consent via our cookie banner. You can change your preferences at any time through the "Manage cookies" link in the footer. For detailed information, see our Cookie Policy.
12. Children's Privacy
DEMFACT is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification
- Prominent notice on the platform
The "Last updated" date at the top indicates when the policy was last revised.
14. Complaints
If you believe your data protection rights have been violated, you can:
- Contact us at privacy@demfact.com
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens — AP). Because DEMFACT's main establishment is in Belgium, the Belgian APD/GBA is our lead supervisory authority under GDPR Art. 56 and will typically coordinate cross-border cases; you may address either authority.
Lead supervisory authority (for reference):
Autorité de protection des données / Gegevensbeschermingsautoriteit (APD/GBA) — Belgium
Rue de la Presse 35 / Drukpersstraat 35
1000 Bruxelles / Brussel, Belgium
www.dataprotectionauthority.be
15. Contact Us
For questions or concerns about this Privacy Policy or our data practices:
Your privacy matters. DEMFACT is committed to transparent and responsible data handling.