Privacy Policy
Last updated: 24 June 2026This Privacy Policy explains how MS07 GmbH (“MS07”, “we”, “us” or “our”) collects, uses and protects personal data when you use Invoxly (the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).
1. Data controller
MS07 GmbH
Salzachstraße 15 Top 15, 1200 Wien, Austria
E-Mail: privacy@ms07.at
Full company details are available in our Imprint.
Salzachstraße 15 Top 15, 1200 Wien, Austria
E-Mail: privacy@ms07.at
Full company details are available in our Imprint.
2. What data we store and where
Application data is stored in our database and backend platform provided by Convex. The Service stores the following categories of data in Convex:
- Account & authentication data — your email address, name, optional profile image, a securely hashed password (for email/password sign-in) and session information. Authentication is handled via Better Auth.
- Organisation data — organisation names, descriptions, identifiers (slugs), default currency, membership records (which user belongs to which organisation and with which role), and invitations (invitee email address, role, invite token and status).
- Contracts & addresses — contract names, billing periods, start/end dates, tags, colours, external references, and invoice/billing addresses you create.
- Invoices & documents — uploaded invoice files (e.g. PDFs), the billing period and issue dates, amounts, currencies, exchange rates and converted amounts, and data extracted from documents (such as vendor/seller details, invoice numbers, amounts, VAT breakdowns and bill-to information).
- Integration & connector data — configuration for data sources you connect (such as Gmail), and temporary OAuth state used to establish those connections.
- Secrets — credentials and access tokens for your connected integrations are stored encrypted (AES-256-GCM) and are never exposed to the browser in plaintext.
- Audit & access logs — records of access to stored secrets (action, the acting user and reason) for security and accountability.
Uploaded files are stored using Convex file storage. We do not intentionally collect special categories of personal data; please avoid uploading documents containing such data unless necessary.
3. How we use your data
- to provide, operate and secure the Service;
- to authenticate you and manage organisations and access rights;
- to collect, store, convert and extract data from your invoices and documents;
- to send service-related and transactional emails;
- to maintain audit logs and prevent abuse; and
- to comply with legal obligations.
4. Legal bases (GDPR Art. 6)
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you have signed up for;
- Legitimate interests (Art. 6(1)(f)) — to keep the Service secure, prevent abuse and improve it;
- Consent (Art. 6(1)(a)) — where you connect a third-party source such as Gmail; you may withdraw consent at any time; and
- Legal obligation (Art. 6(1)(c)) — where we are required to retain or disclose data by law.
5. Subprocessors
We use the following subprocessors to operate the Service. Where required, we have data processing agreements in place and rely on appropriate safeguards for any transfers outside the EU/EEA:
- Convex — database, backend and file storage.
- Vercel AI Gateway — AI-based extraction of invoice and document content. Requests run under Zero Data Retention: the content you submit for extraction is not stored or used for training by Vercel or the underlying model providers, and is retained only for the moment needed to return a result.
- Daytona — secure, isolated sandbox compute used to process documents and extract invoice data.
- Carbone — rendering and generation of invoice documents from your templates.
- Google — sign-in with Google (authentication) and, optionally, Gmail mailbox access where you connect a mailbox so that invoices can be collected.
- Microsoft — sign-in with Microsoft (authentication).
- Frankfurter — historical currency exchange rates for amount conversion (no personal data is sent).
- Shablon — transactional email delivery for sign-in, invitation and notification emails.
6. Retention
We retain personal data for as long as your account and organisations are active and as needed to provide the Service. You can delete invoices, contracts and other content from within the Service. When you delete your account or an organisation, associated data is deleted or anonymised, except where we must retain it to comply with legal obligations (for example, retention periods under tax and commercial law).
7. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise these rights, contact privacy@ms07.at.
You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), www.dsb.gv.at.
8. Security
We use appropriate technical and organisational measures to protect your data, including encryption of sensitive secrets, access controls and audit logging. No method of transmission or storage is completely secure, but we work to protect your data and respond to incidents appropriately.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email. The “Last updated” date above indicates when this policy was last revised.
10. Contact
For any questions about this Privacy Policy or your personal data, contact us at privacy@ms07.at.