Política de privacidad
About this policy
This policy explains what personal data Invroot collects, why, who it is shared with, and what rights you have. It covers the invroot.com website and the Invroot application.
It describes the service as it is actually built. Where we name a third party, it is one the product genuinely uses; where we describe what leaves our systems, that is what leaves them.
Two different roles — and why the distinction matters
For the personal data of our own customers — the people who sign up, and their team members — we are the data controller. We decide why and how it is processed, and this policy governs it.
For the data a customer enters about their own clients — names, addresses, tax numbers, invoice lines, payment records — the customer is the controller and we are their processor. We handle that data on their instructions to provide the service, and we do not use it for our own purposes.
If you have received an invoice produced with Invroot and want to know why a business holds your data, contact that business: they hold the relationship and the records. We will support them in answering you.
What we collect
Account and workspace data
- Your name, email address, phone number and password (stored only as a salted hash — never in readable form).
- Business details: company name, address, country, currency, tax registration number, logo, stamp and signature image, and the name and title of your authorised signatory.
- Team members you invite, and their role in the workspace.
Records you create
- Clients and their contact details, invoices, quotes, receipts, credit notes, payments, expenses, catalogue items and bank account details you choose to display on documents.
- This may include personal data about your customers. You are the controller of it; see above.
Billing data
- Plan, subscription status, billing country and currency, invoice history for your subscription, and any promotional code applied.
- Card details are collected and held by Stripe. They do not pass through and are not stored on our servers.
Technical data
- IP address, browser and device information, and timestamps, recorded in server and security logs.
- An audit log of significant actions in your workspace, which exists so that you can see who did what.
- Approximate country, derived from your IP address, used to show prices in the right currency.
Support correspondence
- Messages you send us, and our replies.
We do not use third-party analytics, advertising or tracking services. No advertising pixels, session recorders or cross-site trackers are loaded by the site or the app.
Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service — creating your workspace, storing your records, rendering documents | Performance of a contract |
| Taking payment and managing subscriptions | Performance of a contract |
| Sending service email — verification, password reset, invoices and receipts for your subscription, and reminders you have configured | Performance of a contract |
| Keeping the service secure, preventing fraud and abuse, and diagnosing faults | Legitimate interests |
| Improving the product and understanding which features are used | Legitimate interests |
| Meeting our own tax, accounting and record-keeping obligations | Legal obligation |
| Optional marketing email about the product | Consent — withdrawable at any time |
We do not sell personal data. We do not use your data, or your customers' data, to train machine-learning models.
AI features and what is sent
Where you use an AI feature, the text needed to answer is sent to our AI provider, Anthropic, over an encrypted connection and processed to return a result.
Specifically:
- For AI invoicing: the description you type, and the client and catalogue context needed to draft the invoice.
- For the website assistant: your question and the product documentation it answers from.
Anthropic processes this to return the result and does not use it to train its models. We do not send your full customer database, your payment records, or your uploaded files to any AI provider. If you would rather no data reached an AI provider, do not use the AI features — the rest of the product works without them.
Who we share it with
We do not sell personal data or share it for advertising. We use a small number of processors, each handling only what their function requires:
| Provider | What it does | What it receives |
|---|---|---|
| Stripe | Payment processing and subscription billing | Your name, email, billing country, subscription and payment details. Card data goes directly to Stripe. |
| Anthropic | AI invoicing and the website assistant | Only the text described in "AI features" above, and only when you use those features. |
| Cloud hosting and object storage | Running the application and storing uploaded files such as logos and stamps | Workspace data at rest and in transit. Stored objects are private. |
| Email delivery (SMTP) | Sending service email on your behalf and to you | Recipient address and message content, including attached PDFs. |
We may also disclose data where the law requires it, to establish or defend legal claims, or to protect the rights and safety of our users — and, if the business is ever reorganised or sold, to the acquiring party, subject to this policy.
Where your data is stored
Our production servers and database are located in Frankfurt, Germany, within the European Union. Backups are held in the same region.
Some of our processors operate outside the EU — Stripe and Anthropic among them. Where personal data is transferred outside the EEA, that transfer is made under an appropriate safeguard, ordinarily the European Commission's Standard Contractual Clauses, together with additional measures where needed.
How long we keep it
We keep data for as long as it is needed for the purpose it was collected:
- Workspace records — for as long as your account is open.
- After you close your account or a subscription ends — we keep your records for 90 days so the account can be recovered and your data exported, then delete or irreversibly anonymise them, unless we must keep them longer by law.
- Billing records — retained for as long as tax and accounting law requires, typically between five and ten years depending on jurisdiction.
- Security and audit logs — retained for up to 12 months.
- Support correspondence — retained for up to 24 months.
You can export your invoices, clients and payments at any time from inside the app. We recommend doing so before closing an account.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of data that is wrong or incomplete.
- Erasure — deletion, where we have no overriding obligation to keep it.
- Restriction — to limit how we use it while a question is resolved.
- Portability — to receive it in a structured, machine-readable format.
- Objection — to processing based on our legitimate interests, and to marketing at any time.
- Withdrawing consent — where consent was the basis, without affecting what was done beforehand.
- Complaint — to your data protection authority. In the EU that is the authority in your country of residence; we are also happy to hear from you first.
These rights are recognised in different forms under the EU and UK GDPR, the UAE Personal Data Protection Law, the Saudi Personal Data Protection Law, South Africa's POPIA, and comparable laws in the other countries we serve. To exercise them, email support@invroot.com. We answer within one month, and will tell you if we need longer. We may ask you to confirm your identity before acting.
If your request concerns data held by one of our customers about you, we will refer you to that customer, who controls it.
Cookies
We use cookies only where they are needed to run the service. We do not use advertising or analytics cookies, so there is no consent banner to click through.
What we set:
- Authentication cookies that keep you signed in and allow your session to be refreshed. They are httpOnly, meaning scripts in the browser cannot read them, and are marked Secure and SameSite.
- A preference for your chosen language and billing country, so the site opens the way you left it.
Blocking these will stop you signing in. Your browser can clear them at any time.
How we protect it
Measures we take include:
- Encryption in transit using TLS for all traffic, and encryption of stored files at rest.
- Passwords stored only as salted hashes, never in a readable form.
- Strict separation between workspaces, so one customer cannot reach another's records.
- Role-based access inside a workspace, with an audit log of significant actions.
- Uploaded files stored as private objects, served through short-lived links rather than public URLs.
- Internal access to production limited to the people who need it to operate the service.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and tell you without undue delay where the breach is likely to present a high risk to you.
Children
The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has provided us with personal data, contact support@invroot.com and we will delete it.
Changes to this policy
We update this policy when the service or the law changes. The date at the top always shows the current version. Where a change materially affects how we handle your data, we will tell you by email or in the app rather than relying on you to notice.
Contact us
Invroot is operated by legal entity (trading as Trasealla Solutions), registered at registered address, registration number reg number, which is the data controller for the purposes described in this policy.
For any privacy question or to exercise a right: support@invroot.com. For other business matters: info@trasealla.com.