Back to home

Security and data protection

This page summarizes where ZUGFeRD-Bereit is operated, how long files are stored and which service providers are involved. The legal details are in the privacy policy.

Hosting & encryption

The website and the service run on servers of Hetzner Online GmbH in the Nuremberg data center, Germany.

All connections between your browser and our server are encrypted with TLS. With HSTS we instruct browsers to open the website over HTTPS only.

Data retention & deletion

Uploaded source files and generated results are stored under an identifier without your name or email address; the file contents remain unchanged.

They are deleted automatically after 7 days for guest use and after 90 days for use with an account.

The account database (not the uploaded files) is backed up daily; a copy is kept on a second Hetzner server in Nuremberg. The backups are kept for 14 days.

Validation

The generator checks generated files before download against EN 16931 (Schematron) and PDF/A-3 (veraPDF); if a validation service is temporarily unavailable, you receive the file without that check.

Both checks run on our own server.

Use of AI

For single uploaded files whose content needs to be extracted, file contents may be sent to Microsoft Azure OpenAI. The Azure OpenAI resource used is located in the Sweden Central region (EU).

Batch processing of CSV and Excel files does not use AI.

Details in the privacy policy

Sub-processors

For processing invoice data we use Hetzner Online GmbH (hosting) and Microsoft Ireland Operations Ltd. (AI extraction) as sub-processors. We use Stripe only to process payments for our plans, Google only for our email communication and PostHog only for web analytics with your consent.

We host Umami ourselves on our server at Hetzner; like PostHog, it is only active with your consent.

Service providers we use
ProviderPurposeLocationRole
Hetzner Online GmbHHostingGermanySub-processor
Microsoft Ireland Operations Ltd.AI extraction (single files only)Sweden Central region (EU)Sub-processor
Stripe Payments Europe, Ltd.Payment processingsee privacy policyOther service
GoogleEmail (Google Workspace)see privacy policyOther service
PostHog Inc.Web analytics, only with consentEU cloudOther service
Details in the privacy policy

Abuse protection

Rate limits protect the service against abuse, for example for conversions, sign-in, password resets and the contact form.

The internal processing interface is not publicly reachable.

DPA & contact

For business use we conclude a data processing agreement (DPA, German: AVV) with you under Art. 28 GDPR. Please request it via the contact form before personal data is processed.

We hold no certifications.

For questions about security and data protection, please also use the contact form.

Go to the contact form