en16931.dev← Back to site

Privacy Policy

Effective date: 2026-08-06

The short version. Invoice documents you send to the API are processed in memory, in EU data centers, to produce the response — and are not stored afterwards. This website sets no tracking cookies. We keep only what is needed to run accounts and billing.

1. Controller

Anton Bogoslov, sole proprietor (private entrepreneur), Yerevan, Republic of Armenia. Contact for all privacy matters: hello@en16931.dev.

2. What we process

Contact data. If you write to us or request early access, we process your email address and what you tell us, to reply and to notify you about the launch. Legal basis: your request (Art. 6(1)(b)/(f) GDPR where it applies).

Account and billing data (at launch). Email, plan, and usage totals needed to operate your subscription. Payment card details are collected and processed by Paddle as merchant of record — we never see full card numbers. Legal basis: contract performance.

API payload data. Invoice files and JSON you submit are processed transiently to validate, generate or convert the document, and are deleted from memory when the response is returned. They are not written to persistent storage, not used for training or analytics, and not shared. Where such payloads contain personal data of your customers, you remain the controller and we act as your processor; a data processing agreement with EU Standard Contractual Clauses is available on request.

Technical logs. Request metadata (timestamp, endpoint, status code, document count, approximate IP-derived region) is kept for security and billing for up to 12 months. Logs do not contain invoice contents.

3. Where processing happens

API processing runs in data centers located in the European Union. The website is served via a global content delivery network. Where personal data is transferred outside the EU/EEA (for example, to us as operator, or to a sub-processor), the transfer is protected by EU Standard Contractual Clauses or another lawful mechanism.

4. Sub-processors

We use a small set of service providers: Cloudflare (website hosting and delivery), Paddle (payments, as merchant of record), and a transactional email provider for account messages. Each processes data only as needed for its function. A current list is available on request.

5. Cookies

This website sets no advertising or analytics cookies. If that changes, this policy will be updated first and consent will be requested where required.

6. Retention

Correspondence: up to 24 months. Account and billing records: for the life of the account plus statutory retention periods. Technical logs: up to 12 months. API payloads: not retained.

7. Your rights

Where the GDPR or similar laws apply to you, you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority. Write to hello@en16931.dev and we will respond within one month.

8. Changes

The current version of this policy is always published on this page with its effective date.