arvekram.ee

Buchhaltung, die nicht wehtut.

Privacy policy

Last updated: 2026-08-08

1. Controller

The operator is responsible for data processing on this platform — see the Imprint.

2. Data we process

  • Account data: name, email, password (bcrypt-hashed, never stored in clear text)
  • Company data: company name, address, VAT ID (KMKR), registry code, bank details
  • Accounting data: invoices, receipts, customer records — everything you enter
  • Uploaded files: receipt photos and PDFs, stored tenant-isolated
  • Server logs: IP address, timestamp, user agent (security + error analysis, max 30 days)

3. AI receipt extraction (important)

If you use the "Extract with AI" feature, the uploaded receipt is sent to an external AI provider:

  • Provider: OpenRouter.ai as a router to language models (Google Gemini Flash by default)
  • Data transmitted: the receipt image/PDF (may contain supplier name, address, VAT ID, amount)
  • Purpose: automatic extraction of invoice fields to pre-fill the form
  • Legal basis: GDPR Art. 6(1)(b) — contract performance — or (f) legitimate interest in efficiency
  • Data location: may be a third country (US) at Google. Transfer under Standard Contractual Clauses.

You can use this feature optionally or enter receipts manually. Files themselves remain on our EU servers.

4. Where your data is stored

The application runs on EU-based servers (Hostinger / Hetzner). A data processing agreement is in place.

5. Retention

Accounting records (invoices, receipts, journal entries) are retained for 7 years as required by the Estonian Accounting Act (Raamatupidamise seadus §12). Account data can be deleted at any time, except for records under statutory retention.

6. Your rights under GDPR

  • Right of access (Art. 15)
  • Rectification (Art. 16)
  • Erasure where no retention obligation applies (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21)
  • Complaint to the competent data protection authority (Andmekaitse Inspektsioon for Estonia)

7. Security

  • TLS encryption for all connections
  • Bcrypt password hashing
  • Tenant isolation in the database (tenant_id on every table)
  • Rate limits against brute force and abuse
  • Audit trail on accounting-relevant changes
  • Daily backups

← Back to home · Imprint

Impressum · Datenschutz