Privacy Policy
The current version reflects the product direction, but not a final legal release state.
Data Controller
Rose Gurme Food GmbH Kreuzberger Ring 24 65205 Wiesbaden Email: contact@e-rechnung-inbox.de
Purpose of processing
Processing inbound invoice documents, user accounts, export data, audit trails and product-related communication.
Data location
Our primary hosting and storage posture is Germany/EU regions (Frankfurt, Germany); sub-processor and technical support flows are disclosed separately in this privacy policy.
Cookies and consent management
We use two cookie categories that you can manage at any time via the consent banner or the “Cookie settings” footer link: Essential: Login sessions, security tokens (CSRF, Turnstile) and language preference. Without these cookies the service cannot function. Analytics: Google Analytics 4 (conversion and usage measurement). These cookies are only set after your explicit consent; without consent no script is loaded and no request is sent to googletagmanager.com or google-analytics.com. Your consent decision is stored locally in your browser under the key “cookie-consent-v1” and can be withdrawn at any time via the footer link. A final legal review of this section (data processing agreement with Google, third-country data transfers, retention periods) is part of the GA preparation.
Data Processors / Sub-Processors
The following external service providers process personal data on our behalf in accordance with Art. 28 GDPR:
Microsoft Ireland Operations Limited
Service: Azure Document Intelligence (OCR processing of PDF receipts). Processing region: Germany West Central (Frankfurt). Retention: maximum 24 hours during processing; the analyse result is also actively deleted via the Delete-Analyze-Result API immediately after our server has retrieved it. Contractual basis: Microsoft Products and Services Data Protection Addendum (DPA), including EU Standard Contractual Clauses. Data categories: PDF content of uploaded receipts (may contain personal data — e.g. names, addresses, contact details of suppliers and employees). Purpose: Structured extraction of invoice data from PDF receipts that are not in EN-16931 XML format. Legal basis: Art. 6 (1) (b) GDPR (performance of contract) in conjunction with Art. 28 GDPR (data processing on behalf).
European Commission (VIES — VAT Information Exchange System)
Service: VAT identification number validation via the public VIES REST API (https://ec.europa.eu/taxation_customs/vies/). Processing region: European Union. Retention: in accordance with the retention rules of the public VIES register; the validation result is cached in our database for a maximum of 30 days. Data categories: VAT-ID (public business identifier); for validated numbers VIES returns company name and address from the public register. Purpose: Validating the validity of a VAT-ID, in particular for cross-border transactions within the EU. Legal basis: Art. 6 (1) (c) GDPR (legal obligation; § 18e UStG requires the plausibility check of business partners' VAT-IDs).
Supervisory Authority
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Gustav-Stresemann-Ring 1 65189 Wiesbaden Phone: +49 611 1408-0 Email: poststelle@datenschutz.hessen.de