Privacy & data handling
What happens to your invoices
This describes what the system actually does, not a general promise. Where a setting changes the answer — like retention mode — both answers are given.
What we collect
An account is just an email address — sign-in is a one-time code, there is no password to store. A corpus is the invoices you upload for regression testing, plus whatever a run against it produces: which rules newly failed, which invoices they hit, and — if you have notifications on — an email about it.
We do not run analytics, tracking pixels, or third-party scripts on this site. There is nothing here watching how you use it beyond your own account activity.
Checking a single invoice needs no account and stores nothing about the document at all — not the XML, not even a record that a check happened. The one thing kept is an IP address, hashed, paired with a timestamp, purely to stop the same address checking an unreasonable number of documents in an hour. That row carries no trace of what was checked and is deleted within about an hour either way.
Retention: full vs. metadata-only
Chosen per corpus when you create it, in NewCorpus.
Full
The invoice XML is stored, encrypted at rest, so it can be replayed the next time a rule set changes without asking you to re-upload it.
Metadata only
The document's content hash, filename, and every finding a run produces are kept — the XML itself is discarded once that run finishes. This is the setting for anyone who does not want to ship commercial documents to a third party at all, at the cost of needing to re-upload for the next run.
Where it's stored
Structured data (accounts, runs, findings) lives in our database. Invoice bodies, for corpora on full retention, live in S3-compatible object storage, encrypted before they're written — the storage provider holds ciphertext, not your document.
Third parties, and exactly what each one sees
Nothing here is a general "we may share data with partners" clause. This is the complete list, and what each one receives.
| Who | What for | What they see |
|---|---|---|
| Resend | Sending sign-in codes and run-breakage notifications | Your email address, and the email's own text — rule codes, invoice counts, and a general explanation of the rule change. Never invoice content. |
| DeepSeek | Writing the plain-language explanation of what changed between two rule sets | The rule set content itself — test expressions, severity, dependency variables. For our own reference corpus only (public test fixtures from OpenPEPPOL, not anyone's real invoices), illustrative field values from those fixtures. Your corpus is never sent here, under any setting — explanations for a customer corpus are either the general one already written for the reference corpus, or nothing. |
| Object storage provider | Storing invoice bodies for full-retention corpora | Encrypted invoice bytes. The encryption key is not given to them, so what they hold is unreadable without it. |
Deleting your data
Deleting a corpus (from Corpora) is immediate and complete: every invoice row and every stored body, across any storage provider it was ever written to, is removed. This can't be undone.
Deleting your account entirely isn't yet a self-service action — email privacy@revalidate.eu and we'll remove it by hand. We'd rather say that plainly than show a button that doesn't do anything yet.
Questions
For anything on this page — a question, a correction, a deletion request — write to privacy@revalidate.eu.