Privacy & data handling

What happens to your invoices

This describes what the system actually does, not a general promise. Where a setting changes the answer — like retention mode — both answers are given.

What we collect

An account is just an email address — sign-in is a one-time code, there is no password to store. A corpus is the invoices you upload for regression testing, plus whatever a run against it produces: which rules newly failed, which invoices they hit, and — if you have notifications on — an email about it.

We do not run analytics, tracking pixels, or third-party scripts on this site. There is nothing here watching how you use it beyond your own account activity.

Checking a single invoice needs no account and stores nothing about the document at all — not the XML, not even a record that a check happened. The one thing kept is an IP address, hashed, paired with a timestamp, purely to stop the same address checking an unreasonable number of documents in an hour. That row carries no trace of what was checked and is deleted within about an hour either way.

Retention: full vs. metadata-only

Chosen per corpus when you create it, in NewCorpus.

Full

The invoice XML is stored, encrypted at rest, so it can be replayed the next time a rule set changes without asking you to re-upload it.

Metadata only

The document's content hash, filename, and every finding a run produces are kept — the XML itself is discarded once that run finishes. This is the setting for anyone who does not want to ship commercial documents to a third party at all, at the cost of needing to re-upload for the next run.

Where it's stored

Structured data (accounts, runs, findings) lives in our database. Invoice bodies, for corpora on full retention, live in S3-compatible object storage, encrypted before they're written — the storage provider holds ciphertext, not your document.

Third parties, and exactly what each one sees

Nothing here is a general "we may share data with partners" clause. This is the complete list, and what each one receives.

WhoWhat forWhat they see
ResendSending sign-in codes and run-breakage notificationsYour email address, and the email's own text — rule codes, invoice counts, and a general explanation of the rule change. Never invoice content.
DeepSeekWriting the plain-language explanation of what changed between two rule setsThe rule set content itself — test expressions, severity, dependency variables. For our own reference corpus only (public test fixtures from OpenPEPPOL, not anyone's real invoices), illustrative field values from those fixtures. Your corpus is never sent here, under any setting — explanations for a customer corpus are either the general one already written for the reference corpus, or nothing.
Object storage providerStoring invoice bodies for full-retention corporaEncrypted invoice bytes. The encryption key is not given to them, so what they hold is unreadable without it.

Deleting your data

Deleting a corpus (from Corpora) is immediate and complete: every invoice row and every stored body, across any storage provider it was ever written to, is removed. This can't be undone.

Deleting your account entirely isn't yet a self-service action — email privacy@revalidate.eu and we'll remove it by hand. We'd rather say that plainly than show a button that doesn't do anything yet.

Questions

For anything on this page — a question, a correction, a deletion request — write to privacy@revalidate.eu.

RRevalidate

Corpus regression testing for Peppol e-invoices. Rule sets are pulled from docs.peppol.eu, compiled through the ISO Schematron skeleton, and executed with Saxon.

Scope

  • Peppol BIS Billing
  • UBL and CII
  • CEN and Peppol layers

Peppol is a registered trademark of OpenPeppol AISBL. Revalidate is an independent tool and is not affiliated with or endorsed by OpenPeppol. Privacy & data