Privacy Policy
Last updated: 29 September 2026
Version 2.1
General Privacy Statement
SIA "NUMBERO APP" (hereinafter - the "Company" or "we") fully understands the importance of protecting the confidentiality and privacy of information circulation, therefore the protection of your personal data is one of the main priorities of the Company's activities. This Privacy Policy sets out the main aspects regarding the observance of information confidentiality and the legally correct processing of personal data, in the implementation of the provision of invoices, delivery notes and other comparable accounting documents and their management services, as well as ensuring the operation of the website as a whole (hereinafter - "services"). We undertake to process personal data only as set out in this Privacy Policy.
The maintainer of the website https://numbero.app (hereinafter - the Website), the web application https://my.numbero.app and the mobile applications (hereinafter collectively - the Application) and, accordingly, the controller of personal data processing is the Company, which in its activities undertakes to comply with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and the free circulation of such data and which repeals Directive 95/46/EC (General Data Protection Regulation) and other regulatory acts, if applicable to data processing. This Privacy Policy applies to both the Website and the Application.
In the sense of the General Data Protection Regulation, we as the controller of personal data act only in relation to the data provided in the profile registration procedure of our customers, namely service users, which meet the definition of the term "personal data" given in the regulation.
With regard to the business partners of a user registered on the Website, whose data this user uses within the framework of using our services, we act as a "processor" in accordance with Article 4, Clause 8) of the General Data Protection Regulation. This means that the legality of this processing of personal data is determined by the user of the Website as the controller of personal data. Any person whose rights or interests in the field of personal data processing are violated, should immediately contact the personal data controller - the user of our services, who independently assumes responsibility for the legal processing of personal data. On the other hand, our responsibility as processors is limited to data security measures and liability to the controller in the event of a security incident.
Information subject to processing
The Privacy Policy applies to all information submitted and processed using the Company's services and which is reasonably subject to confidentiality requirements or can be recognized as data of a natural person (hereinafter - personal data). If you use those of our services for which it is not necessary to register a user profile, we process personal data only to the extent necessary for the operation of the relevant service (for example, when filling in the contact form, using the e-invoice reader or rating news posts; described in more detail below in this section). If you merely browse service prices and other freely available information on our website, personal data is not processed (except for the use of cookies).
In order to access the full range of services offered on our Website, you must become a registered user, thus the Privacy Policy applies to registered users who voluntarily provide their personal data information to the extent requested in the profile registration procedure. For user registration, we need a minimum of information, which can be identified by data types as:
1. Information you voluntarily provide when registering a user profile:
- email address,
- password,
- name and surname (optional),
- registration source (for example, the advertising channel through which the registration took place).
2. In the mobile applications, in addition to the above: device name and device identifier.
3. Information from publicly available databases, such as open data of the Register of Enterprises or the VAT payer status verification tool (VIES).
4. Credit institution account data. Information needed to process your payments. Payment processing is provided by third parties - licensed payment service providers: Klix (provides payments in Latvia). The Company does not receive or store your payment card data; it is processed by the relevant payment service provider.
5. Bank synchronization. If you connect your bank account in your user profile in order to automatically receive account statements and transaction history (dates, amounts, currency, payment purposes, payer and recipient data), we obtain the data only with the consent you give at your bank, which is usually valid for 90 to 180 days depending on the bank. Access to bank data is provided by a licensed account information service provider GoCardless (privacy policy). We use the data received to match payments with invoices and monitor their payment status, and we store it for as long as necessary to provide the service.
6. Cookies. When you browse our website, one or more cookies are sent to your computer or other device used for browsing. A cookie (or cookie) is a small text file with configuration information that is stored on your computer or portable device, identifies your browser, helps the Website "remember" your actions and settings in the current user session for a certain period of time. The purpose of using cookies is to improve the quality of our services, including storing user preferences, generating recommendations and following user trends. Our website mainly uses functional cookies and analytical cookies. Functional cookies are necessary for certain pages of the website to function, such as authentication cookies. Analytical cookies are used only for internal research and service improvement. The information associated with cookies is not used to identify you personally. We activate analytics and advertising measurement tools only after you consent in the cookie management window; the full list of tools is available in the cookie settings. In the mobile applications, we use analytics, error and performance monitoring tools, as well as advertising measurement tools, which we activate only after you consent. Our Website uses the following cookies or similar tracking technologies:
- Authentication and session cookies – ensure safe and fast connection to the user profile, access to the platform service and saving of language settings;
- Cookie consent management tool (CookieScript) – stores your choice regarding cookie categories;
- Google cookies (Analytics, Ads) – allow you to analyze the behavior of website visitors, improve its operation and measure the effectiveness of advertisements;
- Sentry – identifies and analyzes software errors to improve website stability (data is processed in the European Union).
7. Audit log information (server log files). When you access our Website services, our servers automatically record certain technical information that your browser sends to the server. These server log files may include information such as the browser's request to load the website, Internet Protocol (IP) address, browser type and language, device screen resolution, access date, time and approximate location, or other similar technical records. This information is deleted after one month.
8. Contact form on the website. When you submit the contact form, we process the name, email address, telephone number, company name and message you provide, as well as technical data (IP address, browser type and the page from which the request was sent), in order to receive and respond to your request. This data is stored for 30 days, and for the processing of the request it may be transferred to providers of internal team communication and email delivery services.
9. E-invoice reader. When you use the e-invoice reader, the e-invoice XML file you upload, which may also contain personal data of your business partners, is processed in a service maintained by the Company or its group company in order to create a preview of the invoice. The preview is automatically deleted after 24 hours; the link to it is available to anyone who knows the link. The e-invoice reader can also be used via the MCP interface; no authorization is required to use it, and the uploaded XML is not written to log files.
10. Custom email sending settings (SMTP). If you specify your own SMTP server (host, port, username and password) in the application settings, we store this data in a protected form and use it only to send the documents you have prepared. In the sending log we store the message subject, recipients and message ID (without the SMTP settings data); we keep this log for as long as the relevant company profile exists, as proof of document delivery. You are responsible for the choice of your email service provider and its terms.
11. API access. We store API keys in a protected form and display them only once – at the time of their creation. Actions performed with your key are recorded in the history of the relevant document. We apply limits on the number of requests to the use of the API, which we may change. You are responsible for your integrations and for the confidentiality of the keys.
12. Artificial intelligence assistant functions. For artificial intelligence assistant functions, we use service providers that comply with European Union requirements; personal data is not transferred to these providers. The assistant's suggestions are not an automated decision within the meaning of Article 22 of the General Data Protection Regulation.
13. Communicating with the Website user via e-mail, WhatsApp messaging app, telephone. The e-mails or other communications sent by you to the Company may be saved to process and respond to your requests, to ensure quality customer service, to improve the quality of the services we provide. The legal basis for data processing is our legitimate interests in providing effective communication and customer support. If you have agreed to receive our marketing messages, your email address and name may be transferred to an email marketing service provider; you can opt out of marketing messages at any time by using the opt-out option provided in the message.
14. Voluntarily provided additional information in surveys or questionnaires. For example, gender, hobby or other data that you provide voluntarily, but which is not directly necessary for receiving services, nor does it affect the availability of services, but may be used in accordance with the procedures specified in the Privacy Policy, for example, for the purpose of statistics or service improvement, as well as for the purpose of implementing possible contests or raffles aimed at service fee discounts.
This Privacy Policy applies only to the services provided by the Company, within the framework of which the data of natural persons are processed or the data of such natural persons are processed in the interests of a legal entity (for example, representatives, contacts). Our Website may contain links to the websites of other companies or organizations. We have no reasonable ability to influence the privacy practices of other websites, including the cookies they use, the data they collect, or the amount of personal data they request. Therefore, we ask that you familiarize yourself with the privacy policies of these websites before providing any personal data or using these websites.
Our website and services are not intended for persons under the age of 18. We do not knowingly collect personal data about minors. If after registration it is discovered that the user is under 18 years of age, his data will be deleted and access to the services will be denied.
Purposes of personal data processing
The Company processes personal data only for the purposes specified in this Privacy Policy, which are:
- Execution of agreements between the website user and the Company;
- Providing services offered by the company;
- research and analysis of log files to maintain the website, protect and improve our services;
- provision of technological requirements for our Website and Services;
- protecting the rights, interests or property of website users and the Company;
- planning and development of innovative services.
For any use of your personal data for purposes other than those specified above, we will ask for your consent before starting the data processing.
The legal basis for the purpose of personal data processing is:
- consent of the data subject - Article 6, paragraph 1, subparagraph a) of the General Data Protection Regulation;
- fulfillment of contractual obligations - Article 6, Clause 1, subparagraph b) of the General Data Protection Regulation;
- observance of legitimate interests - Article 6, Clause 1, subparagraph f) of the General Data Protection Regulation;
- fulfillment of obligations laid down by law - Article 6, Clause 1, subparagraph c) of the General Data Protection Regulation (for example, retention of accounting and tax documents for the periods specified in regulatory acts, justified requests from public authorities).
Principles of data processing
The Company's personal data processing operations are strictly subject to the following general principles:
- limitation of the purpose of data processing – personal data is processed only for the above-mentioned data processing purposes and purpose of use, or for activities that have been clearly authorized by the data subject;
- data quality and proportionality – the data subject has the opportunity to submit accurate personal data and update it in the user profile if necessary (a deviation from this principle is possible only in the case of the personal data subject's own unjustified or careless actions in submitting or updating data). Personal data are requested, not exceeding the necessary amount, they are applicable, taking into account the purpose of processing;
- transparency – the data subject has a known and understandable possibility to access his personal data in the user profile, which is important for fair data processing;
- security - technical and organizational security measures are applied in data processing in accordance with possible risk during processing, including measures against accidental or illegal destruction of information or accidental loss, modification, unauthorized disclosure or access directly or with the help of malware;
- minimization – data is regularly reviewed in order to delete data that are no longer necessary for the purpose of processing.
Place and duration of personal data processing
Personal data is processed and stored mainly on servers located in the European Union - specifically in Germany and Finland. Certain service providers (for example, providers of analytics, marketing or error monitoring tools) may also process data outside the EU and the EEA; in such cases, we apply the safeguards referred to in the section "Transfer of personal data and exchange of information".
The duration of storage of personal data depends on the validity period of the user profile, the duration of its maintenance in accordance with the Terms of Use of the Website. The user profile is deleted after 3 months from the last activity in this profile, when the data deletion procedure is initiated. We store accounting documents and data related to the Company's accounting for the periods specified in regulatory acts – at least 5 years.
Personal data may be stored longer if necessary for handling a complaint or possible legal proceedings.
Transfer of personal data and exchange of information
We may disclose aggregated information of a statistical nature that is not considered personal data, such as the number of users on the website, the number of registered user profiles or clicks on any of the available service types on the website's service platform. Such information cannot be used to identify a person.
Personal data may be transferred to third parties outside the Company only if we have received your express and voluntary consent, or if the transfer is provided for in regulatory acts. We have the right to transfer personal data to third parties in order to:
- to ensure the performance of the contract, within the framework of which the personal data used in your user profile may be included in accounting documents and disclosed to the recipient of the invoice,
- comply with the legal requirements, fulfill the imperative requests of the court or representatives of public authorities,
- implement the terms and contracts of the Company's services provided on the website, including investigating possible violations of these terms and contracts,
- ensure our legitimate interests, detect, prevent or otherwise deal with criminal offences, security, technological or certain procedural issues, protect the rights, legal interests or property of the Company, Website users against damage or threats, as far as this is determined or permitted by law,
- receive legal and advisory services, including cooperation with legal service providers, auditors, tax or data protection specialists.
In order to provide the services, we use processors – service providers – in the following categories: hosting and infrastructure (in the European Union), content delivery network, error monitoring, analytics and advertising measurement tools (only with your consent), email delivery and sending of marketing messages, internal team communication, payment services, account information services (bank synchronization), artificial intelligence services, cookie consent management. The full list of tools is available in the cookie settings; for our customers, we provide the list of processors within the framework of the data processing agreement.
If personal data is transferred outside the EU and the EEA, we ensure that such transfer takes place in accordance with the requirements of the General Data Protection Regulation, for example, on the basis of the standard contractual clauses approved by the European Commission or the EU–US Data Privacy Framework, thus ensuring an equivalent level of data protection.
If you yourself share your documents via WhatsApp, Telegram or other communication channels, the terms and privacy policy of the relevant platform apply to further data processing.
Certain personal data may be collected in the form of information in which it is not possible to identify you, but which is aimed at statistical analysis. For example, we may work with advertising companies to tell you how many people have visited a particular website on our site, or the proportion of men and women, or the proportion of individuals and legal entities that have registered with a user profile on our Website. However, the communicated information does not enable the identification of specific persons in any way.
Data security guarantees
In order to protect the information obtained on the website, prevent unauthorized access to personal data, maintain data accuracy and ensure their correct processing, the Company has implemented appropriate technical and organizational security measures, including physical security measures, electronic security solutions, data processing management procedures. The website complies with modern security standards and its security is regularly tested and improved, including through third-party security tests. Data is transmitted in encrypted form using TLS technology. At the same time, it should be taken into account that no security system is absolute, and there is a minimal risk that cannot be completely excluded.
User profile passwords, SMTP passwords and API keys are stored in our systems in a protected form using modern and secure technologies. Each registered user is independently responsible for the confidentiality of his password and API keys. We are not responsible for unauthorized access to a user's profile or personal data due to password disclosure, theft or user negligence.
We cannot take responsibility for how third parties use your personal data obtained in the future after we have legally transferred it to these third parties in accordance with the Privacy Policy. However, within reasonable limits, we require that third parties undertake to use personal data only in the provision of relevant services or in the exercise of functions and competences prescribed by law.
The right to access and correct your information
Access to your personal data that we store is provided online by authenticating to your user profile. In the user profile, you have a free opportunity to correct or clarify your personal data, change and edit the settings of the user profile, thus choosing parameters for public availability of information or restriction of access. This procedure ensures that personal data information is continuously up-to-date while being protected to the extent you see fit.
In addition, you have the right to request access to your personal data, their rectification, erasure, restriction of processing and data portability, to object to data processing, and to withdraw your consent at any time. You can submit a request by writing to info@numbero.app; we respond within 1 month. You also have the right to lodge a complaint with the Data State Inspectorate.
Amendments to the Privacy Policy
The Company's Privacy Policy may be subject to change, so this document may also be amended accordingly. No significant changes are planned, but it cannot be ruled out that new insights may emerge in practice or theory in the field of personal data protection, which will inevitably affect this Privacy Policy as well. At the same time, it is not expected that changes in the field of personal data protection could be significant, but if they do happen, they will most likely not be aimed at reducing the rights of the subject of personal data. Any changes to the Privacy Policy will be announced on our website, and in the case of significant changes we will also notify registered users by email.
Contact information
If you have questions about this Privacy Policy or concerns about the security of your personal data, you can contact our specialists:
SIA "NUMBERO APP"
Rīga, Varkaļu iela 13A, LV-1067
Phone: +371 28253335
Reģ. nr. 40203279164
PVN Reģ. nr. LV40203279164
Email: info@numbero.app (for data protection matters)