1. Our commitment
Vangelder Solutions BV builds the EU E-Invoicing Connector to be privacy-by-design and data-minimising. The App is engineered so that buyer personal data is processed only as long as strictly necessary to build and send an invoice, and is not stored in our database.
2. Controller and processor roles
- For your customers' invoice data and your business data, you are the controller and we are your processor, under a GDPR Article 28 DPA.
- For your own account and support data, we are the controller, as set out in the Privacy Policy.
3. Lawful bases
We rely on performance of a contract (Art. 6(1)(b)), processing on documented instructions (Art. 28), legitimate interests in reliable and secure operation (Art. 6(1)(f)), and legal obligations such as Belgian VAT retention (Art. 6(1)(c)). Details are in the Privacy Policy, Section 4.
4. Data minimisation
Buyer names, addresses, emails and VAT numbers are handled transiently in memory to produce the UBL invoice and then transmitted to the Peppol Access Point. Our database keeps only the session, your configuration (credentials encrypted with AES-256-GCM), non-identifying invoice metadata and the gapless number counters.
5. Your rights
Data subjects have the right to access, rectification, erasure, restriction, portability and objection, and the right not to be subject to solely automated decisions with legal effect (the App makes none). Because we hold no buyer personal data, requests about a buyer's invoice should go to the merchant (controller); the merchant and the Access Point hold the invoice. Requests about data we control can be sent to support@vangeldersolutions.be.
6. Shopify privacy webhooks
We implement Shopify's mandatory webhooks — customers/data_request, customers/redact and shop/redact — and act on them, deleting all data for a shop after uninstall.
7. Sub-processors and transfers
We use a limited set of EEA-based sub-processors (Shopify, your chosen Peppol Access Point provider, and Microsoft Azure). Processing takes place within the EEA; any transfer outside the EEA is covered by an appropriate safeguard such as Standard Contractual Clauses. The current list is in DPA Annex C.
8. Security
Encryption at rest (AES-256-GCM) with keys in Azure Key Vault, TLS/HTTPS in transit, signature-verified webhooks, tenant isolation per shop, and least-privilege production access. Full measures are in DPA Annex B.
9. Breach notification
Where we act as processor, we notify you of a personal data breach affecting your data without undue delay and within 48 hours of becoming aware, so you can meet your own obligations.
10. Supervisory authority
You may lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels — gegevensbeschermingsautoriteit.be.
11. Contact
Privacy questions or requests: support@vangeldersolutions.be — Vangelder Solutions BV, Pastorijstraat 27, 9100 Nieuwkerken-Waas, Belgium.