PERSONAL DATA · GDPR
Privacy policy
What data we process, why, for how long, with whom, and how to exercise your rights. This is an English translation of our French privacy policy, which prevails in case of difference. Hosted in Switzerland, no advertising or audience-measurement cookie.
VERSION IN FORCE ON OCT 2, 2026
Data controller
The data controller is Adama CISSE EI, a sole trader (entrepreneur individuel) operating InvoiceBridge, SIREN 883 782 534, 2 rue Maurice Dampierre, 95310 Saint-Ouen-l'Aumône. For any question about your data, write to [email protected].
Our two roles
Data controller for the data of our visitors, our customers and their users: account, subscription billing, support, website security. This policy describes that processing.
Processor, within the meaning of article 28 of the GDPR, for the data of our customers' own customers (the buyers appearing in the transactions our customers connect). We process that data only on our customer's instructions, under the data processing agreement annexed to our terms (in French). If you are a customer of one of our customers, send your requests to that merchant, who is the controller; we will help them answer.
Processing, legal bases and retention
| PURPOSE | DATA | LEGAL BASIS | RETENTION |
|---|---|---|---|
| Creating and running the account, providing the Service | Company name, business email, password (stored hashed, never in plain text), organization settings, log of sensitive actions | Performance of the contract | Life of the account; data deleted 30 days after the account deletion request (article 10 of our terms) |
| Subscription billing and accounting | Billing identity, plan, invoices, payment history (card data is processed by Stripe, never by us) | Performance of the contract; legal obligation | 10 years for accounting records (article L. 123-22 of the French commercial code) |
| Service emails (address verification, password reset, alerts and summaries) | Email, organization name, content of the alert | Performance of the contract | Life of the account |
| Email support | Email, content of the exchanges | Legitimate interest in answering and following up requests | 3 years after the last exchange |
| Free compliance check | The uploaded file is analysed in memory and never stored; only the technical validation report is kept, for the sharing link | Legitimate interest in providing the requested tool | 12 months for the report; sharing link valid for 7 days |
| Website security and abuse prevention | IP address, date and requested page, sign-in attempts | Legitimate interest in protecting the Service | Anti-abuse counters: a few minutes to one hour; technical logs: 12 months at most |
We sell no data, do no profiling and take no automated decision producing legal effects concerning you. The fields of the sign-up form are needed to open the account: without them, the account cannot be created.
Stripe app
When you install the InvoiceBridge app from the Stripe App Marketplace, you allow InvoiceBridge to read some of the data in your Stripe account, read-only. Every permission it requests is a read permission (event_read, invoice_read, charge_read, customer_read, credit_note_read and checkout_session_read): the app never creates, changes or refunds anything in your account.
| DATA READ | PURPOSE | RETENTION |
|---|---|---|
| Invoices, payments, refunds, credit notes and Checkout sessions | Classify each sale (e-invoicing or e-reporting) and produce the invoices, credit notes and filings | Life of the InvoiceBridge account; data deleted 30 days after an account deletion request. The raw content received from Stripe for each sale is reduced to its identifiers only 13 months after it was imported; the sale and its documents stay. Documents already issued stay available after you uninstall the app, until that deletion (article 10 of our terms) |
| Customers: name, SIREN or SIRET number, VAT number, billing address, email; the rest of the customer record returned by Stripe is not kept | Information a French e-invoice must show. For sales to consumers, which are reported in aggregate, the buyer's identity is never transmitted. | Life of the InvoiceBridge account; data deleted 30 days after an account deletion request (encrypted backups are erased at the end of their rotation cycle) |
| Events of your Stripe account | Process each change without delay; the content of an event is kept only until it is processed. An event whose processing fails is kept for 30 days at most, so it can be processed again, then deleted | Event identifier and type, kept for the life of the account so that no event is ever processed twice, then deleted 30 days after an account deletion request |
| OAuth access tokens issued by Stripe | Read the data above on behalf of your account | Encrypted with AES-256-GCM, never logged, deleted as soon as the app is uninstalled (encrypted backups are erased at the end of their rotation cycle) |
| Name of your Stripe account (business name or display name) | Name the connection in your InvoiceBridge dashboard | Life of the InvoiceBridge account; data deleted 30 days after an account deletion request |
For the data of your customers and your sales (the first two rows of the table, including when it arrives through an event), InvoiceBridge acts as your company's processor, under the data processing agreement (in French). For the access tokens, the identifiers of your Stripe account and Stripe user, and the account name, InvoiceBridge is the controller, on the basis of the performance of the contract. All this data is hosted in Switzerland like the rest of the Service.
The app's settings page, shown in your Stripe Dashboard, sends InvoiceBridge your Stripe account identifier and the signed-in user's identifier, signed by Stripe, only to display the connection status; the user identifier is not stored. Test data (test mode and Stripe sandboxes) is only ever loaded into an organization in sandbox mode and never leads to a real transmission to a certified platform (Plateforme Agréée).
Recipients and processors
Your data is accessible to the publisher and, within the limits of their task, to the following providers, bound by contract:
| PROVIDER | ROLE | LOCATION |
|---|---|---|
| Infomaniak Network SA | Hosting of the website, the application, the database and the documents | Switzerland |
| Cloudflare, Inc. | Domain name, routing and protection of web traffic | United States |
| Twilio Ireland Limited (SendGrid) | Sending service emails | Ireland; processing in the United States by Twilio Inc. |
| Stripe Payments Europe, Limited | Subscription payment and billing; Stripe also acts as a controller for its own obligations (fraud prevention, financial obligations) | Ireland; processing also in the United States by Stripe, LLC |
| SUPER G SAS (SuperPDP) | Certified platform (Plateforme Agréée), transmission of our customers' invoices and e-reporting in production | France |
| MXroute LLC | Mailbox of the contact and support address | United States (Texas) |
The website's fonts are hosted on our own servers: no third-party service is contacted to display them. Data may also be disclosed to authorities that request it, where the law requires it.
Transfers outside the European Union
Some providers are located outside the European Union. Switzerland benefits from an adequacy decision of the European Commission. Cloudflare, Inc., Twilio Inc. and Stripe, LLC are certified under the EU-US Data Privacy Framework, which also benefits from an adequacy decision. The MXroute LLC mailbox falls under neither an adequacy decision nor standard contractual clauses: it only receives the messages you choose to send us by email. A copy of the existing safeguards can be obtained by writing to us.
Security
Encrypted connections (HTTPS), hashed passwords, our customers' secrets encrypted with AES-256-GCM, read-only access to connected Stripe accounts, technical logs without personal data, daily backups, hosting in Switzerland. In case of a personal data breach presenting a risk, we notify the CNIL within 72 hours and, if the risk is high, the people concerned.
Your rights
You have the rights of access, rectification, erasure, restriction, objection (for processing based on legitimate interest) and portability of your data, as well as the right to set instructions on what happens to it after your death. You can export and correct your data from the dashboard, or write to us at [email protected]. We answer within one month, which may be extended by two months for a complex request, in which case we let you know. Proof of identity may be requested in case of reasonable doubt.
If you believe your rights are not respected, you can lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr/fr/plaintes), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
Changes
This policy evolves with the Service. The date of the version in force is shown at the top of the page; customers are notified by email of any significant change.