This is a translation for convenience. In case of doubt the German version of this privacy policy prevails.
Controller
- Name and address
- Klaus Pfeiffer (Invoisary)Josef Karner Platz 1, 3423 Wördern, AustriaVAT ID: ATU69615348
- Contact for privacy matters
- office@invoisary.com
- Data protection officer
- We are not required to appoint a data protection officer (Art. 37 GDPR). Please send privacy requests to the address above.
1. Scope
This policy covers the invoisary.com website and all of its pages. The application itself (my.invoisary.com) has its own privacy policy: there we process personal data mostly on behalf of our customers, as a processor. What applies in that case is the data processing agreement under Art. 28 GDPR and the list of subprocessors.
For the processing described here we are the controller within the meaning of Art. 4(7) GDPR. No automated decision-making and no profiling takes place.
2. What this website does not do
Since it answers most questions up front, here is the negative list. This website:
- sets no cookies - neither our own nor anyone else's. A cookie banner is therefore not required.
- embeds no content from third-party servers. Fonts, images, logos and scripts all sit on our own webspace. In particular, no Google Fonts are loaded from Google's servers: the Inter typeface is downloaded when the site is built and shipped along with it.
- uses no advertising, retargeting or social media pixels, and no services from Google Analytics, Meta, LinkedIn or comparable providers.
- builds no cross-device profiles and does not recognise returning visitors from one day to the next.
- transfers no data to the USA or any other third country.
We store exactly one value in your browser's local storage: your preference for the light or dark appearance. It never leaves your device, contains nothing personal and serves only to restore the appearance you chose on your next visit. It is therefore strictly necessary within the meaning of § 165(3) TKG 2021 and permitted without consent.
3. Server logs
When you open this website, your browser transmits technically necessary data that our web server records in log files. This is unavoidable when running a website and serves delivery, stability and defence against attacks.
| Data category | Example | Purpose |
|---|---|---|
| IP address | 192.0.2.10 | Technical delivery of the page, detecting and blocking abusive access |
| Date and time | 14/08/2026, 10:22:41 | Troubleshooting, attack detection |
| Address requested | /en/features/e-rechnung/ | Troubleshooting, operations |
| HTTP status code and volume | 200, 14 kB | Troubleshooting, operations |
| Browser and operating system | Firefox 130, Windows | Troubleshooting, compatibility |
| Referring page | https://www.google.com/ | Troubleshooting, operations |
The legal basis is our legitimate interest in the secure and uninterrupted operation of the website (Art. 6(1)(f) GDPR). Log files are deleted after 14 days at the latest; we keep them longer only where a specific security incident needs to be investigated. This data is not combined with any other source.
4. Analytics with Umami
To understand which content gets read and whether our pages work, we measure reach with Umami. Umami is open-source analytics software that we host ourselves on our own server in Germany (Hetzner). The data never leaves our own infrastructure, and no analytics provider is involved as a recipient.
Per page view, only the following is recorded:
- the page opened and when it was opened,
- the referring page that brought you to us,
- country, browser, operating system and approximate screen size,
- whether one of the three steps of the sign-up form was reached (form opened, email submitted, registration link clicked) - without the email address entered.
Your IP address is neither recorded nor stored. Umami uses it only in passing, to derive an irreversible checksum from it together with your browser identification and a random value that changes daily, so that page views can be grouped into a visit. Neither the IP address nor the checksum allows any conclusion about you personally, and because the random value changes every day, recognition beyond a single day is technically impossible.
No cookies are set in the process, and nothing is stored on or read from your device beyond what displaying the page requires anyway. A consent banner is therefore not required. If your browser sends the “Do Not Track” signal, no measurement takes place at all.
The legal basis is our legitimate interest in designing our website to suit its readers (Art. 6(1)(f) GDPR). Given how little data is involved, our assessment is that your interests do not override it. We keep the aggregated statistics for up to 24 months so that trends can be compared across years. You can exercise your right to object under Art. 21 GDPR at any time, either by sending us an informal message or by enabling “Do Not Track” in your browser.
5. Sign-up and account creation
Using the “Start for free” button you can leave your email address to create an account. The address goes directly to our application (my.invoisary.com), which sends you a sign-up link. It is not stored on this website.
We process the email address along with the time and technical circumstances of the request. The legal basis is taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR). If no registration follows, we delete the address after 90 days. If you register via Google, Apple or LinkedIn, that happens exclusively on our application's sign-up page; this website establishes no connection to those providers.
6. Contacting us
If you write to us by email, we process your address and the content of your message in order to answer it. The legal basis is Art. 6(1)(b) GDPR where the enquiry concerns a contract, otherwise our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR).
We keep correspondence for as long as handling it requires, and beyond that only where statutory retention duties apply - in particular the seven years under § 132 BAO for business-relevant records.
7. Recipients and processors
Nobody receives personal data from the operation of this website except the service providers running our servers. For the website and the analytics instance that is our hosting provider with data centres in the EU, with whom a data processing agreement under Art. 28 GDPR is in place.
No transfer to third countries outside the EEA takes place in connection with this website. The subprocessors used in the application itself, and the safeguards that apply there, are listed in full on the “Subprocessors” page.
We disclose data to authorities only where legally obliged to. Your data is never sold and never used for third-party advertising.
8. Your rights
You have the following rights regarding your personal data:
- access to whether and which data we process (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability in a common format (Art. 20 GDPR),
- objection to processing based on a legitimate interest (Art. 21 GDPR) - on this website that means the analytics,
- withdrawal of any consent given, with effect for the future (Art. 7(3) GDPR).
An informal message to office@invoisary.com is enough. We respond within one month. Please note that our analytics holds no data that can be attributed to you, so a request for access can only come back empty there (Art. 11 GDPR).
Independently of this you may lodge a complaint with a supervisory authority at any time. In Austria that is the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb@dsb.gv.at.
9. Security and changes
This website is served exclusively over encrypted HTTPS. Access to the analytics instance is password-protected and limited to a small group of people.
We update this policy when the website or the legal situation changes. The version published here is the one that applies; the date of the current version appears at the top of this page.
Questions about privacy?
Write to us. We answer requests for access, erasure or objection within one month - an informal email is enough.
Send a privacy request
