Privacy notice
This is the United Kingdom version, written to meet UK GDPR and the Data Protection Act 2018.
Who we are
Jonathan Mills, trading as Bivetica Invoice, a sole trader established in the United Kingdom at 28–30 High Street, Nettlebed, Henley-on-Thames, Oxfordshire, RG9 5DD.
This notice explains how we handle personal information and is written to meet the UK GDPR and the Data Protection Act 2018.
If you have any question about how we handle information, the contact details are at the end of this notice.
The two roles we play
We act in two different capacities, and which one applies changes your rights and who you should approach.
When you open an account with us, we decide how your account, billing, support and security information is handled. For that information we are the one responsible, and you should come to us directly.
When you use the software to record your own customers, employees, contractors and suppliers, you decide what to enter and why. For that information you are responsible and we simply act on your instructions. If you are one of our customer's customers or employees and you want your information changed or removed, please contact that business rather than us. We will help them do it, but the decision is theirs.
What we collect
Account and billing information. Your name, email address, a securely hashed password, your business or trading name, your subscription plan and your payment status. We do not see or store your card number.
The business records you enter. Customers (name, company, contact name, email, phone, billing address and tax number), invoices, quotes, products, expenses, suppliers and payment records.
Previously entered employee and contractor information. Payroll is currently paused; this description covers records already held. This can include name, email, phone, date of birth, gender, National Insurance number, tax code, National Insurance category, student loan plan, pension status and salary. This is sensitive identity information and we treat it accordingly. Contractor records may include a Unique Taxpayer Reference.
Photographs of receipts and invoices, if you use the scanning feature. The picture is stored with the expense as your record of it. Whatever is written on the paper is therefore held too, which may include a shop name, what was bought, and the last four digits of a payment card printed on the receipt.
Enquiries. If you use the contact form we keep your name, email, business name, what you asked about and your message. We store a one-way hash of your IP address to limit abuse of the form, not the address itself.
Technical and security information. Sign-in times, actions taken in the account for audit purposes, and error logs. We do not run analytics or advertising trackers.
Why we use it
To provide the service you have asked for: creating and sending invoices, recording payments, preparing reports and preparing VAT drafts. Payroll is currently paused.
To take payment for your subscription and keep our own accounting records.
To keep accounts secure, investigate misuse and maintain an audit trail.
To answer your questions when you contact us.
To meet our own legal obligations, including tax and accounting record-keeping.
Where your data is stored
The Bivetica Invoice application and its primary database are hosted in the United Kingdom with Hawk Host Inc.
Receipt photos, original documents and processed scans are stored in a separate private Backblaze B2 bucket in its European region. Access is checked through your business account. Temporary working files on the application server are removed after document processing.
Document cropping, cleanup and local text reading run on our server. Ordinary uploads and local scanning do not send your document to an AI provider. If optional AI reading is offered and you choose it, selected document images are sent to Anthropic in the United States.
UK application hosting does not mean all connected services process data only in the UK. Payment providers, receipt scanning and your chosen integrations may process the information they receive in other countries, as described below.
Sending data outside the United Kingdom
Our application and primary database are hosted in the UK. Expense documents are stored privately in Backblaze B2 in its European region. Optional AI reading sends selected images to Anthropic in the United States only when chosen. Payment providers and other chosen integrations may also process data outside the UK.
UK law allows this only with a recognised safeguard in place, such as the International Data Transfer Agreement, the UK Addendum to the European Commission's standard contractual clauses, or the UK Extension to the EU–US Data Privacy Framework where the recipient is certified under it.
Contact hello@bivetica.com for the applicable provider terms and transfer safeguard information. Provider privacy notices describe their own international processing. UK hosting alone does not establish the safeguards for those separate services.
Who else sees it
Document storage. Backblaze provides private B2 object storage for uploaded expense documents, their originals and processed scans in its European region.
Hosting. Hawk Host Inc. provides the UK hosting for the application and its primary database.
Payments to Bivetica. Stripe processes card payments for our own subscriptions and services; GoCardless processes Direct Debit where offered. We send the payer name, email, business/order reference, amount, currency and billing terms needed for checkout. We retain provider identifiers, payment and subscription status, amounts, refunds and receipt links for billing, support, reconciliation and legal record-keeping. We do not receive your card security code or online-banking password.
Stripe collects payment information on its hosted checkout and billing-management pages, including payment-method, device and network information needed for processing, authentication and fraud prevention. Optional Link features may remember payment details if you choose them. Stripe also uses data for its own payment, security and regulatory purposes, under its privacy notice at https://stripe.com/privacy. Provider processing may take place internationally under the applicable arrangements described in its notice and terms.
Payments from your customers are a separate feature. Where a merchant connection is approved and enabled, your business authorises its own provider account and remains responsible for its customers, refunds and disputes. For GoCardless invoice payments, we send the customer contact details, invoice reference, amount and currency needed for the authorised payment. We retain provider account, mandate, payment and refund identifiers, amounts, statuses and event history for reconciliation and support. Pay by Bank, retry handling and in-app refunds are currently in sandbox review and are not generally available to customers. Paying Bivetica through Stripe does not connect Stripe to your customer invoices or dealer vehicle sales.
Email delivery. Invoices and notices are sent either from our own mail server or, if you have set it up, from your own business email account using credentials you supply. Those credentials are encrypted.
Reading scanned receipts. Local scanning and text reading run on our server without an external AI request. Optional AI reading, when available, sends selected document images to Anthropic in the United States only when you choose that action. It returns suggested details for your review. Anthropic does not use this API data to train its models, and neither do we. You can use local scanning or enter details yourself without optional AI reading.
Accounting software. If you choose to export or connect to Xero, QuickBooks, Sage or Zoho, the data you export goes to them under their terms.
HMRC receives authorised VAT information and browser/device/network details required for fraud prevention when you use the VAT connection. These include a browser identifier, user agent, screen and window dimensions, scaling, timezone, account identifier and network address/port. The current VAT connection is sandbox-only; live filing is not switched on yet. Payroll and live PAYE/RTI submissions remain unavailable. PAYE/RTI development uses fictional test data; developer registration is not HMRC recognition or approval of the software.
Professional advisers and authorities, where we are legally required to disclose.
We do not sell your data. We do not share it for advertising. We do not use it to train artificial intelligence models.
How long we keep it
Account and business records are kept for as long as your account is open. If you close your account, you can export everything first, and you should, because you own it.
After an account closes we keep records for six years where we need them for our own tax and accounting obligations, then delete them.
Receipt photographs are kept with the expense they belong to, for the same six years, because they are the evidence behind the figure.
Enquiry messages are kept for two years.
Security and audit logs are kept for twelve months.
We do not keep data indefinitely without a reason.
How we protect it
Connections to the service use TLS encryption. Passwords are hashed and never stored in a readable form. Email credentials you give us for sending are encrypted individually.
Access inside an account is controlled by role, so a person only reaches the parts of the system their job needs. Employees using the payslip portal can see only their own payslips.
We never ask for card security codes or online banking passwords, and neither will any genuine message from us. If you receive one, it is not from us.
No system is perfectly secure. We tell you honestly what we do rather than promising what we cannot guarantee.
Your rights
Under UK data protection law you have the right to ask us for a copy of your information, to have it corrected if it is wrong, and to have it deleted where we no longer need it.
You can also ask us to restrict how we use it, to object to our using it, and to receive it in a portable format so you can take it elsewhere. Where we rely on your consent, you can withdraw it at any time.
We do not make decisions about you by automated means that produce legal effects.
To make any of these requests, email the address at the bottom of this notice. We will respond within the time the law allows and will not charge you for it. We may need to confirm who you are first, so that we do not hand your information to somebody else.
Cookies
Invoice uses essential cookies and the browser storage described below. We do not add advertising or audience-analytics trackers to Invoice.
bivetica_invoice_session keeps you signed in. XSRF-TOKEN protects forms against a common attack. bv_region remembers which country's pricing you chose to look at.
The first two support sign-in and form security. The third remembers your pricing-region choice. When you use HMRC VAT, local storage named bivetica-hmrc-device keeps a persistent browser identifier for fraud prevention until you clear browser storage. Stripe and GoCardless hosted payment pages use their own cookies or similar technologies for checkout and security; optional remembered-payment features are governed by the choices and notices on those pages. See https://stripe.com/legal/cookies-policy for Stripe details.
Children
The service is for businesses. It is not intended for children and we do not knowingly collect information about them.
Changes to this notice
If we change this notice we will update the date at the top. If a change materially affects account holders — a new subprocessor, or a change of hosting country — we will tell them directly rather than relying on them to notice.
How to complain
If you are unhappy with how we have handled your information, please tell us first and give us the chance to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk or on 0303 123 1113. You do not have to come to us first, and complaining costs nothing.
How to contact us
Email hello@bivetica.com and say what you would like us to do. If your question is about records held by a business that uses Bivetica Invoice — an invoice you received, or your payslip — please contact that business first, because they decide what happens to those records and we act on their instructions.
Our regulator for this version of the notice is the Information Commissioner's Office.
Stripe privacy notice · Stripe cookie policy · GoCardless payer privacy