We process your data under the GDPR (EU 2016/679) and applicable national law. Updated: 2026-06-18.
1. Controller
Ferkovics Lionel Jenő
Straße I. 4.
7061 Trausdorf an der Wulka
Austria
Email: hello@billtree.at
2. Data we process
- Account data: name, email, password (hashed), language, login times.
- Company & billing data: company name, address, VAT ID, IBAN, and the customers, products, invoices and expenses you enter.
- Payment data: via Stripe (we never store card data).
- Technical data: IP address, device/browser, logs (security, debugging).
3. Purposes & legal bases
- Providing the service — performance of a contract (Art. 6(1)(b)).
- Retaining invoices — legal obligation (Art. 6(1)(c); Austrian BAO §132: 7 years).
- Security, abuse prevention — legitimate interest (Art. 6(1)(f)).
- Marketing/newsletter — consent (Art. 6(1)(a)), revocable anytime.
4. Processors
We use trusted providers under data-processing agreements:
- Hostinger — server hosting (EU, Frankfurt).
- Amazon Web Services (SES) — email delivery (EU, Frankfurt – eu-central-1).
- Stripe — payment processing.
- Anthropic — AI assistant / receipt scanning (only when you use that feature).
5. Transfers to third countries
Some providers (e.g. Stripe, Anthropic) may process data outside the EU; in such cases the EU Standard Contractual Clauses and appropriate safeguards apply.
6. Retention
Account data is kept for the life of the account; billing data for the statutory retention period (generally 7 years), after which it is deleted or anonymized.
7. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent. Requests: hello@billtree.at.
8. Complaints
You may lodge a complaint with a supervisory authority: in Austria the Datenschutzbehörde (dsb.gv.at), in Hungary the NAIH (naih.hu).
9. Cookies
We use only strictly necessary cookies (login, language, active company). No advertising trackers.
10. Web analytics
On our public website (billtree.at) we use a cookieless, privacy-friendly analytics tool (Umami) that produces only aggregate visit statistics. It sets no cookies, stores no personal data and does not identify individual users — so no separate consent (cookie banner) is required.