Skip to content
Zugflow

Privacy policy

Effective 1 October 2026.

Zugflowis operated by Altix Code Ltd, a company incorporated in and governed by the law of the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data we collect when you sign up for and use our website, dashboard and API (the “Service”), what we process on your behalf when the Service compiles an invoice document for you, why, how long it is kept, who we share it with, and the rights you have over it.

Two different roles are in play throughout this policy, and the distinction matters: for data about you, your organisation and your team, Altix is the data controller. For the buyer and seller data inside the invoices you ask us to compile -- names, addresses, VAT identifiers, bank details, amounts -- your organisation is the controller and Altix is a data processor acting only on your instructions. See “When we process invoice data on your behalf” below.

1. Data we collect about you

When you sign up and use the Service, we collect:

  • Account details-- your email address, an optional name, your organisation’s name, and a bcrypt hash of your password. We never store or have access to your actual password.
  • Team and permission data-- if more than one person has access to your organisation, we store each member’s email, role (owner, admin or member), who invited them, and when, so an owner or admin can manage access.
  • Organisation seller profile -- the legal name, address, VAT identifier, tax number, email, phone, IBAN and BIC you optionally store under Settings to be stamped onto invoices that do not supply their own seller block. This is business, not personal, data in the ordinary case, but may identify an individual where your organisation is a sole trader.
  • Billing information -- your subscription plan, status and renewal date. Card and payment details are collected and held by Stripe, our payment processor; we only ever receive a subscription and customer identifier from them, never your card number.
  • Support and account communications -- anything you send us by email, including transactional email we send you (password resets, email verification, team invitations).
  • Security audit log -- a record of membership actions on your organisation (invitations, role changes, removals, and deletion requests) and of API key and webhook endpoint changes, each tagged with the actor and the time it happened.
  • Technical data -- standard web server and request logs (IP address, user agent, timestamps) generated when you use the dashboard or API, kept briefly for security and abuse prevention.

2. When we process invoice data on your behalf

The core of the Service is turning a billing event into a compliant hybrid invoice: a PDF/A-3 document with an embedded UN/CEFACT Cross Industry Invoice XML payload, validated against the official Factur-X schema. To do this we process, on your instructions and for your organisation’s own invoices:

  • Buyer and seller identity: name, address, VAT identifier and tax number, as supplied in your API request or in a Stripe invoice.finalized or Shopify orders/paid webhook payload you have pointed at your endpoint.
  • Line items, totals, currency and tax breakdown needed to produce a mechanically correct invoice.
  • Your organisation’s own seller details (IBAN, BIC, contact information) when stamped onto a document that does not supply its own.

This generation happens entirely on our own infrastructure: XSD schema validation (xmllint) and PDF/A-3 conformance checking (veraPDF, where configured) are local tools we run ourselves, not calls to a third-party invoicing API, so the content of a document you compile is never sent to another service in order to produce it.

We receive your Stripe or Shopify webhook payloads only because you configure your own Stripe or Shopify account to send them to an endpoint URL and signing secret the Service generates for you. We never request or hold API credentials for your Stripe or Shopify account, and have no access to it beyond the webhook events you choose to forward.

Your organisation remains the controller of this data and is responsible for its own legal basis for processing it (ordinarily, performance of a contract with your own customer, or a legal obligation to issue a compliant invoice) and for anything you tell your own customers about it. We process it solely to provide the Service to you, under the instructions in this section and your use of the API and dashboard, and never for our own purposes, marketing, or analytics.

3. Why we process it

  • To provide, maintain and secure the Service -- compiling your documents, operating your dashboard, enforcing plan quotas, and preventing abuse.
  • To bill you, via Stripe, for a paid subscription you chose.
  • To communicate with you about your account, including emails necessary to operate it (verification, password resets, team invitations) and, if you have not opted out, occasional product updates.
  • To maintain a security audit trail of who did what on your organisation, so owners and admins can review activity and we can investigate suspected compromise.
  • To comply with our own legal and accounting obligations, including tax law.

4. Who we share it with

We do not sell personal data. We share it only with the processors needed to run the Service, each used solely to provide their service to us:

  • Stripe, Inc. -- payment processing and subscription billing for your Zugflow plan.
  • Resend (via its SMTP relay) -- delivery of transactional email (verification, password reset, team invitations).
  • Cloudflare, Inc. -- bot and abuse protection (Turnstile) on our sign-up and password-reset forms.
  • Hetzner Online GmbH -- our infrastructure host, where our servers and database physically run (EU-located).

Invoices issued to you for your own Zugflowsubscription are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company. This is never shared outside Altix.

Some of these processors are located outside the European Economic Area. Where that is the case, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.

We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property or safety of Altix, our customers, or others. We do not sell, license, or otherwise disclose the buyer or seller data inside your invoices to any processor other than those listed above, and never to an advertising or data-broker party.

5. How long we keep it

  • Account, team and billing data is kept for as long as your organisation is active.
  • Generated invoice documents (PDF and XML) are kept for at least your plan’s advertised retention window -- 30 days on Free, up to 10 years on Scale -- so you can download or regenerate them; see Pricing for the figure on your plan. This is a minimum we commit to, not a maximum: we do not currently delete a document automatically the moment its window elapses, so treat your plan’s window as the floor, and keep your own durable archive of anything you are legally required to retain for longer.
  • If you delete your organisation, every generated document, API key and webhook endpoint, and every team member’s access, is removed immediately and permanently -- see “Deleting your organisation”. This happens regardless of your plan’s retention window, so export anything you still need before deleting.
  • Invoices already issued to you for your own subscription remain in our internal invoicing system independently of your organisation, for as long as Cyprus tax and accounting law requires us to keep financial records (currently up to seven years).
  • Security audit log entries are retained after an organisation is deleted, because the point of a security log is to survive the event it may need to explain; entries are kept for as long as needed for security, fraud-prevention and legal purposes.
  • Server and request logs are kept briefly (typically a few weeks) and then deleted or anonymised.

6. Deleting your organisation

An organisation owner can permanently delete it from Settings at any time. Doing so:

  • Cancels any active subscription immediately -- you are not billed again, and lose access right away rather than at the end of the billing period.
  • Permanently deletes every generated invoice document (PDF and XML), API key and webhook endpoint belonging to the organisation.
  • The invoices it deletes may include ones you are still required to retain under your own jurisdiction’s bookkeeping law (for example, Germany’s GoBD requires up to ten years). That retention obligation is yours as the document’s issuer, independent of this Service, and deletion does not wait for it to lapse -- download or archive anything you need to keep first.
  • Removes every team member’s access to the organisation immediately.
  • Records that the deletion happened, in a log entry that is not deleted with the organisation (see above).
  • Does not affect invoices already issued to you for your own subscription, which remain in our internal invoicing system under our own legal retention obligations, independently of the deleted organisation.

This action cannot be undone. The dashboard asks you to type your organisation’s name to confirm before it proceeds.

7. Cookies

Our dashboard uses a single strictly necessary cookie to keep you signed in. Our sign-up and password-reset forms, where Cloudflare Turnstile is enabled, may set a cookie used only to distinguish you from a bot -- never for advertising or cross-site tracking. We do not use advertising or analytics cookies on Zugflow’s marketing site.

8. Your rights

If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to:

  • Access the personal data we hold about you, and get a copy of it.
  • Correct inaccurate data.
  • Erase your data, including by deleting your organisation yourself as described above.
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw consent, where processing relies on it (for example, optional product-update emails).
  • Lodge a complaint with your local data protection authority -- for Cyprus, the Office of the Commissioner for Personal Data Protection.

To exercise any of these rights, email privacy@altixcode.com. If the request concerns buyer or seller data inside an invoice compiled for an organisation you are not the owner of, we will direct it to that organisation, which is the controller for that data, unless it has instructed us otherwise.

9. Security

Passwords are hashed with bcrypt and never stored in plain text. Invite, password-reset and email-verification links use single-use, cryptographically random tokens that are hashed at rest. API keys are stored only as a SHA-256 digest and shown to you once, at creation. Webhook signing secrets you did not choose yourself are encrypted at rest with AES-256-GCM. Traffic to the Service is encrypted in transit with TLS. Access to production infrastructure is restricted to the people who need it to operate the Service.

10. Children

The Service is intended for businesses and professionals and is not directed at, or knowingly used to collect data from, children under 16.

11. Changes to this policy

If we make a material change to this policy, we will notify organisation owners by email and update the effective date above before the change takes effect.

12. Contact

Altix Code Ltd (Republic of Cyprus). For any question about this policy or your data, email privacy@altixcode.com.