Privacy Policy

1. Introduction

At EU Trace, your privacy is a top priority. This Privacy Policy explains how Kairosys GmbH collects, uses, shares, and protects your personal information when you use our compliance API platform. By using EU Trace, you agree to the practices described here. Please also review our Terms and Conditions for additional legal information. This policy applies to all users of EU Trace, including visitors, customers, and anyone accessing our services.

2. Information We Collect

We collect information to provide and improve our services: (a) Account Data — name, email address, company name, and billing information when you register for the sandbox or a paid plan. (b) API Payloads — invoice data you submit for validation, auditing, or generation. We process this data solely to deliver the service and do not access it for other purposes. (c) Technical Data — IP address, browser type, device information, operating system, and logs for analytics, security, and troubleshooting. (d) Cookies and Tracking — see the Cookies section below. (e) Voluntary Information — data you provide via contact forms, newsletter sign-ups, or support requests.

3. How We Use Your Information

We use your information for the following purposes: to provide, maintain, and improve the EU Trace API and website; to process and respond to your inquiries and support requests; to send service-related communications, including updates, security alerts, and account notifications; to analyze usage and trends to enhance user experience and develop new features; to ensure the security, integrity, and lawful use of our platform; to comply with legal obligations and regulatory requirements; and to protect the rights, property, or safety of Kairosys GmbH, our users, or the public. The legal bases for processing are Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal obligation), and Art. 6(1)(f) GDPR (legitimate interests).

4. Cookies and Tracking Technologies

EU Trace uses cookies and similar technologies to collect and store certain information. Cookies help us understand user behavior, remember preferences, and improve our services. We use only essential cookies for basic website operation. Analytics are collected via Plausible (a privacy-first, cookieless analytics tool) by default. Google Analytics may be used only after your explicit consent via our cookie banner. You can control cookies through your browser settings and withdraw consent at any time.

5. Data Sharing and Disclosure

We do not sell your personal information to third parties. We may share data with trusted sub-processors who help us operate and improve EU Trace, including hosting providers and email services. These providers are contractually bound by Data Processing Agreements (DPA) per Art. 28 GDPR and are required to protect your data. We do not transfer personal data to third countries. We may disclose information if required by law, regulation, or legal process, or to protect our rights, users, or the public.

6. Data Security and Retention

We take reasonable technical and organizational measures to protect your information, including TLS 1.3 encryption in transit, AES-256-GCM encryption at rest, SHA-256 hash chains for audit ledger integrity, and multi-tenant isolation with tenant-specific KMS keys. However, no method of transmission over the Internet is 100% secure. We retain your data only as long as necessary for the purposes described in this policy or as required by law. Form data is deleted 12 months after last contact. Newsletter subscriptions remain until cancellation. GDPR erasure is supported via cryptographic key destruction for audit ledger data.

7. Your Rights and Choices

Under the GDPR, you have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict processing (Art. 18), data portability (Art. 20), and object (Art. 21) to the processing of your personal data. To exercise your rights, contact us by email. You may also opt out of certain data collection via your browser settings or cookie preferences. You have the right to lodge a complaint with the competent supervisory authority: The Hessian Data Protection Commissioner.

8. Children's Privacy

EU Trace is not intended for children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can remove it. Parents and guardians are encouraged to monitor their children's online activities.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. We will notify registered users of material changes by email. Your continued use of EU Trace after changes are posted constitutes your acceptance of the revised policy. We encourage you to review this policy regularly. This policy is dated July 2026.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact Kairosys GmbH: via email at the address provided on our website (kairosys.org), or through our GitHub repository. We are committed to addressing your privacy concerns promptly and transparently.

See also our Terms and Conditions.

Ready to Integrate? Start Free Today

Get your API key in under 30 seconds and validate your first e-invoice against XRechnung, ZUGFeRD, and EN 16931 — no commitment, no setup call.

Get StartedFree SandboxNo Credit Card30-Minute IntegrationInstant API KeyXRechnungZUGFeRDEN 16931Get StartedFree SandboxNo Credit Card30-Minute IntegrationInstant API KeyXRechnungZUGFeRDEN 16931Get StartedFree SandboxNo Credit Card30-Minute IntegrationInstant API KeyXRechnungZUGFeRDEN 16931
No credit card required
30-minute integration
Free sandbox environment