Skip to main content

Data Handling

This page describes how faktoora manages data residency, retention, backup, and deletion.

Data Residency

All faktoora production infrastructure is hosted in Germany by an EU-based, ISO 27001 certified infrastructure provider. Customer data — including invoices, contacts, and account information — resides exclusively within the European Union.

Data Retention

faktoora retains data in accordance with German and European legal requirements.

Business Documents

Data typeRetentionLegal basis
Outgoing invoices10 years from end of calendar yearGoBD, AO § 147
Incoming invoices10 years from end of calendar yearGoBD, AO § 147
Offers, letters, reminders6 years from end of calendar yearGoBD
Peppol transmission records10 yearsPeppol agreements, GoBD
VeriFactu registration records10 yearsSpanish tax law
Bank transaction data10 yearsGoBD
Subscription and payment records10 yearsGoBD

Operational Data

Data typeRetentionPurpose
User accountsUntil deletion requestedService provision
Session data24 hours (auto-expiry)Authentication
Activity and audit logsIndefiniteSecurity, compliance
Export archives90 daysTemporary user downloads
ICT incident recordsMinimum 5 yearsDORA compliance

Backups

Backups are encrypted and retained for up to 24 months for disaster recovery purposes. Backup data follows the same access restrictions as production data.

Deletion

Account Deletion

Users can request account deletion at any time. Upon cancellation:

  1. The account is deactivated — users can no longer log in
  2. Personal data (name, email, settings) is anonymised or deleted upon request
  3. Invoice and financial data is retained per legal requirements (see retention periods above)
  4. Once legal retention periods expire, remaining data can be permanently deleted upon request

GDPR Erasure Requests

We honour all GDPR erasure requests to the extent permitted by law. German accounting law (GoBD) requires retention of invoice and financial records, which takes precedence over erasure requests during the applicable retention period. We will inform you of any limitations when processing your request.

Backup Retention

Data deleted from production may persist in encrypted backups for the backup retention period (up to 24 months). Backups follow the same access controls and encryption standards as production data.

Data Portability

faktoora provides self-service data export in multiple formats:

FormatUse case
CSVSpreadsheet-compatible tabular data
XLSXMicrosoft Excel format
JSONMachine-readable structured data
XMLStandards-compliant e-invoice formats (ZUGFeRD, XRechnung, Peppol UBL)

Data Integrity

Invoice data integrity is ensured through:

  • Immutable audit trail that is tamper-evident and independently verifiable
  • Parameterised database queries preventing injection attacks
  • Frozen calculation functions — core invoice calculation logic is battle-tested and protected from modification
  • Backup integrity verification with regular automated checks

Questions?

For questions about data handling, contact privacy@faktoora.com.