Last updated: 2026-09-27. Applies to complyfort.com (the hub page) and E-Invoice Check on complyfort.com, part of the ComplyFort family of compliance tools.
ComplyFort is run by InnoDigital, the trading name of a sole proprietorship registered in Poland. The controller of your personal data under the GDPR is:
Adam Szydło (sole proprietorship, trading as InnoDigital)
Kościuszki 40/11, 46-320 Praszka, Poland
NIP 5761448946, REGON 524963224
Email: hello@innodigital.io
Write to that address about anything in this notice. We have not appointed a data protection officer; at our size the law does not require one, so the address above reaches the person who decides.
To keep the free tier fair we count uses per day against a one-way hash of your IP address, the date and a secret salt. The hash cannot be turned back into your address and changes every day.
Legal basis: carrying out the service you asked for (GDPR Art. 6(1)(b)) and our legitimate interest in preventing abuse (Art. 6(1)(f)).
When you enter your email address (to receive a result, to buy, or to join a waiting list) we store it with what you asked for in the tool's own records and in our internal customer records (a CRM we host on our own servers), so we know who used which tool and can honour an opt-out or deletion request across all our products at once. Our logs never contain your address in readable form: they hold a one-way hash of the part before the @, next to the domain.
Legal basis: carrying out what you asked for (Art. 6(1)(b)) and our legitimate interest in keeping a record of who contacted us (Art. 6(1)(f)). You can object at any time.
Where a form offers product news, the checkbox is unticked by default. We add your address to that tool's mailing list at Brevo, our email provider, only when you tick it. If you leave it unticked you get only the messages needed for what you asked for. When you tick the box we store a consent record in our own database: your email address, the time, the form you used and the wording of the checkbox you saw, so we can show later that you agreed. We keep it while you stay subscribed and for 3 years after you withdraw consent. Every product-news email has an unsubscribe link, and one unsubscribe covers all our products.
Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time without affecting what happened before.
Paid features are sold through Stripe Managed Payments. For each purchase Link, LLC, a Stripe company, is the merchant of record: Link is the seller on your receipt and card statement, collects and pays the VAT or sales tax, sends the receipt and handles refunds and payment disputes. Stripe collects your card details, billing address and, where relevant, your tax id on its hosted checkout page; we never see or store the card. Stripe and Link process that data as independent controllers under their own privacy policies.
After a successful payment Stripe tells us your email address, what you bought and the subscription or checkout id. We keep these, together with a one-way hash of your key or code (never the key itself), to know what you are entitled to, to send you your key or code and as evidence if a payment is disputed.
Legal basis: the contract with you (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)).
We send email through Brevo. A hidden copy (BCC) of every email we send goes to an internal company mailbox on Google Workspace, so we can check that our emails went out and handle replies and bounces. The copy contains what you received, including any key or code. It is not used for marketing.
Legal basis: our legitimate interest in running and checking our own email delivery (Art. 6(1)(f)).
Our edge server keeps a standard access log (IP address, the requested address including any query string, and the time) on our host in Finland. It is size-capped, so old entries are overwritten; in practice that is about a week. The application itself keeps no access log. Visitors from countries under EU or US sanctions (Iran, North Korea, Syria, Cuba, Russia, Belarus) are blocked at the edge based on their IP address.
Legal basis: our legitimate interest in keeping the service secure and in complying with sanctions law (Art. 6(1)(f)).
Two things happen when you view a page:
Session replay is switched on. It records the page as it is displayed to you, with mouse movement, scrolling, clicks and page changes, so we can see where a form confuses people. Text you type into a field is masked. The parts of the page that show your validation results or the invoice you generated are blocked from the recording entirely, so the recording shows an empty box there. Replay recordings are deleted after 30 days.
Page-view statistics are kept for 10 years. The analytics script sets no cookies; it writes one random identifier into your browser's local storage and, while replay runs, one flag into session storage. There is no opt-out switch on the site yet; a browser content blocker that blocks analytics.complyfort.com stops the script, and the tools work without it.
Legal basis: our legitimate interest in understanding how the tools are used and improving them (Art. 6(1)(f)). You can object at any time by writing to us.
When you validate a UBL, CII or Factur-X invoice, the file is processed in memory to produce your report and discarded when the request ends. It is never written to disk, to a database or to a log. We keep only which syntax was checked, the score and how many rules failed, which contains no personal data.
Invoices usually contain other people's data: your customers' or suppliers' names, addresses, VAT ids and bank details. We process that data only to produce the result you asked for and keep none of it.
The seller, buyer and line details you type into the generator are turned into a UBL and a CII file in memory and returned to you. Nothing you enter is stored or logged.
If you ask to be told when the API is live, we store your email address, its domain, the date and the short note sent with the form, and whether you ticked the product-news box and when. Sections 2.2 and 2.3 apply.
When you subscribe to Pro we mint an API key and email it to you once. We store only a one-way hash of the key, never the key itself, with your email address, the subscription id, the price id, the date it was created and, if the subscription ends, the date it was revoked. You send the key in a request header, never in the address bar.
Legal basis for section 3: carrying out the service you asked for and the contract with you (Art. 6(1)(b)).
We do not sell your data and we do not share it with advertisers. These service providers process it for us, or receive it as independent controllers where noted:
| Recipient | Role | What | Where |
|---|---|---|---|
| Hetzner Online GmbH | hosting (processor) | all application data, databases, analytics and logs | Helsinki, Finland |
| Amazon Web Services EMEA SARL | backup storage (processor) | encrypted daily backups, kept 30 days (35 days for the customer-records database) | Frankfurt, Germany |
| Link, LLC and Stripe (Stripe Managed Payments) | merchant of record and payment processor (independent controllers) | card details, billing address, tax id, email, payment history | US (Link, LLC) and Ireland (Stripe Technology Europe, Limited), with Stripe group companies in the US |
| Sendinblue SAS (Brevo) | email delivery and mailing lists (processor) | email address, email content, delivery events | France |
| Google Ireland Ltd (Google Workspace) | internal mailbox for the copy of outgoing email (processor) | copies of the emails we send | EU, with Google group companies in the US |
| Cloudflare, Inc. | DNS only; our pages are not proxied through Cloudflare | DNS lookups for complyfort.com made by your resolver | global |
Where a provider transfers data outside the European Economic Area (Link, Stripe and Google group companies in the US), the transfer relies on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
| Data | Kept for |
|---|---|
| Invoices you check and details you type into the generator | the length of the request only |
| Validation counts (syntax, score, failed rules; no personal data) | kept as usage statistics |
| Free-use counters (hashed IP address) | the hash changes every day; the daily files are cleared when the service restarts, at the latest after the quarterly review |
| Email address and lead record | 24 months after your last contact with us |
| Product-news subscription | until you unsubscribe or withdraw consent |
| Consent record (email, time, form, checkbox wording) | while you stay subscribed, then 3 years |
| Purchase and entitlement records | the life of your purchase or subscription, then 5 years for Polish accounting rules |
| Edge access log | size-capped, in practice about a week |
| Analytics page views | 10 years |
| Session replay recordings | 30 days |
| Backups of the databases above | 30 days (35 days for the customer-records database) |
We delete replay recordings automatically, and invoices and generator input never outlive the request. The other periods in this table are applied by a manual review we run at least once a quarter.
You can ask us for access to your data, to correct it, to delete it, to restrict or object to its use, and to receive it in a portable format. You can withdraw the product-news consent at any time. Write to hello@innodigital.io; we may ask you to confirm the email address the request concerns.
We handle requests manually and answer within one month, as the GDPR requires. Deleting your data means removing your records from the tool and from our internal customer records and taking you off any mailing list, except records the law requires us to keep. Backups expire on their own within 35 days. To delete what Stripe and Link hold, contact them as well; they will tell us.
You can also complain to a data protection authority. Ours is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl; you can also contact the authority where you live or work.
Giving us your data is voluntary. Without an email address we cannot send you a result or a key; the free check needs no account.
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
E-Invoice Check sets no cookies of its own. The validator and the generator use no browser storage. The analytics script writes one random identifier into local storage and, while replay runs, one flag into session storage, as described in section 2.7. Stripe sets its own cookies on its checkout pages under Stripe's cookie policy.
We will post any change on this page with a new "last updated" date. The terms cover the rest of how the service works.