Privacy Policy
Last updated: 2 September 2026
1. Controller and contact details
This privacy notice explains how personal data is processed when you visit zugferd.randomstar.org or use the E-Rechnung Pro service (the "Service"). It is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR").
The controller within the meaning of Article 4(7) GDPR is:
CHERNOVA LILIIA PETRIVNA
Private entrepreneur under the law of Ukraine, trading as E-Rechnung Pro
Masyv Raiduzhnyi 24, 67804 Lymanka, Odesa district, Odesa region, Ukraine
Email: zugferd@randomstar.org
Telephone: +380 99 149 57 47
1.1 Data protection officer
The controller is not obliged to designate a data protection officer under Article 37 GDPR and has not designated one. Please direct all data protection enquiries to the contact details set out above.
2. Where your data is stored
The Service, including the invoice validation service and the document rendering service, runs on servers operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in the data centre location Falkenstein, Germany. Email is delivered from the same infrastructure.
All account data, uploaded files and generated documents are stored exclusively within the European Union. No user data is stored outside the European Union.
The controller is established in Germany. All account data, uploaded files and generated documents are processed on servers within the European Union. The only processing that involves a country outside the European Economic Area is payment processing, described in section 3.6.
3. Processing activities, purposes and legal bases
3.1 Visiting the website
Each time a page is requested, the web server records: your IP address, date and time of the request, the requested resource, HTTP status code, volume of data transferred, the referring page and the browser and operating system identifier transmitted by your browser.
Purpose: delivering the website, ensuring stability, detecting and investigating attacks and misuse, diagnosing faults.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of the Service. Log data is not combined with your user account and is not used to identify you as a person.
Retention: 90 days, after which the records are deleted.
3.2 Registration and administration of your user account
To create an account we process: your name, your email address, your password (stored only as a bcrypt hash, never in plain text), and optionally your company name. We generate an email verification token and record the date of registration and of your last sign-in.
Purpose: creating and administering your account, authenticating you, providing the Service.
Legal basis: Article 6(1)(b) GDPR, performance of a contract and the taking of steps at your request prior to entering into a contract.
Retention: for the duration of your account. Accounts whose email address is not verified are deleted automatically after 7 days.
3.3 Signing in with a Google account
You may optionally register or sign in using your Google account. If, and only if, you actively choose this option, Google transmits to us your Google user identifier, your name and your email address. No data is transmitted to Google unless you choose this sign-in method.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Information on Google's own processing is available at policies.google.com/privacy.
Legal basis: Article 6(1)(b) GDPR, since the sign-in is necessary to give you access to the account you requested.
3.4 Company profile and invoice content
In order to produce invoices, you may store a company profile containing: company name, VAT identification number, tax number, registration number, postal address, telephone number, email address, website, IBAN, BIC, name of your bank, company logo and free invoice footer text.
You also supply the content of the invoices you create, convert or validate. That content may include personal data relating to third parties, in particular your own customers, such as their name, address, contact details and the description and value of the goods or services supplied.
Purpose: generating, converting and validating ZUGFeRD and Factur-X documents at your request; pre-filling your invoices.
Legal basis: Article 6(1)(b) GDPR.
Important: in respect of personal data contained in the invoices you process, we act as a processor on your behalf and you act as the controller. That relationship is governed by a separate data processing agreement pursuant to Article 28(3) GDPR, which is available on request and which forms part of your contract with us.
3.5 Processing of your documents
PDF files that you upload, and the documents generated for you, are stored so that they remain available in your document history and can be downloaded again. In order to validate a document against the ZUGFeRD and Factur-X specifications and to render document previews, files are transmitted to two supporting services operated by the controller at validator.randomstar.org and render.randomstar.org. Both run on the same infrastructure in Falkenstein, Germany, described in section 2, and are not accessible to any third party.
We record, for each document, its type, the time of processing, whether it was processed within your free allowance and the technical result of the validation.
Legal basis: Article 6(1)(b) GDPR.
Retention: for the duration of your account, and thereafter as set out in section 5.
3.6 Subscriptions and payments
Payments are processed by our payment service provider Stripe Payments Europe, Limited. Your full card number, expiry date and security code are entered on the payment provider's own page and are never transmitted to us or stored by us. We receive and store: the amount, currency, our internal order reference, the transaction status and date, the masked card number and card scheme, and a payment token which allows a recurring subscription charge to be made without you re-entering your card details.
Purpose: processing your subscription, renewals, downgrades, cancellations and refunds; complying with accounting and tax obligations.
Legal basis: Article 6(1)(b) GDPR for the performance of the subscription contract, and Article 6(1)(c) GDPR for the retention of accounting records under applicable tax law.
Retention: payment records are retained for eight years from the end of the year in which the transaction took place, in accordance with section 147(3) of the German Fiscal Code (Abgabenordnung). A stored payment token is deleted when you remove the payment method or terminate your subscription.
3.7 Contact form and support
If you use the contact form we process the name, email address, company name, subject and message that you provide, together with the time of submission. The form is protected by a challenge image and a hidden field in order to block automated submissions.
Legal basis: Article 6(1)(b) GDPR where your enquiry relates to an existing or prospective contract, otherwise Article 6(1)(f) GDPR, our legitimate interest in answering enquiries addressed to us.
Retention: 12 months from the conclusion of the correspondence.
3.8 Newsletter
If you subscribe to our newsletter we process your email address, your language preference and the date and source of your subscription. We use a confirmed opt-in procedure: you will receive an email asking you to confirm your subscription, and we record the confirmation.
Legal basis: Article 6(1)(a) GDPR, your consent. You may withdraw your consent at any time with effect for the future, using the unsubscribe link contained in every newsletter or by writing to us. Withdrawal does not affect the lawfulness of processing carried out before it.
3.9 Cookies and similar technologies
We do not use any analytics, tracking, advertising, profiling or social media technologies. No third party places cookies through this website. There is therefore no consent banner, because none of the cookies used require consent.
The following cookies are strictly necessary in order to provide the service you have expressly requested, within the meaning of section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Article 82 of the French Data Protection Act (Loi Informatique et Libertes). They are stored on the basis of Article 6(1)(f) GDPR, our legitimate interest in a functioning website:
- PHPSESSID — maintains your session while you are signed in and secures forms against cross-site request forgery. Deleted when you close your browser.
- lang — stores the interface language you selected, so that you are not returned to the default language on every visit.
- remember token — set only if you tick "remember me" when signing in, so that you are not required to sign in on every visit. Valid for up to 365 days, deleted when you sign out.
- auth removed — a short-lived technical cookie used to complete the sign-out process correctly.
You can delete cookies at any time in your browser settings and configure your browser to refuse them. If you do so, you will not be able to sign in to the Service.
4. Recipients of your data
Your data is not sold, rented or made available for the purposes of third party advertising. It is disclosed only to the following categories of recipient:
- Hetzner Online GmbH, Gunzenhausen, Germany — hosting of servers, storage and email delivery. Processor under Article 28 GDPR. Data remains in Germany.
- Stripe Payments Europe, Limited, Ireland — payment processing. Receives the data necessary to execute your payment and does not receive the content of your invoices. Acts as a controller in its own right in respect of the card data you enter on its page. Stripe may transfer personal data to Stripe, Inc. in the United States and to other countries outside the European Economic Area; those transfers are covered by the standard contractual clauses adopted by the European Commission and by Stripe's certification under the EU-US Data Privacy Framework.
- Google Ireland Limited — only if you actively choose to sign in with a Google account, see section 3.3.
- Public authorities — where we are required to disclose data by law binding upon us.
An up to date list of processors is available at any time from the contact address in section 1.
5. Erasure and retention periods
We delete personal data as soon as it is no longer required for the purpose for which it was collected and no statutory retention obligation prevents its erasure. In particular:
- Server log files: 90 days.
- Unverified registrations: 7 days.
- Account data, company profile and stored documents: for the duration of your account. If you terminate your account, they are erased within 30 days, save for the payment records referred to below.
- Payment and accounting records: eight years from the end of the year of the transaction, on the basis of Article 6(1)(c) GDPR in conjunction with section 147(3) of the German Fiscal Code.
- Contact form messages: 12 months.
- Newsletter data: until you withdraw your consent.
You may request the deletion of your account at any time by writing to zugferd@randomstar.org from the email address registered to the account. We will action the request without undue delay and in any event within one month.
6. Your rights
You have the following rights in relation to the personal data we hold about you:
- Access (Article 15 GDPR) — to obtain confirmation as to whether we process your data, and a copy of that data.
- Rectification (Article 16 GDPR) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17 GDPR) — to have your data deleted where one of the grounds listed in that article applies.
- Restriction of processing (Article 18 GDPR).
- Data portability (Article 20 GDPR) — to receive the data you provided to us in a structured, commonly used and machine readable format.
- Objection (Article 21 GDPR) — to object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR.
- Withdrawal of consent (Article 7(3) GDPR) — to withdraw at any time any consent you have given, with effect for the future.
To exercise these rights, write to zugferd@randomstar.org or to the representative named in section 1.1. We will respond within one month of receipt of your request. Exercising your rights is free of charge.
7. Right to lodge a complaint
Without prejudice to any other remedy, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
< You have the right to lodge a complaint with a data protection supervisory authority in the EU member state of your habitual residence, place of work or the place of the alleged infringement. In France, the competent authority is the Commission Nationale de l'Informatique et des Libertes (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07. In Germany, competence lies with the data protection authority of the relevant federal state; a list is published by the Federal Commissioner for Data Protection and Freedom of Information.8. Security
We apply appropriate technical and organisational measures pursuant to Article 32 GDPR, having regard to the state of the art, the costs of implementation and the risks presented by the processing. These include in particular:
- Encryption of all traffic between your browser and our servers using TLS.
- Storage of passwords exclusively as bcrypt hashes; passwords are never stored or transmitted in plain text and cannot be read by us.
- Single use, time limited and hashed tokens for password resets and email verification.
- Strict separation of user accounts, so that documents are accessible only to the account that created them.
- Access to production systems restricted to the controller, using individual authenticated accounts.
- Regular backups and installation of security updates.
Please note that no method of transmission over the internet can be guaranteed to be absolutely secure.
9. No automated decision-making
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR, and we do not carry out profiling.
10. Minors
The Service is directed exclusively at businesses and self-employed professionals. It is not intended for, and must not be used by, persons under the age of 18. We do not knowingly collect data relating to children.
11. Obligation to provide data
The provision of the data described in sections 3.2, 3.4 and 3.6 is necessary in order to enter into and perform the contract. Without it we cannot create an account for you or provide the Service. There is no statutory obligation on you to provide the data, and you are under no obligation to use the Service.
12. Changes to this notice
We may amend this notice in order to reflect changes to the Service or to the applicable law. The version in force is the one published on this page, and the date of the last amendment appears at the top. In the case of material changes affecting registered users, we will inform you by email in advance.