Essentio Privacy Policy

Last updated: 29 September 2026

Effective from its publication on essentio.pro.

1. Who we are

Essentio is an online service for issuing invoices, run by CPV Corporate Services Ltd ("Essentio", "we"). For the personal data this policy describes, we are the controller.

We have not appointed a data protection officer: we do not monitor people on a large scale or process special categories of data, so the law does not require one. Write to support@essentio.pro with any question about your data.

2. What this policy covers

This policy covers the people whose data we decide how to use:

What it does not cover. A Business uses Essentio to keep details of its own Clients, the customers it invoices, and to send them invoices. For that data the Business is the controller and Essentio processes it on the Business's behalf, under our Data Processing Agreement. A Client who wants to know what is held about them, or to have it corrected or deleted, should ask the Business that invoiced them. We help the Business answer.

Essentio is for businesses only. It is not meant for use outside a trade, business or profession.

3. What we collect

We collect no payment card details and no special categories of data such as health or religion. A card is typed on Stripe's own payment page and never reaches us.

If you do not give the data a form marks as required, we cannot open your account or provide that feature. Billing details are needed to charge for a paid plan and are kept as tax records.

We use your data only for the purposes below. "Contract" means we need it to provide the service you signed up for (GDPR Art. 6(1)(b)); "legal obligation" means a law requires it (Art. 6(1)(c)); "legitimate interests" means we have a reason of our own that does not override your rights (Art. 6(1)(f)), and we name that reason.

We do not sell personal data, use it for advertising, or make decisions about you by automated means alone.

5. Who receives your data

All data is stored on servers we rent from Hetzner in Germany. These companies process some of it for us, under contracts that bind them to our instructions:

Stripe. Stripe Payments Europe, Ltd. (Ireland) takes payment for Essentio's plans and issues their invoices. It receives an Owner's name, email, billing address, VAT ID and card, and the Subscription's payments, invoices and credit notes; for a referred Owner, the Partner discount. Stripe processes this partly for us and partly as an independent controller, for example to choose payment methods, prevent fraud and meet its own legal duties. Stripe's privacy policy explains that part.

Recipients you choose. These receive data because you or your Business asked us to send it, and they use it under their own terms:

We also disclose data where the law requires it, or to defend legal claims. If Essentio or its business is sold or merged, the data passes to the new owner under this policy.

Cloudflare provides our domain names only; no personal data passes through it. A monitoring service checks that essentio.pro is up and receives no personal data.

6. Transfers outside the EEA

Most of your data never leaves the European Economic Area. Where it does:

The Data Privacy Framework is an EU adequacy decision (Decision (EU) 2023/1795) covering the certified US companies listed at dataprivacyframework.gov. You can ask us for a copy of the standard contractual clauses at support@essentio.pro.

When you connect an AI assistant or other software, the data it reads goes wherever that provider processes it, under your agreement with them.

7. How long we keep it

We keep data while your account or Business exists. Something you delete is kept for 30 days, so it can be restored on request, and is then erased for good.

8. Cookies, browser storage and page statistics

We use no advertising or tracking cookies. The cookies below are needed to provide the service you ask for, so they need no consent.

Page statistics. Essentio and its developer site count page visits and actions with PostHog, hosted in the EU. It sets no cookie and stores nothing in your browser, and we do not send it names or email addresses. Your browser still sends it the page address, the kind of browser and device, and a rough location derived from the IP address, which PostHog does not keep. You can stop it by blocking eu.i.posthog.com in your browser or an extension; Essentio keeps working. Test businesses and public invoice links send no statistics at all.

Paying. The payment page and the page for managing a Subscription are Stripe's own. Stripe sets its own cookies there, under its own policy. Essentio's pages load no Stripe code.

Invoice links. A Client who opens an invoice link is not tracked: we record only when the document was first opened and how many times, not who opened it or from where.

9. Google and Microsoft mailboxes

A Business sends its invoices, reminders and receipts through Essentio's own mail server — from Essentio's address in the Business's name, with replies going to the Business's own address — or from its own address, through its own mail server or by connecting its Gmail or Microsoft 365 mailbox. An Owner or Admin chooses this in Settings → Email.

Google user data. When you connect Gmail, Essentio asks Google for two permissions only:

Essentio never reads, searches or stores the contents of your mailbox. It keeps the connected address and an access key, stored encrypted, and uses the key only to send the Business's own emails when a member of its team asks. It shares no Google user data with anyone, uses none of it for advertising, and uses none of it to train AI models. No person at Essentio reads it, except with your explicit consent, for security, or where the law requires. You can disconnect at any time in Settings → Email or in your Google Account's security settings; the access key is then deleted.

Essentio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Microsoft 365. Connecting a Microsoft mailbox works the same way. Essentio asks for Mail.Send to send the Business's emails, User.Read to show which address is connected, and offline_access so that sending keeps working without signing in each time. It never reads the mailbox.

10. Connected apps, the API and AI assistants

A Business can let other software work with its data:

They read and change the Business's Clients, documents, payments and products only as far as their role allows, and never beyond the person who connected them. The data they receive leaves Essentio and is kept and used under the rules of whoever runs that software. For an AI assistant, the data goes to its provider, such as Anthropic or OpenAI, under your own account with them. Essentio does not receive your conversation with the assistant, only the requests the assistant makes to Essentio. ChatGPT adds your language, an approximate location and anonymous identifiers to each request; we do not store them.

Essentio does not review software that developers register. Check what you connect. You can disconnect any app in Settings; a connection also ends when the person who made it leaves the Business, or after 90 days without use.

Notifications. An Owner or Admin, or a connected app, can register a web address that receives a message when an invoice is issued, sent, opened, paid or cancelled, or a payment is recorded or reversed. The message describes that document or payment, including the Client's name and the amount.

What we keep. For each API key and connection: its name, Business, role, who created it and when. For each request: which key or app, when, the action, the result and the IP address, kept 30 days. Owners and Admins can see this log for their Business.

11. Your rights

Under the GDPR you can ask us to:

Your right to object. Where we rely on legitimate interests (section 4), you can object at any time to our use of your data on grounds relating to your situation. We will stop unless we have compelling legitimate grounds that override your interests, or need the data for legal claims. To object, write to support@essentio.pro.

For anything you cannot do yourself, write to support@essentio.pro. We answer within one month, and may ask you to confirm your identity first. If you are a Business's Client, see section 2.

12. Security, age, changes and complaints

Security. All connections are encrypted (HTTPS). Passwords are stored only as one-way hashes; mailbox passwords and access keys are encrypted. Every User confirms their email address, and repeated wrong logins are blocked for a while. Each Business sees only its own data, and inside a Business each person has one of four roles. The database cannot be reached from the internet and is backed up daily. Our staff work in a separate console with their own accounts and a second login step; they see a Business's Clients, documents and payments only when its Owner gives Support access, read-only, for 24 hours at most, and every change they make is logged with a reason. If a breach puts your data at risk, we tell you and the Commissioner as the GDPR requires.

Automated decisions. We make no decisions about you based solely on automated processing that have legal or similarly significant effects.

Age. Essentio is for businesses, and Users must be 18 or older. We do not knowingly collect data about children.

Changes. We will post any change here with a new date. If a change affects how we use your data in a significant way, we tell Owners by email and in Essentio before it takes effect, and ask for your consent where the law or Google's rules require it.

Contact. support@essentio.pro, or CPV Corporate Services Ltd, 23, 28th October str., 3rd floor, Engomi, 2414 Nicosia, Cyprus.

Complaints. You can complain to the Office of the Commissioner for Personal Data Protection, Kypranoros 15, 1061 Nicosia, Cyprus (P.O. Box 23378, 1682 Nicosia), tel. +357 22818456, commissioner@dataprotection.gov.cy, gov.cy/dataprotection, or to the authority in the EU country where you live or work. We would be glad to try to resolve it first.