Last updated: 29 September 2026
Effective from its publication on essentio.pro.
Essentio is an online service for issuing invoices, run by CPV Corporate Services Ltd ("Essentio", "we"). For the personal data this policy describes, we are the controller.
| Company | CPV Corporate Services Ltd, a private limited company registered in Cyprus |
| Registration number | HE 252516 |
| Registered office | 23, 28th October str., 3rd floor, Engomi, 2414 Nicosia, Cyprus |
| VAT number | CY10252516A |
| Telephone | +357 96609721 |
| Privacy contact | support@essentio.pro |
We have not appointed a data protection officer: we do not monitor people on a large scale or process special categories of data, so the law does not require one. Write to support@essentio.pro with any question about your data.
This policy covers the people whose data we decide how to use:
What it does not cover. A Business uses Essentio to keep details of its own Clients, the customers it invoices, and to send them invoices. For that data the Business is the controller and Essentio processes it on the Business's behalf, under our Data Processing Agreement. A Client who wants to know what is held about them, or to have it corrected or deleted, should ask the Business that invoiced them. We help the Business answer.
Essentio is for businesses only. It is not meant for use outside a trade, business or profession.
We collect no payment card details and no special categories of data such as health or religion. A card is typed on Stripe's own payment page and never reaches us.
| Who | What we hold | Where it comes from |
|---|---|---|
| Visitors | Pages visited and actions taken, without names or cookies (see section 8); the IP address in our web server log | Your browser |
| Users | Name, email address, password (stored only as a one-way hash), the Businesses you belong to and your role in each, your display settings, your session and, briefly, your IP address to limit repeated login attempts | You, when you sign up and use Essentio |
| Users | A record of who recorded a payment, changed a document number, or created an API key or connection | Your use of Essentio |
| Owners | Your plan, the end of your Trial, your Subscription's status, and which Stripe customer record is yours. The Business's plan, which Businesses you chose to keep covered or free, and how many Invoices it issued on the Free plan this year | You and Stripe |
| Owners | A Business's name, legal name, address, contacts, VAT, tax and company registration numbers, bank accounts, logo and signature image, and its email sending settings. Passwords and access keys for mailboxes are stored encrypted | You |
| Owners | The Business's VAT number in a normalised form, compared with other Owners' free Businesses so that one VAT number gets one free Business and one Trial | You |
| Owners and Businesses | Whether the VAT number is valid, and the name and address the EU's VIES register holds for it | The European Commission's VIES service |
| Invited people | Your email address, the role offered to you, and who invited you | The person who invited you |
| Referred Owners | Which Partner referred you | The Partner's link or invitation you used |
| Partners | Your application, the dates it was approved or withdrawn, your referral link, and which Owners you referred and whether each one pays (never the amount) | You and your use of the programme |
| Developers | Each API key and connected app: its name, Business, role, who created it and when; a log of each request made with it (which one, when, the action, the result and the IP address, but no invoice or Client data) | Your software's use of the API |
| Anyone who writes to us | Your message and the details you give, and, for in-app feedback, your User and Business numbers; your email only if you agree to be contacted | You |
If you do not give the data a form marks as required, we cannot open your account or provide that feature. Billing details are needed to charge for a paid plan and are kept as tax records.
We use your data only for the purposes below. "Contract" means we need it to provide the service you signed up for (GDPR Art. 6(1)(b)); "legal obligation" means a law requires it (Art. 6(1)(c)); "legitimate interests" means we have a reason of our own that does not override your rights (Art. 6(1)(f)), and we name that reason.
| Purpose | Data | Legal basis |
|---|---|---|
| Opening your account, logging you in, running your Businesses and your team | Account, Business and team data | Contract |
| Sending account emails: confirming your address, resetting your password, invitations, notices about your Business | Name, email | Contract |
| Charging for a paid plan, running the Trial, and deciding which Businesses a plan covers | Owner and plan data, Stripe's payment status | Contract |
| Keeping invoices and payment records for Essentio's own tax returns | Billing details, Stripe's invoices | Legal obligation |
| Checking VAT numbers against the EU's VIES register | VAT number | Contract |
| Allowing one free Business and one Trial per person and per VAT number | Normalised VAT number, Owner data | Legitimate interests: keeping the Free plan and the Trial fair and preventing abuse |
| Finding and fixing errors | Error reports with User and Business numbers; masked screen recordings of sessions where an error happened | Legitimate interests: a working, secure service |
| Understanding how Essentio is used | Anonymous page visits and actions | Legitimate interests: improving the product. See section 8 |
| Protecting accounts: limiting login attempts, logging API requests | IP address, request log | Legitimate interests: security |
| Supporting you, including reading a Business's data during Support access its Owner gave | Your messages; the Business's data, read-only | Contract |
| Logging what our staff change (plans, restores, Partners) | Staff member, the change, its reason | Legitimate interests: accountability and resolving disputes |
| Running the Partner programme: attributing referrals, applying the discount, showing a Partner whether a referred Owner pays | Referral and plan status | Contract with the Partner and the referred Owner; the Owner is told at sign-up |
| Handling feedback you send | Message, User and Business numbers, email if you agree | Legitimate interests: improving the product |
| Answering legal claims and authorities' requests | Any of the above, as needed | Legal obligation or legitimate interests: defending our rights |
We do not sell personal data, use it for advertising, or make decisions about you by automated means alone.
All data is stored on servers we rent from Hetzner in Germany. These companies process some of it for us, under contracts that bind them to our instructions:
| Processor | What it receives | Why | Where |
|---|---|---|---|
| Hetzner Online GmbH | Everything Essentio stores, the account emails we send, and the emails a Business sends through Essentio's mail server | Hosting, backups and our mail server | Germany |
| Functional Software, Inc. (Sentry) | Error reports with User and Business numbers, no names or emails; masked screen recordings of sessions where an error happened | Finding and fixing errors | EU; some account data in the US |
| PostHog, Inc. | Anonymous page visits and actions, without cookies or names | Usage statistics | EU |
| GitHub, Inc. | Feedback messages, with User and Business numbers, and your email only if you agree to be contacted | Handling feedback | US |
Stripe. Stripe Payments Europe, Ltd. (Ireland) takes payment for Essentio's plans and issues their invoices. It receives an Owner's name, email, billing address, VAT ID and card, and the Subscription's payments, invoices and credit notes; for a referred Owner, the Partner discount. Stripe processes this partly for us and partly as an independent controller, for example to choose payment methods, prevent fraud and meet its own legal duties. Stripe's privacy policy explains that part.
Recipients you choose. These receive data because you or your Business asked us to send it, and they use it under their own terms:
We also disclose data where the law requires it, or to defend legal claims. If Essentio or its business is sold or merged, the data passes to the new owner under this policy.
Cloudflare provides our domain names only; no personal data passes through it. A monitoring service checks that essentio.pro is up and receives no personal data.
Most of your data never leaves the European Economic Area. Where it does:
| Recipient | Country | Safeguard |
|---|---|---|
| Sentry (account data) | United States | EU–US Data Privacy Framework, and the EU standard contractual clauses (Decision (EU) 2021/914) |
| GitHub (feedback) | United States | EU–US Data Privacy Framework |
| Stripe (part of its processing) | United States | EU–US Data Privacy Framework, and the EU standard contractual clauses in Stripe's data transfers addendum |
| New Zealand business register | New Zealand | EU adequacy decision |
The Data Privacy Framework is an EU adequacy decision (Decision (EU) 2023/1795) covering the certified US companies listed at dataprivacyframework.gov. You can ask us for a copy of the standard contractual clauses at support@essentio.pro.
When you connect an AI assistant or other software, the data it reads goes wherever that provider processes it, under your agreement with them.
We keep data while your account or Business exists. Something you delete is kept for 30 days, so it can be restored on request, and is then erased for good.
| Data | Kept for |
|---|---|
| Your User account | Until you delete it; then erased at once |
| A Business, with everything in it | Until it is deleted, then 30 more days |
| A deleted Client, draft, product or payment | 30 days, except a Client named on a document, and a payment with a receipt: these stay until the Business is erased, so that its documents and receipt numbers stay whole |
| Login session | Ends after 2 hours without activity; "Remember me", if you tick it, about 400 days |
| Password reset link | 1 hour |
| Team invitation | Valid 7 days, erased 30 days after that |
| A full download of a Business's data | 7 days |
| API request log, and copies of notifications sent to a Business's web addresses | 30 days |
| Messages received from Stripe | 90 days |
| Error log file; web server log | 30 days; until it reaches 50 MB, usually days |
| Database backups | Up to 8 weeks: erased data leaves the backups as they are replaced |
| An Owner's Stripe customer record and Stripe's invoices | As long as Cypriot tax law requires, also after the account is deleted |
| Our staff's change log, and the record of each Support access use | 6 years |
| A Partner's application and referrals | 6 years after the partnership ends |
| A connected app's access | Renewed hourly; ends after 90 days without use, or when it is disconnected |
We use no advertising or tracking cookies. The cookies below are needed to provide the service you ask for, so they need no consent.
| Name or kind | Why | How long |
|---|---|---|
| Session cookie | Keeps you logged in; also remembers a Partner's referral link until you sign up | Until 2 hours without activity |
| Security (XSRF) cookie | Protects forms from misuse by other websites | As the session |
| "Remember me" cookie | Keeps you logged in on this device, only if you tick the box | About 400 days |
| Display settings (browser storage) | Remembers screen choices, such as a selected tab; no personal data | Until you clear your browser |
| Error recording marker (browser session storage) | Links a masked screen recording to an error report | Until the tab is closed |
Page statistics. Essentio and its developer site count page visits and actions with PostHog, hosted in the EU. It sets no cookie and stores nothing in your browser, and we do not send it names or email addresses. Your browser still sends it the page address, the kind of browser and device, and a rough location derived from the IP address, which PostHog does not keep. You can stop it by blocking eu.i.posthog.com in your browser or an extension; Essentio keeps working. Test businesses and public invoice links send no statistics at all.
Paying. The payment page and the page for managing a Subscription are Stripe's own. Stripe sets its own cookies there, under its own policy. Essentio's pages load no Stripe code.
Invoice links. A Client who opens an invoice link is not tracked: we record only when the document was first opened and how many times, not who opened it or from where.
A Business sends its invoices, reminders and receipts through Essentio's own mail server — from Essentio's address in the Business's name, with replies going to the Business's own address — or from its own address, through its own mail server or by connecting its Gmail or Microsoft 365 mailbox. An Owner or Admin chooses this in Settings → Email.
Google user data. When you connect Gmail, Essentio asks Google for two permissions only:
gmail.send, to send the emails the Business asks Essentio to send, from its own address;userinfo.email, to show which address is connected.Essentio never reads, searches or stores the contents of your mailbox. It keeps the connected address and an access key, stored encrypted, and uses the key only to send the Business's own emails when a member of its team asks. It shares no Google user data with anyone, uses none of it for advertising, and uses none of it to train AI models. No person at Essentio reads it, except with your explicit consent, for security, or where the law requires. You can disconnect at any time in Settings → Email or in your Google Account's security settings; the access key is then deleted.
Essentio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Microsoft 365. Connecting a Microsoft mailbox works the same way. Essentio asks for Mail.Send to send the Business's emails, User.Read to show which address is connected, and offline_access so that sending keeps working without signing in each time. It never reads the mailbox.
A Business can let other software work with its data:
They read and change the Business's Clients, documents, payments and products only as far as their role allows, and never beyond the person who connected them. The data they receive leaves Essentio and is kept and used under the rules of whoever runs that software. For an AI assistant, the data goes to its provider, such as Anthropic or OpenAI, under your own account with them. Essentio does not receive your conversation with the assistant, only the requests the assistant makes to Essentio. ChatGPT adds your language, an approximate location and anonymous identifiers to each request; we do not store them.
Essentio does not review software that developers register. Check what you connect. You can disconnect any app in Settings; a connection also ends when the person who made it leaves the Business, or after 90 days without use.
Notifications. An Owner or Admin, or a connected app, can register a web address that receives a message when an invoice is issued, sent, opened, paid or cancelled, or a payment is recorded or reversed. The message describes that document or payment, including the Client's name and the amount.
What we keep. For each API key and connection: its name, Business, role, who created it and when. For each request: which key or app, when, the action, the result and the IP address, kept 30 days. Owners and Admins can see this log for their Business.
Under the GDPR you can ask us to:
Your right to object. Where we rely on legitimate interests (section 4), you can object at any time to our use of your data on grounds relating to your situation. We will stop unless we have compelling legitimate grounds that override your interests, or need the data for legal claims. To object, write to support@essentio.pro.
For anything you cannot do yourself, write to support@essentio.pro. We answer within one month, and may ask you to confirm your identity first. If you are a Business's Client, see section 2.
Security. All connections are encrypted (HTTPS). Passwords are stored only as one-way hashes; mailbox passwords and access keys are encrypted. Every User confirms their email address, and repeated wrong logins are blocked for a while. Each Business sees only its own data, and inside a Business each person has one of four roles. The database cannot be reached from the internet and is backed up daily. Our staff work in a separate console with their own accounts and a second login step; they see a Business's Clients, documents and payments only when its Owner gives Support access, read-only, for 24 hours at most, and every change they make is logged with a reason. If a breach puts your data at risk, we tell you and the Commissioner as the GDPR requires.
Automated decisions. We make no decisions about you based solely on automated processing that have legal or similarly significant effects.
Age. Essentio is for businesses, and Users must be 18 or older. We do not knowingly collect data about children.
Changes. We will post any change here with a new date. If a change affects how we use your data in a significant way, we tell Owners by email and in Essentio before it takes effect, and ask for your consent where the law or Google's rules require it.
Contact. support@essentio.pro, or CPV Corporate Services Ltd, 23, 28th October str., 3rd floor, Engomi, 2414 Nicosia, Cyprus.
Complaints. You can complain to the Office of the Commissioner for Personal Data Protection, Kypranoros 15, 1061 Nicosia, Cyprus (P.O. Box 23378, 1682 Nicosia), tel. +357 22818456, commissioner@dataprotection.gov.cy, gov.cy/dataprotection, or to the authority in the EU country where you live or work. We would be glad to try to resolve it first.