Normbeleg

Normbeleg App — Privacy Notice

Version 1.0 · effective 10 October 2026

This notice explains what the Normbeleg app for Stripe does with personal data. The website, waitlist and contact form have their own notice at normbeleg.ppftec.com/privacy.

1. Who we are

PPFTEC S.R.L., Str. Patriarh Iustinian Marina nr. 17-19B, bl. DC12, mansardă, ap. 25, 240469 Râmnicu Vâlcea, Romania; ONRC J2026052999008; CUI 55537142; trading as Normbeleg.

Contact for privacy requests: privacy@ppftec.com. Support: support@ppftec.com or the contact form at normbeleg.ppftec.com/contact. Security issues: security@ppftec.com. Post: the address above. We have no data protection officer because the law does not require one (Art. 37 GDPR).

2. Two roles

  • Invoice data — we are the processor. The business that installs Normbeleg (our customer) decides which invoices we process and is the controller. We act only on its instructions under our Data Processing Agreement (normbeleg.ppftec.com/dpa). If you are a buyer on one of our customers' invoices, please contact that business first; we will pass your request on.
  • Account, billing and support data — we are the controller. That is data about our customers and their users, which we need to run the contract.

3. What the app reads from Stripe

The app reads only with the read-only permissions shown when you install it. It cannot change anything in your Stripe account.

What the app reads from Stripe
PermissionWhat we readWhy
EventsNotices that an invoice or credit note was finalized, paid, updated or voided; install and uninstallStart generation at the right time; stop on uninstall
InvoicesFinalized invoices: number, dates, lines, prices, taxes, totals, buyer details as stored on the invoice, buyer e-mailCreate the e-invoice and deliver or submit it
Credit notesCredit notes and their linesCreate the matching e-credit note
CustomersBuyer name, address, e-mail, tax IDsThey must appear on the e-invoice
Tax ratesRate and countryState the VAT category
Connected accountYour business name, address and support contact, oncePrefill your seller details, which you confirm

The app does not read card or other payment-method data. We also receive your Stripe account ID and the Stripe user ID and role of the person using the app, in requests signed by Stripe, to know which account a request belongs to and to record who changed settings or accepted the Terms.

4. What you enter in the app

Seller details (legal name, address, VAT and tax numbers, register data, contact person, bank details); delivery settings; reply-to and test-recipient e-mail addresses (each verified by a link); for Romania, an ANAF access token issued after a person with a qualified certificate approves it; for Poland (test mode only at present), a KSeF token or a company KSeF certificate. We record which person or Stripe user authorised a connection and when.

5. Purposes and legal bases

Purposes and legal bases
DataPurposeOur role and legal basis
Invoice and buyer data, seller details, delivery and Authority records, CredentialsGenerate, validate, deliver or submit and archive e-invoicesProcessor for our customer (Art. 28 GDPR); our customer's basis is usually Art. 6(1)(c) (legal invoicing duty) and 6(1)(b)
Stripe account ID, user IDs, plan, usage counts, settings historyProvide the service, enforce quotas, keep an audit trailController; Art. 6(1)(b) (contract) and 6(1)(f) (legitimate interest: secure, traceable service)
Acceptance of the Terms and of the express-acceptance clauses (version, hash, time, user, role)Prove the contractController; Art. 6(1)(b) and 6(1)(f)
Purchase data, once paid Plans are offered: business name, address, VAT number and its VIES check, e-mail, plan, payment statusBill you and issue our invoicesController; Art. 6(1)(b); 6(1)(c) for tax and accounting records
Support and privacy requests (contact form or e-mail)Answer your requestController; Art. 6(1)(b), otherwise 6(1)(f)
Security events (IDs only, no invoice content)Detect abuse and incidentsController; Art. 6(1)(f)
Service and legal notices by e-mail (changes, incidents, renewal reminders)Run the contractController; Art. 6(1)(b) and 6(1)(c)

We do not sell data, do not use invoice data for marketing, analytics or training of AI models, and make no automated decisions with legal effect about anyone. We do not store personal data in Stripe-hosted app storage.

6. Who receives the data

  • Cloudflare, Inc. hosts the app as our processor. Storage is in the EU (EU-jurisdiction database and archive). Code runs on Cloudflare's worldwide network, so data may pass briefly through other countries, including the US; Cloudflare is certified under the EU-U.S. Data Privacy Framework and its Data Processing Addendum includes the EU Standard Contractual Clauses. Cloudflare also sends our e-mails (Cloudflare Email Service) and forwards mail to our addresses (Email Routing).
  • Google provides our company mailbox (Google Workspace) as our processor under the Google Cloud Data Processing Addendum (last modified 8 June 2026). E-mails to support@, privacy@ and security@ppftec.com and contact-form notifications arrive there. Google may process them outside the EU/EEA, including in the US, under the transfer terms of that addendum.
  • ANAF (Romanian Ministry of Finance) receives invoices because the law requires it, on our customer's instruction. In test mode, KSeF test systems (Polish Ministry of Finance) and verified test e-mail addresses may receive test Documents.
  • Stripe, once paid Plans are offered, processes payment data for our subscriptions under its own terms and privacy policy.
  • Our accounting provider (Keez, Romania) receives our own sales invoices and payment records for bookkeeping, once we invoice paid Plans.
  • Authorities or courts when the law requires it.

7. How long we keep data

How long we keep data
DataPeriod
Documents and their records12 months from generation; with the paid "Long-term archive" option, once offered, until the end of the 8th year after the issue year, also after uninstall (as our customer instructs)
ANAF / KSeF credentialsDeleted at once when disconnected or when the app is uninstalled
Stripe event records and raw event copies30 days
Download links1 day
Unverified e-mail addresses90 days
Database point-in-time history30 days
Account, settings history, acceptance recordsContract term + 3 years, longer only if a claim is pending
Our invoices and accounting recordsAs Romanian accounting and tax law requires
Support messagesUntil the request is settled, at most 6 months after receipt

After uninstall or termination your data stays exportable for at least 30 days (EU Data Act), then is deleted except write-protected archive copies until their period ends and records we must keep by law.

8. Your rights

You can ask for access, correction, erasure, restriction, portability and object to processing based on legitimate interest (Arts. 15–18, 20, 21 GDPR) by writing to privacy@ppftec.com. For invoice data we act for our customer and will pass your request to them; invoices that the law requires to be kept may be restricted rather than deleted until the retention period ends. You can complain to the Romanian supervisory authority ANSPDCP (www.dataprotection.ro) or to the authority in your country.

9. Changes

We announce changes to this notice in the app before they take effect. Earlier versions stay available on request.

Version 1.0. SHA-256 of the text of this version, as recorded when you accept it in the app: ccb9cf6ebd4bf9d70aea32ed5cbd372c9b9804105f9dfb8b1dd38242b190bd3f