EdiEZ VeriFactu Privacy Policy
This privacy policy explains what data the EdiEZ VeriFactu mobile app ("the App") collects, why we process it, and with whom we share it. It is specific to the App; data processing for the EdiEz website is described in its Privacy Policy.
Data controller: EDIEZONLINE SL (EdiEz). Data Protection contact: info@ediez.online
What data we collect
The App collects only the data needed to provide the VeriFactu e-invoicing service:
- Email address: to identify you and send the access code you use to sign in.
- Name: to identify your account and personalise the App.
- Invoice photos: when you use "Scan invoice", the camera captures the document image to extract its data.
- Invoice financial data: amounts, taxes, recipient details and other information contained in the invoices you create or scan.
The App does not collect location or contacts data, and does not use tracking or advertising identifiers.
Purpose and legal basis
We process your data to:
- Provide the VeriFactu invoicing service: generate, register and submit your invoices to the Spanish Tax Agency (AEAT) under the VeriFactu regulations. The legal basis is performance of the service contract and compliance with tax-law obligations.
- Manage your account: authentication via a code sent to your email address and access administration.
Who we share data with
- Spanish Tax Agency (AEAT): invoices are submitted to AEAT on your behalf, as the core purpose of the service and in compliance with tax law.
- Infrastructure providers (cloud hosting) that process data on EdiEz's behalf under a data-processing agreement.
We do not share your data with third parties for advertising or tracking. The App contains no ads.
Security
All data is transmitted encrypted (HTTPS/TLS). The session token is stored securely on the device using the operating system's secure storage.
How long we keep your data
We keep your account data while your account remains active. Invoices and tax records are kept for the period legally required by Spanish tax law (generally several years), after which they are deleted. Deleting your account does not immediately remove tax records subject to mandatory legal retention.
Your rights
You may exercise your rights of access, rectification, erasure, restriction, portability and objection by contacting info@ediez.online, proving your identity. You may also request deletion of your account following the instructions on the Delete account page.
If you wish, you may lodge a complaint with the Spanish Data Protection Agency (https://www.aepd.es).
