As of: 18 September 2026
Belegbote: application at app.belegbote.de and belegbote.de
fino data services GmbH, Universitätsplatz 12, 34127 Kassel, Germany
Thank you for using Belegbote. In this Privacy Policy, we inform you about which personal data we process when you use the application at app.belegbote.de, for what purposes and on what basis this takes place, and what rights you have.
The processing of personal data, such as the name, address, email address or telephone number of a data subject, is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the applicable country-specific data protection regulations. With this Privacy Policy, we would like to inform you and the public about the nature, scope and purpose of the personal data we collect, use and process. Furthermore, this Privacy Policy informs data subjects of the rights to which they are entitled.
As the controller, fino data services GmbH has implemented numerous technical and organizational measures (TOMs) to ensure the most complete protection possible of the personal data processed through our services. Nevertheless, internet-based data transmissions can in principle have security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example by telephone.
Belegbote is a service of fino data services GmbH.
The controller within the meaning of the General Data Protection Regulation, other data protection laws applicable in the Member States of the European Union and other provisions of a data protection nature is:
fino data services GmbH
Universitätsplatz 12
34127 Kassel
Germany
Phone: +49 4550 996 9000
Fax: +49 4550 996 9001
Email: support@belegbote.de
Authorized representatives: Florian Christ, Björn Kahle
Any data subject may contact our data protection officer directly at any time with any questions or suggestions regarding data protection. The data protection officer of the controller is:
BullProtect, a brand of NetBull GmbH
Patrick Vaillant
https://bullprotect.de
You can reach our data protection officer by post at the address given above, marked "Data Protection Officer", or by email at privacy@finodata.com.
In providing Belegbote, we process personal data in two different roles. This distinction is essential for your rights:
For the data of your user account and your company account, for the verification of your business identity and for the analysis of usage, we are the controller within the meaning of Art. 4(7) GDPR. This Privacy Policy applies to these processing operations.
For the contents of the documents received and sent via your mailbox, we act as a processor for the business using Belegbote. The basis for this is the Data Processing Agreement that the business concludes upon registration. The respective business is the controller for this data; data subjects should contact that business in this respect.
The Peppol infrastructure (the Service Metadata Locator, the Peppol Directory, and the Service Metadata Publishers and Access Points of the respective counterparty) consists of independent bodies that act neither on our behalf nor under our responsibility.
Our services collect a range of general data and information each time they are accessed or used by a data subject or an automated system. This general data and information is stored in the server log files.
The following may be collected, for example:
the operating system used by the accessing system,
the date and time of access,
an Internet Protocol address (IP address),
the internet service provider of the accessing system,
any hash values or assignment data used to legitimize the access,
and other similar data and information used to avert danger in the event of attacks on our information technology systems.
We need this information to deliver and display the content of our services correctly, to ensure the long-term functionality of our information technology systems and the technology of our services, and to provide law enforcement authorities with the information necessary for prosecution in the event of a cyberattack. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the security and stability of the service.
Art. 6(1)(a) GDPR serves as our legal basis for processing operations for which we obtain consent for a specific processing purpose. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, the processing is based on Art. 6(1)(b) GDPR. The same applies to processing operations necessary for carrying out pre-contractual measures. If we are subject to a legal obligation that requires the processing of personal data, the processing is based on Art. 6(1)(c) GDPR. Processing operations not covered by any of the aforementioned legal bases may be based on Art. 6(1)(f) GDPR if the processing is necessary to safeguard a legitimate interest of ours or of a third party, provided that the interests, fundamental rights and freedoms of the data subject do not override them.
The legal basis relevant to each individual processing operation is stated for that processing operation in Section 7.
The application is operated by Amazon Web Services Inc. (410 Terry Avenue North, Seattle WA 98109, USA; https://aws.amazon.com/de/; information on data protection is available at https://aws.amazon.com/de) in the eu-central-1 region (Frankfurt am Main). To achieve security, stability and sufficient loading speed, we use the Cloudflare content delivery network (CDN) of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; website: https://www.cloudflare.com; privacy policy: https://www.cloudflare.com/privacypolicy/.
Personal data collected in the course of this hosting is also stored on the host's servers. This may include, in particular, IP addresses, contact requests, metadata and communication data, website accesses and other data generated via a website.
This is done for the purpose of performing the contract (Art. 6(1)(b) GDPR) and in our legitimate interest in the secure, fast and efficient provision of our online offering (Art. 6(1)(f) GDPR). We have concluded data processing agreements pursuant to Art. 28 GDPR with the providers used.
Registration is required to use Belegbote. Only persons who confirm that they represent a business can register; we store this confirmation with a timestamp. A company account and a personal user access are created.
Data processed: name, email address, password (hashed only), language, time zone, format and notification settings, two-factor authentication secrets (encrypted), passkeys.
Purpose and legal basis: provision of the account and performance of the user agreement, Art. 6(1)(b) GDPR.
Verification of the email address is required before use. Upon registration, we additionally log consent to the General Terms and Conditions and to the Data Processing Agreement, including document version, timestamp, IP address and user agent. This logging serves as proof of the conclusion of the contract; the legal basis is Art. 6(1)(f) GDPR.
Login is possible by password, by a login code sent to your email address (passwordless) or by passkey. In addition, you can activate two-factor authentication (TOTP). We store login codes only as a hash and with an expiry; recovery codes are stored hashed. Login attempts are rate-limited.
Purpose and legal basis: securing access, Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR in our legitimate interest in the security of accounts.
Before activation, we verify the identity of the business. For this purpose, we process the company name, address, country, a business identifier (VAT identification number, GLN, Leitweg-ID or, alternatively, IBAN), the name and telephone number of the legal representative, and the confirmation of authority to represent with a timestamp. In addition, a supporting document must be uploaded, such as an extract from the commercial register or a business registration certificate.
For verification, we compare the information with public register services. In particular, the European Commission's VAT Information Exchange System, GS1 Germany, GLEIF and national commercial registers are queried. We store the results of these checks.
Purpose and legal basis: verification of eligibility to use a service restricted to businesses and prevention of abusive registrations, Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
We carry out this verification under our own responsibility. It is not carried out on behalf of the business using Belegbote but is based on our own decision about purposes and means: we establish the identity of participants in order to prevent abusive registrations and to ensure that Belegbote is used only by businesses. In addition, we are obliged to carry out this verification under our agreement with the Peppol Authority.
Activation is always decided by one of our employees. They review the documents and the results of the register queries and decide independently whether the registration is legitimate. Your account can only be used once this decision has been made.
During registration, we also ask which software you use. This information serves market research purposes and is entirely voluntary.
We also carry out this processing under our own responsibility and not on behalf of the business using Belegbote (Section 3).
If you upload a supporting document, we pass it, together with the company name and address, to an AI model. Using publicly available sources, the model checks whether the specified business exists and provides an assessment. It is operated by Amazon Web Services in the eu-central-1 region (Frankfurt am Main). The provider undertakes not to use the data provided to train its models.
This assessment is not a decision. It facilitates and speeds up the review but does not replace it. Your registration is in all cases decided by one of our employees, regardless of whether the assessment is positive or negative. The employee has full access to the reasoning behind the assessment and independently checks, based on the documents, whether the registration is legitimate. Your account can only be used after this decision.
A negative assessment therefore does not lead to the rejection of your registration. It may also have purely technical causes, such as an illegible document or one uploaded upside down or rotated.
This processing does not involve any decision based solely on automated processing within the meaning of Art. 22(1) GDPR.
Purpose and legal basis: establishing the business identity before activation. The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR; our legitimate interest lies in preventing abusive registrations and restricting the service to businesses.
After successful verification, we set up a Peppol address for your business and enter it in the Service Metadata Locator. Only then does your business become reachable in the Peppol network. For this purpose, we operate our own certified Access Point and our own Service Metadata Publisher; no third-party Peppol service provider is involved.
Via your Peppol address, we receive electronic business documents and make them available to you for viewing in the browser and for download as an XML file, original file and rendered PDF. The documents are kept in the folders "Inbox", "Flagged", "Archive" and "Trash". The trash is emptied automatically after 30 days.
The documents may contain personal data, for example about contact persons at your business partners. For the contents of these documents, we act as a processor (Section 3); processing takes place on the basis of the Data Processing Agreement and in accordance with the instructions of the business.
The document files are stored at Amazon Web Services, and the associated metadata in our database. Downloads take place exclusively via short-lived signed links valid for 15 minutes.
Belegbote is not an audit-proof archive in accordance with the German principles of proper bookkeeping. Your statutory retention obligations remain your own.
We notify you of new documents by email, either individually per document, hourly or as a daily summary. The notifications contain only metadata of the document (sender, document number and amount), never the document itself.
Purpose and legal basis: performance of the user agreement, Art. 6(1)(b) GDPR.
For sending, we use a service provider that carries out processing on servers within the European Union (Section 12).
You can upload completed electronic invoices as an XML file or as a hybrid PDF. We validate the file and send it under your own verified Peppol address. Sending under a third-party sender name is technically rejected. Belegbote does not create invoices.
Purpose and legal basis: performance of the user agreement, Art. 6(1)(b) GDPR. Section 3 applies to the contents.
You can create business partners in an address book. The company, email address, city, identifiers and Peppol address are processed. We check the reachability of these business partners against the Peppol Directory. The address book is deleted together with the account.
If you want to send an invoice to a recipient who cannot be reached in the Peppol network, you can invite them by email. The trigger is always a specific delivery attempt. The invitation names you as the initiator, contains the metadata of the pending document and offers the recipient three options: to set up a free mailbox, to register an existing Peppol address, or to permanently decline invitations. The pending document is held until the recipient becomes reachable and is then delivered.
Fixed limits apply to invitations: invitations can only be sent from accounts with a verified Peppol identity, with a maximum of 20 per day and 100 per month per sender. Per recipient address, we send at most one invitation in seven days and three per quarter, as well as a single reminder after seven days. An invitation expires after 28 days. Each invitation contains an unsubscribe link.
Information for invited persons (Art. 14 GDPR)
If you have received an invitation from us without having registered with Belegbote, the following applies to you:
We did not collect your email address from you, but from the business named in the invitation that wanted to deliver an invoice to you. Your email address, the company name, the metadata of the pending document and status timestamps are processed.
After the invitation expires, we delete your email address in plain text; only a hash value remains to ensure compliance with the limits mentioned above. If you permanently decline invitations, we store your email address so that your objection remains effective (Section 7.11). The inviting business is only informed that delivery was not possible, not that you objected.
If a person permanently declines invitations, we store the hash value of their email address to prevent future invitations to this address. This storage takes place across the product and across accounts so that the objection remains effective.
You can authorize your own AI assistants via an interface to read your mailbox and send documents. In doing so, invoice data and time-limited download links valid for 15 minutes flow to the provider you have chosen.
The authorization is your decision. Before authorization, a consent dialog shows you the client and the account concerned; the connection can be revoked at any time in the settings. The provider of the application you have authorized is not our processor. You are responsible for selecting the provider and for the data protection arrangements of your relationship with it.
We record product events linked to accounts and users (such as login, receipt, sending, invitation and account deletion) and analyze them in order to understand the use of the service and to develop it further.
Purpose and legal basis: Art. 6(1)(f) GDPR; our legitimate interest lies in the further development and commercial management of the service.
If you contact our support with a request, we process your name, your email address and the content of your request in order to handle it. Requests are managed in a ticket system (Section 12). The legal basis is Art. 6(1)(b) GDPR insofar as the request concerns the performance of the contract, and otherwise Art. 6(1)(f) GDPR.
You can delete your account yourself at any time in the settings. In doing so, your Peppol address is removed from the Service Metadata Publisher and the Service Metadata Locator, pending invitations are cancelled, the company account is deactivated and personal accesses are deleted. Existing sessions become invalid.
What remains even after account deletion:
messages already transmitted via the Peppol network, including transport evidence and the transmitted documents, which we continue to retain as a Peppol service provider;
the records of your consent to the General Terms and Conditions and to the Data Processing Agreement, which remain as evidence.
So that you do not have to type addresses in full, we offer an autocompletion function. For this purpose, we transmit the company name you enter to the Places API of Google Ireland Limited, Gordon House, Barrow Street 4, Dublin, Ireland, and receive address suggestions in return.
If the business is a sole proprietorship whose company name contains the name of the owner, personal data is also transmitted. This cannot be avoided with this function because the company name is the search term.
Purpose and legal basis: facilitating input and improving the quality of address data. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in user-friendly input and correct address data.
To manage our customers and users and for email communication relating to Belegbote, we use a CRM system from ActiveCampaign, LLC, 150 N. Michigan Ave Suite 1230, Chicago, IL, USA. We transfer the master data of your company account and your user access to it, in particular company name, name and email address.
The purpose and legal basis of this management are the maintenance of the contractual relationship and the handling of your requests, Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
In addition, we would like to inform you by email about new features and changes to Belegbote. We send such informational emails only if you have given us your consent; the legal basis is Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future, via the unsubscribe link in every such email or in your account settings. Without your consent, you will only receive emails from us that are necessary for the operation of your mailbox, such as notifications about received documents.
The transfer to the United States is based on the European Commission's Standard Contractual Clauses, unless an adequacy decision applies.
We pass on or disclose personal data to the following recipients:
processors engaged by us, in particular for hosting, email sending, monitoring, security services and the management of support requests (Section 12);
the bodies of the Peppol infrastructure to which documents are delivered: the Service Metadata Publishers and Access Points of the respective counterparty. These act under their own responsibility;
register services that we query to verify business identity (Section 7.3);
OpenPeppol in the context of statistical Peppol reporting. This reporting is aggregated and does not relate to individuals;
providers of applications that you have authorized yourself via the interface (Section 7.12).
Where links are provided to websites of other providers, this Privacy Policy does not apply to their content.
If we transfer personal data to service providers outside the European Economic Area, the transfer only takes place if the European Commission has confirmed an adequate level of data protection for the third country or if other appropriate data protection safeguards are in place, in particular the European Commission's Standard Contractual Clauses. The service providers used and the respective basis are listed in the overview of sub-processors engaged.
We process and store personal data only for as long as necessary for the respective purpose or as long as statutory retention obligations exist. If the purpose ceases to apply or a retention obligation ends, we delete or block the data.
We determine how long data is stored in each individual case based on the following criteria:
how long the data is needed for the purpose for which we collected it, in particular for the operation of your mailbox;
how long it is needed to be able to demonstrate proper operation, the delivery of documents and the verification of your registration;
whether and for how long statutory or contractual retention obligations exist, including those arising from our position as a Peppol service provider;
how long claims can be asserted, exercised or defended.
Some periods are already fixed, and we tell you what they are: we delete the data of your personal access when it is deleted. We delete documents in the trash of the mailbox view after 30 days. We delete the plain-text address of an expired invitation after 28 days; only a hash value remains to ensure compliance with the invitation limits. We delete log data on access to the application at the end of the year following its creation.
We expressly draw your attention to three data sets because they persist beyond the deletion of your account: we continue to retain messages already transmitted via the Peppol network, including transport evidence and the transmitted documents, as a Peppol service provider. The records of your consent to the General Terms and Conditions and to the Data Processing Agreement remain as evidence. And if a person has permanently declined invitations, we store the hash value of their email address without time limit, because this is the only way their objection remains effective. Your company account is deactivated upon account deletion.
In the application, we use only functionally necessary cookies. They serve session management, protection against cross-site request forgery and the storage of your language setting. No analysis of your behavior takes place; we do not use advertising cookies. A consent banner is therefore not provided in the application.
The sub-processors currently engaged for Belegbote, their purposes and the basis for any transfers to third countries can be found in the overview of sub-processors pursuant to Art. 28(2) GDPR at https://legal.finodata.com/belegbote/de/subprocessors.html.
This Privacy Policy is based on the terminology used by the European legislator in adopting the General Data Protection Regulation (GDPR). Our Privacy Policy should be easy to read and understand for the public as well as for our customers and business partners. To ensure this, we would like to explain the terms used in advance. In this Privacy Policy, we use, among others, the following terms:
a) Personal data
"Personal data" means any information relating to an identified or identifiable natural person (hereinafter "data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
b) Data subject
"Data subject" means any identified or identifiable natural person whose personal data is processed by the controller.
c) Processing
"Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
d) Restriction of processing
"Restriction of processing" means the marking of stored personal data with the aim of limiting its processing in the future.
e) Profiling
"Profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
f) Pseudonymization
"Pseudonymization" means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.
g) Filing system
"Filing system" means any structured set of personal data which is accessible according to specific criteria, whether centralized, decentralized or dispersed on a functional or geographical basis.
h) Controller
"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
i) Processor
"Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
j) Recipient
"Recipient" means a natural or legal person, public authority, agency or another body to which the personal data is disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
k) Third party
"Third party" means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
l) Consent
"Consent" of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
m) Enterprise
"Enterprise" means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
n) Group of undertakings
"Group of undertakings" means a controlling undertaking and its controlled undertakings.
You have the following rights. To exercise them, a message to the contact details given in Section 1 or 2 is sufficient.
Right to confirmation and access under Art. 15 GDPR as to whether and which personal data concerning you we process, including a copy of this data;
Right to rectification of inaccurate data and completion of incomplete data under Art. 16 GDPR;
Right to erasure under Art. 17 GDPR, insofar as the processing is not necessary;
Right to restriction of processing under Art. 18 GDPR;
Right to data portability under Art. 20 GDPR, insofar as the processing is based on consent or a contract and is carried out by automated means;
Right to object under Art. 21 GDPR to processing based on Art. 6(1)(e) or (f) GDPR, on grounds relating to your particular situation;
Right not to be subject to a decision based solely on automated processing under Art. 22 GDPR; we do not make such decisions in the context of Belegbote (Section 7.4);
Right to withdraw consent given at any time with effect for the future.
If you believe that the processing of your personal data violates the GDPR, you have the option under Art. 77 GDPR to lodge a complaint with our data protection officer or with a data protection supervisory authority. The supervisory authority responsible for us is:
The Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit)
Postfach 3163, 65021 Wiesbaden, Germany
If your request concerns data for which we act as a processor (Section 3), i.e. the contents of the documents received and sent, we will forward your request to the responsible business without undue delay. We respond directly ourselves to inquiries about your user account, the verification of your business identity and the resulting verification results.
We will adapt this Privacy Policy if the service or the legal situation changes. The current version is linked on our website, in the login area, in the user menu and in the footer of every email.