Privacy Policy
Last updated: March 2026
1. Controller
The controller responsible for data processing is MATO Solutions GmbH, c/o Impact Hub Vienna, Lindengasse 56, 1070 Wien, Austria. Email: support@invoice-matcher.io
2. Data we collect
We collect and process the following data: account data (name, email address) provided during registration; invoice data (uploaded PDFs, images, and extracted text) for the purpose of invoice matching; bank transaction data (imported CSV/OFX files) for matching; usage data (log files, session data) for service operation and security; payment data processed exclusively by Stripe, we do not store credit card or bank details.
3. Purpose of processing
We process your data to provide our invoice matching service, including AI-based extraction and matching of invoices to bank transactions; to manage your account, organizations, and team members; to process payments via Stripe; to improve our service and fix technical issues; to comply with legal obligations.
4. Legal basis
We process your data based on: contract performance (Art. 6(1)(b) GDPR), to provide the service you signed up for; legitimate interest (Art. 6(1)(f) GDPR), for security, fraud prevention, and service improvement; legal obligation (Art. 6(1)(c) GDPR), to comply with tax and commercial law; consent (Art. 6(1)(a) GDPR), where explicitly given, e.g., for marketing communications.
5. Data storage and location
All data is stored on servers in Frankfurt, Germany (AWS, ISO 27001 certified). AI extraction is processed via EU-based services in France (Mistral AI). No data is transferred outside the EU.
6. Subprocessors
We use the following subprocessors: Amazon Web Services (S3) in Frankfurt, Germany, encrypted document storage; Mistral AI in Paris, France, AI extraction of invoice data; MongoDB Atlas in Frankfurt, Germany, application database; Stripe in the EU, payment processing.
7. Data retention
Documents and files are stored while your account is active. On account deletion, all files are permanently removed within 30 days. Account data (email, name, organization) is removed immediately upon deletion. Logs are deleted after 90 days. Payment data is managed exclusively by Stripe.
8. Your rights
Under the GDPR, you have the right to: access your data; rectify inaccurate data; delete your data; restrict processing; data portability; object to processing; withdraw consent at any time. To exercise these rights, contact us at support@invoice-matcher.io.
9. Cookies
We use only essential cookies required for the service to function (e.g., session cookies, language preference). We do not use tracking cookies or third-party advertising cookies.
10. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via email or in-app notification. The current version is always available on this page.
11. Contact
For privacy-related questions, contact us at support@invoice-matcher.io or by mail at MATO Solutions GmbH, c/o Impact Hub Vienna, Lindengasse 56, 1070 Wien, Austria.