1. Overview & Commitment
At VAT Tools (“we”, “us”, “our”), we design our identity and tax verification systems around data minimization and evidentiary integrity. This Privacy Policy explains how we collect, process, retain, and protect personal data in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and applicable data protection legislation.
2. Data Controller
For personal data collected when you register an account, navigate our website, configure developer keys, or communicate with our support team, the data controller is:
Contact: Data Protection & Privacy Lead
Email: privacy@vat.tools
Where you submit corporate identity queries or VAT numbers on behalf of your business via our API or workspace, VAT Tools acts as a data processor or independent verification gateway retrieving authoritative public registry records in accordance with your explicit instructions.
3. Categories of Data We Collect
We process only the data necessary to provide and secure our verification services:
- Account & Profile Information: Name, business email address, organization name, hashed authentication credentials, and billing details provided during sign-up.
- Verification Query Inputs: VAT identification numbers, EORI numbers, company registration numbers, and trade names submitted for registry check or format validation.
- Technical & Security Diagnostics: IP address, browser user-agent, API request timestamps, response codes, and rate-limiting metrics required to defend against automated abuse.
- Client-Side Utilities: Free client-side tools (such as our WYSIWYG invoice generator and VAT calculator) process input lines, company names, and invoice figures strictly within your local browser memory; no invoice drafts are transmitted to or stored on our servers.
4. Lawful Bases for Processing (GDPR Art. 6)
We process personal data under the following lawful bases:
- Performance of a Contract (Art. 6(1)(b) GDPR): To provision your user account, execute requested registry checks, provide API access, and manage subscriptions.
- Legitimate Interests (Art. 6(1)(f) GDPR): To safeguard platform infrastructure against fraud and brute-force queries, maintain service uptime, and authenticate API key permissions.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): To satisfy statutory bookkeeping, tax reporting, and accounting requirements for customer transactions.
5. Purposes of Processing
We use collected data solely to:
- Execute live verifications against official public registers (such as VIES and national gazettes).
- Produce source-linked evidentiary records with cryptographic time anchors for audit compliance.
- Issue API keys, monitor quota consumption, and enforce environment isolation (sandbox vs. live).
- Deliver critical platform updates, security notifications, and billing invoices.
We do not sell, rent, or monetize your query history or business data to third-party data brokers or advertisers.
6. Data Retention & Purging Policies
We retain personal data only for as long as necessary to fulfill the purposes outlined herein. Customers may configure automated retention policies in workspace settings (e.g. 30, 90, or 365 days) to automatically purge past check logs. Upon organization deletion or explicit erasure request, query records and developer keys are permanently wiped from operational databases within 30 days.
7. Subprocessors & Data Transfers
Our infrastructure and databases are hosted in European Union cloud facilities ensuring robust data residency and adherence to EU privacy benchmarks. Where subprocessors are engaged (e.g., cloud hosting, email delivery, transaction processing), they are bound by strict Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs).
8. Your Rights Under GDPR (Art. 15–22)
Under the GDPR, you have the right to:
- Right of Access (Art. 15): Request confirmation and a copy of personal data processed about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal records.
- Right to Erasure / “Be Forgotten” (Art. 17): Request deletion of your data where retention is no longer necessary.
- Right to Restriction (Art. 18): Request temporary restriction of processing in case of disputes.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV).
- Right to Object (Art. 21): Object to processing carried out under our legitimate interests.
To exercise any of these rights, email us at privacy@vat.tools. We respond to all verified requests within thirty (30) days without cost.
9. Security Measures (Art. 32 GDPR)
We maintain rigorous technical and organizational security controls to protect data against unauthorized disclosure, loss, or alteration. These include:
- Enforced TLS 1.3 encryption for all web and API traffic in transit.
- Encrypted database storage at rest using AES-256.
- Cryptographically hashed developer tokens and API credentials.
- Strict least-privilege role-based access control (RBAC) across all administrative tools.
11. Supervisory Authority
If you are located in the European Economic Area and believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with your local Data Protection Authority (DPA).
12. Data Protection Contact
For any questions, data subject access requests, or privacy concerns, please contact our privacy team:
Email: privacy@vat.tools
Subject: GDPR Data Request / Privacy Question