Legal
Privacy policy
Effective 1 October 2026.
Datevbridgeis operated by Altix Code Ltd, a company incorporated in and governed by the law of the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data we collect when you use our website and dashboard (the “Service”), what we process on your behalf when you connect your own Stripe account, why, how long we keep it, who we share it with, and the rights you have over it.
1. Data we collect about you
When you sign up and use the Service, we collect:
- Account details — your email address, an optional name, your org name, and a salted, irreversibly hashed copy of your password. We never store or have access to your actual password.
- Team and permission data — one person can belong to more than one org here (via `Membership`, not a single account-wide role), so for every org you join we store your email, your role in that org, who invited you, and when.
- Billing information — your subscription plan, status, and renewal date for our own subscription to you. Card details are collected and held by Stripe, our payment processor; we only ever receive a subscription and customer identifier from them, never your card number.
- Support and account communications — anything you send us by email, and transactional email we send you (password resets, email verification, team invitations).
- Security audit log— membership actions on your org (invitations, role changes, removals, and org-deletion requests), each tagged with the acting member’s email and the time it happened.
- Technical data — standard web server and request logs (IP address, user agent, timestamps) generated when you use the dashboard, kept briefly for security and abuse prevention.
2. When we process data on your behalf
Datevbridge reads balance transactions — charges, refunds, fees, disputes, payouts, their amounts, currency, timestamps, and free-text descriptions — from your own Stripe account, using a restricted, read-only API key you paste into Settings yourself. We encrypt that key at rest with AES-256-GCM and use it only to read balance transactions; a full secret key (sk_…) is rejected outright, because nothing here needs the ability to move money. For this data, you are the data controller and Altix is a data processor, acting only on your instructions — which are, concretely, to import the transactions you request and compile them into a DATEV export using the account mapping and VAT treatment you configure.
That data may itself contain personal data about your own customers — for example, a charge description or a Stripe customer email captured in the transaction payload we store (`StripeTransaction.payload`, kept verbatim so a booking can always be re-derived). You remain the controller of that data and responsible for your own lawful basis for processing it; we process it solely to produce your accounting export.
We do not have any connection, account, or data-sharing relationship with DATEV GmbH. This product has no DATEV API integration. It generates a DATEV EXTF Buchungsstapelfile — a standard accounting-interchange format — which you or your Steuerberater then import into your own DATEV software, entirely outside this Service. DATEV never receives anything from us; the file simply has to be in a shape DATEV’s own software can read.
3. Why we process it
- To provide, maintain, and secure the Service — operating your dashboard and API.
- To import your Stripe balance transactions and compile the DATEV export you request, per your configured account mapping.
- To bill you, via Stripe, for a paid subscription you chose.
- To communicate with you about your account, including emails necessary to operate it (verification, password resets, invites).
- To maintain a security audit trail of who did what on your org, so owners can review activity and we can investigate suspected compromise.
- To comply with our own legal and accounting obligations, including tax law.
4. Who we share it with
We do not sell personal data. We share it only with the processors needed to run the Service, each used solely to provide their service to us:
- Stripe, Inc.— our own subscription billing, and the channel through which we read balance-transaction data from the Stripe account you connect (we only ever call Stripe’s read endpoints with your restricted key; we do not send your transaction data to any other Stripe customer or third party).
- Resend (via its SMTP relay) — delivery of transactional email.
- Cloudflare, Inc. — bot and abuse protection (Turnstile) on our sign-up form.
- Hetzner Online GmbH, via our own Coolify deployment — our infrastructure host, where our servers and database physically run (EU-located, Germany).
Invoices we issue for your subscription to Datevbridgeare recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company.
Where any of these processors sit outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer. We may also disclose data where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Altix, our customers, or others.
5. How long we keep it
- Account, Stripe-transaction, ledger and export data is kept for as long as your org is active.
- If you delete your org, that data, every member’s access to it, and your stored Stripe key are removed immediately and permanently — see “Deleting your org”.
- Invoices we have already issued for your subscription remain in our invoicing system independently of your org, for as long as Cyprus tax and accounting law requires us to keep financial records (currently up to seven years).
- Security audit log entries are retained after an org is deleted, because the point of a security log is to survive the event it may need to explain; entries are kept for as long as needed for security, fraud-prevention, and legal purposes.
- Server and request logs are kept briefly (typically a few weeks) and then deleted or anonymised.
6. Deleting your org
An org owner can permanently delete the org from Settings at any time. Doing so:
- Cancels any active subscription immediately — you are not billed again.
- Permanently deletes every synced Stripe transaction, ledger booking, API key, and stored export for that org, and your encrypted Stripe key.
- Removes every team member’s access to the org immediately.
- Records that the deletion happened, in a log entry that is not deleted with the org (see above).
- Does not reach records outside this Service. A Buchungsstapel file you have already downloaded, or that your Steuerberater has already imported into DATEV, continues to exist independently of this product and remains subject to the German statutory bookkeeping-retention period that applies to it (GoBD / §147 AO, commonly up to ten years) — that obligation belongs to you as the business keeping the books, was never ours to discharge, and deleting your org here has no effect on it.
This action cannot be undone. The dashboard asks you to type your org’s exact name to confirm before it proceeds.
7. Cookies
Our website and dashboard use a single strictly necessary cookie (a signed session token) to keep you signed in. Our sign-up form may load Cloudflare Turnstile, which sets its own cookie solely to distinguish humans from bots. We do not use advertising or cross-site tracking cookies.
8. Your rights
If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to access, correct, and erase the personal data we hold about you (including by deleting your org yourself, as described above), to restrict or object to certain processing, to receive your data in a portable format, to withdraw any consent processing relies on, and to lodge a complaint with your local data protection authority — for Cyprus, the Office of the Commissioner for Personal Data Protection.
To exercise any of these rights, email privacy@altixcode.com. If your request concerns Stripe-transaction or ledger data where you are the controller rather than us (see §2), we will direct it to you as the org that connected the Stripe account, unless you have instructed us otherwise.
9. Security
Passwords are hashed with bcrypt and never stored in plain text. Password-reset, email- verification, and team-invite links are single-use, cryptographically random tokens hashed at rest. Your connected Stripe key is encrypted at rest with AES-256-GCM under a key held only in server configuration, never in the database. Traffic to the Service is encrypted in transit with TLS.
10. Children
The Service is intended for businesses and accounting professionals and is not directed at, or knowingly used to collect data from, children under 16.
11. Changes to this policy
If we make a material change to this policy, we will notify org owners by email and update the effective date above before the change takes effect.
12. Contact
Altix Code Ltd (Cyprus). For any question about this policy or your data, email privacy@altixcode.com.