Skip to content
Viesproof

Privacy policy

Effective 1 October 2026.

Viesproofis operated by Altix Code Ltd, a company registered in the Republic of Cyprus (“Altix”, “we”, “us”). This policy explains what personal data we collect when you use our website, dashboard and API (the “Service”), why, how long we keep it — including the VAT-check receipts the Service exists to produce — who we share it with, and the rights you have over it.

Two different roles are in play, and they matter: for data about you, your organisation (“org”) and its team, Altix is the data controller. For the VAT numbers, your own requester identity, and any trader details a check returns — the facts a VAT check is actually about — your org is the controller and Altix is a data processor acting only on your instructions. See “When we process data on your behalf” below.

1. Data we collect about you and your org

  • Account details — your email address, an optional name, and a bcrypt hash of your password. We never store or have access to your actual password.
  • Org and team data— your org’s name, slug, and VAT identity (your own country code and VAT number, when you supply one), plus every team member’s email, role (Owner, Admin or Member), and who invited whom and when, so an Owner or Admin can manage access.
  • Billing information — your subscription plan, status, and renewal date. Card and payment details are collected and held by Stripe, our payment processor; we only ever receive a customer and subscription identifier from them, never your card number.
  • API keys — stored only as a SHA-256 digest and a short, non-secret preview; the plaintext key is shown to you once, at creation, and never stored.
  • Security and membership audit log — a record of invites, role changes, member removals, API key creation/revocation, and org deletion requests, each tagged with the acting person’s email and the time it happened.
  • Support and account communications — anything you send us by email, and transactional email we send you (email verification, password resets, team invites).
  • Technical data — standard web server and request logs (IP address, user agent, timestamps), kept briefly for security and abuse prevention, and a bot-protection check (Cloudflare Turnstile) on our authentication forms.

2. When we process data on your behalf

Every time you or your API integration submits a VAT number to check, we process, on your instructions and for the sole purpose of performing that check and producing its receipt:

  • The VAT number and country code you are checking.
  • Your org’s own requester VAT identity, when configured in Settings — this is what makes a check requester-qualified and lets VIES issue a consultation number.
  • The trader name and address the member state returns, and any field-by-field match result, when you supplied details to confirm.
  • The consultation number, timestamp, and outcome (valid, invalid, or unavailable), which together with the above become one entry in your org’s hash-chained receipt.

This data is sent to the European Commission’s VIES REST API (ec.europa.eu/taxation_customs/vies), a free public service of the EU, to perform the consultation — that is the one unavoidable third-party disclosure a VAT check requires, and it happens for every check regardless of plan. We do not send this data to any other third party, and we do not use it for any purpose beyond performing your check, building your receipt chain, and (only while your org exists) letting you query and verify your own archive.

Where the VAT number or trader details you check identify an individual (for example a sole trader) rather than only a company, you remain responsible for having a lawful basis to check that counterparty’s details, the same way you are responsible for your own records more generally — we act only on your instruction.

3. Why we process it

  • To provide the Service: performing checks, building receipts, enforcing plan limits, and preventing abuse.
  • To bill you, via Stripe, for a paid subscription you chose.
  • To communicate with you about your account, including emails necessary to operate it (verification, password resets, team invites).
  • To maintain a security audit trail of who did what on your org, so Owners and Admins can review activity and we can investigate suspected compromise.
  • To comply with our own legal and accounting obligations, including tax law.

4. Who we share it with

We do not sell personal data. We share it only with the processors needed to run the Service:

  • The European Commission (VIES) — receives the VAT number and country code you check, and your own requester VAT identity when configured, as described above. This is a public EU service, not a commercial vendor, and we have no contractual relationship with it.
  • Stripe, Inc. — payment processing and subscription billing.
  • Our transactional email relay — delivery of account and invite email, over SMTP.
  • Cloudflare, Inc. — bot and abuse protection (Turnstile) on our authentication forms, and TLS/DNS for our domain.
  • Hetzner Online GmbH — our infrastructure host, where our servers and database physically run (EU-located).

Issued invoices are recorded in Altix Code Ltd’s own internal invoicing system, used across our products, so we can meet our accounting and tax obligations as a single company.

Some of these processors are located outside the European Economic Area. Where that is the case, we rely on the European Commission’s Standard Contractual Clauses, or an equivalent recognised safeguard, to cover the transfer.

5. How long we keep it, and why the receipt archive is different

Account, team and billing data is kept for as long as your org is active.

VAT-check receipts are not ordinary application data, and we want to be specific about what retention actually means for them. Each receipt exists to be your evidence — under Article 138 of Directive 2006/112/EC — that you performed a requester-qualified check before treating an intra-Community supply as zero-rated. The statutory period for which youmay need to retain that evidence is set by your own member state’s tax law, not by us, and commonly runs five to ten years or longer. We are not ourselves subject to that obligation — we hold the records because we generated them on your behalf, not because we are the regulated party relying on them.

  • Every plan advertises a retention window for receipts (30 days on Free, up to 10 years on Scale — see Pricing). That window is a floor, not a ceiling: as of this policy’s effective date we do not yet run an automated job that purges receipts once they age past it, so in practice receipts persist for as long as your org exists, regardless of plan, unless you delete them or your org yourself. We are telling you this plainly rather than letting the pricing page’s wording imply otherwise; if we do add automatic pruning at the advertised window in future, we will update this policy and notify account Owners first.
  • Deleting your org permanently deletes every receipt in its chain, with no recovery. We cannot restore a receipt once an org is deleted, and we do not keep a separate copy on your behalf — see “Deleting your org” below. If you may still need this evidence for your own tax authority, export your archive (via the Audit page or the /api/v1/audit endpoint) before deleting. As our own pricing page puts it: evidence you do not hold is evidence you can lose.
  • Security audit log entries (invites, role changes, removals, deletion requests) are retained even after the org they describe is deleted — the point of a security log is to survive the event it may need to explain.
  • Invoices already issued remain in our invoicing system independently of your org, for as long as Cyprus tax and accounting law requires us to keep financial records (currently up to seven years).
  • Server and request logs are kept briefly (typically a few weeks) and then deleted or anonymised.

6. Deleting your org

An org Owner can permanently delete the org from Settings at any time, by typing the org’s name to confirm. Doing so:

  • Cancels any active Stripe subscription immediately — you are not billed again, and lose access right away rather than at the end of the billing period.
  • Permanently deletes every VAT-check receipt in the org’s chain. See the warning in the previous section — this is irreversible, and nothing about it is paused for you to reconsider once confirmed.
  • Removes every team member’s access immediately.
  • Records that the deletion happened, in a log entry that is not deleted with the org (see above).
  • Does not affect invoices already issued, which remain in our invoicing system under our legal retention obligations, independently of the deleted org.

7. Cookies

Our dashboard uses a single strictly necessary cookie to keep you signed in. Cloudflare Turnstile, used on our authentication forms to tell a human from a bot, may set its own cookie for that purpose. We do not use advertising or cross-site tracking cookies.

8. Your rights

If you are in the European Economic Area, the UK, or another jurisdiction with similar protections, you have the right to access, correct, erase, restrict or object to processing of, and receive a portable copy of, the personal data we hold about you; to withdraw consent where processing relies on it; and to lodge a complaint with your local data protection authority — for Cyprus, the Office of the Commissioner for Personal Data Protection.

To exercise any of these rights, email privacy@altixcode.com. If your request concerns VAT-check data where your org is the controller rather than us (see Section 2), we will direct the request to the org, unless it has instructed us otherwise.

9. Security

Passwords are hashed with bcrypt and never stored in plain text. Invite, password-reset and email-verification links use single-use, cryptographically random tokens that are hashed at rest. API keys are stored only as a SHA-256 digest. Every VAT-check receipt is SHA-256 hash-chained to the one before it and HMAC-signed under a server-only key, so a party who can read or even write to the database cannot forge a valid chain without also holding that key. Traffic to the Service is encrypted in transit with TLS.

10. Children

The Service is intended for businesses and professionals and is not directed at, or knowingly used to collect data from, children under 16.

11. Changes to this policy

If we make a material change to this policy, we will notify org Owners by email and update the effective date above before the change takes effect.

12. Contact

Altix Code Ltd (Cyprus). For any question about this policy or your data, email privacy@altixcode.com.