Who is responsible
STRICS IT GmbH is responsible for personal data processed through STRICS Invoice. Privacy questions and requests can be sent to david@strics.at.
Data we process
- account identifiers, name, email address, authentication provider, and sign-in metadata supplied through Google or Sign in with Apple;
- business profile, contact details, addresses, tax identifiers, bank details, numbering, currency, language, and template settings;
- customer and contact names, email addresses, phone numbers, billing and shipping addresses, tax identifiers, payment terms, and notes;
- estimates, invoices, line items, free-form notes, logos, PDFs, payment records, document history, and security audit events;
- App Store or Stripe subscription product, customer, transaction, entitlement, billing-status, and expiry information needed to provide STRICS Invoice PRO;
- company-lookup searches, location hints, and public company suggestions when you explicitly use the AI customer-assist feature; and
- connector client identifiers, approved permissions, authorization and revocation timestamps, short-lived download links, and connector audit events when you connect ChatGPT, Codex, or another compatible client;
- limited SDK diagnostic, device, approximate-location, and usage metadata processed by Firebase and Google Sign-In to authenticate users, secure the service, and monitor SDK reliability.
Why we process it
We process data to create and protect your account, provide invoicing and document features, generate PDFs, synchronize STRICS Invoice PRO, prevent abuse, keep the service reliable, support you, and comply with legal obligations. The legal basis is generally performance of our agreement, legitimate interests in a secure and reliable service, your consent where requested, or compliance with law.
AI customer assist
When you explicitly request a company lookup, the business name and optional country or city hints are sent to OpenAI to search public sources. Requests use a pseudonymous safety identifier and are not used to train OpenAI models by default. OpenAI may retain API inputs and outputs for up to 30 days for abuse prevention unless stricter retention controls apply. STRICS Invoice caches the public suggestion for up to 30 days under a one-way hash of the search fields. Suggestions are shown for review and are not added to a customer until you choose to apply and save them.
ChatGPT and Codex connector
The connector is off until a workspace administrator enables it. When you connect a compatible client, STRICS Invoice shows the requested permissions and records only those you approve. The client can receive customer or document data only when it calls an allowed tool. Creating drafts, reading records, downloading issued PDFs, and issuing documents are separate permissions; issuing additionally requires a short-lived preview and explicit confirmation. Access and refresh tokens are stored only as one-way hashes, can be revoked in Settings, and stop working when the connector is disabled. Data returned to ChatGPT, Codex, or another client is then processed under that client provider's privacy terms and your agreement with that provider.
Processors and international transfers
We use Google Firebase for authentication, application data, private files, and backend processing; Vercel for the web frontend; Google and Apple for sign-in; Apple for App Store subscriptions; Stripe for web subscriptions when enabled; and OpenAI for company suggestions you request. These providers process data under their contractual and security commitments. Where data is transferred outside the EEA, appropriate safeguards are used where required.
Customer data
If you enter personal data about customers or contacts, your organization normally acts as controller for that data and STRICS Invoice processes it to provide the service. You are responsible for having a lawful basis, giving required notices, and responding to those individuals.
Retention and deletion
Workspace data is retained while your account is active. The in-app account-deletion action removes your Firebase authentication account, organization records, private files, and provider-specific billing mappings after required reauthentication. A minimal one-way-hashed deletion marker may remain to prevent deleted subscription data from being recreated. Service providers may retain limited security, transaction, or legal records under their own obligations. You remain responsible for retaining business records required by tax or commercial law before deleting your account.
Tracking, advertising, and local storage
STRICS Invoice does not display advertising and does not use your data to track you across other companies' apps or websites. The application uses technically necessary identifiers and local storage to keep you signed in, protect sessions, and remember language and interface settings. Google Sign-In and Firebase may process limited analytics and diagnostic metadata described above, but it is not used by STRICS Invoice for advertising.
Your rights
Depending on your situation, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent where processing depends on it and lodge a complaint with the Austrian Data Protection Authority or your local supervisory authority.
Security and updates
We use access controls, organization-scoped security rules, server-side validation, protected storage, and encrypted transport to reduce risk. No system is completely secure. We may update this policy as the product or law changes and will publish the new date here.