Skip to content

Legal

How Syllevo handles personal data

Syllevo collects invoices, and invoices are full of personal data: names, addresses, email addresses, amounts. This page says what we hold, why we hold it, where it lives, and how to get it corrected, exported, or deleted. If anything is unclear, write to us and a person will answer.

Draft dated August 30, 2026, not yet in force. See the note at the end.

Who we are

Syllevo is a product of Businice S.R.L., a Romanian company, CUI 47561697, registered office [REGISTERED ADDRESS TBC], trade registry number [TRADE REGISTRY NUMBER TBC].

For anything on this page, write to security@syllevo.com. [DPO STATUS TBC: state here whether a data protection officer has been appointed.]

Two roles, one important difference

GDPR separates the party that decides why data is processed, the controller, from the party that processes it on instructions, the processor. Syllevo is each of those for different data, and your rights point at a different door depending on which.

For your account, your billing relationship with us, and your visits to this website, Syllevo is the controller. We decide what is collected and we answer for it directly.

For the invoice documents in your organization and the data extracted from them, your organization is the controller and Syllevo is the processor. We store, read, and chase on your instructions, and those instructions are real operations in the product: export everything, delete everything, per organization and per client company.

An accounting firm is often itself a processor for its clients. In that case Syllevo acts as the firm's sub-processor, under the same instructions.

We offer a data processing agreement (DPA) to every organization, and acceptance is recorded with a timestamp and a version. Write to security@syllevo.com for the current text.

If your accountant uses Syllevo and you want your data corrected or deleted, start with your accountant: for that data they are the controller, and we act on their instruction. If that goes nowhere, write to us anyway and we will help.

What we hold, and why

  • Account data: your name, email address, and organization membership, from when you sign up. Sign-in itself is handled by WorkOS, our authentication provider. Basis: the contract with you.
  • Billing data: your organization's billing details and VAT ID, held by Stripe. Card numbers never reach our servers; checkout and payment methods live on Stripe's hosted pages. On our side we keep a reference to the Stripe customer and a mirror of the subscription state. Basis: the contract, and tax law.
  • Invoice documents and the data inside them: files arriving by email, upload, or e-Factura, and the structured fields read from them, such as supplier names, dates, and amounts. This is the data we process as processor, on your organization's instructions.
  • Email sent to your organization's ingestion address, including the sender's address and the attachments. Mail that cannot be matched to any organization is quarantined and destroyed automatically after 30 days.
  • Names and email addresses of the people your organization asks us to remind about missing invoices. Reminders go out in the organization's name; the organization is the controller for that data.
  • e-Factura data: with your organization's authorization, we fetch its invoices from ANAF, the Romanian tax authority. ANAF is a public authority, not a company working for us.
  • Technical data: an audit trail of actions in the product (who did what, when, and from which IP address) and operational logs. Kept for security and accountability, not for advertising. Basis: our legitimate interest in running a secure product.

Cookies, all three of them

There is no analytics script, no advertising pixel, and no third-party tracker on syllevo.com or in the app. This is the complete list of cookies:

  • Sign-in cookies in the app, which keep you signed in. Essential, and not readable by scripts.
  • A language cookie, set when you choose English or Romanian, so the site remembers your choice.
  • A referral cookie named syllevo_ref, set only if you arrive through someone's referral link. It holds that referral code and nothing else, expires after 60 days, and is read once if you sign up, to credit the person who introduced you. It identifies the referrer, not you. We only store it if you accept it in the cookie bar at the bottom of the page; if you decline, or never answer, the code is not stored at all.

Where your data lives

All personal and invoice data at rest lives in the European Union: the database, the document store, and the infrastructure in between.

Where a vendor offers an EU region, we use it. A vendor that cannot process data in the EU does not receive personal data.

Some of the companies below are based in the United States. Where personal data leaves the EU, the transfer must rest on a recognized legal mechanism, such as standard contractual clauses or an adequacy decision. [TRANSFER MECHANISM TBC: confirm per vendor before this page goes live.]

Who else touches your data

These companies process data so Syllevo can work. Adding one is a deliberate decision announced through the DPA process, never a silent change. The DPA carries the authoritative, current list.

  • WorkOS, for sign-in and authentication. A United States company. [DATA LOCATION AND TRANSFER MECHANISM TBC.]
  • Stripe, for payments, subscriptions, and VAT handling. Card data goes to Stripe directly and never reaches us. After you delete your organization, Stripe keeps the billing records tax law obliges it to keep, acting for those as an independent controller.
  • Cloudflare, for DNS, TLS, routing of ingestion email, and document storage (R2) set to EU jurisdiction.
  • Vercel, hosting this website and the web app, with server functions pinned to Frankfurt, in the EU.
  • Sentry, for error tracking, set to EU data residency, with personal data scrubbed from reports before they are sent.
  • [SUB-PROCESSOR TBC]: the EU data-center provider running our database and processing servers.
  • [SUB-PROCESSOR TBC]: the email delivery service that carries reminders and notifications. Not selected yet; EU processing is a requirement of the selection.
  • [SUB-PROCESSOR TBC]: the document extraction service that turns scanned invoices into structured data. EU endpoints are required, and provider-side retention and training on submitted data are disabled.

How long we keep things

  • Invoice documents and their data: as long as your organization is active. Romanian law requires businesses to retain financial documents for years, typically 5 to 10 depending on the document class, so each organization's retention defaults to the legal minimum for its jurisdiction and can be raised by the controller, never lowered below it.
  • Misdirected or rejected email: 30 days in quarantine, then destroyed automatically.
  • The audit trail: as long as the organization's data. IP addresses and related network fields on audit entries are removed automatically after 12 months.
  • Operational logs: kept briefly for debugging and security, and never containing invoice contents, credentials, or email bodies. [OPERATIONAL LOG RETENTION PERIOD TBC.]
  • When you delete your organization, we offer a full export first, then delete the database records and the stored documents on a stated schedule. Billing records stay with Stripe, as described above. Deletion is audited, and you can confirm it happened.

Your rights, and where to send them

Under GDPR you can ask for access to your data, a copy you can take elsewhere, correction, deletion, restriction of processing, and you can object to processing based on legitimate interest.

If Syllevo is the controller (your account, your billing, this website), send the request to security@syllevo.com and we will answer within a month. If the data sits in an organization's invoice archive, the organization is the controller: we pass the request on and support them in honoring it.

You can also complain to a data protection authority. In Romania that is ANSPDCP, the National Supervisory Authority for Personal Data Processing; elsewhere in the EU, the authority of the country you live in. [SUPERVISORY AUTHORITY CONTACT DETAILS TBC.]

How it is protected

Every connection is encrypted, data is encrypted at rest, stored credentials and connection tokens get an extra layer of application-level encryption, and access is denied by default. The security page covers this in detail, with statements specific enough to check.

Read the security page

When this page changes

We update this page when the facts change, and the draft date with it. A new sub-processor or a new purpose is a material change: organizations are notified through the DPA process before it takes effect.

Questions

Questions, requests, and complaints about personal data all go to the same address, read by a person: security@syllevo.com

A note on this draft

This page is a draft dated August 30, 2026, prepared for review by a lawyer. It describes Syllevo's systems as they are actually built, but it has not yet had legal review, it is not legal advice, and the bracketed placeholders mark details still to be confirmed. It should not be relied on until this note is gone.