Privacy, terms & data processing
Three documents, written to be read rather than skipped. If anything here is unclear, ask us before you agree to it — that is what the address at the bottom is for.
Last updated: 24 August 2026
Privacy policy
What we collect about you, the person who subscribes to Billoo, and what we do with it.
Who we are
Billoo is operated by Nedermann Financial Services SRL, a company registered in Romania. Contact for anything on this page, including data protection questions: contact@billoo.eu.
Two different roles — this matters
For your account — your e-mail, your company details, your subscription — we decide what is collected and why, so we are the controller and this policy applies.
For the data you put into Billoo about your own customers — their names, addresses, e-mails on the invoices you write — you are the controller and we only act on your instructions, as your processor. What we may and may not do with it is set out in the Data processing agreement below, not here.
What we collect and why
| What | Why | Legal basis | Kept for |
|---|---|---|---|
| E-mail address, password (stored only as a one-way hash) | To create your account and let you sign in | Performance of our contract with you | Until you delete your account |
| Company name, address, registration and VAT number, logo, bank details | These are printed on the invoices you issue | Performance of our contract with you | Until you delete your account |
| Subscription and payment records | To take payment and to meet our own accounting obligations | Contract, and legal obligation for the accounting records | As required by Romanian accounting law |
| Failed sign-in attempts (IP address, e-mail tried, time) | To stop someone guessing passwords against your account | Our legitimate interest in keeping accounts secure | 24 hours |
| Administrator activity log (which account was opened, by whom, when) | So that support access to your account is never invisible to us or to you | Our legitimate interest in accountability | 12 months |
A session cookie (billoo_sid) |
To keep you signed in between pages | Strictly necessary for a service you asked for | Until you sign out, max 30 days |
What we do not do
- We do not sell or rent your data, or your customers' data, to anyone.
- We do not use it to advertise to you or to profile you.
- We run no advertising trackers and no analytics that follow you across other websites.
- We do not read your invoices except when you ask us for support, and every such access is written to the activity log described above.
Who else can see it
Only the companies we need in order to run the service, and only for that purpose:
- Our hosting provider, which stores the database and the application files. Servers are located in the European Union.
- Our payment provider, which processes your subscription payment. We never see or store your full card number.
Each of them is bound by a written contract to use the data only for us. If we ever add or change one, we will tell you before it happens, so that you can object or leave.
Where your data is stored
Inside the European Union. If that ever has to change, we will tell you in advance and put a lawful transfer mechanism in place first.
Your rights
Under the GDPR you can ask us to:
- Show you what we hold (access) — you do not have to ask: Settings → Your data → Download my data gives you the lot immediately.
- Correct it if it is wrong — most of it you can edit yourself in the app.
- Delete it — Settings → Your data → Delete account removes the account and everything in it straight away. We do not keep a shadow copy.
- Give it to you in a portable form — the same download, in a standard file that other software can read.
- Restrict or object to a particular use, where the law gives you that right.
Write to contact@billoo.eu for anything the app cannot do for you. We answer within 30 days. If you think we have handled your data badly, you may complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority where you live.
If something goes wrong
If personal data is exposed and there is a real risk to the people involved, we notify the supervisory authority within 72 hours of becoming aware of it, and we tell you directly when the risk to you or to your customers is high. We will describe what happened plainly, including what we do not yet know.
Data processing agreement
Required by Article 28 GDPR. It governs the data you put into Billoo about your own customers. It takes effect when you create an account and applies for as long as you have one.
In one paragraph
Your customers' data stays yours. We hold it for you, use it only to run the invoicing service you are paying for, keep it inside the EU, protect it, tell you quickly if anything goes wrong, and give it back or destroy it when you leave. We never use it for our own purposes.
1. Roles
You are the controller of the personal data you enter about your customers. We are your processor. You decide what to collect and why; we act only on your instructions.
2. Subject matter and duration
We process that data only to provide Billoo — storing your records, producing invoices, generating PDFs and sending the documents you ask us to send — for as long as your account exists.
3. What is processed, and about whom
Categories of people: your customers, and any contact person you record for them.
Categories of data: name, company name, contact name, e-mail address, telephone number, postal address, registration and VAT number, plus whatever you choose to type into the free-text notes on a customer or an invoice.
Please do not put special-category data in the notes
The notes field accepts any text, which means it will also accept things like health information. Data of that kind carries much stricter obligations under Article 9 GDPR, and Billoo is not built for it. Keep the notes to what is needed for invoicing.
4. Our obligations
- We process the data only on your documented instructions. Using Billoo is your instruction; anything beyond it, we ask you first.
- Everyone with access is bound to confidentiality.
- We keep the security measures listed in section 7 and keep them up to date.
- We help you answer your customers when they ask for access, correction or deletion — you can do most of it yourself in the app.
- We tell you without undue delay if their data is ever exposed, so that you can meet your own 72-hour deadline.
- On request we show you how we comply and accept an audit, reasonably scheduled.
- If we believe an instruction of yours breaks data protection law, we tell you instead of quietly carrying it out.
5. Sub-processors
You give us general permission to use sub-processors. Today they are:
| Who | What for | Where |
|---|---|---|
| Our hosting provider | Servers, database and backups | European Union |
| Our payment provider | Collecting your subscription fee | European Union |
Each is bound by the same obligations as we have towards you, and we remain fully responsible to you for what they do. We will give you notice before adding or replacing one, and you may object; if we cannot resolve the objection, you may terminate and get a refund of any period you have paid for and not used.
6. Transfers outside the EU
There are none. If that changes, we will notify you in advance and use a lawful transfer mechanism, such as the European Commission's standard contractual clauses.
7. Security measures
Article 32 requires measures appropriate to the risk. Concretely, today:
- All traffic is encrypted with HTTPS; plain HTTP is redirected and refused.
- Passwords are stored only as one-way hashes. Nobody at Billoo can read them, and we cannot tell you what your password is — only let you set a new one.
- Every account is isolated: each query is restricted to the signed-in account, so one customer cannot reach another's records even by manipulating the request.
- Repeated failed sign-ins are throttled, per account and per network address, to stop password guessing.
- Configuration files, backups and the database are not reachable over the web.
- Support access to a customer account is limited to named administrators, is never anonymous, and is recorded with who, which account and when.
- Backups are taken regularly and are restorable.
8. When you leave
Deleting your account deletes your data, including your customers' data, immediately and permanently. Take a copy first if you need one — Settings → Your data → Download my data. Residual copies may persist in encrypted backups for a short rotation period, after which they are overwritten; they are not used for anything in the meantime.
Your own obligations, briefly
This agreement covers our side. You still need a lawful basis for holding your customers' data, your own privacy notice telling them who you are and what you do with it, and you must answer them if they exercise their rights. Note also that invoices you have already issued generally must be kept for accounting purposes even if a customer asks to be deleted — the right to erasure yields to a legal obligation. In that case, delete the customer record and keep the invoice.
Terms of service
The agreement between you and Nedermann Financial Services SRL for the use of Billoo.
The service
Billoo is invoicing software. You use it to create, store and send invoices to your own customers. We provide the tool; the content of your invoices, and their correctness under the tax law that applies to you, are yours.
We are not your accountant
Billoo does not decide which VAT rate you owe, whether you may invoice without VAT, or how your invoices must be numbered where you trade. You enter those yourself, and checking them is your responsibility. If you are unsure, ask an accountant before you issue the invoice, not after.
Subscription, trial and payment
- Billoo costs €4.90 per month. Any applicable VAT is added.
- New accounts start with a 14-day free trial. No payment is taken during it.
- The subscription renews monthly until you cancel. Cancel at any time; you keep access until the end of the period you have already paid for.
- We do not refund part-months, except where section 5 of the DPA applies or where the law requires it.
Your account
Keep your password to yourself and use one you do not use anywhere else. You are responsible for what happens under your account. Tell us at once if you think someone else has got into it.
Acceptable use
Do not use Billoo to issue false or fraudulent invoices, to send unsolicited bulk mail, to break the law, or to attack the service or other customers. We may suspend an account that does, and will tell you why.
Availability
We work to keep Billoo available and take regular backups, but we do not promise uninterrupted service. Maintenance is announced in advance where we can.
Liability
Nothing here limits liability that cannot be limited by law, including for death, personal injury, or our own fraud or gross negligence. Beyond that, our total liability in any twelve-month period is limited to the amount you paid us in that period. We are not liable for lost profit or for tax penalties arising from what you chose to put on an invoice.
Ending it
You may delete your account at any time from Settings. We may end the agreement with 30 days' notice, or immediately for a serious breach of the acceptable-use section. Either way, export your data first — deletion is permanent.
Law
Romanian law applies, and the courts of Romania have jurisdiction. If you are a consumer, this does not take away the protection of the mandatory law of the country you live in.
Cookies
Short section, because there is little to say.
Billoo sets one cookie, billoo_sid. It keeps you signed in as you move
between pages. It carries no advertising identifier and follows you nowhere.
We also store your theme choice — dark or light — in your browser's local storage. It never leaves your device and is not a cookie.
That is the whole list. There are no analytics, advertising or third-party tracking cookies, which is why you are not being asked to accept anything: cookies strictly necessary for a service you asked for do not require consent.
Blocking the session cookie will stop you being able to sign in.
