Security and data protection

You trust us with your myDATA credentials and your invoices. Here is how we protect them.

Your myDATA credentials

  • Stored encrypted with AES-256-GCM and bound to your account: they cannot be used in another one.
  • Never shown in logs or in the data export.
  • Revoke them whenever you want by deleting the REST API user in the myDATA registration app.

Where the data lives

  • The database is in the EU (Frankfurt) and the application also runs in Frankfurt.
  • Every client is isolated at database level (row-level security): no account can see another account’s data.
  • All connections are encrypted (HTTPS with HSTS).

Artificial intelligence

  • The AI only receives the fields each line needs: supplier, invoice type, VAT and amounts.
  • We use paid AI services that do not train their models on your data.
  • The AI only proposes: only what you approve is sent to myDATA.

Control and traceability

  • Every approval, correction and submission to myDATA is logged: who, what and when.
  • Sign-in uses secure account management (Clerk).

Your rights (GDPR)

  • Download all your data as a JSON file, yourself, from the “Account and data” page.
  • Delete your account and all its data permanently, also yourself. The myDATA data stays with AADE.

Sub-processors

To run the service we use the providers below. For those outside the EEA, transfers rely on standard contractual clauses or the EU–US framework.

ProviderPurposeLocation
NeonDatabaseEU (Frankfurt)
VercelApplication hostingEU (Frankfurt) · US company
ClerkAccounts and sign-inUS
Google (Gemini) / Anthropic (Claude)AI classification proposalsUS
ResendEmail delivery (weekly report)EU (Ireland)

Security questions or to report a problem: hola@taktiko.gr