Security and data protection
You trust us with your myDATA credentials and your invoices. Here is how we protect them.
Your myDATA credentials
- Stored encrypted with AES-256-GCM and bound to your account: they cannot be used in another one.
- Never shown in logs or in the data export.
- Revoke them whenever you want by deleting the REST API user in the myDATA registration app.
Where the data lives
- The database is in the EU (Frankfurt) and the application also runs in Frankfurt.
- Every client is isolated at database level (row-level security): no account can see another account’s data.
- All connections are encrypted (HTTPS with HSTS).
Artificial intelligence
- The AI only receives the fields each line needs: supplier, invoice type, VAT and amounts.
- We use paid AI services that do not train their models on your data.
- The AI only proposes: only what you approve is sent to myDATA.
Control and traceability
- Every approval, correction and submission to myDATA is logged: who, what and when.
- Sign-in uses secure account management (Clerk).
Your rights (GDPR)
- Download all your data as a JSON file, yourself, from the “Account and data” page.
- Delete your account and all its data permanently, also yourself. The myDATA data stays with AADE.
Sub-processors
To run the service we use the providers below. For those outside the EEA, transfers rely on standard contractual clauses or the EU–US framework.
| Provider | Purpose | Location |
|---|---|---|
| Neon | Database | EU (Frankfurt) |
| Vercel | Application hosting | EU (Frankfurt) · US company |
| Clerk | Accounts and sign-in | US |
| Google (Gemini) / Anthropic (Claude) | AI classification proposals | US |
| Resend | Email delivery (weekly report) | EU (Ireland) |
Security questions or to report a problem: hola@taktiko.gr