Legal

Privacy Policy

Translation notice. This is an English translation of the German-language Datenschutzerklärung provided for information and accessibility purposes only. In the event of any discrepancy between this translation and the German original, the German version shall prevail. The applicable law is Austrian and EU law.
Controller

Niko Andersson · Schnirchgasse 11, 1030 Vienna, Austria · hello@bonvio.eu

No data protection officer required (Art. 37 GDPR).

Data Processed
  • Name and e-mail address
  • Receipt data
  • Payment references (card and bank details are not processed by Bonvio)
  • Usage data

No advertising profiles. No disclosure for advertising purposes. Bonvio is not designed for special categories of personal data within the meaning of Art. 9 GDPR.

Legal Bases

Art. 6(1)(b) GDPR — Performance of contract: provision of the service.

Art. 6(1)(c) GDPR — Compliance with statutory retention obligations where such obligations exist (§ 132 BAO: seven years).

Art. 6(1)(b) GDPR — the contractually promised archiving of up to ten years, to the extent it goes beyond the statutory retention period. Statutory responsibility for compliance with retention obligations rests with the user.

Art. 6(1)(f) GDPR — Legitimate interests: abuse detection, system security, and improving recognition accuracy.

Advertising, newsletters and profiling do not take place.

Retention Periods
  • Receipt data: by default up to 10 years, then automatic deletion. This exceeds the statutory retention periods (§ 132 BAO: seven years) and to that extent rests on our contractual undertaking, not on a legal obligation. Statutory responsibility for retention compliance rests with the user.
  • Incoming e-mails (technical): 90 days
  • Customer configuration: until termination, then 30 days
  • System logs: 30 days
Processors
  • EU cloud provider: Data storage and processing. Data processing agreement in place.
  • E-mail service provider (EU): Transactional communications. Processed within the EU/EEA — no third-country transfer.
  • Payment service provider (USA): Payment processing. Card and bank details not processed by Bonvio. Standard contractual clauses.
  • AI service provider (EU): automated text recognition of receipt photos. Processed exclusively within the EU — no third-country transfer. Data processing agreement in place.
  • Hosting and CDN provider: delivery of the bonvio.eu website. Processes the connection data technically necessary to serve the page, including the IP address. Legal basis: Art. 6(1)(f) GDPR (secure and functional provision of the website).

A list naming the processors we use is available on request at hello@bonvio.eu; it forms part of the data processing agreement under Art. 28 GDPR.

Automated Processing of Receipt Photos

To extract vendor, date, amount and VAT, the receipt photo is passed to an automated recognition system based on an AI model. This processing takes place exclusively on servers within the EU; no third-country transfer occurs. Receipt data is not used to train AI models.

No automated decision-making with legal effect takes place (Art. 22 GDPR). The extracted values are suggestions the user can correct at any time; the original receipt always prevails.

Improving recognition

When you correct a recognised value, Bonvio may use that correction together with the original automatic reading to improve recognition accuracy and fix errors. This processing is strictly internal and serves only the quality of the service. Your receipt data is not used to train third-party AI models, is not used for advertising, and is not shared with third parties.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the service). You may object to this processing at any time at hello@bonvio.eu (Art. 21 GDPR).

Your Rights

Access (Art. 15) · Rectification (Art. 16) · Erasure (Art. 17, subject to statutory retention obligations) · Restriction (Art. 18) · Data portability (Art. 20) · Objection (Art. 21)

Requests: hello@bonvio.eu

Security

Technical and organisational measures are in place. No system can guarantee absolute security. Access to Bonvio is tied to the security of the e-mail account used; users are responsible for protecting their own account.

Right to Lodge a Complaint

Austrian Data Protection Authority · Barichgasse 40–42, 1030 Vienna · dsb@dsb.gv.at · www.dsb.gv.at

Cookies & Tracking

bonvio.eu uses no cookies, no tracking and no analytics tools. No usage profiles are created and no data is collected or shared for advertising purposes.

When you visit the website, however, the hosting and CDN provider processes technically necessary connection data (including IP address, timestamp and page requested) in order to serve the page and secure its operation. Bonvio does not combine this data or use it to identify individual visitors.

As of: August 2026