Privacy Policy
Effective date: August 2026
1. Who We Are
Zero Loop Labs Ltd ("we", "us", "our") is the data controller for the personal data described in this policy, processed through getpeppr and the getpeppr.dev website — see "Our role" below for where we act as a processor instead. We are registered in England & Wales, Company No. 17035492, and registered with the UK Information Commissioner's Office (ICO), registration reference ZC202770.
Zero Loop Labs Ltd17 Heronsforde
London W13 8JE
United Kingdom
privacy@getpeppr.dev
Our role. For the data described in this policy — your account, billing, website, support, and newsletter data — we act as the data controller. For personal data contained in the invoices our customers send and receive through getpeppr (for example contact names of their counterparties), we act as a processor on the customer's behalf: the customer remains the controller of that data, and data-subject requests concerning invoice content should be addressed to the business that issued or received the invoice.
2. Data We Collect
2.1 Developer Accounts & API Usage
When you create an account and use the getpeppr API, we collect:
- Account credentials (name, email — managed via Clerk)
- API keys (stored as one-way SHA-256 hashes — we cannot recover plaintext keys)
- Invoice data you submit via the API (sender/receiver details, line items, amounts)
- E-invoices you receive through the Peppol network (sender name and identifier, invoice number, amounts, and the invoice document itself)
- Business contacts and payment details you store for invoicing (contact names, emails, phone numbers, postal addresses, and bank account details such as IBAN and BIC)
- Business-representative attestation data (name, email address, IP address) when an identifier attestation is requested
- API usage logs (timestamps, document IDs, response codes)
- Billing information (managed via Stripe — we do not store card numbers)
- Optional acquisition feedback — if you choose to answer “How did you hear about us?” during onboarding, we store your answer to understand which channels bring developers to getpeppr. It is free text, entirely optional, used only internally, and deleted with your account.
2.2 Live Chat
We use Crisp (Crisp IM SAS, France) to provide a live chat widget on our website and dashboard. Crisp may set cookies on your device to maintain chat sessions and remember conversation history. These cookies are functional and are not used for advertising or cross-site tracking.
2.3 Website Analytics & Monitoring
We use Vercel Web Analytics, a cookieless, privacy-friendly service that counts page views without advertising identifiers or cross-site tracking. We also use Sentry for error and performance monitoring on both the website and the console, including sampled, fully masked session replays (see section 5). We do not use Google Analytics or advertising trackers. Apart from the cookies set by Crisp for live chat functionality (see section 2.2), no tracking cookies are placed by the marketing website.
2.4 Peppol Identifier Verification (KYB / Trust Layer)
To comply with our obligations as an OpenPeppol-accredited Integrator (UK EDIRA scheme) and to prevent impersonation on the Peppol e-invoicing network, when you register a Peppol identifier that requires verification we verify it against the relevant public business registry:
- UK VAT numbers (scheme
GB:VAT) → HMRC (HM Revenue & Customs, “Check a UK VAT number” API). Not active yet: until HMRC grants us production access, UK identifiers are reviewed manually by our team and no data is sent to HMRC. We previously verified UK companies against Companies House using a company registration number; that check was withdrawn in August 2026 because the identifier it used is not routable on the Peppol network, and no data is sent to Companies House any more. - Belgian enterprise numbers (scheme
0208) → VIES (European Commission VAT Information Exchange System), with fallback to the KBO/BCE (Crossroads Bank for Enterprises, Belgium) - German VAT numbers (scheme
9930) → VIES (note: Germany withholds the registered name from VIES responses per member-state privacy policy; we verify only VAT validity) - French SIRENE/SIRET identifiers (schemes
0002/0009) → VIES and INSEE Sirene (for SIRET identifiers the INSEE check also runs when VIES matches, to verify the specific establishment) - French CTC identifiers (scheme
0225) → INSEE Sirene only - Swedish organisation numbers (scheme
0007) → Bolagsverket (Swedish Companies Registration Office; for sole traders the organisation number can be a personal identity number)
The verification compares your declared company name to the registry's name and returns a verdict (match / mismatch / not found). We retain the verification record — the identifier, your declared company name, the verification status and date — for the lifetime of your account: removing an identifier from your dashboard marks it as removed but keeps its verification record, and the record is removed from our production database 30 days after account deletion. The Know-Your-Business evidence we keep alongside it is a minimised audit record — provider, verdict, similarity score, partially masked identifier, and verification metadata; the raw registry name and address are not stored. That evidence is kept for 6 years from the verification date — a period we align with the six-year limit for bringing a claim on a simple contract under the Limitation Act 1980, so we can establish and defend claims about who we admitted to the network. It is then purged by a monthly job, so it may persist for up to a further month (see section 7).
2.5 Newsletter
Our newsletter (the EU e-Invoicing Mandate Tracker, which also carries getpeppr product announcements) has two subscription channels:
- Website signup — legal basis: consent (Article 6(1)(a) UK GDPR), with double opt-in: you must click a confirmation link before any newsletter content is sent to you. We record your email address and the date, IP address, and browser used at signup as evidence of consent.
- Console onboarding — when you set up your Peppol identity, a pre-ticked checkbox offers to add your account email to the newsletter under the “soft opt-in” rule for existing customers (PECR regulation 22(3)) and our legitimate interests (Article 6(1)(f) UK GDPR). Clear the checkbox before you submit and nothing is added — you can refuse before we ever send you anything, and every newsletter we do send carries an unsubscribe link. The checkbox is only shown to the holder of the account email address, so nobody can subscribe a colleague. No IP address or browser data is recorded for this channel. An earlier opt-out always prevails: if you have previously unsubscribed, we do not show the checkbox and do not re-subscribe you.
Processor: We use Resend (Resend.com Inc., USA) to deliver emails. Email delivery data is governed by Resend's privacy policy and a Data Processing Agreement we have in place.
Retention: We retain your data while you are subscribed. If you unsubscribe, we keep your email address, your subscription status, and the signup evidence we hold (for website signups: the date, IP address, and browser of your most recent signup). The suppression record ensures we never email you again, and the signup evidence documents that consent (Article 7(1) UK GDPR). Both are kept until you request full erasure via privacy@getpeppr.dev.
You can unsubscribe at any time using the link in any newsletter email, or by emailing privacy@getpeppr.dev.
2.6 Business Prospect Contacts
We contact businesses that publish invoicing or business-management software, to introduce getpeppr. Where the details we use identify a person — a named work email address, for example — they are personal data that we did not obtain from that person directly. This section is the information notice required by Article 14 UK GDPR in that situation. We provide it, or a link to it, no later than the earliest of these three moments: one month after we obtain the details, our first message to you, and the first time we pass the details to anyone else — the deadlines set by Article 14(3)(a) to (c).
What we hold. The company name and its registration or VAT number, the name of its software product, the business contact details it publishes (email address, telephone number, website), the functional claims it publishes about that product — for instance whether it declares that it can send or receive electronic invoices — our own assessment of whether getpeppr is relevant to it, and a record of any message we send and any reply we receive.
Where it comes from (Article 14(2)(f)). The company details and the contact details we start from come from publicly accessible sources only: official government registers — such as the list of compliant e-invoicing applications published on the Belgian federal e-invoicing portal operated by the FPS Policy and Support (BOSA) at efacture.belgium.be — the public Peppol participant directory operated by OpenPeppol, and the company's own public communications, chiefly its website. Three things in the record do not come from those sources: our relevance assessment, which we produce ourselves; the messages we send, which we also produce ourselves; and any replies, which come from you directly. We do not buy contact lists, we do not use contact-enrichment services, and we do not collect personal data from private or access-restricted sources.
Why, and on what basis. Business-to-business prospecting, on our legitimate interests (Article 6(1)(f) UK GDPR) in offering a service to companies whose published activity indicates it may be useful to them. We have weighed that interest against the rights of the people concerned: the details are professional rather than private, the business published them so that it could be contacted, each message concerns that business's own stated activity, and every message carries a plain way to stop it.
Who we may write to. Being allowed to hold these details is not the same as being allowed to email them: that is governed by electronic-marketing law, which differs by country, and we apply the rules of the recipient's own country. Two tests matter in practice. Under the UK Privacy and Electronic Communications Regulations, sole traders and some partnerships count as individual rather than corporate subscribers, and we do not send to them without consent. In Belgium, Article XII.13 of the Code of Economic Law requires prior consent as the rule, and exempts only impersonal addresses at legal persons — so for Belgian recipients we write to generic addresses such as info@ or sales@ only, never to a named individual's address, unless we have consent. Publishing an address is not by itself consent to receive marketing, and we do not treat it as such.
Where it is held, and who else sees it. Prospect records are kept in a private version-controlled repository, which is mirrored to two hosts: LeaseWeb in the Netherlands and GitHub in the United States. They are also held in our mailboxes at Fastmail. Because the repository is version-controlled, earlier versions of a record stay readable in its history after the record itself is changed. Deleting a record therefore removes it from the current version, and we purge it from the history as well when you ask us to erase your details — that purge rewrites the repository, so we carry it out as a deliberate operation on request rather than automatically. We say so plainly because a policy that promised instant erasure from a version-controlled store would be promising something the storage cannot do. The research and drafting we do on these records uses Anthropic (Claude) and OpenAI (Codex), and we use Firecrawl to read the public pages of a company's website; each of these therefore processes the details too. Prospect records are not loaded into the getpeppr platform, they are not mixed with customer account data, and they are not shared with anyone beyond the processors named in section 5.
How to stop it. Reply “stop” to any message, or email privacy@getpeppr.dev. We add the business to a suppression list and do not contact it again. You may also object to this processing, or ask for erasure or a copy of what we hold, at any time (section 8). We will not ask you to justify an objection to direct marketing: that right is unconditional under Article 21(2) UK GDPR.
3. Legal Basis for Processing
- Consent (Article 6(1)(a) GDPR) — for product announcements and marketing communications. You may withdraw consent at any time by using the unsubscribe link included in our emails, or by contacting us at privacy@getpeppr.dev.
- Contract (Article 6(1)(b) GDPR) — for account management, API access, invoice processing, and billing. This data is necessary to provide the service.
- Legitimate interests (Article 6(1)(f) GDPR) — for security monitoring, fraud prevention, improving service reliability, understanding how developers discover getpeppr (optional self-reported acquisition feedback), and sending service and product updates to existing customers under the PECR regulation 22(3) soft opt-in (every message includes a one-click unsubscribe link).
- Legitimate interests — business prospecting (Article 6(1)(f) GDPR) — for contacting businesses whose publicly declared activity indicates that getpeppr may be relevant to them, using contact details those businesses have themselves published (section 2.6). The right to object to this processing is unconditional, and every message states how to stop.
- Legal obligation (Article 6(1)(c) GDPR) — for retaining financial records as required by UK law.
- Multi-angle basis — Peppol identifier verification: We verify business registrations (section 2.4) under the combined authority of Article 6(1)(b) (contract necessity — our Terms of Service require a verified identifier before production sends) and Article 6(1)(f) (legitimate interest in preventing impersonation on the Peppol e-invoicing network). The Know-Your-Business duties that OpenPeppol accreditation places on Integrators are contractual rather than statutory, so we do not rely on Article 6(1)(c) here. You can therefore object to this processing and ask us to erase the record; we will do so unless we have compelling legitimate grounds to continue, or need it to establish or defend a legal claim.
4. How We Use Your Data
- To send product announcements and service updates (consent-based for website newsletter signups, PECR soft opt-in for existing customers — with one-click unsubscribe either way)
- To provide, operate, and improve the getpeppr API service
- To process invoices and transmit them to the Peppol network via our access point provider
- To manage billing and subscriptions via Stripe
- To detect and prevent abuse, fraud, and security incidents
- To comply with legal and regulatory obligations
5. Third-Party Processors and Data Sources
We share data with trusted processors under Data Processing Agreements:
- Clerk — identity and authentication management; sign-up is protected against automated abuse with Cloudflare Turnstile, which processes browser and device signals to distinguish humans from bots (US — transfer safeguards in section 6)
- Stripe — payment processing (US/EU — transfer safeguards in section 6; Stripe also acts as an independent controller for some of its own fraud-prevention and regulatory purposes)
- Storecove — Peppol network access point for sending and receiving invoices; we register your legal-entity details (name, address, Peppol identifiers) with them to route documents (Netherlands/EU)
- PandaDoc — electronic signature of contractual documents we sign with you (for example platform Order Forms): we share the signers' names and email addresses on both sides and the content of the document to be signed (PandaDoc, Inc., US — transfer safeguards in section 6)
- Crisp — live chat support widget (Crisp IM SAS, France)
- Neon — serverless Postgres database hosting (UK region, London)
- LeaseWeb — hosting of the private internal repository in which our prospect research is held (LeaseWeb Netherlands B.V., Netherlands/EU). It holds no customer account data
- Resend — transactional email delivery (US, Standard Contractual Clauses)
- Upstash — rate limiting and API response caching (EU region, Ireland)
- Vercel — website and API hosting, and Vercel Web Analytics (US, Standard Contractual Clauses)
- Sentry — error and performance monitoring for the console and the website (Functional Software, Inc., US). Event data is stored in Sentry's EU region (Germany). Error reports are linked to your user ID and to your organisation's ID and name. We record sampled Session Replay recordings in which all text, inputs, and media are masked in your browser before anything is transmitted, and we apply automated scrubbing of sensitive fields to events before they are sent
- Cloudflare R2 — storage of our daily encrypted database backups (Cloudflare, Inc., US; backups stored under EU jurisdiction with a 30-day retention)
- GitHub — CI infrastructure (GitHub, Inc., US, a Microsoft company) that runs our daily database backup job: the backup is encrypted before upload, and an integrity check restores it transiently inside the isolated job environment. GitHub also hosts a mirror of the private repository holding our prospect research (section 2.6)
- Anthropic and OpenAI — assistants we use to research and draft prospect records and outreach messages (section 2.6); the details in those records are processed by them for that purpose (Anthropic PBC and OpenAI, L.L.C., US). They receive no customer account data and no invoice content
- Firecrawl — retrieval of public web pages, used to find a company's published contact details (section 2.6); the page address is sent and the page content returned (Sideguide Technologies, Inc., US)
- Slack — internal operational alerts; for example, an account deletion notification includes the organisation name (Slack Technologies / Salesforce, US)
- Fastmail — hosting of our support and privacy mailboxes, i.e. any correspondence you send us (Fastmail Pty Ltd, Australia, with mail infrastructure in the US)
For Peppol identifier verification (section 2.4) and Peppol directory lookups we additionally query business registries and directories operated by independent data controllers. We transmit the identifier being verified (or, for directory searches, the name or identifier you search for); for sole traders these values can themselves be personal data:
- HMRC — HM Revenue & Customs, the UK tax authority, via its “Check a UK VAT number” API (public service, UK). Not active yet — see section 2.4
- European Commission VIES — EU VAT Information Exchange System (public service, EU)
- INSEE Sirene — French national business registry (public service, France)
- KBO/BCE (Crossroads Bank for Enterprises) — Belgian federal business registry (public service, Belgium)
- Bolagsverket — Swedish Companies Registration Office (public service, Sweden)
- Peppol Directory — the public Peppol participant directory (operated by OpenPeppol AISBL, Belgium); when you search the directory through getpeppr or we look up a participant, the searched company name or participant identifier is sent as the query
The prospect data described in section 2.6 is held in a private repository mirrored to LeaseWeb and GitHub, researched and drafted with Anthropic and OpenAI, enriched from public web pages via Firecrawl, delivered by Resend, and stored as correspondence in Fastmail — all listed above. We do not use contact-enrichment or list-broking services, and we do not buy contact data.
We do not sell your personal data to third parties.
6. International Transfers
Some processors are located outside the UK/EEA (for example Clerk, Stripe, PandaDoc, Resend, Vercel, Sentry, Cloudflare, GitHub, Slack, Fastmail, and — for prospect research under section 2.6 — Anthropic, OpenAI, and Firecrawl). Where data is transferred internationally, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (where this policy mentions Standard Contractual Clauses for a processor, they are implemented together with the UK Addendum), or the UK Extension to the EU-US Data Privacy Framework where the processor is certified. Where a processor offers UK or EU data residency, we use it: our database is hosted in London, Sentry event data is stored in Germany, and database backups are stored under EU jurisdiction.
7. Data Retention
- Account data: for the duration of your account, plus 30 days after account deletion to allow recovery; after which your data is removed from our production database. Some records survive account deletion: encrypted database backups for a further 30 days (below), newsletter suppression records (section 2.5), legacy waitlist entries (below), administrative audit logs (below), operational incident records (below), the billing records described below, and contractual documents you have signed with us electronically, which we retain as legal records
- Invoice data: invoices you send and e-invoices you receive through getpeppr are retained for the duration of your account — they are your business records. Our access point provider retains delivery data in accordance with its retention policy; financial records are kept for the billing-records period below
- API usage logs: retained for 90 days, then automatically purged in accordance with GDPR Article 5(1)(c) (data minimisation)
- API response cache: up to 24 hours for idempotency and performance (automatically purged)
- Rate limiting data: IP addresses are pseudonymised with a keyed hash (HMAC-SHA256) before being used as rate-limit counters; counters expire on short rolling windows (from 60 seconds up to one hour), and aggregate rate-limit analytics may retain the pseudonymised counter beyond the window. Raw IP addresses are not stored for rate limiting
- Encrypted database backups: a daily encrypted backup of our database is kept in immutable storage for 30 days, after which it becomes eligible for automatic deletion. Our storage provider carries the deletion out asynchronously, so a backup may persist for a few days past that point before it is physically removed; we monitor this and treat anything beyond 35 days as a fault
- Billing records: 7 years (UK accounting rules require six years; we keep one further year as a margin). These are the records of what we billed you for: one entry per chargeable document, holding whether it was sent or received, the environment, an opaque provider reference for the document, the moment it happened, the billing period it fell in, your plan at that moment and its position against your included quota. They are legal accounting records, so they survive account deletion. When your account is deleted we erase the payment-provider customer reference and any sub-account reference you supplied; what remains is the internal account identifier and the accounting figures, which is what makes the record usable as one. They never contain the contents of a document, nor the identity of the other party to it. While your account is live, a billing record may carry the internal reference of the legal entity that sent or received the document and, for platform customers, the reference you yourself chose for your own client — both are erased when your account is deleted
- Signed contracts (electronic signature): contractual documents signed electronically via PandaDoc (for example platform Order Forms) are legal records: we keep the signed document — including a sealed copy in our own database — for the duration of our commercial relationship and for 7 years after it ends, in line with UK limitation and accounting periods (legal obligation, Article 6(1)(c), and legitimate interests in evidencing and defending contractual claims, Article 6(1)(f)). Draft contracts that were never sent for signature are removed from PandaDoc when your account is deleted; completed signed documents survive account deletion as legal records
- Legacy waitlist: our closed pre-launch waitlist (email address, source, signup date) is an opt-in list retained for launch announcements; entries are erased on request
- Business prospect records (section 2.6): kept for up to 24 months from our most recent contact with the business, then deleted. If the business tells us to stop, we delete the rest of the record and keep only what is needed to honour that instruction — the business identity, its domain, and the date — on a suppression list, so that we do not contact it again. That suppression entry is kept for as long as we need it to honour the objection, and a general erasure request does not remove it: deleting it would allow us to source the same details again and contact you, which is the opposite of what you asked. It is never used for any other purpose
- Peppol identifier verification records (Trust Layer): the minimised Know-Your-Business evidence record (provider, verdict, similarity score, partially masked identifier, verification metadata — never the raw registry name or address) is kept for 6 years from the verification date — a period we align with the six-year Limitation Act 1980 limit for bringing a claim on a simple contract, so we can establish and defend claims about who we admitted to the network — then purged by a monthly job (so it may persist for up to a further month), or earlier if you delete your account. The verification record itself (identifier, declared company name, verification status and date) is retained for the lifetime of your account — including for identifiers you have removed — and is deleted with your account
- Attestation and audit records: business-representative attestation records (email address, IP address, user ID) are kept for the lifetime of your account and deleted with it; administrative audit logs are accountability records retained without a fixed expiry, until erasure is requested and no overriding legal ground applies
- Operational incident records: when something fails — a webhook we could not attribute, a scheduled job that errored — we keep a minimised record so we can investigate it. It is redacted at the moment it is written, never at display, and it holds no document content; it is purged after 90 days. Because such a record can concern an event with no account attached, and because it is what we would rely on to explain an incident, it is not tied to your account and survives its deletion until that 90-day window expires
8. Your Rights
Under UK GDPR, you have the right to:
- Access — request a copy of data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data ("right to be forgotten"), subject to legal retention obligations
- Portability — receive your data in a machine-readable format
- Restriction — ask us to limit how we process your data
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, without affecting lawfulness of prior processing
If we have contacted you as a business prospect (section 2.6), your right to object is unconditional: we stop on request, without asking for a reason, because the processing is direct marketing (Article 21(2) UK GDPR). You may also ask us to confirm where we obtained your details; section 2.6 sets out the sources we use.
To exercise any right, email privacy@getpeppr.dev. We will respond within 30 days.
Complaining to us. You have the right to complain directly to us if you believe we have infringed your data protection rights (section 164A of the Data Protection Act 2018, in force since 19 June 2026). Write to privacy@getpeppr.dev with “complaint” in the subject line, or by post to the address in section 1. We will acknowledge your complaint within 30 days of receiving it, look into it, and tell you the outcome. You do not have to complain to us first: you may go straight to the ICO.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority.
9. Security
We implement appropriate technical and organisational measures including TLS encryption in transit, SHA-256 hashing of API keys, rate limiting keyed on pseudonymised IP addresses, encrypted off-site backups, and access controls. No method of transmission over the internet is 100% secure.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email (to registered users) or a notice on this page. Continued use of the service after changes constitutes acceptance.
11. Contact
Questions about this policy? Email us at privacy@getpeppr.dev.