Comprovia
FeaturesComplianceBenefitsPricing
Log inStart for free
Back to home

Privacy Policy

Comprovia

This statement informs you about the nature, scope, and purpose of the processing of personal data when using Comprovia.

1. Controller

The controller of personal data, within the meaning of Law 172-13 on the Comprehensive Protection of Personal Data of the Dominican Republic, is:

Comprovia

DGII electronic invoicing software

Samaná

Dominican Republic

Email: info@xrechnungs.de

A data protection officer has not been appointed, as there is no express legal obligation to do so under applicable Dominican law.

2. General Information on Data Processing

We process personal data exclusively in accordance with Law 172-13 on the Comprehensive Protection of Personal Data and other applicable Dominican data protection regulations.

Processing is carried out for:

  • Provision of our electronic invoicing SaaS services
  • Performance of the service contract
  • Ensuring IT security
  • Improvement of our offering

3. Types of Data Processed

3.1 Registration and Account Data

  • Name
  • Email address
  • Password (stored as a hash)
  • Company data (e.g. company name, address, RNC tax ID)

Purpose: Account management and use of the application

Legal basis: performance of the service contract with the user

3.2 Invoice and Business Data

  • Names and addresses of customers, suppliers, and business partners
  • Email addresses and phone numbers
  • RNC and other tax identification numbers
  • Invoice and payment data (amounts, bank details, payment status)
  • Service descriptions and e-CF invoice numbers
  • Employee data (where indicated on invoices or documents)

Purpose: Creation, validation, signing, and submission of electronic tax receipts (e-CF) to the DGII

Legal basis:

  • Performance of the service contract with the user
  • Legitimate interest in providing the SaaS platform

3.3 Technical Usage Data

  • IP address
  • Date and time of access
  • Browser and device information
  • Login times and activity logs
  • Log files

Purpose: Operational security, error analysis, abuse detection

Legal basis: legitimate interest in the operational security of the platform

4. Hosting and Processors

For the technical provision of the service, we use the following processors, with whom data processing agreements are in place:

Service ProviderLocationPurposeLegal Basis
Hetzner Online GmbHGermany (EU)Server infrastructure hosting (VPS), backend and databaseData processing agreement
Hetzner Object StorageGermany (EU)Object storage for documents and attachmentsData processing agreement
Vercel Inc.USAWeb application hosting (frontend)Data processing agreement
Stripe PaymentsIreland (EU)Payment processing and subscriptionsData processing agreement
Resend Inc.USASending transactional emailsData processing agreement
OpenAI, Inc.USAAI-powered text recognition (OCR) when using the purchase-invoice conversion featureData processing agreement and contractual safeguards for international transfer

Data processing agreements are in place with all service providers. Where a provider processes data outside the Dominican Republic, the transfer is made only on the basis of appropriate contractual safeguards.

5. AI-Powered Text Recognition (OCR)

When using the OCR purchase-invoice conversion feature, uploaded invoice documents (PDF or image files) are transmitted to the API of OpenAI, Inc., USA for automated extraction of invoice data.

This may involve the transfer of personal data contained in the document (e.g. names, addresses, RNC tax ID, payment data).

OpenAI does not use API inputs to improve or train models. According to OpenAI's own statements, data is deleted after a maximum of 30 days.

The transfer is based on appropriate contractual safeguards for international data transfer.

Legal basis: performance of the service contract.

More information: openai.com/policies/privacy-policy

6. Electronic Receipt Validation

For the technical validation of electronic tax receipts (e-CF), we verify the XML document structure against the schemas (XSD) published by the DGII. Validation is performed server-side. The data contained in the receipts is technically verified before signing and submission.

Legal basis: performance of the service contract.

7. Payment Processing

For processing subscriptions and payments, we use Stripe Payments.

Payment data (e.g. name, billing address, payment information) is processed directly by Stripe. Comprovia does not store complete payment data.

Legal basis: performance of the service contract.

More information: stripe.com/en/privacy

8. Web Analytics – Google Analytics

If you have consented, we use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google Analytics uses cookies that enable analysis of how our website is used. We have activated IP anonymization, so your IP address is truncated before storage.

Legal basis: your consent.

Data transfer to Google servers abroad cannot be excluded. This transfer is based on appropriate contractual safeguards. You can revoke your consent at any time via the cookie settings.

More information: policies.google.com/privacy

9. Cookies

We use:

  • Technically necessary cookies (login, session, security)
  • Analytics or statistics cookies (only with consent)

Technically necessary cookies: legitimate interest in the secure operation of the platform

Analytics/statistics cookies: your consent

10. Storage Period and Data Deletion

Personal data is only stored for as long as necessary for contract performance or as required by statutory retention obligations applicable in the Dominican Republic (in particular under the Tax Code and DGII regulations on electronic tax receipts).

Invoice and account data remains stored as long as an active account exists.

Data deletion upon termination

Upon cancellation of the user account or termination of the usage agreement, we make your stored documents and data available for download for a period of 30 calendar days.

  • We will notify you by email at least 7 days before expiry of this period about the upcoming data deletion.
  • After the 30-day period, all stored data and documents will be irrevocably deleted. Recovery is technically not possible.
  • The deletion is logged internally.

Please note: Comprovia stores your documents for the duration of active account use. As a user, you are solely responsible for complying with your tax and commercial retention obligations towards the DGII and other Dominican authorities. We recommend regularly creating your own backup copies outside the platform.

Insofar as statutory retention obligations on our part prevent immediate deletion, the relevant data will be stored until the expiry of such obligation and then deleted without delay.

11. Data Processing Agreement (DPA)

In the context of using Comprovia, we process personal data on behalf of our customers. The corresponding Data Processing Agreement (DPA) is part of the usage agreement.

By registering and using the platform, you electronically agree to the DPA. The DPA (Comprovia – Data Processing Agreement (DPA)) is available after registration in the user area of the platform.

The DPA governs in particular the nature, scope, and purpose of processing, the sub-processors used, and the applicable technical and organizational measures (TOMs).

12. Your Rights under Law 172-13

You have the following rights (ARCO rights, recognized under Law 172-13 on the Comprehensive Protection of Personal Data):

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to update your data
  • Right to cancellation or erasure of your data
  • Right to object to processing
  • Right to withdraw consent given

To exercise your rights, please contact: info@xrechnungs.de

13. Right to Lodge a Complaint

You have the right to lodge a complaint with the competent personal data protection authority of the Dominican Republic, or to pursue the constitutional Habeas Data procedure before the competent Dominican courts.

14. Security

We implement appropriate technical and organizational measures, in particular:

  • TLS/HTTPS encryption of all data transmissions
  • Two-factor authentication (2FA) for system access
  • Role-based access control
  • Logical tenant separation of user data
  • Encrypted data backups
  • Monitoring and logging of security-relevant events
  • Regular security updates

The complete description of our technical and organizational measures (TOMs) is available in the annex of the DPA.

Despite all technical and organizational measures, absolute protection of data against access by third parties cannot be fully guaranteed.

15. Automated Decision-Making

No automated decision-making, including profiling, that produces legal effects on the user without human intervention takes place.

16. Changes to this Privacy Policy

This privacy policy may be updated as needed. The current version is always available on this page. We will notify you by email of any significant changes.

Last updated: August 2026 | Version 2.0 | Comprovia – Samaná, Dominican Republic