Overview
FreeBillGen is a free hosted invoicing service at freebillgen.com. This policy explains what personal data we collect, why, who else sees it, how long we keep it, and the rights you have under EU law.
It is structured to provide the information described in Articles 13 and 14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and relevant Lithuanian data-protection law. The next section identifies the data controller; the rest of the page covers each topic in turn.
Who is the data controller
The service is operated by MB Libranet, a small partnership based in Vilnius, Lithuania. It is the controller under GDPR Article 4(7) for account, billing and service-operation data. When a customer enters another person's data in an invoice, that customer will usually determine the purpose and means of that processing; FreeBillGen processes the data to provide the service on the customer's instructions. For privacy enquiries, write to info@freebillgen.com. Full legal entity details, including registration and VAT codes, are on the company information page.
We have not appointed a Data Protection Officer because our processing does not meet the Article 37 thresholds. The person responsible for data protection is reachable at the email address above.
What data we process
We process the following limited categories of personal data, on the legal bases listed:
- Account data. Your name, email address, a one-way password hash created by the application's configured hashing driver or a passkey public key, and a Google account identifier if you choose Google sign-in. Lawful basis: Performance of contract - Art. 6(1)(b) GDPR.
- Invoice and client data you create. Only the data you choose to enter: client names, addresses, VAT numbers, line items, totals, payment status. Lawful basis: Performance of contract - Art. 6(1)(b) GDPR.
- Received invoices (Inbox). E-invoice files you manually upload to your Inbox. We parse selected UBL/CII syntax into readable fields and keep the original file for your records. Invoice-by-email intake is not currently available. Lawful basis: Performance of contract - Art. 6(1)(b) GDPR.
- No-account document tools. The guest generator uses the seller, client, line, tax and payment fields you submit to render a PDF without creating a saved invoice record. The public e-invoice validator writes the XML to temporary upload storage, reads it for the requested checks, attempts to delete the upload immediately after processing, deletes validation scratch files, and creates no document or report record. Lawful basis: Performance of the service you request - Art. 6(1)(b) GDPR; legitimate interests in securing the service - Art. 6(1)(f) GDPR.
- Feedback and bug reports. If you send feedback while signed in, we keep the message, report type, page URL, IP address, and the browser, operating system, viewport, locale and user-agent details selected by the feedback form. You can attach a private PNG, JPEG or WebP screenshot. The operator email and inbox notice receive the report reference and link, not a copy of the message or screenshot. Lawful basis: Legitimate interests in answering feedback and improving the service - Art. 6(1)(f) GDPR.
- Session and security cookies. A signed session cookie and a CSRF token cookie used to keep you signed in and reject forged browser-session requests. Lawful basis: Strictly necessary - Art. 6(1)(f), legitimate interests.
- Optional guest document draft. If you select the remember-draft control, only the guest form fields supported for draft saving are stored in this browser. They can include client and bank payment details. Saving them does not create a document in your FreeBillGen account or database. Lawful basis: Consent - Art. 6(1)(a) GDPR. You can withdraw it at any time by clearing the draft.
- Operations and security records. Application logs can contain an IP address, user-agent, request metadata and error context. Authentication events can include the account or email reference, IP address, user-agent, event type, time and limited context. Operator notices keep only the error, order, provider event or feedback reference needed to investigate the event. Lawful basis: Legitimate interests - Art. 6(1)(f) GDPR.
- Checkout, purchase and provider-event records. If you start or complete Pro checkout, we process the accepted offer and checkout intent, Paddle customer and transaction references, billing country, purchase status, adjustments, refunds, withdrawal records and purchase-confirmation delivery state. A verified Paddle webhook initially includes the encrypted exact payload, source IP address, user-agent and processing context so it can be authenticated, ordered, retried and reconciled safely. Lawful basis: Performance of contract - Art. 6(1)(b) GDPR; accounting and consumer-law obligations - Art. 6(1)(c) GDPR; legitimate interests in payment integrity and replay protection - Art. 6(1)(f) GDPR.
- Sanctions-warning acknowledgements. If you acknowledge a sanctioned-country warning, the service records the user, invoice or guest-draft reference, country, IP address, user-agent, notice version and time. This documents which warning was shown and acknowledged; it does not decide whether a transaction is lawful. Lawful basis: Legitimate interests in applying and documenting the service's sanctions warning - Art. 6(1)(f) GDPR.
- VIES audit log. When you ask to validate an EU buyer VAT ID, we store the request identifier, queried country and number, result, consultation number, and returned name or address. This supports the validation feature and preserves the evidence returned for your transaction. Lawful basis: Performance of our contract with the account holder - Art. 6(1)(b) GDPR; client data is processed on the account holder's instructions.
Some data belongs to invoice clients or suppliers rather than the account holder. You are the source because you enter or upload it. For that client or supplier data, you will usually be the controller and must have your own lawful basis and provide any required notice. We process it on your instructions to provide the invoicing service.
We never sell your data. We do not share it with advertisers, brokers, or analytics networks. We do not use personal data for advertising tracking, advertising profiles, or behavioural targeting.
Sub-processors
The service uses the providers below for specific functions. None is used as an advertising or behavioural-analytics network. Their role and the data sent depend on which function you use.
SMTP2GO (transactional email)
When you send an invoice by email or receive a system notification, the message is dispatched through SMTP2GO via its EU region (mail-eu.smtp2go.com). Data shared: sender, recipient address, subject, body, and any attached PDF. SMTP2GO Inc. is established in New Zealand with EU infrastructure; transfers are covered by Standard Contractual Clauses.
Cloudflare Turnstile (bot protection)
The /login and /register forms render a Cloudflare Turnstile challenge to block automated abuse. The widget loads from challenges.cloudflare.com and exchanges a short-lived token with Cloudflare's siteverify endpoint. Data shared: your IP address, user-agent, and a one-time challenge token. Turnstile does not set tracking cookies and is not used for advertising. Cloudflare, Inc. is US-based; transfers are covered by the EU-US Data Privacy Framework and Standard Contractual Clauses.
bunny.net (font CDN)
The site loads two web fonts from fonts.bunny.net, a privacy-friendly font CDN operated by BunnyWay d.o.o. (Slovenia, EU). Data shared: your IP address and user-agent for the duration of the font request. See their privacy statement.
European Commission VIES (VAT validation)
When you validate a buyer VAT ID, the country code and VAT number you entered are sent to the European Commission's VAT Information Exchange System (VIES) at ec.europa.eu. The recipient is an EU institution; processing is governed by Regulation (EU) 2018/1725.
Hosting and PDF rendering (in-house)
The application database and hosted files run on infrastructure inside the European Union. Invoice PDFs are rendered on the application server using mPDF; no external PDF-generation service receives the invoice.
Optional Google sign-in redirects you to Google OAuth and receives a stable account identifier, verified email address and name when you approve the sign-in. Paddle is the merchant of record for Pro checkout and processes billing, tax and payment details under its own privacy terms. Neither provider is used for site analytics or advertising. There are no Meta pixels, analytics SDKs or external error-reporting services.
Data retention
Account, invoice, client, company, uploaded Inbox file, outbound mail log and VIES request data remain while the account is active. Self-service deletion immediately blocks access and replaces the account name and email. The scheduled tenant purge deletes those records and the user row after 30 days. The payment and sanctions records described below use separate limits.
Feedback reports and private screenshots are kept for up to 365 days and are deleted sooner when the related tenant is purged. The matching feedback notice is deleted with the report. Other operator notifications are kept for up to 365 days.
Application-managed local log files rotate for no more than 30 days. Hosting and infrastructure services may keep their own access or security logs under their published retention criteria. Authentication event identifiers, including the user or email reference, IP address, user-agent and context, are removed after 30 days; only the event type and time remain. VIES request logs remain with the active account and are deleted by the tenant purge.
Cancelled or expired checkout intents that produced no order are deleted once both their expiry and latest activity are at least 30 days old. For processed or stale Paddle events, the exact payload, source IP address, user-agent, ordering key and error detail are removed after 30 days; the provider event ID, type, payload hash, status and timestamps are kept for up to 10 years. Raw evidence for an unresolved event remains until it is resolved and is covered by automated stale-case review. A purchase-confirmation recipient address is removed after 30 days when delivery is sent or failed, after 365 days when delivery remains uncertain, or on the next retention run when the order is no longer linked to an account. Completed order, adjustment, refund and withdrawal records remain while linked to an active account. Once that link is removed, the completed financial record set is deleted 10 years after its latest activity. A documented legal hold can delay that deletion; holds carry a review date and an audit trail.
Manually uploaded Inbox invoices follow the account rule above. If an inbound email receipt record exists, a processed replay-protection record is deleted after 30 days. For a pending or failed receipt, user and error identifiers are removed after 30 days while the source hash, state and retry counters remain until the receipt is resolved.
The IP address, user-agent and guest-draft reference on a sanctions acknowledgement are removed after 30 days. User and invoice links are removed during the tenant purge. The remaining country, notice version and acknowledgement time are kept for up to 10 years, then the acknowledgement is deleted.
The guest generator creates no server-side invoice record. The public validator creates no document or report record. It attempts to delete the temporary upload immediately after processing and deletes its validation scratch file during the check. If an upload is left behind after a failed deletion or interrupted request, local temporary-upload cleanup removes it after it is older than 24 hours. Request metadata can still appear in the application logs described above.
An opted-in guest draft expires from browser local storage seven days after its last saved update. You can remove it immediately with Clear saved draft or by deleting this site's data in your browser. FreeBillGen does not copy that browser draft into an account automatically.
Your rights under the GDPR
Under the GDPR you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). Where processing is based on consent, you may withdraw it at any time (Art. 7(3)).
You also have the right under Article 77 GDPR to lodge a complaint with a supervisory authority - typically the one in the EU/EEA country where you live, work, or where the alleged infringement took place. Because the operator is established in Lithuania, the lead authority is the State Data Protection Inspectorate (State Data Protection Inspectorate of Lithuania, VDAI).
For a step-by-step guide on how to exercise each right, including timelines and what to put in a request, see the dedicated GDPR rights page.
Automated decision-making
FreeBillGen does not use automated decision-making or profiling within the meaning of Article 22 GDPR. No decision that produces legal or similarly significant effects on you is made solely by automated means. We do not score, rank, or profile users for advertising, credit, fraud, or any other purpose.
Data security
Technical and organisational measures (Art. 32 GDPR):
- Passwords stored with the configured one-way hashing driver; passkeys (WebAuthn) supported.
- Optional time-based 2FA via any TOTP-compatible authenticator app.
- CSRF tokens protect state-changing browser-session forms and actions; stateless API writes use separate authentication or signature controls.
- Framework query builders and parameter bindings are used for application data access.
- HTTPS/TLS in transit; HTTP Strict Transport Security enabled.
- Content Security Policy and other hardening headers.
- Application-layer audit log for security-sensitive actions.
- Source-controlled retention limits govern scheduled deletion and de-identification. If a required limit is missing or invalid, the pruning job stops before changing records.
International transfers
The service database and hosted files are in the European Union. SMTP2GO, Cloudflare Turnstile, optional Google sign-in and Paddle checkout may involve processing or a transfer outside the EEA for their specific functions:
- Cloudflare Turnstile - transfers to the United States, covered by the EU-US Data Privacy Framework and the European Commission's Standard Contractual Clauses.
- SMTP2GO - the operating company is established in New Zealand (a country with a European Commission adequacy decision) and uses EU-region infrastructure for delivery. Where transfers occur, they are covered by Standard Contractual Clauses.
Google and Paddle describe their international-transfer safeguards in their own privacy notices. FreeBillGen does not send invoice data to either provider for analytics or advertising. If the provider list or transfer arrangements change, this policy will be updated.
Children
FreeBillGen is a business tool and is not directed to children under 16. We do not knowingly collect personal data from children.
Changes to this policy
Changes are published on this page with a new "last updated" date. The date at the top identifies the current version.
Contact
Privacy questions and rights requests: info@freebillgen.com. Postal address and full legal entity details are on the company information page.