Legal
Privacy Policy
Last updated: 5 August 2026
We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR). This policy explains what we collect, why, and your rights.
Data Controller
The data controller for vatnode is:
- Company
- TMI Iurii Rogulia
- VAT ID
- FI29845875
- Address
- Vanhanpellonkatu 5, 53850 Lappeenranta, Finland
- Location
- Finland, European Union
- Privacy contact
- [email protected]
Introduction
vatnode ("we", "our", "us") is committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).
This Privacy Policy explains what personal data we collect, on what legal basis, how we use it, and your rights as a data subject. It applies to all users of vatnode.dev and the vatnode API.
Required data. Providing your email address is required to create an account and use the Service. Without it, we cannot provide access. Your name is optional.
We have assessed that appointment of a Data Protection Officer is not mandatory under Art. 37 GDPR for our current processing activities.
If you have concerns about how we handle your data, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) at tietosuoja.fi or with your local EU supervisory authority (Art. 13(2)(d) GDPR).
UK and Northern Ireland.This Privacy Policy is also written to satisfy the equivalent requirements of the UK GDPR and the UK Data Protection Act 2018 for data subjects in the United Kingdom (including Northern Ireland). UK data subjects have the same substantive rights described here and may lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
Information you are receiving (Arts. 13 & 14 GDPR). This Privacy Policy is the notice through which we satisfy our information obligations to data subjects under Art. 13 GDPR (data collected directly from you) and Art. 14 GDPR (data we receive from third parties such as VIES, national registries, or our payment processor Mollie). The identity of the controller, contact details, processing purposes, legal bases, recipients, retention periods, data sources, and your rights are all disclosed in the relevant sections below.
Information We Collect
3.1 Account Information
- Email address (required to use the Service)
- Name (optional)
- Password (stored as a bcrypt hash — never in plaintext)
- IP address at registration and at each login, stored in our security events log
3.2 Payment Information
Payment information is processed directly by Mollie, our payment processor. We never see or store your payment card details. We receive from Mollie only the payment and mandate identifiers we need to manage your subscription (Mollie customer, mandate, subscription and payment IDs) and the payment status. Invoices are not received from the processor — vatnode generates and stores your invoices itself from the billing details you provide.
3.3 API Usage Data
We log each API request to the VAT validation endpoint. Each log record includes:
- The VAT number queried — a business identifier that may constitute personal data where it identifies a sole trader (see §3.9)
- Timestamp of the request
- API key identifier used
- Response outcome (valid/invalid, source, response time)
3.4 Automatically Collected Data
- Browser type and version
- Operating system
- Referring website
- Pages viewed (aggregate analytics only)
3.5 Account Activity and Audit Logs
We maintain a comprehensive audit log of account and security-related events. For each recorded event we store the event type, timestamp, IP address of the actor, and relevant metadata (for example, which API key was created or deleted, which email address was changed). The following events are recorded:
- Login events — timestamp, IP address, user agent
- API key events — creation, deletion, and revocation of API keys
- Account change events — email address changes, password changes, plan changes, webhook configuration changes, and account deletion requests
The legal basis for this processing is our legitimate interests (Art. 6(1)(f) GDPR) in maintaining security, preventing fraud, and enabling customers to demonstrate compliance in their own audit trails. We have assessed that this interest outweighs the minimal privacy impact given the limited scope and duration of data collected.
3.6 Onboarding Survey Responses
When you first log in to the vatnode dashboard, you may be shown an optional one-time welcome survey. The survey asks about your role, team size, use case, current VAT validation approach, and what brought you to vatnode. All fields are entirely optional; you may skip the survey at any time.
If you choose to answer any questions, your responses — together with your account email address and display name — are sent by email to the vatnode founder via Resend (our transactional email provider). Survey responses are not stored in the vatnode database. The only database record created is a timestamp indicating that you have seen the modal, so it is not shown again.
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR). Our interest is in understanding who uses vatnode so we can prioritise product improvements. Participation is voluntary, the data is used only for internal product decisions, and you may skip without any effect on your access. To object or request deletion, contact [email protected].
3.7 Your EU VAT Number (Requester Setting)
Through the Account Settings page, you may optionally provide your own EU VAT registration number. This enables vatnode to submit your VAT number as the "requester" identifier in calls to the VIES system, which causes VIES to return a consultation number (a reference issued by the European Commission confirming the validation was performed). This feature is designed for businesses that need to demonstrate they performed a valid VIES check at a specific point in time for EU VAT zero-rating purposes.
When set, vatnode stores your country code and VAT number in your account profile. This data is used exclusively to populate the requester field in outbound VIES API calls made by your account.
Personal data consideration: If you are a sole trader (natural person), your EU VAT number may constitute personal data under Art. 4(1) GDPR. If you are a legal entity, your VAT number is business identifier data and generally does not constitute personal data.
Legal basis: Contract (Art. 6(1)(b) GDPR) — processing is necessary to provide the consultation number feature you have requested. You may clear your requester VAT at any time through Account Settings.
3.8 VIES Consultation Numbers
When your account has a requester VAT number configured (see §3.7) and you perform a VAT validation, VIES returns a requestIdentifier — a consultation number issued by the European Commission. This consultation number is stored alongside the validation record in your VAT check history.
The consultation number is a reference that proves a specific validation was performed by a specific requester at a specific time. It is retained as part of your validation audit log and is included in any data export you request. Consultation numbers are issued and controlled by the European Commission; vatnode stores them solely to make them available to you.
Legal basis: Contract (Art. 6(1)(b) GDPR) — retention is necessary to provide the audit-log feature of the Service.
3.9 Company Enrichment Data from National Registries
When validating a VAT number, vatnode may retrieve additional company information from national business registries of EU member states. This enrichment data may include: legal form, industry description, national registry code, and company registration date. This data originates from official national registries and is returned to you in the API response.
Important — controller / processor roles. Where the validated VAT number belongs to a sole trader or individual entrepreneur (a natural person), the enrichment data — including their business name, address, legal form, and registration details — may constitute personal data within the meaning of Art. 4(1) GDPR.
- You (the API customer) are the data controller — you determine the purposes and means of processing this personal data within your application.
- vatnode acts as your data processor — we retrieve and transmit this data on your behalf in accordance with your API request.
As the data controller, you are responsible for ensuring you have a valid legal basis under Art. 6 GDPR for retrieving and processing this enrichment data, and for complying with all applicable data protection obligations in relation to your end users.
The Data Processing Agreement (DPA) governs vatnode's role as your data processor. By using the vatnode API, you agree to the terms of the DPA.
3.10 Public VAT-Verification Pages (/check/)
vatnode publishes a public verification page for individual EU VAT numbers at vatnode.dev/check/. Each page shows whether the number is currently active in the EU VIES system and, where VIES and official national registers make it available, the registered company name, address, country, registration date and the applicable VAT rates. This data comes from the European Commission's VIES service and national business registers — not from you — and mirrors what those official sources already publish for a public query. We do not add contact details, financial data or any information beyond the public register record, and the VIES consultation number is never shown on these public pages.
Sole traders and individuals.In several member states a VAT number is registered to a natural person trading under their own name. Those records are served like any other, with the same details — but they are kept out of search engines: an automated check reads the legal form in the registered name, and a page that identifies an individual is marked “noindex”, left out of our sitemaps and left out of the aggregate country listings and statistics pages. It stays reachable by direct link, and every such page carries a removal link.
Registers that hide a record.Some national registers let a registrant restrict the publication of their details — for example the French “non-diffusible” status, Dutch afscherming and Danish adressebeskyttelse. Where a register tells us a record is restricted, the name and address are masked on the public page and no map is shown.
Legal basis.For the small number of records that may relate to an identifiable person, we rely on our legitimate interests (Art. 6(1)(f) GDPR) in operating a VAT-verification tool that lets businesses confirm a counterparty's registration, balanced against the rights of the people concerned. Because this data reaches us from public registers rather than from you, this notice is how we meet our transparency duty under Art. 14 GDPR; providing individual notice to every registrant would involve disproportionate effort (Art. 14(5)(b)), so we publish this information here instead.
Your choices. You can object to publication and ask us to remove a page at any time — use the removal link on the page itself, or email [email protected]. We respond within 14 days. On request we mask the name and address on the page, or take the page down altogether, and exclude the number from future sitemaps. Where the data identifies you as an individual, you do not need to give us a reason. You also keep all the data-subject rights described in this Policy.
Legal Basis for Processing (GDPR Art. 6)
| Processing Activity | Legal Basis |
|---|---|
| Account creation and authentication (email, OAuth provider IDs, passkey credentials)Necessary to provision and secure your account and to authenticate you on each session. | Contract (Art. 6(1)(b)) |
| Payment processing and billing (Mollie payment and mandate identifiers; invoice records issued and stored by vatnode)Contract for executing the subscription; legal obligation for tax and accounting retention under Finnish law. | Contract + Legal obligation (Art. 6(1)(b), (c)) |
| VAT check logs (queried VAT ID, country code, validation result, timestamp)Contract for delivering the validation result; legitimate interests in service operation, fraud detection, and providing an operator-side audit trail. Balancing test performed; minimal personal data involved. | Contract + Legitimate interests (Art. 6(1)(b), (f)) |
| Public VAT-verification pages (/check/) — publishing VIES-active status with registered company name, address, country and registration date; records naming a natural person are served but marked noindex and excluded from sitemaps, country listings and statistics pagesOur interest in operating a public VAT-verification tool and reaching customers via search, using data that public registers already publish. Balancing performed: consultation number withheld, no contact or financial data added, nothing beyond the public register record, pages naming individuals kept out of search indexes and aggregate listings, name and address masked where the source register marks the record as restricted, a removal link on every such page, and any page removed on request to [email protected] within 14 days. Transparency is met under Art. 14(5)(b) (disproportionate effort) with this Policy as the public notice. | Legitimate interests (Art. 6(1)(f)) |
| API key usage tracking (last_used_at)Our interest in detecting abuse, compromised keys, and providing usage telemetry to the customer. Limited retention and scope; outweighs minimal user impact. | Legitimate interests (Art. 6(1)(f)) |
| Fraud prevention and rate limitingOur interest in preventing abuse does not override your rights given the minimal data involved. | Legitimate interests (Art. 6(1)(f)) |
| Transactional emails (welcome, billing receipts, security alerts, password resets)Necessary to operate the account you have asked us to provide. | Contract (Art. 6(1)(b)) |
| Lifecycle / onboarding emails (a limited sequence of product-guidance and upgrade-suggestion messages sent to free-plan users during their first weeks)Sent only to non-paying users, based on simple product-usage milestones. Every message includes one-click unsubscribe and you can opt out at any time; opting out stops the sequence immediately. We do not send general newsletters and never share your address for third-party marketing. | Legitimate interests (Art. 6(1)(f)) |
| Accounting and tax record retentionFinnish Accounting Act (Kirjanpitolaki 1336/1997, ch. 2 §10) sets a 6-year minimum for voucher records (invoices) from the end of the financial year; thereafter invoices are kept as immutable accounting records. | Legal obligation (Art. 6(1)(c)) |
| Website analytics — self-hosted Umami, client-side (cookieless pageviews, no cross-site identifiers)Aggregate-only pageview measurement, runs on our own EU infrastructure, no cookies set in the default configuration; balancing test concludes minimal impact. | Legitimate interests (Art. 6(1)(f)) |
| Internal product & revenue analytics — self-hosted Umami, server-side (validation and purchase events keyed to your account ID)A small set of backend events (e.g. a completed VAT validation, a confirmed subscription payment) is recorded against your account ID so we can measure feature adoption and revenue. Balancing: minimal data (event type, plan, amount — no queried VAT numbers or card details), processed only on our own EU infrastructure, never shared with any third party, and involving business customers in the ordinary operation of the Service; the impact on you is minimal and does not override your interests. | Legitimate interests (Art. 6(1)(f)) |
| Third-party analytics (Google Analytics, Microsoft Clarity)Loaded only after you opt in through the cookie banner on first visit. You can change or withdraw your consent at any time on the Cookie Policy page (/legal/cookies); withdrawal also deletes the cookies these providers set in your browser. | Consent (Art. 6(1)(a)) |
| Security audit logging and account activity monitoringOur interest in security, fraud prevention and compliance assistance outweighs the minimal impact on users given the limited scope of data collected. | Legitimate interests (Art. 6(1)(f)) |
| Onboarding survey response forwardingVoluntary, categorical responses only; opt-out via Skip button available at any time. | Legitimate interests (Art. 6(1)(f)) |
| Storing requester VAT numberNecessary to provide the consultation number feature. | Contract (Art. 6(1)(b)) |
| Storing VIES consultation numbersNecessary to provide the validation audit-log feature. | Contract (Art. 6(1)(b)) |
| Processing enrichment data from national registriesProcessed as data processor on customer’s behalf; see DPA. | Contract (Art. 6(1)(b)) |
Data Sharing & Subprocessors
We do not sell, rent, or trade your personal data. To deliver specific operations that we cannot reasonably perform in-house — payment processing, transactional email, content delivery, error monitoring, and server hosting — we engage a small number of carefully selected sub-processors. Each is bound by a written data processing agreement that imposes, at minimum, the obligations required by Art. 28 GDPR.
5.1 Categories of sub-processors
The table below summarises the categories of sub-processors and the data they receive. The complete and current list — with legal entity names, addresses, and processing details — is maintained at vatnode.dev/legal/subprocessors. That page is the authoritative source and supersedes any summary here in case of discrepancy.
| Category | Data processed | Location | Safeguard |
|---|---|---|---|
| Hosting & database (e.g. Vultr Holdings LLC) | All personal data stored by vatnode (account, API keys, check history, subscriptions) | Frankfurt, Germany (EU) | No transfer outside EEA — no Chapter V safeguard required |
| Payment processing (e.g. Mollie B.V.) | Email, billing name and address, Mollie payment and mandate identifiers | Amsterdam, Netherlands (EU) | No transfer outside EEA — no Chapter V safeguard required; written DPA under Art. 28 |
| Transactional email (e.g. Resend, Inc.) | Email address, display name, message contents (incl. onboarding survey answers when submitted) | USA | SCCs (Commission Decision 2021/914), Module 2 — Controller-to-Processor |
| Content delivery & security (e.g. Cloudflare, Inc.) | Connection metadata (IP address, request headers) for all traffic — processed in transit only, not stored at rest | USA (EU edge locations for EU traffic where available) | SCCs (Commission Decision 2021/914), Module 2 |
| Error monitoring (e.g. Functional Software, Inc. — Sentry) | Backend error events and stack traces with a pseudonymous account identifier; client IP, credentials and queried VAT numbers are stripped before events are sent | USA | SCCs (Commission Decision 2021/914), Module 2 |
| Optional website analytics & ads — consent only (e.g. Google, Microsoft) | Website usage events and cookie/device identifiers of visitors who have consented; not Customer API data | USA | SCCs (Commission Decision 2021/914), Module 2 — engaged only after consent |
5.2 International transfers and safeguards
Our primary hosting is in Frankfurt, Germany — inside the EEA — so no international transfer occurs for the bulk of your data. Where a sub-processor accesses personal data from the United States (currently Resend, Cloudflare and Sentry, plus Google and Microsoft only where you consent to optional analytics), the transfer is covered by the European Commission's Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, Module 2 (Controller-to-Processor), as adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021. We have performed a transfer impact assessment for each US-based recipient. Copies of the executed SCCs are available on request from [email protected]. See also Section 6 below for additional detail on transfer mechanisms.
5.3 Change notification and right to object
We will give all active customers at least 14 days' advance notice — sent to the email on your account — before engaging a new sub-processor or replacing an existing one. The same notice will be reflected on the public sub-processor list at /legal/subprocessors.
Customers who have entered into our Data Processing Agreement may object to any such change by emailing [email protected] within the notice period. We will work with you in good faith to address the objection; if no resolution is reached, you may terminate the affected portion of the Service without penalty. Continued use of the Service after the notice period expires constitutes acceptance of the new sub-processor.
5.4 VIES and national tax authority recipients
When validating VAT numbers, we transmit the queried VAT number — and, where you have configured it, your requester VAT number — to the European Commission's VIES service and, where applicable, to national tax authority and company registry APIs of covered EU member states. These entities act as independent data controllers, not as sub-processors of vatnode. VAT numbers are business identifiers and generally do not constitute personal data, except where they identify a sole trader as a natural person.
We may also disclose data to law-enforcement or other public authorities when required by Finnish or EU law (Art. 6(1)(c) GDPR).
International Data Transfers
Our primary infrastructure — server, database, API, and web hosting — is hosted by Vultr Holdings LLC in Frankfurt, Germany (EU). As this location is within the European Economic Area, no international transfer of personal data occurs for these processing activities.
We use Mollie for payment processing and Resend for transactional email. Mollie B.V. is established in Amsterdam, Netherlands (EU) and processes payment data within the European Economic Area, so no international transfer outside the EEA occurs for payment processing. Resend operates from the United States; transfers to it are governed by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c) (Commission Implementing Decision 2021/914 of 4 June 2021), Module 2 (Controller-to-Processor).
Cloudflare, Inc. provides our CDN, DNS and DDoS/WAF protection, so all inbound traffic passes through it; it processes connection metadata (including IP addresses) in transit only and does not store your data at rest. Cloudflare operates from the United States, with EU traffic served from EU edge locations where available; transfers are governed by the same SCCs under GDPR Art. 46(2)(c), Module 2. We also use Sentry (Functional Software, Inc.) in the United States for backend error monitoring; it receives error events and stack traces with a pseudonymous account identifier only — client IP addresses, credentials and queried VAT numbers are stripped before events leave our servers — under the same SCCs. Where you consent to optional analytics or ads cookies, Google and Microsoft may also receive data in the United States under the same SCCs — see the Cookie Policy.
Copies of the applicable SCCs are available on request by contacting [email protected].
Data Retention
| Data type | Retention |
|---|---|
| Account data (email, name) | Until account deletion + 30-day recovery window. After deletion, email is retained indefinitely in anonymised form for audit integrity; it is no longer linked to any identifiable person. |
| VAT check history (checkId, verifiedAt, subject VAT, validation result, optional consultation number, enrichment fields) | Stored in full for as long as your account is active and is deleted within 30 days of account deletion. In addition, after 5 years from the date of each check — aligned with standard EU VAT audit retention — the record is anonymised: the identifying fields (the queried VAT number, company name and address, registry code and name, and any industry description) are removed. The remaining non-identifying information — country code, date of the check, and validity result — is kept indefinitely as anonymised, aggregated usage statistics that can no longer be linked to any identifiable person. |
| Requester VAT number (your own EU VAT, if set in Settings) | Until you clear it from Settings or delete your account. Deleted within 30 days of account deletion. |
| Security events (sign-in and sign-out, API key creation and revocation) — with IP address and user agent | 1 year. IP address and user agent anonymised after 30 days. |
| Audit logs (account and billing changes, key management) — with IP address | 1 year. IP address anonymised after 30 days. |
| Email change history | Indefinitely. No personal data is retained after anonymisation. |
| Payment and invoice records | Retained for at least the statutory minimum — 6 years from the end of the financial year (Finnish Accounting Act, Kirjanpitolaki 1336/1997, ch. 2 §10) — and thereafter kept indefinitely as immutable accounting records. Each invoice records the buyer identity you provide: name (or, for a sole trader, the account email), company name if given, billing address, VAT ID and the account email. These records survive account deletion because we are legally required to keep them. |
| Cancellation feedback (optional churn reason and free-text comment you provide when cancelling) | Retained for the lifetime of your account record. Both fields are optional and user-authored; provide none, and none is stored. You may request deletion at any time via [email protected]. |
| Website analytics / auto-collected data | Session duration; aggregates retained indefinitely (no personal data after anonymisation). |
Your Rights (GDPR)
As a data subject in the EU/EEA, you have the following rights under GDPR Arts. 15–22. Contact us at [email protected] — we will respond within 30 days (extendable to 90 days for complex requests per Art. 12(3)).
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) at tietosuoja.fi or with your local EU supervisory authority (Art. 13(2)(d) GDPR).
Access (Art. 15)
Request a copy of your personal data
Rectification (Art. 16)
Correct inaccurate or incomplete data
Erasure (Art. 17)
Request deletion of your data
Restriction (Art. 18)
Request that we restrict processing
Portability (Art. 20)
Receive your data in machine-readable format
Object (Art. 21)
Object to processing based on legitimate interests
Withdraw Consent (Art. 7(3))
We do not currently rely on consent as a legal basis. If we add consent-based processing in the future, you may withdraw consent at any time.
Supervisory Authority Complaint (Art. 77)
Lodge a complaint with the Finnish Data Protection Ombudsman at tietosuoja.fi or your local EU supervisory authority.
Data Security
We implement appropriate technical and organisational measures, including:
- HTTPS/TLS encryption for all connections
- Passwords stored as bcrypt hashes
- API keys stored as HMAC-SHA-256 hashes
- Database encrypted at rest
- Access to production systems restricted to authorised personnel
- Comprehensive audit logging of account and security events (see §3.5)
In the event of a personal data breach, we will notify the Finnish Data Protection Ombudsman within 72 hours and affected users without undue delay, as required by GDPR Arts. 33–34.
Automated Processing
We use automated processes for operational purposes that are necessary for the performance of our contract with you (Art. 6(1)(b) GDPR):
- Quota enforcement — API access is automatically suspended when the monthly request limit for your plan is reached.
- Rate limiting — requests exceeding per-second thresholds are automatically rejected to protect service availability.
- Account suspension — accounts may be automatically suspended after a payment grace period expires.
Quota enforcement and rate limiting are operational controls that do not produce legal effects or similarly significant effects on you as a person within the meaning of Art. 22 GDPR. They reflect the technical boundaries of your chosen subscription plan.
Account suspension decisions that significantly affect your access to the Service may be reviewed by a human. To request such a review, contact [email protected].
No profiling. We do not build marketing profiles, credit-style scores, or behavioural advertising segments. Our onboarding emails (see §4) are triggered by simple product-usage milestones — for example, whether you have made your first API call — not by profiling in the sense of Art. 4(4) GDPR.
Cookies
Essential cookies — a session cookie that maintains your login state and a CSRF token that protects against cross-site request forgery — are always on, as the Service cannot function without them.
With your consent we also use optional analytics (Google Analytics 4, Microsoft Clarity) and marketing-measurement (Google Ads) cookies. Until you consent these run in cookieless mode under Google Consent Mode v2 and store nothing on your device, and you can change your choice at any time. Self-hosted Umami analytics is cookieless and always on. The full cookie inventory, retention periods and consent controls are in our Cookie Policy.
Children's Privacy
Our Service is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email at least 14 days before the changes take effect. The updated date at the top of this page reflects the last revision.
Contact
For privacy-related questions, to exercise your rights, or to request a Data Processing Agreement (DPA) for your organisation:
We aim to respond within 30 days. For complex requests we may extend to 90 days and will notify you of the extension (Art. 12(3) GDPR).