Skip to content
vat.tools
Product
How it worksPricingCoverageBlogDevelopers
Menu
Product
Use cases (9)
Accounting & Tax AdvisoryB2B Wholesale & DistributionSaaS & Cloud ServicesMarketplaces & DAC7ERP & E-Invoicing ISVsLogistics & Freight ForwardingB2B CheckoutE-Invoicing & ViDAAudit Defense
Free tools (14)
VAT rates by countryHistorical VAT ratesVAT calculatorWhat VAT rate applies?VAT registration thresholdsE-invoicing mandate trackerVAT number format validatorVAT number lookupVAT number finderEU VAT invoice generatorVAT invoice wording generatorEORI number validatorB2B VAT overcharge calculatorVIES status and uptime radar
How it worksPricingCoverageBlogDevelopersTerms of ServicePrivacySign in
Checking account…
VAT Tools/Legal

Privacy Policy (GDPR)

Effective Date: 16 September 2026 · GDPR / Regulation (EU) 2016/679 Compliant

Contents1. Overview & Commitment2. Data Controller3. Data We Collect4. Lawful Bases (GDPR Art. 6)5. Purposes of Processing6. Data Retention & Purging7. Subprocessors & Transfers8. Your Rights Under GDPR9. Security Measures10. Cookies & Local Storage11. Supervisory Authority12. Data Protection Contact

1. Overview & Commitment

At VAT Tools (“we”, “us”, “our”), we design our identity and tax verification systems around data minimization and evidentiary integrity. This Privacy Policy explains how we collect, process, retain, and protect personal data in compliance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and applicable data protection legislation.

2. Data Controller

For personal data collected when you register an account, navigate our website, configure developer keys, or communicate with our support team, the data controller is:

VAT Tools

Contact: Data Protection & Privacy Lead

Email: privacy@vat.tools

Where you submit corporate identity queries or VAT numbers on behalf of your business via our API or workspace, VAT Tools acts as a data processor or independent verification gateway retrieving authoritative public registry records in accordance with your explicit instructions.

3. Categories of Data We Collect

We process only the data necessary to provide and secure our verification services:

  • Account & Profile Information: Name, business email address, organization name, hashed authentication credentials, and billing details provided during sign-up.
  • Verification Query Inputs: VAT identification numbers, EORI numbers, company registration numbers, and trade names submitted for registry check or format validation.
  • Technical & Security Diagnostics: IP address, browser user-agent, API request timestamps, response codes, and rate-limiting metrics required to defend against automated abuse.
  • Client-Side Utilities: Free client-side tools (such as our WYSIWYG invoice generator and VAT calculator) process input lines, company names, and invoice figures strictly within your local browser memory; no invoice drafts are transmitted to or stored on our servers.

4. Lawful Bases for Processing (GDPR Art. 6)

We process personal data under the following lawful bases:

  • Performance of a Contract (Art. 6(1)(b) GDPR): To provision your user account, execute requested registry checks, provide API access, and manage subscriptions.
  • Legitimate Interests (Art. 6(1)(f) GDPR): To safeguard platform infrastructure against fraud and brute-force queries, maintain service uptime, and authenticate API key permissions.
  • Compliance with Legal Obligations (Art. 6(1)(c) GDPR): To satisfy statutory bookkeeping, tax reporting, and accounting requirements for customer transactions.

5. Purposes of Processing

We use collected data solely to:

  • Execute live verifications against official public registers (such as VIES and national gazettes).
  • Produce source-linked evidentiary records with cryptographic time anchors for audit compliance.
  • Issue API keys, monitor quota consumption, and enforce environment isolation (sandbox vs. live).
  • Deliver critical platform updates, security notifications, and billing invoices.

We do not sell, rent, or monetize your query history or business data to third-party data brokers or advertisers.

6. Data Retention & Purging Policies

We retain personal data only for as long as necessary to fulfill the purposes outlined herein. Customers may configure automated retention policies in workspace settings (e.g. 30, 90, or 365 days) to automatically purge past check logs. Upon organization deletion or explicit erasure request, query records and developer keys are permanently wiped from operational databases within 30 days.

7. Subprocessors & Data Transfers

Our infrastructure and databases are hosted in European Union cloud facilities ensuring robust data residency and adherence to EU privacy benchmarks. Where subprocessors are engaged (e.g., cloud hosting, email delivery, transaction processing), they are bound by strict Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs).

8. Your Rights Under GDPR (Art. 15–22)

Under the GDPR, you have the right to:

  • Right of Access (Art. 15): Request confirmation and a copy of personal data processed about you.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete personal records.
  • Right to Erasure / “Be Forgotten” (Art. 17): Request deletion of your data where retention is no longer necessary.
  • Right to Restriction (Art. 18): Request temporary restriction of processing in case of disputes.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV).
  • Right to Object (Art. 21): Object to processing carried out under our legitimate interests.

To exercise any of these rights, email us at privacy@vat.tools. We respond to all verified requests within thirty (30) days without cost.

9. Security Measures (Art. 32 GDPR)

We maintain rigorous technical and organizational security controls to protect data against unauthorized disclosure, loss, or alteration. These include:

  • Enforced TLS 1.3 encryption for all web and API traffic in transit.
  • Encrypted database storage at rest using AES-256.
  • Cryptographically hashed developer tokens and API credentials.
  • Strict least-privilege role-based access control (RBAC) across all administrative tools.

10. Cookies & Client-Side Storage

VAT Tools does not deploy third-party advertising, analytics, or behavioral tracking cookies. We utilize strictly necessary first-party storage solely for:

  • Session Authentication: Maintaining your logged-in session securely.
  • Theme Preference: Remembering your light or dark mode setting locally.

11. Supervisory Authority

If you are located in the European Economic Area and believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with your local Data Protection Authority (DPA).

12. Data Protection Contact

For any questions, data subject access requests, or privacy concerns, please contact our privacy team:

VAT Tools Privacy Office

Email: privacy@vat.tools

Subject: GDPR Data Request / Privacy Question

vat.tools

European VAT intelligence, business identity resolution, and automated compliance infrastructure with source-linked evidence.

Data Protection & Privacyprivacy@vat.tools

Platform

Finance workspaceIndustry use casesLive VAT checksCompany resolutionBulk verificationsBlog & ResearchAPI & MCP integrationPricing & plans

Free Tools

VAT rates by countryHistorical VAT ratesEU VAT calculatorEU VAT invoice generatorVAT number lookupE-invoicing trackerBrowse all 14 tools →

Developers

API QuickstartREST API referenceMCP serverAuthenticationEvidence architectureError codes & recovery

Legal & Trust

Terms of ServicePrivacyHow it worksCountry & registry coverageSign inStart free account
© 2026 VAT Tools. All rights reserved.·Business identity. Clear evidence.
TermsPrivacyContact