GDPR Compliant

Privacy Policy

Last updated: May 2026  ·  Effective: May 12, 2026  ·  Contact: boeq@polsia.app

Boeq is a financial tool for EU freelancers. We handle your business data with care. Short version: we collect only what's needed, we don't sell it, you can delete it anytime.

1. Who we are

Boeq is operated by Polsia (polsia.app). We provide invoicing, VAT calculation, and financial management tools for freelancers and small businesses in the European Union.

Data controller contact: boeq@polsia.app

2. What data we collect

Data typeWhat it includesWhy we collect it
Account dataName, email address, password (hashed)Authentication and account management
Business dataCompany name, VAT number (BTW/TVA), address, IBANInvoice generation and VAT compliance
Client dataClient names, VAT numbers, addresses, email addressesInvoice generation; you own this data
Invoice dataLine items, amounts, VAT rates, payment statusCore product functionality
Expense dataExpense descriptions, amounts, receipts (uploaded files)Expense tracking and VAT deduction
Usage dataLogin timestamps, feature interactionsSecurity and product improvement

3. How we use your data

  • Deliver the service — generate invoices, calculate VAT, manage your finances
  • Authentication — verify your identity on login, including optional 2FA
  • Transactional emails — password resets, 2FA codes, invoice notifications
  • Payment processing — subscription billing via Stripe
  • Legal compliance — maintain records as required by EU tax law
  • Product improvement — anonymous aggregate usage statistics

We do not use your data for advertising, profiling, or sale to third parties.

4. Legal basis (GDPR)

  • Contract performance (Art. 6(1)(b)) — processing necessary to provide the service you signed up for
  • Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud prevention, aggregate analytics
  • Legal obligation (Art. 6(1)(c)) — tax record keeping as required by Belgian and EU law
  • Consent (Art. 6(1)(a)) — optional cookies and non-essential features (you can withdraw anytime)

5. Data retention

DataRetention period
Account and business dataWhile your account is active + 7 years (Belgian tax law)
Invoice data7 years from invoice date (legal requirement)
Expense data and receipts7 years from expense date
Login and session data90 days
Deleted account dataFully deleted within 30 days of account deletion request

6. Third-party services

  • Neon (neon.tech) — PostgreSQL database hosting. Your data is stored on Neon-managed servers in the EU. Neon Privacy Policy
  • Stripe — payment processing for subscriptions. Stripe stores payment card details; Boeq never sees raw card numbers. Stripe Privacy Policy
  • Polsia (polsia.app) — infrastructure provider. Our platform runs on Polsia's infrastructure (Render-hosted Node.js). Polsia Privacy Policy
  • OpenAI — powers the "Ask Boeq" AI assistant feature. Queries are sent to OpenAI's API; no invoice data is included in AI queries without your explicit action. OpenAI Privacy Policy

7. Cookies and local storage

NameTypePurposeDuration
connect.sidEssentialSession cookie — keeps you logged in30 days
boeq_langFunctionallocalStorage — remembers your language choicePersistent
boeq_cookie_consentEssentiallocalStorage — records your cookie preferencesPersistent
polsia_vidAnalyticslocalStorage — anonymous visitor ID for aggregate page view countingPersistent

Functional and Analytics cookies are set only after consent. Essential cookies are required for the service to function.

8. Your rights

Under GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and data ("right to be forgotten")
  • Portability — receive your data in a machine-readable format (JSON/CSV export available in-app)
  • Restriction — request we limit processing of your data
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — withdraw any consent you've given, at any time

To exercise any right: email boeq@polsia.app. We respond within 30 days. You also have the right to lodge a complaint with the Belgian Data Protection Authority (GBA / APD): dataprotectionauthority.be

9. Data security

  • Passwords are hashed with bcrypt (cost factor 10) — never stored in plain text
  • All connections use TLS/HTTPS encryption
  • OAuth tokens encrypted with AES-256-GCM
  • Session cookies are HttpOnly and Secure
  • Database access is restricted to application servers only

10. Children's data

Boeq is a professional business tool. We do not knowingly collect data from individuals under 16 years of age.

11. Changes to this policy

We will notify you by email if we make material changes to this policy. The "last updated" date at the top of this page reflects the most recent revision.

12. Contact

Questions about privacy or to exercise your rights:

Email: boeq@polsia.app
Response time: Within 30 calendar days