Boeq is a financial tool for EU freelancers. We handle your business data with care. Short version: we collect only what's needed, we don't sell it, you can delete it anytime.
1. Who we are
Boeq is operated by Polsia (polsia.app). We provide invoicing, VAT calculation, and financial management tools for freelancers and small businesses in the European Union.
Data controller contact: boeq@polsia.app
2. What data we collect
| Data type | What it includes | Why we collect it |
| Account data | Name, email address, password (hashed) | Authentication and account management |
| Business data | Company name, VAT number (BTW/TVA), address, IBAN | Invoice generation and VAT compliance |
| Client data | Client names, VAT numbers, addresses, email addresses | Invoice generation; you own this data |
| Invoice data | Line items, amounts, VAT rates, payment status | Core product functionality |
| Expense data | Expense descriptions, amounts, receipts (uploaded files) | Expense tracking and VAT deduction |
| Usage data | Login timestamps, feature interactions | Security and product improvement |
3. How we use your data
- Deliver the service — generate invoices, calculate VAT, manage your finances
- Authentication — verify your identity on login, including optional 2FA
- Transactional emails — password resets, 2FA codes, invoice notifications
- Payment processing — subscription billing via Stripe
- Legal compliance — maintain records as required by EU tax law
- Product improvement — anonymous aggregate usage statistics
We do not use your data for advertising, profiling, or sale to third parties.
4. Legal basis (GDPR)
- Contract performance (Art. 6(1)(b)) — processing necessary to provide the service you signed up for
- Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud prevention, aggregate analytics
- Legal obligation (Art. 6(1)(c)) — tax record keeping as required by Belgian and EU law
- Consent (Art. 6(1)(a)) — optional cookies and non-essential features (you can withdraw anytime)
5. Data retention
| Data | Retention period |
| Account and business data | While your account is active + 7 years (Belgian tax law) |
| Invoice data | 7 years from invoice date (legal requirement) |
| Expense data and receipts | 7 years from expense date |
| Login and session data | 90 days |
| Deleted account data | Fully deleted within 30 days of account deletion request |
6. Third-party services
- Neon (neon.tech) — PostgreSQL database hosting. Your data is stored on Neon-managed servers in the EU. Neon Privacy Policy
- Stripe — payment processing for subscriptions. Stripe stores payment card details; Boeq never sees raw card numbers. Stripe Privacy Policy
- Polsia (polsia.app) — infrastructure provider. Our platform runs on Polsia's infrastructure (Render-hosted Node.js). Polsia Privacy Policy
- OpenAI — powers the "Ask Boeq" AI assistant feature. Queries are sent to OpenAI's API; no invoice data is included in AI queries without your explicit action. OpenAI Privacy Policy
7. Cookies and local storage
| Name | Type | Purpose | Duration |
connect.sid | Essential | Session cookie — keeps you logged in | 30 days |
boeq_lang | Functional | localStorage — remembers your language choice | Persistent |
boeq_cookie_consent | Essential | localStorage — records your cookie preferences | Persistent |
polsia_vid | Analytics | localStorage — anonymous visitor ID for aggregate page view counting | Persistent |
Functional and Analytics cookies are set only after consent. Essential cookies are required for the service to function.
8. Your rights
Under GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your account and data ("right to be forgotten")
- Portability — receive your data in a machine-readable format (JSON/CSV export available in-app)
- Restriction — request we limit processing of your data
- Objection — object to processing based on legitimate interests
- Withdraw consent — withdraw any consent you've given, at any time
To exercise any right: email boeq@polsia.app. We respond within 30 days. You also have the right to lodge a complaint with the Belgian Data Protection Authority (GBA / APD): dataprotectionauthority.be
9. Data security
- Passwords are hashed with bcrypt (cost factor 10) — never stored in plain text
- All connections use TLS/HTTPS encryption
- OAuth tokens encrypted with AES-256-GCM
- Session cookies are HttpOnly and Secure
- Database access is restricted to application servers only
10. Children's data
Boeq is a professional business tool. We do not knowingly collect data from individuals under 16 years of age.
11. Changes to this policy
We will notify you by email if we make material changes to this policy. The "last updated" date at the top of this page reflects the most recent revision.
12. Contact
Questions about privacy or to exercise your rights:
Email: boeq@polsia.app
Response time: Within 30 calendar days