TRANSPARENCY

Privacy and preview service

ApiVect is operated by KPdesign, CVR 41134194, Bavnehøjen 5, 4690 Haslev, Denmark. Contact: contact@apivect.com. This deployment is a private technical preview. Paid subscriptions and public customer onboarding are not enabled yet. Use synthetic test data until the customer agreement and DPA are available.

Invoice processing

Invoice XML is processed in memory. The service does not archive invoice contents or include them in application logs. Encrypted sanitized results are available for idempotent retries for 24 hours. The cleanup worker runs every 30 seconds; operational metadata remains for usage accounting. A passing technical validation does not establish legal or tax compliance.

VAT and domain providers

VAT country and number are sent to EU VIES. Company names and addresses returned by VIES are discarded. Valid results may be cached for 60 minutes and invalid results for five minutes. Domain names and selectors are queried through Cloudflare's public DNS-over-HTTPS resolver; certificate and MTA-STS checks connect to the requested domain's public HTTPS service. These external requests are necessary for their respective checks.

Account and security data

Account email, organization, API-key hashes and usage metadata are stored to operate the service. Keys are shown at creation and verified using keyed hashes. Owner access requires an authenticator after initial setup. Application audit events expire after 90 days. Logs are size-rotated; Apache access logs contain client IP, method, path, status and timestamp but not query strings or request bodies. Metrics exclude customer identifiers, and stored traces are retained for 24 hours with URLs, client addresses and user agents removed.

Backups and cookies

Daily backups are encrypted and retained as seven daily, four weekly and six monthly snapshots. Copies are transferred into the operator's Google Drive folder. Deletion/export and backup-retention procedures require final review before customer onboarding. The portal uses essential security and session cookies. This site does not load advertising trackers.

Recovery and website services

Verified account holders can request a password reset. Reset tokens expire after 30 minutes and can be used once. Mail content is encrypted while queued and removed on delivery or expiry; delivery metadata is retained for seven days. Authentication admission counters contain keyed hashes and expire within two hours. Google reCAPTCHA verifies protected form submissions. Optional Google Analytics loads only after acceptance on public information pages; see cookie preferences. Google services may process data outside the EEA under their applicable terms and safeguards.

Commercial launch

Final terms, the data processing agreement, a complete subprocessor list must be published before public customer onboarding. For information, contact KPdesign through kpdesign.dk.