Factuveri is a Shopify app that issues your store's invoices under the Spanish VERI*FACTU system and submits them to the Spanish Tax Agency (AEAT). Doing so involves processing personal data belonging to your business and to your customers. This policy explains what that data is, why we process it, who it is shared with, how long it is kept and how to exercise your rights. It is written under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
The producer and owner of the Factuveri invoicing system is HH AI COMPANY, with its address at Việt Nam. It is the same entity that signs the producer's responsible declaration required by article 13 of Royal Decree 1007/2023, which you can download from inside the app.
For anything related to this policy or to data protection: soporte@factuveri.com.
Two sets of data need to be told apart, because each party's role differs.
Data about your store's end customers (buyers). Here you, the merchant, are the data controller: you decide to issue the invoices, with what data and for whom. Factuveri acts as data processor within the meaning of article 28 GDPR: we process that data solely on your instructions and in order to provide you with the invoicing service, never for our own purposes. We do not disclose it to anyone other than the recipients listed in section 5, we do not use it for profiling or advertising, and staff with access are bound by confidentiality. Installing the app and accepting these terms constitute the processing instruction; at your request we sign a separate processing agreement with the content of article 28(3).
Data about your own business (the store contact person, the issuer's tax ID and legal name, service billing and support). For this data we are the controller, because we need it to provide the service, meet our own legal obligations and communicate with you.
The app processes exactly the data it needs in order to build a valid invoice and a valid billing record. Specifically:
We do not process payment data. Factuveri neither receives nor stores card numbers, bank details or buyers' payment credentials: that information stays with Shopify and its payment gateway, and the app has no access to it. Nor do we process special categories of data under article 9 GDPR, and we use no analytics or advertising cookies on the service's public pages.
The purpose is single and very specific: to issue the store's invoices and submit the corresponding billing record to the AEAT. The ancillary functions of the service follow from it: generating the PDF with its verification QR code, emailing the invoice to the customer if the merchant enables that, maintaining the ledger of issued invoices and allowing it to be exported, and retrying submissions the AEAT has not accepted.
The main legal basis is compliance with a legal obligation to which the controller is subject, article 6(1)(c) GDPR. The specific obligations are the duty to issue and keep invoices under Royal Decree 1619/2012, which approves the invoicing obligations regulation, and the duty to generate and submit billing records under Royal Decree 1007/2023 and Order HAC/1177/2024, issued in development of article 29.2.j) of Law 58/2003, the General Tax Law.
For what is not a legal obligation, the basis is performance of the contract under article 6(1)(b) GDPR: providing the service you subscribed to, billing you for it through Shopify and answering your support requests.
Data is disclosed only to those strictly necessary to deliver the service:
We do not sell personal data, we do not transfer it to third parties for commercial purposes, and we do not use it for advertising, profiling or model training.
Data is stored and processed on servers located in the European Union (Amsterdam region, the Netherlands), with no international transfers for storage. Communications with the AEAT and with VIES are likewise addressed to recipients in the European Union. Should a transfer outside the European Economic Area ever become necessary, it would be carried out under one of the safeguards in chapter V GDPR and announced on this page beforehand.
Invoices, billing records and proof of submission to the AEAT are kept for at least four years, the limitation period for tax obligations under article 29.2.e) of Law 58/2003, the General Tax Law, read together with article 19 of Royal Decree 1619/2012.
Records are unalterable by design: once created they are neither edited nor deleted, not even from our side, because they are hash-chained and altering one would break the chain. A mistake is corrected by issuing a rectifying invoice or a cancellation record, which are appended to the chain without removing anything.
If you uninstall the app, tax data continues to be retained for that period, precisely because the law requires it: deleting it on request would leave you without the documentation the tax authority may demand from you. Throughout that time you can export it in full. The Shopify session, by contrast, is deleted immediately on uninstall. Once the retention period has elapsed, the data is deleted.
Anyone whose data is processed in the service may exercise the rights of access, rectification, erasure, restriction of processing, objection and portability recognised in articles 15 to 22 GDPR.
If you are a store's customer, the controller is the store that sold to you: address your request to it. As processor we will handle and forward any request we receive, and assist the merchant in resolving it.
If you are a merchant, you can exercise your rights by writing to soporte@factuveri.com from the address associated with the store. We reply within the one-month period set by article 12(3) GDPR.
The right to erasure is limited by the tax retention obligation. We cannot delete an invoice or its record within the four-year period, because keeping it answers a legal obligation and article 17(3)(b) GDPR expressly excepts that case. We do delete data that is not needed for tax compliance, such as the customer's email address and language.
If you believe the processing does not comply with the rules, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the supervisory authority in your country.
Shopify requires every app to handle three compliance webhooks. This is how we handle them, and why in some cases the answer cannot be deletion:
customers/data_request — a customer's access request. We log the request in the audit trail and the merchant can export them at any time, who is the controller and must answer the customer. From the Reports section the merchant obtains the ledger of issued invoices as CSV, filterable by order or tax ID, together with the corresponding PDFs — which is exactly the information the app holds about that customer.customers/redact — a customer's erasure request. From the affected invoices we delete the data that is not of tax content: the customer's email address and language. We keep the name or legal name, tax ID and billing address shown on the invoice, because these are mandatory particulars under article 6 of Royal Decree 1619/2012 and form part of a document the law requires to be kept for four years; deleting them would turn the invoice into an invalid document and break the record chain. The operation is noted in the audit trail with the number of invoices affected.shop/redact — a request to erase a store's data, which Shopify sends 48 hours after uninstall. We log the request and acknowledge it, but we do not delete invoices or billing records while the tax retention period is still running, for the same reason. The Shopify session and access token are deleted on uninstall. The merchant’s electronic certificate, if one was uploaded, is deleted when this request arrives: it is not covered by the tax retention obligation.The technical and organisational measures under article 32 GDPR that we apply are, in essence:
Should a personal data breach occur, we would notify the affected merchant without undue delay, so that they can comply with articles 33 and 34 GDPR.
For any privacy question, to request the data processing agreement or to exercise your rights: soporte@factuveri.com. We reply within one business day.
If this policy changes materially — for instance, if a new data recipient is added — we will publish the new version at this same address and notify active merchants before it takes effect.