Privacy Policy
Pursuant to the General Data Protection Regulation (GDPR).
At a glance
This application does not set analytics, advertising or tracking cookies, and it does not run any third-party tracker. Merely visiting the sign-in page or these legal pages does not process any personal data beyond what your browser sends to every website (see Section 5). Everything past the sign-in belongs to the internal billing tool that MADE-WITH.AI LTD uses to invoice its own customers - what is processed there is described in Section 3.
1. Controller
MADE-WITH.AI LTD
26 Anthipolochagou Georgiou M.Savva, Shop 1-2, 8201 Paphos, Cyprus
E-mail address appears once the page has loaded
2. The public part of this site
The sign-in page and these two legal pages are the only pages reachable without signing in. Submitting the sign-in form sends the entered password to our server for comparison; it is never stored or logged. On success, the server sets one cookie (invoice_session) containing a signed expiry timestamp, nothing else. It is required to keep you signed in and is set on this basis alone - as a strictly necessary cookie it does not require consent under Section 25 TDDDG. It expires after fourteen days or when you sign out.
3. Invoicing data (the tool behind the sign-in)
Behind the sign-in, MADE-WITH.AI LTD manages its own invoicing: invoice series, customers, invoices and credit notes, and incoming payments. For each customer this includes name, billing address, country, e-mail address, VAT identification number where applicable, and any note added manually. For each invoice it includes the line items, amounts, VAT treatment, dates, and its delivery and payment status.
Purpose and legal basis: issuing invoices to customers of MADE-WITH.AI LTD and reconciling their payment, which is necessary to perform the underlying contract with that customer (Art. 6(1)(b) GDPR) and to meet the statutory bookkeeping obligations that apply to MADE-WITH.AI LTD (Art. 6(1)(c) GDPR).
Retention: for as long as applicable tax and commercial law requires invoices and the records behind them to be kept.
If you are a customer of MADE-WITH.AI LTD and want to exercise a right described in Section 7 over the data held about you here, write to the address in Section 1.
4. Where this data is stored and processed
The database behind this application (Baserow) and the service that renders invoices as PDF (Gotenberg) run on our own servers under our own control - no invoice or customer data leaves our infrastructure to reach either of them.
Three services outside our own infrastructure are involved, each only for its stated purpose:
- Mailjet(Mailjet SAS, Paris) delivers quotations, invoices, credit notes and reminders to the customer's e-mail address. The e-mail address and the document PDF pass through their systems for the sole purpose of delivery.
- Stripe, where configured, processes checkout payments and reports the paid amount and a payment identifier back to us, so an invoice can be created or marked paid automatically.
- Revolut Business is the bank account MADE-WITH.AI LTD holds; its transaction history (amount, date, counterparty name and payment reference) is read back to match incoming payments to open invoices. This is the same information that already exists on our bank statement.
Use of each of these providers is governed by their respective terms and, where applicable, their standard data processing terms under Art. 28 GDPR. No customer or invoice data is sent to any service beyond these three, and none of it is used to train any AI model - this application does not call any AI service.
5. Server logs
Our hosting infrastructure automatically records technical information that your browser transmits on every request - browser type and version, operating system, the referring page, the time of the request and your IP address. This is used only to operate and secure the service (Art. 6(1)(f) GDPR) and is not combined with any other data source.
6. Your rights
Right of access (Art. 15 GDPR)
to obtain confirmation of and access to your personal data
Right to rectification (Art. 16 GDPR)
to have inaccurate data corrected
Right to erasure (Art. 17 GDPR)
to have your data deleted
Right to restriction (Art. 18 GDPR)
to have processing restricted
Right to data portability (Art. 20 GDPR)
to receive your data in a common format
Right to object (Art. 21 GDPR)
to object to processing based on legitimate interest
To exercise any of these rights, write to E-mail address appears once the page has loaded. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR).
7. Changes to this policy
We update this page whenever what the application actually does changes. This version has the status shown below.
Stand: 12 August 2026