Privacy policy¶
Last update: 2 September 2026.
This policy describes how Antoine LE BORGNE, entrepreneur individuel, trading as Orvel (“we”), processes personal data when you use the Factur-X API and MCP service at https://facturx.orvel.dev.
Contact: le.borgne.antoine.pro@gmail.com — 10 rue Casabianca, 56600 Lanester, France.
What we process¶
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Account e-mail, name, billing address, VAT number if you provide one | Create the customer account, send receipts, comply with accounting rules | Contract; legal obligation |
| Payment data | Taken by Stripe. We never see full card numbers | Contract; Stripe as processor / independent controller for the payment |
| API key and monthly usage counters | Authenticate calls and enforce the plan quota | Contract |
Invoice files and JSON you send to /v1 or /mcp |
Generate, validate or extract the document | Contract |
| Technical logs (time, route, invoice number, rule ids, duration, IP) | Security, debugging, abuse | Legitimate interest |
| Docs site cookies | Remember language / theme if the browser allows it | Legitimate interest (strictly necessary) |
Invoice files are processed in memory and discarded. We do not keep PDF/XML bodies, party names, or amounts in logs.
Hosting and subprocessors¶
- Application: Railway Corporation (USA), Europe West region (Amsterdam). Documents are processed in the EU; Railway acts as processor under its DPA with EU standard contractual clauses.
- Payments and customer portal: Stripe (Ireland / EU).
- Usage counters: Upstash Redis when configured, otherwise in-memory on the machine.
Retention¶
- Customer and billing data: duration of the contract + 10 years (French accounting).
- Technical logs: 30 days.
- API keys: until you cancel or we disable the key.
Your rights¶
Access, rectification, erasure, restriction, portability, objection: write to the e-mail above. You may complain to the CNIL.
We do not sell data and we do not use it for advertising.
Payments¶
Card and mandate data are handled by Stripe under their privacy policy. Failed or successful payments produce a Stripe receipt sent to the e-mail you entered at checkout.