kvitta

Security and data

Where Kvitta runs, who can do what, and what it keeps.

Where it runs

The application, the database and uploaded files are hosted in Frankfurt, on Vercel and Neon.

Rule drafting runs on Anthropic and email intake on Postmark, both in the United States, under the European Commission's standard contractual clauses. Every provider is on the sub-processors page.

Sign-in

Microsoft work accounts, through Entra ID. Kvitta holds no passwords. Colleagues join a company by invitation.

Who can do what

Viewers read. Preparers work through batches and take journals. Approvers also change rules, accounts and connections.

Access is separate per organisation and per company, and a person reaches only the companies they were given.

Writing to Business Central

Kvitta writes only into Business Central batches an administrator has allowed, under the signed-in person's own Microsoft account. A journal is posted when a person chooses to post it.

The record

An append-only record of every file imported, journal taken, batch posted and batch handed over, with who and when.

What Kvitta reads

The readers take references, amounts and dates. A payer's name stays in the original file, as it was delivered.

Uploaded files and results are kept while the account is open. A file and its record can be removed until its journal reaches Business Central.

AI

Kvitta's AI drafts rules and explains unmatched lines, from the structure of your files and the shape of your references. A person approves every rule. The AI does not choose which invoice a payment settles or write a figure.

Submitted data is not used to train models, and one company's rules stay with that company.

Encryption

TLS in transit. Data at rest is encrypted by the hosting providers.

Documents

Privacy notice, terms, data processing agreement and sub-processors. These are the documents that govern the service.