LEGAL
Privacy Policy
How Snapfact handles your data — and why you keep control.
Last updated: 21 September 2026
1. Who we are
Snapfact is operated by FNI Solutions SRL, a Belgian private company.
Address: Brussels, Belgium
Contact: privacy@snapfact.be
Data controller: FNI Solutions SRL (BCE/KBO: 0799.769.057)
2. What data we collect
We collect the following categories of personal and business data:
- Account data: name, email, phone (when provided), company name, physical address, VAT number
- Invoice and financial operations data: client names and contacts, amounts, IBAN / bank details, invoice and purchase content, photos or files you upload
- Support and messaging content: customer-support tickets and replies, in-app chat / email-style messages with your accountant or our support team, and voice notes when you use those features
- Trust / identity verification data: company lookup details and identity documents you choose to submit for business verification
- Device and push identifiers: mobile device push tokens (see §4b) and technical identifiers needed to deliver the app and secure your session
- Operational logs: first-party server access and application logs generated when you use Snapfact (API requests, authentication events). We do not ship third-party crash or analytics SDKs (no Firebase Analytics, Crashlytics, or Sentry) in the mobile apps
- AI interaction data: Spark queries, responses, and related voice or document inputs processed for Spark (stored on Belgian servers for the core AI workload)
3. How we use your data
We use your data to:
- Provide the Snapfact invoicing, purchases, banking-matching, VAT and accountant collaboration service
- Generate Peppol-compliant e-invoices and related documents
- Run Spark AI on your invoicing and portfolio context
- Send transactional emails, payment reminders, and push notifications you enable
- Verify your business (Trust) and secure accounts (including multi-factor authentication where enabled)
- Process subscriptions and billing via our payment provider (see §4c)
- Provide customer support
3b. What we do not do
We do NOT sell your data. We do NOT share with advertising networks. We do NOT use your content for third-party advertising or cross-app tracking.
4. Where your data is stored
Primary business, invoice, Spark AI and file data for Snapfact are stored and processed on FNI Solutions infrastructure in Belgium / the EU.
AI inference for Spark runs on our own GPU hardware in Brussels. We do not send Spark conversation content to OpenAI, AWS, Google Cloud, or Azure for model inference.
Limited technical data may be processed by specialised processors outside Belgium only where required to operate a feature you use — in particular push delivery (§4b) and card/subscription payments (§4c). Those transfers are limited to what the processor needs for that purpose and are covered by appropriate safeguards (including Standard Contractual Clauses where applicable).
4b. Push notifications (Firebase Cloud Messaging)
The Snapfact iOS and Android apps use Google Firebase Cloud Messaging (FCM) to deliver push notifications (for example messages, alerts and support updates you enable).
When push is enabled, a device push token is created and sent to Snapfact so we can target notifications to your device. Google acts as a processor for FCM delivery; Google may process the token and related delivery metadata on Google infrastructure, which can include processing outside the EU/EEA.
We do not use Firebase Analytics or Crashlytics. FCM is used for notification delivery, not for advertising.
You can disable notifications in the device system settings and in Snapfact notification preferences where available.
4c. Payments (Stripe)
Subscription and related billing payments are processed by Stripe. We do not store your full payment card details on Snapfact servers. Stripe acts as an independent payment processor under its own terms and privacy notice when you complete checkout or manage billing.
5. Your GDPR rights
Under the GDPR, you have the following rights:
- Right to access your data (email privacy@snapfact.be)
- Right to correction
- Right to deletion ("right to be forgotten") — public form: https://snapfact.be/account-deletion (also Settings → Privacy and data in the Snapfact app). Personal login deletion does not erase Belgian invoices we must retain.
- Right to data portability (export as JSON or CSV)
- Right to withdraw consent
- Right to lodge a complaint with the Belgian DPA (APD/GBA): www.dataprotectionauthority.be
6. Data retention
Active accounts: operational data is kept for the duration of the subscription. Retention is category-specific; not every data category has the same period.
Belgian invoices, invoice copies, accounting books and related supporting documents are generally retained for 10 years, calculated according to the applicable legal starting date. When an account is closed, legally retained records are restricted from ordinary processing rather than destroyed, and are deleted when the applicable retention period expires.
Erasable personal data that is not legally retained is deleted after identity, authority and retention review. Deleted live data that is not legally retained ages out of ordinary CNPG/Barman object-store backups, logical dumps and Snapfact file-volume snapshots according to the documented 35-day rotation. Legally retained records are not covered by ordinary deletion expiry. See https://snapfact.be/account-deletion.
Push tokens are kept while the device remains registered for notifications and are removed or rotated when you sign out, reinstall, or the token is replaced.
7. Cookies
On the website and web app we use essential cookies only (session management, language preference).
No advertising cookies. No tracking pixels. No third-party marketing analytics.
See our Cookie Policy for details.
8. Changes
We will notify you by email of any material changes to this policy.
Continued use of Snapfact after notification constitutes acceptance.
9. Contact
For any privacy questions: privacy@snapfact.be
We aim to acknowledge privacy requests within 5 business days as an internal service objective. Formally, we respond without undue delay and normally within one month. Where a request is complex or numerous, this period may be extended by up to two additional months. If an extension is necessary, we will inform the requester within the first month and explain the reason.