EVENHELM
Legal

Privacy Policy

How EvenHelm collects, uses, shares, and protects personal data — written in plain language, grounded in what the product actually does.

Effective date: 28 June 2026Last updated: 28 June 2026

This policy explains how EvenHelm handles personal data for visitors to our website and users of our cloud and AI cost-tracking and invoicing service (the “Service”). It covers our obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the CPRA (“CCPA”).

01Who we are

EvenHelm is operated by Meta Mine OOD (EIK 208222364), a limited liability company incorporated in the Republic of Bulgaria, registered at Zornitsa 42, Apt. 3, Burgas 8018, Bulgaria (“EvenHelm”, “we”, “us”). We are the data controller for the personal data described in section 03 under “Account & identity”, “Authentication & security”, “Session & device”, and “Billing”.

For any privacy question or to exercise your rights, contact us via our contact form.

We have not appointed a Data Protection Officer; one is not mandatory for our processing activities. Privacy enquiries go through our contact form above. We have not appointed an Art. 27 GDPR representative, as Meta Mine OOD is established in the EU (Bulgaria), so the requirement does not apply.

02Controller vs. processor — an important distinction

EvenHelm plays two different roles depending on the data, and your rights flow accordingly:

EvenHelm is the controller

For data about you as an account holder — your login identity, authentication and security data, session records, and billing relationship. We decide how and why this data is processed, so this policy governs it directly.

EvenHelm is the processor

For the content you upload into your workspace— in particular the client and invoice information you enter for invoicing (client names, billing addresses, VAT numbers, invoice line items, expenses, generated PDFs). Your organisation is the controller of that data; we process it only on your instructions to provide the Service. If you are an individual whose details appear on a customer’s invoice, please direct privacy requests to that customer (the controller); we will assist them as their processor.

Processing of controller-vs-processor data for business customers is also governed by our Data Processing Agreement.

03Data we collect

We collect only what the Service needs to function. We do not collect special-category data (such as health, biometric, or data revealing race, religion, or political opinion).

Data we collect as controller

CategoryWhat it includesWhere it comes from
Account & identityEmail address, full name, UI language preference, notification opt-out settings.You provide it at registration / in settings.
Authentication & securityYour password (stored only as a hash — never in plain text), two-factor authentication secret and recovery codes (stored securely), and email verification and password-reset tokens.Generated when you set up sign-in and 2FA.
Session & deviceIP address and browser user-agent string, captured on each authenticated request to maintain and secure your session.Collected automatically when you are signed in.
BillingA customer reference held by our payment processor. Card numbers and billing identity are handled by that processor — we never store full payment-card details.Created when you start a paid plan.
Audit recordsA log of actions taken in your workspace (who did what, and the names/labels involved — never secrets).Generated by your activity in the app.

Data we process on your behalf (you are the controller)

CategoryWhat it includes
Client & invoice dataClient names, billing addresses, VAT numbers, payer details, subject matter, and notes you enter; financial line items; and an immutable snapshot of client details frozen into each invoice.
Generated documentsInvoice PDFs, stored in a private, access-controlled storage bucket.
Expenses & vendorsExpense records and vendor details you log.
Connected provider credentialsAPI keys for the third-party cloud and AI providers whose cost and usage you choose to track. These are encrypted at rest; only a masked hint is ever shown back to you. These are secrets, not personal data.

The cost and usage figures we read from connected providers are your organisation’s own aggregated billing and usage data, scoped to your accounts. See section 06.

04How and why we use it — and our legal bases

Under the GDPR and UK GDPR we must have a lawful basis for each use of your personal data. The table below sets out our purposes and the basis we rely on.

PurposeData usedLawful basis
Provide the Service — create your account, sign you in, render dashboards and invoices.Account & identity, authentication, client/invoice data.Performance of a contract (Art. 6(1)(b)).
Secure your account — maintain sessions, detect and investigate suspicious activity, throttle abuse.Session IP address & user-agent, authentication data, audit records.Legitimate interests (Art. 6(1)(f)) in keeping the Service and accounts secure.
Send transactional email — verification, password reset, invitations, security and budget alerts.Email address, name.Performance of a contract / legitimate interests.
Take payment for paid plans.Billing reference, account identity.Performance of a contract.
Comply with legal, accounting, and tax obligations.Billing and invoice-related records.Legal obligation (Art. 6(1)(c)).
Measure website usage with analytics.Cookie/analytics identifiers, anonymised IP.Consent (Art. 6(1)(a)) — only if you accept analytics.

Where we rely on legitimate interests (notably for security logging of session IP addresses and user-agents), we have weighed those interests against your rights and consider the processing proportionate and expected. You may object at any time — see section 10.

05Sharing & sub-processors

We do not sell your personal data. We share it only with the service providers (sub-processors) we rely on to run EvenHelm, each bound by contract to protect it and use it only for the purposes we specify.

Sub-processor categoryPurposeLocation
Cloud database & file-storage providerApplication database and private file storage.EU
Cloud hosting & infrastructure providerHosting for the application and background processing.EU
Payment processing providerPayment processing and subscription billing.United States (SCCs / EU-US Data Privacy Framework)
Transactional email providerTransactional email delivery (verification, reset, invites, alerts).EU
Analytics providerWebsite usage analytics (consent-gated, IP-anonymised).United States (SCCs / EU-US Data Privacy Framework)

We may also disclose personal data where required by law, to enforce our terms, or in connection with a merger or acquisition (in which case we will notify you).

06AI providers & your data

EvenHelm connects to third-party AI providers only to read your organisation’s own cost and usage figures through their administrative/billing APIs. To be unambiguous:

  • We never send your content or prompts to AI providers. Only your own aggregated cost and usage data is read.
  • We do not use your data to train any AI model, and we do not allow our sub-processors to do so on our behalf.
  • Provider credentials you connect are encrypted at rest and used only with read-only, least-privilege scopes.

07Cookies & analytics

We use a small number of cookies and similar technologies that are strictly necessary to sign you in and keep your session secure. These do not require consent.

For website analytics we use a third-party analytics provider with IP anonymisation enabled. Analytics only load after you consent via our cookie banner, and you can withdraw your consent at any time.

Full details of each cookie are set out in our cookie notice.

08International transfers

Your account data is stored in the EU: our database and file-storage provider, our hosting and infrastructure provider, and our transactional email provider all process this data in the EU. These do not involve a transfer outside the EEA.

A small number of sub-processors — our payment processing and analytics providers — are located in the United States. For these US transfers we rely on the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies), or an adequacy decision where one applies.

09How long we keep data

We keep personal data only as long as we need it for the purposes above, then delete or anonymise it.

DataRetention
Account & identity, authentication dataKept for the life of your account, then anonymised or deleted on account closure (we support account erasure).
Session records (IP + user-agent)Sessions expire after 30 days. Expired or revoked session records are then pruned automatically once they are more than 30 days past expiry or revocation.
Invoice & financial recordsRetained for 10 years in accordance with the Bulgarian Accountancy Act (counted from 1 January of the year following the accounting period).
Audit logAudit-log entries are pruned automatically after approximately 400 days (about 13 months).
Analytics dataKept for a limited period in line with our analytics provider’s retention settings.

10Your rights (GDPR / UK GDPR)

If you are in the EEA or UK, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data (“right to be forgotten”), subject to our legal retention duties.
  • Restrict or object to processing — including processing based on legitimate interests, such as security logging.
  • Port your data to another service in a structured, machine-readable format.
  • Withdraw consent at any time (e.g. for analytics), without affecting prior processing.

To exercise any of these, contact us via our contact form. A self-service data-subject request (DSAR) flow is being built; in the meantime we handle requests manually and will respond within one month, as required by law. We will verify your identity before acting on a request.

11Your rights (CCPA / CPRA — California residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose.
  • Delete personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of the “sale” or “sharing” of personal information.
  • Non-discrimination — we will not treat you differently for exercising your rights.

Do Not Sell or Share My Personal Information. EvenHelm does not sell your personal information, and we do not share it for cross-context behavioural advertising. Because we do not sell or share, no opt-out is required — but you may still contact us with any request via our contact form. We do not knowingly process the personal information of consumers we know to be under 16.

12Security

We apply appropriate technical and organisational measures to protect personal data, including encryption of data in transit and at rest, strict access controls and tenant isolation, and support for two-factor authentication.

No system is perfectly secure, but we work continuously to protect your data and to detect and respond to risks.

13Children

EvenHelm is a business-to-business product intended for organisations and their staff. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

14Data breaches

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it (Art. 33 GDPR). Where the breach is likely to result in a high risk to you, we will also notify you directly. As a processor, we will notify the relevant controller (your organisation) without undue delay.

15Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you by email or in-app. Please review it periodically.

16Contact & complaints

For any privacy question, or to exercise your rights, contact us via our contact form.

If you are in the EEA or UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner’s Office). We would appreciate the chance to address your concern first. This policy is governed by the laws of the Republic of Bulgaria.