Privacy and cookie policy
Last updated 08/09/2026 · Applies to wavell.dgblend.net
Who is writing
DGBLEND LTD runs the invoicing service at wavell.dgblend.net (the "Service"). This page says what personal data the Service handles, why, for how long, who else sees it, and what you can ask of us.
DGBLEND LTDStrovolou 77, Strovolos Center, Flat/Office 301, 2018 Strovolos, Cyprus
info@dgblend.net
Write to the address above for anything about your data. We answer within one month, as the GDPR requires.
Who is responsible for what
For the people who sign in, DGBLEND LTD is the data controller of their account: name, email address, sign-in credentials and the record of what they did.
For the clients, suppliers and contacts a company enters, that company is the data controller and DGBLEND LTD is its data processor, acting only on the company's instructions under a data processing agreement. If your details are in the Service because a company you deal with put them there, that company is the one to write to first; we will pass a request on to them if it reaches us instead.
For the security records kept to protect the Service, such as the addresses that sign-ins come from, we act as controller in our own legitimate interest.
What data the Service handles
Nothing is collected beyond what running an invoicing service needs.
- Accounts
- Name, email address, a hash of the password, the secret behind the second factor, any passkeys registered, the chosen language, and the companies the person belongs to with their role.
- Company records
- What each company enters to run its business: clients and suppliers with their addresses, VAT and tax numbers, contacts, email addresses and phone numbers; quotes, invoices, credit notes, contracts and expenses; products; bank accounts and imported bank movements; internal notes. Where a client or supplier is a natural person, these are their personal data.
- People who receive documents
- When a quote is accepted or an invoice paid online, the Service records the email address the offer was sent to, the one-time code used to confirm it, the time of the acceptance with its time zone, and the network address it came from. That record is what makes the acceptance provable.
- Payments and mandates
- Card payments and direct-debit mandates are taken on pages run by the payment provider. The Service keeps only what the provider returns: a reference, the status, the last digits or the bank's name, never full card numbers or account details.
- Technical records
- An audit trail of who did what and when, with the network address of the request; server logs kept briefly to keep the Service running and to investigate abuse.
Why, and on what legal basis
- To provide the Service to the companies that use it and to the people they send documents to: performance of a contract (Article 6(1)(b) GDPR).
- To keep the accounting and tax records the law requires companies to keep, and to make an accepted offer or a paid invoice provable: a legal obligation (Article 6(1)(c)).
- To keep the Service secure, to prevent abuse, and to keep backups: our legitimate interest (Article 6(1)(f)), which we have weighed against yours.
The Service does no profiling, no automated decisions with legal effect, and no advertising.
How long data is kept
Company records stay for as long as the company's account is active and, after that, for as long as the law requires accounting records to be kept, which in Cyprus is eight years from the end of the year the document belongs to. An issued invoice is never deleted, only marked; that is what the law asks of the company issuing it.
Accounts are kept while they are used. A person removed from every company keeps only what the audit trail already says about their past actions.
Backups are taken nightly and kept for thirty days, after which they are overwritten. Server logs are kept only briefly, for troubleshooting, and are rotated away by size.
Who else sees the data
DGBLEND LTD does not sell or rent data to anyone. The Service relies on these providers, each bound by a contract to handle data only for the purpose named here:
- Hosting
- The Service runs on servers operated by DGBLEND LTD in the European Union. The database and uploaded files never leave them in the course of normal operation.
- Off-site backups
- An encrypted copy of each nightly backup is stored with Cloudflare, Inc. (R2 object storage) in a bucket bound to Cloudflare's European Union jurisdiction, so it never leaves the EU, and is deleted after thirty days.
- Offers, invoices, reminders, sign-in codes and notifications are sent through Resend, Inc. from its European region (Ireland). Resend sees the recipient's address and the message.
- Card payments and mandates
- Where a company has connected Stripe, payments and SEPA direct-debit mandates are taken by Stripe Payments Europe, Ltd. on its own pages under its own privacy policy.
- Direct debit
- Where a company has connected GoCardless, direct-debit mandates and collections are handled by GoCardless Ltd. under its own privacy policy.
- Public registers
- To check a VAT number the Service queries VIES, run by the European Commission, and for United Kingdom companies HM Revenue & Customs and Companies House. Only the number or company name being checked is sent.
- Accountants
- A company may give its accountant read access to its records, or export them. That is the company's choice and under its control.
Data is stored and processed in the European Union. Cloudflare and Resend are established in the United States and are bound, for any access from outside the European Economic Area, by the European Commission's standard contractual clauses or the EU–US Data Privacy Framework. GoCardless operates from the United Kingdom under the Commission's adequacy decision. Stripe Payments Europe, Ltd. is established in Ireland and may rely on affiliates outside the EEA under the same safeguards.
Data is disclosed to a public authority only where the law obliges us to.
How the data is protected
Every connection is encrypted. Signing in requires a second factor or a passkey. Passwords are stored only as hashes; the keys a company gives the Service for its payment provider are stored encrypted. Access is limited to the people a company has invited, each with a role, and every change is written to an audit trail. Backups are tested and kept encrypted off site.
Your rights
You may ask to see the data held about you, to have it corrected or deleted, to restrict or object to its use, and to receive it in a portable form. Where the Service holds your data on a company's behalf, we will forward your request to that company, since the decision is theirs.
Write to DGBLEND LTD at the address at the top of this page. Asking costs nothing and needs no particular form.
You may also complain to a supervisory authority, in particular the Commissioner for Personal Data Protection of the Republic of Cyprus or the authority of the country you live in.
Changes to this policy
When this page changes, the date at the top changes with it. Whatever the date, the page always describes what the Service actually does.