Legal
Privacy notice
This notice explains how Temlavo handles personal information when you visit the service, create an account, use the API, process invoices, manage billing, or contact us.
1. Scope
This notice applies to the Temlavo website, account console, Invoice Extraction API, TypeScript SDK and CLI, and official integration examples.
When a customer submits invoice or related document content for processing, Temlavo generally processes that content to provide the service on the customer's instructions. Customers remain responsible for deciding whether they are permitted to submit that content and for their own downstream use of the results.
2. Information we process
Account and contact information
We process information needed to create and secure an account, authenticate users, provide support, and communicate about the service. Authentication is provided through Clerk.
Billing information
Stripe handles payment-method and payment-processing information. Temlavo receives and stores the identifiers, subscription state, usage records, invoices or billing status needed to administer plans and reconcile usage. Temlavo does not need to store complete payment-card numbers.
API and operational information
We process API-key authentication state, request and document identifiers, processing state, timestamps, retry and idempotency records, usage events, security events, bounded provider request identifiers, and privacy-safe operational telemetry needed to run, secure, bill, debug, and maintain the service.
Invoice and document content
Submitted source files may contain personal information about vendors, customers, employees, sole traders, or other people. Processing may also create OCR/layout intermediates and structured extraction results. Temlavo treats this content separately from ordinary operational telemetry.
Accounting-entity discovery information
When you supply an accounting-entity ID, processing that ends in completed or needs_review records the raw ID and first/last-seen timestamps in a separate account-scoped index used to find entities in account usage views. These customer-supplied identifiers are not anonymous data or the pseudonymous attribution used in financial records.
3. How we use information
We use information only as needed to:
- provide, secure, and operate the service;
- authenticate users and API requests;
- process documents and return structured results;
- detect duplicate submissions and preserve idempotency;
- measure plan usage and administer billing;
- prevent abuse and control provider spend;
- maintain, troubleshoot, and improve service reliability;
- respond to support, privacy, and security requests; and
- meet applicable legal, accounting, and security obligations.
Temlavo does not use invoice content for advertising and does not intentionally place invoice values, raw OCR text, source files, prompts, or model responses into normal application logs.
4. Legal bases for Temlavo's own processing
Where Temlavo acts as a controller and EU/EEA data-protection law applies, the legal basis depends on the purpose:
- Contract and steps requested before a contract: account access, service delivery, plan administration, support, and billing functions needed to provide the service you request.
- Legitimate interests: securing the service, preventing abuse and fraud, maintaining reliability, diagnosing content-free operational failures, and improving service operation where those interests are not overridden by individual rights and freedoms.
- Legal obligations: records or processing required for tax, accounting, legal claims, regulatory requests, or other obligations that apply to Temlavo.
- Consent: where Temlavo specifically asks for consent for an optional purpose. Consent is not the basis for core invoice-processing needed to provide the requested service.
For customer personal data processed on a customer's behalf, the customer determines the applicable lawful basis and Temlavo processes that data on the customer's documented instructions.
5. Invoice and document data
Source files are uploaded directly to private object storage using short-lived signed upload authorization. The public API server does not proxy the source bytes.
Temlavo uses document-processing providers to read the submitted file and extract structured invoice data. Mistral is used for OCR and OpenRouter is used to reach eligible AI model endpoints for structured extraction.
The API may return extracted invoice values, line items, consistency checks, duplicate signals, review outcomes, and processing metadata. A completed result means the declared checks found no blocking issue under the document's policy; it is not a certification that every extracted value is correct and it does not authorize payment.
6. Service providers
Temlavo relies on the service providers listed below to operate the product.
| Provider | Purpose | Data category |
|---|---|---|
| Vercel | Application hosting and runtime | Application requests, operational data, and request and callback destination metadata in platform logs |
| Supabase | Database and private object storage | Account/service records, source files, processing artifacts |
| Clerk | Account authentication | Identity and authentication data |
| Mistral | Invoice OCR | Submitted invoice/document content |
| OpenRouter and eligible routed model providers | Structured AI extraction | OCR/layout content needed for extraction |
| Stripe | Billing and payments | Billing, subscription, payment, and usage information |
| Sentry | Privacy-filtered operational monitoring | Content-free diagnostics and service telemetry |
For personal data processed on a customer's behalf, the Data Processing Addendum (DPA) sets out processing terms and its contractual subprocessor schedule. The table above also covers providers used for account administration, payments, and service operations.
7. Retention and deletion
- Source files and processing intermediates
- A 24-hour default expiry applies from each stored object's creation for confirmed source files and processing intermediates. Unconfirmed uploads expire 24 hours after document creation. Physical cleanup can follow expiry and may wait for processing recovery or storage-deletion retries.
- Structured document results
- Seven days from completion by default. API access to the result ends at the authoritative result-expiry timestamp exposed by the document resource; physical cleanup can follow.
- Idempotency records
- Retained for seven days to preserve safe replay behavior.
- Operational records
- Generally retained for approximately 90 days where needed for service operation, security, and reliability.
- Pseudonymous duplicate fingerprints
- Submissions ending in
completedorneeds_reviewwith duplicate detection enabled retain tenant-keyed fingerprints, account/document references, scope and completion time without automatic expiry. These are not plaintext invoice identifiers or anonymous data. Explicit document deletion or account closure removes the associated entries. Submissions with duplicate detection disabled add no entries. - Billing and financial records
- Retained for as long as required for billing integrity, accounting, tax, fraud prevention, dispute handling, and other applicable legal obligations.
- Accounting-entity discovery IDs
- Raw customer-supplied accounting-entity IDs and their first/last-seen timestamps are retained for the active account lifetime. They survive individual document deletion and have no automatic expiry. Removal is part of coordinated account closure, separate from document deletion and financial-record retention.
Customers can explicitly delete a document through the API. Deletion ends document API access and clears stored results and document fields. Storage deletion is attempted immediately and retried if needed. The separate accounting-entity discovery index remains, as do required billing, security, and operational records under their respective retention rules.
Document deletion and subscription cancellation do not close an account. To request account closure or return/deletion of retained personal data, contact privacy@temlavo.com. There is no self-service account-closure or export workflow. Requests require separate coordination of content, keys, billing obligations, identity, and retained records.
Vercel may retain request metadata (such as URLs, query parameters, browser and referrer information), callback destinations, and related error logs under its separate retention policy. Completing a callback or deleting a document removes Temlavo's stored callback URL and event payload, but does not delete Vercel's platform logs.
Copies created by a customer's own systems, including n8n execution history, callbacks, logs, CI output, or downstream databases, remain under that customer's control and retention policy.
8. International processing
Temlavo is operated from Cyprus and uses service providers that may process information in other countries. For information about provider locations and applicable transfer arrangements, contact privacy@temlavo.com.
9. Your choices and rights
Depending on where you live and the context in which information is processed, you may have rights to request access, correction, deletion, restriction, portability, or objection, to withdraw consent where processing depends on consent, and to complain to a relevant data-protection authority.
Temlavo's service returns extraction and review information to the customer; Temlavo does not itself decide whether an invoice is paid, posted, accepted, rejected, or otherwise given a legal or similarly significant business effect.
If Temlavo processes personal data on behalf of a customer, the customer may be the appropriate first contact for a request about that invoice or document. Temlavo will support customers with processor obligations as described in the DPA.
Privacy requests: privacy@temlavo.com
10. Security
Temlavo uses account-scoped authorization, private object storage, short-lived signed upload authorization, encryption for protected application state, bounded retention, content-minimized observability, abuse controls, and operational monitoring.
No internet service can guarantee absolute security. Security issues can be reported to security@temlavo.com. See the Security & retention page for the current technical boundaries.
11. Changes to this notice
We may update this notice as the product, legal requirements, or service-provider arrangements change. The current version will be posted here with its updated date. Material changes will be communicated when required.