Privacy Policy for BelegOne
English translation of the German original. In case of discrepancies, the German version prevails, subject to mandatory law.
This Privacy Policy describes the processing of personal data when using the web-based BelegOne application at belegone.cn1.ch. The separate Neumann IT Solutions Privacy Policy applies to the general company website.
1. Controller
Neumann IT Solutions
Christian Neumann
Burghügelweg 1
9604 Lütisburg
Switzerland
UID: CHE-170.758.290 VAT
Data protection contact: info@cn1.ch
Product support: support@cn1.ch
2. Scope and roles
Neumann IT Solutions is responsible for data processing necessary for registration, contract management, billing, security, support and operation of BelegOne.
The customer is generally the controller for personal data entered in its tenant concerning its own customers, employees, suppliers, contact persons or other individuals. Neumann IT Solutions processes this data as a processor in accordance with the BelegOne Terms and Conditions and the customer's instructions.
3. Legal bases and principles
Processing is based in particular on the Swiss Federal Data Protection Act. To the extent that the European Union's General Data Protection Regulation is applicable to a specific situation, its requirements will also be taken into account.
Personal data is processed in good faith, proportionately, for a specific purpose and with appropriate security.
4. Data during registration and contract management
When registering and managing a BelegOne account, the following data in particular may be processed:
- company or organization
- First name and last name
- Email address, phone number and country
- selected tariff and billing interval
- Account status, tenant assignment and user role
- Confirmation of email address
- Version and time of acceptance of the general terms and conditions and data protection declaration
- IP address, user agent and technical registration information
This data is used for account creation, identity and email verification, conclusion of the contract, communication, billing, prevention of misuse and evidence of legally relevant declarations.
5. Authentication and security
Passwords are not stored in plain text but are processed using an appropriate cryptographic password hash. Verification tokens are only stored in hashed form.
Technical authentication information is processed for logged in sessions. BelegOne can save technically necessary data in the browser. This storage is used exclusively for registration, session management and security and not for tracking or advertising.
Security logs may include, in particular, IP address, time, function called, user ID, result of a request and technical error data.
6. Company data and settings
In particular, the following data may be stored in the tenant:
- Company name, legal name, address and contact details
- UID and VAT number
- Bank details with account holder, IBAN, bank name and BIC or SWIFT
- Company logo and other uploaded files
- VAT, price, document and other client settings
The data is used to configure the tenant and create the documents requested by the customer.
7. Customer, supplier, document and content data
BelegOne processes the data entered or uploaded by the customer to provide the application. These can include:
- Customer, supplier and contact details including names, addresses, email addresses and telephone numbers
- Invoices, receipts, credit notes, offers, delivery notes and reminder documents
- externally imported invoices, receipts and credit notes as PDF files
- Line items, quantities, prices, tax rates, payment details and due dates
- Notes, references, document numbers and status information
- Signatures, logos, PDF files and other uploaded files
- Document contents and document data derived from them recognized through PDF text extraction and OCR
- Accounting and export metadata
Neumann IT Solutions does not use this content for advertising, profiling or its own unrelated purposes.
8. Document creation, PDF import, export and download
To create PDF documents, CSV files and complete tenant exports, the necessary tenant, customer, supplier, document, line-item and file data is processed.
For externally uploaded PDF documents, BelegOne processes the files on the BelegOne server infrastructure using PDF text extraction and, if necessary, local OCR. Document type, document number, supplier or customer, date, due date, amounts, currency and other document data can be automatically recognized.
Automatically recognized data is used to support the customer in recording and further processing documents. The information recognized may be incomplete or incorrect and must be checked by the customer.
The full tenant export may include customers, suppliers, documents, line items, company settings, uploaded files, PDF files, export metadata and SHA256 checksums.
After downloading, the customer is responsible for the safe storage and further processing of the exported files.
9. Emailing
When a customer triggers email sending from BelegOne, the recipient address, subject, message, sender information, document data and, if applicable, PDF attachments are processed and transmitted to the email provider used.
The email service is provided via infrastructure from Metanet AG in Switzerland. During delivery, data can also be processed by the recipient's mail provider and server. These can also be located abroad.
Email sending is blocked in the demo tenant.
10. Payments with Stripe
Stripe is used to purchase and manage paid subscriptions. Neumann IT Solutions generally does not receive full card details or account credentials.
When making a payment via Stripe, the data required for payment, subscription, fraud prevention and legal checks is transmitted to Stripe and participating financial partners. This may include name, email address, billing information, payment status, transaction reference, IP address, device information and payment details.
Stripe can also process personal data outside of Switzerland as part of its international infrastructure. According to its own information, Stripe uses the necessary legal transfer mechanisms and protective measures for such transfers.
Further information: Stripe privacy policy.
Stripe processes certain data under its own data protection responsibility.
11. Server operation and hosting
BelegOne is operated on server infrastructure from IONOS SE in Germany. When accessing, technical data is processed, in particular IP address, date and time, resource accessed, HTTP status, referrer, browser and operating system information.
The public company website and email infrastructure are operated by Metanet AG in Switzerland.
The processing is carried out to provide the service, error analysis, capacity control, system security and detection of abusive access.
12. Backups and recovery
Neumann IT Solutions creates regular technical backups of database and project files. The backups are stored encrypted and technically checked.
Additional encrypted backup copies can be stored on a separate backup infrastructure in Switzerland. The production server does not have the private key to decrypt these backups.
Deleted or modified data may continue to be contained in encrypted backups during a limited rotation period. They will not be used for any other purposes and will be removed upon expiry of the respective security period.
13. Demo tenant
The Business Pro demo tenant is separate from production customer operations. It must not contain production data or unnecessary personal data.
Demo data may be reset or deleted periodically and without notice. Documents, PDFs, CSV files and other outputs are marked as demo. Demo data is not transferred to a customer tenant.
14. Recipients and processors
Personal data will only be transmitted to recipients to the extent necessary for operations, contract fulfillment, payment, security, support or legal obligations. These include in particular:
- IONOS SE, Germany, server and network infrastructure
- Metanet AG, Switzerland, email and web infrastructure
- Stripe and involved financial partners, payment processing and subscription management
- Authorities, courts or other bodies if there is a legal obligation
Subcontractors are contractually obliged to maintain appropriate confidentiality and security when acting as processors.
15. International data transfers
Data processing may take place in Switzerland, Germany, the European Economic Area, the United States, India and other countries in which Stripe, participating financial partners or infrastructure partners operate.
For transfers to countries without an adequate level of data protection recognised by the Swiss Federal Council, appropriate safeguards are used where required. These may include recognised standard data protection clauses and additional protective measures.
16. No Analytics or Marketing Services
BelegOne does not use its own tracking services, web analytics or marketing cookies. There is no behavioral advertising by Neumann IT Solutions.
If you are redirected to Stripe, the technical procedures and data protection regulations of Stripe apply. Stripe may use its own cookies or similar technologies.
17. Retention and deletion
Personal data is retained for as long as necessary for operations, contract processing, support, security, record keeping or legal obligations.
- Account and contract data are generally stored during the contractual relationship.
- Due to legal obligations, business and accounting documents can usually be retained for ten years.
- Customer data in the client will be deleted or anonymized after the end of the contract after a reasonable export and processing period, unless there are legal or security-related reasons to the contrary.
- Verification and security tokens are deleted or technically invalid after use or expiration.
- Log data is only retained for as long as necessary for security, error analysis and abuse tracking.
- Encrypted backups are overwritten or deleted according to the respective rotation schedule.
Before final deletion, the customer is responsible for downloading the full tenant export.
18. Data Security
Neumann IT Solutions uses risk-appropriate technical and organizational measures. These include in particular:
- encrypted transmission via HTTPS
- hashed passwords and hashed verification tokens
- Role and client-related access controls
- Restricting administrative access
- Logging of security-relevant processes
- regular encrypted and technically tested backups
- Separation of productive server and private backup key
- Security updates and technical monitoring
Despite appropriate measures, absolute security cannot be guaranteed.
19. Rights of Data Subjects
Within the scope of applicable law, data subjects may request access, rectification, erasure, restriction of processing or data portability.
For data that a BelegOne customer has collected about its own customers, employees or other people, the request must first be directed to the respective BelegOne customer as the person responsible. Neumann IT Solutions supports the customer to the extent technically possible and proportionate.
Requests concerning data for which Neumann IT Solutions is the controller may be sent to info@cn1.ch. Identity verification may be required to prevent unauthorised disclosure.
20. Automated decisions
As part of BelegOne, Neumann IT Solutions does not make any automated individual decisions with significant legal or comparable effects.
Stripe may use automated fraud, risk, identity or payment verification procedures. The data protection information and rights as specified by Stripe apply to these procedures.
21. Changes to this Privacy Policy
This data protection declaration can be adjusted if BelegOne, the service providers used or legal requirements change. The currently valid version is published with version number and date.
Significant changes affecting registered customers will be communicated within BelegOne or by email.
22. Further legal information
The BelegOne Terms and Conditions and the central Neumann IT Solutions Legal Notice also apply.