Privacy Notice

Last updated: 02 March 2026

This notice explains how we handle personal data when you use the faffless website and e-invoice generator.

Who we are

This website is operated by fafflessvat.co.uk / fafflessvat.co.uk (“we”, “us”, “our”).

What data we collect

The data we collect depends on how you use the site. It may include:

  • Invoice details you enter (for example: business/customer name, address, VAT number, invoice number, line items, totals).
  • Technical data such as IP address and browser/device information (used for security and basic performance).
  • Support emails if you contact us.

How we use your data

  • To provide the tool and generate the XML/PDF outputs you request.
  • To keep the website secure and prevent abuse.
  • To respond to enquiries and provide support.
  • To improve the service (for example, understanding which pages are used most) (only if we run analytics).

Lawful basis (UK GDPR)

We process personal data under one or more of the following lawful bases (as applicable):

  • Performance of a contract — to provide the service you request.
  • Legitimate interests — to operate, secure, and improve the website.
  • Legal obligation — if we must keep certain records by law (if applicable).

Invoice data processing

How your invoice data is used

When you click Download e-invoice XML or Download PDF, the invoice details you entered are sent to our servers to generate the file and return it to your browser.

Retention: We do not store invoice content after file generation is complete, except where needed briefly for security, troubleshooting, or to comply with legal obligations.

If you decide to store invoice drafts in the future (for example, user accounts or saved drafts), this notice will be updated to reflect the retention period and purpose.

Sharing and service providers

We may use trusted service providers (processors) to run the site (for example hosting and email). They only process data on our instructions.

  • Hosting provider: Vercel
  • Email provider: fafflessvat.co.uk
  • Analytics (if used): fafflessvat.co.uk

We do not sell personal data.

International transfers

Some providers may process data outside the UK. Where required, we use appropriate safeguards (such as UK adequacy regulations or standard contractual clauses).

Security

We take reasonable technical and organisational measures to protect personal data. No internet service is completely secure, but we aim to minimise risk and prevent misuse.

Cookies

We do not use cookies

Your rights

You may have rights to access, correct, delete, restrict or object to processing of your personal data, and to data portability (where applicable).

To exercise your rights, email hello@fafflessvat.co.uk.

You can also complain to the UK Information Commissioner’s Office (ICO).

Changes to this notice

We may update this notice from time to time. The latest version will always be posted on this page.