Kwito

Privacy Policy

Last updated: 21 July 2026

Who we are, and our two roles

Kwito is an e-invoicing application for Shopify that turns Belgian B2B orders into Peppol e-invoices. Kwito is operated by:

Noctixal SARL-S (in formation), Luxembourg 36, rue du Commerce L-3616 Kayl Luxembourg RCS Luxembourg: [pending incorporation] VAT: [pending incorporation] Contact: support@kwito.eu

Until Noctixal SARL-S completes incorporation, the service is operated by its founder, Charel Lejeune, in Luxembourg. He is the responsible party for the purposes of this policy, and the identity and contact details above will be updated with the company’s registration numbers once incorporation completes.

Kwito acts in two distinct data protection roles, and it is important to keep them apart:

What data we process and why

Kwito processes personal data only to generate, send, receive, and archive e-invoices. We do not use any of it for analytics, advertising, profiling, sale, or AI training.

Lawful basis

Because Kwito acts in two roles, the lawful basis differs by data type:

Retention

Sub-processors

All invoice and buyer personal data is stored in the EU (Germany and Finland). We use the following sub-processors:

Sub-processorRole and personal dataLocation
Hetzner Online GmbHHosting and encrypted backups (all invoice and account data)Germany and Finland (EU)
RecommandCertified Peppol access point (invoice transmission)Belgium (EU)
ResendTransactional email: VAT requests and accountant forwarding (email addresses)EU data region
MigaduSupport and account mailbox hosting (email we exchange with you)Swiss company; mailboxes hosted in France and Germany (EU)
Cloudflare, Inc.Authoritative DNS for kwito.eu only; no invoice or personal dataUnited States

We maintain a data processing agreement with each sub-processor. If we add or replace a sub-processor that handles personal data, we will update this list and, for merchants, give advance notice as described in our Data Processing Agreement so they can object.

International transfers

Invoice and buyer personal data is stored and processed in the EU. Two providers involve a country outside the EEA, and each is covered by a lawful transfer mechanism:

Where a sub-processor with EU data residency is part of a group established outside the EEA, we rely on that provider’s Standard Contractual Clauses or Data Privacy Framework certification, as set out in its data processing agreement.

Security

Data is encrypted in transit (TLS everywhere) and at rest (AES-256-GCM over buyer personal data, invoice XML, and PDFs). Access to decrypted buyer data is logged. Breaches are assessed and, where required, notified to affected merchants and to the CNPD within 72 hours (GDPR art. 33). Our breach notification commitments to merchants are set out in our Data Processing Agreement.

Your rights

Buyers and merchants have the GDPR rights of access, rectification, erasure (subject to the 10-year invoice retention obligation), restriction, portability, and objection. Because Kwito is the processor for buyer data, a buyer should exercise these rights with the merchant who issued their invoice (the controller); we will assist that merchant in responding. For merchant account data, where Kwito is the controller, merchants may contact us directly at support@kwito.eu.

Supervisory authority

For merchant account data, our lead supervisory authority is the Commission nationale pour la protection des données (CNPD), Luxembourg (https://cnpd.public.lu). You have the right to lodge a complaint with the CNPD or with your local data protection authority.

Changes

We will update this policy as the service and its legal registration evolve; the “Last updated” date above reflects the current version.