Last updated: 21 July 2026
Kwito is an e-invoicing application for Shopify that turns Belgian B2B orders into Peppol e-invoices. Kwito is operated by:
Noctixal SARL-S (in formation), Luxembourg 36, rue du Commerce L-3616 Kayl Luxembourg RCS Luxembourg: [pending incorporation] VAT: [pending incorporation] Contact: support@kwito.eu
Until Noctixal SARL-S completes incorporation, the service is operated by its founder, Charel Lejeune, in Luxembourg. He is the responsible party for the purposes of this policy, and the identity and contact details above will be updated with the company’s registration numbers once incorporation completes.
Kwito acts in two distinct data protection roles, and it is important to keep them apart:
Kwito processes personal data only to generate, send, receive, and archive e-invoices. We do not use any of it for analytics, advertising, profiling, sale, or AI training.
Because Kwito acts in two roles, the lawful basis differs by data type:
customers/redact request where no legal retention applies.shop/redact request
(48-hour grace), except the invoice archive, which is exported and made
available to the merchant and then deleted after their confirmation or 30
days. See the “Uninstalling” section of our
support page for what happens to the archive when
a merchant leaves.All invoice and buyer personal data is stored in the EU (Germany and Finland). We use the following sub-processors:
| Sub-processor | Role and personal data | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and encrypted backups (all invoice and account data) | Germany and Finland (EU) |
| Recommand | Certified Peppol access point (invoice transmission) | Belgium (EU) |
| Resend | Transactional email: VAT requests and accountant forwarding (email addresses) | EU data region |
| Migadu | Support and account mailbox hosting (email we exchange with you) | Swiss company; mailboxes hosted in France and Germany (EU) |
| Cloudflare, Inc. | Authoritative DNS for kwito.eu only; no invoice or personal data | United States |
We maintain a data processing agreement with each sub-processor. If we add or replace a sub-processor that handles personal data, we will update this list and, for merchants, give advance notice as described in our Data Processing Agreement so they can object.
Invoice and buyer personal data is stored and processed in the EU. Two providers involve a country outside the EEA, and each is covered by a lawful transfer mechanism:
Where a sub-processor with EU data residency is part of a group established outside the EEA, we rely on that provider’s Standard Contractual Clauses or Data Privacy Framework certification, as set out in its data processing agreement.
Data is encrypted in transit (TLS everywhere) and at rest (AES-256-GCM over buyer personal data, invoice XML, and PDFs). Access to decrypted buyer data is logged. Breaches are assessed and, where required, notified to affected merchants and to the CNPD within 72 hours (GDPR art. 33). Our breach notification commitments to merchants are set out in our Data Processing Agreement.
Buyers and merchants have the GDPR rights of access, rectification, erasure (subject to the 10-year invoice retention obligation), restriction, portability, and objection. Because Kwito is the processor for buyer data, a buyer should exercise these rights with the merchant who issued their invoice (the controller); we will assist that merchant in responding. For merchant account data, where Kwito is the controller, merchants may contact us directly at support@kwito.eu.
For merchant account data, our lead supervisory authority is the Commission nationale pour la protection des données (CNPD), Luxembourg (https://cnpd.public.lu). You have the right to lodge a complaint with the CNPD or with your local data protection authority.
We will update this policy as the service and its legal registration evolve; the “Last updated” date above reflects the current version.