Data protection

Privacy policy

Controller

Heaviside Solutions
Owner: Christopher Heaviside
Roßschwemme 14
6200 Jenbach
Tirol, Austria
Email: Support@Heaviside-solutions.com
Telephone: +436766603474

Data processed by BillDrift

BillDrift may process account information such as your name and email address, authentication information, billing references, audit results and technical information required to operate and protect the service.

Uploaded and assisted audit files

CSV and XLSX files submitted through the self-service workflow, or supplied directly to the BillDrift operator for an explicitly requested assisted audit, are processed to generate the reconciliation result. Raw uploaded source files are processed transiently and are not intentionally stored by BillDrift.

For an assisted audit received outside the self-service flow, BillDrift requires a clear written request or permission from the company to perform the audit. The company should provide only data it is authorized to share for that purpose and remove irrelevant personal data where practical.

Normalized audit summaries and findings may be stored in the authenticated customer or operator account so that the result can be reviewed, delivered and exported. An authenticated user can permanently delete an individual stored audit result without deleting the BillDrift account or unrelated saved audits.

Free preview

BillDrift uses a one-way technical identifier and a browser cookie to apply free-preview cooldowns and prevent abuse of the service. The browser cooldown is 30 days. A hashed technical connection identifier may additionally prevent another free preview from the same connection for 24 hours. Raw IP addresses are not intentionally stored in the FreeTrial record. Technical FreeTrial records older than 30 days are removed during subsequent free-preview processing.

Abuse prevention and rate limiting

BillDrift uses temporary rate-limit records to restrict repeated requests to sensitive or resource-intensive functions such as account creation, sign-in, password recovery, audits, checkout and billing actions. Stored rate-limit records contain an opaque, secret-keyed technical identifier, a request count and expiry timestamps. Raw IP addresses and email addresses are not intentionally stored in these rate-limit records.

Rate-limit windows currently last no longer than 15 minutes. Expired records no longer restrict requests and are removed during subsequent rate-limit processing.

Account and contract processing

Account and subscription data are processed where necessary to create and administer an account, provide purchased services, maintain audit allowances and fulfil contractual obligations.

Purposes and legal bases

Where the GDPR applies, account creation, authentication, purchased access, audit delivery and subscription administration are processed where necessary to take steps at your request or perform a contract (Article 6(1)(b) GDPR).

Payment, tax, accounting and compliance records may be processed where necessary to comply with legal obligations (Article 6(1)(c) GDPR). Security, abuse prevention, rate limiting and limited service-usage measurement may be processed on the basis of BillDrift's legitimate interests in protecting, operating and improving the service (Article 6(1)(f) GDPR), where those interests are not overridden by the rights and freedoms of affected individuals.

Where a particular processing activity requires consent under applicable law, BillDrift relies on that consent. Consent can be withdrawn for the future without affecting processing that was lawful before withdrawal.

Recipients and service providers

Personal data may be shared, where necessary for the relevant purpose, with categories of service providers including hosting and content-delivery providers, database infrastructure providers, payment and merchant-of-record providers, transactional-email providers and privacy-focused analytics infrastructure. Data may also be disclosed where required by law or necessary for the establishment, exercise or defence of legal claims.

International data transfers

Some infrastructure or payment providers may process data in countries outside the European Economic Area. Where the GDPR applies and a transfer requires additional safeguards, BillDrift relies on the transfer mechanism applicable to the relevant provider and processing, such as an adequacy decision or appropriate contractual safeguards. Information about applicable safeguards can be requested using the contact details above.

Information required to provide the service

Account credentials are required to create and secure a paid BillDrift account. The audit files and fields identified in the upload workflow are required to perform the requested reconciliation. Information required by Stripe/Link for payment is handled through their checkout. If information necessary for a requested service is not provided, BillDrift may be unable to provide that service.

Automated processing

BillDrift applies deterministic reconciliation rules to the structured files supplied for an audit. BillDrift does not use those audit rules to make an automated decision about an individual that produces legal or similarly significant effects on that individual on BillDrift's behalf.

Payments

Payments are processed by Stripe. BillDrift receives payment, customer and subscription references required to grant access and manage billing. Payment-card details are handled by Stripe and do not pass through BillDrift servers.

Hosting and database infrastructure

BillDrift uses external infrastructure providers to host the application and database. These service providers may process technical or account data as necessary to provide their services.

Usage measurement and product analytics

BillDrift uses Vercel Web Analytics to measure aggregated website traffic and understand which pages and tools are used. Before a Vercel Analytics page-view event is sent, BillDrift removes query parameters and URL fragments from the page URL. This is intended to prevent checkout references, password-reset tokens and other query data from being transmitted through the analytics URL.

BillDrift also uses PostHog for limited product analytics. PostHog receives only deliberately defined coarse interaction events used to understand the audit and checkout funnel. BillDrift disables PostHog autocapture, automatic page-view and page-leave capture, rage-click capture, automatic performance and Web Vitals capture, automatic exception capture, session recording and remote feature configuration. The BillDrift client does not enable PostHog console-log capture.

The PostHog client uses in-memory persistence rather than persistent browser storage. It is configured never to create PostHog person profiles. Permitted client and server analytics events are explicitly marked for anonymous processing.

BillDrift permits only its deliberately defined audit, pricing and checkout funnel events to leave the PostHog client. Other PostHog events are rejected before transmission.

Before a permitted PostHog event is sent, BillDrift removes query parameters and URL fragments from PostHog URL and referrer fields.

BillDrift may record coarse interaction events such as whether an audit was started or completed, whether a free result was reached, whether pricing was viewed or opened from an audit result, whether an account was successfully created, and whether a day-pass or monthly checkout step was opened or started. BillDrift may also record server-confirmed coarse lifecycle events when a paid purchase completes, when the first or second paid audit completes, when a Monthly customer completes an audit in a later billing period, or when subscription cancellation is successfully scheduled. These events use only limited labels such as free or paid access and the selected offer type.

Analytics events do not intentionally include names, email addresses, account identifiers, uploaded file names, uploaded file contents, invoice values, audit findings, order references or customer type.

Analytics providers may process limited technical metadata associated with event delivery, such as browser, operating system, device information, referrer or approximate location. This information is used to understand traffic, improve the service and evaluate which BillDrift resources are useful.

Retention

Personal data is retained only for as long as it is required for providing the service, maintaining contractual and billing records, protecting the service against abuse, or complying with applicable legal obligations.

For operator-assisted audits, normalized audit results and findings may remain in the authenticated operator account while the requested audit is reviewed and delivered. Individual saved audit results can be permanently deleted when they are no longer required for that workflow.

Account deletion

Authenticated users can request account deletion from the customer dashboard. When deletion is confirmed, BillDrift disables account access, removes saved audit results and password-reset tokens, detaches account attribution from custom analytics events, and replaces the account profile identifiers with a non-deliverable technical tombstone.

If a monthly subscription is active, BillDrift attempts to schedule the subscription to stop renewing before completing the account deletion. Limited transaction, subscription, checkout-consent, Stripe customer or payment references and similar records may remain where needed for payment reconciliation, accounting, dispute handling or applicable retention obligations. These retained records are not used to restore access to the deleted BillDrift account.

Your rights

Depending on the applicable data-protection law, you may have rights including access, correction, deletion, restriction, objection and data portability. You may also lodge a complaint with a competent data-protection supervisory authority. In Austria, the supervisory authority is the Austrian Data Protection Authority (Datenschutzbehörde).

To exercise a privacy right or ask a data-protection question, contact Support@Heaviside-solutions.com.