GDPR
The General Data Protection Regulation, called AVG in Dutch, sets rules for processing personal data. This page explains practically how roles, responsibilities and privacy requests around Prepaidfactuur.nl work.
What is the GDPR?
The GDPR is European privacy legislation. Personal data is data that directly concerns someone or can be traced back to a person, such as a name, address, email address, customer data, VAT number or data on an invoice.
Why is this relevant for invoicing?
In Prepaidfactuur.nl, users can enter data about their own company, customers and contact persons. This includes invoices, quotes, customers, products, expenses, reports and email settings. That data must be processed and secured carefully.
Controller and processor
For customer and invoice data that the user enters themselves, the user is usually the controller. The user then determines why data is entered and how long the administration is needed. Prepaidfactuur.nl provides the technical environment and usually acts as processor for that data. For its own business operations, such as accounts, payments, security, support, logging and legal administration, OzHold may be controller.
Processing arrangements
When a user processes customers’ personal data via Prepaidfactuur.nl, arrangements may be needed about processing, security, confidentiality, subprocessors, data breaches and deletion or return of data. Contact [email protected] if you need agreements or clarification about this.
Important principles
- Transparency: users should be able to understand which data is processed.
- Purpose limitation: data is used for clear purposes, such as invoicing, account management, payments, support and security.
- Data minimisation: no more data is requested than needed for the selected functions.
- Accuracy: users can manage company, customer and document data in their account.
- Storage limitation: data is not kept longer than needed, taking statutory retention duties into account.
- Security: data is appropriately protected against loss, misuse and unauthorised access.
Data breaches
In the event of a possible data breach, we investigate what happened, which data is involved, what risk exists and whether notification to the Autoriteit Persoonsgegevens or data subjects is required. Users should report suspected misuse or unauthorised access as soon as possible.
Privacy rights
Users and data subjects may exercise rights under certain conditions, such as access, correction, deletion, restriction, portability and objection. For requests about customer data, Prepaidfactuur.nl may involve the user because that user is often responsible for that data.
No legal advice
This page is intended as a practical explanation. For specific questions about your role as controller, retention duties or international data processing, legal or privacy advice is recommended.

