New France e-invoicing mandate goes live September 2026 — our implementation is ready. See all mandates →
Security & Compliance

Your data is safe with us

Clearvo stores all invoice data in the EU, encrypts everything at rest and in transit, and is fully GDPR compliant. Here is exactly what we do — no vague claims.

GDPR compliant
EU data residency
AES-256 at rest
Peppol-certified Access Point

What we do to protect your data

These are the actual controls in place — not marketing assertions. If you need more detail for a vendor assessment, email security@clearvo.io.

Encryption in transit

All traffic between your systems and Clearvo is encrypted using TLS 1.2 or higher. Older protocols are disabled. Connections that do not meet the minimum are rejected.

Encryption at rest

Invoice data, customer records, and credentials are encrypted at rest using AES-256. Database encryption is handled at the storage layer — encrypted before it touches disk.

EU data residency

All data is stored in Azure West Europe (Netherlands region). No invoice data is replicated outside the EU. Our infrastructure runs entirely within the European Economic Area.

GDPR compliance

Clearvo acts as a data processor under GDPR. A Data Processing Agreement (DPA) is available on request for Growth and Enterprise plan customers — see pricing plans for details. We do not sell or share personal data.

Invoice data retention

Invoice records are retained for 7 years, in line with the EU VAT Directive requirement. You can export your full invoice archive at any time from your Clearvo dashboard.

SOC 2 Type II

We are working toward SOC 2 Type II certification. In the meantime, we are happy to complete security questionnaires and provide our current controls documentation for enterprise evaluations.

All data stays in the EU

We chose Azure West Europe as our sole cloud region deliberately. Every invoice submitted through Clearvo — including the raw payload, the authority response, and any linked attachments — is stored in the Netherlands (Azure West Europe).

We do not use US-based services that would transfer data outside the EU. Our database, blob storage, and message queues are all provisioned in West Europe.

  • Database: Azure PostgreSQL Flexible Server — West Europe
  • Blob storage: Azure Storage — West Europe
  • Message queue: Azure Service Bus — West Europe
  • Application hosting: Azure Container Apps — West Europe
  • No cross-region replication outside the EEA
Security at a glance
Data region Azure West Europe
(Netherlands)
Encryption in transit TLS 1.2+
Encryption at rest AES-256
GDPR Compliant
DPA Available on request
(Growth/Enterprise)
Invoice retention 7 years
SOC 2 Type II In progress
Peppol Access Point Certified

Testbed-certified Peppol Access Point

Clearvo is a certified Peppol Access Point, which means we have passed the formal compliance testing required to connect to the Peppol network and route invoices between buyers and suppliers in any participating country.

Peppol certification is not self-assessed — it is granted by OpenPeppol after an independent testbed evaluation. Our Access Point ID is publicly registered in the Peppol SMP directory.

  • BIS Billing 3.0 compliant invoice format
  • AS4 messaging protocol for secure document exchange
  • Registered in the OpenPeppol SML/SMP infrastructure
  • Supports all EU Peppol mandates (Belgium, Netherlands, and others)
Peppol Access Point
Clearvo Technologies Ltd
PIE001162
Testbed-certified by OpenPeppol. Registered in the Peppol SMP/SML directory. Supports BIS Billing 3.0 (UBL 2.1) over AS4 messaging. EU data residency — all Peppol documents routed through Azure West Europe.

Seven-year invoice retention — by default

EU VAT rules require businesses to retain invoice records for a minimum of 7 years (10 years in some member states). Clearvo automatically retains all submitted invoice data for 7 years from the invoice date, at no additional cost.

This includes the original invoice payload, the authority clearance response (where applicable), any rejection notices, and the full submission audit trail. You can search and export this data at any time from your dashboard.

If your jurisdiction requires a longer retention period, contact us — we can configure extended retention for Enterprise plan customers.

Questions or a vendor assessment?

If you have a specific security question, need us to complete a vendor questionnaire, or want to request a copy of our controls documentation, email our security team directly.

We aim to respond to security questionnaires within 2 business days.

Email security@clearvo.io →

Ready to get started?

Sign up and have your first invoice submitted in minutes. No credit card required.

Start for free →