By Glyf
EU-Hosted & GDPR Compliant
If a data-residency requirement is on your evaluation checklist, EU hosting isn't a box to tick after the demo. It's usually the first filter, before pricing or feature lists even get opened. Receipts and invoices carry more than totals: vendor relationships, purchase history, tax identifiers, sometimes addresses. A GDPR-compliant receipt scanner needs a straight answer about where that data lives, not a badge on a footer.
This page is a practical summary, not the legal source of truth. For the governing language, read our Privacy Policy and Terms of Service.
Where does Glyf actually store your data?
Our primary infrastructure and databases are hosted in the EU. That's the core of the hosting claim, and it's the detail most buyers check first when comparing tools. It's also what makes Glyf relevant to teams specifically searching for EU-hosted receipt extraction rather than sending day-to-day document storage somewhere unspecified. Precision matters here, though: some of our service providers may process data outside the EU or EEA for specific functions, and when that happens, we apply appropriate safeguards under applicable data protection law. So the accurate summary isn't "EU-only, full stop." It's this: our primary infrastructure and databases are hosted in the EU, with international-transfer safeguards applied where a provider requires processing outside it.
How GDPR-compliant invoice processing shows up in practice
A GDPR-compliant invoice processing claim only means something if it changes how the product behaves with real documents, not just how a privacy page reads. We process uploaded files to deliver the service you requested, then store the extracted data with your account so it's available in your history and exports. We share data only in the service-provider and legal scenarios described in our Privacy Policy, nothing broader than that. Documents you upload are never used to train the Data Extraction Engine, or any other model, for general product development. A few boundaries hold regardless of context: we don't sell personal information, access to production systems and user data is limited to authorized personnel, and no security control removes every risk. That last point stays in our policy on purpose, because absolute promises are the first thing that should make a buyer suspicious.
Retention, deletion, and access windows
This is where vague privacy pages usually fall apart, so the specifics matter more than the summary. Invoice images for Free and Trial accounts are automatically deleted 90 days after upload, while paid subscription accounts retain images for the duration of the subscription. Account deletion requests enter a 30-day grace period during which data is preserved and the request can be canceled; after that window, data is permanently removed. System backups and operational logs are purged on a rolling basis, typically within 30 to 90 days. Each of these is a distinct rule (how long images live, how long a deletion request can be reversed, how long backups persist), and each is documented in our Privacy Policy rather than left to interpretation.
Encryption and service-provider safeguards
Data in transit is protected with TLS (HTTPS), and stored data is encrypted at rest in our databases. Access to production systems and user records is restricted to authorized personnel, and the service providers we rely on operate under data protection and confidentiality terms. Where a provider processes data outside the EU or EEA, we apply the safeguards required under applicable law rather than treating cross-border processing as an afterthought. Encryption alone doesn't answer every question a serious buyer has. A good evaluation also asks how providers are vetted and what happens the moment data crosses a border. No internet service can honestly promise perfect security, and we say that directly in our Privacy Policy rather than implying otherwise.
What does this mean for audit and bookkeeping records?
For anyone using Glyf to hold onto supplier invoices, receipts, or VAT-heavy paperwork for later reference, retention and residency stop being background details the moment a request for records shows up: from an accountant, an auditor, or a tax authority. Knowing that primary storage sits in the EU, that deletion windows are documented, and that access to that data is restricted turns "can you prove where these documents live" into a page you can point to, instead of a conversation you have to improvise. If organizing those records for retrieval is the more immediate problem, see Audit-ready organization. If accuracy and review controls matter more right now, see Accuracy & quality controls.
A practical checklist
Short enough to use, specific enough to hold up:
- Primary infrastructure and databases hosted in the EU
- International-transfer safeguards applied where a provider requires processing outside the EU/EEA
- Documented retention and deletion windows, not open-ended storage
- Encryption in transit and at rest
- Restricted access to production systems and stored user data
- No sale of personal information, and no use of your documents to train models
Quick answers
Does "EU-hosted" mean no data ever leaves the EU? No, and we'd rather say that plainly than let a claim overreach. Primary infrastructure and databases are EU-based; some providers may process specific data outside the EU or EEA under required safeguards.
Are my documents used to train anything? No. Documents and extracted data are not used to train the Data Extraction Engine or any other model for general product development.
Where's the full legal detail? Use this page as the overview, then confirm exact terms in our Privacy Policy and Terms of Service. If you'd rather test the product first, try Glyf free. 15 analyses, no card required.