Privacy policy
Last updated: 18 May 2026
This document describes how we process personal data when you use the online platform billo.ge (creating, saving and downloading invoices as PDF, templates, client and product lists, electronic signature and related features). For browser cookies and similar technologies, see the separate page: Cookie.
1. Who “we” are and what we do
billo.ge is a software platform – a technical service you use for your own business. The platform is not your legal adviser or accountant; personal data is processed so that the service works and stays secure.
If a specific legal entity (e.g. an LLC or a sole trader) operates the platform, the data controller in practice is the person/organisation that determines the purposes of processing; technical parties may include hosting and infrastructure providers. In this document, “we” means the platform operator together with the technical services it engages, as is usual for the SaaS model.
2. Definitions
- Personal data – any information about a living person that identifies them directly or indirectly (e.g. name, email, phone, IP address in a certain context).
- Processing – any operation on data (collection, storage, modification, deletion, transfer, access, etc.).
- User / you – a person who uses the platform (registered or, where allowed, a guest).
3. What categories of data we collect
3.1. Account and authentication
When you sign up and sign in: email (or username, where applicable), full name (if you provide it), a cryptographic hash of your password (not the password itself), account creation/sign-in time. If you use Google OAuth, we receive the identifier and email that Google shares with us within the scope of your consent – details are in Google's policy.
3.2. Business content you enter yourself
Company card (name, code, address, bank details, logo as an image, colour), client list, products/services, the full content of invoices (lines, amounts, taxes, due dates, status, notes, terms), templates, draft, history. This data may include personal data of your clients – you are responsible for having a lawful basis to process it (contract, consent, business necessity, etc.).
3.3. Electronic signature
If you use the signature feature: the signature image (as a data URI), the method (typed/drawn), the chosen font, the saved profile name and the version of the consent text. When a PDF is downloaded, an audit record may be created: account identifier and email (snapshot), company name and ID, invoice number, a cryptographic hash of the document content, a hash of the signature image, time, IP address and User-Agent string. IP and User-Agent are technical data and may be treated as personal data under regulations such as the GDPR.
3.4. Technical and log data
The server may keep request logs (URL, time, status, IP, error message of limited length) to ensure security, fight abuse and diagnose problems.
4. Legal basis and purposes of processing
Personal data is processed:
- to perform the contract – to provide what you use the platform for (account, invoice storage, PDF);
- for legitimate interests – security, fraud prevention, service stability, aggregated analytics (where used);
- to meet legal requirements – if law enforcement or a court requests it within lawful limits.
At this stage we do not carry out advertising profiling or automated decisions that significantly affect you.
5. Storage, retention and deletion
Invoices and related data are kept until you delete them (e.g. move them to “Trash” and then delete them permanently) or until the account is deleted. Server logs may be kept temporarily (e.g. several weeks/months), depending on infrastructure settings. Backups (if any) must be protected to the same standard.
6. Sharing and subprocessors
We do not sell personal data. Data may be transferred:
- to hosting, database and CDN providers – only to the extent required for the service;
- to email/authentication providers (e.g. Google OAuth);
- where required by law – to public authorities, on the basis of a court order or a lawful request.
7. International transfers
Servers or backup copies may be located outside Georgia (e.g. in a European or US cloud). In such cases we try to follow industry-standard safeguards; if you have special requirements, review your host's policy or contact us.
8. Security
We use HTTPS, restricted server access, password hashing, CSRF protection and other standard practices. Nevertheless, absolute “zero risk” is impossible for an internet service – we recommend a strong password, two-factor authentication (when available) and keeping additional copies of your data.
9. Your rights
Under Georgian law and applicable standards (e.g. some principles of European regulation), you may have the right to:
- see the data we hold about you (access request);
- request correction if data is inaccurate;
- request deletion or restriction of processing where the law allows;
- request an export in a machine-readable format where technically possible.
Use the contact channel indicated on the platform for requests. The response time may depend on the complexity of the request and the steps needed to verify your identity.
10. Minors
The platform is not intended for independent use by persons under 16. If you learn that a minor has created an account, please contact us so that it can be deleted.
11. Changes to this policy
We may update this document (e.g. when a new feature is added). The date at the top reflects the latest revision. For significant changes you may receive an additional notice on the platform or by email – depending on what is technically possible.
12. Contact
For privacy questions, write to info@billo.ge or call +995 595 14 06 23.
This text is for information only and does not replace legal advice. For a specific situation, consult a lawyer. This is a translation; in case of discrepancies, the Georgian version prevails.