Privacy Notice
Last updated: May 2026
1. Controller contact
HermitTaxDE
Email: hello@kedalion.app
Public docs: /apps/hermittaxde/
2. Data we process
- Order data needed for invoice generation, including line items, prices, tax amounts, currency, and customer billing details.
- Store configuration data such as business identity, address, VAT settings, and invoice configuration.
- Billing status data supplied by Shopify's billing APIs. HermitTaxDE does not collect payment card details directly.
3. Why we process it
- To generate GoBD-aware invoice records and invoice documents.
- To create DATEV EXTF export batches for accountant handoff.
- To generate ZUGFeRD and related invoice artifacts where supported.
- To validate VAT-related configuration and support reverse-charge and related tax workflows where configured.
4. Legal basis
Processing is based on contract performance under Art. 6(1)(b) GDPR and, where relevant, legal obligations connected to German bookkeeping and retention requirements under Art. 6(1)(c) GDPR.
5. Retention
Invoice and related financial records are retained for the statutory period required by German tax law, which is generally 10 years. Where Shopify GDPR deletion workflows apply, personal data can be redacted while legally required financial records are preserved.
6. Processors and hosting
HermitTaxDE relies on Shopify as the commerce platform and uses infrastructure providers including Vercel and Supabase for hosting and data storage. The public product materials describe this service as operating on EU-hosted infrastructure for the released workflow.
7. Shopify GDPR requests
HermitTaxDE implements the Shopify GDPR webhook flows used for customer data requests, customer erasure handling, and shop erasure handling. Where financial retention duties apply, records may be anonymized or redacted rather than deleted outright.
8. Your rights
Depending on applicable law, merchants and affected data subjects may have rights of access, rectification, erasure subject to retention obligations, portability, and complaint to a supervisory authority. Contact hello@kedalion.app for privacy-related requests.