This Privacy Policy explains how BravoLisa collects, uses, shares and protects personal data when you visit our website, join our waiting list, create or use a BravoLisa account, communicate with us or use related services.

Part I. General Information and Scope

1. About this Privacy Policy

This Privacy Policy applies to the BravoLisa website, the BravoLisa application and related communications and services that refer to it. It should be read together with our Terms of Use, Cookie Notice, AI Use Notice and, where applicable, Data Processing Terms and any separate engagement letter for human accountant or tax services.

BravoLisa is designed primarily for self-employed professionals in Luxembourg and for professional or business use. The service may be technically accessible from other countries, but its functionality is designed around the needs of self-employed professionals in Luxembourg.

This Privacy Policy does not govern a third-party website or service that acts as an independent controller under its own privacy notice.

2. Who We Are

BravoLisa is operated by the person or entity identified in the About Us section of our website or application. That person or entity is the controller responsible for the processing described in this Privacy Policy when BravoLisa determines why and how personal data is processed. In this Privacy Policy, “BravoLisa”, “we”, “us” and “our” refer to that person or entity.

For privacy questions or to exercise your data protection rights, contact us at privacy [at] bravolisa [dot] lu.

3. Who This Privacy Policy Applies To

This Privacy Policy applies, as relevant, to:

BravoLisa is not intended for children. You must be an adult with legal capacity to use the service in your own name.

4. Our Different Data Protection Roles

4.1 BravoLisa as controller

BravoLisa generally acts as controller for personal data relating to your relationship with us, such as your account, authentication and service-use information, billing records, support communications, communication preferences, technical and security information, and records needed to operate and protect BravoLisa.

4.2 BravoLisa as processor

When you use BravoLisa to enter, upload, store, organise or analyse personal data about your clients, suppliers, invoice recipients or other third parties, you generally determine the purpose of that processing. For such data, you are the controller and BravoLisa generally acts as your processor, processing the data on your documented instructions and in accordance with our Data Processing Terms (annex to the Terms of Use).

4.3 Your responsibilities as controller

Where you act as controller, you are responsible for ensuring that you have an appropriate legal basis, provide required privacy information, respect data-subject rights and upload only information that you are entitled to process in this manner. You should not use BravoLisa as general-purpose storage or upload personal data that is irrelevant to your professional activity.

Part II. Personal Data and How We Use It

5. Personal Data We Collect

5.1 Website and waiting-list data

When you join our waiting list, we collect your email address, name (without any verification), and your field of professional activity (optional) and related records showing when and how you joined or left the list. When you visit the website, our infrastructure may process technical data necessary to deliver and secure the website, such as IP address, browser or device information, request timestamps and server logs.

Our website contact and waiting-list forms are operated for us by Formspree, a provider established in the United States, under a signed data processing agreement that includes the European Commission’s Standard Contractual Clauses.

Our tax calculator and free invoice generator operate in your browser. Based on the current design, BravoLisa does not receive, view, analyze or store the information you enter into those tools.

The cookies and similar technologies used on the website and in the application, the categories they fall into, the providers that set them and the consent we obtain where consent is required, are described in our Cookie Notice.

5.2 Account and authentication data

When you create and use an account, we process your name, email address, authentication identifier, account creation and update timestamps, and information connected with login and account security. We or our authentication and infrastructure providers may also process IP address, browser or device information, login history, failed login attempts, approximate location derived from technical data and related timestamps.

Authentication is currently provided through Clerk. Passwords and authentication sessions are managed by that provider and are not stored in the BravoLisa application database in readable form.

5.3 Business and Workspace data

“Workspace” means the dedicated environment within the BravoLisa application associated with a particular user and their business, in which business information, settings, records, documents and other data are stored, organised, processed and displayed.

We process information used to set up and operate your Workspace, including workspace and business names, legal name, business address, owner identifier, VAT and registration numbers and details, bank-display preferences, bank-account holder name, IBAN, BIC, bank name and other business settings. For a sole trader, this information may identify you personally.

5.4 Invoices, expenses and accounting records

Depending on the features you use, BravoLisa processes invoices, receipts, expenses, payments, allocations, ledger entries, VAT information, fixed assets, catalog items, labels, transaction descriptions, line items, amounts, currencies, dates, statuses and related bookkeeping records. These records may contain your personal data and personal data about clients, suppliers and other counterparties.

Uploaded attachments may include invoice scans, receipts, bank statements, PDFs, screenshots and other business records. File metadata may include the original filename, content type, storage path and an integrity or deduplication hash.

You can also forward invoices and receipts to us by email so that they can be read and added to your records. Inbound and outbound email is handled for us by Resend, which processes the sender or recipient address, the content of the message and any attachment, and delivery events.

5.5 Bank information

You currently upload bank files manually. BravoLisa does not collect or process your online-banking password or other banking login credentials and does not currently connect directly to your bank through open banking.

Uploaded bank statements may contain transaction amounts, direction, currency, dates, descriptions, counterparty names and IBANs, the original parser payload and classification or deduplication information. Bank information is used to provide bookkeeping and analytics to you, not to perform credit scoring or make lending decisions.

5.6 AI-related data

When you use an AI-assisted feature, we may process prompts, AI conversation history, conversation titles, timestamps, documents, extracted text, invoice and bank-transaction information, and relevant Workspace context. AI outputs and associated metadata are also stored as part of the feature where applicable.

5.7 Subscription, billing and payment data

BravoLisa may initially be offered in a beta period without a paid subscription. When paid plans or services become available, payments are expected to be processed through Stripe. BravoLisa may receive payment status, transaction identifier, card type, the last four digits of the card and billing address. BravoLisa does not receive the complete card number or security code.

BravoLisa may generate and retain invoices for its own services. Separate payment and engagement arrangements may apply to human accountant or tax services.

5.8 Support and communications

If you contact us, we process your email address, the content of your request, attachments you choose to provide and related correspondence. We also maintain records of service communications, marketing preferences, consents and opt-outs where applicable.

5.9 Special categories and irrelevant data

BravoLisa is not designed to collect biometric, health, religious, political or other special categories of personal data. Do not upload personal photographs, photographs of other individuals, biometric identifiers, unlawful content or sensitive information that is not strictly necessary for legitimate bookkeeping or business-administration purposes. Because free-text fields and documents are user-controlled, such information may nevertheless be included incidentally; if so, it will be processed only as necessary to provide the service and in accordance with the user's instructions where BravoLisa acts as processor.

6. How We Obtain Personal Data

We obtain personal data:

7. Why We Use Personal Data and Our Legal Bases

The legal basis depends on our role, the data and the purpose. Where BravoLisa acts as processor, the user's legal basis applies and BravoLisa processes data on the user's documented instructions. Where BravoLisa acts as controller, we rely on the bases below.

Personal dataPurposeLegal basis
Account, authentication and contact dataCreate and administer accountsPerformance of our contract; steps requested before entering a contract
Business, financial, document and usage dataProvide website, Workspace, bookkeeping, document and reporting functionsPerformance of our contract; user instructions where we act as processor
AI-related data and relevant Workspace contextProvide AI-assisted extraction, chat, categorisation and insightsPerformance of our contract; user instructions where we act as processor
Email and waiting-list recordsOperate the waiting listConsent
Billing and transaction dataProcess subscriptions, payments and our invoicesPerformance of our contract; compliance with legal obligations
Contact, account, service and correspondence dataProvide support and essential service communicationsPerformance of our contract; legitimate interests in supporting and administering the service
Email, preferences and consent recordsSend newsletters or promotional communicationsConsent, where required
Technical, authentication, log and relevant account dataSecure BravoLisa, prevent misuse and investigate incidentsLegitimate interests in protecting users, systems and the service; legal obligations where applicable
Relevant account, transaction, communication and audit recordsComply with law and establish, exercise or defend claimsLegal obligations; legitimate interests in protecting our legal rights
Feedback and usage information; anonymised AI and service informationImprove BravoLisaLegitimate interests for feedback and ordinary usage information; consent for identifiable or pseudonymised AI or service information used for product improvement; GDPR no longer applies once information is irreversibly anonymised

8. AI and Automated Processing

8.1 How AI is used

BravoLisa uses AI to extract and structure information from documents, categorise expenses and transactions, suggest invoice content, prepare summaries and insights, organise bookkeeping or tax-related information and respond through Lisa, the AI assistant.

AI chat is initiated by the user. When you upload an invoice, receipt or other supported document, AI-assisted extraction may start automatically. The interface displays AI information or a notice where data is processed using AI.

8.2 AI service providers

To provide AI features, BravoLisa sends relevant information to third-party large language model providers. Depending on the feature, this may include your prompt, conversation history, relevant Workspace data, invoices, bank transactions, documents or extracted text. We aim to limit the information sent to what is relevant for the requested function. The current providers and relevant processing details are available on request at privacy [at] bravolisa [dot] lu.

We may use specialist technical providers to record prompts and model responses for fault investigation and quality review. Those records may contain the same information that was sent to the model.

AI-provider processing is subject to the applicable provider terms and data-protection arrangements. Information about the relevant arrangements and safeguards is available on request at privacy [at] bravolisa [dot] lu.

8.3 Improvement and anonymised information

BravoLisa may use aggregated or irreversibly anonymised AI conversations or service information to analyse quality and improve the product. Information is treated as anonymous only where individuals are no longer identifiable by means reasonably likely to be used. If information remains pseudonymised rather than anonymous, we continue to treat it as personal data and use it for product improvement only with your separate opt-in.

8.4 No significant automated decisions

BravoLisa does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. AI outputs support your own review and decisions. They may be inaccurate or incomplete and must be checked before use.

8.5 Your controls and responsibilities

You can delete individual AI conversations through the interface. Deleted conversations may remain temporarily in backend systems and backups until the applicable deletion cycle completes. Do not provide irrelevant or sensitive personal data in AI prompts or uploads.

More information about AI functionality and limitations is available in our AI Use Notice.

Part III. Disclosure and International Data Processing

9. When We Share Personal Data

We disclose personal data only where necessary for the purposes described in this Privacy Policy, where you instruct or authorise us to do so, or where disclosure is required or permitted by law.

9.1 Service providers

We use providers for hosting and infrastructure, authentication, file storage, AI processing, email, website forms, error monitoring, payments, security and technical support. Depending on the activity, providers may act as processors, sub-processors or, for limited activities, independent controllers. A current list of relevant providers is available on request at privacy [at] bravolisa [dot] lu.

Where a provider processes personal data on our behalf, we put in place data processing terms meeting the requirements of Article 28 GDPR, restrict processing to documented purposes, require confidentiality and security measures, and regulate subprocessors and international transfers.

9.2 Human accountant and tax services

A human accountant or tax service may be available separately on individual terms if requested. Such services are provided by an individual professional accountant and are governed by a separate engagement letter. Relevant Workspace information may be made available to the professional accountant only as necessary for the requested service and subject to the applicable engagement, professional obligations and privacy information. The professional accountant's data protection role will depend on the service and will be explained where the service is arranged.

9.3 Authorities, advisers and legal disclosures

We may disclose relevant personal data to courts, regulators, law-enforcement or public authorities, professional advisers, insurers or other parties where necessary to comply with law, respond to a valid request, protect users or systems, investigate misconduct, recover amounts due, or establish, exercise or defend legal claims.

9.4 Business transfers

If BravoLisa is involved in a restructuring, merger, acquisition, financing, sale of business or assets, or transfer of the service, relevant personal data may be disclosed to advisers and prospective or actual participants subject to appropriate confidentiality and data protection safeguards.

10. International Data Transfers and Remote Access

10.1 EEA processing

Some of the providers we use, and authorised personnel supporting BravoLisa, may access or process limited personal data outside the EEA. Where this occurs, we use an applicable lawful transfer mechanism under Chapter V GDPR and appropriate safeguards, as described in section 10.3.

10.2 Authorised founding-team access outside the EEA

Access to production systems is restricted to authorised personnel through named accounts and appropriate technical and organisational safeguards, including access controls, logging and confidentiality obligations. Where access takes place from outside the EEA, the safeguards described in section 10.3 apply.

10.3 Transfer safeguards

If personal data is transferred or made accessible outside the EEA, we use one of the lawful transfer mechanisms permitted by Chapter V GDPR, as appropriate to the relevant transfer. This may include an adequacy decision, European Commission Standard Contractual Clauses and supplementary safeguards. You may contact privacy [at] bravolisa [dot] lu for information about applicable safeguards.

Part IV. Data Governance and Protection

11. How Long We Keep Personal Data

We keep personal data only for as long as reasonably necessary for the relevant purpose, to follow your instructions where we act as processor, to comply with legal or professional obligations, and to establish, exercise or defend legal claims. Retention periods may differ by category and context. The retention of business records and third-party data is governed by the Data Processing Terms and the deletion process in the Terms of Use.

CategoryRetention approach
Account and WorkspaceWhile the account is active. After closure, personal data is scheduled for deletion from active systems within 30 days, except records that must or may lawfully be retained.
User bookkeeping data and uploaded filesWhile needed to provide the service and thereafter according to the user's instructions and Data Processing Terms. After account closure, the 30-day active-system deletion cycle generally applies, subject only to a separate lawful retention obligation or a separately agreed archiving arrangement.
AI conversationsUntil deleted by the user or the account is closed, followed by the applicable 30-day active-system and backup deletion cycles.
BackupsDeleted data may remain in protected backups until overwritten through the normal backup cycle, for no longer than 90 days.
BravoLisa billing and transaction recordsFor the period required by applicable accounting and tax law.
Waiting-list and marketing recordsUntil consent is withdrawn or the relevant purpose ends; limited consent and opt-out evidence may be retained for compliance.
Security and application logs12 months from creation, unless a longer period is needed to investigate a specific incident or to establish, exercise or defend legal claims.
Support correspondence24 months from the close of the request, unless a longer period is needed to establish, exercise or defend legal claims.
Privacy and deletion requestsFor as long as reasonably necessary to document and demonstrate our response and protect legal rights.

11.1 Account closure and deletion

Closing an account does not always require immediate deletion of every record. We may retain limited records such as our own invoices, evidence of a deletion request, essential account identifiers, consent records and relevant correspondence where necessary for legal compliance or the protection of legal rights. We do not retain the full account merely because a limited record must be kept.

Data scheduled for deletion is removed from active systems within 30 days. It may remain inaccessible in protected backups until the backup is overwritten, for no longer than 90 days. Backup copies are not restored for ordinary business use after deletion.

Because unauthorised account closure or deletion could harm the account holder, compromise business records or affect the rights of other persons, we take reasonable steps to verify the identity and authority of the person making the request. Where we have reasonable doubts or identify a risk of an unauthorised request, we may ask for additional information or apply other proportionate verification measures. These may include asking you to submit the request through your account or registered email address, re-authenticate, complete a security check or, where less intrusive measures are insufficient, provide a copy of an official identity document. We will request only the information necessary for verification and will use it solely to verify the request and prevent fraud. Any identity document collected for this purpose will be deleted once verification is complete, unless limited retention is required by law or to establish, exercise or defend legal claims. We may postpone account closure or deletion until the verification process has been completed.

12. How We Protect Personal Data

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the system and risk, these include:

No method of storage or transmission is completely secure. You are responsible for keeping your credentials confidential and notifying us promptly if you suspect unauthorised use of your account.

13. Personal Data Breaches

We maintain procedures to assess and respond to suspected personal data breaches. Where BravoLisa acts as controller, we notify the competent supervisory authority and affected individuals when GDPR requires us to do so. Where BravoLisa acts as processor, we notify the relevant user-controller without undue delay and provide reasonable assistance in accordance with our Data Processing Terms.

Part V. Your Rights and Choices

14. Your Data Protection Rights

Subject to the conditions and exceptions in GDPR, you may have the right to:

These rights are not absolute. For example, we may retain information that we are legally required to keep or that is necessary for the establishment, exercise or defence of legal claims.

15. How to Exercise Your Rights

Send your request to privacy [at] bravolisa [dot] lu. We normally respond without undue delay and within one month after receiving a valid request. Where a request is complex or numerous, GDPR may allow us to extend the response period by up to two additional months; if so, we will inform you within the first month and explain the reason.

We may request information reasonably necessary to confirm your identity where we have reasonable doubts. We will not request more information than needed for verification.

GDPR requests are generally free of charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable administrative fee or refuse to act, as permitted by law.

Commercial or plan-specific export tools may differ from the free rights of access and data portability provided by GDPR. Your ability to exercise a GDPR right does not depend on purchasing a paid export feature.

16. Data Uploaded by a BravoLisa User

If your personal data appears in BravoLisa because a user entered or uploaded it as part of their bookkeeping or business records, that user will normally be the controller and BravoLisa will act as processor. You should ordinarily direct your request to that user. If you contact us, we may ask for information needed to identify the relevant user or Workspace, refer your request to the controller and assist the controller as required by our Data Processing Terms.

17. Communications and Cookie Choices

17.1 Essential service communications

We may send communications necessary to operate and administer your account, including account, authentication, security, service, billing, price and legal-document notices. You cannot opt out of communications that are necessary to maintain an active account, although you may close your account subject to the Terms of Use.

17.2 Marketing communications

We do not plan to send a marketing newsletter at launch. If newsletters or promotional feature communications are introduced later, we will use your email for them only with the consent or other lawful permission required by applicable law. You can unsubscribe at any time using the link in the message or by contacting us.

17.3 Tax reminders and optional notifications

Where available, optional tax-deadline reminders and similar notifications can be enabled or disabled through the communication settings provided in the service.

17.4 Cookies and similar technologies

The website and application use cookies and similar technologies for functionality, authentication, security, user preferences and analytics. Which technologies are used, which providers set them, which require your consent and how you can give or withdraw that consent are set out in our separate Cookie Notice.

18. Complaints

Please contact us first at privacy [at] bravolisa [dot] lu so that we can try to resolve your concern. You also have the right to lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work or the place of an alleged infringement.

In Luxembourg, the supervisory authority is the Commission nationale pour la protection des données (CNPD), 15, boulevard du Jazz, L-4370 Belvaux, Luxembourg, www.cnpd.public.lu.

Part VI. Final Provisions

19. Professional Use and Age Restrictions

BravoLisa is intended for professional and business use by adults aged 18 or over, primarily self-employed professionals in Luxembourg. It is not intended for children, and a person who is not legally able to enter a binding agreement in their own name must not create an account.

20. Changes to this Privacy Policy

We may update this Privacy Policy when our service, providers, processing activities or legal requirements change. The current version will be available through the website or application. If a change materially affects how we use personal data, we will provide an appropriate notice before the change takes effect and request consent where a new processing activity requires it.

21. Contact Details

Controller: the person or entity identified in the About Us section of the website or application.

Privacy contact: privacy [at] bravolisa [dot] lu