Privacy

What is collected, and why

Written to agree with the GDPR and Sub-processors pages rather than to restate them differently.

What is collected

DataWhy
Name and email of the people who sign inAuthentication, attribution of changes, and contacting you about the service
Company name, address and VAT numberInvoicing. VAT number is required. itbudgit sells to businesses only
Everything you enter into a workspaceThis is the service. It may include employee names and salary figures if you use the staffing features
Server logsSecurity and diagnosis. They contain IP addresses and request paths

No behavioural analytics are collected. There is no tracking pixel, no session recording, and no product-usage telemetry.

Payment details

Card details are entered at Stripe and never reach our servers. We store the Stripe customer and subscription identifiers, the plan, and the current billing period.

Who it is shared with

Only the sub-processors listed on Sub-processors, each for the purpose stated there. Nothing is sold, and nothing is shared for advertising.

How long

See GDPR, which states each retention period and why. In summary: workspace for the life of the subscription, revision history 12 months, billing records kept as a legal obligation.

Getting your data out

Export a workbook, any time, with no request and no waiting. The file is a normal .xlsx, it opens in Excel, and it restores everything including teams, allocation keys and users. This is deliberate: a product about defending numbers should not hold them hostage.

Your rights

Access, rectification, erasure, restriction, portability and objection. See GDPR for how each is handled, including the parts of erasure that are legally constrained. Complaints may be made to the Dutch data protection authority (Autoriteit Persoonsgegevens).


Security & compliance: Trust · Security · GDPR · Sub-processors · DPA · Privacy · Terms · Cookies

Questions a page here does not answer: get in touch.