---
title: "Privacy — PeppolStatus"
description: "How PeppolStatus handles data: server logs and IPs for security and rate limiting, Clerk accounts on the app console, API-key usage records, and hosting on Cloudflare. Operated by E-Invoice BV; full policy at e-invoice.be/legal/privacy."
canonical: "https://peppolstatus.com/privacy/"
last-updated: 2026-08-11
---

# Privacy at PeppolStatus.

PeppolStatus is a mostly read-only site for measuring the Peppol network. It
collects very little about you. This notice says plainly what it does process, and
defers to the operator's full privacy policy for the complete detail.

Last updated 2026-08-11.

## Who is responsible

PeppolStatus is operated by **E-Invoice BV** (trading as e-invoice.be), the data
controller:

E-Invoice BV
Brusselsesteenweg 119/A, 1980 Zemst, Belgium
VAT BE1018.265.814

For any privacy question or request, email
[hello@peppolstatus.com](mailto:hello@peppolstatus.com) or write to the address
above.

## What this site processes

The public website, dashboard, and docs on peppolstatus.com are read-only and do
not ask you to sign in. Across peppolstatus.com and its subdomains, we process:

- **Server logs and IP addresses.** Requests to the site and to the API at
  [api.peppolstatus.com](https://api.peppolstatus.com) are logged. IP addresses are
  processed to keep the service secure and to enforce per-IP rate limits on the API.
  The lawful basis is our legitimate interest in operating and protecting the
  service.
- **Account data on the app console.** The app console at
  [app.peppolstatus.com](https://app.peppolstatus.com) uses
  [Clerk](https://clerk.com) for authentication. If you create an account, Clerk
  processes your sign-in credentials and profile on our behalf so you can log in and
  manage access.
- **API-key usage records.** When you use an API key, we record its usage to apply
  your plan's rate limits and quotas and to protect the API from abuse.

We do not run advertising or third-party analytics, and the site sets no tracking
cookies. Sign-in on the app console uses only the cookies Clerk needs to keep you
logged in.

## The Peppol data we display

The network data shown on PeppolStatus — participants, access points, SMPs,
certificates, and change events — is derived from **public Peppol infrastructure**
(the SML and SMP directory) and from **official business registries**. It is
public-register information about organisations on the network, not data that
individuals submit to us. If a record about your organisation looks wrong, email
[hello@peppolstatus.com](mailto:hello@peppolstatus.com) and we will look into it.

## Hosting and processors

The site and API run on **Cloudflare**, which hosts and serves the service and
processes request data (including IP addresses) as our hosting provider on our
behalf. Clerk processes account data for the app console, as described above. The
operator's full privacy policy lists the processors we rely on.

## Your rights

Under the GDPR you have the right to access, rectify, or erase your personal data,
to restrict or object to processing, and to data portability. To exercise any of
these, email [hello@peppolstatus.com](mailto:hello@peppolstatus.com) or write to
E-Invoice BV, Brusselsesteenweg 119/A, 1980 Zemst, Belgium. You also have the right
to lodge a complaint with the Belgian Data Protection Authority.

## The full policy

This page is a short, site-specific notice. For the complete detail — retention
periods, the full list of processors, international transfers, and the operator's
terms — see the policies published by the operator, E-Invoice BV:

- [Full privacy policy](https://e-invoice.be/legal/privacy)
- [Terms](https://e-invoice.be/legal/terms)
- [Contact](/contact/)
