Launch offer: every feature free until 1 Dec 2026 — no card required. See plans

Privacy policy

Effective 5 August 2026.

Aries is business software for issuing and receiving documents, catalogs and a construction module. To work, it has to process data — this policy says which data, why, where and for how long, and what rights you have. It is written to actually be read.

1. Controller

The controller of personal data is Batt Crew d.o.o., Podpeška cesta 132, 1351 Brezovica, Slovenia, VAT ID SI26860813 ("Aries", "we").

For any privacy question or to exercise your rights, write to hello@usearies.io.

2. What data we process

  • Account data: email address, name, password (stored only as a secure hash), interface language.
  • Company data: name, address, tax and registration numbers, IBAN, logo, signature — what you enter so it appears on your documents.
  • Business content: documents you create or upload (invoices, offers, received invoices, BOQs …), your partners, catalog, projects.
  • Subscription data: chosen plan and modules; payment (card) data is processed exclusively by Stripe — we never see or store card numbers.
  • Technical data: IP address, request time and type in server logs, essential cookies (login session, chosen language).

3. Why, and on what legal basis

  • Performance of the contract: everything the app does — creating documents, reading received invoices, sending email on your behalf, VAT computations (Art. 6(1)(b) GDPR).
  • Legal obligations: retention of accounting records and tax data as required by Slovenian VAT and accounting law (Art. 6(1)(c)).
  • Legitimate interest: service security, abuse prevention, debugging (Art. 6(1)(f)).

We send no marketing without your consent and we never sell your data.

4. Data inside your documents — our processor role

Your documents often contain personal data of third parties: your customers’ contacts, sole traders, invoice recipients. For that data you are the controller, and Aries processes it strictly on your instructions as a processor — to make the app work, and for nothing else.

When you submit a document for automated reading (e.g. a photo of a received invoice), it is sent for that purpose to an AI provider listed in section 5. Reading happens only when you trigger it; these providers do not use your content to train their models.

5. Our processors

We use carefully chosen providers to run the service:

  • Railway (USA) — server and database hosting.
  • Vercel (EU/USA) — web application hosting.
  • Cloudflare (EU/USA) — file storage (logos, PDFs, uploaded attachments).
  • Resend (USA) — email delivery (confirmations, documents you send to clients).
  • Stripe (EU/USA) — subscription payments and our invoices for them.
  • Anthropic and xAI (USA) — automated document reading, only when you trigger it.

We have a data-processing agreement with every processor.

6. Transfers to third countries

Some of the providers above process data in the USA. Transfers rely on the EU-US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.

7. How long we keep data

  • Account data: for as long as you have an account; removed within 30 days of deletion.
  • Business documents: for as long as you keep them in the app. They are accounting records with statutory retention of up to 10 years — export them before closing your account, because we cannot restore them after deletion.
  • Server logs: at most 90 days.

8. Your rights

You can at any time request access to your data, its correction, deletion, restriction of processing, portability, or object to processing. Write to hello@usearies.io; we respond within 30 days. You can also export all your documents and partners yourself, directly in the app.

If you believe we process your data unlawfully, you may complain to the Slovenian Information Commissioner (Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si).

9. Cookies

We use essential cookies only: the login session and your chosen language. There are no analytics, advertising or tracking cookies — which is why there is no cookie banner.

10. Security

Data travels encrypted between you and the servers (TLS), passwords are stored as secure hashes, and access to production systems is restricted and audited. If a personal-data breach could put you at risk, we notify you as the GDPR requires.

11. Changes to this policy

For material changes we notify you by email or in the app at least 15 days before they take effect. The version published on this page is always the one that applies.