Privacy policy
Updated: 2026-08-25
Numerio processes only the data the service needs in order to work — we process almost nothing about website visitors (no tracking, just one functional language-preference cookie), and for pilot-programme users we see only the emails and attachments that look like invoices, plus the bank statements you upload yourself. Mailbox access is read-only and you can disconnect it at any time. We keep data in the EU only. No automated decision affects you without human review. This summary is an explanation only and is not legally binding — the binding text is below.
1. Data controller
The data controller is MB „Blue age lab", company registration number 306656523, VAT number LT100016571516, registered office at Saulėtekio al. 15-1, LT-10224 Vilnius, Lithuania (hereinafter — Numerio or we).
To contact us about privacy matters:
- by email: hello@numerio.ai
- by phone: +370 5 208 0417
2. Who this policy applies to
This policy describes how we process personal data:
- when you visit our website numerio.ai (website visitors);
- when you take part in the Numerio pilot programme as a registered user (pilot-programme users).
Numerio is currently at pilot stage — the service has not been publicly launched. Real customer data is only connected after the data-processing terms have been expressly agreed with the individual pilot participant (see section 4).
3. Data about website visitors
The numerio.ai website uses no tracking, analytics or marketing cookies. The only cookie it stores is the functional language-preference cookie numerio-lang: it is written only when you yourself click the language switcher; it holds nothing but the value lt or en; it lasts one year; and it contains no identifier by which you could be recognised or tracked. Such a cookie is strictly necessary to carry out a preference you have explicitly expressed, and therefore requires no separate consent under EU ePrivacy rules.
For traffic statistics we use an EU-hosted, cookieless analytics service that does not identify any individual — which is why we show no cookie-consent banner on the website: none is needed.
If you write to us by email (hello@numerio.ai) or send an early-access request by email, we process the contact details you provide (name, email address, company name, message content) solely in order to answer your enquiry or consider your request.
Legal basis: our legitimate interest in answering enquiries and developing the service (GDPR Article 6(1)(f)).
4. Data about pilot-programme users
When you join Numerio as a pilot participant, you create an account and can connect data sources. The categories of data processed are:
| Data category | What it covers specifically | Source |
|---|---|---|
| Account data | Name, email address, company details, sign-in events | Data you provide / sign-in through Google |
| Mailbox content | Only invoice-related emails and their attachments — identified by automated but assistive selection | Gmail (through Google OAuth) or iCloud Mail (through an Apple app-specific password) |
| Data extracted from documents | Supplier name, invoice number, amount, date, VAT and other fields present on the invoice | Automated document extraction, ultimately confirmed by a human |
| Bank statement lines | Lines from bank statement files you upload yourself, used only to match invoices against payments | Files you upload |
Just as important is what Numerio does not process:
- Numerio never connects directly to your bank account and takes no payment actions — we work only with the bank statement files you upload yourself.
- Numerio does not reach into your whole mailbox — access is read-only, and our system selects only invoice-related correspondence.
4.1 Mailbox access — how it works
- Access to Gmail is granted through Google OAuth, and access to iCloud Mail through an app-specific password generated by Apple. In both cases access is read-only — Numerio cannot send, delete or change your mail.
- Credentials (OAuth access tokens and Apple passwords) are stored encrypted, are not accessible to unauthorised persons, and never appear in logs.
- You can disconnect a mailbox at any time in your account settings. When you do: no new mail checks are started; if the mailbox was Gmail, Numerio revokes its own access through Google (which invalidates the Google access token at the same time), and the local credential is deleted once the revocation is confirmed; if the mailbox was iCloud, we cannot revoke access remotely (Apple offers no such facility) — we delete the password we hold from our system immediately and show you how to revoke the password itself at account.apple.com; data already collected into the Numerio system before disconnection (for example invoices already processed) continues to be retained under section 6, unless you delete the whole workspace.
- Unselected, non-invoice mail content is never stored as raw copies — Numerio does not accumulate an archive of your whole mailbox.
4.2 Automated extraction and human review
Invoice data is recognised by an automated system, but that system never makes the final decision without a human:
- Every extracted field is assigned a confidence level (low, medium, high).
- Low-confidence fields always require review; medium-confidence fields show a warning; and even high-confidence data becomes confirmed only when a person accepts it.
- No confidence level by itself generates or sends the accountant package — that is always done by a person, through a deliberate action.
This means that, for the purposes of GDPR Article 22, Numerio does not take decisions producing legal effects concerning you or similarly significantly affecting you based solely on automated processing — data extraction is an assistive tool, not a decision-making mechanism.
4.3 Google user data — Limited Use
Numerio’s use of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. Specifically, for data received through the Gmail API (scope gmail.readonly):
- We use it only to provide and improve the user-facing features described in this policy — detecting invoice-related emails, extracting invoice data, and matching invoices against payments — features you see in Numerio itself.
- We do not transfer it to anyone else, except: to sub-processors, to the extent necessary to provide or improve those same features (the full list is in the Data Processing Agreement, published at
/dpa); for security purposes (for example to investigate abuse); where required by applicable law; or as part of a merger, acquisition or transfer of assets — in that last case only with your explicit prior consent. - We do not sell it and we do not use it for advertising of any kind.
- No human reads this data, except: with your explicit, recorded consent (for example when you ask for help with a specific document); where necessary for security purposes; where required by applicable law; or where the data has been aggregated and anonymised and is used only for internal operations.
- We do not use it to create, improve or train any artificial-intelligence or machine-learning model. Automated invoice extraction sends a document to the EU processing boundary described in section 7 to process a single request only — no model is trained on this data.
- These commitments also apply to our employees, contractors, agents and successors.
5. Purposes and legal bases of processing
| Purpose | Legal basis |
|---|---|
| Providing an account and the service under the pilot-programme terms | GDPR Article 6(1)(b) — performance of a contract (the pilot-programme terms) |
| Automatically detecting and extracting invoice data | GDPR Article 6(1)(b) — necessary to the substance of the service |
| Matching bank statement lines against invoices | GDPR Article 6(1)(b) |
| Service security, fraud prevention, system operation logs | GDPR Article 6(1)(f) — legitimate interest |
| Improving the service based on pilot-programme feedback | GDPR Article 6(1)(f) — legitimate interest |
| Complying with legal obligations (for example requests from accounting or tax authorities) | GDPR Article 6(1)(c) |
6. Retention periods
- Original documents (received email attachments that became invoices in the Numerio system) are kept for as long as your workspace exists — that is, until you delete it. This lets you review history and regenerate the accountant package at any time.
- Once a workspace is deleted, the data associated with it, including original documents, is removed from the active system; what remains in backups is removed in line with our backup cycle.
- Credentials (OAuth access tokens, Apple passwords) are kept only for as long as the source is connected, or while its disconnection (revocation) is in progress — see section 4.1.
- Contact enquiries (section 3) are kept for as long as needed to deal with the enquiry, and no longer than 24 months.
Because the service is at pilot stage, we confirm retention and deletion terms separately and explicitly with each pilot participant before real company data is connected — you know these terms before any real data is processed.
7. Where data is stored
All Numerio data — including original documents, the fields extracted from them and account information — is stored only in the European Union region, using managed infrastructure services located in the EU. Data is encrypted both in transit and at rest. Automated extraction of invoice data uses an EU-resident artificial-intelligence processing boundary — which is likewise within the EU region.
8. Who we share data with (sub-processors)
Numerio uses several service providers (sub-processors) in order to deliver the service — for example for mailbox access, document extraction and infrastructure. The full, specific list, with purpose, region and safeguards, is set out in our Data Processing Agreement (DPA), published at /dpa. We do not transfer data to third parties for marketing purposes and we do not sell it.
9. Your rights
As a data subject, you have the right under the GDPR to:
- access the data we process about you;
- rectify inaccurate data;
- request erasure of data (the “right to be forgotten”), subject to legal retention obligations;
- restrict processing;
- port your data (receive it in a structured, machine-readable format);
- object to processing based on legitimate interest;
- withdraw consent where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, write to hello@numerio.ai. We will respond no later than one month from receipt of the request.
10. Right to lodge a complaint
If you believe your data is being processed in breach of the GDPR, you have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (VDAI), L. Sapiegos g. 17, 10312 Vilnius, ada@ada.lt, www.ada.lt — or with the supervisory authority of any other EU Member State, if that is where you habitually reside or work.
11. Changes to this policy
This policy may be updated, particularly as the service leaves pilot stage. We will publish material changes on this page with a new “Updated” date, and will notify pilot participants by email where a change materially affects them.
12. Contact
MB „Blue age lab", Saulėtekio al. 15-1, LT-10224 Vilnius, Lithuania
Tel. +370 5 208 0417 · email hello@numerio.ai