templit — SAP Business One invoice automation

Privacy Policy

Last updated: 2 August 2026

This policy explains what templit collects when you use our SAP Business One add-on and our website, why we collect it, who else ever sees it, and how long we keep it. We've tried to write it in plain language rather than boilerplate — if anything here is unclear, email us at contact@templit.one.

The short version

  • Setting up a template needs one sample invoice. That single PDF goes to our servers, and to Anthropic — the AI provider that works out where each field sits on the page.
  • Every invoice you import afterwards is read entirely on your own computer, next to your SAP Business One install. It is never uploaded anywhere.
  • We store that one sample PDF encrypted, tied to the template it created.
  • We don't sell your data, and we don't train anything on it.

Where your data goes

Exactly two parties besides us ever touch anything of yours, and both only ever see the one sample invoice — never the invoices you import day to day.

Anthropic

Reads the one sample PDF to work out the invoice's layout, on their infrastructure in the United States. Their commercial terms do not permit training on data submitted through their API — if you need that on file for your own compliance review, ask us and we'll point you at the current terms.

Our hosting provider

Runs the templit API and the database that holds your encrypted sample and your account record. The servers are in Germany, so your sample stays inside the EU — it is only the Anthropic step above that reaches the US. We name the provider on request.

Nobody else. We don't sell, rent, or otherwise share your data, and we don't use it for advertising.

What we collect, and why

The sample invoice used to build a template

When you create or update a template in the add-on, you choose one PDF invoice from that supplier and pick the fields you want templit to capture. That single PDF is uploaded to our servers, where it is processed and also sent to Anthropic to work out the invoice's layout. We store that sample PDF, encrypted at rest, for as long as the template exists — it is the reference copy behind the template, and is kept even if a template build fails, so we can see why. Deleting or deactivating a template does not retroactively un-send this file to Anthropic; it only affects what we ourselves keep going forward.

Every invoice you import after that

Once a template exists, importing invoices does not involve us at all. The add-on reads the PDF and extracts the fields locally, on the same computer that runs SAP Business One. That document, and the data on it, is never transmitted to our servers, to Anthropic, or to anyone else.

Account information

We keep your company name and a contact email so we can reach you. The add-on authenticates with a single API key; we store only a one-way hash of that key, plus its first few characters so we can identify it in support — never the key itself in readable form.

Usage monitoring

Each time the add-on runs a template against a dropped invoice, it sends us a small ping: which template was used, when, whether it succeeded, and the add-on version. It does not include the invoice, the extracted data, or any supplier information.

Diagnostic logs

Building a template is logged so we can work out why one failed. Those logs hold the sample's filename and size, and the extraction spec produced at each attempt. A spec contains labels lifted from the invoice — the exact wording a supplier uses for "Invoice no.", a column heading, and similar — so logs can contain fragments of your document's text. They are kept for 3 days and then deleted.

Our website

templit.one runs no analytics and no advertising trackers, and loads no fonts, scripts, or assets from anyone else's servers. It sets no cookies beyond what your browser needs to load the page.

Who is responsible for what

If you are an SAP Business One partner running templit for a client, the chain runs like this: your client decides what happens to their invoice data (the controller), you act on their instructions (a processor), and templit acts on yours (a sub-processor). In plain terms — we only ever do what you ask with the sample you send us, we make no decisions about it ourselves, and we never use it for our own purposes.

Data processing agreements are handled individually — contact us and we'll work through your requirements.

How we protect it

Sample invoices are encrypted at rest with AES-GCM. API keys are never stored in plaintext, only as a one-way hash. Access is limited to the people building templit.

Your rights, and deleting your data

You can ask us what we hold about you, ask us to correct it, or ask us to delete it, by emailing contact@templit.one. We action deletion requests within 30 days, and we delete the samples and account record we hold for you when you stop using templit.

One thing we cannot undo: deleting a stored sample removes our copy, but it does not reach back into the processing Anthropic already performed on the copy sent when the template was built.

Changes to this policy

If we change what we collect or how we use it, we'll update this page and change the "Last updated" date above. For material changes we'll tell customers directly rather than relying on you to notice.

Contact

Questions about this policy or your data: contact@templit.one.