* fix(privacy): mask voucher amounts in session replays * fix: persist transaction source filter * fix: clarify invoice filenames and booking previews * fix: truncate long uploaded filenames * feat: add invoice delivery history * fix: harden invoice delivery history * fix: include invoice deliveries in full archive
1.7 KiB
Data Classification and Handling
Restricted data
Swedish personal identity numbers are Restricted personal data. They are not an Article 9 special category by themselves, but their stable government identifier role requires heightened protection.
Controls:
- Customer personal numbers are accepted only for individual customers.
- Values are encrypted with AES-256-GCM before database storage.
- API and UI output exposes only the last four digits.
- Writes require an authenticated company member with write permission.
- RLS and explicit
company_idfilters enforce tenant isolation. - There is no endpoint that returns the full value.
- Logs and audit event payloads must never contain the full value.
Internal business data
Article master records are Internal business data. An unused article may be deleted because issued invoice lines, archived invoice PDFs, journal entries, and audit events retain the accounting evidence independently. Any article that is referenced by an invoice line is protected by the application check and the database foreign key.
Invoice delivery history
Invoice recipient addresses, subjects, and message bodies are Confidential
personal and business data. Exact payloads are retained server-side as delivery
evidence until invoice_deliveries.retention_expires_at. Browser list responses
contain masked recipient domains and operational metadata only. After the BFL
retention date, the daily redaction control removes recipients, message content,
provider message IDs, filenames, and attachment checksums. Selective audit rows
must contain delivery IDs, tenant IDs, status transitions, actors, timestamps,
and document linkage only, never email payload content.