GoBD compliance in detail
A posted line never disappears. Corrections run as a reversal that references the original, and the history stays readable.
Documents and entries are stored as a chain. Any later change breaks the chain and becomes visible.
The processes for capture, processing and retention are documented and available for an audit.
The digital image is stored in its original form, and every access is logged.
Tax-relevant data is retained in accordance with § 147 AO, regardless of contract status.
For cash transactions with a certified technical security system (TSE) under § 146a AO, via the Cash Book plugin.
Data protection and access
Signable online inside your account, with no separate negotiation, including the list of subprocessors.
TOTP for every role, enforceable for admin access. Recovery codes included.
Every change with user, timestamp and previous value, filterable and exportable.
Each key holds only the permissions it needs, revocable at any time, with an access log.
Tools for data subject rights: access, rectification and erasure, as far as no retention obligation applies.
A full export of your data at any time, including in preparation for switching providers.
Questions on security and compliance
Is ZepDesk certified?
The operator's data centers are certified to ISO 27001. For the software itself we do not hold our own ISO certification, and we say so openly; the GoBD requirements (Germany's rules for proper digital bookkeeping) are implemented technically and documented.
Who can see my data?
Only the users you invite, and in a support case only after your approval. Any access by our team is logged.
What happens in the event of a data breach?
We notify the admin roles without delay, stating the scope and the measures taken, so that you can meet your reporting obligations under Art. 33 GDPR.
Why nothing can be changed unnoticed.
Every document and every entry is stored as a chain. If one link is changed, the checksum no longer matches.
This is exactly what the GoBD require under immutability. The proof is generated automatically.
Compliance you can prove.
Create an account, sign the AVV, enable two-factor. After that the audit trail is in place from the start.