Data Processing Agreement
Last Updated: July 24, 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Invoverge ("Processor", "we", "us") and you ("Controller", "Customer") and governs the processing of personal data in connection with the Service.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, such as collection, storage, use, or deletion.
- "Data Subject" means the individual to whom the Personal Data relates.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data.
3. Scope and Purpose of Processing
We process Personal Data only as necessary to provide the Service, including:
- Account management and authentication
- Invoice generation and storage
- Payment processing
- Customer support
- Service improvement and analytics
4. Categories of Data Processed
Customer Data
- Name and contact information
- Business information
- Login credentials (encrypted)
End User Data (Your Clients)
- Client names and contact details
- Invoice and payment information
- Business communications
5. Processor Obligations
We commit to:
- Process Personal Data only on documented instructions from the Controller
- Ensure personnel are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to Data Subject requests
- Notify the Controller of any data breaches without undue delay
- Delete or return Personal Data upon termination of the agreement
- Make available information necessary to demonstrate compliance
6. Sub-processors
We use the following named sub-processors. Each is bound by contractual and legal safeguards, and each publishes its own DPA:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Subscription payments & Stripe Connect Express for invoice payments | United States |
| PayPal Holdings, Inc. | Invoice payments (when configured by the account owner) | United States / Luxembourg |
| MongoDB Atlas | Managed database storage (encrypted at rest) | Canada / United States |
| Cloudflare, Inc. | TLS termination, WAF, DDoS mitigation, CDN | Global edge network |
| Resend, Inc. | Transactional email delivery | United States |
| Sentry (Functional Software, Inc.) | Error monitoring (PII scrubbed before send) | United States |
| OpenAI, L.L.C. (via Emergent LLM) | AI invoice drafting & insights | United States |
| Emergent (hosting provider) | Application hosting (managed Kubernetes) | Canada / United States |
We will notify Customers by email of any material change to this list, allowing at least 30 days to object.
7. Security Measures
We implement security measures including:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (Fernet AES-128-CBC + HMAC-SHA256 for tenant secrets; provider-managed AES-256 disk encryption for the storage volume)
- Access controls and authentication mechanisms (bcrypt-hashed passwords, HttpOnly cookies, optional TOTP 2FA)
- Multi-tenant data isolation verified by an automated regression test suite
- Rate limiting on authentication and payment endpoints
- Confidentiality obligations for personnel with production access
- Documented incident response procedure
- Daily automated backups with a rolling retention
8. Data Subject Rights
We will assist the Controller in fulfilling Data Subject rights requests including access, rectification, erasure, restriction, portability, and objection to processing.
9. International Transfers
Where Personal Data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
10. Data Retention and Deletion
Upon termination of the Service agreement, we will delete or return all Personal Data within 30 days, unless retention is required by law.
11. Audit Rights
Upon reasonable prior written notice (at least 30 days) and no more than once per calendar year, the Controller may audit our compliance with this DPA. Audit rights may be exercised through: (i) responses to a written information-security questionnaire (SIG Lite or equivalent), (ii) review of our Security & Compliance Overview document, or (iii) once available, third-party attestations (e.g., SOC 2). Sensitive information disclosed during an audit is subject to the confidentiality obligations of the underlying Terms of Service.
12. Contact
Data Protection Contact: support@invoverge.com
