Data Processing Agreement

Last Updated: July 24, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Invoverge ("Processor", "we", "us") and you ("Controller", "Customer") and governs the processing of personal data in connection with the Service.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, such as collection, storage, use, or deletion.
  • "Data Subject" means the individual to whom the Personal Data relates.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data.

3. Scope and Purpose of Processing

We process Personal Data only as necessary to provide the Service, including:

  • Account management and authentication
  • Invoice generation and storage
  • Payment processing
  • Customer support
  • Service improvement and analytics

4. Categories of Data Processed

Customer Data

  • Name and contact information
  • Business information
  • Login credentials (encrypted)

End User Data (Your Clients)

  • Client names and contact details
  • Invoice and payment information
  • Business communications

5. Processor Obligations

We commit to:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure personnel are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in responding to Data Subject requests
  • Notify the Controller of any data breaches without undue delay
  • Delete or return Personal Data upon termination of the agreement
  • Make available information necessary to demonstrate compliance

6. Sub-processors

We use the following named sub-processors. Each is bound by contractual and legal safeguards, and each publishes its own DPA:

Sub-processorPurposeLocation
Stripe, Inc.Subscription payments & Stripe Connect Express for invoice paymentsUnited States
PayPal Holdings, Inc.Invoice payments (when configured by the account owner)United States / Luxembourg
MongoDB AtlasManaged database storage (encrypted at rest)Canada / United States
Cloudflare, Inc.TLS termination, WAF, DDoS mitigation, CDNGlobal edge network
Resend, Inc.Transactional email deliveryUnited States
Sentry (Functional Software, Inc.)Error monitoring (PII scrubbed before send)United States
OpenAI, L.L.C. (via Emergent LLM)AI invoice drafting & insightsUnited States
Emergent (hosting provider)Application hosting (managed Kubernetes)Canada / United States

We will notify Customers by email of any material change to this list, allowing at least 30 days to object.

7. Security Measures

We implement security measures including:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (Fernet AES-128-CBC + HMAC-SHA256 for tenant secrets; provider-managed AES-256 disk encryption for the storage volume)
  • Access controls and authentication mechanisms (bcrypt-hashed passwords, HttpOnly cookies, optional TOTP 2FA)
  • Multi-tenant data isolation verified by an automated regression test suite
  • Rate limiting on authentication and payment endpoints
  • Confidentiality obligations for personnel with production access
  • Documented incident response procedure
  • Daily automated backups with a rolling retention

8. Data Subject Rights

We will assist the Controller in fulfilling Data Subject rights requests including access, rectification, erasure, restriction, portability, and objection to processing.

9. International Transfers

Where Personal Data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

10. Data Retention and Deletion

Upon termination of the Service agreement, we will delete or return all Personal Data within 30 days, unless retention is required by law.

11. Audit Rights

Upon reasonable prior written notice (at least 30 days) and no more than once per calendar year, the Controller may audit our compliance with this DPA. Audit rights may be exercised through: (i) responses to a written information-security questionnaire (SIG Lite or equivalent), (ii) review of our Security & Compliance Overview document, or (iii) once available, third-party attestations (e.g., SOC 2). Sensitive information disclosed during an audit is subject to the confidentiality obligations of the underlying Terms of Service.

12. Contact

Data Protection Contact: support@invoverge.com