This Data Processing Agreement ("DPA") applies where InvoiceBadger ("Processor", "we") processes personal data on behalf of you ("Controller") to provide the Service. It supplements our Terms of Service and, for data protection matters, prevails if they conflict. Want a copy countersigned in your company's name, or need changes? Email support@invoicebadger.com and we'll sort one out.
1. Subject matter and duration
We process personal data only to provide the Service to you, for as long as your account is active, plus the retention period in section 8.
2. Nature and purpose
Storing and processing the invoicing data you enter, generating invoices and PDFs, and sending invoice and account emails.
3. Types of personal data
Contact and business details of your clients (name, email, postal address) and the descriptions, hours, rates and amounts you record against them.
4. Categories of data subjects
Your clients and any individuals whose details you enter into the Service.
5. Our obligations
- Process on instruction — only on your documented instructions (using the Service is your instruction), unless the law requires otherwise.
- Confidentiality — anyone we authorise to process the data is bound by confidentiality.
- Security — appropriate technical and organisational measures (section 6).
- Sub-processors — only those in section 7, on terms no less protective than this DPA, and we stay responsible for them.
- Assistance — help you respond to data-subject requests and meet your security, breach and impact-assessment duties.
- Breach notice — tell you without undue delay after becoming aware of a personal data breach affecting your data.
- Deletion or return — on termination, as set out in section 8.
6. Security measures
All data encrypted in transit (TLS/HTTPS with HSTS); passwords hashed with PBKDF2-HMAC-SHA256; strict per-account data isolation enforced at the database layer; signed, HttpOnly, Secure sessions with "log out all devices"; hosting on Cloudflare with the database in the EU and automated point-in-time backups; rate limiting and bot protection; strict security headers. Full summary at /security.
7. Authorised sub-processors
You authorise these sub-processors. We give reasonable notice via our Sub-processors page before adding or replacing one, so you can object.
- Cloudflare, Inc. — hosting, database, PDF rendering, CDN, bot protection (database in the EU; global edge).
- Stripe — payment processing, Pro subscriptions only (EU / US).
- Resend, Inc. — transactional email delivery (US).
8. Retention, return and deletion
While your account is active we keep the data to run the Service. On deletion of your account we remove personal data from our live systems immediately; residual copies in automated backups age out within 30 days. We may keep the minimum required by law. We'll confirm deletion in writing on request.
9. Audit
We'll respond to reasonable written requests for the information needed to demonstrate compliance, no more than once a year unless a supervisory authority or a breach requires otherwise, subject to reasonable confidentiality.
10. International transfers
Where a sub-processor processes data outside the UK/EEA, we ensure an appropriate transfer mechanism is in place (such as the UK IDTA, EU Standard Contractual Clauses, or an adequacy decision).
11. Liability and governing law
Liability under this DPA is subject to the limits in our Terms of Service. This DPA is governed by the laws of England and Wales.