Data Processing Agreement

Last updated: August 25, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Invco ("Processor", "Invco"). It applies whenever Invco processes personal data on your behalf — principally the contact details of the clients you invoice — and is intended to satisfy Article 28 of the UK GDPR and EU GDPR. No signature is needed: it takes effect when you accept the Terms of Service. If your organisation requires a countersigned copy, email privacy@invco.pro and we will provide one.

1. Roles

You are the Controller of the personal data you put into Invco about your own clients and contacts — you decide who they are, what you record, and why. Invco is the Processor of that data and acts only on your instructions.

Invco is separately the Controller of its own account data: your name, your email address, your login and billing records. That relationship is governed by our Privacy Policy, not by this DPA.

SumUp is an independent Controller for payment data it processes when your customer pays. It is not Invco's sub-processor for that purpose, and its own terms and privacy notice govern it.

2. Subject matter and duration

Subject matter: the provision of invoicing, email delivery and payment-initiation software. Duration: for as long as your account exists, plus the deletion period in section 9.

3. Nature and purpose of processing

  • Storing and rendering the invoices, clients, templates and business details you create.
  • Delivering email you ask Invco to send, using the mail credentials you supply, and receiving replies to it.
  • Opening payment checkouts with SumUp against your own merchant account, and recording their outcome.
  • Generating PDFs, statements and exports at your request.
  • Providing support you have asked for, and keeping the service secure and available.

4. Types of personal data

  • Identification and contact data of your clients — name, company name, email address, telephone number, postal address.
  • Transaction data — invoice line items, amounts, references, due dates, payment status and payment method type.
  • Communications — the content of invoice emails, reminders, and replies received into your Invco mailbox.
  • Data your own users generate — names, email addresses and permissions of colleagues or clients you invite into a workspace.

5. Categories of data subject

  • Your clients and their staff.
  • Your own employees, contractors and colleagues who you give access to a workspace.

6. Special category data

Invco is not designed for and must not be used to process special category data (Article 9) or criminal offence data (Article 10). If you place such data into invoice text or attachments, you do so as Controller and on your own assessment of lawfulness.

7. Invco's obligations

  • Process personal data only on your documented instructions, which include your use of the product's features, unless required otherwise by law — in which case we will tell you first, unless the law forbids it.
  • Ensure that anyone authorised to process the data is bound by an obligation of confidentiality.
  • Implement appropriate technical and organisational measures, as described in section 8 and in more detail on our security page.
  • Assist you, as far as reasonably possible, with data subject requests, data protection impact assessments, and consultations with a supervisory authority.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations.
  • Make available the information needed to demonstrate compliance with Article 28 and allow for audits as set out in section 11.

8. Security measures

  • Encryption in transit (TLS 1.2+) for all traffic, and encryption at rest for the database and stored files.
  • AES-256-GCM encryption of the sensitive credentials you entrust to us — payment API keys and mail passwords — with the key held outside the database.
  • Per-workspace isolation enforced in the data layer, so another customer's records are never in scope of a query.
  • Passwords stored only as salted bcrypt hashes; optional two-factor authentication; rate limiting on authentication and payment endpoints.
  • Nightly encrypted off-platform backups that are integrity-checked and restore-tested automatically.
  • Administrative access limited to named personnel and not shared.

9. Return and deletion

You can export your data yourself at any time, including after a subscription lapses — Invco restricts creating new records when an account is unpaid, never reading or exporting existing ones.

On written request, or within 90 days of account closure, Invco will delete the personal data it processes on your behalf, except where retention is required by law. Backups age out on their own retention cycle and are deleted with it rather than being edited in place; while they remain, they stay encrypted and are not used for any other purpose.

10. Sub-processors

You give general authorisation for the sub-processors below. We will give reasonable notice before adding or replacing one, and you may object on reasonable data-protection grounds — if we cannot resolve the objection, you may terminate and receive a pro-rata refund of any prepaid period.

  • Vercel Inc. — application hosting and content delivery (United States).
  • Supabase — PostgreSQL database and file storage, hosted on AWS in us-east-1 (United States).
  • Google LLC — Google Analytics, only where a visitor has accepted analytics cookies (United States).
  • Anthropic PBC — only when you choose to connect an AI assistant to your workspace, and only the data that assistant requests on your instruction (United States).
  • Your own email provider — the SMTP/IMAP service whose credentials you supply, so that mail is sent from and received at your own address.
  • Note that SumUp is not listed here: for payment data it acts as an independent Controller, not as our sub-processor.

11. Audits

On reasonable written notice, and no more than once in any twelve-month period unless a breach or a regulator requires otherwise, Invco will respond to a reasonable security questionnaire and provide the documentation needed to verify compliance with this DPA. Invco is a small independent business and does not currently hold SOC 2 or ISO 27001 certification; we would rather tell you that than imply otherwise.

12. International transfers

Invco's infrastructure is located in the United States, so personal data you enter is transferred outside the UK and EEA. Where required, these transfers rely on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and take effect between the parties where the transfer falls within their scope.

Invco's personnel are based in Pakistan and access production data in the course of providing and supporting the service. That access is covered by the same contractual safeguards and by the confidentiality obligation in section 7.

13. Liability and precedence

The limitations of liability in the Terms of Service apply to this DPA. Where this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.

14. Contact

Data protection enquiries, countersigned copies, sub-processor notices and audit requests: privacy@invco.pro.

Questions about this policy? Email us at support@invco.pro or message us on WhatsApp.