Legal
Last updated: August 1, 2026
This Data Processing Agreement ("DPA") describes how InvoiceOS ("Processor") processes personal data on behalf of a customer ("Controller") using the InvoiceOS platform, including personal data relating to the Controller's own clients that the Controller enters into invoices and records. It supplements our Terms of Service and Privacy Policy.
For personal data of the Controller's clients (e.g. names, emails, GSTIN/PAN references entered on invoices), the Controller acts as Data Controller and InvoiceOS acts as Data Processor, processing that data solely to provide the invoicing, tax, and reporting features requested by the Controller.
Processing consists of storing, organizing, and computing invoice, tax, and financial data entered by the Controller for as long as the Controller maintains an active InvoiceOS account, or until deletion is requested.
The Controller authorizes InvoiceOS to engage the following subprocessors, each contractually bound to data protection obligations consistent with this DPA:
We will provide reasonable advance notice before adding a new subprocessor, giving the Controller the opportunity to raise an objection.
Primary data storage is in AWS's Mumbai (ap-south-1) region. Subprocessors listed above may process limited operational metadata (such as error logs or email delivery status) outside India as part of their global infrastructure; each subprocessor maintains its own data protection commitments for such processing.
Data is encrypted at rest (AES-256) and in transit (TLS 1.3). Access is scoped per workspace at the application layer. Edit history on invoices and tax records is logged in an audit trail retained for 7 years, consistent with Indian Income Tax Act expectations.
Where a data subject (e.g. the Controller's client) contacts InvoiceOS directly about their data, we will refer the request to the relevant Controller and provide reasonable assistance the Controller needs to respond to that request.
InvoiceOS will notify the affected Controller without undue delay after becoming aware of a personal data breach affecting that Controller's data, and will provide available information to help the Controller meet its own notification obligations.
On termination of the Controller's account, InvoiceOS will make the Controller's data available for export for a reasonable period, after which it will be deleted or anonymized, except where retention is required by law (including the 7-year audit trail retention referenced above).
Liability under this DPA is subject to the limitations set out in our Terms of Service. This DPA is governed by the laws of India.
For data processing questions, contact us via the support channel listed in your InvoiceOS account.