Data Processing Agreement (DPA)

Agreement last updated: August 12, 2026

This data processing agreement explains how Invoice Master processes customer, invoice, contact, and payment-related personal data on behalf of customers who use the service.

It covers processor obligations, GDPR Article 32 security measures, subprocessors such as Stripe when payment processing is enabled, data-subject support, breach notice, international transfers, and deletion terms.

1. Parties

Controller (Customer): Any individual or entity registering for the Invoice Master service.

Processor: Enrique Moreno Tent (sole proprietor), Trachauerstraße 5, 01139 Dresden, Germany — support@invoicemaster.org.

2. Subject and duration

Processor hosts and processes Customer personal data to provide the service. This DPA applies for as long as Processor processes Customer personal data and continues as necessary to complete the deletion or return obligations in Section 10.

3. Purpose of processing

  • Store and display invoices, quotes, contacts, and related records.
  • Send transactional email.
  • Process payments through Stripe when enabled by Customer.

4. Data types and data subjects

Names, emails, business identifiers, billing details, invoice line items, payment references, account identifiers, support messages, and technical diagnostic data. Data subjects include Customer’s staff, clients, and suppliers. No special‑category data is intended.

5. Processor obligations

  • Process only on documented instructions from Customer.
  • Keep data confidential and ensure authorized personnel are bound by confidentiality.
  • Apply the security measures in Section 6.
  • Assist Customer with data‑subject requests and DPIAs where reasonable.
  • Delete or return personal data at the end of the engagement as described in Section 10.
  • Make information available to demonstrate compliance with this DPA.

6. Security measures (Art. 32 GDPR)

  • TLS encryption in transit and encryption at rest within hosting infrastructure.
  • Access to production Customer data and service configuration is limited to authorized personnel using provider and application permissions.
  • Multi‑factor authentication is enabled for the staff login that controls Netlify deployments. This statement does not describe Customer organization roles and does not claim that every provider or Customer login is protected by multi‑factor authentication.
  • Change management, privacy‑limited logging, and a documented quarterly review of provider access.

7. Subprocessors

  • Supabase (primary project region in Germany; other locations under its DPA) — database, file storage, authentication, scheduled jobs, and database backups.
  • Render (backend service region in Germany; other locations under its DPA) — backend hosting and API request processing.
  • Netlify (global delivery network) — browser-application and website hosting, deployments, and connection metadata.
  • Stripe (EU and US) — Invoice Master subscriptions and customer-enabled invoice payments.
  • Twilio SendGrid (US and provider locations) — transactional email delivery and delivery records.
  • Zoho Mail (EU and provider locations) — support and account email.
  • Sentry (US and provider locations) — server error monitoring and consent-based browser monitoring.
  • Unlayer (US and provider locations) — the optional custom email-template editor.
  • Crisp (EU storage and global relay locations) — optional support chat in the Web and Portal applications.
  • Hotjar (EU and provider locations) — optional, consent-based website and product-usage analysis.

These providers are covered by this DPA to the extent they process Customer personal data to provide, secure, monitor, or support Invoice Master. Optional support, monitoring, and product-analysis services operate only when enabled or consented to as described in the Privacy Policy.

Processor will notify Customer at least fourteen (14) days before a new subprocessor begins processing Customer personal data. Customer may object during that period on reasonable data-protection grounds.

8. Data‑subject rights

Processor provides tools and support so Customer can fulfil access, rectification, erasure, and portability requests.

9. Personal‑data breach

Processor notifies Customer without undue delay after becoming aware of a personal‑data breach.

10. Deletion and return

For self-service account deletion, after Customer confirms deletion, Processor deletes the relevant sign-in account and removes most active Customer workspace personal data from the primary application database. Uploaded files and some technical or workspace records may remain in active systems. Billing records, security logs, provider backups, transactional email records, and data held by subprocessors may also remain under applicable retention settings or where retention is legally required.

The automated process above is separate from Customer's choice at the end of processing services under this DPA. Customer may exercise that choice by emailing support@invoicemaster.org. Processor then deletes or returns Customer personal data and deletes existing copies unless applicable law requires storage. Cancelling the service while the account remains active does not trigger self-service account deletion.

11. Compliance information

Upon written request (no more than once per year) Processor will provide current security documentation from hosting and payment providers. On‑site audits are not available.

12. International transfers

Data may be transferred outside the EEA even when the primary service region is in Europe. Where required, the applicable provider DPA, Standard Contractual Clauses, or another approved transfer mechanism is used.

13. Liability

For ordinary negligence, liability is capped at fees paid by Customer in the twelve (12) months before the incident. No cap applies for intent or gross negligence.

14. Governing law and venue

German law governs. Exclusive venue is Dresden, Germany.

15. Acceptance

Customer accepts this DPA by creating an account after being shown a signup notice that links to this document, or by executing a contract that references this document.

— Enrique Moreno Tent, Processor (August 12, 2026)