SendInvoice Logo ← Back to Home

Data Processing

Last updated: 11 September 2025

Privacy Policy Data Processing Addendum (DPA) Cookie Policy
This page explains in detail how SendInvoice Ltd (“SendInvoice”, “we”, “our”) processes personal data, our legal bases, retention periods, transfers, and your rights. For the user-friendly summary, see our Privacy Policy. For controller↔processor terms for business customers, see our DPA.

1. Basic Information

Data Controller: SendInvoice Ltd, 123 High Street, London, United Kingdom (example address).

We are not currently required to appoint a Data Protection Officer under GDPR. If that changes, we will notify customers and partners.

Contact: [email protected]

2. Legal Bases for Processing

3. What Data We Process & Why

3.1 Categories

  • Identification: name, company, tax/company ID, date of birth (where needed), IP address.
  • Contact: email, phone, billing/shipping address.
  • Financial: billing records, payment metadata (card/bank data held by providers).
  • Usage: device, browser, interactions, preferences, cookies.
  • Communications: support messages, survey responses.
  • Invoice content: customer names/addresses/tax IDs you include in documents.

3.2 Purposes

  • Account setup, authentication, and customer support.
  • Document generation: invoices, quotes, receipts.
  • Billing, payments, refunds, debt collection.
  • Accounting and tax compliance; audits.
  • Fraud prevention and security monitoring.
  • Service analytics and product improvement.
  • Marketing to existing customers (newsletters, product updates — opt-out anytime).

4. How We Obtain Data

5. Sharing & Processors

We do not sell personal data. We share data only as necessary for the purposes above:

All processors are bound by GDPR-compliant agreements and may only process data per our instructions.

6. International Transfers

Where personal data is transferred outside the UK/EU, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) and rely on certified providers (e.g., ISO 27001, SOC 2). See the Privacy Policy for a summary.

7. Retention

We retain personal data for the duration of your contract and for at least 10 years after termination to meet accounting, tax, and legal obligations and to enforce or defend legal claims. Where a shorter mandatory period applies, we follow the shorter statutory period. When the purpose no longer applies, we delete or anonymize data securely.

8. Cookies

We use cookies for core functionality, analytics, and personalization. You can manage cookies in your browser. For details, see our Cookie Policy.

9. Security Measures

10. Your Rights

Subject to applicable law (e.g., GDPR/UK GDPR), you may:

To exercise your rights, contact [email protected]. We will respond in accordance with legal timelines.

11. Marketing Communications

We may send product updates and newsletters to existing customers. You can opt out at any time using the link in the message or by contacting [email protected].

12. Controller ↔ Processor Terms (DPA)

If you are a business customer and SendInvoice processes your end-customer data on your behalf, our Data Processing Addendum applies. It covers instructions, confidentiality, security, sub-processors, assistance with data subject requests, audits, and data return/deletion on termination.

13. Updates to this Page

We may update this Data Processing page from time to time. We will post changes here and revise the “Last updated” date above. For a summary view, see our Privacy Policy.

Contact

Email: [email protected]
Website: https://www.sendinvoice.net