Invoice Extractor
Pricing
Invoice Extractor

Extract structured data from invoices using AI. Fast, accurate, and secure.

Product

  • Pricing
  • Features
  • How It Works

Legal

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement

© 2025 Invoice Extractor. All rights reserved.

Questions?support@invoiceextractor.app
Back to Home

Data Processing Agreement

Last updated: December 26, 2024

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Invoice Extractor ("Processor", "we", "us") and the customer ("Controller", "you") for the processing of personal data in connection with our invoice extraction service.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person contained in documents you upload to our Service.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, extraction, and deletion.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Sub-processor" means any third party engaged by us to process Personal Data on your behalf.
  • "Data Protection Laws" means all applicable data protection legislation including GDPR, CCPA, and other relevant regulations.

2. Scope and Purpose of Processing

2.1 Subject Matter

This DPA applies to the processing of Personal Data contained in invoice documents that you upload to our Service for the purpose of data extraction.

2.2 Nature and Purpose

We process Personal Data for the following purposes:

  • Extracting structured data from uploaded invoice documents
  • Storing documents temporarily for your access
  • Providing the extraction results to you
  • Enabling export of extracted data

2.3 Types of Personal Data

Personal Data processed may include:

  • Names (company names, individual names)
  • Business addresses
  • Tax identification numbers
  • Bank account details
  • Contact information
  • Any other personal data contained in uploaded invoices

2.4 Categories of Data Subjects

Data Subjects may include your customers, suppliers, business partners, and employees whose information appears on invoices.

3. Controller Obligations

As the Controller, you are responsible for:

  • Ensuring you have a lawful basis to process Personal Data through our Service
  • Providing any required notices to Data Subjects
  • Obtaining any necessary consents
  • Ensuring the accuracy of Personal Data
  • Complying with Data Subject rights requests
  • Not uploading special category data (health, biometric, genetic data) unless legally permitted

4. Processor Obligations

As the Processor, we commit to:

  • Process Personal Data only on your documented instructions
  • Ensure personnel are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist you in responding to Data Subject requests
  • Delete or return Personal Data upon termination (subject to legal retention requirements)
  • Make available information necessary to demonstrate compliance
  • Notify you of any data breach without undue delay

5. Security Measures

We implement the following technical and organizational measures to protect Personal Data:

5.1 Technical Measures

  • 256-bit SSL/TLS encryption for data in transit
  • Encryption of stored documents
  • Secure authentication mechanisms (OAuth 2.0, email verification)
  • Access controls limiting data access to authenticated users
  • Automatic deletion of documents after 7 days
  • Regular security updates and patches

5.2 Organizational Measures

  • Confidentiality obligations for personnel
  • Data protection training
  • Regular security reviews
  • Incident response procedures
  • Vendor security assessments

6. Sub-processors

6.1 Authorized Sub-processors

You authorize our use of the following sub-processors for Personal Data processing:

Sub-processorPurposeLocation
AI Service ProviderAI document processing and data extractionInternational
StripePayment processingUSA/EU
Google CloudAuthenticationUSA/EU
ResendEmail deliveryUSA

6.2 Sub-processor Changes

We will notify you of any intended changes to sub-processors, giving you the opportunity to object. If you have a reasonable objection, we will work with you to find an alternative solution or you may terminate the affected services.

7. International Transfers

Personal Data may be transferred to countries outside the European Economic Area (EEA). When such transfers occur, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) with sub-processors where applicable
  • Adequacy decisions where available
  • Supplementary technical measures (encryption, access controls)

Note: Invoice documents are processed by AI services that may have servers in various international locations. By using our Service, you acknowledge and accept this transfer. Documents are processed in real-time and not retained by the AI provider.

8. Data Subject Rights

We will assist you in fulfilling your obligations to respond to Data Subject requests including:

  • Access requests
  • Rectification requests
  • Erasure requests ("right to be forgotten")
  • Restriction of processing requests
  • Data portability requests
  • Objection to processing

Due to our 7-day automatic deletion policy, most data will be deleted before such requests are received. For urgent requests, contact us immediately at privacy@invoiceextractor.app

9. Data Breach Notification

In the event of a Personal Data breach, we will notify you without undue delay (and within 72 hours where feasible) providing:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach
  • Contact point for further information

10. Data Retention and Deletion

We retain Personal Data as follows:

  • Uploaded documents: Automatically deleted after 7 days
  • Extracted data: Automatically deleted after 7 days
  • Processing logs: Retained for security purposes, anonymized or deleted after 30 days

Upon termination of services or at your request, we will delete or return all Personal Data within 30 days, except where retention is required by law.

11. Audit Rights

Upon reasonable request and subject to confidentiality obligations, we will provide you with information necessary to demonstrate our compliance with this DPA. We may satisfy audit requests by providing third-party certifications, audit reports, or other documentation demonstrating our security practices.

12. Liability

Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of Data Protection Laws where such limitation is not permitted by law.

13. Term and Termination

This DPA remains in effect for the duration of your use of our Service. Upon termination, our data processing obligations continue until all Personal Data has been deleted or returned in accordance with Section 10.

14. Governing Law

This DPA is governed by the same laws that govern our Terms of Service. For EU/EEA users, nothing in this DPA limits any rights under GDPR or other applicable Data Protection Laws.

15. Contact Information

For DPA-related inquiries or to exercise your rights:

Data Protection Contact: privacy@invoiceextractor.app

Legal Inquiries: legal@invoiceextractor.app

See also: Terms of Service • Privacy Policy