Back to Invoizify
Draft, pending legal review. These policies are being finalised and are not yet in effect. Highlighted items are still to be confirmed.

Legal & Trust

Data Processing Addendum

Effective Effective date · Last updated Last-updated date · Operated by Legal entity name

About this Addendum: This Addendum governs situations where an enterprise, firm, or business Customer acts as a Data Controller / Data Fiduciary with respect to their end-client records, and engages Invoizify as a Data Processor under applicable Indian data protection law.

Parties:

  1. Legal entity name (“Invoizify” or “Data Processor”)
  2. The customer agreeing to these terms (“Customer” or “Data Fiduciary”)

1. Definitions & interpretation

1.1. In this Addendum:

(a) “Applicable Data Protection Law” means the Information Technology Act, 2000, the SPDI Rules, 2011, and the Digital Personal Data Protection Act, 2023 (along with rules framed thereunder, including DPDP Rules 2025), to the extent formally in force in India.

(b) “Customer Personal Data” means any personal data of the Customer’s clients, contractors, or representatives uploaded to or processed via the Invoizify platform by or on behalf of Customer.

(c) “Data Fiduciary” and “Data Processor” shall carry the meanings ascribed to them under the DPDPA 2023 (comparable to Data Controller and Data Processor respectively under international frameworks).

2. Scope, role, and processing instructions

2.1. Role of the Parties: The parties acknowledge that with respect to Customer Personal Data processed within generated invoices (e.g., end-client contact details, billing addresses), Customer acts as the Data Fiduciary and Invoizify acts solely as a Data Processor.

2.2. Documented Instructions: Invoizify shall process Customer Personal Data strictly pursuant to Customer’s documented instructions—namely, to provide, maintain, and deliver the Invoizify invoicing software pursuant to the Principal Agreement (Terms of Service). Invoizify shall not process Customer Personal Data for any other purpose without the prior written instruction of Customer or as required by law.

3. Confidentiality and personnel

Invoizify ensures that all personnel authorized to access Customer Personal Data are under appropriate contractual or statutory obligations of confidentiality and have received appropriate data protection training.

4. Sub-processors

4.1. Authorized Sub-processors: Customer grants general authorization to Invoizify to engage third-party sub-processors (including cloud hosting providers, WhatsApp/Meta API infrastructure, and AI inference engines) to support service delivery.

4.2. Sub-processor Obligations: Invoizify will impose contractual data protection obligations on any engaged sub-processor that are no less protective than those set forth in this Addendum.

5. Security measures

Invoizify shall implement and maintain appropriate technical and organizational measures (as described in Document E) designed to protect Customer Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage.

6. Assistance with data principal rights

Taking into account the nature of the processing, Invoizify shall provide reasonable assistance to Customer, via built-in platform capabilities (such as search, export, and delete functions) or administrative intervention, to enable Customer to respond to requests from Data Principals seeking to exercise their rights of access, correction, or erasure under Applicable Data Protection Law.

7. Security incident notification

In the event Invoizify discovers a verified breach of security leading to the accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to Customer Personal Data on systems managed directly by Invoizify, Invoizify shall notify Customer without unreasonable delay upon verification, and take prompt reasonable steps to mitigate the impact.

8. Deletion and return of personal data

Upon termination of the Principal Agreement, Invoizify shall, at Customer’s written election, delete or return all Customer Personal Data within DPA delete/return window (e.g. 30 days), save to the extent that retention is mandated by applicable statutory, tax, or corporate laws of India.

9. Audit and assurance

Upon reasonable prior written notice (not less than thirty (30) business days) and no more than once per calendar year, Invoizify shall make available to Customer information reasonably necessary to demonstrate compliance with this Addendum, provided Customer agrees to reasonable non-disclosure obligations and executes such review without disrupting Invoizify’s active production operations.