Data Processing Agreement

Last Updated: July 27, 2025

Effective Date: July 27, 2025

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Data Controller") and NovaInvoice (the "Data Processor") and governs the processing of personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Definitions

For the purposes of this DPA, the following terms have the meanings set out below:

  • "Data Controller": The natural or legal person who determines the purposes and means of processing personal data
  • "Data Processor": The natural or legal person who processes personal data on behalf of the Data Controller
  • "Data Subject": An identified or identifiable natural person
  • "Personal Data": Any information relating to an identified or identifiable natural person
  • "Processing": Any operation performed on personal data
  • "Data Protection Laws": GDPR, CCPA, and other applicable data protection regulations

3. Scope and Applicability

This DPA applies to the processing of personal data by NovaInvoice on behalf of the Data Controller in connection with:

  • Invoice creation and management services
  • Client relationship management
  • Payment processing and financial transactions
  • Email communications and notifications
  • Usage analytics and service improvement

4. Data Controller and Data Processor Responsibilities

4.1 Data Controller Responsibilities

As the Data Controller, you are responsible for:

  • Determining the purposes and means of processing personal data
  • Ensuring you have a lawful basis for processing
  • Obtaining necessary consents from data subjects
  • Providing privacy notices to data subjects
  • Responding to data subject requests
  • Ensuring data accuracy and completeness
  • Implementing appropriate data protection measures

4.2 Data Processor Responsibilities

As the Data Processor, NovaInvoice is responsible for:

  • Processing personal data only on documented instructions from the Data Controller
  • Implementing appropriate technical and organizational measures
  • Assisting with data subject requests
  • Maintaining records of processing activities
  • Notifying the Data Controller of any data breaches
  • Returning or deleting personal data upon termination

5. Categories of Personal Data

The personal data processed under this DPA includes:

Category Data Types Purpose
Identity Data Name, email address, phone number Account management, communication
Business Data Company name, address, tax ID Invoice creation, compliance
Financial Data Payment information, transaction records Payment processing, billing
Usage Data IP address, browser information, activity logs Service provision, analytics
Communication Data Email content, timestamps, delivery status Service delivery, tracking

6. Categories of Data Subjects

The data subjects whose personal data is processed include:

  • Account Holders: Individuals who create and manage NovaInvoice accounts
  • Invoice Recipients: Clients and customers who receive invoices
  • Authorized Users: Employees or agents acting on behalf of account holders
  • Payment Contacts: Individuals involved in payment processing

7. Processing Activities

NovaInvoice processes personal data for the following purposes:

  • Providing invoice management services
  • Facilitating payment processing through Stripe Connect
  • Sending invoice notifications and reminders
  • Tracking invoice delivery and engagement
  • Providing customer support services
  • Analyzing usage patterns for service improvement
  • Ensuring security and preventing fraud
  • Complying with legal and regulatory requirements

8. International Data Transfers

Personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, NovaInvoice ensures appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules (where applicable)
  • Other appropriate safeguards as recognized by data protection authorities

9. Technical and Organizational Measures

NovaInvoice implements appropriate technical and organizational measures to protect personal data:

Technical Measures:

  • Encryption of data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security monitoring and vulnerability assessments
  • Secure data backup and recovery procedures
  • Network security and firewall protection

Organizational Measures:

  • Data protection training for employees
  • Access controls and need-to-know basis
  • Regular security audits and assessments
  • Incident response procedures
  • Data protection impact assessments

10. Data Subject Rights

NovaInvoice will assist the Data Controller in responding to data subject requests, including:

  • Right of Access: Providing copies of personal data
  • Right to Rectification: Correcting inaccurate data
  • Right to Erasure: Deleting personal data
  • Right to Restriction: Limiting processing activities
  • Right to Data Portability: Exporting data in a structured format
  • Right to Object: Objecting to certain types of processing

11. Data Retention

Personal data will be retained for the following periods:

  • Account Data: For the duration of the account plus 30 days
  • Invoice Data: 7 years for accounting and tax purposes
  • Payment Data: 7 years for financial compliance
  • Usage Logs: 2 years for security and analytics
  • Communication Data: 3 years for customer support

12. Data Breach Notification

In the event of a personal data breach, NovaInvoice will:

  • Notify the Data Controller without undue delay (within 72 hours)
  • Provide details of the breach, including affected data and individuals
  • Describe the likely consequences and mitigation measures
  • Assist in breach notification to supervisory authorities
  • Cooperate in communication with affected data subjects

13. Sub-processors

NovaInvoice may engage sub-processors to assist in providing services. Current sub-processors include:

  • Stripe: Payment processing and financial services
  • Email Service Providers: Email delivery and communication
  • Cloud Infrastructure Providers: Hosting and data storage

We will inform you of any changes to sub-processors and obtain your consent where required.

14. Data Protection Impact Assessment

NovaInvoice will assist the Data Controller in conducting Data Protection Impact Assessments (DPIAs) when required by law, particularly for high-risk processing activities.

15. Audits and Compliance

NovaInvoice will:

  • Maintain records of processing activities
  • Provide information necessary for demonstrating compliance
  • Allow for and contribute to audits by the Data Controller
  • Cooperate with supervisory authorities

16. Termination

Upon termination of this DPA, NovaInvoice will:

  • Return all personal data to the Data Controller, or
  • Delete all personal data at the Data Controller's choice
  • Provide certification of deletion when requested
  • Ensure sub-processors comply with the same obligations

17. Liability and Indemnification

Each party shall be liable for damages caused by its own breach of this DPA or applicable data protection laws. The Data Controller shall indemnify NovaInvoice for any claims arising from the Data Controller's breach of its obligations under this DPA.

18. Amendments

This DPA may be amended to reflect changes in data protection laws or our processing activities. We will notify you of any material changes and obtain your consent where required.

19. Contact Information

For questions about this DPA or data protection matters:

Data Protection Officer: [email protected]

Privacy Team: [email protected]

Legal Team: [email protected]

Website: https://novainvoice.com

GDPR Compliance: This Data Processing Agreement ensures compliance with GDPR and other data protection regulations. By using our service, you acknowledge that you have read and understood your responsibilities as a Data Controller.