Data Processing Agreement

Processor

Name
Not provided yet
Address
Not provided yet
Email
Not provided yet

This document hasn't been published yet

It is being finalised and will appear here once it is approved.

Annex: Sub-processors

ProviderPurposePersonal dataWhenLocationTransfer safeguard
Google CloudHosting of the application, its database and stored files (receipts, uploaded contracts and other uploads kept on the service volume).All account, client, invoice, contract, expense, time-tracking and bank-feed data held in Payzio.On every useTo be confirmedTo be confirmed
Amazon Web Services (S3)File storage for logos, signatures, profile photos and attachments, in deployments configured to store uploads in S3.Uploaded images and files, which can include a handwritten signature.Only when file storage is configured to use S3.To be confirmedTo be confirmed
OpenAIAI features: reading receipts an account holder scans into expenses, drafting payment reminders for AI collections, and answering the Co-Pilot assistant.Receipt images; for reminder drafts, the overdue invoice's number, amounts and dates, the client's name and payment-reliability figures and the sender's business name; for the Co-Pilot, the conversation and whatever business data it looks up to answer, which can include client names, email and postal addresses, VAT and Peppol IDs, and invoice, contract, expense, bank-transaction and time-tracking records.Only when an account holder uses receipt scanning, AI collections or the Co-Pilot.To be confirmedTo be confirmed
StripeSubscription billing for account holders, and online card payment of invoices when an account holder connects Stripe.Account holder's name, email, billing address and subscription; for invoice payments, the invoice amount and reference and the payer's payment details entered at Stripe checkout.On every useTo be confirmedTo be confirmed
PayPalOnline payment of invoices when an account holder connects PayPal.The invoice amount and reference, and the payer's details entered at PayPal checkout.Only when an account holder connects PayPal.To be confirmedTo be confirmed
Enable BankingBank feed: connecting an account holder's bank account and reading its transactions to match incoming payments to invoices.Bank account details and transactions, including counterparty names and payment references.Only when an account holder connects a bank account.To be confirmedTo be confirmed
RecommandDelivery of e-invoices over the Peppol network.The e-invoice, including the seller's and buyer's names, addresses, VAT and Peppol identifiers.Only when an account holder sends an invoice via Peppol.To be confirmedTo be confirmed
ip-api.comApproximate location (country, region, city) for the login history and unusual-sign-in alerts.The IP address of each sign-in.On every useTo be confirmedTo be confirmed
PostHogProduct analytics.Page views and product events with a pseudonymous identifier.Only after a visitor opts in to analytics in the cookie banner or settings.To be confirmedTo be confirmed
Email delivery providerDelivery of transactional email: invoices, reminders, contracts and account notices.Recipient email addresses and names, and the message content.On every useTo be confirmedTo be confirmed