Data Processing Addendum
Version 1.1 · Published 3 September 2026
This Data Processing Addendum (the “DPA”) forms part of, and is incorporated by reference into, the applicable end user licence agreement or service terms between the Customer and InvoiceNow Biz F.Z.C. (“InvoiceNow Biz” or “ASP”) (the “Agreement”). It governs the processing of personal data comprised in Customer Data in the course of providing the Services. Capitalised terms not defined here have the meaning given in the Agreement.
The Services may be provided in more than one country. This DPA applies to all processing of personal data comprised in Customer Data in connection with the Services, and ASP will process such data in compliance with the data-protection laws, and the requirements of the competent tax and data-protection authorities, of each country in which the relevant Services are provided (together with the other laws applicable to ASP as processor, “Applicable Law”, and those authorities, the “Competent Authorities”).
1. Roles of the parties
1.1 For the purposes of Applicable Law, the Customer is the controller and ASP is the processor of the personal data comprised in Customer Data. ASP processes that personal data on the Customer’s behalf and not for its own purposes. Where ASP engages another party to carry out processing, that party acts as ASP’s sub-processor and not as a sub-processor of, or processor for, any other party.
1.2 ASP is the Customer’s direct processor for the Services. No other party is interposed in the processing chain for the Services.
2. Scope of processing
| Item | Detail |
|---|---|
| Subject matter and duration | Provision of the Services for the term and any transition period, and retention thereafter as required by Applicable Law. |
| Nature and purpose | Collection, structuring, validation, mapping, transmission, reporting to the relevant Competent Authority, storage, archiving and retrieval of electronic invoicing data. |
| Types of personal data | Business contact details of the Customer’s personnel and counterparties; names and identifiers on invoices and credit notes; portal user credentials and access logs. |
| Categories of data subjects | Customer personnel; counterparty personnel; and natural persons who are counterparties. |
| Location of processing | As agreed with the Customer and as required by Applicable Law. |
3. Processor obligations
3.1 ASP will: (a) process personal data only on the Customer’s documented instructions (which the Agreement and the Customer’s use of the Services constitute) and as required by Applicable Law, including lawful requests of a Competent Authority; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the security measures in section 4; (d) respect the conditions for engaging sub-processors in section 5; (e) assist the Customer, taking account of the nature of processing, in responding to data-subject requests and in meeting its own security, breach-notification and impact-assessment obligations; and (f) at the Customer’s choice, delete or return the data as set out in section 7.
4. Security
4.1 ASP implements technical and organisational measures appropriate to the risk, including multi-factor authentication for user access, encryption of data in transit and at rest, regular security monitoring, and certification to ISO/IEC 27001 held by ASP or its group affiliates, together with compliance with any additional security, hosting or residency requirements the Customer notifies in writing or that a Competent Authority requires, as further described in ASP’s Security Schedule at https://www.invoicenow.biz/legal/security.
5. Sub-processors
5.1 The Customer authorises ASP to engage sub-processors (including members of ASP’s group and its infrastructure providers) to process personal data in connection with the Services. ASP maintains and, on request, makes available a list of sub-processors at https://www.invoicenow.biz/legal/subprocessors, imposes data-protection obligations on each sub-processor no less protective than those in this DPA, and remains fully responsible for the acts and omissions of its sub-processors.
6. International transfers and authority access
6.1 ASP will not transfer personal data across borders except in accordance with Applicable Law and subject to appropriate safeguards, including any data-residency requirements of a Competent Authority. The Customer acknowledges that, where a Competent Authority is entitled by law to access, use or share data processed under the Services, ASP may provide such access as required by law.
7. Breach notification, deletion and return
7.1 ASP will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, with the information reasonably available, in time for the Customer to meet its own notification obligations to any Competent Authority. On expiry of the applicable retention period, or on the Customer’s written instruction where Applicable Law permits, ASP will delete or return the personal data; ASP may retain data for as long as, and to the extent, required by Applicable Law.
8. Audit
8.1 ASP will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or its mandated auditor on reasonable notice, subject to confidentiality and to not compromising the security of other customers.
9. Governing law
9.1 This DPA is governed by the governing law of the Agreement and the applicable data-protection law of each country in which the relevant Services are provided.