Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in the applicable account or order form (“Customer”) and InvoToday, a business operated from British Columbia, Canada (“InvoToday”), governing use of the InvoToday service (the “Agreement”). It applies whenever InvoToday processes personal data contained in Customer Data on Customer’s behalf, and is automatically accepted by Customer’s use of the Service. In case of conflict between this DPA and the Agreement, this DPA controls with respect to the processing of personal data.
1. Definitions
“Data Protection Laws” means all laws applicable to the processing of personal data under the Agreement, including, where applicable, the EU and UK General Data Protection Regulation (“GDPR”), Canada’s PIPEDA, British Columbia’s PIPA, and Malaysia’s PDPA. “personal data”, “controller”, “processor”, “data subject”, and “processing” have the meanings given in the applicable Data Protection Laws. “SCCs” means the Standard Contractual Clauses approved by European Commission decision 2021/914 (Module Two: controller to processor), as amended or replaced.
2. Roles and scope
Customer is the controller (or a processor acting for another controller) of personal data in Customer Data; InvoToday is Customer’s processor. Each party will comply with the Data Protection Laws applicable to it. Customer is responsible for the lawfulness of the personal data it submits, including obtaining any required notices and consents from its own customers, vendors, and employees. The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex A.
3. InvoToday’s obligations
InvoToday will:
- Instructions: process personal data only on Customer’s documented instructions — namely the Agreement, this DPA, Customer’s configuration of the Service, and its use of the Service’s features — unless required otherwise by law, in which case InvoToday will inform Customer unless legally prohibited. InvoToday will inform Customer if, in its opinion, an instruction infringes Data Protection Laws;
- Confidentiality: ensure persons authorized to process personal data are bound by confidentiality obligations;
- Security: implement and maintain the technical and organizational measures described in Annex B, which Customer agrees provide a level of security appropriate to the risk;
- Assistance: taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures (including the Service’s export, correction, deletion, and audit-trail features) in fulfilling Customer’s obligations to respond to data-subject requests, and provide reasonable assistance with data protection impact assessments and consultations with supervisory authorities, at Customer’s reasonable expense where material effort is required;
- Data-subject requests: promptly forward to Customer any request received directly from a data subject relating to Customer Data, and not respond except to direct the data subject to Customer, unless legally required;
- Breach notification: notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, targeting notification within 72 hours of confirmation, and provide information reasonably available to InvoToday about the nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken. InvoToday’s notification is not an admission of fault;
- Deletion and return: upon termination or expiry of the Agreement, make Customer Data available for export for at least 30 days, then delete it from production systems, with residual copies aging out of encrypted backups within approximately 90 days, unless retention is required by law; and
- Records: maintain records of processing as required by Data Protection Laws.
4. Subprocessors
Customer grants InvoToday general written authorization to engage the subprocessors listed in Annex C. InvoToday will impose data protection obligations on subprocessors that are materially no less protective than this DPA, and remains liable for their performance. InvoToday will update Annex C (published at our website) at least 15 days before adding or replacing a subprocessor; Customer may object on reasonable data-protection grounds within that period, and if the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period as its exclusive remedy. Third-party services that Customer chooses to connect (for example Intuit QuickBooks Online, the LHDN MyInvois platform, or the AI provider whose API key Customer supplies) are not subprocessors of InvoToday; they are separate controllers or processors engaged directly by Customer.
5. International transfers
Customer authorizes processing in Canada, the United States, and the other locations listed in Annex C. To the extent processing involves a transfer of personal data protected by the GDPR to a country without an adequacy decision, the SCCs are incorporated into this DPA, with Customer as “data exporter” and InvoToday as “data importer”; Annexes A–C serve as the SCC appendices; the optional docking clause applies; the governing law and forum for the SCCs are those of Ireland where required, and audits and instructions operate as set out in this DPA to the extent permitted. Canada currently benefits from an EU adequacy decision for PIPEDA-governed commercial organizations.
6. Audits
InvoToday will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and completed security questionnaires. Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by documentation, Customer may conduct (directly or through an independent auditor bound by confidentiality) an audit of InvoToday’s relevant processing, no more than once per 12 months, on at least 30 days’ written notice, during business hours, without disrupting operations, and at Customer’s expense. Audit results are InvoToday’s confidential information.
7. Liability
Each party’s liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Agreement, to the maximum extent permitted by law.
Annex A — Description of processing
- Subject matter and duration: provision of the InvoToday business-management service for the term of the Agreement, plus the post-termination export and deletion periods.
- Nature and purpose: hosting, storage, transmission, display, backup, and related technical processing needed to provide invoicing, purchasing, inventory, accounting, CRM, HR, point-of-sale, e-invoicing, printing, and reporting features, and to secure and support the Service.
- Categories of data subjects: Customer’s users and employees; Customer’s own customers, vendors, and business contacts; individuals appearing in documents Customer stores.
- Categories of personal data: identification and contact details (names, addresses, emails, phone numbers), business and employment details (job titles, departments, leave records), financial and transactional data (invoices, payments, bank account references, tax identifiers), and content of stored documents and notes. The Service is not intended for special categories of data (health, biometric, etc.), and Customer agrees not to submit them.
- Frequency: continuous, as driven by Customer’s use.
Annex B — Technical and organizational measures
- Encryption of data in transit (TLS 1.2+); one-way hashing of passwords; encrypted storage of integration credentials and API keys.
- Logical multi-tenant isolation with tenant-scoped queries and database-level row-level security on tenant tables.
- Role- and permission-based access control within workspaces, configurable by Customer; optional two-factor authentication; session revocation.
- Commit-scoped audit trail of data changes, including actor, time, and source.
- Hardened infrastructure: firewalled hosts, non-root service containers, security headers, restricted administrative access.
- Routine encrypted backups with defined rotation; documented restore procedures; per-tenant backup and export tooling.
- Observability and error monitoring for detection of anomalies; least-privilege access for operations personnel.
- Vendor due diligence for subprocessors; documented incident-response process (see the Security & Cyber Liability Statement).
Annex C — Authorized subprocessors
- Amazon Web Services, Inc. (Canada/USA) — cloud hosting, storage, and backups.
- Stripe, Inc. (USA/Ireland) — payment processing and subscription billing (InvoToday never stores full card numbers).
- Transactional email provider (USA) — delivery of system emails such as receipts, reminders, and security notices.
- Pydantic Services Inc. (Logfire) (USA) — application performance and error telemetry.
Customer-directed connections (not subprocessors): Intuit Inc. (QuickBooks Online), Lembaga Hasil Dalam Negeri Malaysia (MyInvois), and the AI provider configured by Customer (e.g. OpenAI, L.L.C. or Anthropic, PBC) under Customer’s own API key.