Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in the applicable account or order form (“Customer”) and InvoToday, a business operated from British Columbia, Canada (“InvoToday”), governing use of the InvoToday service (the “Agreement”). It applies whenever InvoToday processes personal data contained in Customer Data on Customer’s behalf, and is automatically accepted by Customer’s use of the Service. In case of conflict between this DPA and the Agreement, this DPA controls with respect to the processing of personal data.

1. Definitions

Data Protection Laws” means all laws applicable to the processing of personal data under the Agreement, including, where applicable, the EU and UK General Data Protection Regulation (“GDPR”), Canada’s PIPEDA, British Columbia’s PIPA, and Malaysia’s PDPA. “personal data”, “controller”, “processor”, “data subject”, and “processing” have the meanings given in the applicable Data Protection Laws. “SCCs” means the Standard Contractual Clauses approved by European Commission decision 2021/914 (Module Two: controller to processor), as amended or replaced.

2. Roles and scope

Customer is the controller (or a processor acting for another controller) of personal data in Customer Data; InvoToday is Customer’s processor. Each party will comply with the Data Protection Laws applicable to it. Customer is responsible for the lawfulness of the personal data it submits, including obtaining any required notices and consents from its own customers, vendors, and employees. The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex A.

3. InvoToday’s obligations

InvoToday will:

4. Subprocessors

Customer grants InvoToday general written authorization to engage the subprocessors listed in Annex C. InvoToday will impose data protection obligations on subprocessors that are materially no less protective than this DPA, and remains liable for their performance. InvoToday will update Annex C (published at our website) at least 15 days before adding or replacing a subprocessor; Customer may object on reasonable data-protection grounds within that period, and if the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period as its exclusive remedy. Third-party services that Customer chooses to connect (for example Intuit QuickBooks Online, the LHDN MyInvois platform, or the AI provider whose API key Customer supplies) are not subprocessors of InvoToday; they are separate controllers or processors engaged directly by Customer.

5. International transfers

Customer authorizes processing in Canada, the United States, and the other locations listed in Annex C. To the extent processing involves a transfer of personal data protected by the GDPR to a country without an adequacy decision, the SCCs are incorporated into this DPA, with Customer as “data exporter” and InvoToday as “data importer”; Annexes A–C serve as the SCC appendices; the optional docking clause applies; the governing law and forum for the SCCs are those of Ireland where required, and audits and instructions operate as set out in this DPA to the extent permitted. Canada currently benefits from an EU adequacy decision for PIPEDA-governed commercial organizations.

6. Audits

InvoToday will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and completed security questionnaires. Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by documentation, Customer may conduct (directly or through an independent auditor bound by confidentiality) an audit of InvoToday’s relevant processing, no more than once per 12 months, on at least 30 days’ written notice, during business hours, without disrupting operations, and at Customer’s expense. Audit results are InvoToday’s confidential information.

7. Liability

Each party’s liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Agreement, to the maximum extent permitted by law.

Annex A — Description of processing

Annex B — Technical and organizational measures

Annex C — Authorized subprocessors

Customer-directed connections (not subprocessors): Intuit Inc. (QuickBooks Online), Lembaga Hasil Dalam Negeri Malaysia (MyInvois), and the AI provider configured by Customer (e.g. OpenAI, L.L.C. or Anthropic, PBC) under Customer’s own API key.