Data Processing Addendum
This addendum forms part of the Terms of Service between the company using Invoverse ("Customer", the controller) and the operator of this Invoverse platform ("Processor").
- Subject. Processor processes personal data that Customer puts into the Service (its members' accounts, its clients' and contacts' details, and any personal data in its documents and messages) only to provide the Service, on Customer's documented instructions, which are these terms and Customer's use of the Service.
- Confidentiality. People authorised to process the data are bound to confidentiality.
- Security. Processor keeps appropriate technical and organisational measures, including encryption of each company's secrets with its own key, isolation of companies and of agents' commands, access controls with two-factor sign-in, and logged, permission-based support access.
- Sub-processors. Customer authorises hosting, email delivery, payment (Stripe) and the AI providers Customer chooses. Processor will tell Customer about new sub-processors in advance; Customer may object.
- Assistance. Processor helps Customer answer data subjects' requests and meet its security, breach notification and impact-assessment obligations, taking into account the nature of the processing.
- Breaches. Processor tells Customer without undue delay after becoming aware of a personal data breach.
- Deletion. When Customer deletes its company, Processor deletes its data and destroys its encryption key; copies in backups expire on their normal schedule.
- Audits. Processor makes available the information needed to show compliance with this addendum.
- Transfers. Where data leaves Customer's region, Processor uses a lawful transfer mechanism.
Contact for data protection matters: the contact address of this platform.