Legal

Data Processing Agreement

Last updated 23 July 2026

When you invoice someone, you put their name, address and contact details into Invoice Forever. That is your customer's personal data, not yours, which under the GDPR makes you its controller and us your processor. Article 28 requires a written agreement between us covering exactly that. This page is it.

It applies automatically from the moment you create an account. You do not need to sign anything, request a copy or negotiate terms, which is deliberate: a freelancer invoicing three clients should not have to chase a company for paperwork to be compliant.

The short version. We process the client data you enter only to run the service, only on your instructions, with confidentiality and security obligations, using the subprocessors listed publicly on this page. You can export or delete it yourself at any time. If there is a breach, we tell you without undue delay.

1. Who is who

You, the account holder, are the controller. Thomas van der Bruggen Holding B.V., registered in the Netherlands under number 75464136, is the processor. This agreement covers only data you enter about other people. For your own account data we are the controller, and the privacy policy governs that instead.

2. What we process, and for how long

Subject matter: providing an invoicing service. Duration: as long as your account exists. Nature and purpose: storing, organising and rendering the records you create, so you can produce invoices, estimates and credit notes and send them.

Categories of data subject: your clients and their contacts. Categories of personal data: names, business names, postal addresses, email addresses, tax identification numbers, and whatever you choose to write in a line item or note.

The service is not built for special-category data under Article 9, and you should not put health, biometric or similar data into an invoice line.

3. Our obligations

Under Article 28(3) we commit to the following.

  • Only on your instructions. We process the data only to provide the service, or where EU or member-state law requires otherwise, in which case we tell you first unless that law forbids it. We do not sell it, mine it, use it for advertising, or use it to train machine-learning models.
  • Confidentiality. Anyone with access is bound to keep it confidential. In practice the number of people who can reach production is one.
  • Security. We take the measures required by Article 32, described in plain terms on the security page: encryption in transit and at rest, per-account isolation enforced on the server for every single request, and hashed credentials.
  • Subprocessors. You give general authorisation for those listed on the subprocessors page. We publish any change there before it takes effect so you can object, and every subprocessor is bound to equivalent obligations.
  • Helping you answer your own data subjects. If a client asks you for access, correction, deletion or a copy of their data, the app already lets you do all of it yourself. Where it does not, we help.
  • Breach notification. If personal data is breached we notify you without undue delay after becoming aware, with what we know and what we are doing about it, so you can meet your own 72-hour obligation.
  • Assistance with Articles 32 to 36. We help with security, breach handling and impact assessments as far as is reasonable given the information available to us.
  • Deletion or return. Deleting your account erases the data immediately, and you can export everything first from Settings. Backups age out on their normal cycle.
  • Demonstrating compliance. We make available the information needed to show these obligations are met, and allow audits or inspections on reasonable notice.

4. International transfers

Your invoice and client records are stored in the EU. Website hosting and transactional email involve United States providers under Standard Contractual Clauses. Each provider, its location and its transfer basis is listed on the subprocessors page.

5. Your side of it

You are responsible for having a lawful basis to hold your clients' data in the first place, for its accuracy, and for telling those clients what they need to be told. We cannot do any of that for you, because we never see the relationship behind the invoice.

6. Liability and governing law

The limitations in the terms of service apply to this agreement, except where the GDPR does not permit them to. It is governed by Dutch law. Where this agreement and the terms of service conflict on the processing of client personal data, this agreement wins.

7. Changes

If this agreement changes materially we update the date above and note it in the changelog. Questions, or a need for a countersigned copy for your own records? Email hello@invoiceforever.com and you will get a reply from a person.