Data processing agreement
Terms and information for using Bivetica Invoice.
Scope and roles
For customer, supplier, employee or other personal data entered by a business, that business is the controller and Bivetica acts as processor to provide the subscribed service. Processing continues for the service duration and applicable return, deletion or legally required retention period. Account administration, Bivetica billing and security records are handled under the separate controller purposes in the privacy notice.
Data and instructions
Processing covers storing, organising, retrieving, displaying, exporting and, when instructed, sending business contact details, invoices, quotes, expenses, documents and associated transaction records. The people concerned include customers, suppliers, employees, contractors and contacts identified in those records. We process these records on documented instructions, including authorised account actions, except where the law requires otherwise. We inform you of a legal requirement unless prohibited and flag instructions we believe infringe applicable data-protection law.
Confidentiality and security
We limit access to authorised people subject to confidentiality duties and use measures appropriate to the risk, including encrypted connections, hashed passwords, permission checks and protected integration credentials. We do not promise that any system is immune to incidents. The security notice explains reporting and assistance.
Service providers
You authorise the providers described in our service-provider register for the relevant functions. We give notice of material processor changes so you can raise a reasonable data-protection objection and discuss an alternative or ending the affected service. Processors handling business records must be subject to appropriate written duties; Bivetica remains responsible for its processor obligations. Stripe and GoCardless may also act as independent controllers for payment, fraud and regulatory purposes, as explained in their notices.
Rights, incidents and assistance
We assist with access, correction, deletion and other rights requests, security incidents, impact assessments and regulatory consultation as appropriate to the information and service involved. Tell us at hello@bivetica.com. We notify the controller without undue delay after becoming aware of a personal-data breach affecting records processed for it and provide available information and updates.
Return, deletion and accountability
At the end of the service, we provide reasonable assistance to return or delete business personal data at your choice, subject to legal retention duties. Retained backups remain protected until replaced or removed. We make information reasonably needed to demonstrate our processor obligations available and cooperate with proportionate audits or inspections under confidentiality and security arrangements. International processing must use a lawful transfer basis; contact us for the applicable provider and safeguard information.
Stripe privacy notice · Stripe cookie policy · GoCardless payer privacy · Bivetica privacy notice