EU / EEA / UK users · Legal notice · effective September 25, 2026

EU/UK GDPR Addendum

European General Data Protection Regulation disclosures, lawful bases, controller information, and data subject rights.

This EU / UK GDPR Addendum supplements the Invozaa Privacy Policy and applies solely to natural persons located in the European Union, Iceland, Liechtenstein, Norway, and the United Kingdom (“Data Subjects”). In the event of a conflict between this Addendum and the global Privacy Policy, this Addendum prevails for EU/UK-based individuals.


1. Controller & EU Representative
Controller identity: Invozaa
EU Representative (Article 27): Where Invozaa is not established in the EU, we have appointed an EU-based representative located at the following address: support@invozaa.com. EU Data Subjects may address correspondence relating to their GDPR rights to this representative in any official EU language.
UK Representative (UK GDPR Article 27): Same representative as above, additionally designated under UK GDPR.


2. Categories of personal data processed & corresponding lawful bases (Article 6)
- Account registration data (name, email, business identity fields): Article 6(1)(b) — necessary for the performance of the contract for the provision of the Service to you. Legitimate interest basis (6(1)(f)) is not relied upon for registration.
- Document & line-item content: Article 6(1)(b) performance of contract. Where submitted data relates to third parties, you confirm that you act as the independent controller for that third-party data and that you have the appropriate legal basis to share it with us as a processor.
- IP address, User-Agent, PDF download metadata: Article 6(1)(f) legitimate interest — enforcement of paid-download quotas, fraud prevention, and abuse detection. Our balancing test: we record the minimum fields necessary (no full request body, no payload content) and the data is retained for only 18 months before automatic deletion.
- Payment transaction metadata (gateway ref, currency, amount, payer identity): Article 6(1)(b) performance of contract + Article 6(1)(c) legal obligation (7-year tax/accounting retention requirement).
- Marketing communication consent: Article 6(1)(a) explicit, opt-in consent. Unsubscribe / withdraw-consent link is present in every marketing message.
- Compelled disclosures by public authority: Article 6(1)(c) legal obligation; Article 6(1)(e) where processing is necessary for a task carried out in the public interest.


3. Data subject rights (Articles 15–22)
Right of access (15): You may request a structured copy of all personal data we hold about you, including the purpose(s) of processing, categories of recipient, storage location country, and envisaged retention period.
Right to rectification (16): Corrections requested by email to support@invozaa.com are implemented within 10 business days where validated.
Right to erasure / “Right to be forgotten” (17): We honour this right where applicable, except where processing is required by EU/UK law (for example accounting retention of 7 years). If an invoice or receipt was paid and sent to a third party, we will retain a minimum audit record of the transaction for the legally required period, and remove your free-text client notes, logos, and branding fields.
Right to restriction (18): If you dispute the accuracy of the data, or if the processing is unlawful and you oppose erasure, we will restrict active processing (to storage only) during a 30-day review window.
Right to data portability (20): Structured export of data you directly provided to us (account fields, invoices you authored, receipt data you submitted) is available as a JSON file from the authenticated “Reports” page or via a signed request to support@invozaa.com.
Right to object (21): You may object at any time to processing based on Article 6(1)(f) legitimate interest or 6(1)(e) public-interest basis. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests and rights.
Right to object to direct marketing: One-click unsubscribe link in every message. Requests honoured within 10 working days.
Rights related to automated decision-making & profiling (22): Invozaa does NOT perform any fully automated decision-making (including profiling) that produces legal or similarly significant effects on Data Subjects. All pricing, download quota, and feature-limit decisions are deterministic policy parameters that you can review in-product at any time before taking action.


4. Supervisory authority
EU Data Subjects may file a complaint with the supervisory data protection authority of the EU Member State of their habitual residence, place of work, or place of an alleged infringement. UK Data Subjects may file a complaint with the UK Information Commissioner’s Office (ICO, ico.org.uk).


5. International transfers
Where Invozaa transfers EU/UK personal data to a processor established outside the EU/UK without an adequacy decision, the transfer is performed exclusively under the European Commission Standard Contractual Clauses (SCCs) (2021/914) or the UK International Data Transfer Addendum (IDTA, SI 2022/129 Sch 1) as applicable, supplemented by Binding Corporate Rules (BCRs) for intra-group transfers where the sub-processor has published BCRs.
A copy of our executed SCCs / IDTA Addendums for any sub-processor is available on written request to support@invozaa.com.


6. Sub-processors
Payment processing — Flutterwave (card, bank transfer, wallet methods): data sent = payer name, payer email, invoice/receipt number, currency, amount. Payload encrypted TLS 1.3 between browser and gateway.
Cloud infrastructure — VPS provider with encrypted storage; data centre jurisdiction = currently Frankfurt, Germany (AWS eu-central-1 / Hetzner Nuremberg).
Transactional email delivery — SMTP service provider with AES-256 at-rest storage, EU data residency selected.
All sub-processor agreements satisfy Article 28 GDPR / Sch 1 IDTA requirements (topic, duration, nature/purpose of processing, type of personal data, categories of data subjects, controller obligations and liabilities, technical and organisational security measures, sub-processing authorisation flow, deletion or return at end of service, audit rights, cooperation obligations).


7. Breach notification (Article 33 & 34)
Notification to competent supervisory authority (Art. 33): within 72 hours of becoming aware of a personal data breach where the breach is not unlikely to result in a risk to the rights and freedoms of natural persons, including a description of the nature of the breach, categories and approximate number of data subjects concerned, categories and approximate number of personal data records concerned, the likely consequences, and the measures taken or proposed to mitigate.
Communication to Data Subject (Art. 34): without undue delay where the personal data breach is likely to result in a high risk to their rights and freedoms. Communication includes recommendations to mitigate and a point of contact for more information.
8. Data Protection Officer (DPO)
Where required by Article 37 GDPR, Invozaa has appointed a DPO. Contact the DPO for matters relating to processing of personal data, exercise of rights, or DPIA review at: support@invozaa.com