Legal notice · effective September 25, 2026

Privacy Policy

How we collect, process, share, and protect personal information on our platform.

1. Who we are
This Privacy Policy describes how Invozaa (“we”, “our”, “the Controller”) collects, uses, shares, stores, and protects personal information when you use our invoice and receipt platform. If you have any privacy-related questions or requests, email our Data Protection lead at support@invozaa.com.


2. Personal data we collect
Account information: full name, email address, business / company name, telephone number, uploaded logo file, tax ID / company registration number, business address, website URL.
Document content: client names, client emails, client phone numbers, line-item descriptions, quantities, amounts, payment references, and any free-form notes you add to invoices and receipts.
Usage data: authenticated session cookies, magic-link tokens (short-lived), IP address and browser User-Agent (recorded at the time of every PDF download for quota enforcement), and de-identified server request logs.
Payment information: payment amounts, currency, gateway reference codes, payment status, payer name and payer email. We do NOT store full card numbers, CVV, or authentication values — those are handled exclusively by the payment processor (currently Flutterwave) on their PCI DSS compliant systems.


3. Why we process it & legal bases
Performance of contract: we use your account data and document content to generate the PDFs you request, to enforce paid download quotas, and to support your dashboard history view.
Legitimate interest: fraud prevention, quota enforcement, de-identified product analytics, and sending transactional emails (magic links, verify emails, payment receipts).
Consent: sending promotional marketing messages — only if you explicitly opt-in. You can withdraw consent at any time.
Compliance with law: retention of transaction records and business correspondence required by tax, accounting, and data protection legislation in the jurisdictions in which we operate.


4. International transfers of data
Your personal data may be processed by sub-processors outside the country in which you are resident, including but not limited to server infrastructure, cloud storage providers, and payment processors. Where we transfer personal data outside an adequate jurisdiction, we rely on recognised transfer mechanisms including the EU Standard Contractual Clauses (SCCs), UK International Data Transfer Addendum (IDTA), Binding Corporate Rules (BCRs), or operator adequacy decisions.


5. Retention schedule
Account profile data: retained for as long as your account is active, plus a 365-day grace period following closure.
Invoices, receipts, and payment records: retained for 7 years from the date of last transaction to satisfy tax and accounting record-keeping obligations in our operating jurisdictions.
Download-tracking IP and User-Agent records: retained for 18 months for quota enforcement and fraud review, then automatically deleted.
Magic-link tokens, email-verification tokens, and session data: deleted automatically within 24 hours of creation or expiry, whichever occurs first.


6. Data subject rights
Depending on your jurisdiction, you may be entitled to: (a) access a copy of the personal information we hold about you; (b) request rectification of inaccurate data; (c) request erasure (“right to be forgotten”) where processing is no longer necessary; (d) restrict processing; (e) request portability of data you provided to us in a structured, machine-readable format; (f) object to processing based on legitimate interest or direct marketing; (g) where processing is automated, to receive the logic of any automated decision that produces significant effects.
To exercise any of these rights, send a signed request to support@invozaa.com. We respond to valid identity-verified requests within 30 days, extended by an additional 60 days if the request is complex or voluminous.


7. Cookies & similar technologies
We use strictly-necessary cookies only: (1) the Laravel session cookie that keeps you authenticated once you click a magic link, and (2) the XSRF-TOKEN cookie that protects your forms against cross-site request forgery. No tracking cookies, analytics cookies, or third-party ad cookies are set by Invozaa on the public site. The consent dialog on the invoice studio records a 12-month first-party cookie named “policy_consent” to remember your Accept/Reject choice and prevent the dialog from reappearing.


8. Security measures
In-transit encryption: all connections to our platform and API use TLS 1.2 or higher; HSTS is enforced via response headers.
At-rest encryption: sensitive database columns, uploaded logo files, and payment-tracking records are encrypted at rest using AES-256-GCM with keys rotated quarterly.
Access control: access to production systems requires role-based access controls, two-factor authentication, and per-user audit logging.
Backups: encrypted daily off-site backups retained for 30 days with an annual immutable snapshot.
Encryption of PHI (HIPAA users): Protected Health Information submitted in the US is encrypted in-transit and at-rest with separate keys, access audit trails, and employee workforce training logs.


9. Breach notification procedure
Any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data is assessed within 24 hours of detection. Notifications to supervisory authorities are made within 72 hours of awareness where the breach results in a risk to the rights and freedoms of natural persons, consistent with GDPR, NDPR, and HIPAA Breach Notification Rule timelines. Affected individuals are notified without undue delay where the breach is likely to result in a high risk.


10. Children’s privacy
The Service is not directed to, and we do not knowingly collect personal information from, children under the age of 13 (or the relevant age limit in your jurisdiction). If we learn we have collected personal information from a child, we will delete that information immediately.


11. Changes to this Privacy Policy
We update this Privacy Policy from time to time to reflect changes in our processing activities, product features, or applicable law. The current effective date is posted at the end of this page; material changes are communicated to active account holders via email at least 14 days before they take effect.


12. Contact the Controller
support@invozaa.com