Data Processing Addendum
Last updated: 4 May 2026. This DPA forms part of the Terms of Service between you and CHIMISMART LTD and governs the processing of personal data in connection with the Invoicify Service.
1. Definitions
Terms defined in the Terms of Service have the same meaning here. In addition:
- “Applicable Data Protection Law” means (a) UK GDPR and the Data Protection Act 2018; (b) EU GDPR (Regulation (EU) 2016/679); and (c) any other applicable data protection legislation, as amended from time to time.
- “Controller” means the Customer, who determines the purposes and means of processing personal data.
- “Processor” means CHIMISMART LTD, who processes personal data on behalf of the Controller.
- “Data Subject” means an identified or identifiable natural person whose personal data is processed.
- “Personal Data” has the meaning given in Applicable Data Protection Law.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- “SCCs” means the Standard Contractual Clauses adopted by the European Commission or the UK Information Commissioner’s Office for international transfers of personal data.
- “Sub-processor” means any third party engaged by CHIMISMART LTD to process Personal Data on behalf of the Customer.
2. Roles and Responsibilities
The parties acknowledge that, in connection with the provision of the Service:
- The Customer acts as the Controller of Personal Data relating to its clients, employees, and other Data Subjects whose data is uploaded to or processed through the Service.
- CHIMISMART LTD acts as the Processor, processing that Personal Data solely on the documented instructions of the Customer and for the purpose of providing the Service.
- CHIMISMART LTD acts as an independent Controller in respect of its own account management, billing, and marketing data (governed separately by the Privacy Policy).
3. Processing Details (Schedule 1)
| Subject matter | Processing of personal data to deliver the Invoicify invoice management service. |
| Duration | For the term of the Customer’s Subscription, plus the 30-day post-cancellation data export window and subsequent backup retention period. |
| Nature of processing | Storage, retrieval, display, PDF generation, email delivery, and backup of invoice data and associated client records. |
| Purpose | To enable the Customer to create, manage, and send professional invoices to its clients. |
| Types of Personal Data | Client names, business names, email addresses, postal addresses, phone numbers, and financial transaction amounts as entered by the Customer. |
| Categories of Data Subjects | The Customer’s clients, suppliers, or other third parties whose details the Customer enters into the Service. |
4. Obligations of the Processor
CHIMISMART LTD, as Processor, shall:
- Process Personal Data only on documented instructions from the Customer (which includes the Terms of Service and this DPA), unless required to do so by applicable law;
- Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations;
- Implement and maintain appropriate technical and organisational security measures as described in Schedule 3 of this DPA;
- Not engage Sub-processors without the Customer’s prior general written authorisation (given by acceptance of this DPA) and only on terms equivalent to those in this DPA;
- Assist the Customer, where technically and commercially reasonable, in meeting its obligations to respond to Data Subject requests under Applicable Data Protection Law;
- Assist the Customer in ensuring compliance with its obligations regarding security, breach notification, and data protection impact assessments;
- At the Customer’s option, delete or return all Personal Data on termination of the Service, and delete existing copies unless retention is required by applicable law;
- Make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA.
5. Sub-processors (Schedule 2)
The Customer grants CHIMISMART LTD general authorisation to engage the following categories of Sub-processors. We will provide at least 14 days’ notice (by email or via this page) before adding or replacing a Sub-processor:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud hosting provider | Infrastructure, storage, and database services | EU / UK |
| Stripe, Inc. | Payment processing and subscription billing | USA (SCCs apply) |
| Transactional email provider | Sending invoice and notification emails | EU / UK |
| Analytics provider | Aggregated usage analytics (no Personal Data from Customer Data) | EU |
An up-to-date list of Sub-processors is available on request at info@useinvoicify.com.
6. International Data Transfers
We endeavour to host and process Customer Data within the EU or UK. Where a Sub-processor is located outside the EU/UK in a country not recognised as providing adequate protection (such as the United States), we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) for transfers from the EU; and/or
- UK International Data Transfer Agreements (IDTAs) or UK Addenda to EU SCCs for transfers from the UK.
Copies of applicable SCCs or IDTAs are available on request at info@useinvoicify.com.
7. Security Measures (Schedule 3)
CHIMISMART LTD implements and maintains the following technical and organisational measures:
- Encryption in transit: TLS 1.2 or higher for all data transmitted between the Service and end users.
- Encryption at rest: Customer Data stored in encrypted form using industry-standard algorithms.
- Access control: Role-based access controls; production systems accessible only to authorised personnel via authenticated sessions.
- Password security: Passwords hashed using a strong one-way algorithm; plain-text passwords are never stored.
- Backups: Automatic daily backups retained for a minimum of 30 days; backups are encrypted.
- Vulnerability management: Regular review of dependencies and patches; security updates applied on a risk-prioritised basis.
- Incident response: Documented procedures for identifying, containing, and recovering from security incidents.
8. Personal Data Breach Notification
In the event of a Personal Data Breach affecting Customer Data, CHIMISMART LTD shall:
- Notify the Customer without undue delay and, where feasible, within 72 hours of becoming aware of the breach;
- Provide sufficient information to enable the Customer to meet its notification obligations to supervisory authorities and Data Subjects;
- Co-operate with the Customer and take reasonable steps to mitigate the effects of the breach.
Breach notifications should be sent to the Customer’s registered email address. The Customer is responsible for notifying the relevant supervisory authority (e.g. the UK ICO) where required.
9. Data Subject Rights
CHIMISMART LTD will, on request, assist the Customer in responding to Data Subject requests (access, rectification, erasure, restriction, portability, and objection) relating to Personal Data processed on behalf of the Customer. Where a Data Subject contacts CHIMISMART LTD directly, we will promptly forward the request to the Customer’s registered email address.
10. Data Retention and Deletion
On termination or expiry of the Customer’s Subscription, Customer Data remains accessible for export for 30 days. After that period:
- Live Customer Data is deleted from production systems;
- Encrypted backup copies may be retained for up to a further 90 days before being permanently deleted;
- We may retain anonymised or aggregated data that cannot be linked to an individual or to the Customer.
You may request early deletion of your Customer Data by contacting info@useinvoicify.com.
11. Audit Rights
The Customer may, on reasonable notice (not less than 30 days) and no more than once per 12-month period, request information from CHIMISMART LTD to verify compliance with this DPA. CHIMISMART LTD will respond to such requests by providing a written compliance summary and, where applicable, relevant third-party audit certifications. Physical audits of CHIMISMART LTD infrastructure may be conducted only with reasonable prior notice and subject to confidentiality obligations.
12. Governing Law
This DPA is governed by and construed in accordance with the laws of England and Wales. Any dispute arising from this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
13. Contact
For any data protection queries, to exercise Data Subject rights, or to request a signed copy of this DPA, contact our data protection contact:
CHIMISMART LTD (trading as Invoicify)
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: info@useinvoicify.com
Legal notice: This DPA is a starting-point template adapted for a UK-registered SaaS. The sub-processor table, transfer mechanisms, and security measures should be verified against your actual infrastructure before relying on this document. We recommend review by a UK solicitor or data protection specialist, particularly the SCCs/IDTA provisions.
