Third-Party Data Processors
Last updated: August 19, 2026
This Annexure forms an integral part of the Invoice45.com Privacy Policy (the “Policy”) and provides a comprehensive, detailed, and granular inventory of all third-party service providers, data processors, sub-processors, and infrastructure providers that Invoice45.com engages in the course of operating, maintaining, securing, and improving the Service. Each entity listed in this Annexure has been carefully evaluated, contracted, and bound by a legally enforceable Data Processing Agreement (DPA) that ensures compliance with the General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”), and all other applicable data protection laws.
This Annexure should be read in conjunction with Section 6 (“Third-Party Services and Data Processors”) of the Privacy Policy, which provides the overarching framework governing our relationships with third-party processors. The purpose of maintaining this Annexure as a separate, standalone document is to facilitate easy reference, to enable efficient updates as our processor ecosystem evolves, and to ensure that the most current and accurate information regarding our data processing arrangements is always available to data subjects, supervisory authorities, and other interested parties.
We review this Annexure at least quarterly and whenever there is a material change in our processor relationships. Each update to this Annexure is logged with a version number and effective date. If you require a historical version of this Annexure or a copy of any specific Data Processing Agreement referenced herein, please contact us at invoice45@allwebtech.in.
The following table provides a complete and exhaustive inventory of all third-party entities that process personal data on behalf of Invoice45.com. For each processor, we specify the legal entity name, jurisdiction of incorporation, the specific service provided, the categories of personal data processed, the legal basis relied upon for the transfer and processing, whether your explicit consent is required before the processor is activated, and whether a Data Processing Agreement is in place. This inventory is current as of the “Last updated” date shown at the top of this page.
| Service | Provider | Purpose | Data Processed | Consent Required |
|---|---|---|---|---|
| Google Analytics | Google LLC (United States) | Website traffic analysis, conversion tracking, user journey mapping, audience demographics, acquisition channel analysis, and cross-device reporting | Anonymised IP address (last octet truncated), pages viewed and session duration, screen resolution, device type and model, operating system, browser type and version, referring URL, geographic region (country-level only), language preferences, scroll events, click events, and custom event parameters | Yes (analytics) — activated only after explicit opt-in consent via the Cookiebot consent management banner |
| PostHog | PostHog Inc. (United States) | Product analytics, feature flag management, A/B testing, session replay (if enabled by configuration), funnel analysis, cohort analysis, and retention tracking | Page views, feature interaction events, custom event properties, distinct user identifier, session identifier, device type, operating system, browser information, and geographic region (country-level); data can be hosted in EU data centres upon request | Yes (analytics) — activated only after explicit opt-in consent via the Cookiebot consent management banner |
| Ahrefs | Ahrefs Pte. Ltd. (Singapore) | SEO analytics, competitive analysis, backlink monitoring, organic search performance tracking, keyword research, content gap analysis, and domain authority assessment | Traffic sources, organic keyword rankings, top-performing pages, referring domains, backlink profile data, crawl data, and domain-level metrics | Yes (analytics) — activated only after explicit opt-in consent via the Cookiebot consent management banner |
| Razorpay | Razorpay Software Private Limited (India) | Payment gateway services for processing credit/debit card payments, Unified Payments Interface (UPI) transactions, net banking, wallet payments, and EMI options | Transaction reference identifiers, payment amounts, payment method type (tokenised), payment authorisation status, refund and chargeback data, settlement identifiers; card details (PAN, CVV, expiry) are never stored, processed, or accessible to Invoice45.com and are handled entirely within Razorpay’s PCI DSS Level 1 certified tokenisation infrastructure | No (contractual necessity — Art. 6(1)(b); payment processing is essential to the service agreement) |
| Cashfree | Cashfree Payments India Private Limited (India) | Payment gateway services for processing bank transfers, National Electronic Funds Transfer (NEFT), Real-Time Gross Settlement (RTGS), Immediate Payment Service (IMPS), UPI collect requests, and bulk payouts | Transaction reference identifiers, payment amounts, bank account identifiers (masked), IFSC codes (masked), payment authorisation status, settlement data, and payout batch details | No (contractual necessity — Art. 6(1)(b); payment processing is essential to the service agreement) |
| All Web Tech | All Web Tech (India) | Cloud server hosting and infrastructure provision including compute instances, managed database hosting, block storage, object storage, networking, firewall configuration, and DDoS mitigation at the infrastructure layer | No access to production user data; infrastructure-level access only for server maintenance, security patching, operating system updates, performance monitoring, capacity planning, and disaster recovery operations | No (legitimate interest — Art. 6(1)(f); infrastructure access is necessary for service operation and security) |
| Nodemailer | Self-hosted (operated on Invoice45.com infrastructure within All Web Tech data centres) | Delivery of transactional emails including invoice PDFs, proposal notifications, proforma invoice copies, password reset links, account verification emails, account alerts, and system notifications | Recipient email address, email subject line, email body content (including invoice and proposal PDF content), delivery status (sent, delivered, bounced, deferred), open tracking data (if enabled), click tracking data (if enabled) | No (contractual necessity — Art. 6(1)(b); transactional email delivery is essential to the service) |
| Cookiebot / Usercentrics | Usercentrics GmbH (Germany) | Consent Management Platform (CMP) for recording, storing, and managing cookie consent preferences; generating proof of consent records; and controlling the activation of non-essential cookies and scripts | Consent timestamp, unique consent identifier, consent preferences per cookie category (necessary, analytics, marketing), anonymised user identifier, browser type and version, and the version of the consent banner displayed | No (legal obligation — Art. 6(1)(c); GDPR Article 7(1) requires proof of consent) |
| Cloudflare | Cloudflare Inc. (United States) | Content Delivery Network (CDN) for static asset acceleration, Distributed Denial of Service (DDoS) protection and mitigation, SSL/TLS certificate management and termination, bot detection and management, and Web Application Firewall (WAF) services | IP address (temporary, processed in transit only and not persisted in standard operation), HTTP request headers, cached static assets (CSS, JavaScript, images), security challenge results (CAPTCHA, JavaScript challenge), and TLS session data | No (legitimate interest — Art. 6(1)(f); CDN and DDoS protection are necessary for service availability and security) |
We maintain written, legally enforceable Data Processing Agreements with every third-party processor that handles personal data on our behalf. These agreements have been drafted to comply with the requirements of Article 28 of the GDPR and incorporate, at minimum, the following contractual provisions, which together ensure that each processor meets the high standards of data protection required by law:
Requesting Copies of DPAs
To request a copy of any specific Data Processing Agreement referenced in this Annexure, please contact us at invoice45@allwebtech.in and specify the processor whose DPA you wish to review. We will provide the requested document within thirty (30) calendar days of receipt. Where the DPA contains confidential commercial terms unrelated to data protection, such terms may be redacted.
Certain processors listed in this Annexure are located in jurisdictions outside the European Economic Area (EEA) and the United Kingdom that may not provide an adequate level of data protection as determined by the European Commission. Where personal data is transferred internationally, we rely on one or more of the following legal mechanisms to ensure that the data is protected to a standard essentially equivalent to that guaranteed within the EEA, in accordance with Chapter V of the GDPR:
| Processor | Jurisdiction | Transfer Mechanism | Additional Safeguards |
|---|---|---|---|
| Google LLC | United States | EU-US Data Privacy Framework (DPF) adequacy decision (Commission Implementing Decision (EU) 2023/1795); Standard Contractual Clauses (SCCs) as fallback (Decision 2021/914) | IP anonymisation enabled; data minimisation configured; retention limits enforced; no data shared with Google for Google’s own purposes |
| PostHog Inc. | United States | Standard Contractual Clauses (SCCs) (Decision 2021/914) | EU data residency available upon request; data encrypted at rest and in transit; minimal data collection principle applied |
| Cloudflare Inc. | United States | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs) as fallback | IP addresses processed in transit only; no persistent logging of personal IP data in standard operation; TLS 1.3 enforced |
| Ahrefs Pte. Ltd. | Singapore | EU adequacy decision for Singapore; Standard Contractual Clauses (SCCs) as fallback | Anonymised and aggregated data only; no directly identifiable personal data transferred in standard operation |
| Razorpay Software Pvt. Ltd. | India | Standard Contractual Clauses (SCCs); contractual necessity (Art. 6(1)(b)) | PCI DSS Level 1 certified; tokenisation of card data; no card data stored by Invoice45.com |
| Cashfree Payments India Pvt. Ltd. | India | Standard Contractual Clauses (SCCs); contractual necessity (Art. 6(1)(b)) | PCI DSS Level 1 certified; bank details masked; TLS encryption enforced |
| Usercentrics GmbH | Germany | EEA-based processor; no cross-border transfer | None required; data remains within the EEA at all times |
We continuously monitor the performance, compliance posture, and security practices of all third-party processors. In the event that we determine, in our sole discretion, that a processor no longer meets our standards for data protection, security, reliability, or compliance, we will take prompt action to either require remediation, impose additional contractual safeguards, or terminate the engagement and migrate to an alternative processor. We will update this Annexure promptly upon any change to our processor inventory, including the addition of new processors, the removal of existing processors, or material changes to the nature or scope of processing activities performed by any listed processor.
Where we introduce a new processor that processes personal data, we shall inform registered users via email and/or a prominent in-app notification at least thirty (30) calendar days before the new processor begins processing personal data, unless a shorter notice period is required by law or is impracticable due to urgent security or operational needs. During this notice period, you may object to the proposed change by contacting us at invoice45@allwebtech.in.