Legal

Annexure 01

Third-Party Data Processors

Last updated: August 19, 2026

Purpose

Purpose of This Annexure

This Annexure forms an integral part of the Invoice45.com Privacy Policy (the “Policy”) and provides a comprehensive, detailed, and granular inventory of all third-party service providers, data processors, sub-processors, and infrastructure providers that Invoice45.com engages in the course of operating, maintaining, securing, and improving the Service. Each entity listed in this Annexure has been carefully evaluated, contracted, and bound by a legally enforceable Data Processing Agreement (DPA) that ensures compliance with the General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”), and all other applicable data protection laws.

This Annexure should be read in conjunction with Section 6 (“Third-Party Services and Data Processors”) of the Privacy Policy, which provides the overarching framework governing our relationships with third-party processors. The purpose of maintaining this Annexure as a separate, standalone document is to facilitate easy reference, to enable efficient updates as our processor ecosystem evolves, and to ensure that the most current and accurate information regarding our data processing arrangements is always available to data subjects, supervisory authorities, and other interested parties.

We review this Annexure at least quarterly and whenever there is a material change in our processor relationships. Each update to this Annexure is logged with a version number and effective date. If you require a historical version of this Annexure or a copy of any specific Data Processing Agreement referenced herein, please contact us at invoice45@allwebtech.in.

Inventory

Complete Processor Inventory

The following table provides a complete and exhaustive inventory of all third-party entities that process personal data on behalf of Invoice45.com. For each processor, we specify the legal entity name, jurisdiction of incorporation, the specific service provided, the categories of personal data processed, the legal basis relied upon for the transfer and processing, whether your explicit consent is required before the processor is activated, and whether a Data Processing Agreement is in place. This inventory is current as of the “Last updated” date shown at the top of this page.

ServiceProviderPurposeData ProcessedConsent Required
Google AnalyticsGoogle LLC (United States)Website traffic analysis, conversion tracking, user journey mapping, audience demographics, acquisition channel analysis, and cross-device reportingAnonymised IP address (last octet truncated), pages viewed and session duration, screen resolution, device type and model, operating system, browser type and version, referring URL, geographic region (country-level only), language preferences, scroll events, click events, and custom event parametersYes (analytics) — activated only after explicit opt-in consent via the Cookiebot consent management banner
PostHogPostHog Inc. (United States)Product analytics, feature flag management, A/B testing, session replay (if enabled by configuration), funnel analysis, cohort analysis, and retention trackingPage views, feature interaction events, custom event properties, distinct user identifier, session identifier, device type, operating system, browser information, and geographic region (country-level); data can be hosted in EU data centres upon requestYes (analytics) — activated only after explicit opt-in consent via the Cookiebot consent management banner
AhrefsAhrefs Pte. Ltd. (Singapore)SEO analytics, competitive analysis, backlink monitoring, organic search performance tracking, keyword research, content gap analysis, and domain authority assessmentTraffic sources, organic keyword rankings, top-performing pages, referring domains, backlink profile data, crawl data, and domain-level metricsYes (analytics) — activated only after explicit opt-in consent via the Cookiebot consent management banner
RazorpayRazorpay Software Private Limited (India)Payment gateway services for processing credit/debit card payments, Unified Payments Interface (UPI) transactions, net banking, wallet payments, and EMI optionsTransaction reference identifiers, payment amounts, payment method type (tokenised), payment authorisation status, refund and chargeback data, settlement identifiers; card details (PAN, CVV, expiry) are never stored, processed, or accessible to Invoice45.com and are handled entirely within Razorpay’s PCI DSS Level 1 certified tokenisation infrastructureNo (contractual necessity — Art. 6(1)(b); payment processing is essential to the service agreement)
CashfreeCashfree Payments India Private Limited (India)Payment gateway services for processing bank transfers, National Electronic Funds Transfer (NEFT), Real-Time Gross Settlement (RTGS), Immediate Payment Service (IMPS), UPI collect requests, and bulk payoutsTransaction reference identifiers, payment amounts, bank account identifiers (masked), IFSC codes (masked), payment authorisation status, settlement data, and payout batch detailsNo (contractual necessity — Art. 6(1)(b); payment processing is essential to the service agreement)
All Web TechAll Web Tech (India)Cloud server hosting and infrastructure provision including compute instances, managed database hosting, block storage, object storage, networking, firewall configuration, and DDoS mitigation at the infrastructure layerNo access to production user data; infrastructure-level access only for server maintenance, security patching, operating system updates, performance monitoring, capacity planning, and disaster recovery operationsNo (legitimate interest — Art. 6(1)(f); infrastructure access is necessary for service operation and security)
NodemailerSelf-hosted (operated on Invoice45.com infrastructure within All Web Tech data centres)Delivery of transactional emails including invoice PDFs, proposal notifications, proforma invoice copies, password reset links, account verification emails, account alerts, and system notificationsRecipient email address, email subject line, email body content (including invoice and proposal PDF content), delivery status (sent, delivered, bounced, deferred), open tracking data (if enabled), click tracking data (if enabled)No (contractual necessity — Art. 6(1)(b); transactional email delivery is essential to the service)
Cookiebot / UsercentricsUsercentrics GmbH (Germany)Consent Management Platform (CMP) for recording, storing, and managing cookie consent preferences; generating proof of consent records; and controlling the activation of non-essential cookies and scriptsConsent timestamp, unique consent identifier, consent preferences per cookie category (necessary, analytics, marketing), anonymised user identifier, browser type and version, and the version of the consent banner displayedNo (legal obligation — Art. 6(1)(c); GDPR Article 7(1) requires proof of consent)
CloudflareCloudflare Inc. (United States)Content Delivery Network (CDN) for static asset acceleration, Distributed Denial of Service (DDoS) protection and mitigation, SSL/TLS certificate management and termination, bot detection and management, and Web Application Firewall (WAF) servicesIP address (temporary, processed in transit only and not persisted in standard operation), HTTP request headers, cached static assets (CSS, JavaScript, images), security challenge results (CAPTCHA, JavaScript challenge), and TLS session dataNo (legitimate interest — Art. 6(1)(f); CDN and DDoS protection are necessary for service availability and security)
DPAs

Data Processing Agreement Summary

We maintain written, legally enforceable Data Processing Agreements with every third-party processor that handles personal data on our behalf. These agreements have been drafted to comply with the requirements of Article 28 of the GDPR and incorporate, at minimum, the following contractual provisions, which together ensure that each processor meets the high standards of data protection required by law:

  • Documented Instructions: The processor shall process personal data only on the documented instructions of Invoice45.com, including with regard to transfers of personal data to a third country or international organisation, unless required to do so by Union or Member State law; in such case, the processor shall inform Invoice45.com of that legal requirement before processing.
  • Confidentiality: The processor shall ensure that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Security Measures: The processor shall implement appropriate technical and organisational measures as required by Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risk to the rights and freedoms of natural persons.
  • Sub-Processor Restrictions: The processor shall not engage another processor without the prior specific or general written authorisation of Invoice45.com. In the case of general written authorisation, the processor shall inform Invoice45.com of any intended changes, giving Invoice45.com the opportunity to object.
  • Data Subject Rights Assistance: The processor shall assist Invoice45.com by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Invoice45.com’s obligation to respond to requests for exercising the data subject’s rights under Chapter III of the GDPR.
  • Breach Notification: The processor shall notify Invoice45.com without undue delay after becoming aware of a personal data breach and shall provide sufficient information to enable Invoice45.com to meet any obligations to report or inform data subjects of the breach.
  • Data Deletion and Return: Upon termination of the data processing agreement, the processor shall, at the choice of Invoice45.com, delete or return all personal data to Invoice45.com and delete existing copies, unless Union or Member State law requires continued storage of the personal data.
  • Audit and Inspection Rights: The processor shall make available to Invoice45.com all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits and inspections conducted by Invoice45.com or another auditor mandated by Invoice45.com.

Requesting Copies of DPAs

To request a copy of any specific Data Processing Agreement referenced in this Annexure, please contact us at invoice45@allwebtech.in and specify the processor whose DPA you wish to review. We will provide the requested document within thirty (30) calendar days of receipt. Where the DPA contains confidential commercial terms unrelated to data protection, such terms may be redacted.

Safeguards

International Transfer Safeguards

Certain processors listed in this Annexure are located in jurisdictions outside the European Economic Area (EEA) and the United Kingdom that may not provide an adequate level of data protection as determined by the European Commission. Where personal data is transferred internationally, we rely on one or more of the following legal mechanisms to ensure that the data is protected to a standard essentially equivalent to that guaranteed within the EEA, in accordance with Chapter V of the GDPR:

ProcessorJurisdictionTransfer MechanismAdditional Safeguards
Google LLCUnited StatesEU-US Data Privacy Framework (DPF) adequacy decision (Commission Implementing Decision (EU) 2023/1795); Standard Contractual Clauses (SCCs) as fallback (Decision 2021/914)IP anonymisation enabled; data minimisation configured; retention limits enforced; no data shared with Google for Google’s own purposes
PostHog Inc.United StatesStandard Contractual Clauses (SCCs) (Decision 2021/914)EU data residency available upon request; data encrypted at rest and in transit; minimal data collection principle applied
Cloudflare Inc.United StatesEU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs) as fallbackIP addresses processed in transit only; no persistent logging of personal IP data in standard operation; TLS 1.3 enforced
Ahrefs Pte. Ltd.SingaporeEU adequacy decision for Singapore; Standard Contractual Clauses (SCCs) as fallbackAnonymised and aggregated data only; no directly identifiable personal data transferred in standard operation
Razorpay Software Pvt. Ltd.IndiaStandard Contractual Clauses (SCCs); contractual necessity (Art. 6(1)(b))PCI DSS Level 1 certified; tokenisation of card data; no card data stored by Invoice45.com
Cashfree Payments India Pvt. Ltd.IndiaStandard Contractual Clauses (SCCs); contractual necessity (Art. 6(1)(b))PCI DSS Level 1 certified; bank details masked; TLS encryption enforced
Usercentrics GmbHGermanyEEA-based processor; no cross-border transferNone required; data remains within the EEA at all times
Changes

Changes to Processor Inventory

We continuously monitor the performance, compliance posture, and security practices of all third-party processors. In the event that we determine, in our sole discretion, that a processor no longer meets our standards for data protection, security, reliability, or compliance, we will take prompt action to either require remediation, impose additional contractual safeguards, or terminate the engagement and migrate to an alternative processor. We will update this Annexure promptly upon any change to our processor inventory, including the addition of new processors, the removal of existing processors, or material changes to the nature or scope of processing activities performed by any listed processor.

Where we introduce a new processor that processes personal data, we shall inform registered users via email and/or a prominent in-app notification at least thirty (30) calendar days before the new processor begins processing personal data, unless a shorter notice period is required by law or is impracticable due to urgent security or operational needs. During this notice period, you may object to the proposed change by contacting us at invoice45@allwebtech.in.