Personal Data Collection Inventory
Last updated: August 19, 2026
This Annexure forms an integral part of the Invoice45.com Privacy Policy (the “Policy”) and provides a comprehensive, detailed, and granular inventory of all categories of personal data that Invoice45.com collects, receives, records, and processes in connection with the operation of its cloud-based invoicing, proposal management, and professional services automation application (the “Service”). This Annexure specifies, for each collection touchpoint and data category, the precise types of personal data collected, the specific purposes for which the data is processed, the retention period applicable to each data category, the legal basis relied upon for the processing, and whether explicit user consent is required before the collection commences.
The information contained in this Annexure is intended to satisfy the transparency and information obligations imposed by Articles 13 and 14 of the GDPR, to assist data protection officers, supervisory authorities, and other stakeholders in assessing the lawfulness and proportionality of Invoice45.com’s data processing activities, and to provide data subjects with clear, accessible, and complete information about how their personal data is handled throughout its lifecycle, from collection through storage, use, and eventual deletion.
We collect personal data both directly from you when you voluntarily provide it in the course of using the Service and indirectly through automated technical means such as cookies, server logs, and analytics tools. We do not collect personal data that is excessive, irrelevant, or not reasonably necessary for the specific purposes described below. For detailed information about cookies and tracking technologies, please refer to Section 5 of the Privacy Policy. For information about the third-party processors that handle the data listed in this Annexure, please refer to Annexure 01 (Third-Party Data Processors).
The following table provides a complete and exhaustive inventory of all categories of personal data collected through each touchpoint, interaction channel, and automated means. For each touchpoint, the table specifies the exact data elements collected, the purposes for which each element is processed, and the legal basis supporting the processing. This inventory is current as of the “Last updated” date shown at the top of this page and is reviewed at least quarterly.
| Touchpoint | Data Collected | Purpose |
|---|---|---|
| Account Creation | Full name, email address, password (salted and hashed using bcrypt with 12 salt rounds), company or business name, account creation timestamp | To create, maintain, and administer your user account; to authenticate your identity upon login; to communicate with you regarding your account status, security alerts, and service updates; to enforce contractual terms |
| Profile / Settings | Business registered address, phone number, Goods and Services Tax (GST) identification number, Tax Deduction at Source (TDS) details, company logo file, branding colour preferences, default currency, invoice numbering scheme, default payment terms, default tax rates, fiscal year configuration | To personalise invoices, proposals, and proforma invoices generated through the Service; to include legally required business identification details on financial documents; to comply with applicable tax, accounting, and regulatory requirements in your jurisdiction; to maintain consistent branding across your documents |
| Invoicing & Proposals | Client/customer names, client email addresses, client physical addresses, client phone numbers, line item descriptions, quantities, unit prices, discount percentages and amounts, tax rates and tax amounts, subtotals, totals, payment terms and due dates, proposal narrative text, proposal scope descriptions, notes and internal comments, attached files and documents | To enable you to generate, customise, send, track, and manage invoices, proposals, and proforma invoices through the Service; to calculate taxes, discounts, and totals accurately; to deliver documents to your clients via email; to maintain a history of all documents for your reference and record-keeping |
| Payments | Payment method details (credit/debit card type, UPI ID, bank name — all tokenised), transaction reference identifiers issued by the payment gateway, payment amounts and currency, payment initiation timestamp, payment confirmation timestamp, payment status (pending, completed, failed, refunded), refund reference identifiers, refund amounts and dates | To facilitate and process payments initiated by you or your clients through the Service; to reconcile financial records and maintain accurate payment histories; to provide payment status updates and notifications; to support accounting, auditing, and financial reporting requirements |
| Contact / Support | Email address, full name (if provided), subject line and category of enquiry, full message body including any technical details, error messages, or screenshots included, file attachments (if any), timestamps of initial contact and all subsequent correspondence | To respond to your enquiries, feedback, complaints, feature requests, and bug reports in a timely and effective manner; to provide customer support and technical assistance; to track support resolution progress; to improve the quality and responsiveness of our support operations through aggregate analysis |
| Authentication | JSON Web Token (JWT) stored in an HTTP-only, Secure, SameSite=Strict cookie, login timestamp (date and time), IP address at the time of login, browser user agent string (including browser name, version, operating system, and device type), unique session identifier | To establish, maintain, and secure your authenticated session; to enforce automatic session timeouts for security; to detect and prevent unauthorised access attempts, credential stuffing, and account takeover attacks; to maintain an audit trail of authentication events for security monitoring |
| Analytics (opt-in only) | Anonymised IP address (last octet truncated to prevent identification), pages viewed with timestamps and duration, referring URL (source page), device type and model, operating system and version, browser type and version, screen resolution and pixel density, language and locale preferences, click events and interaction data, scroll depth and time on page, search query terms (if applicable) | To understand usage patterns, user journeys, and feature adoption; to identify and resolve performance bottlenecks, errors, and usability issues; to prioritise product development efforts based on actual usage data; to improve the overall quality, usability, reliability, and accessibility of the Service |
The following table maps each category of personal data to its applicable retention period and the justification for the retention. This table should be read in conjunction with Section 7 (“Data Retention Periods”) of the Privacy Policy, which provides additional context and detail. We adhere to the principle of storage limitation and ensure that personal data is not retained for longer than is necessary for the purposes for which it is processed:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account data (name, email, company name, tax details) | Duration of active account plus thirty (30) calendar days after account deletion | Necessary to provide the Service during the subscription period; 30-day post-deletion window allows for account recovery in case of accidental deletion and satisfies audit trail requirements under applicable financial regulations |
| Invoice and proposal data (invoices, proposals, proforma invoices, line items, amounts, notes, attachments) | Duration of active account plus thirty (30) calendar days after account deletion | Core service functionality during the subscription period; applicable tax laws in most jurisdictions require retention of financial records for a minimum period; users are responsible for maintaining their own copies for tax compliance purposes |
| Customer data (your clients' names, emails, addresses, billing information) | Duration of active account plus thirty (30) calendar days after account deletion | Service functionality; users act as data controllers for this data and Invoice45.com acts as data processor; users should export this data before account deletion as it may not be recoverable after the deletion process |
| Payment records (transaction IDs, amounts, payment status, refund data) | Duration of active account plus thirty (30) calendar days | Financial compliance, audit trail, dispute resolution, and chargeback management; payment processors (Razorpay, Cashfree) may retain transaction records independently in accordance with their own retention policies and PCI DSS requirements |
| Analytics data (Google Analytics, PostHog, Ahrefs) | Fourteen (14) months from date of collection (Google Analytics default configuration); PostHog and Ahrefs retain per their default policies | Service improvement and usage analysis; data is anonymised or aggregated after the retention period expires; individual-level tracking data is not retained beyond this period under any circumstances |
| Server and access logs (IP addresses, request paths, timestamps, response codes, user agent strings) | Ninety (90) calendar days from date of log creation | Security monitoring, incident response, forensic analysis, and compliance with security best practices and audit requirements; logs are automatically purged after the 90-day window and are not recoverable |
| Database backups (full and incremental encrypted backups) | Ninety (90) calendar days rolling window | Disaster recovery and business continuity planning; backups are encrypted at rest using AES-256 encryption; older backups are securely and irreversibly deleted as they fall outside the rolling window |
| Cookie consent records (consent timestamp, consent ID, cookie preferences per category) | Twelve (12) months from date of last consent action | Proof of valid consent as required by GDPR Article 7(1) and the ePrivacy Directive; records are maintained in an auditable format to demonstrate compliance in the event of a regulatory audit, complaint, or investigation |
| Support correspondence (emails, chat logs, support tickets, attachments) | Twenty-four (24) months from date of last correspondence in the thread | Customer service continuity, quality assurance, staff training, pattern analysis for common issues, and dispute resolution; anonymised for aggregate analysis after the retention period expires |
Data Export Before Deletion
Before initiating account deletion, you are strongly encouraged to export all of your personal data using the application's built-in CSV export feature. Once the deletion process has been completed and confirmed, we may be unable to recover or retrieve any data, as it is permanently and irreversibly purged from production systems within thirty (30) calendar days. For assistance with data export, please contact us at invoice45@allwebtech.in.
The following table maps each category of personal data to the specific legal basis relied upon for its processing, in accordance with Article 6(1) of the GDPR. This mapping ensures that every processing activity is supported by a valid and documented legal basis, and that data subjects are informed of the legal foundation underpinning each aspect of their personal data processing:
| Data Category | Legal Basis | Explanation |
|---|---|---|
| Account data | Art. 6(1)(b) — Contract | Processing of your account information (name, email, company) is necessary for the performance of the service contract between you and Invoice45.com |
| Profile and settings data | Art. 6(1)(b) — Contract; Art. 6(1)(c) — Legal obligation | Profile data is processed to personalise the Service as contracted; tax identification details are processed to comply with applicable tax legislation requiring invoice formatting standards |
| Invoice and proposal data | Art. 6(1)(b) — Contract | The creation, storage, and delivery of invoices and proposals constitutes the core functionality of the Service that you have contracted to receive |
| Payment data | Art. 6(1)(b) — Contract | Processing payment information is strictly necessary to execute financial transactions that you initiate through the Service |
| Support correspondence data | Art. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interest | Support communications are necessary for the performance of the service agreement; we also have a legitimate interest in maintaining records of support interactions for quality assurance and dispute resolution |
| Authentication data | Art. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interest | Session tokens are necessary for the service to function; security logging is based on our legitimate interest in protecting our systems and users from unauthorised access |
| Analytics data | Art. 6(1)(a) — Consent | Analytics data is collected only after you provide explicit, informed, opt-in consent through the Cookiebot consent banner; no analytics processing occurs before consent is obtained |
Where the legal basis for processing is consent (as is the case for analytics data), you have the unconditional right to withdraw your consent at any time without affecting the lawfulness of processing that occurred prior to withdrawal. Withdrawal may be exercised through the Cookiebot settings interface, in-app controls, or by contacting us at invoice45@allwebtech.in. We shall cease the relevant processing within seventy-two (72) hours of receiving a valid withdrawal request.
The Service is designed and intended for use by adults and business professionals. We do not knowingly collect, solicit, request, or process personal data from any person under the age of sixteen (16) years, or such other minimum age as may be specified by applicable law in the relevant jurisdiction (e.g., thirteen (13) years under the Children’s Online Privacy Protection Act in the United States). We do not direct any portion of the Service to children under the applicable minimum age, and we have no actual knowledge of collecting personal data from children without verified parental or guardian consent.
If we become aware, whether through a user report, an automated detection mechanism, or any other means, that we have inadvertently collected personal data from a child under the applicable minimum age without adequate verification of parental or guardian consent, we shall take immediate and proportionate steps to delete such information from our production systems and from all backups within seventy-two (72) hours of discovery. If you are a parent, legal guardian, or other responsible adult and believe that a child under your care has provided personal data to Invoice45.com without your consent, please contact us immediately at invoice45@allwebtech.in with sufficient information to enable us to identify and delete the relevant data, and we will expeditiously and completely remove such data from our systems.