Legal

Annexure 02

Personal Data Collection Inventory

Last updated: August 19, 2026

Purpose

Purpose of This Annexure

This Annexure forms an integral part of the Invoice45.com Privacy Policy (the “Policy”) and provides a comprehensive, detailed, and granular inventory of all categories of personal data that Invoice45.com collects, receives, records, and processes in connection with the operation of its cloud-based invoicing, proposal management, and professional services automation application (the “Service”). This Annexure specifies, for each collection touchpoint and data category, the precise types of personal data collected, the specific purposes for which the data is processed, the retention period applicable to each data category, the legal basis relied upon for the processing, and whether explicit user consent is required before the collection commences.

The information contained in this Annexure is intended to satisfy the transparency and information obligations imposed by Articles 13 and 14 of the GDPR, to assist data protection officers, supervisory authorities, and other stakeholders in assessing the lawfulness and proportionality of Invoice45.com’s data processing activities, and to provide data subjects with clear, accessible, and complete information about how their personal data is handled throughout its lifecycle, from collection through storage, use, and eventual deletion.

We collect personal data both directly from you when you voluntarily provide it in the course of using the Service and indirectly through automated technical means such as cookies, server logs, and analytics tools. We do not collect personal data that is excessive, irrelevant, or not reasonably necessary for the specific purposes described below. For detailed information about cookies and tracking technologies, please refer to Section 5 of the Privacy Policy. For information about the third-party processors that handle the data listed in this Annexure, please refer to Annexure 01 (Third-Party Data Processors).

Collection

What Personal Data We Collect — Detailed Inventory

The following table provides a complete and exhaustive inventory of all categories of personal data collected through each touchpoint, interaction channel, and automated means. For each touchpoint, the table specifies the exact data elements collected, the purposes for which each element is processed, and the legal basis supporting the processing. This inventory is current as of the “Last updated” date shown at the top of this page and is reviewed at least quarterly.

TouchpointData CollectedPurpose
Account CreationFull name, email address, password (salted and hashed using bcrypt with 12 salt rounds), company or business name, account creation timestampTo create, maintain, and administer your user account; to authenticate your identity upon login; to communicate with you regarding your account status, security alerts, and service updates; to enforce contractual terms
Profile / SettingsBusiness registered address, phone number, Goods and Services Tax (GST) identification number, Tax Deduction at Source (TDS) details, company logo file, branding colour preferences, default currency, invoice numbering scheme, default payment terms, default tax rates, fiscal year configurationTo personalise invoices, proposals, and proforma invoices generated through the Service; to include legally required business identification details on financial documents; to comply with applicable tax, accounting, and regulatory requirements in your jurisdiction; to maintain consistent branding across your documents
Invoicing & ProposalsClient/customer names, client email addresses, client physical addresses, client phone numbers, line item descriptions, quantities, unit prices, discount percentages and amounts, tax rates and tax amounts, subtotals, totals, payment terms and due dates, proposal narrative text, proposal scope descriptions, notes and internal comments, attached files and documentsTo enable you to generate, customise, send, track, and manage invoices, proposals, and proforma invoices through the Service; to calculate taxes, discounts, and totals accurately; to deliver documents to your clients via email; to maintain a history of all documents for your reference and record-keeping
PaymentsPayment method details (credit/debit card type, UPI ID, bank name — all tokenised), transaction reference identifiers issued by the payment gateway, payment amounts and currency, payment initiation timestamp, payment confirmation timestamp, payment status (pending, completed, failed, refunded), refund reference identifiers, refund amounts and datesTo facilitate and process payments initiated by you or your clients through the Service; to reconcile financial records and maintain accurate payment histories; to provide payment status updates and notifications; to support accounting, auditing, and financial reporting requirements
Contact / SupportEmail address, full name (if provided), subject line and category of enquiry, full message body including any technical details, error messages, or screenshots included, file attachments (if any), timestamps of initial contact and all subsequent correspondenceTo respond to your enquiries, feedback, complaints, feature requests, and bug reports in a timely and effective manner; to provide customer support and technical assistance; to track support resolution progress; to improve the quality and responsiveness of our support operations through aggregate analysis
AuthenticationJSON Web Token (JWT) stored in an HTTP-only, Secure, SameSite=Strict cookie, login timestamp (date and time), IP address at the time of login, browser user agent string (including browser name, version, operating system, and device type), unique session identifierTo establish, maintain, and secure your authenticated session; to enforce automatic session timeouts for security; to detect and prevent unauthorised access attempts, credential stuffing, and account takeover attacks; to maintain an audit trail of authentication events for security monitoring
Analytics (opt-in only)Anonymised IP address (last octet truncated to prevent identification), pages viewed with timestamps and duration, referring URL (source page), device type and model, operating system and version, browser type and version, screen resolution and pixel density, language and locale preferences, click events and interaction data, scroll depth and time on page, search query terms (if applicable)To understand usage patterns, user journeys, and feature adoption; to identify and resolve performance bottlenecks, errors, and usability issues; to prioritise product development efforts based on actual usage data; to improve the overall quality, usability, reliability, and accessibility of the Service
Retention

Data Retention by Category

The following table maps each category of personal data to its applicable retention period and the justification for the retention. This table should be read in conjunction with Section 7 (“Data Retention Periods”) of the Privacy Policy, which provides additional context and detail. We adhere to the principle of storage limitation and ensure that personal data is not retained for longer than is necessary for the purposes for which it is processed:

Data CategoryRetention PeriodJustification
Account data (name, email, company name, tax details)Duration of active account plus thirty (30) calendar days after account deletionNecessary to provide the Service during the subscription period; 30-day post-deletion window allows for account recovery in case of accidental deletion and satisfies audit trail requirements under applicable financial regulations
Invoice and proposal data (invoices, proposals, proforma invoices, line items, amounts, notes, attachments)Duration of active account plus thirty (30) calendar days after account deletionCore service functionality during the subscription period; applicable tax laws in most jurisdictions require retention of financial records for a minimum period; users are responsible for maintaining their own copies for tax compliance purposes
Customer data (your clients' names, emails, addresses, billing information)Duration of active account plus thirty (30) calendar days after account deletionService functionality; users act as data controllers for this data and Invoice45.com acts as data processor; users should export this data before account deletion as it may not be recoverable after the deletion process
Payment records (transaction IDs, amounts, payment status, refund data)Duration of active account plus thirty (30) calendar daysFinancial compliance, audit trail, dispute resolution, and chargeback management; payment processors (Razorpay, Cashfree) may retain transaction records independently in accordance with their own retention policies and PCI DSS requirements
Analytics data (Google Analytics, PostHog, Ahrefs)Fourteen (14) months from date of collection (Google Analytics default configuration); PostHog and Ahrefs retain per their default policiesService improvement and usage analysis; data is anonymised or aggregated after the retention period expires; individual-level tracking data is not retained beyond this period under any circumstances
Server and access logs (IP addresses, request paths, timestamps, response codes, user agent strings)Ninety (90) calendar days from date of log creationSecurity monitoring, incident response, forensic analysis, and compliance with security best practices and audit requirements; logs are automatically purged after the 90-day window and are not recoverable
Database backups (full and incremental encrypted backups)Ninety (90) calendar days rolling windowDisaster recovery and business continuity planning; backups are encrypted at rest using AES-256 encryption; older backups are securely and irreversibly deleted as they fall outside the rolling window
Cookie consent records (consent timestamp, consent ID, cookie preferences per category)Twelve (12) months from date of last consent actionProof of valid consent as required by GDPR Article 7(1) and the ePrivacy Directive; records are maintained in an auditable format to demonstrate compliance in the event of a regulatory audit, complaint, or investigation
Support correspondence (emails, chat logs, support tickets, attachments)Twenty-four (24) months from date of last correspondence in the threadCustomer service continuity, quality assurance, staff training, pattern analysis for common issues, and dispute resolution; anonymised for aggregate analysis after the retention period expires

Data Export Before Deletion

Before initiating account deletion, you are strongly encouraged to export all of your personal data using the application's built-in CSV export feature. Once the deletion process has been completed and confirmed, we may be unable to recover or retrieve any data, as it is permanently and irreversibly purged from production systems within thirty (30) calendar days. For assistance with data export, please contact us at invoice45@allwebtech.in.

Legal Basis

Legal Basis by Data Category

The following table maps each category of personal data to the specific legal basis relied upon for its processing, in accordance with Article 6(1) of the GDPR. This mapping ensures that every processing activity is supported by a valid and documented legal basis, and that data subjects are informed of the legal foundation underpinning each aspect of their personal data processing:

Data CategoryLegal BasisExplanation
Account dataArt. 6(1)(b) — ContractProcessing of your account information (name, email, company) is necessary for the performance of the service contract between you and Invoice45.com
Profile and settings dataArt. 6(1)(b) — Contract; Art. 6(1)(c) — Legal obligationProfile data is processed to personalise the Service as contracted; tax identification details are processed to comply with applicable tax legislation requiring invoice formatting standards
Invoice and proposal dataArt. 6(1)(b) — ContractThe creation, storage, and delivery of invoices and proposals constitutes the core functionality of the Service that you have contracted to receive
Payment dataArt. 6(1)(b) — ContractProcessing payment information is strictly necessary to execute financial transactions that you initiate through the Service
Support correspondence dataArt. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interestSupport communications are necessary for the performance of the service agreement; we also have a legitimate interest in maintaining records of support interactions for quality assurance and dispute resolution
Authentication dataArt. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interestSession tokens are necessary for the service to function; security logging is based on our legitimate interest in protecting our systems and users from unauthorised access
Analytics dataArt. 6(1)(a) — ConsentAnalytics data is collected only after you provide explicit, informed, opt-in consent through the Cookiebot consent banner; no analytics processing occurs before consent is obtained

Where the legal basis for processing is consent (as is the case for analytics data), you have the unconditional right to withdraw your consent at any time without affecting the lawfulness of processing that occurred prior to withdrawal. Withdrawal may be exercised through the Cookiebot settings interface, in-app controls, or by contacting us at invoice45@allwebtech.in. We shall cease the relevant processing within seventy-two (72) hours of receiving a valid withdrawal request.

Children

Collection of Children’s Data

The Service is designed and intended for use by adults and business professionals. We do not knowingly collect, solicit, request, or process personal data from any person under the age of sixteen (16) years, or such other minimum age as may be specified by applicable law in the relevant jurisdiction (e.g., thirteen (13) years under the Children’s Online Privacy Protection Act in the United States). We do not direct any portion of the Service to children under the applicable minimum age, and we have no actual knowledge of collecting personal data from children without verified parental or guardian consent.

If we become aware, whether through a user report, an automated detection mechanism, or any other means, that we have inadvertently collected personal data from a child under the applicable minimum age without adequate verification of parental or guardian consent, we shall take immediate and proportionate steps to delete such information from our production systems and from all backups within seventy-two (72) hours of discovery. If you are a parent, legal guardian, or other responsible adult and believe that a child under your care has provided personal data to Invoice45.com without your consent, please contact us immediately at invoice45@allwebtech.in with sufficient information to enable us to identify and delete the relevant data, and we will expeditiously and completely remove such data from our systems.