Last updated: August 19, 2026
This Privacy Policy (“Policy”) sets forth the comprehensive and detailed practices employed by Invoice45.com (hereinafter referred to as “we,” “our,” “us,” or “Invoice45.com”) with respect to the collection, receipt, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction of your personal data arising out of or in connection with your access to, use of, or interaction with our proprietary cloud-based invoicing, proposal management, and professional services automation application (the “Service”). This Policy applies to all users of the Service regardless of geographic location and covers all data processing activities undertaken by Invoice45.com whether directly or through its authorised sub-processors, affiliates, and service providers.
This Policy has been drafted in compliance with the European Union General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”), the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados) (“LGPD”), and all other applicable national, federal, state, provincial, territorial, and local data protection and privacy laws and regulations that may be applicable to the data processing activities described herein. We reserve the right to amend or update this Policy at any time and for any reason, and such amendments shall be effective upon posting the revised Policy on the Service unless a later effective date is specified therein.
By creating an account, accessing, browsing, or otherwise using the Service in any manner, you acknowledge that you have carefully read, fully understood, and freely agree to be bound by all terms and conditions of this Privacy Policy. If you do not agree with any provision of this Policy, you must immediately cease all use of the Service and contact us at invoice45@allwebtech.in to request account deletion and data erasure. Your continued use of the Service following the posting of any changes to this Policy constitutes your binding acceptance of such changes.
For the purposes of the GDPR and other applicable data protection legislation, the data controller responsible for determining the purposes and means of the processing of your personal data is the following entity, which operates and maintains the Invoice45.com Service and is ultimately accountable for ensuring that your personal data is processed in accordance with applicable law:
Our designated Data Protection Officer and primary privacy contact can be reached at invoice45@allwebtech.in. All privacy-related inquiries, requests, complaints, and communications shall be directed to this email address. We are committed to acknowledging receipt of your inquiry within five (5) business days and providing a substantive written response within thirty (30) calendar days of receipt, extendable by a further sixty (60) calendar days where the complexity or volume of requests so requires, in which case we shall inform you of the extension and the reasons therefor within the initial thirty-day period.
The Data Protection Officer is responsible for monitoring compliance with the GDPR, with other Union or Member State data protection provisions and with the policies of Invoice45.com in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the conduct of audits and reviews. The Data Protection Officer shall report directly to the highest management level of Invoice45.com and shall not receive instructions regarding the exercise of these tasks.
We collect and process various categories of personal data through multiple touchpoints, interaction channels, automated means, and user-initiated activities. The specific categories of personal data we collect, the sources from which we obtain such data, the purposes for which we process it, and the legal bases supporting each processing activity are set forth in comprehensive detail below. We collect personal data both directly from you when you interact with the Service and indirectly through automated technical means such as cookies, server logs, and analytics tools. We do not collect personal data that is excessive, irrelevant, or not reasonably necessary for the purposes described in this Policy.
The complete, detailed inventory of all personal data collected at each touchpoint — including the specific data elements, retention periods, and legal basis mapping — is set forth in Annexure 02 (Personal Data Collection Inventory), which is incorporated into this Policy by reference. For a summary of the key data categories, please refer to the table below:
| Touchpoint | Data Collected | Purpose |
|---|---|---|
| Account Creation | Full name, email, hashed password, company name | Account creation, identity authentication, service communications |
| Profile / Settings | Business address, phone, GST/TDS details, logo, branding | Invoice personalisation and tax compliance |
| Invoicing & Proposals | Client names, emails, addresses, line items, amounts | Document generation, delivery, and tracking |
| Payments | Payment method (tokenised), transaction IDs, amounts | Payment processing and financial reconciliation |
| Contact / Support | Email, name, message content, attachments | Customer support and service improvement |
| Authentication | JWT token, login timestamp, IP, user agent | Session security and unauthorised access prevention |
| Analytics (opt-in only) | Anonymised IP, pages viewed, device info, clicks | Usage analysis and service improvement |
Full Data Collection Inventory
For the complete and detailed inventory of all data elements collected at each touchpoint, including retention periods, legal basis mapping, and children’s data provisions, refer to Annexure 02 — Personal Data Collection Inventory.
We do not knowingly collect, solicit, or process personal data from any person under the age of sixteen (16) or such other age as may be specified by applicable law in the relevant jurisdiction. If we become aware that we have collected personal data from a child without verification of parental consent, we shall take immediate steps to delete such information from our systems. If you are a parent or guardian and believe that your child has provided personal data to us without your consent, please contact us immediately at invoice45@allwebtech.in and we will expeditiously remove such data.
Under Article 6(1) of the GDPR, personal data shall only be processed lawfully if and to the extent that at least one of the following legal bases applies. We have carefully assessed and documented the legal basis relied upon for each category of processing activity. Where the legal basis is consent, you have the right to withdraw consent at any time. Where the legal basis is contractual necessity, the processing is a prerequisite for the performance of the contract to which you are a party. Where the legal basis is legitimate interest, we have conducted a balancing test and documented our assessment of your rights and freedoms against our legitimate interests. The following table sets forth the complete mapping of processing activities to their respective legal bases:
| Processing Activity | Legal Basis | Explanation |
|---|---|---|
| Account creation and management | Art. 6(1)(b) — Contract | Processing is necessary for the performance of the contract between you and Invoice45.com for the provision of the Service, including account setup, authentication, profile management, and customer support |
| Invoice/proposal generation and delivery | Art. 6(1)(b) — Contract | The creation, customisation, and delivery of invoices and proposals constitutes the core functionality of the Service that you have contracted to receive; processing cannot be separated from these activities |
| Payment processing and reconciliation | Art. 6(1)(b) — Contract | Processing payment information is strictly necessary to execute financial transactions that you initiate through the Service and to maintain accurate financial records as required by the service agreement |
| Transactional communications (invoice delivery, account notifications, password resets) | Art. 6(1)(b) — Contract | Sending transactional emails and notifications is required to deliver the service and maintain the security and operability of your account |
| Security logging, fraud prevention, and abuse detection | Art. 6(1)(f) — Legitimate interest | We have a legitimate interest in protecting our systems, infrastructure, and users from fraud, abuse, unauthorised access, and other security threats; the impact on your rights is minimal as this processing uses anonymised or minimal data |
| Analytics and service improvement (Google Analytics, PostHog, Ahrefs) | Art. 6(1)(a) — Consent | Analytics scripts and tracking technologies are only activated after you provide explicit, informed, freely given, specific, and unambiguous opt-in consent through our Cookiebot consent management banner; no analytics data is collected before consent is obtained |
| Marketing and promotional communications | Art. 6(1)(a) — Consent | Marketing cookies and promotional communications are only deployed after you provide explicit opt-in consent; you may withdraw this consent at any time without detriment |
| Legal, tax, and regulatory compliance | Art. 6(1)(c) — Legal obligation | Retention of certain records (invoices, payment records, tax data) is mandated by applicable tax laws, financial regulations, and accounting standards that impose legal obligations on Invoice45.com |
| Enforcement of terms and dispute resolution | Art. 6(1)(f) — Legitimate interest | We have a legitimate interest in being able to enforce our Terms and Conditions and to establish, exercise, or defend legal claims in the event of a dispute arising from your use of the Service |
Withdrawal of Consent
Where the processing of your personal data is based on your consent (including analytics, marketing, and non-essential cookies), you have the unconditional right to withdraw your consent at any time and for any reason without affecting the lawfulness of the processing that occurred prior to the withdrawal. You may exercise this right by clicking the link located in the footer of every page on the Service, by adjusting your browser settings to reject cookies, or by contacting us directly at invoice45@allwebtech.in. Upon receipt of your withdrawal request, we shall cease the relevant processing activities within a reasonable timeframe and in any event no later than seventy-two (72) hours from receipt.
The Service uses cookies, web beacons, pixels, local storage, and similar tracking technologies (collectively, “Cookies”) to operate efficiently, secure your session, remember your preferences, and, only with your explicit consent, collect analytics data about how you interact with the Service. We implement Cookiebot, a Consent Management Platform (CMP) provided by Usercentrics, to provide you with granular, layered, and transparent control over which categories of Cookies are active on your device. All non-essential Cookies and tracking scripts are completely blocked at the network level until you actively and affirmatively consent to their use through the Cookiebot consent banner. No tracking, analytics, or marketing data is collected, transmitted, or processed before consent is obtained. Your cookie consent preferences are stored locally and can be revised at any time.
You may manage, review, update, or withdraw your cookie consent preferences at any time by clicking the “Cookie Settings” link located in the footer of every page on the Service, which will re-open the Cookiebot consent banner and allow you to toggle individual cookie categories on or off. Additionally, most web browsers provide settings that allow you to block or delete all cookies, restrict cookies to specific websites, or receive a notification when a cookie is set. Please note that disabling strictly necessary cookies may impair or prevent the functioning of the Service entirely.
We do not use browser fingerprinting, device fingerprinting, cross-device tracking, or any other covert identification techniques. We do not employ dark patterns, guilt trips, or deceptive user interface designs to manipulate you into providing consent. The Cookiebot consent banner presents all cookie categories equally and allows you to accept or reject each category independently without any pre-selected options.
In order to provide, maintain, secure, and improve the Service, we engage a limited number of carefully selected third-party service providers who act as data processors on our behalf. Each third-party processor is bound by a legally binding Data Processing Agreement (DPA) that requires them to implement appropriate technical and organisational measures, to process personal data only on our documented instructions, to ensure the confidentiality of personal data, to implement security measures consistent with Article 32 of the GDPR, to assist us in responding to data subject rights requests, to delete or return personal data upon termination of the agreement, and to submit to audits and inspections. The complete and detailed inventory of all third-party processors — including jurisdiction, transfer mechanisms, and consent requirements — is set forth in Annexure 01 (Third-Party Data Processors), which is incorporated into this Policy by reference. For a summary of the key processors, please refer to the table below:
| Service | Provider | Purpose | Consent Required |
|---|---|---|---|
| Google Analytics | Google LLC (US) | Website traffic analysis, conversion tracking, user journey mapping | Yes (analytics) — via Cookiebot |
| PostHog | PostHog Inc. (US) | Product analytics, feature flags, A/B testing | Yes (analytics) — via Cookiebot |
| Ahrefs | Ahrefs Pte. Ltd. (SG) | SEO analytics, competitive analysis | Yes (analytics) — via Cookiebot |
| Razorpay | Razorpay Software Pvt. Ltd. (India) | Payment processing (cards, UPI, net banking) | No (contractual necessity) |
| Cashfree | Cashfree Payments India Pvt. Ltd. (India) | Payment processing (bank transfers, NEFT, RTGS, IMPS) | No (contractual necessity) |
| All Web Tech | All Web Tech (India) | Server hosting and infrastructure | No (legitimate interest) |
| Nodemailer | Self-hosted | Transactional emails (invoice delivery) | No (contractual necessity) |
| Cookiebot / Usercentrics | Usercentrics GmbH (Germany) | Consent Management Platform | No (legal obligation) |
| Cloudflare | Cloudflare Inc. (US) | CDN, DDoS protection, SSL/TLS, bot management | No (legitimate interest) |
Full Processor Inventory and DPA Details
For the complete inventory of all third-party processors including data categories processed, transfer jurisdictions, applicable safeguard mechanisms, and Data Processing Agreement summary provisions, refer to Annexure 01 — Third-Party Data Processors.
Data Processing Agreements (DPAs)
We maintain written, legally enforceable Data Processing Agreements with every third-party processor that handles personal data on our behalf. These agreements conform to the standard contractual clauses recommended by the European Commission and incorporate the following provisions: (a) processing only on documented instructions from Invoice45.com; (b) confidentiality obligations on all personnel with access to personal data; (c) implementation of appropriate technical and organisational security measures in line with Article 32 of the GDPR; (d) restrictions on sub-processing without prior written authorisation; (e) assistance in responding to data subject rights requests; (f) deletion or return of all personal data upon termination of the engagement; and (g) making available all information necessary to demonstrate compliance and allowing for and contributing to audits and inspections. To request copies of any applicable Data Processing Agreement, please contact us at invoice45@allwebtech.in.
We adhere to the principle of storage limitation as set forth in Article 5(1)(e) of the GDPR, which requires that personal data be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. We have established the following retention periods for each category of personal data, taking into account the purposes for which the data is processed, applicable legal and regulatory retention requirements, contractual obligations, legitimate interests, and the expectations and reasonable assumptions of our users. The table below sets forth the specific retention periods applicable to each category of data:
| Data Type | Retention Period | Justification |
|---|---|---|
| Account data (name, email, company name, tax details) | Duration of active account plus thirty (30) calendar days after account deletion | Necessary to provide the Service during the subscription period; retained for 30 days post-deletion to allow for account recovery in case of accidental deletion and to comply with audit trail requirements |
| Invoice and proposal data (invoices, proposals, proforma invoices, line items, amounts) | Duration of active account plus thirty (30) calendar days after account deletion | Core service functionality; additionally, applicable tax laws in most jurisdictions require retention of financial records for a minimum period; you remain responsible for retaining copies of your own invoices for tax compliance purposes |
| Customer data (your clients' names, emails, addresses, billing information) | Duration of active account plus thirty (30) calendar days after account deletion | Service functionality; you act as the data controller for this data and Invoice45.com acts as the data processor; we recommend you export this data before account deletion |
| Payment records (transaction IDs, amounts, payment status) | Duration of active account plus thirty (30) calendar days | Financial compliance, audit trail, and dispute resolution; payment processors may retain transaction records independently in accordance with their own retention policies and PCI DSS requirements |
| Analytics data (Google Analytics, PostHog, Ahrefs) | Fourteen (14) months from date of collection (Google Analytics default), or as configured per provider | Service improvement and usage analysis; data is anonymised or aggregated after the retention period; individual-level tracking data is not retained beyond this period |
| Server and access logs (IP addresses, request paths, timestamps, response codes) | Ninety (90) calendar days from date of creation | Security monitoring, incident response, forensic analysis, and compliance with security best practices; logs are automatically purged after the 90-day window |
| Database backups (full and incremental) | Ninety (90) calendar days rolling window | Disaster recovery and business continuity; backups are encrypted at rest; older backups are securely deleted as they fall outside the rolling window |
| Cookie consent records (consent timestamp, consent ID, preferences) | Twelve (12) months from date of consent | Proof of valid consent as required by GDPR Article 7(1) and the ePrivacy Directive; records are maintained to demonstrate compliance in the event of a regulatory audit or complaint |
| Support correspondence (emails, chat logs, support tickets) | Twenty-four (24) months from date of last correspondence | Customer service continuity, quality assurance, staff training, and dispute resolution; anonymised for aggregate analysis after retention period |
Upon receipt of a valid account deletion request or when you delete your account through the Service interface, all personal data associated with your account is permanently and irreversibly removed from our production databases within thirty (30) calendar days. Data within encrypted database backups is purged within the 90-day rolling backup window. You are strongly encouraged to export all of your data using the application's CSV export feature prior to initiating account deletion, as we may be unable to recover data after the deletion process has been completed. Certain anonymised or aggregated data that can no longer be attributed to you may be retained indefinitely for statistical and analytical purposes.
Where data is retained for longer periods to comply with legal obligations (such as tax record retention requirements under the Income Tax Act, 1961 or equivalent legislation in your jurisdiction), such data is restricted from any further processing and is securely deleted upon expiry of the applicable statutory retention period.
Under the General Data Protection Regulation and other applicable data protection laws, you possess a comprehensive set of rights in relation to your personal data. We are committed to facilitating the exercise of these rights and have implemented procedures, technical capabilities, and in-app tools to enable you to exercise them promptly and without undue burden. The following rights are available to you, and we shall respond to all valid requests within thirty (30) calendar days of receipt, extendable by an additional sixty (60) calendar days where necessary and in accordance with Article 12(3) of the GDPR:
The Service is operated from infrastructure located in India, and certain third-party data processors that we engage are located in jurisdictions outside the European Economic Area (EEA), the United Kingdom, and other jurisdictions that may have different data protection laws than those applicable in your jurisdiction. When personal data is transferred internationally, we ensure that appropriate safeguards and legal mechanisms are in place to protect your personal data to a standard that is essentially equivalent to the protection afforded under the GDPR, in accordance with Chapter V of the GDPR. The following specific transfer mechanisms and safeguards are in place for each cross-border data transfer:
Our primary application servers, production databases, and backup infrastructure are hosted in Mumbai, India, within data centres that maintain SOC 2 Type II and ISO 27001 certifications. All data at rest is encrypted using AES-256 encryption, and all data in transit is protected by TLS 1.2 or higher. Database backups are encrypted, stored in the same geographic region, and are part of a 90-day rolling backup window. We do not transfer, replicate, or synchronise production data to servers outside of the designated hosting region without your explicit consent.
If you require specific, detailed information about data residency, data sovereignty, or the geographic location of your data, or if you wish to discuss dedicated hosting arrangements, please contact us at invoice45@allwebtech.in.
We implement a comprehensive, multi-layered information security programme that includes administrative, technical, and physical safeguards designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures are continuously reviewed, tested, and improved in accordance with industry best practices and the requirements of Article 32 of the GDPR. The following is a non-exhaustive summary of the key technical and organisational measures we have implemented:
🛡️ Production Environment Security
All Web Tech employees, contractors, and all development partners are strictly prohibited from accessing production user data under any circumstances. Only automated systems, monitoring agents, and security scanning tools operate within the production environment, and all access attempts — whether successful or failed — are logged, time-stamped, and subject to regular audit review. Any unauthorised access attempt is treated as a security incident and investigated immediately. Production database access requires multi-factor authentication and is subject to time-limited, purpose-specific access controls with full audit trail logging.
If you have any questions, concerns, comments, requests, or complaints regarding this Privacy Policy, our data processing practices, or the exercise of your data subject rights, we encourage you to contact us using any of the following channels. We are committed to addressing all privacy-related communications promptly, thoroughly, and in accordance with applicable law:
We will acknowledge receipt of your privacy-related communication within five (5) business days and will provide a substantive written response within thirty (30) calendar days of receipt. Where the complexity or volume of a request requires additional time, we may extend the response period by up to sixty (60) additional calendar days, in which case we will inform you of the extension and the reasons therefor within the initial thirty-day period. All identity verification for data subject rights requests is conducted proportionately and in accordance with the principle of data minimisation.
If you are not satisfied with our response to your privacy concern, or if you believe that our processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with a supervisory data protection authority in your country of habitual residence, your place of work, or the place of the alleged infringement. For users in the European Union, a list of supervisory authorities and their contact details is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. For users in India, complaints may be directed to the relevant authority under the Digital Personal Data Protection Act, 2023, once operationalised. For users in California, you may contact the Office of the California Attorney General. We encourage you to contact us first so that we may attempt to resolve your concern directly before you lodge a complaint with a supervisory authority.
The GDPR distinguishes between data controllers and data processors, each of which carry different legal obligations and responsibilities. Understanding this distinction is important for determining which party is responsible for compliance with data protection obligations in relation to different categories of personal data processed through the Service. The following describes the roles that apply to the different categories of data processed through Invoice45.com:
This dual role structure means that when you use Invoice45.com, you should be aware that we process some data as your processor (on your behalf and under your direction) and other data as an independent controller (for our own purposes as described in this Policy). If you are uncertain about which role applies to a particular category of data, or if you require further clarification about how we handle specific types of data, please contact us at invoice45@allwebtech.in.
We reserve the right to update, modify, amend, or replace this Privacy Policy at any time and from time to time at our sole discretion to reflect changes in our services, data processing practices, technology, legal requirements, regulatory guidance, judicial decisions, or industry best practices. The “Last updated” date displayed at the top of this page indicates the date of the most recent revision and should be checked periodically for changes. All material changes to this Policy shall be documented with a summary of the changes and the effective date of the revised Policy.
In the event of material changes to this Policy — including, but not limited to, changes in the categories of data we collect, the purposes for which we process data, the legal bases relied upon, or the rights available to you — we shall make reasonable efforts to notify you of such changes via email sent to the address associated with your account, through a prominent in-app notification displayed upon your next login, and/or through a banner on the Service. However, it is your responsibility to review this Policy periodically to stay informed of any updates.
Your continued access to, use of, or interaction with the Service following the posting of any changes to this Privacy Policy, or following notification of such changes (whichever occurs first), constitutes your binding acceptance of and agreement to the revised Policy. If you do not agree with any changes to this Policy, you must immediately cease all use of the Service, delete your account, and contact us at invoice45@allwebtech.in to request deletion of your personal data.
No Unauthorised Third-Party Data Access: All Web Tech employees, contractors, and development partners are strictly prohibited from accessing production user data; only automated systems interact with production servers
Opt-In Analytics Only: All analytics scripts and tracking technologies are completely blocked at the network level until you provide explicit, informed, opt-in consent through our Cookiebot consent management banner
Full GDPR Data Subject Rights: Access, rectify, erase, restrict, port, and object — all exercised through convenient in-app tools or by contacting invoice45@allwebtech.in within 30 calendar days
Clear and Enforceable Retention Periods: Personal data is retained only for as long as strictly necessary for the purposes described in this Policy, with a maximum retention of 30 calendar days after account deletion from production systems
Your Data, Your Complete Control: Export your data in CSV format, modify your profile, manage cookie preferences, or permanently delete your account at any time through the application without requiring any external communication
Industry-Leading Security Measures: bcrypt password hashing, HTTP-only JWT cookies, parameterised queries, TLS encryption, CSP headers, multi-tenant data isolation, and comprehensive access logging
Transparent Cross-Border Transfer Safeguards: Standard Contractual Clauses, EU-US Data Privacy Framework, and documented Data Processing Agreements protect your data in every international transfer