Legal

Privacy Policy

Last updated: August 19, 2026

Overview

Introduction

This Privacy Policy (“Policy”) sets forth the comprehensive and detailed practices employed by Invoice45.com (hereinafter referred to as “we,” “our,” “us,” or “Invoice45.com”) with respect to the collection, receipt, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction of your personal data arising out of or in connection with your access to, use of, or interaction with our proprietary cloud-based invoicing, proposal management, and professional services automation application (the “Service”). This Policy applies to all users of the Service regardless of geographic location and covers all data processing activities undertaken by Invoice45.com whether directly or through its authorised sub-processors, affiliates, and service providers.

This Policy has been drafted in compliance with the European Union General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”), the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados) (“LGPD”), and all other applicable national, federal, state, provincial, territorial, and local data protection and privacy laws and regulations that may be applicable to the data processing activities described herein. We reserve the right to amend or update this Policy at any time and for any reason, and such amendments shall be effective upon posting the revised Policy on the Service unless a later effective date is specified therein.

By creating an account, accessing, browsing, or otherwise using the Service in any manner, you acknowledge that you have carefully read, fully understood, and freely agree to be bound by all terms and conditions of this Privacy Policy. If you do not agree with any provision of this Policy, you must immediately cease all use of the Service and contact us at invoice45@allwebtech.in to request account deletion and data erasure. Your continued use of the Service following the posting of any changes to this Policy constitutes your binding acceptance of such changes.

Controller

Identity and Contact Details of the Data Controller

For the purposes of the GDPR and other applicable data protection legislation, the data controller responsible for determining the purposes and means of the processing of your personal data is the following entity, which operates and maintains the Invoice45.com Service and is ultimately accountable for ensuring that your personal data is processed in accordance with applicable law:

EntityAll Web Tech (operating as “Invoice45.com”)
Emailinvoice45@allwebtech.in

Our designated Data Protection Officer and primary privacy contact can be reached at invoice45@allwebtech.in. All privacy-related inquiries, requests, complaints, and communications shall be directed to this email address. We are committed to acknowledging receipt of your inquiry within five (5) business days and providing a substantive written response within thirty (30) calendar days of receipt, extendable by a further sixty (60) calendar days where the complexity or volume of requests so requires, in which case we shall inform you of the extension and the reasons therefor within the initial thirty-day period.

The Data Protection Officer is responsible for monitoring compliance with the GDPR, with other Union or Member State data protection provisions and with the policies of Invoice45.com in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the conduct of audits and reviews. The Data Protection Officer shall report directly to the highest management level of Invoice45.com and shall not receive instructions regarding the exercise of these tasks.

Collection

What Personal Data We Collect

We collect and process various categories of personal data through multiple touchpoints, interaction channels, automated means, and user-initiated activities. The specific categories of personal data we collect, the sources from which we obtain such data, the purposes for which we process it, and the legal bases supporting each processing activity are set forth in comprehensive detail below. We collect personal data both directly from you when you interact with the Service and indirectly through automated technical means such as cookies, server logs, and analytics tools. We do not collect personal data that is excessive, irrelevant, or not reasonably necessary for the purposes described in this Policy.

The complete, detailed inventory of all personal data collected at each touchpoint — including the specific data elements, retention periods, and legal basis mapping — is set forth in Annexure 02 (Personal Data Collection Inventory), which is incorporated into this Policy by reference. For a summary of the key data categories, please refer to the table below:

TouchpointData CollectedPurpose
Account CreationFull name, email, hashed password, company nameAccount creation, identity authentication, service communications
Profile / SettingsBusiness address, phone, GST/TDS details, logo, brandingInvoice personalisation and tax compliance
Invoicing & ProposalsClient names, emails, addresses, line items, amountsDocument generation, delivery, and tracking
PaymentsPayment method (tokenised), transaction IDs, amountsPayment processing and financial reconciliation
Contact / SupportEmail, name, message content, attachmentsCustomer support and service improvement
AuthenticationJWT token, login timestamp, IP, user agentSession security and unauthorised access prevention
Analytics (opt-in only)Anonymised IP, pages viewed, device info, clicksUsage analysis and service improvement

Full Data Collection Inventory

For the complete and detailed inventory of all data elements collected at each touchpoint, including retention periods, legal basis mapping, and children’s data provisions, refer to Annexure 02 — Personal Data Collection Inventory.

We do not knowingly collect, solicit, or process personal data from any person under the age of sixteen (16) or such other age as may be specified by applicable law in the relevant jurisdiction. If we become aware that we have collected personal data from a child without verification of parental consent, we shall take immediate steps to delete such information from our systems. If you are a parent or guardian and believe that your child has provided personal data to us without your consent, please contact us immediately at invoice45@allwebtech.in and we will expeditiously remove such data.

Legal Basis

Purpose and Legal Basis for Processing

Under Article 6(1) of the GDPR, personal data shall only be processed lawfully if and to the extent that at least one of the following legal bases applies. We have carefully assessed and documented the legal basis relied upon for each category of processing activity. Where the legal basis is consent, you have the right to withdraw consent at any time. Where the legal basis is contractual necessity, the processing is a prerequisite for the performance of the contract to which you are a party. Where the legal basis is legitimate interest, we have conducted a balancing test and documented our assessment of your rights and freedoms against our legitimate interests. The following table sets forth the complete mapping of processing activities to their respective legal bases:

Processing ActivityLegal BasisExplanation
Account creation and managementArt. 6(1)(b) — ContractProcessing is necessary for the performance of the contract between you and Invoice45.com for the provision of the Service, including account setup, authentication, profile management, and customer support
Invoice/proposal generation and deliveryArt. 6(1)(b) — ContractThe creation, customisation, and delivery of invoices and proposals constitutes the core functionality of the Service that you have contracted to receive; processing cannot be separated from these activities
Payment processing and reconciliationArt. 6(1)(b) — ContractProcessing payment information is strictly necessary to execute financial transactions that you initiate through the Service and to maintain accurate financial records as required by the service agreement
Transactional communications (invoice delivery, account notifications, password resets)Art. 6(1)(b) — ContractSending transactional emails and notifications is required to deliver the service and maintain the security and operability of your account
Security logging, fraud prevention, and abuse detectionArt. 6(1)(f) — Legitimate interestWe have a legitimate interest in protecting our systems, infrastructure, and users from fraud, abuse, unauthorised access, and other security threats; the impact on your rights is minimal as this processing uses anonymised or minimal data
Analytics and service improvement (Google Analytics, PostHog, Ahrefs)Art. 6(1)(a) — ConsentAnalytics scripts and tracking technologies are only activated after you provide explicit, informed, freely given, specific, and unambiguous opt-in consent through our Cookiebot consent management banner; no analytics data is collected before consent is obtained
Marketing and promotional communicationsArt. 6(1)(a) — ConsentMarketing cookies and promotional communications are only deployed after you provide explicit opt-in consent; you may withdraw this consent at any time without detriment
Legal, tax, and regulatory complianceArt. 6(1)(c) — Legal obligationRetention of certain records (invoices, payment records, tax data) is mandated by applicable tax laws, financial regulations, and accounting standards that impose legal obligations on Invoice45.com
Enforcement of terms and dispute resolutionArt. 6(1)(f) — Legitimate interestWe have a legitimate interest in being able to enforce our Terms and Conditions and to establish, exercise, or defend legal claims in the event of a dispute arising from your use of the Service

Withdrawal of Consent

Where the processing of your personal data is based on your consent (including analytics, marketing, and non-essential cookies), you have the unconditional right to withdraw your consent at any time and for any reason without affecting the lawfulness of the processing that occurred prior to the withdrawal. You may exercise this right by clicking the link located in the footer of every page on the Service, by adjusting your browser settings to reject cookies, or by contacting us directly at invoice45@allwebtech.in. Upon receipt of your withdrawal request, we shall cease the relevant processing activities within a reasonable timeframe and in any event no later than seventy-two (72) hours from receipt.

Cookies

Cookies and Tracking Technology

The Service uses cookies, web beacons, pixels, local storage, and similar tracking technologies (collectively, “Cookies”) to operate efficiently, secure your session, remember your preferences, and, only with your explicit consent, collect analytics data about how you interact with the Service. We implement Cookiebot, a Consent Management Platform (CMP) provided by Usercentrics, to provide you with granular, layered, and transparent control over which categories of Cookies are active on your device. All non-essential Cookies and tracking scripts are completely blocked at the network level until you actively and affirmatively consent to their use through the Cookiebot consent banner. No tracking, analytics, or marketing data is collected, transmitted, or processed before consent is obtained. Your cookie consent preferences are stored locally and can be revised at any time.

Strictly Necessary Cookies (always active)

  • auth-token — An HTTP-only, secure, SameSite=Strict JWT cookie that contains your encrypted authentication token and is essential for maintaining your authenticated session. This cookie is issued upon successful login and is deleted when you log out or when your session expires due to inactivity. Without this cookie, the Service cannot function. Legal basis: Art. 6(1)(b) Contract; exempt from consent requirements under the ePrivacy Directive.
  • CookieConsent — Set by Cookiebot to record your cookie consent preferences (which categories you accepted or rejected). This cookie is required to prove that valid consent was obtained in accordance with GDPR Article 7(1) and the ePrivacy Directive. Expires after twelve (12) months from the date it was last updated. Legal basis: Art. 6(1)(c) Legal obligation.
  • csrf_token — A cross-site request forgery protection token that is generated fresh for each session and validated on every state-changing request (POST, PUT, DELETE) to prevent CSRF attacks. This is a session-scoped cookie that expires when the browser is closed. Legal basis: Art. 6(1)(f) Legitimate interest in maintaining service security.
  • __cf_bm — Cloudflare bot management cookie that helps distinguish between human visitors and automated bots to protect the Service from malicious traffic, DDoS attacks, and credential stuffing attempts. Legal basis: Art. 6(1)(f) Legitimate interest in maintaining service availability and security.

Analytics Cookies (opt-in only — blocked until consent)

  • _ga, _ga_* — Google Analytics cookies that assign a randomly generated, unique visitor identifier and track session data including pages visited, duration of visit, referring source, and approximate geographic region (country level only). IP addresses are anonymised by truncating the last octet before storage. These cookies expire after fourteen (14) months from the date of setting. Legal basis: Art. 6(1)(a) Explicit consent obtained via Cookiebot. Data is processed by Google LLC in the United States under the EU-US Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs).
  • ph_* — PostHog product analytics cookies and localStorage entries that track session identifiers, distinct user identifiers, feature flag evaluations, A/B test assignments, and page view events to help us understand how users interact with specific features of the Service. Data is stored in PostHog's infrastructure and can be hosted in EU data centres upon request. Legal basis: Art. 6(1)(a) Explicit consent obtained via Cookiebot.
  • Ahrefs Analytics — Ahrefs tracking script that collects anonymised traffic data including traffic sources, keyword rankings, backlink profiles, and top-performing pages for SEO analysis and competitive intelligence. Legal basis: Art. 6(1)(a) Explicit consent obtained via Cookiebot. Data is processed by Ahrefs Pte. Ltd. in Singapore.

Marketing Cookies (opt-in only — currently inactive)

  • As of the date of this Policy, Invoice45.com does not set any marketing, advertising, or remarketing cookies of its own. No advertising networks, social media pixels, or retargeting scripts are loaded on the Service.
  • In the event that third-party payment providers such as Razorpay or Cashfree set their own cookies during the payment checkout process (e.g., fraud detection cookies, session cookies for payment form rendering), those cookies are governed exclusively by the respective provider's own privacy and cookie policies, which you should review directly on their respective websites.
  • If Invoice45.com introduces marketing cookies in the future, we will update this Policy accordingly and require explicit opt-in consent through the Cookiebot consent banner before any such cookies are activated.

You may manage, review, update, or withdraw your cookie consent preferences at any time by clicking the “Cookie Settings” link located in the footer of every page on the Service, which will re-open the Cookiebot consent banner and allow you to toggle individual cookie categories on or off. Additionally, most web browsers provide settings that allow you to block or delete all cookies, restrict cookies to specific websites, or receive a notification when a cookie is set. Please note that disabling strictly necessary cookies may impair or prevent the functioning of the Service entirely.

We do not use browser fingerprinting, device fingerprinting, cross-device tracking, or any other covert identification techniques. We do not employ dark patterns, guilt trips, or deceptive user interface designs to manipulate you into providing consent. The Cookiebot consent banner presents all cookie categories equally and allows you to accept or reject each category independently without any pre-selected options.

Third Parties

Third-Party Services and Data Processors

In order to provide, maintain, secure, and improve the Service, we engage a limited number of carefully selected third-party service providers who act as data processors on our behalf. Each third-party processor is bound by a legally binding Data Processing Agreement (DPA) that requires them to implement appropriate technical and organisational measures, to process personal data only on our documented instructions, to ensure the confidentiality of personal data, to implement security measures consistent with Article 32 of the GDPR, to assist us in responding to data subject rights requests, to delete or return personal data upon termination of the agreement, and to submit to audits and inspections. The complete and detailed inventory of all third-party processors — including jurisdiction, transfer mechanisms, and consent requirements — is set forth in Annexure 01 (Third-Party Data Processors), which is incorporated into this Policy by reference. For a summary of the key processors, please refer to the table below:

ServiceProviderPurposeConsent Required
Google AnalyticsGoogle LLC (US)Website traffic analysis, conversion tracking, user journey mappingYes (analytics) — via Cookiebot
PostHogPostHog Inc. (US)Product analytics, feature flags, A/B testingYes (analytics) — via Cookiebot
AhrefsAhrefs Pte. Ltd. (SG)SEO analytics, competitive analysisYes (analytics) — via Cookiebot
RazorpayRazorpay Software Pvt. Ltd. (India)Payment processing (cards, UPI, net banking)No (contractual necessity)
CashfreeCashfree Payments India Pvt. Ltd. (India)Payment processing (bank transfers, NEFT, RTGS, IMPS)No (contractual necessity)
All Web TechAll Web Tech (India)Server hosting and infrastructureNo (legitimate interest)
NodemailerSelf-hostedTransactional emails (invoice delivery)No (contractual necessity)
Cookiebot / UsercentricsUsercentrics GmbH (Germany)Consent Management PlatformNo (legal obligation)
CloudflareCloudflare Inc. (US)CDN, DDoS protection, SSL/TLS, bot managementNo (legitimate interest)

Full Processor Inventory and DPA Details

For the complete inventory of all third-party processors including data categories processed, transfer jurisdictions, applicable safeguard mechanisms, and Data Processing Agreement summary provisions, refer to Annexure 01 — Third-Party Data Processors.

Data Processing Agreements (DPAs)

We maintain written, legally enforceable Data Processing Agreements with every third-party processor that handles personal data on our behalf. These agreements conform to the standard contractual clauses recommended by the European Commission and incorporate the following provisions: (a) processing only on documented instructions from Invoice45.com; (b) confidentiality obligations on all personnel with access to personal data; (c) implementation of appropriate technical and organisational security measures in line with Article 32 of the GDPR; (d) restrictions on sub-processing without prior written authorisation; (e) assistance in responding to data subject rights requests; (f) deletion or return of all personal data upon termination of the engagement; and (g) making available all information necessary to demonstrate compliance and allowing for and contributing to audits and inspections. To request copies of any applicable Data Processing Agreement, please contact us at invoice45@allwebtech.in.

Retention

Data Retention Periods

We adhere to the principle of storage limitation as set forth in Article 5(1)(e) of the GDPR, which requires that personal data be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed. We have established the following retention periods for each category of personal data, taking into account the purposes for which the data is processed, applicable legal and regulatory retention requirements, contractual obligations, legitimate interests, and the expectations and reasonable assumptions of our users. The table below sets forth the specific retention periods applicable to each category of data:

Data TypeRetention PeriodJustification
Account data (name, email, company name, tax details)Duration of active account plus thirty (30) calendar days after account deletionNecessary to provide the Service during the subscription period; retained for 30 days post-deletion to allow for account recovery in case of accidental deletion and to comply with audit trail requirements
Invoice and proposal data (invoices, proposals, proforma invoices, line items, amounts)Duration of active account plus thirty (30) calendar days after account deletionCore service functionality; additionally, applicable tax laws in most jurisdictions require retention of financial records for a minimum period; you remain responsible for retaining copies of your own invoices for tax compliance purposes
Customer data (your clients' names, emails, addresses, billing information)Duration of active account plus thirty (30) calendar days after account deletionService functionality; you act as the data controller for this data and Invoice45.com acts as the data processor; we recommend you export this data before account deletion
Payment records (transaction IDs, amounts, payment status)Duration of active account plus thirty (30) calendar daysFinancial compliance, audit trail, and dispute resolution; payment processors may retain transaction records independently in accordance with their own retention policies and PCI DSS requirements
Analytics data (Google Analytics, PostHog, Ahrefs)Fourteen (14) months from date of collection (Google Analytics default), or as configured per providerService improvement and usage analysis; data is anonymised or aggregated after the retention period; individual-level tracking data is not retained beyond this period
Server and access logs (IP addresses, request paths, timestamps, response codes)Ninety (90) calendar days from date of creationSecurity monitoring, incident response, forensic analysis, and compliance with security best practices; logs are automatically purged after the 90-day window
Database backups (full and incremental)Ninety (90) calendar days rolling windowDisaster recovery and business continuity; backups are encrypted at rest; older backups are securely deleted as they fall outside the rolling window
Cookie consent records (consent timestamp, consent ID, preferences)Twelve (12) months from date of consentProof of valid consent as required by GDPR Article 7(1) and the ePrivacy Directive; records are maintained to demonstrate compliance in the event of a regulatory audit or complaint
Support correspondence (emails, chat logs, support tickets)Twenty-four (24) months from date of last correspondenceCustomer service continuity, quality assurance, staff training, and dispute resolution; anonymised for aggregate analysis after retention period

Upon receipt of a valid account deletion request or when you delete your account through the Service interface, all personal data associated with your account is permanently and irreversibly removed from our production databases within thirty (30) calendar days. Data within encrypted database backups is purged within the 90-day rolling backup window. You are strongly encouraged to export all of your data using the application's CSV export feature prior to initiating account deletion, as we may be unable to recover data after the deletion process has been completed. Certain anonymised or aggregated data that can no longer be attributed to you may be retained indefinitely for statistical and analytical purposes.

Where data is retained for longer periods to comply with legal obligations (such as tax record retention requirements under the Income Tax Act, 1961 or equivalent legislation in your jurisdiction), such data is restricted from any further processing and is securely deleted upon expiry of the applicable statutory retention period.

Your Rights

Data Subject Rights Under the GDPR

Under the General Data Protection Regulation and other applicable data protection laws, you possess a comprehensive set of rights in relation to your personal data. We are committed to facilitating the exercise of these rights and have implemented procedures, technical capabilities, and in-app tools to enable you to exercise them promptly and without undue burden. The following rights are available to you, and we shall respond to all valid requests within thirty (30) calendar days of receipt, extendable by an additional sixty (60) calendar days where necessary and in accordance with Article 12(3) of the GDPR:

  • Right of Access (Art. 15 GDPR) — You have the right to obtain confirmation as to whether or not personal data concerning you is being processed by Invoice45.com, and where that is the case, to access the personal data and the following information: the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipients, the envisaged retention periods, the existence of your other rights, the source of the data (if not collected directly from you), and the existence of automated decision-making including profiling. You may exercise this right directly through the in-app data export tool or by emailing us.
  • Right to Rectification (Art. 16 GDPR) — You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you and to have incomplete personal data completed, including by means of providing a supplementary statement. You may exercise this right directly through the in-app profile settings and account management interface.
  • Right to Erasure / Right to Be Forgotten (Art. 17 GDPR) — You have the right to obtain the erasure of your personal data without undue delay where one of the following grounds applies: the data is no longer necessary for the purpose for which it was collected; you withdraw consent on which the processing is based and there is no other legal ground for the processing; you object to the processing and there are no overriding legitimate grounds; the data has been unlawfully processed; the data must be erased for compliance with a legal obligation. Please note that this right is subject to exceptions where retention is required for legal obligations, the establishment, exercise, or defence of legal claims, or other grounds specified in Article 17(3) of the GDPR.
  • Right to Restriction of Processing (Art. 18 GDPR) — You have the right to obtain restriction of processing where: you contest the accuracy of the data (for a period enabling us to verify accuracy); the processing is unlawful and you oppose erasure; we no longer need the data but you require it for legal claims; you have objected to processing pending verification of whether our legitimate grounds override yours. Where processing is restricted, such data shall only be processed with your consent or for legal claims.
  • Right to Data Portability (Art. 20 GDPR) — You have the right to receive the personal data which you have provided to Invoice45.com in a structured, commonly used, and machine-readable format (CSV or JSON), and you have the right to transmit that data to another controller without hindrance where the processing is based on consent or a contract and is carried out by automated means. The in-app CSV export feature supports this right.
  • Right to Object (Art. 21 GDPR) — You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on legitimate interests (including profiling). Invoice45.com shall no longer process the data unless it demonstrates compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims. You have an absolute right to object to processing for direct marketing purposes.
  • Right to Withdraw Consent (Art. 7(3) GDPR) — Where the processing of your personal data is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing that occurred before the withdrawal. Withdrawal shall be as easy as giving consent and may be exercised through Cookiebot settings, in-app controls, or by contacting us at invoice45@allwebtech.in.
  • Right Not to Be Subject to Automated Decision-Making (Art. 22 GDPR) — You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Invoice45.com does not currently employ any automated decision-making or profiling systems that produce legal or similarly significant effects.
  • Right to Lodge a Complaint — Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR.

How to Exercise Your Rights

  • In-app tools (fastest method): Export your personal data in CSV format, edit your profile and account information, delete individual records or your entire account directly through the application interface without requiring any external communication.
  • Email: Send your request to invoice45@allwebtech.in with a clear description of the right you wish to exercise and sufficient information to verify your identity. We respond within thirty (30) calendar days of receipt and will verify your identity before processing any request.
  • Cookie settings: Manage analytics and marketing consent preferences at any time via the “Cookie Settings” link in the footer of every page on the Service.
Transfers

Cross-Border Data Transfers

The Service is operated from infrastructure located in India, and certain third-party data processors that we engage are located in jurisdictions outside the European Economic Area (EEA), the United Kingdom, and other jurisdictions that may have different data protection laws than those applicable in your jurisdiction. When personal data is transferred internationally, we ensure that appropriate safeguards and legal mechanisms are in place to protect your personal data to a standard that is essentially equivalent to the protection afforded under the GDPR, in accordance with Chapter V of the GDPR. The following specific transfer mechanisms and safeguards are in place for each cross-border data transfer:

  • Google Analytics (Google LLC, United States) — Personal data is transferred from the EEA to the United States under the EU-US Data Privacy Framework (DPF) adequacy decision adopted by the European Commission on 10 July 2023. Google LLC is certified under the DPF. Where the DPF is not available, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914). IP anonymisation (truncation of the last octet) is enabled in all Google Analytics configurations, reducing the personal data transferred.
  • PostHog (PostHog Inc., United States) — Personal data is transferred under the Standard Contractual Clauses (SCCs) incorporated into our Data Processing Agreement with PostHog. PostHog offers EU-hosted data residency as an option, which we can enable upon request. PostHog implements encryption at rest and in transit for all data.
  • Ahrefs (Ahrefs Pte. Ltd., Singapore) — Personal data is transferred under the Standard Contractual Clauses (SCCs) incorporated into our Data Processing Agreement with Ahrefs. Singapore is recognised by the European Commission as providing an adequate level of data protection under the GDPR adequacy framework.
  • Payment Processors (Razorpay, Cashfree — India) — Transaction data is processed under the legal basis of contractual necessity (Art. 6(1)(b)) as payment processing is an essential element of the service you have contracted. Both Razorpay and Cashfree operate PCI DSS Level 1 certified payment infrastructure and implement end-to-end encryption of payment data. Card details are tokenised and never stored on Invoice45.com servers.

Server and Data Residency

Our primary application servers, production databases, and backup infrastructure are hosted in Mumbai, India, within data centres that maintain SOC 2 Type II and ISO 27001 certifications. All data at rest is encrypted using AES-256 encryption, and all data in transit is protected by TLS 1.2 or higher. Database backups are encrypted, stored in the same geographic region, and are part of a 90-day rolling backup window. We do not transfer, replicate, or synchronise production data to servers outside of the designated hosting region without your explicit consent.

If you require specific, detailed information about data residency, data sovereignty, or the geographic location of your data, or if you wish to discuss dedicated hosting arrangements, please contact us at invoice45@allwebtech.in.

Security

Data Security Measures

We implement a comprehensive, multi-layered information security programme that includes administrative, technical, and physical safeguards designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Our security measures are continuously reviewed, tested, and improved in accordance with industry best practices and the requirements of Article 32 of the GDPR. The following is a non-exhaustive summary of the key technical and organisational measures we have implemented:

  • Password Security: All user passwords are irreversibly hashed using the bcrypt algorithm with a minimum of 12 salt rounds before storage. Passwords are never stored in plaintext, transmitted in clear text, or accessible to any employee, contractor, or third party of Invoice45.com under any circumstances.
  • Authentication and Session Management: User authentication is performed using JSON Web Tokens (JWT) issued upon successful credential verification. JWT tokens are stored exclusively in HTTP-only, Secure, SameSite=Strict cookies that are inaccessible to client-side JavaScript, mitigating cross-site scripting (XSS) attack vectors. Session tokens expire after a configurable period of inactivity and are invalidated upon explicit logout.
  • Input Validation and Sanitisation: All user-supplied input undergoes rigorous server-side validation, sanitisation, and encoding before processing. This includes type checking, length restrictions, format validation, character encoding, and HTML entity encoding to prevent injection attacks, cross-site scripting, and data corruption.
  • SQL Injection Protection: All database queries are executed using parameterised queries (prepared statements) that strictly separate SQL code from user-supplied data, providing comprehensive protection against SQL injection attacks regardless of the input validation layer.
  • Tenant Data Isolation: The Service implements a robust multi-tenant architecture with logical data isolation at the application, API, and database query layers. Every database query is scoped to the authenticated user's tenant context, ensuring that no user can access, view, modify, or delete data belonging to another user under any circumstances.
  • Encryption in Transit: All network communication between client devices and our servers, and between our internal services, is encrypted using Transport Layer Security (TLS) 1.2 or higher. HTTP Strict Transport Security (HSTS) headers are deployed to enforce HTTPS and prevent protocol downgrade attacks. HTTP to HTTPS redirection is enforced at the server level.
  • Security Headers: The following security headers are deployed on all responses: Content Security Policy (CSP) to restrict resource loading origins; X-Content-Type-Options: nosniff to prevent MIME-type sniffing; X-Frame-Options: DENY to prevent clickjacking; X-XSS-Protection: 1; mode=block for legacy browser protection; Referrer-Policy: strict-origin-when-cross-origin; Permissions-Policy to restrict browser feature access.
  • Access Logging and Monitoring: All data access events, authentication events, administrative actions, and API requests are logged with timestamps, source IP addresses, user identifiers, and action details. Logs are monitored for anomalous activity, reviewed during security audits, and retained for ninety (90) days in compliance with our security policies.
  • Vulnerability Management: We conduct regular automated vulnerability scans, dependency audits, and periodic penetration testing of the Service. Critical and high-severity vulnerabilities are remediated within documented SLAs based on severity classification.
  • Incident Response: We maintain a documented incident response plan that defines procedures for detection, containment, eradication, recovery, and notification in the event of a personal data breach. Where a breach is likely to result in a high risk to your rights and freedoms, we shall notify the relevant supervisory authority within seventy-two (72) hours and notify affected data subjects without undue delay, in accordance with Articles 33 and 34 of the GDPR.

🛡️ Production Environment Security

All Web Tech employees, contractors, and all development partners are strictly prohibited from accessing production user data under any circumstances. Only automated systems, monitoring agents, and security scanning tools operate within the production environment, and all access attempts — whether successful or failed — are logged, time-stamped, and subject to regular audit review. Any unauthorised access attempt is treated as a security incident and investigated immediately. Production database access requires multi-factor authentication and is subject to time-limited, purpose-specific access controls with full audit trail logging.

Contact

Privacy Contact and Complaints

If you have any questions, concerns, comments, requests, or complaints regarding this Privacy Policy, our data processing practices, or the exercise of your data subject rights, we encourage you to contact us using any of the following channels. We are committed to addressing all privacy-related communications promptly, thoroughly, and in accordance with applicable law:

Privacy Emailinvoice45@allwebtech.in
Response TimeWithin 30 calendar days (extendable by 60 days for complex requests)

We will acknowledge receipt of your privacy-related communication within five (5) business days and will provide a substantive written response within thirty (30) calendar days of receipt. Where the complexity or volume of a request requires additional time, we may extend the response period by up to sixty (60) additional calendar days, in which case we will inform you of the extension and the reasons therefor within the initial thirty-day period. All identity verification for data subject rights requests is conducted proportionately and in accordance with the principle of data minimisation.

If you are not satisfied with our response to your privacy concern, or if you believe that our processing of your personal data infringes applicable data protection laws, you have the right to lodge a complaint with a supervisory data protection authority in your country of habitual residence, your place of work, or the place of the alleged infringement. For users in the European Union, a list of supervisory authorities and their contact details is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en. For users in India, complaints may be directed to the relevant authority under the Digital Personal Data Protection Act, 2023, once operationalised. For users in California, you may contact the Office of the California Attorney General. We encourage you to contact us first so that we may attempt to resolve your concern directly before you lodge a complaint with a supervisory authority.

Roles

Data Controller and Processor Roles

The GDPR distinguishes between data controllers and data processors, each of which carry different legal obligations and responsibilities. Understanding this distinction is important for determining which party is responsible for compliance with data protection obligations in relation to different categories of personal data processed through the Service. The following describes the roles that apply to the different categories of data processed through Invoice45.com:

  • You are the Data Controller for all customer data that you enter into Invoice45.com in the course of using the Service, including but not limited to your clients' names, email addresses, physical addresses, phone numbers, billing information, transaction details, and any other personal data relating to third parties that you input, upload, or otherwise provide to the Service. As the data controller, you are responsible for ensuring that you have a valid legal basis for collecting and providing this data to Invoice45.com, for responding to data subject requests from your clients, and for complying with applicable data protection laws in relation to this data.
  • Invoice45.com acts as a Data Processor for the customer data described above, processing it solely on your documented instructions and for the purposes of providing you with the invoicing, proposal management, and related functionality of the Service. We process this data in accordance with our Data Processing Agreement and do not use it for any purpose other than providing the Service to you, unless required to do so by applicable law.
  • Invoice45.com is the Data Controller for your account data, including your name, email address, company information, payment history, usage data, preferences, and any other personal data that you provide directly to Invoice45.com for the purpose of establishing and maintaining your account and using the Service. As the data controller for this category of data, we determine the purposes and means of processing and are responsible for complying with applicable data protection laws in relation to it.

This dual role structure means that when you use Invoice45.com, you should be aware that we process some data as your processor (on your behalf and under your direction) and other data as an independent controller (for our own purposes as described in this Policy). If you are uncertain about which role applies to a particular category of data, or if you require further clarification about how we handle specific types of data, please contact us at invoice45@allwebtech.in.

Changes

Updates to This Privacy Policy

We reserve the right to update, modify, amend, or replace this Privacy Policy at any time and from time to time at our sole discretion to reflect changes in our services, data processing practices, technology, legal requirements, regulatory guidance, judicial decisions, or industry best practices. The “Last updated” date displayed at the top of this page indicates the date of the most recent revision and should be checked periodically for changes. All material changes to this Policy shall be documented with a summary of the changes and the effective date of the revised Policy.

In the event of material changes to this Policy — including, but not limited to, changes in the categories of data we collect, the purposes for which we process data, the legal bases relied upon, or the rights available to you — we shall make reasonable efforts to notify you of such changes via email sent to the address associated with your account, through a prominent in-app notification displayed upon your next login, and/or through a banner on the Service. However, it is your responsibility to review this Policy periodically to stay informed of any updates.

Your continued access to, use of, or interaction with the Service following the posting of any changes to this Privacy Policy, or following notification of such changes (whichever occurs first), constitutes your binding acceptance of and agreement to the revised Policy. If you do not agree with any changes to this Policy, you must immediately cease all use of the Service, delete your account, and contact us at invoice45@allwebtech.in to request deletion of your personal data.

Summary

Key Privacy Commitments

No Unauthorised Third-Party Data Access: All Web Tech employees, contractors, and development partners are strictly prohibited from accessing production user data; only automated systems interact with production servers

Opt-In Analytics Only: All analytics scripts and tracking technologies are completely blocked at the network level until you provide explicit, informed, opt-in consent through our Cookiebot consent management banner

Full GDPR Data Subject Rights: Access, rectify, erase, restrict, port, and object — all exercised through convenient in-app tools or by contacting invoice45@allwebtech.in within 30 calendar days

Clear and Enforceable Retention Periods: Personal data is retained only for as long as strictly necessary for the purposes described in this Policy, with a maximum retention of 30 calendar days after account deletion from production systems

Your Data, Your Complete Control: Export your data in CSV format, modify your profile, manage cookie preferences, or permanently delete your account at any time through the application without requiring any external communication

Industry-Leading Security Measures: bcrypt password hashing, HTTP-only JWT cookies, parameterised queries, TLS encryption, CSP headers, multi-tenant data isolation, and comprehensive access logging

Transparent Cross-Border Transfer Safeguards: Standard Contractual Clauses, EU-US Data Privacy Framework, and documented Data Processing Agreements protect your data in every international transfer