Version 1.0

Data Processing Agreement

Effective 1 October 2026

Takes effect on 1 October 2026

This version is published in advance so you can read it before it applies. It is not yet in force.

What changed in this version

First published version. Establishes Invoro's Article 28 obligations as processor for customer data, replacing the single privacy-policy reference in section 7.2 of the Peppol Service Agreement.

1. Parties and scope

This Data Processing Agreement (“DPA”) is entered into between:

Procyon Web S.àr.l.-S, operator of the Invoro service, 16 avenue Pasteur, L-2310 Luxembourg, RCS B234376, VAT LU31200358 (“Invoro”, the “Processor”); and

the customer identified in the Invoro account under which the Services are used (the “Customer”, the “Controller”).

This DPA forms part of, and is incorporated by reference into, the Invoro Terms and Conditions. It governs all processing of personal data carried out by Invoro on the Customer’s behalf, from the moment an account is created, and applies whether or not the Customer has activated any delivery network. Where this DPA conflicts with the Terms and Conditions or with the Peppol Service Agreement, this DPA prevails in respect of the processing of personal data.

This DPA is drawn up having regard to Commission Implementing Decision (EU) 2021/915 on standard contractual clauses between controllers and processors under Article 28(7) of Regulation (EU) 2016/679.

2. Roles of the parties

The Customer is the controller of the personal data described in Annex I. Invoro is a processor acting on the Customer’s documented instructions.

Invoro acts as an independent controller, and this DPA does not apply, in respect of:

a) account, billing and support data that Invoro processes to operate its own business; b) identity and business verification data (KYC/KYB) and sanctions screening, which Invoro processes to meet its own legal obligations under anti-money-laundering and Peppol accreditation rules; c) service telemetry and security logs processed for the security and integrity of the Services.

Invoro’s processing in those capacities is described in the Invoro Privacy Policy.

3. Subject matter, duration, nature and purpose

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.

The processing lasts for as long as the Customer holds an Invoro account, and thereafter only for the periods described in section 11.

4. Instructions

Invoro shall process personal data only on the Customer’s documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law to which Invoro is subject. Where such a requirement applies, Invoro shall inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

The Customer’s documented instructions consist of this DPA, the Terms and Conditions, the Peppol Service Agreement where applicable, and the instructions the Customer gives through the ordinary use of the Services, such as submitting a document for transmission or requesting extraction of data from an uploaded file.

Invoro shall immediately inform the Customer if, in its opinion, an instruction infringes Regulation (EU) 2016/679 or other Union or Member State data protection provisions, and may suspend the affected processing until the instruction is withdrawn, confirmed or amended.

5. Purpose limitation and confidentiality

Invoro shall process personal data only for the purposes set out in Annex I, and shall not use it for its own purposes, sell it, or use it to train machine learning models.

Invoro shall ensure that persons authorised to process personal data are bound by an appropriate statutory obligation of confidentiality or have committed themselves to confidentiality in writing, and that access is limited to those persons who need it to provide the Services.

6. Security of processing

Invoro shall implement the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk, in accordance with Article 32 of Regulation (EU) 2016/679.

Invoro may update the measures in Annex II over time, provided that the level of security is not reduced. Invoro shall make the current version of Annex II available on its website.

7. Sub-processors

The Customer gives Invoro general written authorisation to engage the sub-processors listed in Annex III.

Invoro shall inform the Customer at least 30 days in advance of any intended addition or replacement of a sub-processor, by email to the Customer’s registered account address and by publication on Invoro’s sub-processor page. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees.

Invoro shall impose on each sub-processor, by contract, data protection obligations that are no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.

8. International transfers

Invoro processes personal data exclusively within the European Union and the European Economic Area, and shall not transfer personal data to a third country or international organisation without the Customer’s prior written instruction. All sub-processors listed in Annex III are established, and process personal data, within the EU/EEA.

Recipients of documents transmitted over the Peppol network are not sub-processors and are not covered by this commitment. Where the Customer addresses a document to a participant established outside the EU/EEA, that transmission is carried out on the Customer’s instruction and the Customer is responsible for its lawfulness.

9. Assistance with data subject rights

Taking into account the nature of the processing, Invoro shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests for exercising data subject rights under Chapter III of Regulation (EU) 2016/679.

Invoro shall promptly notify the Customer of any request it receives directly from a data subject relating to personal data processed on the Customer’s behalf, and shall not respond to that request itself except to direct the data subject to the Customer, unless authorised to do so.

The Customer can exercise access, export and deletion functions directly through the Services. The limits in section 10 apply to deletion.

10. Personal data breaches and assistance with Articles 32 to 36

Invoro shall notify the Customer of a personal data breach affecting personal data processed on the Customer’s behalf without undue delay and in any event within 48 hours of becoming aware of it. The notification shall describe, as far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where information is not available at the time of notification, Invoro shall provide it in phases without undue delay.

Invoro shall provide the Customer with the information the Customer reasonably needs to meet its own notification obligations, including obligations arising under Directive (EU) 2022/2555 (NIS2) where the Customer is an essential or important entity, on a timeline that allows the Customer to meet those obligations.

Invoro shall assist the Customer in ensuring compliance with Articles 32 to 36 of Regulation (EU) 2016/679, including with data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to Invoro.

Security concerns may be reported to Invoro at security@invoro.lu.

11. Deletion and return of data

On termination of the Services, Invoro shall, at the Customer’s choice, delete or return all personal data processed on the Customer’s behalf and delete existing copies, except to the extent that Union or Member State law requires storage of the personal data. Two such limits apply and the Customer acknowledges both:

a) Statutory retention. Luxembourg commercial, accounting and tax law requires retention of invoices and supporting records for a period of up to ten years, and Peppol operational procedures require retention of transmission records. Invoro shall retain data falling within those requirements for the period the law requires and for no other purpose, applying the security measures in Annex II throughout, and shall delete it at the end of that period.

b) Documents already transmitted. Once a document has been successfully delivered over the Peppol network, a copy is held by the recipient’s access point and by the recipient, who are separate controllers outside Invoro’s control. Invoro can delete its own copy but cannot recall, amend or delete a transmitted document elsewhere. Requests concerning those copies must be directed to the recipient.

Invoro shall provide an export of the Customer’s data in a structured, commonly used and machine-readable format on request, at no charge.

12. Audit and demonstration of compliance

Invoro shall make available to the Customer all information necessary to demonstrate compliance with Article 28 of Regulation (EU) 2016/679, and shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

Invoro will satisfy this obligation in the first instance by providing its current technical and organisational measures, its sub-processor register, and written responses to the Customer’s reasonable security questionnaires, within 30 days of a request.

Where that information is insufficient, the Customer may conduct an on-site audit on at least 30 days’ written notice, no more than once in any twelve-month period except following a personal data breach or at the request of a supervisory authority. Audits shall take place during business hours, shall not unreasonably disrupt Invoro’s operations, and shall be subject to confidentiality undertakings. Each party bears its own costs.

13. Obligations of the Customer

The Customer warrants that it has a lawful basis for the processing it instructs, that it has provided any information required under Articles 13 and 14 of Regulation (EU) 2016/679 to the data subjects whose personal data it submits, including the personal data of its own customers and suppliers contained in invoices, and that its instructions comply with applicable law.

The Customer is responsible for the accuracy of the data it submits and for ensuring that documents it transmits do not contain personal data beyond what is necessary for the transaction.

14. Liability and governing law

Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Invoro Terms and Conditions, save that nothing in this DPA limits either party’s liability towards data subjects under Article 82 of Regulation (EU) 2016/679, or any liability that cannot be limited under applicable law.

This DPA is governed by the laws of the Grand Duchy of Luxembourg. The courts of Luxembourg City have exclusive jurisdiction.

15. Changes to this DPA

Invoro may publish a new version of this DPA on at least 30 days’ notice to the Customer’s registered account address, and shall highlight material changes in that notice.

The general right to amend the Terms and Conditions on notice does not extend to reducing Invoro’s obligations or the Customer’s rights under this DPA. Any such change requires the Customer’s agreement. Changes that add protections for the Customer, reflect a change in law, or update Annex II without lowering the level of security, take effect on notice.

Every published version of this DPA remains permanently available in Invoro’s legal document archive, identified by version number and content hash, so that the Customer can establish which text applied at any point in time.


Annex I - Description of the processing

Categories of data subjects

  • The Customer’s employees and other authorised users of the Services
  • The Customer’s customers, suppliers and other business counterparties, and their contact persons, where their details appear in documents processed through the Services
  • Senders of documents and emails received by the Customer through the Services

Types of personal data

  • Identification and contact details: name, business email address, telephone number, postal address, job title
  • Business identifiers that may relate to a natural person, such as the VAT or registration number of a sole trader, and Peppol participant identifiers
  • Document content: invoice line items, references, payment details including IBAN, and free-text fields completed by the Customer or by a counterparty
  • Message metadata: sender, recipient, document type, timestamps, delivery status
  • Email content and attachments received at an Invoro-provided inbound address
  • Authentication and access logs relating to the Customer’s users

No special categories of personal data within the meaning of Article 9, and no criminal conviction data within the meaning of Article 10, are required by the Services. The Customer should not submit such data.

Nature and purpose of the processing

a) Creating, validating and storing electronic invoices and other business documents b) Transmitting documents to, and receiving documents from, the Peppol network and other delivery networks on the Customer’s instruction, including publication of the Customer’s participant identifier and supported document types in the Service Metadata Publisher so that other participants can address documents to the Customer c) Receiving email at Invoro-provided inbound addresses and routing it to the Customer’s document inbox d) Extracting structured fields from PDF documents the Customer uploads or receives, so that the Customer can review and confirm them e) Converting, rendering and archiving documents, and making them available to the Customer f) Providing support in relation to the above

Duration

For the term of the Customer’s account, and thereafter as set out in section 11.


Annex II - Technical and organisational measures

Invoro maintains the measures below. The current version is published at invoro.eu/security.

Infrastructure and data residency. All production systems and data are located in the European Union, in data centres in Germany, the Netherlands and Finland. Infrastructure is provisioned as code and deployed through a reviewed, version-controlled pipeline.

Encryption. Personal data is encrypted in transit using TLS, and at rest using encrypted block storage. Message exchange over the Peppol network uses AS4 with signed and encrypted payloads. Selected sensitive fields are additionally encrypted at application level.

Access control. Access to production systems requires single sign-on with multi-factor authentication. Authorisation is role-based and granted on a least-privilege basis. Application API access uses sender-constrained tokens (DPoP, RFC 9449). Administrative access is restricted to named individuals and requires connection through a controlled network path.

Secret management. Credentials and keys are held in a dedicated secret management system with audited access, injected into workloads at runtime, and never stored in source code or images. Database credentials are issued dynamically with limited lifetimes.

Network security. Workloads run under default-deny network policies with explicit allow rules. Containers run as non-root with read-only filesystems. Public endpoints are fronted by a reverse proxy with rate limiting and automated threat detection.

Logging and monitoring. Application, authentication, administrative and system logs are centrally collected and retained on immutable, encrypted storage. Monitoring and alerting run continuously, with runtime security detection on production workloads and independent external availability monitoring hosted at a separate provider.

Vulnerability management. Container images are scanned for known vulnerabilities on every build, with critical findings blocking release. Operating systems receive automatic security updates.

Change management. All application and infrastructure changes are made through version control, reviewed before merge, and deployed by an automated pipeline that records what was deployed and when.

Resilience and backup. Databases are backed up continuously with point-in-time recovery, to encrypted storage in more than one European location. Recovery procedures are documented and tested.

Incident response. A documented incident response plan defines severity classification, roles, containment and recovery steps, and notification timelines, including those in section 10 of this DPA.

Personnel. Access to personal data is limited to personnel who require it, who are bound by confidentiality obligations, and whose access is removed when it is no longer required.


Annex III - Sub-processors

All sub-processors are established in the European Union or European Economic Area and process personal data within it.

This annex lists only those providers that process personal data on the Customer’s behalf. Providers Invoro engages for its own purposes as described in section 2, such as payment processing, identity and business verification, sanctions screening and meeting scheduling, are not sub-processors under this DPA. They are described in the Invoro Privacy Policy.

Sub-processor Location Purpose
Hetzner Online GmbH Germany Cloud infrastructure hosting and data storage
Impossible Cloud GmbH Germany Storage of encrypted backups and log archives
Mistral AI SAS France Extraction of structured fields from PDF documents uploaded or received by the Customer
Lettermint B.V. Netherlands Delivery of transactional email

The current list, together with the date of the most recent change, is published at invoro.eu/security.

Document integrity

This exact text is identified by the SHA-256 hash below. We record it against every acceptance, so you can always confirm which wording you agreed to.

6f4af6be9daad675dfb8e1f41ad5a084262f88e81916a6f5441279abb01b9669

Verify it yourself

We publish the exact bytes we hash athttps://invoro.eu/legal/dpa-1.0.txt, so you can reproduce the value above without trusting us:

curl -s https://invoro.eu/legal/dpa-1.0.txt | sha256sum
How it is calculated
  1. Take the document source in Markdown, without the metadata header.
  2. Strip a leading UTF-8 byte order mark, if present.
  3. Replace Windows (CRLF) and classic Mac (CR) line endings with Unix line endings (LF).
  4. Normalise the text to Unicode NFC, so accented characters have one representation.
  5. Remove trailing whitespace from the end of the document.
  6. Hash the resulting UTF-8 bytes with SHA-256.