Privacy policy

Your privacy.

What personal data we collect, why, where it goes, how long we keep it, and your rights under UK GDPR.

Version 1.0 · 12 September 2026

1. Who we are

InvoicePro is operated by AX Studio Labs Ltd, a company registered in England and Wales, the data controller for the personal data described in this policy. For any data protection query, email privacy@invoicepro.co.uk. We are registered with the UK Information Commissioner's Office as a data controller.

InvoicePro is a separate product from StatementPro, also operated by AX Studio Labs Ltd. They share no account, no database and no billing, and personal data is not moved between them.

2. What this policy covers

The personal data we process when you are given an InvoicePro account and use it to convert invoice documents into schedules. It does not cover third-party sites you reach from links in our service.

3. The personal data we process

  • Account data — your email address, the firm your account belongs to, and sign-in timestamps.
  • Usage data — a record of each job: when it ran, how many documents it held, how many were billable, and the price that applied.
  • Document contents — the files you upload and the rows extracted from them. These routinely contain personal data about third parties: supplier contacts, sole traders' names and addresses, and similar.
  • Technical data — request logs and IP addresses, generated by our hosting provider in the ordinary course of serving the site.

We do not use cookies for advertising or analytics profiling. The only cookie we set is the one that keeps you signed in.

4. Your clients' data — who is responsible for what

Where you upload documents relating to your clients, you are the controller of the personal data inside those documents and we are your processor. We process it only on your instructions — which, in practice, means converting the documents you upload and letting you download the result. A Data Processing Agreement is available on request.

5. Why we process it, and our lawful basis

PurposeLawful basis
Giving you an account and signing you inPerformance of a contract
Converting your documents and storing the output for re-downloadPerformance of a contract
Keeping a usage record so we can invoice youPerformance of a contract; legal obligation for accounting records
Keeping the service secure and diagnosing faultsLegitimate interests
Answering a support request you raiseLegitimate interests

We do not sell personal data, we do not share it for advertising, and we do not use your documents or your clients' documents to train models.

6. Who we share it with

Four sub-processors, each listed with its role, region and what it can see, on our security page. In summary: Render (hosting and file storage, Frankfurt), Supabase (authentication and database, London), Anthropic (reading document contents during conversion, United States) and Resend (sign-in emails, United States). We may also disclose data where we are legally required to.

International transfer. Document contents are sent to Anthropic's API in the United States for the reading step, under standard contractual clauses and commercial terms which state that API content is not used to train models. If you cannot place your clients' documents outside the UK or EEA, InvoicePro will not be suitable for your firm.

7. How long we keep it

Uploaded source files are deleted once the job's output exists and you have had a reasonable window to download it. Extracted rows are kept so past jobs stay re-downloadable, and you can delete any job yourself at any time. Usage records are retained for as long as required for accounting and tax purposes. Account data is deleted when your account is closed, subject to those record-keeping obligations.

8. Your rights

You have the right to be informed, to access, to rectification, to erasure, to restrict processing, to data portability and to object. To exercise any of them, email privacy@invoicepro.co.uk — we respond within 7 working days, and in any event within one month as the legislation requires. If you are not satisfied, you may complain to the Information Commissioner's Office at ico.org.uk.

9. Security

Encryption in transit and at rest, per-row access control enforced at the database, magic-link sign-in with no passwords stored anywhere, and an invitation-only access model. The detail, including where documents are read, is on the security page.

10. Changes to this policy

If we change it materially we will email account holders and update the version and date at the top of this page. Previous versions are available on request.