How we handle your documents.
What we process, where it goes and who else touches it. It should take about five minutes to read the whole thing.
Version 1.0 · 12 September 2026
1. What we process
When you upload invoices, InvoicePro reads the contents of those documents to extract the fields on the schedule — invoice date, due date, counterparty, reference, description, net, VAT, gross, currency and document type — together with the checks applied to each row.
We hold limited account data (your email address, the firm you belong to) and a usage record for each job: how many documents it contained, how many were billable, what it was priced at, and when it ran. We also retain the structured output — the extracted rows — so you can re-download a past job as Excel or as a Xero bill-import CSV without uploading the source files again.
We do not extract or store card numbers or banking credentials, and we have no access to your accounting system or to your clients'. We do not look at the contents of your jobs except where strictly necessary to run the service, answer a support request you have raised, or meet a legal obligation.
2. Where it is processed and stored
Uploaded files and job output are held on the application's own encrypted disk in Frankfurt (eu-central). Account and usage data is held in London (eu-west-2). Application hosting is provided by Render; authentication and the database by Supabase; transactional email by Resend.
3. Sub-processors
Four, each a major provider with published security and DPA documentation.
| Provider | Role | What it sees | Region |
|---|---|---|---|
| Anthropic | Reading document contents during conversion | Document contents, transiently | US, under DPA |
| Render | Application hosting, file storage during and after a job | Uploaded files and job output | Frankfurt |
| Supabase | Authentication, database, account and usage records | Email, firm, job metadata, extracted rows | London (eu-west-2) |
| Resend | Sign-in emails | Email address only — no documents | US, under DPA |
There is no payment provider in the product, because there is no checkout: billing is a monthly invoice raised against the usage record. No card details exist in this system to be exposed.
4. Retention and deletion
Uploaded source files are deleted once a job's output has been produced and you have had a reasonable window to re-download from it. The extracted rows are retained so that past jobs stay re-downloadable, and can be deleted by you at any time from the job itself.
Deletion is recorded rather than hidden: when files are removed, the usage record keeps the fact and the date. That record is immutable by design: it is write-once at the database level, and only three fields on it can ever change, none of which is the amount. Neither we nor anyone else can go back and rewrite what a job cost.
5. Access control
Sign-in is by emailed magic link. There are no passwords in this product, so there is no password to reuse, leak or reset, and no password database to breach. The session is a server-set, HTTP-only cookie.
A job belongs to the person who ran it and to the firm they belong to. A request for someone else's job returns "not found" rather than "forbidden" — the existence of another firm's work is not disclosed by the error message.
Access to the service is by invitation, at firm-domain or individual-address level. There is no open sign-up, so there is no route for an unknown party to place documents into the system at all.
6. Security commitments
- Data in transit is encrypted with TLS 1.2 or higher.
- Data at rest is encrypted, both on the application disk and in the database.
- Database access is enforced per-row at the database level, not only in application code.
- Service credentials are server-side only and never reach the browser.
- Our infrastructure providers publish their own SOC 2 Type II reports.
- Sign-in email is DKIM-signed with a published DMARC record.
7. Incident response
If we confirm an incident affecting your account, we will tell you by email to the address on file within 72 hours of confirming it. Where the ICO requires notification under UK GDPR, we will notify within 72 hours of becoming aware, in line with the statutory obligation.
8. Your rights under UK GDPR
You have the right to access, correct, delete and port your personal data, and to object to or restrict processing in certain circumstances. Most of this can be done immediately from within the app; for anything else, email support@invoicepro.co.uk and we will respond within 7 working days. You may also complain to the Information Commissioner's Office at ico.org.uk.
9. Your clients' data
Where you upload documents belonging to your clients, you are the controller and we are the processor. A Data Processing Agreement is available on request — email support@invoicepro.co.uk.
10. Who we are
InvoicePro is operated by AX Studio Labs Ltd, a company registered in England and Wales. We are registered with the Information Commissioner's Office as a data controller. InvoicePro is a separate product from StatementPro, also operated by AX Studio Labs Ltd: the two share no database, no login and no billing, and data does not move between them.