Invoice PilotInvoice Pilot← Back to site

On this page

1. Purpose and scope2. Definitions3. Roles4. Controller instructions5. Controller obligations6. Confidentiality and personnel7. Security8. Sub-processors9. International transfers10. Data-subject requests11. Personal Data Breaches12. DPIAs and regulatory consultation13. Deletion and return14. Information and audits15. Records and regulatory cooperation16. Liability17. TermAnnex 1 — Processing detailsAnnex 2 — Technical & organisational measuresAnnex 3 — Sub-processor list

Data Processing Agreement

Last updated: 16 July 2026

Effective date: the date the Customer accepts the Terms of Service or first uses Invoice Pilot to process Customer Personal Data, whichever occurs first.

This Data Processing Agreement (“DPA”) forms part of the Invoice Pilot Terms of Service between:

  1. Andrew Richardson, sole trader, trading as Invoice Pilot (“Processor”); and
  2. the customer accepting the Terms (“Controller”).

1. Purpose and scope

This DPA applies where the Processor processes personal data on behalf of the Controller in connection with Invoice Pilot.

It reflects the parties’ obligations under applicable Data Protection Law, including the UK GDPR and Data Protection Act 2018.

If there is a conflict concerning processing of Customer Personal Data, this DPA takes priority over the Terms.

2. Definitions

Applicable Data Protection Law: data-protection and privacy law applying to the processing, including the UK GDPR, Data Protection Act 2018 and PECR where relevant.

Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Special Category Data: have the meanings given in Applicable Data Protection Law.

Customer Personal Data: Personal Data contained in Customer Data and processed by Invoice Pilot on the Controller’s behalf.

Sub-processor: another processor engaged by Invoice Pilot to process Customer Personal Data.

3. Roles

The Controller determines the purposes and essential means of processing Customer Personal Data.

Invoice Pilot acts as Processor, except where it independently determines a purpose, such as administering its own customer accounts, security, billing or legal compliance. Those independent activities are covered by the Invoice Pilot Privacy Policy.

4. Controller instructions

The Processor will process Customer Personal Data only:

  • on the Controller’s documented instructions;
  • as necessary to provide, secure and support the Service;
  • to comply with applicable law.

The Terms, this DPA, account configuration and lawful use of Service features constitute the Controller’s documented instructions.

If the Processor believes an instruction infringes Applicable Data Protection Law, it will inform the Controller unless prohibited by law and may pause the affected processing.

The Controller may issue additional reasonable written instructions that are consistent with the Service. Work outside standard functionality may be subject to agreed fees.

5. Controller obligations

The Controller warrants that:

  • it has a valid lawful basis for processing Customer Personal Data;
  • it has provided required privacy information;
  • it has authority to instruct the Processor;
  • its instructions comply with Applicable Data Protection Law;
  • it collects only information that is adequate, relevant and necessary;
  • it has identified any required Article 9 condition and Data Protection Act 2018 requirement for Special Category Data;
  • it will not instruct the Processor to process Personal Data unlawfully;
  • it will manage data-subject requests and determine retention periods;
  • it will configure authorised-user access appropriately.

6. Confidentiality and personnel

The Processor will ensure that people authorised to process Customer Personal Data:

  • are bound by confidentiality obligations;
  • access it only where required for their role;
  • receive appropriate data-protection and security guidance.

7. Security

Taking account of the state of the art, implementation cost, nature, scope, context and purposes of processing, and risks to individuals, the Processor will maintain appropriate technical and organisational measures.

Current measures are described in Annex 2. The Processor may update them where the overall level of protection is not materially reduced.

8. Sub-processors

The Controller gives general written authorisation for the Processor to use Sub-processors.

The Processor will:

  • publish or make available a current Sub-processor list (see Annex 3);
  • give at least 30 days advance notice of a new Sub-processor where reasonably practicable;
  • impose data-protection obligations providing an equivalent level of protection required by this DPA;
  • remain responsible for the Sub-processor’s performance of those obligations to the extent required by law.

The Controller may object to a new Sub-processor on reasonable data-protection grounds by writing to support@invoicepilot.co.uk before the change takes effect.

The parties will work in good faith to find a reasonable solution. If none is available, the Controller may stop using the affected feature or terminate the affected Service without penalty before the Sub-processor begins processing.

9. International transfers

The Processor will not make a restricted transfer of Customer Personal Data unless a lawful transfer mechanism is in place.

This may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to standard contractual clauses;
  • another valid safeguard or derogation.

The Controller authorises the Processor to enter into necessary transfer terms on its behalf where permitted.

10. Data-subject requests

Taking account of the nature of processing, the Processor will provide reasonable assistance to help the Controller respond to requests concerning:

  • access;
  • correction;
  • deletion;
  • restriction;
  • portability;
  • objection;
  • withdrawal of consent, where relevant.

If the Processor receives a request relating to Customer Personal Data, it will normally direct the requester to the Controller and notify the Controller, unless prohibited by law.

The Processor will not respond substantively on the Controller’s behalf unless instructed or legally required.

11. Personal Data Breaches

The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Where available, the notice will include:

  • the nature of the breach;
  • categories and approximate numbers of affected individuals and records;
  • likely consequences;
  • measures taken or proposed;
  • a contact point for further information.

Information may be supplied in phases where it is not all available at once.

The Processor will take reasonable steps to contain, investigate and mitigate the breach. Notification does not amount to an admission of fault or liability.

The Controller is responsible for deciding whether notification to the ICO or affected individuals is required.

12. DPIAs and regulatory consultation

The Processor will provide reasonable information and assistance required for:

  • data-protection impact assessments;
  • prior consultation with a regulator;
  • security and risk assessments relating to the Service.

Assistance beyond standard documentation or functionality may be subject to reasonable agreed charges.

13. Deletion and return

During the subscription, the Controller may delete or export Customer Personal Data using available features.

On termination, the Processor will, at the Controller’s choice and subject to available functionality:

  • provide a reasonable opportunity to export Customer Personal Data; and
  • delete or anonymise Customer Personal Data after 30 days,

unless applicable law requires retention.

Residual data may remain in secured backups for up to 7 days. During that period it will remain protected and will not be restored except for disaster recovery, legal compliance or security purposes.

Deletion does not apply to information Invoice Pilot independently controls and must retain for billing, tax, fraud prevention, legal claims or compliance.

14. Information and audits

The Processor will make available information reasonably necessary to demonstrate compliance with this DPA, such as:

  • this DPA;
  • security information;
  • Sub-processor information;
  • relevant policies or independent assurance reports, where available.

If this is insufficient, the Controller may request an audit no more than once in any 12-month period, unless a breach or regulator requires otherwise.

Audits must:

  • be on reasonable written notice;
  • occur during normal business hours;
  • avoid disruption;
  • protect other customers and confidential systems;
  • be conducted by an independent auditor under confidentiality duties;
  • be at the Controller’s cost, unless the audit identifies a material breach by the Processor.

The Processor is not required to disclose information that would compromise another customer, security, privileged material or trade secrets beyond what is legally required.

15. Records and regulatory cooperation

The Processor will maintain records required of a processor under Applicable Data Protection Law and cooperate with the ICO where legally required.

16. Liability

Liability under this DPA is subject to the liability provisions in the Terms, except where Applicable Data Protection Law prohibits that limitation.

17. Term

This DPA continues while the Processor processes Customer Personal Data on behalf of the Controller.

Annex 1 — Processing details

Subject matter

Provision of Invoice Pilot, a cloud-based administration platform for childcare, education and activity providers.

Duration

For the subscription term, post-termination export period and protected backup-retention period, unless law requires longer.

Nature and purpose

  • hosting and organising provider records;
  • managing children, parents and guardians;
  • session, attendance and booking administration;
  • invoice generation and payment tracking;
  • expense, receipt and profit reporting;
  • document storage and electronic signing;
  • email delivery and reminders;
  • support, security, backup and troubleshooting.

Data subjects

  • children;
  • parents and guardians;
  • emergency contacts and authorised collectors;
  • customer owners, staff and authorised users;
  • document signatories;
  • suppliers or payees shown in expense records.

Personal Data

  • names;
  • contact details;
  • addresses;
  • dates of birth and ages;
  • child–parent or guardian relationships;
  • emergency contact details;
  • session, attendance and booking records;
  • invoice, fee, funded-hours and payment information;
  • expense, supplier and receipt information;
  • signatures, confirmations, timestamps and audit information;
  • uploaded forms, policies, permissions and notes;
  • account, authentication, device and usage records.

Special Category Data

Only where uploaded or entered by the Controller, this may include:

  • health information;
  • allergies and medical conditions;
  • disability or additional-needs information;
  • safeguarding-related information;
  • other sensitive information contained in provider forms or notes.

The Controller must decide whether such information is necessary and identify a lawful basis, Article 9 condition and any Data Protection Act 2018 requirements.

Processing frequency

Continuous or intermittent, depending on Customer use.

Annex 2 — Technical and organisational measures

Access and identity

  • authenticated user accounts;
  • unique user identities;
  • role-based or function-based access;
  • read-only restrictions where relevant;
  • limited privileged production access;
  • prompt removal of unnecessary access.

Tenant and database protection

  • logical separation of customer records;
  • Supabase Row Level Security on customer-data tables;
  • server-side authorisation checks where required;
  • validation of user-supplied identifiers.

File protection

  • private storage buckets for receipts and other sensitive documents;
  • time-limited signed URLs rather than permanent public links for private buckets;
  • file-type and size validation;
  • customer-scoped storage paths;
  • access policies preventing cross-customer access.

Transmission and hosting

  • HTTPS/TLS encryption in transit;
  • hosting through vetted cloud suppliers;
  • data encrypted at rest, as provided by Supabase and Vercel’s underlying infrastructure as standard;
  • supplier contracts and data-protection terms.

Application security

  • dependency and security updates;
  • production build and lint checks;
  • separation of development and production credentials;
  • secrets stored outside client-side source code;
  • input validation and safe database queries;
  • restricted administrative tools.

Availability and recovery

  • daily automated database backups, provided as part of the Supabase Pro plan;
  • backups retained on a rolling 7-day basis; restoration is available via Supabase’s standard dashboard/support-assisted recovery process;
  • incident response and recovery procedures;
  • resilience provided by hosting suppliers.

Monitoring and incident management

  • security and error logging appropriate to the Service;
  • investigation and containment procedures;
  • Personal Data Breach escalation;
  • customer notification without undue delay where required.

Organisational controls

  • confidentiality duties;
  • least-privilege access;
  • supplier review;
  • documented retention and deletion processes;
  • secure development practices;
  • periodic review of risks and controls.

Annex 3 — Sub-processor list

Sub-processorServiceData involvedLocation / transfer mechanism
Supabase, Inc.Database, authentication and storageAccount and Customer Dataeu-west-1 (Ireland). Data resides within the EEA.
Vercel Inc.Application and website hostingTechnical data and data transmitted through the appUnited States (Washington, D.C. region, default). UK Addendum to Standard Contractual Clauses applies to the transfer.
Resend, Inc.Transactional emailNames, email addresses and email contentUnited States (AWS US-East). Certified under the EU-US Data Privacy Framework and UK Extension.
Stripe group entity serving the CustomerSubscription/payment processingAccount, billing and transaction dataProcessed under Stripe's own published data processing terms; standard contractual transfer safeguards apply.
Vercel AnalyticsWebsite analyticsAggregated usage dataIncluded as part of the Vercel hosting sub-processor above.
MetaAdvertising measurement (Meta Pixel)Conversion/advertising dataProcessed under Meta's own published data processing terms. Currently active on every page load; not yet gated behind a consent mechanism.
PrivacyTermsData Processing AgreementSupport
© 2026 Invoice Pilot. Built for activity providers.