Last updated: 16 July 2026
Effective date: the date the Customer accepts the Terms of Service or first uses Invoice Pilot to process Customer Personal Data, whichever occurs first.
This Data Processing Agreement (“DPA”) forms part of the Invoice Pilot Terms of Service between:
This DPA applies where the Processor processes personal data on behalf of the Controller in connection with Invoice Pilot.
It reflects the parties’ obligations under applicable Data Protection Law, including the UK GDPR and Data Protection Act 2018.
If there is a conflict concerning processing of Customer Personal Data, this DPA takes priority over the Terms.
Applicable Data Protection Law: data-protection and privacy law applying to the processing, including the UK GDPR, Data Protection Act 2018 and PECR where relevant.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Special Category Data: have the meanings given in Applicable Data Protection Law.
Customer Personal Data: Personal Data contained in Customer Data and processed by Invoice Pilot on the Controller’s behalf.
Sub-processor: another processor engaged by Invoice Pilot to process Customer Personal Data.
The Controller determines the purposes and essential means of processing Customer Personal Data.
Invoice Pilot acts as Processor, except where it independently determines a purpose, such as administering its own customer accounts, security, billing or legal compliance. Those independent activities are covered by the Invoice Pilot Privacy Policy.
The Processor will process Customer Personal Data only:
The Terms, this DPA, account configuration and lawful use of Service features constitute the Controller’s documented instructions.
If the Processor believes an instruction infringes Applicable Data Protection Law, it will inform the Controller unless prohibited by law and may pause the affected processing.
The Controller may issue additional reasonable written instructions that are consistent with the Service. Work outside standard functionality may be subject to agreed fees.
The Controller warrants that:
The Processor will ensure that people authorised to process Customer Personal Data:
Taking account of the state of the art, implementation cost, nature, scope, context and purposes of processing, and risks to individuals, the Processor will maintain appropriate technical and organisational measures.
Current measures are described in Annex 2. The Processor may update them where the overall level of protection is not materially reduced.
The Controller gives general written authorisation for the Processor to use Sub-processors.
The Processor will:
The Controller may object to a new Sub-processor on reasonable data-protection grounds by writing to support@invoicepilot.co.uk before the change takes effect.
The parties will work in good faith to find a reasonable solution. If none is available, the Controller may stop using the affected feature or terminate the affected Service without penalty before the Sub-processor begins processing.
The Processor will not make a restricted transfer of Customer Personal Data unless a lawful transfer mechanism is in place.
This may include:
The Controller authorises the Processor to enter into necessary transfer terms on its behalf where permitted.
Taking account of the nature of processing, the Processor will provide reasonable assistance to help the Controller respond to requests concerning:
If the Processor receives a request relating to Customer Personal Data, it will normally direct the requester to the Controller and notify the Controller, unless prohibited by law.
The Processor will not respond substantively on the Controller’s behalf unless instructed or legally required.
The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Where available, the notice will include:
Information may be supplied in phases where it is not all available at once.
The Processor will take reasonable steps to contain, investigate and mitigate the breach. Notification does not amount to an admission of fault or liability.
The Controller is responsible for deciding whether notification to the ICO or affected individuals is required.
The Processor will provide reasonable information and assistance required for:
Assistance beyond standard documentation or functionality may be subject to reasonable agreed charges.
During the subscription, the Controller may delete or export Customer Personal Data using available features.
On termination, the Processor will, at the Controller’s choice and subject to available functionality:
unless applicable law requires retention.
Residual data may remain in secured backups for up to 7 days. During that period it will remain protected and will not be restored except for disaster recovery, legal compliance or security purposes.
Deletion does not apply to information Invoice Pilot independently controls and must retain for billing, tax, fraud prevention, legal claims or compliance.
The Processor will make available information reasonably necessary to demonstrate compliance with this DPA, such as:
If this is insufficient, the Controller may request an audit no more than once in any 12-month period, unless a breach or regulator requires otherwise.
Audits must:
The Processor is not required to disclose information that would compromise another customer, security, privileged material or trade secrets beyond what is legally required.
The Processor will maintain records required of a processor under Applicable Data Protection Law and cooperate with the ICO where legally required.
Liability under this DPA is subject to the liability provisions in the Terms, except where Applicable Data Protection Law prohibits that limitation.
This DPA continues while the Processor processes Customer Personal Data on behalf of the Controller.
Provision of Invoice Pilot, a cloud-based administration platform for childcare, education and activity providers.
For the subscription term, post-termination export period and protected backup-retention period, unless law requires longer.
Only where uploaded or entered by the Controller, this may include:
The Controller must decide whether such information is necessary and identify a lawful basis, Article 9 condition and any Data Protection Act 2018 requirements.
Continuous or intermittent, depending on Customer use.
| Sub-processor | Service | Data involved | Location / transfer mechanism |
|---|---|---|---|
| Supabase, Inc. | Database, authentication and storage | Account and Customer Data | eu-west-1 (Ireland). Data resides within the EEA. |
| Vercel Inc. | Application and website hosting | Technical data and data transmitted through the app | United States (Washington, D.C. region, default). UK Addendum to Standard Contractual Clauses applies to the transfer. |
| Resend, Inc. | Transactional email | Names, email addresses and email content | United States (AWS US-East). Certified under the EU-US Data Privacy Framework and UK Extension. |
| Stripe group entity serving the Customer | Subscription/payment processing | Account, billing and transaction data | Processed under Stripe's own published data processing terms; standard contractual transfer safeguards apply. |
| Vercel Analytics | Website analytics | Aggregated usage data | Included as part of the Vercel hosting sub-processor above. |
| Meta | Advertising measurement (Meta Pixel) | Conversion/advertising data | Processed under Meta's own published data processing terms. Currently active on every page load; not yet gated behind a consent mechanism. |