← Back to InvoiceForge

GDPR Compliance

1. Our Commitment to GDPR

InvoiceForge UK is fully committed to compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. We have implemented comprehensive measures to protect your personal data.

2. Lawful Basis for Processing

We process your personal data only where we have a lawful basis, including:

  • Contractual necessity: To provide the invoicing and business management services you have signed up for
  • Legal obligation: To comply with UK tax and financial regulations
  • Legitimate interest: To improve our Service and communicate with you about your account
  • Consent: Where you have given explicit consent for specific processing activities

3. Data Protection Officer

We have appointed a Data Protection Officer who oversees our data protection practices. You can contact them at dpo@invoiceforge.co.uk.

4. Data Processing Agreement

For business customers who require a Data Processing Agreement (DPA), we provide a standard DPA that meets GDPR requirements. Contact us at legal@invoiceforge.co.uk to request a DPA.

5. International Transfers

Your data is stored and processed within the EU/UK. We do not transfer personal data outside the EEA unless adequate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

6. Breach Notification

In the event of a personal data breach, we will notify the ICO and affected data subjects within 72 hours as required by GDPR Article 33 and Article 34.

7. Your Rights

Under GDPR, you have the following rights:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restrict processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Rights regarding automated decision-making (Article 22)

To exercise any of these rights, contact us at privacy@invoiceforge.co.uk.