nvoyce.
nvoyce · Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") is incorporated into and forms part of the Nvoyce Terms of Service between Nvoyce AI LLC ("Nvoyce", "Processor") and the user of the Nvoyce platform ("Controller"). It governs Nvoyce's processing of personal data on the Controller's behalf in accordance with applicable data protection law, including the GDPR where applicable.

Effective date
April 28, 2026
Controller
You (the registered Nvoyce user)
Processor
Nvoyce AI LLC
01

Definitions

As used in this DPA:

Personal Data: Any information relating to an identified or identifiable natural person, as defined under applicable data protection law (including GDPR Article 4(1)).
Controller: The natural or legal person who determines the purposes and means of processing Personal Data — in this context, the Nvoyce user (you).
Processor: The entity that processes Personal Data on behalf of the Controller — in this context, Nvoyce AI LLC.
Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
Data Subject: An identified or identifiable natural person whose Personal Data is processed — in this context, your clients and their contact information.
Sub-processor: A third party engaged by Nvoyce to process Personal Data in connection with providing the Service.
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data.
Service: The Nvoyce platform for invoice and proposal generation, as described in the Terms of Service.
02

Scope and Purpose

2.1 Subject Matter

This DPA applies to Personal Data that the Controller uploads, enters, or generates through the Service, including client names, email addresses, phone numbers, company names, and any other contact details entered into the Nvoyce platform.

2.2 Nature and Purpose of Processing

Nvoyce processes Personal Data solely to provide the Service — specifically to generate, send, and track invoices and proposals on the Controller's behalf. Nvoyce does not use Personal Data for its own commercial purposes, advertising, or analytics beyond what is necessary to operate the Service.

2.3 Categories of Data Subjects

The Data Subjects are the Controller's clients and prospective clients whose contact information is entered into the platform.

2.4 Categories of Personal Data

2.5 Duration

Processing continues for the duration of the Controller's active Nvoyce account, and is terminated as described in Section 12.

03

Processor Obligations

Nvoyce, as Processor, agrees to:

04

Sub-processors

4.1 Authorised Sub-processors

The Controller authorises Nvoyce to engage the following sub-processors, each of whom has agreed to data protection obligations consistent with this DPA:

Sub-processorPurposeLocationPrivacy Policy
Supabase, Inc.Database hosting and storageUSA (AWS us-west-2)Privacy Policy ↗
Clerk, Inc.Authentication and user managementUSAPrivacy Policy ↗
Stripe, Inc.Payment processingUSAPrivacy Policy ↗
Resend, Inc.Transactional email deliveryUSAPrivacy Policy ↗
Vercel, Inc.Application hosting and CDNUSA (AWS / Edge)Privacy Policy ↗
Anthropic, PBCAI-powered document generation (Claude)USAPrivacy Policy ↗

4.2 Changes to Sub-processors

Nvoyce will notify the Controller of any intended addition or replacement of sub-processors by updating this DPA and, where feasible, by email notice. The Controller may object to a new sub-processor within 14 days of notification by contacting legal@nvoyce.ai.

05

Data Subject Rights

Nvoyce will assist the Controller in fulfilling its obligations to respond to Data Subject requests (including access, rectification, erasure, restriction, portability, and objection rights) under applicable law. The Controller, as the primary relationship holder with its clients, is responsible for receiving and triaging such requests.

If a Data Subject contacts Nvoyce directly regarding their rights, Nvoyce will forward the request to the Controller within 5 business days and will not respond to the Data Subject on the Controller's behalf without the Controller's authorisation.

For requests involving the Controller's own personal data (i.e., data about the Controller as an individual), please use the account deletion flow in Settings or email support@nvoyce.ai.

06

Security Measures

Nvoyce implements and maintains the following technical and organisational measures to protect Personal Data:

Nvoyce continuously evaluates and improves its security posture. The specific measures described above reflect the state of the Service as of the effective date and may be updated to reflect improvements.

07

International Transfers

Nvoyce and its sub-processors operate primarily in the United States. Where Personal Data of EU/EEA residents is transferred to the United States, Nvoyce relies on one or more of the following transfer mechanisms:

A copy of applicable SCCs or transfer mechanism documentation is available upon request at legal@nvoyce.ai.

08

Data Retention and Deletion

8.1 Retention During Service

Nvoyce retains Personal Data for as long as the Controller's account is active or as necessary to provide the Service.

8.2 Deletion on Request

The Controller may delete individual client records at any time through the Clients section of the dashboard. Deletion removes the record from Nvoyce's database. Residual copies in backups are purged on the applicable backup rotation cycle (typically 7–30 days depending on the sub-processor).

8.3 Account Deletion

Upon account deletion (via Settings → Danger Zone or by request to support@nvoyce.ai), Nvoyce will delete all Personal Data associated with the account within 30 days, except where retention is required by law (e.g., financial records for tax or audit purposes, which may be retained for up to 7 years).

8.4 Return of Data

The Controller may request an export of their data by contacting support@nvoyce.ai prior to account deletion. Nvoyce will provide a machine-readable export within 30 days of request.

09

Breach Notification

In the event of a Personal Data breach affecting data processed under this DPA, Nvoyce will notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Notification will include, to the extent known at the time:

The Controller is responsible for notifying relevant supervisory authorities and Data Subjects as required by applicable law. Nvoyce will cooperate in providing information needed for such notifications.

Breach notifications will be sent to the email address associated with the Controller's Nvoyce account.

10

Audit Rights

Nvoyce will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. This includes:

More extensive audits (e.g., on-site inspections) may be conducted by the Controller or an independent third party, subject to at least 30 days' prior written notice to legal@nvoyce.ai, during normal business hours, and at the Controller's expense. Nvoyce may require the auditor to sign a confidentiality agreement before granting access.

11

Liability

Each party's liability under this DPA is subject to the limitations and exclusions set forth in the Nvoyce Terms of Service. Where applicable data protection law imposes liability that cannot be limited by contract, such mandatory provisions shall apply.

As between Nvoyce and the Controller, the Controller is responsible for ensuring it has a valid legal basis for processing the Personal Data of its clients and for providing any required notices to Data Subjects.

12

Term and Termination

This DPA takes effect on the date the Controller accepts the Nvoyce Terms of Service and remains in force for the duration of the Service relationship.

This DPA automatically terminates when the Terms of Service terminate. Sections 5, 6, 8, 9, 10, and 11 survive termination to the extent necessary to give them effect.

Upon termination, Nvoyce will delete or return Personal Data as described in Section 8.3, unless applicable law requires otherwise.

13

Governing Law

This DPA is governed by the laws of the State of California, USA, without regard to conflict-of-law principles. Where GDPR applies, the parties acknowledge that the DPA is intended to satisfy Article 28 GDPR requirements, and any conflict between this DPA and GDPR shall be resolved in favour of GDPR compliance.

Disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.

Questions about this DPA?

For data protection enquiries, sub-processor documentation, or to exercise rights under this agreement, contact our privacy team.

legal@nvoyce.ai

Questions? legal@nvoyce.ai

Privacy PolicyTerms of ServiceCookie Notice

© 2026 Nvoyce AI LLC