Data Processing Addendum

Last updated: 28 June 2026

This DPA describes how we process personal data on your behalf when you use Enki Invoice, including security measures, sub-processors, and international transfers. This document is a general template and is not legal advice. You should have it reviewed by qualified counsel before relying on it.

1. Roles of the parties

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Controller") and Enki Invoice ("Processor"). For the personal data you upload about your clients and contacts, you act as the Controller and we act as the Processor. For your own account data, we act as Controller (see the Privacy Policy).

2. Subject matter and nature of processing

We process personal data only to provide the Service and on your documented instructions (including via configuration in the app). The processing covers:

  • Categories of data subjects — your clients, their contacts, and signatories.
  • Categories of data — names, contact details, billing details, invoice and contract content, time entries, and related metadata.
  • Purpose — invoicing, contracts and e-signature, time tracking, payments, and client communications.

3. Our obligations

  • process personal data only on your documented instructions;
  • ensure personnel are bound by confidentiality;
  • implement appropriate technical and organisational security measures;
  • assist you, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations; and
  • delete or return personal data at the end of the engagement, subject to legal retention.

4. Sub-processors

You authorise us to engage sub-processors in the functional categories below. We impose data-protection terms on each that are no less protective than this DPA, and we remain responsible for their performance.

  • Our cloud hosting and database provider: database, auth, storage
  • Our application hosting and content-delivery provider: hosting and delivery
  • A privacy-focused analytics provider: product analytics
  • Our payment processing provider: payments
  • Our transactional email provider: transactional email delivery
  • An optional connection to your own email account: optional email delivery from your own email account
  • Our AI processing providers: voice transcription, timesheet parsing, and contract review
  • Our caching and rate-limiting provider: caching and rate limiting
  • Our error-monitoring provider: error monitoring

A current list of named sub-processors is available to customers on request. We will give notice of intended changes to sub-processors so you can object on reasonable grounds.

5. International transfers

Where personal data is transferred outside the UK, EEA, or Australia, we rely on appropriate safeguards including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.

6. Security measures

  • row-level security isolating each tenant's data;
  • encryption of data in transit;
  • least-privilege access controls and audit logging of sensitive operations;
  • rate limiting and abuse protection on sensitive endpoints; and
  • monitoring and incident response.

7. Breach notification

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, and will provide information reasonably necessary for you to meet your own notification obligations.

8. Audits

On reasonable request and subject to confidentiality, we will make available information necessary to demonstrate compliance with this DPA and allow for reasonable audits.

9. Return and deletion

On termination, you may export your data. We will delete personal data within a reasonable period afterwards, except where retention is required by law.

10. Contact

For DPA matters, contact hello@enkidigital.solutions.