What this is
This is the agreement required by Article 28 of the GDPR whenever one company processes personal data on behalf of another. When a merchant installs Invocourier, we process their customers' data for them — so this document sets out what we may do with it, how we protect it, who else touches it, and what happens when the relationship ends.
It applies automatically. By installing or using Invocourier, the merchant and LIQUID ECOMM S.R.L. enter into this agreement; no signature is needed. If your organisation requires a signed copy or its own template, write to [email protected].
1. Parties and roles
| Controller | The merchant — the Shopify store that installed Invocourier. The merchant determines why and how their customers' personal data is processed. |
|---|---|
| Processor | LIQUID ECOMM S.R.L., Str. Dealu Nou 13A, Sat Sărata, Comuna Sărata, Bacău county, 607361, Romania. CUI 48989226, Trade Registry J2023001636041. Trading as Invocourier. |
| Contact | [email protected] |
This agreement governs only the data we process on the merchant's behalf — principally the personal data appearing on invoices. Data we hold for our own purposes, such as the merchant's account and billing records, is covered by our Privacy Policy, where we are the controller.
2. Subject matter, duration, nature and purpose
Subject matter and purpose: generating legally compliant electronic invoices and credit notes from the merchant's Shopify orders, transmitting them to the recipient or the relevant network, and archiving them so the merchant can meet their statutory retention duty.
Nature of the processing: collection from Shopify, structuring into standard invoice formats (Peppol BIS 3.0, XRechnung, Factur-X/ZUGFeRD and equivalents), validation, transmission, storage, retrieval and erasure.
Duration: for as long as the merchant has Invocourier installed, and thereafter only as clause 9 provides.
Categories of data subjects: the merchant's customers (buyers), and where a buyer is a business, that business's contact people.
Types of personal data: name; billing address; email address; VAT identification number or company registration number where supplied; purchased items, quantities and amounts; the invoice number, date and payment status; and the result of any VAT-number validation performed for that buyer.
We do not process special categories of personal data under Article 9, and the app does not request the buyer's telephone number from Shopify.
3. Our obligations as processor
- Documented instructions. We process personal data only on the merchant's documented instructions — which are: this agreement, the app's settings as the merchant configures them, and any support request they make — unless EU or member-state law requires otherwise, in which case we inform the merchant beforehand unless that law forbids it.
- No other use. We do not use the data for our own purposes, do not sell it, do not use it to train models, and do not use it for advertising or profiling.
- Unlawful instructions. If we consider an instruction to infringe the GDPR or other data protection law, we tell the merchant immediately and may suspend that instruction.
- Confidentiality. Everyone authorised to process the data is bound by confidentiality. Access is limited to the company's administrator.
- Security. We apply the measures in Annex 2 and keep them under review.
- Assistance with data subject rights. Where a buyer exercises a right, we assist the merchant with appropriate technical and organisational measures, taking the nature of the processing into account. In practice the app already surfaces the answer: the Invoices page lets the merchant view, download and export every document held for any order.
- Assistance with Articles 32–36. We help the merchant meet their obligations on security, breach notification, data protection impact assessments and prior consultation, to the extent the information is available to us.
- Information and audit. We make available all information necessary to demonstrate compliance with Article 28, and allow and contribute to audits or inspections by the merchant or an auditor they mandate. Audits take place on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, and must not disrupt the service or compromise other merchants' data. We may satisfy an audit request with documentation and written answers where these reasonably address it.
4. Shopify's role
Order data reaches us from Shopify, the merchant's own platform, under the merchant's own arrangements with Shopify. Shopify is not our sub-processor and we do not pass personal data to them; we receive it. What we may request from Shopify is limited by the protected customer data access Shopify grants the app, which is restricted to the fields an invoice requires.
5. Sub-processors
The merchant gives general written authorisation for us to engage sub-processors. Those currently engaged:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application and database | Helsinki, Finland (EU) |
| Cloudflare, Inc. | DNS, TLS termination and network edge | Global edge; US company |
| Recommand BV | Peppol access point for transmission to Belgian recipients | Belgium (EU) |
We impose on every sub-processor, by contract, data protection obligations no less protective than those in this agreement, and we remain fully liable to the merchant for their performance.
Changes. Before adding or replacing a sub-processor we give the merchant at least 30 days' notice by email and by updating this page. The merchant may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the merchant may terminate the affected service without penalty and receive a pro-rata refund of any prepaid fees.
6. Invoice recipients are not sub-processors
An invoice is a document the merchant is legally required to send to someone. When we transmit one — over the Peppol network to the recipient's access point, by email to the buyer, or to a tax authority platform where the law requires it — that recipient receives the invoice as an independent controller under their own legal obligations, not as our sub-processor. Delivering the document is the service the merchant instructs us to perform.
7. International transfers
Personal data is stored and processed within the European Union (Helsinki, Finland). We do not transfer it outside the EEA except where a sub-processor listed above operates global infrastructure — currently Cloudflare, a US company — in which case the transfer relies on the European Commission's Standard Contractual Clauses together with appropriate supplementary measures.
Where an invoice is addressed to a recipient outside the EEA, transmitting it there is a transfer necessary for the performance of the contract between the merchant and their customer, and for compliance with the merchant's legal obligations.
8. Personal data breaches
We notify the merchant without undue delay after becoming aware of a personal data breach affecting their data, and in any event within 48 hours. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once, we provide it in phases without further undue delay.
The merchant, as controller, decides on and makes any notification to their supervisory authority or to affected individuals. We support them with the facts.
9. Deletion and return of data
When a merchant uninstalls Invocourier, Shopify notifies us and we delete all personal data we hold for that shop — archived invoices included — 48 hours after the uninstall, unless EU or member-state law requires us to keep it. Nothing is retained as a backup copy beyond the rotation of our encrypted backups, which are overwritten in the ordinary cycle.
The archive leaves with the merchant, not with us. The statutory duty to keep invoices for the retention period of the merchant's country stays with the merchant. Before uninstalling, merchants must export their documents from the Invoices page, where every invoice and credit note is downloadable in its original format. We cannot restore data after deletion.
The merchant may at any time, during the term, ask us to return or delete specific data; we act on such a request without undue delay, subject to any legal obligation to retain it.
10. Erasure requests and the invoice exception
Where a buyer asks the merchant to erase their data, an issued invoice cannot simply be deleted: Article 17(3)(b) of the GDPR excludes erasure where processing is necessary for compliance with a legal obligation, and invoice retention is exactly such an obligation. On an erasure request we identify for the merchant which documents contain that buyer's data, confirm we hold nothing else about them, and retain the documents on that basis. Everything not contained in an invoice, we do not store in the first place.
11. Liability, term and precedence
This agreement takes effect when the merchant installs Invocourier and remains in force for as long as we process personal data on their behalf. Clauses 9 and 10 survive termination.
Liability under this agreement is governed by our general terms of service and by Article 82 of the GDPR. Nothing here limits either party's liability towards a data subject.
If this agreement conflicts with any other agreement between the parties on the subject of personal data processing, this agreement prevails. It is governed by Romanian law, without prejudice to any mandatory provision of the GDPR or of the merchant's own national data protection law.
Changes. We may update this agreement to reflect changes in the service or in the law. Material changes are notified to merchants by email at least 30 days before they take effect, and the version and date at the top of this page are updated.
Annex 1 — Details of the processing
| Subject matter | Generation, transmission and archiving of electronic invoices and credit notes from the merchant's Shopify orders |
|---|---|
| Duration | For the term of the merchant's use of Invocourier; deletion 48 hours after uninstall (clause 9) |
| Nature | Collection, structuring, validation, transmission, storage, retrieval, erasure |
| Purpose | Compliance with the merchant's statutory e-invoicing and invoice-retention obligations |
| Data subjects | The merchant's customers; contact people at business customers |
| Personal data | Name; billing address; email address; VAT or company registration number; purchased items, quantities and amounts; invoice number, date and payment status; VAT-validation results |
| Special categories | None |
Annex 2 — Technical and organisational measures (Article 32)
- Encryption in transit: TLS on every connection — to the app, to Shopify, to the Peppol access point, and for email delivery.
- Encryption at rest: the production server's storage is encrypted; database backups are encrypted independently.
- Access control: production access is limited to the company's administrator, by SSH key only, with password authentication disabled. Administrative accounts use a password manager and two-factor authentication.
- Network isolation: the database and the application listen on the loopback interface only, reachable exclusively through the reverse proxy; a cloud firewall permits only HTTPS, HTTP and SSH.
- Tenant separation: every record is keyed by shop domain and every query is scoped to the authenticated shop, so one merchant's data cannot be returned to another.
- Separation of environments: development runs against a separate application, a separate store and a separate database; no production data is used in development.
- Integrity of documents: invoice numbering is gapless and documents are archived in the exact form transmitted, so an archived document can be shown to be the one that was issued.
- Logging: administrative access is logged; the application logs each document's issue, delivery outcome and any redaction decision.
- Resilience: the service restarts automatically on failure; deliveries that fail transiently are retried on a fixed schedule rather than dropped.
- Patching: unattended security updates are enabled on the production server.
- Incident response: a written procedure covering detection, containment, assessment within 24 hours, notification, remediation and a post-incident review; reviewed yearly.
These measures are reviewed as the service develops, and never reduced below the level described here without notifying merchants.
Annex 3 — Sub-processors
The current list is in clause 5 above, which is the authoritative version and is updated whenever it changes.