Privacy Policy
Last updated: 1 September 2026
1. Who we are
InvoiceFlow ("InvoiceFlow", "we", "us", "our") is a multi-tenant e-invoicing and business access management platform for UAE businesses, available as a web application and an Android app. This policy explains what personal data we collect, why, how it is used, how long we keep it, and the rights you have under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the "PDPL").
If your company (a "tenant") uses InvoiceFlow, your company is the controller of the business data entered into the platform (customer and supplier records, invoices, credit and debit notes, and similar), and InvoiceFlow acts as a processor on your company's documented instructions. For the account and login data that identifies you as an individual user, and for operating and securing the platform itself, InvoiceFlow is the controller. Where InvoiceFlow acts as a processor, this policy is supplemented by the data-processing terms in our Terms & Conditions.
Questions about this policy, or any request relating to your personal data, can be sent to our data protection contact at security@invoiceflow.ae.
2. Data we collect
Account & login data
- Name, email address, username, and phone number
- Password (stored as a salted hash — we never store or can see your plaintext password)
- Two-factor authentication setup (a TOTP secret and backup codes, both stored encrypted/hashed)
- Login history, IP address, and device/browser information, for security and audit purposes
Business data you or your company enter
- Customer and supplier records (company name, Tax Registration Number, address, contact name, email, phone)
- Invoices, credit notes, debit notes, and their line items
- Documents you choose to upload — for example, a Purchase Order PDF used to pre-fill a customer record
Mobile-specific data (Android app)
- A push-notification token, used to deliver in-app alerts (e.g. an item awaiting your approval)
- Biometric app unlock (fingerprint/face) is verified entirely by your device's own operating system — InvoiceFlow never receives, stores, or has access to your biometric data itself
Billing data
Subscription and billing is handled by Stripe. InvoiceFlow does not store your full card number — Stripe processes payment details directly under its own privacy policy.
3. How we use your data
- To provide and operate the InvoiceFlow platform, including e-invoice creation, submission to the UAE Federal Tax Authority's Peppol network, and access administration
- To authenticate you and keep your account secure
- To send account-related communications — email verification, password resets, invitations, and approval notifications
- To maintain an audit trail of actions taken in the system, as required for compliance and dispute resolution
- To provide customer support when you contact us
- To improve the platform and diagnose technical issues
We do not sell your personal data, and we do not use it for third-party advertising. InvoiceFlow does not currently use any third-party analytics or advertising tracking services.
Our legal basis for processing (PDPL Article 4)
We process personal data only where the PDPL permits it — principally:
- Performance of a contract — to provide the platform to you and your company under our Terms & Conditions.
- Compliance with a legal obligation — for example, transmitting e-invoices to the Federal Tax Authority and retaining tax records for the periods UAE law requires.
- Our legitimate interests — securing the platform, preventing fraud and abuse, maintaining an audit trail, and improving the service — weighed against your rights and interests.
- Consent — where we ask for it specifically, such as optional communications; you can withdraw consent at any time without affecting processing already carried out.
4. Who we share data with
We share data only with the service providers that help us run InvoiceFlow, and only to the extent needed for that purpose:
| Who | What for |
|---|---|
| UAE Federal Tax Authority (via the Peppol network) | Submitting your e-invoices, credit notes, and debit notes, as legally required for FTA e-invoicing compliance |
| Anthropic (Claude API) | When you use the "Import Customer from PO" feature, the uploaded PDF is sent to Anthropic's API to extract the buyer's details. The document is used only to generate that one response and is not stored by InvoiceFlow afterward. See Anthropic's own privacy policy for how they handle API data. |
| Stripe | Processing subscription payments |
| Brevo | Sending transactional emails (verification, password reset, notifications) |
| Firebase Cloud Messaging (Google) | Delivering push notifications to the Android app |
| Oracle Cloud Infrastructure | Hosting the application, database, and file storage |
We may also disclose data where required by law, such as in response to a valid request from the FTA or another UAE regulatory or judicial authority, or to establish, exercise, or defend a legal claim.
5. International data transfers
Our core application database and file storage are hosted on Oracle Cloud Infrastructure in the Dubai (UAE) region. Some of the service providers listed above process data on infrastructure located outside the UAE — for example, Stripe, Brevo, Anthropic, and Google (Firebase Cloud Messaging). Where personal data is transferred outside the UAE, we do so only in the circumstances the PDPL permits: to a jurisdiction the UAE recognises as providing an adequate level of protection, or, where no adequacy decision applies, under an appropriate safeguard such as contractual clauses that bind the recipient to protection standards equivalent to the PDPL, or with your explicit consent.
You can ask us for more detail on where a specific category of data is stored by contacting security@invoiceflow.ae.
6. Data retention
We retain your account and business data for as long as your company's InvoiceFlow subscription is active, and for a further period afterward as required for tax, legal, and audit purposes — UAE tax law generally requires invoice and accounting records to be retained for at least five years (longer for certain real-estate records). Audit log entries are retained on a configurable policy and purged automatically once that period elapses. An unverified sign-up that is never completed is discarded automatically. A source PDF uploaded for AI-assisted customer creation is not retained after the extraction result is returned.
When a retention period ends, or when we accept a valid deletion request, personal data is deleted or irreversibly anonymised.
7. Your rights under the PDPL
Subject to the conditions and exceptions in the PDPL, you have the right to:
- be informed about how your personal data is processed, and to request access to a copy of it;
- have inaccurate or incomplete data corrected;
- request deletion of your personal data, subject to our legal obligation to retain certain financial records for the periods required by UAE tax law;
- request that we stop or restrict processing, or object to processing based on our legitimate interests;
- receive the personal data you provided to us in a structured, machine-readable format, and ask us to transfer it where technically feasible;
- withdraw consent where processing is based on consent; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. InvoiceFlow does not make such decisions about you — the AI-assisted PO import only pre-fills a form that a person reviews and saves.
You can review and update most of your account information directly within InvoiceFlow. For anything else, email security@invoiceflow.ae from the address associated with your account; we will verify your identity and respond within the period required by the PDPL. If the business data you are asking about was entered by a tenant company that uses InvoiceFlow, we will refer your request to that company as the controller.
If you believe we have not handled your personal data in line with the PDPL, you may lodge a complaint with the UAE Data Office (the federal supervisory authority for data protection). We would appreciate the chance to address your concern first.
8. Data security
We use appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS) between your device and our servers, encrypted database connections, password hashing, optional two-factor authentication, row-level tenant isolation, and role-based access controls that limit who inside your company — and inside InvoiceFlow — can see what. Access to production systems by our staff is restricted to those who need it and is logged. We keep an audit trail of security-relevant actions within the platform.
We encourage you to use a strong, unique password and to enable two-factor authentication on your account.
9. Data breach notification
If a personal-data breach occurs that is likely to prejudice your privacy, confidentiality, or security, we will notify the UAE Data Office and affected users without undue delay, in line with the timeframes and content requirements of the PDPL and its Executive Regulations. Where InvoiceFlow acts as a processor for a tenant company, we will notify that company promptly so it can meet its own notification obligations.
10. Cookies and local storage
InvoiceFlow uses only the cookies and browser storage needed to run the application — keeping you signed in, remembering your selected tenant and interface preferences, and protecting against cross-site request forgery. We do not use advertising or cross-site tracking cookies. The Android app uses your device's own secure storage for the same purposes and, if you enable it, for a biometric-protected credential vault.
11. Children's privacy
InvoiceFlow is a business application intended for use by adults acting on behalf of a company. It is not directed at, and we do not knowingly collect personal data from, children.
12. Changes to this policy
We may update this policy from time to time, for example as InvoiceFlow adds new features or as regulations change. We will update the "Last updated" date above when we do, and material changes will be communicated to account administrators before they take effect.
13. Contact us
For questions about this policy or how your data is handled, or to exercise any of the rights above, contact us at security@invoiceflow.ae. For general enquiries, use info@invoiceflow.ae.