← Back to InvoiceFlow

Privacy Policy

1. Who we are

InvoiceFlow ("InvoiceFlow", "we", "us", "our") is a multi-tenant e-invoicing and business access management platform for UAE businesses, available as a web application and an Android app. This policy explains what personal data we collect, why, how it is used, how long we keep it, and the rights you have under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the "PDPL").

If your company (a "tenant") uses InvoiceFlow, your company is the controller of the business data entered into the platform (customer and supplier records, invoices, credit and debit notes, and similar), and InvoiceFlow acts as a processor on your company's documented instructions. For the account and login data that identifies you as an individual user, and for operating and securing the platform itself, InvoiceFlow is the controller. Where InvoiceFlow acts as a processor, this policy is supplemented by the data-processing terms in our Terms & Conditions.

Questions about this policy, or any request relating to your personal data, can be sent to our data protection contact at security@invoiceflow.ae.

2. Data we collect

Subscription and billing is handled by Stripe. InvoiceFlow does not store your full card number — Stripe processes payment details directly under its own privacy policy.

3. How we use your data

We do not sell your personal data, and we do not use it for third-party advertising. InvoiceFlow does not currently use any third-party analytics or advertising tracking services.

We process personal data only where the PDPL permits it — principally:

4. Who we share data with

We share data only with the service providers that help us run InvoiceFlow, and only to the extent needed for that purpose:

We may also disclose data where required by law, such as in response to a valid request from the FTA or another UAE regulatory or judicial authority, or to establish, exercise, or defend a legal claim.

5. International data transfers

Our core application database and file storage are hosted on Oracle Cloud Infrastructure in the Dubai (UAE) region. Some of the service providers listed above process data on infrastructure located outside the UAE — for example, Stripe, Brevo, Anthropic, and Google (Firebase Cloud Messaging). Where personal data is transferred outside the UAE, we do so only in the circumstances the PDPL permits: to a jurisdiction the UAE recognises as providing an adequate level of protection, or, where no adequacy decision applies, under an appropriate safeguard such as contractual clauses that bind the recipient to protection standards equivalent to the PDPL, or with your explicit consent.

You can ask us for more detail on where a specific category of data is stored by contacting security@invoiceflow.ae.

6. Data retention

We retain your account and business data for as long as your company's InvoiceFlow subscription is active, and for a further period afterward as required for tax, legal, and audit purposes — UAE tax law generally requires invoice and accounting records to be retained for at least five years (longer for certain real-estate records). Audit log entries are retained on a configurable policy and purged automatically once that period elapses. An unverified sign-up that is never completed is discarded automatically. A source PDF uploaded for AI-assisted customer creation is not retained after the extraction result is returned.

When a retention period ends, or when we accept a valid deletion request, personal data is deleted or irreversibly anonymised.

7. Your rights under the PDPL

Subject to the conditions and exceptions in the PDPL, you have the right to:

You can review and update most of your account information directly within InvoiceFlow. For anything else, email security@invoiceflow.ae from the address associated with your account; we will verify your identity and respond within the period required by the PDPL. If the business data you are asking about was entered by a tenant company that uses InvoiceFlow, we will refer your request to that company as the controller.

If you believe we have not handled your personal data in line with the PDPL, you may lodge a complaint with the UAE Data Office (the federal supervisory authority for data protection). We would appreciate the chance to address your concern first.

8. Data security

We use appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS) between your device and our servers, encrypted database connections, password hashing, optional two-factor authentication, row-level tenant isolation, and role-based access controls that limit who inside your company — and inside InvoiceFlow — can see what. Access to production systems by our staff is restricted to those who need it and is logged. We keep an audit trail of security-relevant actions within the platform.

We encourage you to use a strong, unique password and to enable two-factor authentication on your account.

9. Data breach notification

If a personal-data breach occurs that is likely to prejudice your privacy, confidentiality, or security, we will notify the UAE Data Office and affected users without undue delay, in line with the timeframes and content requirements of the PDPL and its Executive Regulations. Where InvoiceFlow acts as a processor for a tenant company, we will notify that company promptly so it can meet its own notification obligations.

10. Cookies and local storage

InvoiceFlow uses only the cookies and browser storage needed to run the application — keeping you signed in, remembering your selected tenant and interface preferences, and protecting against cross-site request forgery. We do not use advertising or cross-site tracking cookies. The Android app uses your device's own secure storage for the same purposes and, if you enable it, for a biometric-protected credential vault.

11. Children's privacy

InvoiceFlow is a business application intended for use by adults acting on behalf of a company. It is not directed at, and we do not knowingly collect personal data from, children.

12. Changes to this policy

We may update this policy from time to time, for example as InvoiceFlow adds new features or as regulations change. We will update the "Last updated" date above when we do, and material changes will be communicated to account administrators before they take effect.

13. Contact us

For questions about this policy or how your data is handled, or to exercise any of the rights above, contact us at security@invoiceflow.ae. For general enquiries, use info@invoiceflow.ae.