Overview & our commitment
The General Data Protection Regulation (GDPR) is the European Union law that governs how personal data is collected, used, and protected. If you are located in the EU or the European Economic Area (EEA), or if we process personal data about people in those regions on your behalf, this page explains our approach.
EZY Invoice is an invoicing and accounting product built for small businesses. When you use it, you are typically the data controller for your customers' and vendors' details, and EZY Invoice acts as a data processor handling that information on your instructions. For your own account data — your login, billing, and contact details — we act as the controller.
This page is an illustrative, plain-English template and is not a substitute for legal advice. If GDPR compliance is critical to your business, please review it with your own counsel.
Lawful basis for processing
GDPR requires a valid lawful basis before personal data is processed. Depending on the activity, we rely on one or more of the following:
- Contract — to provide the service you signed up for, including creating invoices, quotes, and reports.
- Legitimate interests — to keep the platform secure, prevent fraud and abuse, and improve the product, balanced against your rights.
- Legal obligation — to meet tax, accounting, and record-keeping requirements that apply to us.
- Consent — where we ask for it explicitly, such as optional marketing communications. You can withdraw consent at any time.
Your rights under GDPR
If you are in the EU or EEA, you have a set of rights over your personal data. We will honour these requests within the timeframes the law allows:
- Right of access — request a copy of the personal data we hold about you and information about how it is used.
- Right to rectification — ask us to correct data that is inaccurate or incomplete.
- Right to erasure — ask us to delete your personal data where there is no lawful reason to keep it (the "right to be forgotten").
- Right to restriction — ask us to pause processing of your data in certain circumstances while a concern is resolved.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another provider where technically feasible.
- Right to object — object to processing based on legitimate interests, and opt out of direct marketing at any time.
You also have the right to lodge a complaint with your local supervisory authority if you believe your data has been mishandled.
Data subject requests
To exercise any of the rights above, get in touch through our contact page. Please tell us which right you want to exercise and include enough detail for us to locate your records. We may need to verify your identity before acting, to protect your data from unauthorised disclosure.
We aim to respond to valid requests within 30 days. If a request is unusually complex or you have made several, we may extend this by up to two further months and will let you know if that happens. There is normally no charge to make a request.
If you are an end customer or vendor of one of our users — rather than an account holder yourself — please direct your request to the business that issued you an invoice, as they are the controller of that data. We will support them in responding.
International data transfers
EZY Invoice is operated from Australia, and some of our infrastructure and sub-processors may be located outside the EEA. Where personal data is transferred internationally, we put appropriate safeguards in place, such as Standard Contractual Clauses approved by the European Commission, so that your data continues to receive an equivalent level of protection.
We only transfer data where it is necessary to deliver the service, and we keep the number of locations involved as small as practical.
Data processing & sub-processors
When EZY Invoice acts as your processor, we only process personal data on your documented instructions and for the purposes of delivering the service. We commit to:
- applying appropriate technical and organisational security measures;
- ensuring that staff with access to data are bound by confidentiality;
- assisting you in responding to data subject requests where the data sits in our systems;
- notifying you without undue delay if we become aware of a personal data breach affecting your data; and
- deleting or returning personal data at the end of our engagement, subject to any retention obligations.
We use a limited set of trusted sub-processors for hosting, email delivery, payment processing, and similar functions. Each is contractually required to meet data-protection standards consistent with this commitment. A current list is available on request through our contact page.
Data retention
We keep personal data only for as long as it is needed to provide the service, meet legal and accounting obligations, and resolve disputes. Invoicing records in particular may need to be retained for several years to satisfy tax requirements. When data is no longer required, we delete it or anonymise it.
For a fuller breakdown of what we collect, why, and how long we keep it, see our Privacy Policy.
Contact & DPO
If you have questions about this page, want to exercise a right, or wish to raise a data-protection concern, please reach out via our contact page and mark your message for the attention of our data protection contact.
We treat every enquiry seriously and will do our best to resolve it quickly and openly. You can also review our security practices to understand how we protect the data in our care.