Data Processing Agreement
Last updated: 19 August 2026
When you send documents through NordInvoice, you decide what is processed and why; we process it on your instructions. This agreement records that relationship in the terms of Article 28 GDPR. It applies automatically to every account, together with the Terms of Service; a countersigned copy is available on request via [email protected].
1. Roles and scope
You (the account holder) are the controller of the personal data contained in the documents you submit. Nordreg (KvK 42137606, btw-id NL005526020B24), operating NordInvoice from the Utrecht region, the Netherlands, acts as processor: we validate, generate and deliver those documents on your documented instructions, which consist of your use of the dashboard, the API and this agreement.
For our own account data (your email address, billing records, audit logs) we are the controller; that processing is described in the Privacy Policy, not here.
2. What we process on your behalf
Invoice documents and their content: party names and addresses, identifiers such as VAT and KvK numbers, bank details, line items and amounts. Documents are processed in memory to answer your request and are then discarded; we retain only metadata: a cryptographic fingerprint, the profile used, the verdict and counts, file size, timestamps and delivery status.
When you use document extraction, the uploaded file is sent to our AI subprocessor to read the fields, the structured result is returned to your screen, and the file is discarded. Extraction inputs are not used to train any model.
Delivery over the Peppol network necessarily shares the document with the receiving access point and recipient you address; that transmission is the service itself.
3. Subprocessors
We use the following subprocessors for the document flow:
- Hetzner Online GmbH (Germany): hosting and storage. All servers are in the EU.
- Cloudflare, Inc.: network security and content delivery in front of the origin.
- Recommand BV (Belgium): certified Peppol access point through which documents are delivered and received.
- Resend, Inc.: transactional email, including email fallback delivery of documents when a receiver is not on the Peppol network.
- Anthropic, PBC: AI document extraction, only when you use the extraction feature.
- Payments are handled by Mollie B.V. as its own controller; we never see full payment details.
4. Confidentiality and security
All traffic is encrypted in transit (TLS). API keys are stored only as hashes. Invoice content is never written to disk or logs, deliberately: what we do not store cannot leak. Access to production systems is limited to the operator and protected by key-based authentication.
Persons authorised to process the data are bound by confidentiality. We assist you, insofar as reasonably possible, with data subject requests and with your own security obligations under Articles 32 to 36 GDPR.
5. Breach notification
We notify you of a personal data breach affecting your data without undue delay and at the latest within 72 hours of becoming aware of it, with the information required by Article 33 GDPR as it becomes available.
6. Subprocessor changes and audits
We may engage new subprocessors and will announce changes on this page at least 14 days before they take effect; if you object on reasonable data protection grounds, you may terminate the affected service. On request we provide the information reasonably necessary to demonstrate compliance with this agreement, up to and including an audit conducted at your cost with reasonable notice.
7. Retention and deletion
Document content is not retained at all. Metadata is retained while your account exists, because it is your usage and delivery history. When your account is deleted, remaining personal data is deleted or anonymised within 30 days, except where law requires longer retention of billing records.
8. Duration and law
This agreement applies as long as you have an account and ends with it. Dutch law governs, like the Terms of Service. The binding language is English.