XOWE Data Processing Addendum
Effective date: 31 August 2026 Last updated: 31 August 2026 (breach notification aligned to 72 hours, notice channels restated, audits scoped, postal address; the sub-processor contract wording restated later the same day)
This Data Processing Addendum ("DPA") forms part of the XOWE Terms of Use between TivForge LLC, a limited liability company registered in North Carolina, United States ("TivForge", "we", "Processor"), and the user of the XOWE app ("you", "Customer", "Controller").
It applies where, in using XOWE, you provide us with personal data about other people — your clients and their staff — and it governs how we process that data on your behalf. It takes effect automatically when you accept the Terms of Use and does not need to be signed.
Where this DPA conflicts with the Terms of Use on the processing of Customer Personal Data, this DPA prevails.
1. Definitions
"Data Protection Law" means, as applicable: Regulation (EU) 2016/679 ("GDPR"); the GDPR as incorporated into the law of the United Kingdom by the Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended ("CCPA"); and any other privacy law applicable to the processing.
"Customer Personal Data" means personal data contained in your content that we process on your behalf — principally the data described in Annex A.
"Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
"Controller", "processor", "sub-processor", "data subject", "processing" and "personal data breach" have the meanings given in the GDPR.
2. Roles
For Customer Personal Data, you are the controller and TivForge is the processor. You determine the purposes and means of processing; we process only as set out in this DPA.
For personal data about you as our user — your business profile, your subscription, your use of the app, your device — TivForge is the controller, and our Privacy Policy governs it, not this DPA.
For the payments your clients make, Stripe acts as an independent controller under its own agreement with you. TivForge is not a processor of card or bank data and never receives it.
Under the CCPA, TivForge is a service provider with respect to Customer Personal Data. We do not sell or share it, we do not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA, and we do not combine it with personal information received from other sources except as the CCPA allows.
3. Scope and instructions
We process Customer Personal Data only on your documented instructions, which consist of: this DPA, the Terms of Use, and the actions you take in the app — creating and syncing clients and documents, previewing or sending a document, sharing its link, enabling email reminders, creating a payment link, and deleting any of the above.
We will not process Customer Personal Data for our own purposes, will not sell it, and will not use it to train machine learning models or to build profiles.
If we are required by law to process Customer Personal Data beyond your instructions, we will inform you before doing so unless that law forbids it. If we believe an instruction infringes Data Protection Law, we will tell you.
Your obligations. You are responsible for the lawfulness of the data you enter: for having a legal basis to process your clients' personal data, for providing them with the information Articles 13 and 14 GDPR require — including that documents may be delivered as a link hosted by us and that reminder emails may be sent by us on your behalf — for the accuracy of what you enter, and for not entering into XOWE any special category data under Article 9 GDPR, data relating to criminal convictions, or personal data of children. XOWE is not designed for such data and you must not use it for it.
4. Confidentiality
We keep Customer Personal Data confidential. Access is limited to personnel who need it to provide or support the Service, and those personnel are bound by confidentiality obligations that survive the end of their engagement.
5. Security
We implement appropriate technical and organisational measures under Article 32 GDPR, described in Annex B. We may update them, provided the level of protection is not reduced.
6. Sub-processors
You give general authorisation for us to engage sub-processors. The sub-processors engaged as at the effective date are listed in Annex C.
Article 28(4) GDPR requires us to engage each sub-processor under a written contract imposing data protection obligations no less protective than those in this DPA, including the onward transfer terms required by Clause 8.8 of the SCCs. We remain fully liable to you for a sub-processor's performance. If you need the position for a particular sub-processor before relying on the Service for your own compliance — which contract is in place and what it covers — ask us at support@tivforge.com and we will tell you what we hold.
If we intend to add or replace a sub-processor, we will give you at least 30 days' notice
by publishing an updated Annex C at tivforge.com/xowe/dpa, dated at the top of this page,
and — where you have enabled notifications — by push notification to your device. Because the
Service has no accounts, we hold no email address for most Customers; if you want these notices
by email, send us an address at support@tivforge.com with the subject "Sub-processor
notices" and we will add it to that list and use it for nothing else. Whether or not you do,
this page is the authoritative record, and checking it is how you stay informed.
If you reasonably object on data protection grounds within those 30 days, tell us at support@tivforge.com and we will use reasonable efforts to offer an alternative. If we cannot, you may terminate by ceasing to use the Service and deleting your data, and we will refund any prepaid unused subscription fees for the remaining term where Apple's rules permit us to do so.
7. Data subject requests
XOWE gives you direct control over Customer Personal Data: you can view, correct, export as PDF and delete any client or document yourself, and delete all of it at once. That is normally sufficient to answer a data subject request without our involvement.
Where it is not, we will provide reasonable assistance, at your cost where the effort is more than trivial, to help you respond to requests for access, rectification, erasure, restriction, portability or objection.
If a data subject contacts us directly about Customer Personal Data, we will not respond substantively. We will tell them to contact you and, where we can identify you, forward the request to you.
8. Assistance
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 GDPR: security, breach notification, data protection impact assessments and prior consultation.
9. Personal data breach
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 72 hours of becoming aware, so that you can meet your own deadline under Article 33 GDPR. Where the full picture is not yet available we will send what we have and follow it with the rest as we establish it, rather than waiting.
Because the Service has no user accounts and we therefore hold no email address for most Customers, we will notify you by every means available to us: a notice published at tivforge.com/xowe/security, which is the authoritative record and is updated first; a push notification where you have enabled them; and email where we hold an address for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed.
Notifying you is not an admission of fault or liability. You are responsible for any notification to a supervisory authority or to data subjects that the law requires of you as controller.
10. Deletion and return
You can delete Customer Personal Data at any time in the app, individually or all at once. On deletion, the corresponding records are erased from our production database immediately. Residual copies may remain in encrypted database backups for up to 30 days, after which they are overwritten by the backup rotation. Backups are not accessed in the ordinary course and are restored only to recover the Service from a failure. If a restore reinstates data that had been deleted, we delete it again as soon as we become aware.
On termination of the Terms of Use, we will delete Customer Personal Data unless the law requires us to retain it. Because you can export every document as a PDF at any time, we provide no separate return mechanism, and we may delete the data without further notice once you have closed your installation.
Server request logs, which contain IP addresses and endpoint paths but no client contact details or document contents, are not keyed to an installation and are deleted on their own 90-day cycle.
11. Audits
On written request, and no more than once in any twelve months unless a supervisory authority or a personal data breach requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including our security documentation and, where we hold them, third party reports.
Where that is genuinely insufficient for your obligations under Article 28(3)(h) GDPR, we will first answer a reasonable written security questionnaire, once in any twelve months. If that too is genuinely insufficient, or where a supervisory authority requires it or a personal data breach affecting your data has occurred, you may conduct an audit through an independent auditor who is not our competitor and who is bound by confidentiality, on at least 30 days' written notice, during business hours, once in any twelve months, limited to the systems and documents relevant to the processing of your Customer Personal Data, without access to the data of any other Customer and without unreasonable disruption to our operations, and at your expense. An audit may not require us to breach a duty of confidentiality owed to anyone else, and remote inspection satisfies this section where it answers the question asked.
12. International transfers
TivForge processes Customer Personal Data in the United States.
Where the transfer of Customer Personal Data from the EEA to TivForge is subject to the GDPR, the Standard Contractual Clauses, Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer, with the following selections:
- Clause 7 (docking clause): applies.
- Clause 9 (sub-processors): Option 2, general written authorisation, with a notice period of 30 days, as set out in section 6.
- Clause 11 (redress): the optional independent dispute resolution paragraph does not apply.
- Clause 17 (governing law): the law of Ireland.
- Clause 18(b) (forum): the courts of Ireland.
- Annex I.A (parties): the Customer as data exporter and controller; TivForge LLC, 5144 Mabe Drive, Holly Springs, NC 27540, United States, support@tivforge.com, as data importer and processor.
- Annex I.B (description of transfer): as set out in Annex A of this DPA. The frequency of transfer is continuous, for the duration of the Terms of Use.
- Annex I.C (competent supervisory authority): the authority determined in accordance with Clause 13.
- Annex II (technical and organisational measures): as set out in Annex B of this DPA.
- Annex III (sub-processors): as set out in Annex C of this DPA.
Where the transfer is subject to the UK GDPR, the UK Addendum is incorporated and applies to the SCCs above. For its Table 4, the party that may end the Addendum under section 19 is the importer. Where the transfer is subject to the FADP, the SCCs apply with references to the GDPR read as references to the FADP, "member state" read as including Switzerland, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
If the SCCs are invalidated or replaced, the parties will apply the successor mechanism.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Use, except where Data Protection Law does not permit that limitation. Nothing in this DPA or in the Terms of Use limits or excludes either party's liability towards a data subject under Article 82 GDPR, under the third party beneficiary rights in the SCCs, or towards a supervisory authority.
14. Term
This DPA takes effect when you accept the Terms of Use and continues for as long as we process Customer Personal Data on your behalf. Sections 4, 9, 10, 12 and 13 survive its end.
Annex A — Description of the processing
Subject matter. Provision of the XOWE invoicing service to the Customer.
Duration. For as long as the Terms of Use are in force and Customer Personal Data remains in the Service.
Nature and purpose. Storing and synchronising the Customer's client records and documents; rendering invoices and estimates into PDF; hosting a link-accessed web page on which the recipient can view, download and pay a document; sending payment reminder emails to recipients where the Customer has enabled them; creating Stripe payment links; and providing support.
Categories of data subjects. The Customer's clients, and the individual contacts at those clients, to whom the Customer issues invoices or estimates.
Categories of personal data.
- Identity and contact data: name, company name, email address, phone number, postal address, website.
- Transaction data: the contents of invoices and estimates — line item descriptions, quantities, unit prices, billing units, tax rates, totals, currency, issue date, due date or validity date, document number and status.
- Delivery and engagement data: whether and when a document link was viewed, whether an invoice was paid, reminder emails scheduled and sent, and email delivery outcomes including bounce and spam complaint records.
Special category data. None. The Customer must not submit it (section 3).
Frequency. Continuous, as the Customer uses the Service.
Retention. Until the Customer deletes the data or deletes their installation; see section 10 and the Privacy Policy.
Annex B — Technical and organisational measures
- Encryption in transit. All traffic between the app, our servers and our sub-processors uses TLS. The public document page is served over HTTPS only.
- Access control. The Service has no user accounts; each installation authenticates with a random identifier and a secret held only on the device, stored server-side as a SHA-256 hash. Every database query for Customer Personal Data is scoped to the authenticating installation, so one Customer's data is not reachable with another's credentials.
- Document links. The public page for a document is reachable only with a high-entropy random token, valid for 180 days, invalidated when the document is re-sent or deleted, and excluded from search engine indexing.
- Administrative access. Production server and database access is restricted to authorised personnel over authenticated channels, using key-based authentication.
- Segregation of environments. Development and production run against separate databases and separate payment and analytics environments; production Customer Personal Data is not copied into development.
- Minimisation towards sub-processors. Analytics and crash reporting receive no Customer Personal Data — no client names, contact details, document contents or amounts. Card and bank details are collected by Stripe and never reach TivForge.
- Logging and monitoring. Requests are logged with a 90-day retention for fault investigation and abuse detection.
- Deletion. Deletion of a document, a client or an entire installation removes the records from the production database in a single transaction, with the installation identifier permanently retired so that it cannot be re-registered.
- Backups. Database backups are taken nightly and encrypted before they are written to disk, so no plaintext copy exists at any point. The decryption key is held by TivForge outside both the production server and the backup storage, and is used only for an actual restore. A copy is kept on the production server for a few days and pulled to storage owned and controlled by TivForge in the United States, where it is retained for 30 days and then deleted. Backups are used only to restore the Service after a failure. No third party holds them.
Annex C — Sub-processors
Sub-processors engaged in the processing of Customer Personal Data as at the effective date:
| Sub-processor | Function | Location |
|---|---|---|
| InMotion Hosting, Inc. | Server and database hosting | Ashburn, Virginia, USA |
| Resend, Inc. | Delivery of document and payment reminder emails to the Customer's clients | USA |
| Apple Inc. | Delivery of push notifications to the Customer's device | USA |
| Namecheap, Inc. (PrivateEmail) | Support mailbox, where a Customer includes client data in a support message | USA |
Not sub-processors of Customer Personal Data: Amplitude and Google (Firebase Crashlytics) receive no Customer Personal Data; Google's Places API receives only address text typed by the Customer, as an independent controller; RevenueCat receives only the installation identifier and Apple transaction data; Stripe acts as an independent controller under its own agreement with the Customer.
Contact
TivForge LLC 5144 Mabe Drive Holly Springs, NC 27540 United States support@tivforge.com