XOWE Data Processing Addendum

Effective date: 31 August 2026 Last updated: 31 August 2026 (breach notification aligned to 72 hours, notice channels restated, audits scoped, postal address; the sub-processor contract wording restated later the same day)

This Data Processing Addendum ("DPA") forms part of the XOWE Terms of Use between TivForge LLC, a limited liability company registered in North Carolina, United States ("TivForge", "we", "Processor"), and the user of the XOWE app ("you", "Customer", "Controller").

It applies where, in using XOWE, you provide us with personal data about other people — your clients and their staff — and it governs how we process that data on your behalf. It takes effect automatically when you accept the Terms of Use and does not need to be signed.

Where this DPA conflicts with the Terms of Use on the processing of Customer Personal Data, this DPA prevails.


1. Definitions

"Data Protection Law" means, as applicable: Regulation (EU) 2016/679 ("GDPR"); the GDPR as incorporated into the law of the United Kingdom by the Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended ("CCPA"); and any other privacy law applicable to the processing.

"Customer Personal Data" means personal data contained in your content that we process on your behalf — principally the data described in Annex A.

"Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.

"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

"Controller", "processor", "sub-processor", "data subject", "processing" and "personal data breach" have the meanings given in the GDPR.


2. Roles

For Customer Personal Data, you are the controller and TivForge is the processor. You determine the purposes and means of processing; we process only as set out in this DPA.

For personal data about you as our user — your business profile, your subscription, your use of the app, your device — TivForge is the controller, and our Privacy Policy governs it, not this DPA.

For the payments your clients make, Stripe acts as an independent controller under its own agreement with you. TivForge is not a processor of card or bank data and never receives it.

Under the CCPA, TivForge is a service provider with respect to Customer Personal Data. We do not sell or share it, we do not retain, use or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA, and we do not combine it with personal information received from other sources except as the CCPA allows.


3. Scope and instructions

We process Customer Personal Data only on your documented instructions, which consist of: this DPA, the Terms of Use, and the actions you take in the app — creating and syncing clients and documents, previewing or sending a document, sharing its link, enabling email reminders, creating a payment link, and deleting any of the above.

We will not process Customer Personal Data for our own purposes, will not sell it, and will not use it to train machine learning models or to build profiles.

If we are required by law to process Customer Personal Data beyond your instructions, we will inform you before doing so unless that law forbids it. If we believe an instruction infringes Data Protection Law, we will tell you.

Your obligations. You are responsible for the lawfulness of the data you enter: for having a legal basis to process your clients' personal data, for providing them with the information Articles 13 and 14 GDPR require — including that documents may be delivered as a link hosted by us and that reminder emails may be sent by us on your behalf — for the accuracy of what you enter, and for not entering into XOWE any special category data under Article 9 GDPR, data relating to criminal convictions, or personal data of children. XOWE is not designed for such data and you must not use it for it.


4. Confidentiality

We keep Customer Personal Data confidential. Access is limited to personnel who need it to provide or support the Service, and those personnel are bound by confidentiality obligations that survive the end of their engagement.


5. Security

We implement appropriate technical and organisational measures under Article 32 GDPR, described in Annex B. We may update them, provided the level of protection is not reduced.


6. Sub-processors

You give general authorisation for us to engage sub-processors. The sub-processors engaged as at the effective date are listed in Annex C.

Article 28(4) GDPR requires us to engage each sub-processor under a written contract imposing data protection obligations no less protective than those in this DPA, including the onward transfer terms required by Clause 8.8 of the SCCs. We remain fully liable to you for a sub-processor's performance. If you need the position for a particular sub-processor before relying on the Service for your own compliance — which contract is in place and what it covers — ask us at support@tivforge.com and we will tell you what we hold.

If we intend to add or replace a sub-processor, we will give you at least 30 days' notice by publishing an updated Annex C at tivforge.com/xowe/dpa, dated at the top of this page, and — where you have enabled notifications — by push notification to your device. Because the Service has no accounts, we hold no email address for most Customers; if you want these notices by email, send us an address at support@tivforge.com with the subject "Sub-processor notices" and we will add it to that list and use it for nothing else. Whether or not you do, this page is the authoritative record, and checking it is how you stay informed.

If you reasonably object on data protection grounds within those 30 days, tell us at support@tivforge.com and we will use reasonable efforts to offer an alternative. If we cannot, you may terminate by ceasing to use the Service and deleting your data, and we will refund any prepaid unused subscription fees for the remaining term where Apple's rules permit us to do so.


7. Data subject requests

XOWE gives you direct control over Customer Personal Data: you can view, correct, export as PDF and delete any client or document yourself, and delete all of it at once. That is normally sufficient to answer a data subject request without our involvement.

Where it is not, we will provide reasonable assistance, at your cost where the effort is more than trivial, to help you respond to requests for access, rectification, erasure, restriction, portability or objection.

If a data subject contacts us directly about Customer Personal Data, we will not respond substantively. We will tell them to contact you and, where we can identify you, forward the request to you.


8. Assistance

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 GDPR: security, breach notification, data protection impact assessments and prior consultation.


9. Personal data breach

If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and in any event within 72 hours of becoming aware, so that you can meet your own deadline under Article 33 GDPR. Where the full picture is not yet available we will send what we have and follow it with the rest as we establish it, rather than waiting.

Because the Service has no user accounts and we therefore hold no email address for most Customers, we will notify you by every means available to us: a notice published at tivforge.com/xowe/security, which is the authoritative record and is updated first; a push notification where you have enabled them; and email where we hold an address for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed.

Notifying you is not an admission of fault or liability. You are responsible for any notification to a supervisory authority or to data subjects that the law requires of you as controller.


10. Deletion and return

You can delete Customer Personal Data at any time in the app, individually or all at once. On deletion, the corresponding records are erased from our production database immediately. Residual copies may remain in encrypted database backups for up to 30 days, after which they are overwritten by the backup rotation. Backups are not accessed in the ordinary course and are restored only to recover the Service from a failure. If a restore reinstates data that had been deleted, we delete it again as soon as we become aware.

On termination of the Terms of Use, we will delete Customer Personal Data unless the law requires us to retain it. Because you can export every document as a PDF at any time, we provide no separate return mechanism, and we may delete the data without further notice once you have closed your installation.

Server request logs, which contain IP addresses and endpoint paths but no client contact details or document contents, are not keyed to an installation and are deleted on their own 90-day cycle.


11. Audits

On written request, and no more than once in any twelve months unless a supervisory authority or a personal data breach requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including our security documentation and, where we hold them, third party reports.

Where that is genuinely insufficient for your obligations under Article 28(3)(h) GDPR, we will first answer a reasonable written security questionnaire, once in any twelve months. If that too is genuinely insufficient, or where a supervisory authority requires it or a personal data breach affecting your data has occurred, you may conduct an audit through an independent auditor who is not our competitor and who is bound by confidentiality, on at least 30 days' written notice, during business hours, once in any twelve months, limited to the systems and documents relevant to the processing of your Customer Personal Data, without access to the data of any other Customer and without unreasonable disruption to our operations, and at your expense. An audit may not require us to breach a duty of confidentiality owed to anyone else, and remote inspection satisfies this section where it answers the question asked.


12. International transfers

TivForge processes Customer Personal Data in the United States.

Where the transfer of Customer Personal Data from the EEA to TivForge is subject to the GDPR, the Standard Contractual Clauses, Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer, with the following selections:

Where the transfer is subject to the UK GDPR, the UK Addendum is incorporated and applies to the SCCs above. For its Table 4, the party that may end the Addendum under section 19 is the importer. Where the transfer is subject to the FADP, the SCCs apply with references to the GDPR read as references to the FADP, "member state" read as including Switzerland, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.

If the SCCs are invalidated or replaced, the parties will apply the successor mechanism.


13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Use, except where Data Protection Law does not permit that limitation. Nothing in this DPA or in the Terms of Use limits or excludes either party's liability towards a data subject under Article 82 GDPR, under the third party beneficiary rights in the SCCs, or towards a supervisory authority.


14. Term

This DPA takes effect when you accept the Terms of Use and continues for as long as we process Customer Personal Data on your behalf. Sections 4, 9, 10, 12 and 13 survive its end.


Annex A — Description of the processing

Subject matter. Provision of the XOWE invoicing service to the Customer.

Duration. For as long as the Terms of Use are in force and Customer Personal Data remains in the Service.

Nature and purpose. Storing and synchronising the Customer's client records and documents; rendering invoices and estimates into PDF; hosting a link-accessed web page on which the recipient can view, download and pay a document; sending payment reminder emails to recipients where the Customer has enabled them; creating Stripe payment links; and providing support.

Categories of data subjects. The Customer's clients, and the individual contacts at those clients, to whom the Customer issues invoices or estimates.

Categories of personal data.

Special category data. None. The Customer must not submit it (section 3).

Frequency. Continuous, as the Customer uses the Service.

Retention. Until the Customer deletes the data or deletes their installation; see section 10 and the Privacy Policy.


Annex B — Technical and organisational measures


Annex C — Sub-processors

Sub-processors engaged in the processing of Customer Personal Data as at the effective date:

Sub-processor Function Location
InMotion Hosting, Inc. Server and database hosting Ashburn, Virginia, USA
Resend, Inc. Delivery of document and payment reminder emails to the Customer's clients USA
Apple Inc. Delivery of push notifications to the Customer's device USA
Namecheap, Inc. (PrivateEmail) Support mailbox, where a Customer includes client data in a support message USA

Not sub-processors of Customer Personal Data: Amplitude and Google (Firebase Crashlytics) receive no Customer Personal Data; Google's Places API receives only address text typed by the Customer, as an independent controller; RevenueCat receives only the installation identifier and Apple transaction data; Stripe acts as an independent controller under its own agreement with the Customer.


Contact

TivForge LLC 5144 Mabe Drive Holly Springs, NC 27540 United States support@tivforge.com