Data Processing Addendum
Poslednje ažuriranje: 22 July 2026
This Data Processing Addendum ("DPA") forms part of the LingvaBill Terms of Service between your business (the "Customer") and Prav Development Ltd, trading as LingvaBill, company no. 17313021, registered office 124 City Road, London, EC1V 2NX, United Kingdom ("LingvaBill"). It applies automatically, without signature, whenever LingvaBill processes personal data on the Customer's behalf. If this DPA and the Terms conflict on data-protection matters, this DPA prevails. "UK GDPR" means the UK General Data Protection Regulation and the Data Protection Act 2018.
1. Roles and scope
For the personal data the Customer enters into the service about its own clients and contacts (the "Customer Data"), the Customer is the controller and LingvaBill is the processor. For the Customer's own account data (its users' names, emails and business details), LingvaBill is an independent controller as described in the Privacy Policy; that processing is outside this DPA.
2. Details of processing
- Subject matter and duration: processing of Customer Data to provide the LingvaBill invoicing service, for the duration of the Customer's use of the service plus the retention period in clause 9.
- Nature and purpose: storing and processing the Customer's business data and its clients' data to create, store, translate on the Customer's request, deliver and take payment for invoices, quotes and credit notes.
- Types of personal data: the Customer's clients' names, addresses, contact details, and the content of invoice, quote and credit-note documents (including line-item text).
- Categories of data subjects: the Customer's clients and their staff, and the Customer's own users.
3. Processing on instructions only
LingvaBill processes Customer Data only on the Customer's documented instructions - namely the Terms, this DPA, and the Customer's use of the product's features (for example, tapping "Translate to English" is the instruction to translate that line-item text) - unless required to do otherwise by UK law, in which case LingvaBill will inform the Customer before processing unless the law prohibits it. Customer Data is never used to train AI models and is never used for advertising.
4. Confidentiality
LingvaBill ensures that every person it authorises to process Customer Data (its personnel and contractors) is committed to confidentiality, and that access is limited to what is needed to provide and support the service.
5. Security
LingvaBill implements and maintains appropriate technical and organisational measures for the risk, including: encryption in transit (HTTPS/TLS); a separate, isolated database per Customer; least-privilege database accounts separated by function (application, background worker, provisioning, backup); administrative access protected by two-factor authentication; daily backups with a defined retention and purge cycle; rate limiting and anti-abuse controls on public endpoints. These measures are reviewed and improved over time. LingvaBill does not currently claim third-party certifications (such as ISO 27001 or SOC 2) and this DPA does not represent that it holds any.
6. Sub-processors
The Customer gives general written authorisation for the sub-processors below. Each is bound by data-protection obligations equivalent to this DPA through its own data-processing terms, and LingvaBill remains fully liable to the Customer for their performance.
- Hetzner Online GmbH (Germany, EU) - hosting and infrastructure; all Customer Data at rest.
- Stripe (USA/international) - subscription billing and, where the Customer enables it, card payments on the Customer's invoices; payer and transaction data. Card data is handled by Stripe and never seen or stored by LingvaBill.
- Brevo (France, EU) - transactional email; recipient names and email addresses.
- Anthropic (USA) - AI translation; only the line-item text the Customer chooses to translate. Not used to train models. Translations are cached keyed by the source text alone, with nothing identifying the Customer or its clients; cached entries are therefore not linked to any account and are not removed on account deletion.
Changes: LingvaBill maintains the current list on this page and will give notice of intended additions or replacements by updating this page at least 14 days in advance (and by email for material changes). The Customer may object on reasonable data-protection grounds within that period, in which case the parties will discuss the concern in good faith; if it cannot be resolved, the Customer may close its account under the Terms.
Cloudflare Turnstile (contact-form anti-spam) and Google Analytics (public website, consent-gated) process website-visitor data only, never Customer Data, and are therefore not sub-processors under this DPA.
7. International transfers
Customer Data is hosted in the EU (Hetzner, Germany), covered for UK-to-EEA transfers by the UK's adequacy regulations. Where a sub-processor processes personal data outside the UK/EEA (Stripe, Anthropic), the transfer is safeguarded by that provider's data-processing terms incorporating the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, and, where the provider is certified under the UK Extension to the EU-US Data Privacy Framework, by that adequacy mechanism.
8. Assistance
Taking into account the nature of the processing, LingvaBill assists the Customer in meeting its own obligations: the product's self-service tools are the primary mechanism (the Customer can view, correct and delete its clients' records at any time, and export all Customer Data from My data), and LingvaBill provides reasonable further assistance with data-subject requests, security, breach notification, data-protection impact assessments and prior consultation on request. LingvaBill will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, with enough information for the Customer to meet its own notification duties.
9. End of the relationship: return and deletion
The Customer can export all Customer Data at any time from My data (this is the "return" of the data). On account deletion, LingvaBill deletes Customer Data after the 7-day grace period, except issued invoices and credit notes, which UK law requires to be retained as business records: these are kept locked and beyond use for 6 years from the end of the relevant accounting period, then permanently deleted. Backups are excluded from restoration and purged on their normal cycle. The full process is described in the Privacy Policy and the Terms.
10. Audit
LingvaBill will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow and contribute to audits by the Customer or its appointed auditor, subject to reasonable notice, not more than once in any 12-month period absent a specific documented concern, during business hours, and without access to other customers' data. Written responses and existing documentation satisfy an audit request where they reasonably can.
11. General
This DPA is governed by the law of England and Wales, like the Terms. LingvaBill may update this DPA as the service or the law changes; material changes are notified in the same way as changes to the Terms. Prior versions are available on request.