Skip to content

Data Processing Agreement

Last updated: August 22, 2026

This Data Processing Agreement ("DPA") forms part of our Terms of Service and applies automatically, without a separate signature, whenever you use Billebly to process personal data about your own clients. It's between you (the "Controller") and Netonic, the company behind Billebly (the "Processor", "we", "us"). Our registered office address and company registration details are available on request by emailing support@billebly.com.

If your organization needs a countersigned copy for its own records, email support@billebly.com and we'll arrange one, since the terms are the same either way.

1. Subject matter and duration

We process personal data on your behalf for as long as you have a Billebly account, solely to provide the Service to you: building and sending invoices, tracking time against your projects, and processing payments through Stripe. Processing ends when your account is deleted, subject to the retention periods in our Privacy Policy.

2. Nature and purpose of processing

Storing, displaying, and transmitting the client and invoice data you enter; generating and emailing invoices, receipts, and reminders on your behalf; and passing the payment amount and your client's checkout details through to Stripe so they can pay you. We only process this data on your documented instructions, given by using the Service the way it's designed to work, and never for our own independent purposes.

3. Categories of data subjects and personal data

  • Data subjects: your clients, and their own contacts (e.g. a named contact person at a client company).
  • Personal data: name, email, phone, billing address, VAT/registration number, and the invoice, project, and time-tracking details you record about them. We never receive card numbers or bank details directly. Those go straight to Stripe.

4. Sub-processors

You authorize us to engage the following sub-processors to help provide the Service:

Sub-processorPurposeLocation
Stripe, Inc.Payment processing, identity verification (KYC), and payoutsEU / US
ResendTransactional email delivery (invoices, receipts, reminders)EU / US
SentryError monitoringEU / US
Our hosting providerApplication, database, and backup hostingEU

Stripe processes identity-verification (KYC) data about your own business directly, acting as your own connected account holder rather than as our sub-processor for your clients' data, under Stripe's own Data Processing Agreement. We'll update this list and give you reasonable notice (e.g. by email or in-app) before adding a new sub-processor that would materially change how your clients' data is handled; if you object on reasonable data-protection grounds, contact us to work through it.

5. Security measures

HTTPS everywhere, encrypted two-factor authentication secrets and recovery codes, access controls limiting who can reach production data, and error monitoring via Sentry to catch problems quickly. Full detail is in our Privacy Policy.

6. Assistance with data subject requests

If one of your clients contacts us directly about their own rights (access, correction, deletion), we'll point them to you as the controller and, where appropriate, notify you. We'll give you reasonable assistance in responding to a request you receive from your own client, to the extent our systems can support it, including through the self-service export and deletion tools already available in your account.

7. Data breach notification

If we become aware of a breach affecting personal data we process on your behalf, we'll notify you without undue delay, and in any event within the timeframe needed for you to meet your own legal obligations, with what we know about the breach's nature and likely impact at the time.

8. Deletion or return of data

When your account is deleted, we delete the personal data we hold on your behalf following the 30-day grace period described in our Privacy Policy, except where we're required to keep specific records longer by law (for example, tax/bookkeeping retention). You can export your data yourself at any time before deletion using the export tools in Settings.

9. Audits

We'll make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice and no more than once a year (or more often if required by a supervisory authority). For a SaaS product at our current scale, this is usually satisfied by us answering a security questionnaire rather than an on-site audit, but we won't refuse a reasonable request.

10. International transfers

Where a sub-processor transfers personal data outside the EU/EEA, it does so under a recognized safeguard, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses. See our Privacy Policy for specifics on Stripe and Google.

11. Liability

Liability under this DPA is subject to the limitation of liability in our Terms of Service.

12. Contact

Questions about this DPA, or a request for a countersigned copy, can be sent to support@billebly.com.