Last updated: 2026-07-01
This Privacy Policy explains how [Company Legal Name] ("we", "us") handles personal data in connection with the invoicing and billing application (the "Service").
For account and billing data we act as the data controller. For the data an organisation uploads about its own students/customers/teachers, that organisation is the controller and we act as its processor, handling that data on its instructions to provide the Service.
To provide and secure the Service, process payments, communicate with you about your account, comply with legal obligations, and improve reliability. We do not sell personal data.
We share data only with service providers who help us run the Service (for example hosting, email delivery and payment processing) under appropriate confidentiality obligations, and where required by law.
We keep personal data for as long as your account is active and as needed to meet legal, tax and accounting requirements, then delete or anonymise it.
We use technical and organisational measures including transport encryption (HTTPS), password hashing, per-tenant data isolation, and access controls. No method is perfectly secure, but we work to protect your data.
Subject to applicable law you may request access, correction, export or deletion of your personal data. Where we act as a processor for an organisation's uploaded data, direct such requests to that organisation.
Data may be processed in the countries where we and our providers operate. [Counsel to specify transfer mechanisms and hosting locations.]
We may update this Policy; the version identifier below will change on material updates.
Privacy questions: [privacy@yourcompany.example].
This is placeholder text. Legal bases for processing, data-subject-rights procedures, sub-processor lists, transfer mechanisms and any regional disclosures (GDPR/DPDP/CCPA, etc.) MUST be completed by legal counsel.