Xenyth Labs Xenyth Invoice

Privacy Policy and Data Retention Statement

Xenyth Invoice

Xenyth Labs Ltd Company number: 17323486 6 Great Lane, Melton Mowbray, LE14 2PB, United Kingdom

ICO registration number: [to be added]

Last updated: [date] Version: 1.0


DRAFT — NOT YET REVIEWED BY A SOLICITOR. This document describes how Xenyth Invoice actually handles data and is intended as a starting point for legal review. Remove this notice before publishing.


1. Who we are

Xenyth Invoice is an online invoicing service for sole traders and small businesses, operated by Xenyth Labs Ltd ("we", "us", "our"). The service is available at https://invoice.xenythlabs.co.uk.

This policy explains what personal data we hold, why we hold it, how long we keep it, and what rights you have.

2. Two different roles

It matters which data we are talking about, because our legal role differs.

Your account data — we are the controller. This is the information you give us to use the service: your email address, your password, and your business details.

Your customers' data — we are the processor. When you add a customer or create an invoice, you decide what information to collect and why. We store and process it on your instruction. You are the controller of that data; we act on your behalf.

This distinction affects who your customers should contact about their data. If one of your customers asks you to delete their information, that request is yours to answer, not ours. We will help you act on it.

A separate Data Processing Agreement sets out our obligations to you as a processor.

3. What we hold

Your account

  • Email address (used to log in and to contact you about your account)
  • Password, stored only as a salted hash — we never store or see your actual password
  • Account creation date
  • Whether your account is active, and any deletion dates if you have closed it

Your business settings

  • Trading name and legal name
  • Business email address, phone number, and postal address
  • VAT registration number, if you provide one
  • Bank account name, sort code, and account number, if you provide them
  • Your business logo, if you upload one

Bank details and VAT numbers are stored so they can appear on the invoices you send. We do not use them to take payments and we do not have access to your bank account.

Your customers and invoices

  • Customer names, company names, email addresses, phone numbers, postal addresses, and VAT numbers, as entered by you
  • Invoices, including invoice numbers, dates, payment terms, line item descriptions, quantities, prices, VAT, and totals

What we do not collect

  • We do not use analytics, tracking pixels, advertising cookies, or any third-party tracking of any kind
  • We do not sell, rent, or share your data with anyone for marketing
  • We do not profile you or make automated decisions about you

4. Cookies

We use one cookie: a session cookie that keeps you logged in. It is strictly necessary for the service to function and is not used for tracking or analytics.

If you tick "Remember me" when logging in, a second cookie keeps you signed in between visits. Both are removed when you log out.

5. Why we are allowed to hold this data

Under UK GDPR we rely on:

  • Performance of a contract — we need your account and business details to provide the service you have signed up for
  • Legal obligation — we may need to retain certain records to meet our own tax and accounting duties
  • Legitimate interests — keeping the service secure, preventing abuse, and maintaining logs of significant account actions

6. Who else processes your data

We use a small number of service providers. Each processes data only as needed to run the service.

Provider Purpose Location
Render Application hosting and database Frankfurt, Germany (EU)
Twilio SendGrid Sending invoices and account emails United States
Cloudflare R2 Storing business logos Distributed

Because our database is hosted in Frankfurt, your data is stored in the European Union. Transfers to providers outside the UK and EU are covered by those providers' standard contractual clauses and equivalent safeguards.

We will update this list before adding any new provider. [When Stripe is added for billing, add it here.]

7. How long we keep things

While your account is open, we keep your data for as long as you continue to use the service. Your invoices and customers remain available to you indefinitely — we do not delete old records on your behalf, because you may need them.

If you close your account, this is what happens:

  1. Your account is closed immediately and you are logged out. You can no longer sign in normally.
  2. Your data is retained for 30 days. During this period you can restore everything by logging in again.
  3. After 30 days, your account and all associated data — invoices, line items, customers, business settings, and your uploaded logo — are permanently deleted.

We email you when your account is closed, confirming the date after which recovery is no longer possible.

Before you close your account, you can download everything we hold: a PDF of every invoice, plus spreadsheets of your invoices, line items, customers, and business settings. We encourage you to do this. As a UK business you may be required to keep your financial records for six years, and once your data is deleted we cannot recover it.

Backups. Our database is backed up automatically. Deleted data may persist in backups for a short period after deletion. During that time it is not accessible in the live service and is not used for any purpose. It is overwritten in the normal backup cycle. [Confirm Render's backup retention window and state it here.]

Logs. We keep application logs recording significant events such as account creation, closure, and errors. These may contain account identifiers and are retained for a limited period for security and troubleshooting.

8. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify anything inaccurate — most of this you can edit yourself in the app
  • Erase your data, which you can do yourself using the account deletion feature in Settings
  • Port your data — use the export feature in Settings to download everything in open formats (PDF and CSV)
  • Restrict or object to our processing in certain circumstances
  • Withdraw consent where we rely on it

Most of these you can exercise directly in the app without contacting us. For anything else, email us at [support address]. We will respond within one month.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk, or by calling 0303 123 1113.

9. How we protect your data

  • All traffic is encrypted in transit using HTTPS
  • Passwords are stored as salted hashes and are never recoverable
  • Each account's data is isolated — one user cannot access another's records
  • Forms are protected against cross-site request forgery
  • Login and registration are rate limited to resist automated attacks
  • Uploaded files are checked to confirm they are genuinely images

No system is perfectly secure, but we take these measures seriously and review them as the service grows.

10. Children

Xenyth Invoice is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.

11. Changes to this policy

If we change this policy we will update the version number and date above. For significant changes affecting your rights, we will email you.

12. Contact

Xenyth Labs Ltd 6 Great Lane, Melton Mowbray, LE14 2PB, United Kingdom [support email address]