Data Processing Agreement
Last updated: October 2, 2026
This Data Processing Agreement applies automatically to every Incusia customer. You do not need to sign it. It covers personal data about your own clients that you upload to Incusia. If you want a counter-signed copy, email me@abassinvoice.com and we will send one.
You are the controller of that client data. Incusia is the processor. Incusia is the controller of your account data, which is described in the Privacy Policy and is not the subject of this agreement.
What is processed
The subject matter is the invoicing service you use. Processing lasts while your account is open, and afterwards only for the issued invoices the Privacy Policy says are kept under the Norwegian Bookkeeping Act.
The nature and purpose are storing and showing the records you create, sending the emails you ask the product to send, and taking payment through Stripe when you enable it.
The data subjects are your clients, and the people named on invoices, estimates, expenses, and time entries.
The personal data is:
- Client name, email, company, postal address, and phone, when you enter them.
- Invoice and estimate contents, including amounts, notes, and payment status.
- Time entry descriptions and expense details, including receipt files you upload.
What Incusia will do
As processor under GDPR Article 28, Incusia will:
- Process client data only on your documented instructions. Using the product, and this agreement, are those instructions. If a law requires something else, we will tell you unless the law forbids it.
- Make sure people who can see production data are bound to confidentiality. Today that is the founder.
- Use the security measures described below.
- Help you answer a data subject request, using the export in Settings and by email when you ask.
- Tell you about a personal data breach without undue delay and within 72 hours of becoming aware of it, and help you with the notices you have to give.
- Delete or return client data when the account ends, except the issued invoice records the Privacy Policy keeps for bookkeeping, and delete those when their retention date passes.
- Make available the information in this agreement and the sub-processor list so you can show what processing looks like. You can ask for a written description of the security measures. We do not offer an on-site audit program beyond that.
Sub-processors
You authorise the sub-processors on the sub-processor page. That page says how a material change is communicated. We remain responsible for their processing of client data under this agreement.
Security measures
- TLS for traffic to incusia.com. HTTP redirects to HTTPS, and the production response includes Strict-Transport-Security.
- Row level security in the database, so a signed-in user is limited to rows with their own user id.
- Access to production is limited to the founder.
- Card numbers are collected by Stripe, not stored on Incusia servers.
- Encryption at rest is what Supabase states for its platform. We have not confirmed that control inside this project's dashboard, so this agreement does not claim we inspected it.
Ending the account
When you delete the account, client records, drafts, files, and the login are deleted then. Issued invoices are retained until 31 December of the year five years after the invoice date, then deleted by a monthly job. A copy of what you can still download before you delete is in Settings, on every plan.
Governing law
This agreement is governed by the laws of Norway. Disputes go to the Norwegian courts. That does not remove a data subject's right to complain to Datatilsynet.
Any questions? Send an email to me@abassinvoice.com and I will get back to you within 24 hours.