Last updated: 29 September 2026
Version 1, an annex to the Essentio Terms of Service.
This agreement is between the business that uses Essentio (the Business, the controller) and CPV Corporate Services Ltd, HE 252516, 23, 28th October str., 3rd floor, Engomi, 2414 Nicosia, Cyprus (Essentio, the processor). It forms part of the Essentio Terms of Service and is accepted with them. It meets Article 28 of the GDPR (Regulation (EU) 2016/679), and follows the structure of the European Commission's standard contractual clauses under Article 28(7) (Implementing Decision (EU) 2021/915), with general written authorisation of sub-processors.
It covers the personal data the Business, its team and the software it connects put into Essentio, and that Essentio processes to provide the service to the Business (the Business Data). Annex I describes that processing.
Where this agreement and the Terms of Service differ on personal data, this agreement wins. Terms defined in the GDPR have the same meaning here.
Instructions. Essentio processes Business Data only on the Business's documented instructions, including on transfers to third countries, unless EU or Member State law requires otherwise; in that case Essentio tells the Business first, unless that law forbids it. The Terms of Service, this agreement, and what the Business's team and connected software do in Essentio (creating, issuing, sending, exporting and deleting) are the Business's complete instructions. Essentio tells the Business immediately if it believes an instruction breaks data protection law.
Purpose. Essentio uses Business Data only to provide, secure and support the service. It does not sell it, use it for advertising, or use it to train AI models.
Confidentiality. Only staff who need Business Data for their work can reach it, and each is bound to confidentiality. Staff read a Business's Clients, documents or payments only with the Owner's Support access (read-only, 24 hours at most, each use logged), or where needed to answer a security incident, a report under the Terms of Service or a legal obligation.
Security. Essentio applies the measures in Annex II, which meet Article 32 of the GDPR, and reviews them at least once a year. It may improve them, but not reduce the overall level of protection.
Data subjects' rights. Essentio lets the Business answer requests itself: it can view, correct, export and delete Business Data in Essentio. If a data subject writes to Essentio directly, Essentio passes the request to the Business without undue delay and does not answer it alone.
Help with compliance. Taking into account what it knows, Essentio helps the Business with security, breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 of the GDPR), for example by answering questions and sharing the information in this agreement.
Records and audits. Essentio keeps the records Article 30(2) requires. It makes available the information needed to show it meets this agreement: on request, it answers written questions and shares its security documentation within 30 days. Where that is not enough, or a supervisory authority requires it, the Business may audit Essentio, or have an independent auditor bound by confidentiality do so, once a year with 30 days' notice, during business hours and at its own cost.
General authorisation. The Business authorises Essentio to use the sub-processors listed in Annex III.
Notice of changes. At least 30 days before adding or replacing a sub-processor, Essentio emails the Owner of every Business, naming the sub-processor, what it will do, the data it will receive and where. The list at essentio.pro/subprocessors is updated at the same time.
Objection. The Business may object on reasonable data protection grounds by replying to that email within 14 days. Essentio will then try, in good faith, to address the objection, for example by not using the sub-processor for that Business. If it cannot within the remaining notice period, the Business may end the Terms of Service before the change applies and receive a refund of the unused prepaid period. A Business that does not object within 14 days authorises the change.
Flow-down. Essentio binds each sub-processor by a written contract to data protection obligations no less protective than this agreement, in particular on security, and remains fully liable to the Business for each sub-processor's performance.
Recipients the Business chooses. Some recipients receive Business Data only because the Business, its team or its software instructs Essentio to send it there. They are not Essentio's sub-processors; they act under the Business's own relationship with them:
Transfers. Business Data is stored in Germany. Essentio transfers it outside the EEA only on the Business's instructions and under Chapter V of the GDPR: to a country with an EU adequacy decision, to a company certified under the EU–US Data Privacy Framework, or under the EU standard contractual clauses (Implementing Decision (EU) 2021/914). Annex III gives the basis for each sub-processor.
Personal data breaches. Essentio notifies the Owner by email without undue delay, and in any case within 48 hours of becoming aware of a breach affecting Business Data. The notice describes, as far as then known, what happened, the categories and approximate number of people and records concerned, the likely consequences, the measures taken or proposed, and a contact point; further information follows as it becomes available. Notifying a breach is not an admission of fault.
Deletion and return. The Business can export its data at any time (Terms of Service, section 8). When the Business, or the Owner's account, is deleted, Business Data stays retrievable for 30 days, then Essentio erases it and it leaves the backups within 8 weeks, unless EU or Member State law requires Essentio to keep it. Essentio confirms the erasure on request.
Where Essentio is a controller. Essentio is an independent controller, under its Privacy Policy, for the data it processes for its own purposes: team members' accounts, billing and the Owner's plan, security and fraud prevention, the log of its staff's actions, and anonymous, aggregated statistics about how Essentio is used.
Changes to this agreement. Essentio notifies the Owner of any change by email at least 30 days before it applies, and asks the Owner to approve it in Essentio. A Business that does not approve may end the Terms of Service before the change applies, with a refund of the unused prepaid period. Changes required by law may apply sooner.
Liability and law. Each party's liability under this agreement is subject to the limits in the Terms of Service, except where the GDPR does not allow a limit. This agreement is governed by the laws of the Republic of Cyprus, and the courts of Nicosia have jurisdiction. The competent supervisory authority for Essentio is the Office of the Commissioner for Personal Data Protection, Cyprus.
| Controller | The Business that accepted the Terms of Service; contact: its Owner's email address |
| Processor | CPV Corporate Services Ltd; contact: support@essentio.pro |
| Subject matter | Providing the Essentio invoicing service to the Business |
| Duration | For as long as the Business uses Essentio, then 30 days for retrieval and up to 8 weeks until erased from backups |
| Nature of processing | Storing, organising, computing, displaying, rendering as PDF and XML, sending by email and web link, exporting, and deleting data, as the Business directs through Essentio and its API |
| Purpose | Letting the Business create, issue, send and keep its commercial documents and payment records |
| Data subjects | The Business's Clients who are natural persons (such as sole traders and private customers) and the contact people of Clients that are companies; the Business's own contact people named on documents; anyone else the Business names in a document, note or line |
| Categories of personal data | Names; postal and email addresses; phone numbers; VAT, tax and company registration numbers; bank account details; the contents of invoices, proforma invoices, credit notes, quotes and receipts; payments and their references; payment terms, credit limits and notes the Business writes; when a document link was opened and how many times |
| Special categories | None are needed. The Business must not enter them, or data about criminal convictions |
| Frequency | Continuous, while the Business uses Essentio |
| Area | Measures |
|---|---|
| Encryption in transit | Every connection to Essentio, its API and its MCP server uses HTTPS (TLS) |
| Encryption at rest and secrets | Mailbox passwords, mailbox access keys and other secrets are encrypted in the database with the application key. User passwords are stored only as salted one-way hashes (bcrypt); API key secrets only as SHA-256 hashes |
| Separation of Businesses | Every Business's data carries its Business and is filtered by it on every query; automated tests in each build fail when code reads past that filter without a listed reason |
| Access inside a Business | Four roles (Owner, Admin, Member, Viewer), each allowed a fixed set of actions; every write endpoint asks the role, and tests check each role against each action on real requests. API keys and connected apps act within a role chosen for them, never above the person who connected them |
| Authentication | Email address confirmed before use; repeated failed logins are throttled; sessions end after 2 hours without activity; connected apps get access tokens valid for 1 hour, and connections unused for 90 days end; API requests are rate-limited |
| Staff access | Staff use a separate console, on its own address, with their own accounts, and sign in only with phishing-resistant passkeys (WebAuthn) that require user verification; there are no passwords. They see a Business's content only with the Owner's Support access, read-only and for 24 hours at most. Every change staff make is logged with who, when, before, after and a mandatory reason, kept 6 years |
| Network | The database and internal services are reachable only from the application's private network, not from the internet; only the web server's ports are open |
| Availability and backups | The database is dumped daily; daily dumps are kept 14 days and weekly dumps 8 weeks. Each dump is checked to be readable by the restore tool before it is kept |
| Monitoring and logging | Errors are reported to Sentry without names or email addresses, and screen recordings sent with an error mask all text and inputs; uptime is monitored; API requests are logged for 30 days without Business Data |
| Development | Every change passes an automated test suite, static analysis and review before release; dependencies are kept current |
| Deletion | Deleted items are erased after 30 days, a deleted Business with everything in it after 30 days, and erased data leaves the backups within 8 weeks |
| Sub-processors | Chosen for their security; bound by a data processing agreement; hosting in the EU |
| Review | These measures are reviewed at least once a year, and after any incident |
This list is also published at essentio.pro/subprocessors. Essentio announces each change as section 3 describes.
| Sub-processor | Service | Business Data it processes | Location | Transfer basis |
|---|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Servers, storage, backups and the mail server Essentio sends a Business's emails through | All Business Data | Germany | Within the EU |
| Functional Software, Inc. (Sentry), San Francisco, USA | Error reporting | Fragments of Business Data that may appear in an error report; masked screen recordings of sessions with an error, with all text and inputs hidden | EU (data region); account metadata in the US | EU–US Data Privacy Framework; standard contractual clauses |
PostHog (usage statistics), GitHub (feedback) and Stripe (Essentio's own billing) receive no Business Data and are listed in the Privacy Policy.