We keep it simple: your data is yours, stored in Europe, never sold.
Last updated: February 2026InvoPass is operated by Eldvarnir ehf., doing business as InvoPass.io, a company registered in Iceland. Kt. 6508080450, VAT 96668.
InvoPass
Registration number: 650808-0450
VAT number: 96668
Idavellir 3, 230 Reykjanesbaer, Iceland
Email: [email protected]
InvoPass is the data controller for all personal data processed through InvoPass. This Privacy Policy explains how we collect, use, and protect that data.
When you sign up, we collect:
InvoPass processes invoice documents that you submit or that arrive via your dedicated inbound email address. This data includes:
We automatically collect:
We do not collect sensitive personal data such as health information, political opinions, or biometric data.
We use your data only to provide and improve the InvoPass service:
We do not sell your data to third parties. We do not use your invoice data for advertising or training AI models for purposes outside your own InvoPass service.
Our legal basis for processing is:
All InvoPass data is stored in the European Union. Our infrastructure uses EU-based cloud providers, and no personal data is transferred to countries outside the EEA without appropriate safeguards.
We protect your data using:
Invoice PDF files are stored in EU-based object storage with strict access controls. Only authenticated users with appropriate permissions can retrieve attachments.
InvoPass uses a small number of carefully selected third-party services. Where these services process your data, we have appropriate data processing agreements in place.
Invoice documents are sent to Anthropic's Claude API for field extraction (vendor name, amount, due date, etc.). Anthropic processes this data as a data processor on our behalf. Invoice content sent to Claude is not used to train Anthropic's models. Anthropic is covered by EU data processing agreements under their enterprise terms.
Subscription billing and payment processing is handled by Lemon Squeezy, who act as the merchant of record. They collect your billing name, email, and payment details. Their privacy policy applies to payment data. We store your subscription status and customer reference only.
If you use the Microsoft 365 mailbox integration, InvoPass connects to Microsoft Graph with your organization's delegated permissions to read invoice emails from a shared mailbox. Microsoft processes this data subject to their own privacy policy and data processing terms.
If you configure Slack, Telegram, or Teams notifications, your notification preferences (channel IDs, chat IDs) are stored and used to send approval request alerts. These providers process message content subject to their own privacy policies.
We do not share your data with any third parties for marketing or advertising purposes.
As a data subject under the GDPR, you have the following rights. To exercise any of these rights, contact us at [email protected].
You can request a copy of the personal data we hold about you at any time. Admins can also use the built-in "Export all data" feature in Settings to download a complete export of all your organization's data.
If any personal data we hold is inaccurate or incomplete, you can ask us to correct it. For your account details, you can update these directly within the application.
You can request deletion of your personal data. For complete account deletion, use the "Delete account" option in Settings, which initiates a 30-day grace period after which all data is permanently deleted. We may retain some data where required by law (for example, financial records subject to accounting retention requirements).
You can export all your data in machine-readable CSV format using the built-in export feature in Settings. This includes all invoices, vendors, users, and audit events.
In certain circumstances, you can request that we limit how we process your data. Contact us to discuss your specific situation.
You can object to processing based on legitimate interests. We will stop processing unless we have compelling legitimate grounds that override your interests.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Icelandic Data Protection Authority (Personuvernd) at www.personuvernd.is.
We will respond to all data rights requests within 30 days. For complex requests, we may extend this to 90 days and will notify you accordingly.
We retain your data for as long as your account is active and for a period afterward as required by law or legitimate business need.
You can configure custom retention policies within InvoPass to archive or delete records earlier, subject to legal minimums.
When you delete your account, all invoice data, vendor data, user data, and settings are permanently deleted within 30 days of the scheduled deletion date. Anonymized aggregate statistics may be retained for service improvement purposes.
InvoPass uses cookies for authentication only. We set a single session cookie when you log in, which is used to maintain your authenticated session. This cookie is strictly necessary for the service to function.
We do not use tracking cookies, advertising cookies, or analytics cookies that follow you across the web. We do not use Google Analytics or similar third-party analytics tools.
The landing page at invopass.io uses no cookies at all. The application at app.invopass.io sets one session cookie on login.
For any questions about this Privacy Policy, your data rights, or our data practices, contact our Data Protection Officer:
Data Protection Officer - InvoPass
Email: [email protected]
InvoPass, Idavellir 3, 230 Reykjanesbaer, Iceland
We may update this Privacy Policy from time to time. When we make significant changes, we will notify account administrators by email and update the "Last updated" date at the top of this page. Continued use of InvoPass after changes take effect constitutes acceptance of the updated policy.