Legal
Data processing agreement
The terms on which BillPigeon processes your clients’ personal data for you.
Version 2026-10
Draft. This page has not yet been reviewed by a lawyer and may change before BillPigeon launches.
Parties and roles
You (the customer) decide why and how the personal data of your clients and contacts is used in your documents: you are the controller. Appentium LLC (BillPigeon) processes that data on your behalf: it is the processor. This agreement applies to that processing and is accepted when you set up your business.
What is processed
- Subject matter: storing, showing, calculating, sending and exporting your invoices, credit notes, estimates and payments.
- Data subjects: your clients and their contacts.
- Kinds of data: names, postal and email addresses, phone numbers, tax identifiers and the content of documents and payments that you enter.
- Duration: until you delete the data or your account.
What BillPigeon does and does not do
- It processes the data only to provide the service and on your instructions, which are given by your use of the apps.
- It makes sure people who work with the data are bound to confidentiality.
- It uses the sub-processors listed on the sub-processors page and tells you before it adds or replaces one, so you can object.
- It helps you answer requests from your clients about their data, for example through the data export, and with security incidents and impact assessments, as far as that is reasonable.
- It tells you without undue delay if it learns of a personal data breach that affects your data.
- It deletes your data when you delete your account and, on request, gives you proof of how it did so. Encrypted backups expire within 30 days.
- It makes available what you need to check that it keeps this agreement.
Security
- Hosting in Germany with encryption of the storage at rest by the hosting provider.
- Encryption of all traffic in transit (TLS 1.2 or higher).
- Separation of every business’s data from every other business’s data, tested automatically.
- Sign-in protection: limits on attempts, hashed email codes, checks of new passwords against known leaks and a list of devices you can revoke.
- Encrypted daily backups to a second location in the EU.
- Logs and error reports without the content of your documents.
Transfers outside the EU
If a sub-processor processes data outside the EU or the EEA, it does so under the safeguards the law requires, such as standard contractual clauses.