Last updated: 25 July 2026
Account details you provide (name, email, password - stored as a salted hash, never plain text); organisation and billing details; invoice, client, and payment records you enter; usage and log data (IP address, timestamps) for security and rate limiting; payment metadata from our payment processor (we do not store full card numbers).
To perform our contract with you (running the Service you signed up for); to comply with legal obligations (tax and audit records); and, for security logs and fraud prevention, our legitimate interest in keeping the Service safe - balanced against your rights.
Sub-processors that help run the Service: Neon (database hosting), Vercel (application hosting), Cloudinary (file and logo storage), our SMTP email provider (delivery of invoices and notifications), Paymish (subscription payment processing), Upstash (rate limiting, which processes IP addresses), and Sentry (error monitoring, which may capture technical request context when something fails). Each processes data only as needed to provide their function to us, under agreement. We do not sell your data.
Our providers operate data centres outside Nigeria; the database and application currently run in the United States, and some providers may process data elsewhere. Where data leaves Nigeria we rely on the safeguards required under the NDPA/NDPR for cross-border transfer. If your organisation needs its data held in a specific region, contact us before signing up.
Active account data is kept for as long as your subscription is active. After cancellation we keep it for 90 days so you can still sign in and export it, then delete or anonymise it, except where longer retention is required by tax or audit law - financial records and audit logs are commonly subject to multi-year statutory retention, and those are kept for as long as the law requires.
Under the NDPA/NDPR you can request access to, correction of, or deletion of your personal data, and request a portable export of your organisation's data. Contact us to exercise these rights; some data (e.g. audit logs required for financial compliance) may be exempt from deletion while a legal retention obligation applies.
Passwords are hashed, not stored in plain text. Sessions can be revoked server-side. Optional multi-factor authentication (TOTP) is available. Access to your organisation's data is restricted to your own team by design (tenant isolation). If a breach affecting your personal data occurs, we will notify affected users and, where legally required, the relevant regulator, without undue delay.
We use only the session cookie required to keep you signed in - no third-party advertising or tracking cookies.
The Service is intended for business use by adults; it is not directed at children.
When you use the Service to invoice your own clients, you are the controller of your clients' personal data and we process it on your instructions (a processor relationship). Once the Service is offered to organisations other than Suwebatu itself, a separate Data Processing Agreement covering this relationship will be provided before onboarding.
We may update this Policy; material changes will be notified by email or in-app before they take effect.
Data protection questions: billing@suwebatu.co.uk.