Invoice Inbox

Invoice Inbox terms

Version 1.0. In force from 9 October 2026. This version stays unchanged at kedgework.com/terms/invoice-inbox/1.0/.

The terms for firms that use Invoice Inbox UK on a paid plan or a founder pilot. Part 1 is the Terms of Service. Part 2 is the Data Processing Agreement for the personal data in the invoices you send us. Both are in English and apply to business customers only. The free tool is covered by the privacy notice (section 12), where Kedgework is the controller. These terms are separate from the Kedgework Terms of work, which cover consulting jobs.

Part 1. Terms of Service

1. Who we are and who these terms are for

1.1 Invoice Inbox UK (the "Service") is provided by Marco Cotas, a self-employed professional (trabalhador independente) in Coimbra, Portugal, trading as Kedgework, email hello@kedgework.com ("Kedgework", "we"). Our tax number (NIF) is 266238262 and our professional address is Rua Manuel Deniz Jacinto 3, Condeixa-a-Nova, Coimbra, Portugal. Our details are also on the Legal page.

1.2 The Service is for businesses and professionals acting in the course of their business (in particular accounting and bookkeeping firms). It is not for consumers. The business that uses the Service is "you" or the "Customer". You accept these terms and the DPA for your business, and confirm you have authority to do so, by ticking the box on the pilot start page, by ticking the terms box on our checkout page, or, where we ask you to, by accepting them in writing by email. We record the version you accepted, the time, the email address the invite was sent to, or the one given at checkout (or that sent the written acceptance) and the business name you gave. For a checkout, the time is when our server records the payment (for a SEPA Direct Debit this can be some days after you pay), and the business name is the one you gave at checkout, if any. If the checkout terms box was not ticked, we ask you to accept these terms in writing, by email, and record that acceptance. Each version of these terms stays online, unchanged, at its own address; this is version 1.0, at https://kedgework.com/terms/invoice-inbox/1.0/.

1.3 These terms, the Data Processing Agreement ("DPA", Part 2 of this page), and the order you place through Stripe form the contract. If they conflict on personal data, the DPA prevails.

2. The Service

2.1 You forward supplier invoices and credit notes (PDF attachments and Peppol UBL XML) to the Invoice Inbox email addresses we give you. We read them, check them (totals, VAT number check digits, VAT rates, duplicates), and send you a CSV for each email, import files for Sage 50, QuickBooks Online, Xero and Sage Accounting, and a daily report by email on days with activity or with a filing deadline reminder.

2.2 Plans. Prices are in GBP and are the ones shown on the order page when you subscribe. VAT, if due, is added by the seller of record (section 6).

Starter
GBP 19 a month. Up to 100 invoices a month and up to 5 inboxes (your main inbox and 4 client inboxes).
Practice
GBP 49 a month. Up to 500 invoices a month and up to 25 inboxes (your main inbox and 24 client inboxes).

The invoice limit is for the whole firm. Invoices above the limit are listed as not read in the CSV and are not charged for.

There are also daily and per-email limits. Each firm can send up to 10 emails with invoices a day, across all its inboxes; a further email that day is refused and the sender gets it back. Each firm has a daily share of reads by the AI model: up to 20 a day on Starter, 100 on Practice and 10 on a founder pilot (a read that has to be repeated counts twice, and the share can run out sooner if invoices are unusually long). E-invoice XML files are read without the AI model and do not use this share. There is also a daily limit for the whole Service, shared by all customers. One email can carry up to 10 invoice files and up to 10 MB; each PDF can be up to 5 MB, and a scanned PDF up to 20 pages. Invoices over a daily limit, and files over the 10-file limit, are listed as not read in the CSV, do not count towards your monthly limit and are not charged for; you can send them again the next day. A PDF over the size or page limit is listed as not readable, and an email over 10 MB is refused. If the whole Service reaches its daily spending limit, it pauses until we restart it, and email sent in the meantime is refused.

2.3 Early access and pilots. During early access, the Service may change, be limited or be paused. A founder pilot (a limited number of invoices or days, no card) is provided as it is, free of charge, and ends on the date stated. Sections 9 and 10 apply to pilots as well.

2.4 The Service reads PDF attachments, including scanned PDFs (these are sent to the AI model as a PDF), and Peppol e-invoices. It does not read image files (such as JPG or PNG) attached to the email. It does not post to your accounting software unless you connect a ledger for a client inbox and a person at your firm approves the invoice on the review page (DPA, section D7.4). Otherwise you import the files yourself.

3. No tax, accounting or legal advice. You always review.

3.1 The Service is a data-entry and checking tool. It does not give tax, VAT, accounting or legal advice, and its checks are not a determination of any tax treatment. A VAT number check confirms the check digits only; it does not confirm registration with HMRC, unless we have switched on the HMRC check and the result says so. Reverse charge, rates and return boxes shown are indications only.

3.2 AI is used to read invoices. The result can be wrong or incomplete. You, a qualified person at your firm, must review every CSV, import file, report and ledger entry before you import or rely on it, and you remain responsible for your clients' books, VAT returns and filings. Invoices that fail a check, and invoices in a currency other than the one of the import files (GBP for the UK version), are marked and left out of the import files. After you review them, you enter them in your ledger yourself or, for a flagged invoice in a client inbox with a connected ledger, approve it on the review page so it is sent there. Passing every check is not a guarantee that a figure is right.

3.3 We have not measured accuracy on real invoices and give no accuracy guarantee.

4. Your use of the Service

4.1 You will: (a) forward only invoices you or your clients are entitled to send us; (b) have a lawful basis to send us the personal data in them and give any required information to the individuals concerned; (c) keep your Invoice Inbox addresses private and approve senders carefully; (d) use the Service in line with these terms and the law.

4.2 You will not: send malicious files or content that breaks the law; try to get around limits, caps or security; send special category or criminal offence data on purpose; resell the Service or use it to build a competing service; or use it to send spam or abuse email systems.

4.3 We may refuse, hold or delete files that break section 4.2, and suspend the Service for serious or repeated breach. We will tell you why when we can.

4.4 Your account depends on your email address. You are responsible for keeping the account email correct and your mailbox secure.

5. Support: email only

5.1 Support is by email to hello@kedgework.com only. There are no phone or video calls, no chat, and no on-site help.

5.2 We read and answer email on business days in Portugal. There is no service level agreement, no reply-time guarantee and no uptime commitment. We do not offer priority support.

5.3 We may announce planned and unplanned stops by email or on the site. We are not liable for stops outside our reasonable control, including failures of Cloudflare, Resend, Anthropic, Google or Stripe, or of your own email provider.

6. Fees, billing and renewal

6.1 Plans are monthly and renew automatically until cancelled. Billing, receipts, sales tax and payment support are handled by Stripe, which acts as merchant of record under Stripe Managed Payments and may show the sale as "Sold through Link". Stripe's own terms and privacy policy apply to payment. We never see your card details.

6.2 Prices are as shown at checkout. We may change prices for future periods by giving you at least 30 days' notice by email. If you disagree, you may cancel before the change takes effect.

6.3 If a payment fails, we may refuse new mail until it is paid. A refund or a chargeback may stop the account; see section 7.3.

7. Cancellation

7.1 You can cancel at any time, with no minimum term and no cancellation fee. Cancel through Link (link.com), which is named on your receipt, or write to hello@kedgework.com from your account email.

7.2 Cancellation takes effect at the end of the month you have paid for. The Service works until then. We do not refund part of a month already paid, except where the law requires it or where we end the Service for reasons other than your breach (section 7.4).

7.3 If your payment is refunded or disputed, we may stop reading mail for the account while keeping your inboxes, and we will tell you.

7.4 We may end or change the Service. If we end the Service entirely, we will tell you at least 30 days in advance and refund the unused part of the period you paid.

7.5 After the Service ends, section 11 and the DPA decide what happens to your data. Sections 3, 8, 9, 10, 11 and 12 survive.

8. Intellectual property and your content

8.1 You keep all rights in the invoices and data you send ("Your Content"), and in the files we produce from them. You give us a limited licence to process Your Content only to provide the Service to you, with one exception you choose: if you switch on the shared supplier list, you also allow us to use the supplier facts a person at your firm confirmed (name, VAT number, usual VAT rate and usual expense category of suppliers whose name ends in Ltd, Limited, PLC, LLP, CIC or LP only; never amounts, dates, invoice numbers, clients or your firm's name) to show majority answers to other firms that switched it on. A fact is shown only when at least 5 other firms gave a value for that supplier. Switching the list off deletes your entries (DPA, sections D3 and D11).

8.2 We keep all rights in the Service, its software, checks and documentation. You get a non-exclusive right to use the Service during your subscription.

8.3 We do not use Your Content to train any model, and our AI provider's commercial terms do not allow it to do so (DPA, section D7.1).

9. Disclaimers

9.1 To the extent the law allows, the Service is provided "as is". We do not promise it will be uninterrupted, error-free or fit for a particular purpose, or that import files will be accepted by every version of Sage, QuickBooks or Xero. The import files are built for the UK editions; import formats can change, and some format details are not yet verified against live products.

9.2 Nothing in the Service replaces your professional judgement or your duties to your clients.

10. Limit of liability

10.1 Nothing in these terms limits or excludes liability that cannot be limited or excluded by law, including liability for death or personal injury caused by negligence, for fraud, and, where the applicable law does not allow it to be limited, for intentional wrongdoing or gross negligence.

10.2 Subject to 10.1, our total liability to you for all claims arising out of or in connection with the Service and these terms, whatever the cause (contract, tort including negligence, or otherwise), is limited to the greater of: (a) the fees you paid us for the Service in the 12 months before the event that first gave rise to the claim; and (b) GBP 100.

10.3 Subject to 10.1, we are not liable for: loss of profit, revenue, business, goodwill or savings; indirect or consequential loss; loss caused by a figure, VAT treatment or filing based on output you did not review; penalties, interest or tax charges imposed on you or your clients; or loss of data you could have avoided by keeping the original invoices (which we do not store).

10.4 Each party must take reasonable steps to limit its losses. The limit in 10.2 is a total for all claims together, not per claim.

11. Personal data

11.1 We are a processor for the personal data in Your Content and the DPA applies to it. You are the controller. We are a controller for our own billing, security and marketing data, as explained in our privacy notice.

11.2 The DPA lists our sub-processors (Cloudflare, Anthropic and Resend), how our support mailbox works (Google; replies to our service emails go there), the other recipients (HMRC for supplier VAT checks, when we switch that check on; your own Xero or QuickBooks Online company, if you connect it; our own Telegram chat for operational alerts, which hold only internal account and payment reference codes, counts and short error messages, never invoice content or email addresses), the role of Stripe as merchant of record, the international transfer safeguards, how long data is kept, and how we tell you about a breach within 48 hours.

11.3 We keep extracted invoice fields for up to 400 days after each invoice is processed and then delete them. We do not keep the PDF files or the email bodies. Your account settings and the supplier rules you confirmed are not deleted automatically when the subscription ends: they are deleted when you ask. Details are in the DPA, section D11.

11.4 Kedgework is established in Portugal and has no office in the United Kingdom. We have not appointed a representative in the UK under Article 27 of the UK GDPR. If we appoint one, we will add their name and address here. Until then, anyone in the UK can contact us about data protection directly at hello@kedgework.com, and can complain to the UK data protection regulator (ico.org.uk).

12. Confidentiality

Each side keeps the other's non-public information confidential, uses it only for the Service, and shares it only with people and processors who need it and are bound to confidentiality, or where the law requires. This continues after the Service ends. It does not cover information that is public through no fault of the receiver, or already known or lawfully obtained elsewhere.

13. Changes to these terms

We may update these terms. For changes that matter, we will give 30 days' notice by email to your account address. If you do not accept the change, you can cancel before it takes effect (section 7). Continued use after that date means you accept the new terms; for that acceptance, our record is the notice we emailed you and the date the new version took effect. Changes required by law may apply sooner. Each version is numbered at the top of this page.

14. General

14.1 Entire agreement: these terms, the DPA and the order are the whole contract on the Service.

14.2 If a clause is invalid, the rest stays in force.

14.3 You may not transfer the contract without our written consent. We may transfer it to a successor of the business and will tell you.

14.4 Notices: by email, to the account email for you, and to hello@kedgework.com for us.

14.5 No third party may enforce these terms. Force majeure: neither side is liable for delay or failure caused by events beyond its reasonable control, except for the payment duty.

14.6 Language: these terms are in English.

14.7 Portuguese law governs these terms. Any dispute goes to the courts of the judicial district of Coimbra, Portugal. This does not stop either side from trying to settle a dispute first, and it does not take away any right that the law of your country gives you and that cannot be excluded by contract.

15. Contact

hello@kedgework.com. Provider identification: Legal page.

Part 2. Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service for Invoice Inbox UK in Part 1 (the "Terms") between:

It meets Article 28 of the UK GDPR and, because Kedgework is established in Portugal, Article 28 of the EU GDPR. If the Customer is also subject to the EU GDPR for the same data and needs further wording (for example the EU Standard Contractual Clauses for a transfer), the Customer may tell Kedgework in writing and the parties will add it.

D1. Definitions

"UK GDPR", "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning in the UK GDPR and the Data Protection Act 2018. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018 (as amended, including by the Data (Use and Access) Act 2025), and any other law on personal data that applies to the processing. "Customer Personal Data" means personal data in the content the Customer or its clients forward to Invoice Inbox, and in the Customer's account, that Kedgework processes for the Customer under the Terms. "Sub-processor" means a third party engaged by Kedgework to process Customer Personal Data. "Other recipient" means a third party that is not a Sub-processor and receives Customer Personal Data because the Customer connected its ledger or because Kedgework switched on the HMRC check (section D7.4).

D2. Roles

D2.1 For Customer Personal Data, the Customer is the controller and Kedgework is the processor. If the Customer processes the data for its own clients, the Customer is a processor of those clients, and Kedgework is its sub-processor; the Customer confirms it has the authority to give the instructions in this DPA.

D2.2 Kedgework is an independent controller for a separate set of data it uses for its own purposes: billing and subscription records, security and abuse logs, site and marketing data, and records it must keep by law. How Kedgework handles that data is explained in its privacy notice. This DPA does not cover it.

D3. Subject matter, nature, purpose and duration (Art. 28(3))

Subject matter and purpose
Reading supplier invoices and credit notes the Customer forwards by email to its Invoice Inbox addresses; extracting the invoice fields; running fixed checks (totals, VAT number check digits, VAT rates, duplicates); returning a CSV, import files for Sage 50, QuickBooks Online, Xero and Sage Accounting, and a daily report by email on days with activity or with a filing deadline reminder; a signed review page where the Customer approves or corrects flagged invoices; supplier rules the Customer confirms. While Kedgework has the HMRC check switched on: checking UK supplier VAT numbers with HMRC (section D7.4). If the Customer switches them on: sending approved invoices to the Customer's own Xero or QuickBooks Online company (section D7.4), and sharing supplier-level facts about suppliers with a company-type name (Terms, section 8.1) in the opt-in shared supplier list.
Nature of processing
Receiving email; reading PDF and Peppol UBL XML attachments; sending invoice content to an AI model (Anthropic) to extract fields; storing extracted fields; producing files; sending email; calling the HMRC and ledger APIs when switched on; deleting data.
Duration
The term of the Terms, plus the retention periods in section D11 and any period needed to carry out deletion.
Data subjects
Suppliers of the Customer and of its clients who are individuals or whose staff are named on an invoice (sole traders, contact people); staff of the Customer who use the service; staff and contacts of the Customer's clients whose names appear on invoices.
Types of personal data
Names, business addresses, email and telephone numbers, VAT and company numbers of sole traders, bank details printed on invoices if present, invoice numbers, dates and amounts linked to a person; email addresses of the Customer's users, of approved senders and of senders waiting for approval; mail metadata (sender address, subject, date); HMRC answers for a supplier VAT number (registered name and address, consultation number), when the HMRC check is on.
Special categories and criminal data
None intended. The Customer must not send invoices that contain special category data or criminal offence data. If an invoice happens to contain such data, Kedgework processes it only as part of the same service and does not use it for any other purpose.
What Kedgework does not keep
The PDF files and the email bodies are not stored after processing. Only the extracted fields are stored.

D4. Customer's instructions

D4.1 Kedgework processes Customer Personal Data only on the Customer's documented instructions: this DPA, the Terms, and the Customer's use of the service (for example, forwarding an invoice, approving a row on the review page, connecting a ledger, or sending a command by email). Kedgework may also process it where UK law requires, and will tell the Customer first unless the law forbids that.

D4.2 Kedgework will tell the Customer if it believes an instruction breaks Data Protection Law.

D4.3 The Customer is responsible for having a lawful basis for the data it sends, for giving the information to data subjects that Data Protection Law requires, and for the accuracy and lawfulness of its instructions.

D5. Confidentiality

Kedgework keeps Customer Personal Data confidential and gives access only to people who need it to provide the service and are bound by a duty of confidentiality. Kedgework is a sole provider; any person it later authorises to access the data will sign a confidentiality commitment first.

D6. Security (Art. 32)

Kedgework applies the technical and organisational measures below, and reviews them as the service changes. They have not been tested by a third party.

D7. Sub-processors and other recipients (Art. 28(2) and (4))

D7.1 General authorisation. The Customer authorises Kedgework to use the Sub-processors below (Cloudflare, Anthropic and Resend). Each one's data processing terms were read on 9 October 2026 at the link given.

Cloudflare, Inc.

What it does
Hosting (Workers), email receiving (Email Routing), database (D1, created in the EU jurisdiction).
Data
All Customer Personal Data in transit and at rest.
Location
EU for stored data; processing at the edge may involve the US and other countries.
Safeguards
Cloudflare Data Processing Addendum v6.4, effective 3 April 2026 (cloudflare.com/cloudflare-customer-dpa): EU SCCs (Module 2 or 3) with the UK Addendum (version B1.0), and the EU-US Data Privacy Framework with its UK Extension. Sub-processors: cloudflare.com/gdpr/subprocessors.

Anthropic Ireland, Limited (with Anthropic, PBC and affiliates)

What it does
AI model (API) that reads the invoice text or pages and returns the invoice fields.
Data
The content of each invoice sent for extraction (its text, or the PDF itself when the text cannot be read, for example a scan), together with the file name and the email subject.
Location
Ireland/EU and the US.
Safeguards
Anthropic Data Processing Addendum, effective 24 February 2025 (anthropic.com/legal/data-processing-addendum), incorporated by the Commercial Terms, effective 17 June 2025 (anthropic.com/legal/commercial-terms): EU SCCs (Modules 2 and 3) with the UK Addendum (B.1.0). The Commercial Terms forbid training models on customer content. Sub-processors: anthropic.com/subprocessors.

Plus Five Five, Inc. (Resend)

What it does
Sends the service emails: CSV and import files, reports, review links, confirmations and notices.
Data
The Customer's email addresses and the extracted invoice fields sent back as files.
Location
US.
Safeguards
Resend Data Processing Addendum, last updated 31 December 2025 (resend.com/legal/dpa), incorporated into its Terms of Service: EU SCCs with the UK Addendum, and the EU-US Data Privacy Framework with its UK Extension. Sub-processors: resend.com/legal/subprocessors.

Support mailbox (Google Gmail)

Email sent to hello@kedgework.com, including replies to service emails, is forwarded by Cloudflare Email Routing to a personal Gmail mailbox that Kedgework uses to read and answer it. It is not a Google Workspace account, and Kedgework has no data processing agreement with Google for it, so Google is not listed as a Sub-processor and section D7.5 does not cover it. The Service never reads invoices from that mailbox: invoices go only to the Invoice Inbox addresses. The Customer should not send invoices, client data or other Customer Personal Data to hello@kedgework.com; a support request needs only the account email and, where useful, an invoice reference number. If personal data does arrive there, Kedgework uses it only to answer the request.

D7.2 Stripe. Paid plans are sold through Stripe Managed Payments. Under it, Stripe is the merchant of record and the customer sees the purchase as "Sold through Link" (docs.stripe.com). Stripe receives only account and billing data, never invoice content. Stripe's Data Processing Agreement (last updated 28 September 2026, stripe.com/legal/dpa) says Stripe acts as a processor for some data and as a controller for its own purposes (such as fraud prevention and legal compliance); it does not address Managed Payments. Kedgework therefore treats Stripe as an independent controller for the payment and billing data it collects as merchant of record, and lists it here only so the Customer has the full picture. This is Kedgework's reading of the two pages above, not a statement by Stripe.

D7.3 Changes. Kedgework will give the Customer at least 30 days' notice by email before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within 14 days of the notice. If the parties cannot agree, the Customer may cancel the subscription and Kedgework will refund the unused part of the month paid. The current list is in this DPA, and is also kept in the privacy notice (section 5).

D7.4 Other recipients. These are not Kedgework's sub-processors, and only what is listed is sent. Data goes to the Customer's ledger only when the Customer connects it. Data goes to HMRC only while Kedgework has the HMRC check switched on: Kedgework switches it on or off for the whole service, not per Customer, and while it is on it applies to every Invoice Inbox account with the UK version.

HM Revenue and Customs (HMRC), API "Check a UK VAT number" v2 (developer.service.hmrc.gov.uk)

When
Kedgework has switched the check on (for the whole service, not per Customer) and an invoice shows a UK (GB or XI) supplier VAT number.
What we send
The supplier's VAT number (9 or 12 digits) and, if the Customer gave it, the Customer's own VAT number, so HMRC returns a consultation number as proof of the check. Nothing else from the invoice.
What we keep
Per check: registered or not, the registered name and address, the consultation number and HMRC's processing date. Per invoice: registered or not, the registered name, the consultation number and the date of the check. A "registered" answer is reused for 30 days and a "not registered" answer for 1 day for the same VAT number; after that HMRC is asked again. Stored checks are deleted 400 days after the check.

The Customer's own Xero organisation (Xero Limited) or QuickBooks Online company (Intuit Inc.)

When
The Customer connects a ledger for a client inbox and a person approves or corrects an invoice on the review page.
What we send
For each approved invoice: supplier name, invoice number, issue and due dates, currency, line descriptions, net amounts, account and tax codes, and a reference "Invoice Inbox #<id>". Xero bills are saved as drafts, and in Xero the supplier contact is matched by name or created if it does not exist yet. QuickBooks Online has no draft bills: the bill is created as a normal bill, and the supplier is created as a vendor if it does not exist yet.
What we keep
OAuth access and refresh tokens (encrypted, section D6) and the push result. The ledger's accounts, tax rates and suppliers are read during each push only to match codes, and are not stored.
Access asked
Xero: offline_access accounting.invoices accounting.contacts accounting.settings.read. QuickBooks Online: com.intuit.quickbooks.accounting.

The ledger provider holds the data under the Customer's own contract with it. HMRC is a public authority that handles the lookup as its own controller. Data sent to a ledger is never passed to the AI model, and Kedgework does not use ledger data to train any model (as Xero's Developer Platform Terms, updated 4 December 2025, also require: developer.xero.com).

D7.5 Kedgework has a written contract with each Sub-processor that imposes the data protection obligations required by Article 28(4) UK GDPR (the documents linked in D7.1), and remains liable to the Customer for each Sub-processor's performance.

D8. International transfers

D8.1 From the Customer in the UK to Kedgework in Portugal: the UK treats transfers to the EEA as adequate. If that cover ever ends, section D8.4 applies. Data returned from Kedgework to the UK (to the Customer, to HMRC, or to a UK ledger) is covered by the European Commission's adequacy decision for the UK, renewed on 19 December 2025 (European Commission).

D8.2 Onward transfers by Kedgework to the US rely on, in this order: (a) the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge), for sub-processors certified to it; (b) otherwise the EU Standard Contractual Clauses with the ICO's International Data Transfer Addendum ("UK Addendum") in the sub-processor's data processing terms (section D7.1). On 8 October 2026, Cloudflare, Inc. and Plus Five Five, Inc. were on the Data Privacy Framework list for the UK Extension. Anthropic relies on (b). Because Kedgework is established in Portugal, these transfers also rely on the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795) for certified sub-processors or, where it does not apply, the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) in the sub-processor's data processing terms.

D8.3 Kedgework will give the Customer, on request, a copy of the safeguard that applies to each Sub-processor, with commercial terms removed.

D8.4 If a restricted transfer between the Customer and Kedgework needs a tool because adequacy does not apply, the parties agree that the UK Addendum to the EU Standard Contractual Clauses (Module 2 for controller to processor, or Module 3 for processor to sub-processor) is incorporated by reference, with these details: Customer as exporter, Kedgework as importer; Part 1 tables completed from sections D3, D6 and D7 of this DPA; and ending the Addendum "neither party". Alternatively, the parties may sign the ICO's International Data Transfer Agreement (IDTA) in place of the Addendum. Both are safeguards UK GDPR organisations can use (ICO glossary).

D9. Data subject rights

Kedgework will help the Customer answer requests from data subjects (access, correction, erasure, restriction, portability, objection) with suitable technical and organisational measures. If Kedgework receives a request directly about Customer Personal Data, it will not answer it itself, except to say it has passed it on, and will send it to the Customer within 5 working days. Kedgework can find, export and erase rows for an inbox on request (stored HMRC answers are found by the Customer's VAT number, not by inbox; where the Customer gave no VAT number, they are found only by the supplier's VAT number and are shared with other checks made without one). The Customer pays no extra charge for ordinary requests; Kedgework may charge a reasonable fee for requests that are manifestly excessive.

D10. Personal data breaches

D10.1 Kedgework will tell the Customer about a personal data breach affecting Customer Personal Data without undue delay and in any case within 48 hours of becoming aware of it, by email to the Customer's account address. This leaves the Customer time to meet its own 72-hour duty to the ICO (Art. 33 UK GDPR). If the breach involves data obtained from a connected Xero organisation, Kedgework also reports it to Xero within 24 hours, as Xero's Developer Platform Terms require, without naming the Customer unless the law requires it.

D10.2 The notice will say, as far as known: the nature of the breach and the categories and approximate numbers of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact for more information. Kedgework may send the information in stages.

D10.3 Kedgework will take reasonable steps to contain the breach and will help the Customer meet its duties to notify the ICO and data subjects, and to carry out data protection impact assessments or prior consultation where needed.

D10.4 Kedgework's notice or help is not an admission of fault.

D11. Retention, return and deletion

D11.1 Kedgework keeps each invoice's extracted fields for 400 days from the day it was processed, then deletes them in a daily job, together with its review records and ledger push records. Stored HMRC checks are deleted 400 days after the check, and the history of supplier rule changes 400 days after each change. PDFs and email bodies are not stored. Free-tool data is kept for 30 days. Operational logs are deleted after 400 days and abuse counters after 40 days; they do not hold the invoice fields, but logs may hold a client label and short error messages from a connected ledger.

D11.2 Account data is not deleted by the daily job: the account email and status, the inbox addresses, the approved senders and the addresses of senders waiting for approval, the client and firm settings, the supplier rules the Customer confirmed (which can name suppliers who are sole traders), the record of each acceptance of these Terms and DPA (the version, how it was accepted, the time, the email address the invite was sent to, or the one given at checkout (or that sent the written acceptance), the business name and, on the pilot start page, a keyed hash of the IP address, made with a secret key so the address cannot be worked out from it without that key), and the record of each acceptance of these Terms for a ledger connection. A founder pilot invite (the invited email, language, country and VAT number if given) is kept until the link is used or expires, whichever comes first, and is deleted 14 days after that, or earlier on erasure. While the subscription runs, the Service needs them. After it ends, they stay until the Customer asks for deletion under D11.4 (except the acceptance records, see D11.4). If the Customer switched on the shared supplier list, its entries stay in the list until the Customer switches it off or asks for deletion; they hold only supplier-level facts about suppliers with a company-type name (Terms, section 8.1).

D11.3 Ledger tokens are wiped as soon as the Customer disconnects the ledger. When a subscription is cancelled or a pilot ends, a daily job revokes and deletes any ledger tokens still stored within 30 days of the end. If a payment is refunded or disputed, the account is stopped but not ended (Terms, section 7.3), and its ledger tokens are not deleted automatically: Kedgework decides by hand, and the Customer can ask for the ledger to be disconnected at any time.

D11.4 At any time after the subscription ends, the Customer can ask in writing for a copy of its data as CSV (or JSON) and for deletion. Kedgework will then return the data and delete it, or delete it only, as the Customer chooses, within 30 days of the request, including the account data in D11.2 and any ledger tokens still stored. Kedgework will delete existing copies unless the law requires it to keep the data, and will tell the Customer which data and why if so; the record of each acceptance of these Terms and DPA (D11.2), and of each ledger connection, is kept as proof of the contract also after the rest of the account is erased: on erasure, Kedgework records with it the date the contract ended (or the date of erasure, if no end date is recorded), and a daily job deletes it 6 years (2192 days) after that date, unless the account is in use again by then; billing records are kept as long as the law requires. Pilot invites are deleted with the account. Backups held by Sub-processors are deleted on their normal cycle.

D11.5 Anthropic deletes API inputs and outputs within 30 days of receipt or generation, unless the law requires longer or longer holding is needed to enforce its usage policy (privacy.claude.com, last updated 1 July 2026).

D12. Audits and information (Art. 28(3)(h))

Kedgework will give the Customer the information needed to show it follows Article 28 and will allow and contribute to reasonable audits, including inspections, by the Customer or an auditor it mandates who is bound by confidentiality. Kedgework may first offer to answer a written questionnaire and share relevant certificates or reports of its Sub-processors; if these are not enough to show compliance, an inspection may take place with 30 days' notice, no more than once a year (unless a regulator requires more or a breach has occurred), during business hours, and without access to other customers' data. The Customer bears its own costs.

D13. Assistance with compliance

Kedgework will give reasonable assistance with the Customer's duties on security, breach notification, data protection impact assessments, and prior consultation with the ICO, taking into account the nature of the processing and the information it has.

D14. Liability

Liability under this DPA is subject to the limits in section 10 of the Terms. This does not limit liability that cannot be limited by law, or a data subject's rights under Article 82 UK GDPR.

D15. Term and order of precedence

D15.1 This DPA lasts as long as Kedgework processes Customer Personal Data.

D15.2 If this DPA conflicts with the Terms on personal data, this DPA prevails. Standard contractual clauses or the UK Addendum, if incorporated, prevail over both.

D16. Contact

Data protection questions and breach notices: hello@kedgework.com. Kedgework has not appointed a Data Protection Officer; on current facts its size and activities do not require one (Art. 37 UK GDPR: no large-scale special category data, no large-scale systematic monitoring).