Data Protection
Two different relationships
numrow handles personal data in two ways, and the difference decides who answers a request about it.
| We are the controller | We are the processor | |
|---|---|---|
| What | Your users' accounts, sign-in records, billing details, the enquiries you send us | Everything your organisation puts into its workspace: supplier and customer records, invoices, documents, bank statements, the people named on them |
| Who decides why it is processed | We do | Your organisation does |
| Where it is described | The Privacy Notice | This page, and the data processing agreement |
Practically: if one of your suppliers asks what numrow knows about them, the answer belongs to you and we help you give it. If one of your staff asks what numrow knows about their account, the answer is ours.
The data processing agreement
Our DPA is offered to every customer and forms part of the Terms of Service. It contains what Article 28 of the GDPR requires and what the Mauritius Data Protection Act 2017 expects of a processor:
- the subject matter, duration, nature and purpose of the processing, and the categories of data and data subjects;
- that we process only on your documented instructions, including on transfers;
- confidentiality undertakings from everyone with access;
- the security measures described below;
- the conditions on which we engage a sub-processor, and your right to object;
- help with data-subject requests, breach notification, and impact assessments;
- deletion or return of the data at the end of the contract;
- the information and audit rights you need to verify all of the above.
Ask privacy@numrow.com for the current text.
Sub-processors
We use a small number of suppliers to run the service. Each is under a written contract with the same obligations we owe you, and each is engaged for one purpose:
| Sub-processor | Purpose | Location |
|---|---|---|
| [SUB-PROCESSOR LIST — hosting, object storage, transactional email, payment processing, and any document-parsing provider that receives customer documents] | ||
We tell customers before adding or replacing one, and you may object. Where a document-parsing model runs on infrastructure we control, no third party receives the document; where it does not, that provider is named in the list above, because a supplier who sees your invoices is a sub-processor whatever it is called.
Where the data lives
The application and its database run at [HOSTING LOCATION], and documents are stored in object storage at [STORAGE LOCATION]. Transfers outside Mauritius rely on the conditions in section 36 of the Data Protection Act 2017 (transfer of personal data outside Mauritius); transfers out of the EEA rely on standard contractual clauses.
Security
- Separation. Every customer's data is scoped to its own tenant, and that scope is enforced in the database rather than only in the application.
- Access. Rights are granted per role and per organisational unit; staff access to production is restricted to the people whose work requires it and is logged.
- Transport and storage. Encrypted in transit. Storage encryption is provided by the hosting and object-storage platforms.
- Audit trail. Financial and privileged actions are recorded with the actor, the time and what changed. Audit records are append-only.
- Backups. Taken on a schedule, held under the same controls as production and restored under test.
- Breach. If a breach affects your data we notify you without undue delay, with what we know, so you can meet your own deadline — 72 hours under both section 25 of the Data Protection Act 2017 and Article 33 of the GDPR.
Retention and deletion
numrow does not apply one global delete age, because financial records do not have one. A record's retention period is the longest of three things: any regulatory obligation that applies to the organisation's jurisdiction, a platform minimum, and any longer period your organisation itself sets. A record is deleted when the last of those has expired and nothing legally holds it.
That means data can outlive a cancelled subscription: an invoice that a tax authority requires to be kept for years is kept for those years, and we cannot delete it earlier at request. Data that is not under such an obligation is deleted when you ask.
A legal hold — a dispute, an investigation — suspends deletion for the records it names until it is lifted.
Making a request
Data-subject requests about your business records come to you, not to us; we give you the tools to find and export the data and will help where the product does not reach. Write to privacy@numrow.com and say which workspace and which records are involved.
Requests about your own numrow account are handled under the Privacy Notice.
Compliance features you control
Some of what a regulator will ask you about is configuration rather than policy: who may see which organisational unit, which fields are masked, how long your entity keeps its records, and who is notified when something is deleted. Those are yours to set in the product, and the audit trail records the setting and who changed it.
Need a signed DPA?
Ask, and we will send the current text for your legal team to review.
Invoice processing, approvals and reconciliation for businesses and the accountants who serve them.