Last Updated: October 23, 2025
Effective Date: October 23, 2025
DueAgent Ltd ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our invoice management and payment follow-up service.
We are the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller: DueAgent Ltd
Contact Email: privacy@dueagent.com
Data Protection Officer: dpo@dueagent.com
We process your personal data under the following legal bases as defined by GDPR:
You have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you. We will provide this in a machine-readable format within 30 days.
You can correct inaccurate or incomplete personal data through your dashboard or by contacting us.
You can request deletion of your account and personal data. Note: We must retain certain financial records for 7 years to comply with legal obligations.
You can receive your data in JSON format and transfer it to another service provider.
You can object to processing based on legitimate interests, including marketing communications and analytics tracking.
You can request temporary suspension of data processing while we resolve disputes about accuracy or lawfulness.
You can withdraw consent at any time for marketing and analytics. This will not affect processing based on other legal bases.
Exercise Your Rights
Visit your Privacy Settings to export data, manage consents, or delete your account. For assistance, contact privacy@dueagent.com.
We share your data with the following trusted third-party processors under Data Processing Agreements (DPAs):
Purpose: User authentication and session management
Location: United States | DPA: clerk.com/legal/dpa
Purpose: Transactional email delivery to your clients
Location: United States | DPA: resend.com/legal/dpa
Purpose: AI-powered email generation
Location: United States | DPA: anthropic.com/legal/dpa | Zero retention policy
Purpose: Application hosting and database services
Location: Europe (Frankfurt), United States (Oregon) | DPA: render.com/legal/dpa
Purpose: Subscription billing and payment processing
Location: Europe, United States | DPA: stripe.com/legal/dpa
Purpose: Accounting system integration (when you connect)
Location: Per your Xero account | Covered by your Xero agreement
International Data Transfers
Some processors are located in the United States. We use Standard Contractual Clauses (SCCs) and additional safeguards (encryption in transit and at rest) to protect your data during international transfers.
We retain your personal data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Active accounts | Duration of service | Contract performance |
| Closed accounts | 7 years | Legal obligation (accounting) |
| Client records | 7 years post-deletion | Business records requirement |
| Invoices and payments | 7 years | Tax and accounting laws |
| Audit logs | 7 years (anonymized) | GDPR accountability |
| Web analytics | 90 days | Performance optimization |
We implement industry-leading security measures to protect your personal data:
We use cookies and similar technologies for the following purposes:
You can manage your cookie preferences through the cookie banner that appears on your first visit or via your Privacy Settings.
In the unlikely event of a data breach, we will:
DueAgent is a business-to-business (B2B) service not directed at children under the age of 16. We do not knowingly collect personal data from children. If we discover we have inadvertently collected such data, we will delete it immediately and notify the parent or guardian.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:
We encourage you to review this Privacy Policy periodically.
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Email: privacy@dueagent.com
Data Protection Officer: dpo@dueagent.com
Privacy Settings: /dashboard/settings/privacy
You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights. For EU users, you can find your national supervisory authority at:
© 2025 DueAgent Ltd. All rights reserved.