UAE accreditation in progress · Pre-production · Not live as an accredited UAE service provider
Last reviewed · 22 September 2026
Privacy & data protection

Clear roles. Controlled use. Data handled with purpose.

This notice explains how Abzer DMCC handles personal data through the Invocor website and how privacy responsibilities work when Invocor is provided under a customer agreement. It separates public-site activity from customer-controlled e-Invoicing data.

Scope & roles

Responsibility follows the processing activity.

Invocor is developed and owned by Abzer DMCC, Dubai, United Arab Emirates. This notice applies to Invocor’s public website and explains the usual platform model; the signed agreement and data processing terms govern each customer service.

01 · Website

Abzer as controller

For website enquiries, resource requests, communications and site administration, Abzer generally decides why and how personal data is processed.

02 · Customer data

Customer as controller

For invoice, supplier, buyer, user and related business data submitted under a service agreement, the customer generally determines the lawful purpose and instructions.

03 · Contracted service

Abzer as processor

Abzer processes customer-controlled data only to deliver, secure, support and administer the contracted service and meet applicable legal obligations.

04 · Independent duties

Limited controller activity

Abzer may act as controller for its own account administration, security, fraud prevention, legal compliance and corporate records where it determines those purposes.

05 · Other parties

Recipients have their own roles

Buyers, suppliers, networks, access points, authorities and other participants may act under their own legal responsibilities when documents are delivered to them.

06 · Contract prevails

Deployment-specific terms

The applicable order, DPA, architecture and service schedules define the actual parties, systems, locations, instructions and responsibilities.

Data we handle

Only what the interaction or service requires.

The categories depend on how you use the website and how a customer configures Invocor. Customers should avoid submitting unnecessary personal data in documents, free-text fields or support requests.

Enquiries

Name, work contact details, organisation, role, market interests, project context, message content and communication preferences you provide.

Site activity

IP address, browser and device details, timestamps, requested pages, security events and consent records needed to operate and protect the website.

Accounts

Business identity, tenant, entity, branch, role, authentication, access history, preferences and administrator-approved permissions.

Documents

Invoice and related business-document fields, which may include names, contact details, addresses, identifiers and transaction references where supplied.

Integrations

System identifiers, API events, document references, timestamps, validation results, acknowledgements, errors and delivery evidence.

Support

Request details, authorised diagnostic information, correspondence, resolution notes and limited evidence necessary to investigate the issue.

Purpose & lifecycle

Use is limited to a defined purpose.

Customer data remains customer-owned. Abzer’s processing rights are limited to the contracted service, security and support needs, and applicable legal obligations.

01

Collect or receive

Receive data directly from you, an authorised customer, connected system or intended exchange participant through approved channels.

02

Use & deliver

Respond to enquiries or, as contracted, validate, transform, route, report, reconcile and support business documents and service activity.

03

Protect & evidence

Authenticate access, monitor service and security events, investigate issues and maintain the audit history required for accountability.

04

Retain or remove

Apply the relevant enquiry, contract, tax, legal, backup, export, return and deletion requirements when the data is no longer needed.

Legal basis and instructions: for Abzer-controlled processing, the applicable basis may include consent, steps requested before a contract, performance of a contract, legitimate interests or legal obligations. For customer-controlled platform data, Abzer acts on the customer’s documented instructions unless law requires otherwise.
Disclosure & sharing

Data is not a product.

Abzer does not sell or rent personal data, and does not use customer-controlled invoice data for third-party advertising. Disclosure is limited to the purpose, contract and legal context.

Service chain

Authorised recipients

  • Customer-authorised users and connected systems
  • Intended buyers, suppliers and document recipients
  • Exchange-network and access-point participants
  • Tax or public authorities where the service or law requires
Vendors

Subprocessors

  • Hosting and infrastructure providers
  • Security, monitoring and operational tooling
  • Support and communications providers where used
  • Equivalent contractual privacy and confidentiality duties
Legal need

Other permitted disclosure

  • Professional advisers, auditors and insurers
  • Regulators, courts and competent authorities
  • Corporate transactions with appropriate safeguards
  • Protection of rights, systems and users where lawful
Residency & transfers

Location commitments belong to the deployment.

Hosting region, backup geography, support access, subprocessors and permitted international transfers are disclosed for the selected configuration and recorded in the applicable agreement.

Discuss your data requirements ↗
HostingThe final architecture identifies the applicable cloud, primary region, environments and customer-controlled components.
ResidencyA residency requirement applies only where agreed for the specific service and supported by the deployed architecture.
Remote accessAny authorised operational or support access is governed by role, purpose, security controls and the contractual location model.
TransfersCross-border transfers or access occur only where permitted and subject to applicable safeguards, contractual terms and legal requirements.
SubprocessorsRelevant providers, purposes and locations are identified through due diligence and the applicable subprocessor process.
ChangeMaterial changes are handled under the agreement, including any required notice, review or reasonable objection process.
No blanket promiseThis public page does not create a universal hosting country, localisation, retention or transfer commitment.

Customers with UAE, GCC, EEA or other jurisdiction-specific requirements should include them in solution design before contracting and production activation.

Retention & rights

Keep what is necessary. Respect applicable rights.

Retention depends on the data, purpose, customer instruction, applicable tax or legal duty, active disputes and the selected service. Contract schedules define platform retention, export, return and deletion obligations.

Individual requests

Access, correction and control

Subject to applicable law, individuals may have rights to access, correct, erase, restrict or object to processing, withdraw consent, receive portable data, and complain to a competent authority. Rights and exceptions vary by jurisdiction and circumstance.

Customer-controlled data

Start with the customer

If your data was submitted by an Invocor customer, contact that organisation first. Abzer will provide reasonable assistance to the customer in handling a verified request as required by the contract and applicable law.

Verification and limits: Abzer may verify identity, authority and the relevant processing before acting. A request may be limited where another person’s rights, legal privilege, security, statutory retention or another lawful exception applies. Consent can be withdrawn without affecting processing already undertaken lawfully.
Safeguards & transparency

Protection is operational, not absolute.

Abzer applies organisational and technical measures appropriate to the service and risk. No internet or storage system is completely secure, so the applicable security schedule and responsibility matrix remain important.

Access

Identity & scope

MFA, role-based permissions, least privilege, tenant and entity restrictions, and access lifecycle controls.

Protection

Data & environments

Encryption, credential and certificate controls, minimisation, separated environments and restricted production access.

Accountability

Logs & response

Audit history, monitoring, investigation, incident escalation and customer communication under applicable obligations.

Assurance

Scoped evidence

Relevant architecture, control and certification evidence may be reviewed subject to scope, currency and confidentiality.

Cookies and measurement: Invocor may use essential technologies required for security, navigation and requested functionality. Any non-essential analytics or similar technology should be disclosed and, where required, activated only after an appropriate choice. The site does not use customer invoice data for advertising profiles.
Business audience: Invocor is designed for organisations and authorised business users, not children. Abzer does not knowingly solicit personal data from children through the website.
Contact and updates: Privacy enquiries may be sent to privacy@invocor.com or addressed to Abzer DMCC, Jumeirah Lakes Towers, Dubai, United Arab Emirates. This notice may be updated when services, practices or legal requirements change; the review date at the top identifies the current public version.
Privacy questions

Privacy FAQ

Who owns customer data processed through Invocor?

The customer retains ownership of its data. Abzer’s processing rights are limited to the contracted service, security and support needs, and applicable legal obligations.

Does this notice replace the customer DPA?

No. This page provides public transparency. The signed agreement, data processing terms, solution design and service schedules govern the specific customer deployment.

Does Invocor use invoice data for marketing?

No. Customer-controlled invoice data is processed to provide and secure the contracted service, support authorised operations and meet applicable legal obligations—not for third-party advertising.

Where is personal data hosted?

Hosting and residency depend on the selected deployment and market requirements. The final architecture and data schedule should identify the cloud, region, backup geography, subprocessors and permitted access model.

How do I make a privacy request?

For website data, email privacy@invocor.com. For data submitted by an Invocor customer, contact that customer first so it can verify and direct the request; Abzer will support the customer as required.

Which privacy law applies?

That depends on the relevant entity, individual, role, location and processing. Applicable laws may include the UAE Personal Data Protection Law and, for certain international activities, other laws such as the GDPR. This page does not provide legal advice.

Define privacy before production.

Bring your data map, residency needs, retention rules and DPA questions into solution design before contracting and activation.

Plan your rollout ↗