Abzer as controller
For website enquiries, resource requests, communications and site administration, Abzer generally decides why and how personal data is processed.
This notice explains how Abzer DMCC handles personal data through the Invocor website and how privacy responsibilities work when Invocor is provided under a customer agreement. It separates public-site activity from customer-controlled e-Invoicing data.
Invocor is developed and owned by Abzer DMCC, Dubai, United Arab Emirates. This notice applies to Invocor’s public website and explains the usual platform model; the signed agreement and data processing terms govern each customer service.
For website enquiries, resource requests, communications and site administration, Abzer generally decides why and how personal data is processed.
For invoice, supplier, buyer, user and related business data submitted under a service agreement, the customer generally determines the lawful purpose and instructions.
Abzer processes customer-controlled data only to deliver, secure, support and administer the contracted service and meet applicable legal obligations.
Abzer may act as controller for its own account administration, security, fraud prevention, legal compliance and corporate records where it determines those purposes.
Buyers, suppliers, networks, access points, authorities and other participants may act under their own legal responsibilities when documents are delivered to them.
The applicable order, DPA, architecture and service schedules define the actual parties, systems, locations, instructions and responsibilities.
The categories depend on how you use the website and how a customer configures Invocor. Customers should avoid submitting unnecessary personal data in documents, free-text fields or support requests.
Name, work contact details, organisation, role, market interests, project context, message content and communication preferences you provide.
IP address, browser and device details, timestamps, requested pages, security events and consent records needed to operate and protect the website.
Business identity, tenant, entity, branch, role, authentication, access history, preferences and administrator-approved permissions.
Invoice and related business-document fields, which may include names, contact details, addresses, identifiers and transaction references where supplied.
System identifiers, API events, document references, timestamps, validation results, acknowledgements, errors and delivery evidence.
Request details, authorised diagnostic information, correspondence, resolution notes and limited evidence necessary to investigate the issue.
Customer data remains customer-owned. Abzer’s processing rights are limited to the contracted service, security and support needs, and applicable legal obligations.
Receive data directly from you, an authorised customer, connected system or intended exchange participant through approved channels.
Respond to enquiries or, as contracted, validate, transform, route, report, reconcile and support business documents and service activity.
Authenticate access, monitor service and security events, investigate issues and maintain the audit history required for accountability.
Apply the relevant enquiry, contract, tax, legal, backup, export, return and deletion requirements when the data is no longer needed.
Abzer does not sell or rent personal data, and does not use customer-controlled invoice data for third-party advertising. Disclosure is limited to the purpose, contract and legal context.
Hosting region, backup geography, support access, subprocessors and permitted international transfers are disclosed for the selected configuration and recorded in the applicable agreement.
Discuss your data requirements ↗Customers with UAE, GCC, EEA or other jurisdiction-specific requirements should include them in solution design before contracting and production activation.
Retention depends on the data, purpose, customer instruction, applicable tax or legal duty, active disputes and the selected service. Contract schedules define platform retention, export, return and deletion obligations.
Subject to applicable law, individuals may have rights to access, correct, erase, restrict or object to processing, withdraw consent, receive portable data, and complain to a competent authority. Rights and exceptions vary by jurisdiction and circumstance.
If your data was submitted by an Invocor customer, contact that organisation first. Abzer will provide reasonable assistance to the customer in handling a verified request as required by the contract and applicable law.
Abzer applies organisational and technical measures appropriate to the service and risk. No internet or storage system is completely secure, so the applicable security schedule and responsibility matrix remain important.
MFA, role-based permissions, least privilege, tenant and entity restrictions, and access lifecycle controls.
Encryption, credential and certificate controls, minimisation, separated environments and restricted production access.
Audit history, monitoring, investigation, incident escalation and customer communication under applicable obligations.
Relevant architecture, control and certification evidence may be reviewed subject to scope, currency and confidentiality.
The customer retains ownership of its data. Abzer’s processing rights are limited to the contracted service, security and support needs, and applicable legal obligations.
No. This page provides public transparency. The signed agreement, data processing terms, solution design and service schedules govern the specific customer deployment.
No. Customer-controlled invoice data is processed to provide and secure the contracted service, support authorised operations and meet applicable legal obligations—not for third-party advertising.
Hosting and residency depend on the selected deployment and market requirements. The final architecture and data schedule should identify the cloud, region, backup geography, subprocessors and permitted access model.
For website data, email privacy@invocor.com. For data submitted by an Invocor customer, contact that customer first so it can verify and direct the request; Abzer will support the customer as required.
That depends on the relevant entity, individual, role, location and processing. Applicable laws may include the UAE Personal Data Protection Law and, for certain international activities, other laws such as the GDPR. This page does not provide legal advice.
Bring your data map, residency needs, retention rules and DPA questions into solution design before contracting and activation.