Effective Date: January 15, 2025 | Last Updated: January 15, 2025
The data controller responsible for processing your personal data is:
iPendio, Inc.
580 Howard Street, Suite 210
San Francisco, CA 94105, United States
Email: privacy@ipendio.com
Phone: +1 (415) 829-7143
For matters concerning data protection, you may contact our Privacy Officer directly at privacy@ipendio.com.
We collect and process the following categories of personal data in the course of providing our services:
Full name, business email address, job title, phone number, organization name, and role within the platform. Collected during registration or when an administrator invites a user.
Actions performed within the platform (invoices submitted, approvals granted, reports generated), feature interactions, session timestamps, and workflow configurations.
IP address, browser type, device identifiers, operating system, referring URLs, and access logs. Collected automatically via standard web protocols.
Invoice line items, vendor payment information, purchase order details, and budget allocations submitted by client organizations. iPendio processes this data on behalf of the client (as a data processor) to deliver platform functionality.
We process personal data for the following specific purposes:
Under the General Data Protection Regulation, we rely on the following legal bases:
| Legal Basis | Processing Activity |
|---|---|
| Performance of Contract | Delivering platform services, processing invoices, executing payment workflows, managing user accounts, and sending transactional notifications. |
| Legitimate Interest | Platform security monitoring, fraud prevention, usage analytics (aggregated/anonymized), and infrastructure optimization. |
| Legal Obligation | Tax reporting, financial audit compliance, law enforcement requests, and regulatory obligations. |
| Consent | Optional operational notifications that users may choose to receive (managed via our Notification Preferences page). |
iPendio does not sell, rent, lease, or trade personal data to any third parties. We do not share personal data with advertisers, data brokers, or marketing partners. This commitment applies to all categories of data we collect, including account data, usage data, technical data, and financial data processed on behalf of our clients.
We will never monetize your data or your end users' data. Our revenue comes solely from platform subscription fees.
We engage a limited number of sub-processors to deliver our services. Each sub-processor is contractually bound to equivalent data protection obligations:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, compute, storage, and database hosting (us-west-2, Oregon) | United States |
| Mailgun (Sinch) | Transactional email delivery via SMTP relay for system notifications | United States / EU |
| Stripe, Inc. | Payment processing for subscription billing | United States |
We do not engage additional sub-processors without prior notice to affected clients. A current list of sub-processors is maintained at our Trust Center.
Our primary infrastructure is located within the United States. When personal data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States, we ensure adequate protection through:
We retain personal data only for as long as necessary to fulfill the purposes described in this policy:
| Data Category | Retention Period |
|---|---|
| Account data | Duration of the service relationship + 90 days post-termination for data export |
| Invoice and financial data | 7 years (tax and audit compliance requirements) |
| Usage data | 24 months, then aggregated/anonymized |
| Technical logs | 12 months |
| Email delivery logs | 90 days |
| Security and access audit logs | 12 months |
| Billing records | 7 years (legal requirement) |
After the applicable retention period, data is securely deleted or irreversibly anonymized.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights regarding your personal data:
To exercise any of these rights, contact privacy@ipendio.com. We will respond within 30 days of receiving your verified request. You also have the right to lodge a complaint with your local data protection authority.
If you are a California resident, the California Consumer Privacy Act (CCPA) provides the following rights:
To submit a CCPA request, email privacy@ipendio.com or call +1 (415) 829-7143. We will verify your identity before processing the request and respond within 45 days.
iPendio uses only strictly necessary cookies for platform operation:
We do not deploy:
Because we use only strictly necessary cookies, no cookie consent mechanism beyond acknowledgment is required under GDPR. However, we provide transparent disclosure in our cookie banner.
We implement comprehensive technical and organizational measures to protect personal data:
For additional details, visit our Trust Center.
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or platform functionality. When we make material changes:
Continued use of the platform after the effective date of a revised policy constitutes acceptance of the updated terms.
For privacy-related inquiries, data subject requests, or concerns about our data practices:
Privacy Officer — iPendio, Inc.
580 Howard Street, Suite 210
San Francisco, CA 94105, United States
Email: privacy@ipendio.com
Phone: +1 (415) 829-7143
For general inquiries: info@ipendio.com
For security issues: security@ipendio.com
For abuse reports: abuse@ipendio.com