Skip to content
Temlavo
PlaygroundDocsPricingSecurity
Sign inStart free trial
PlaygroundDocsPricingSecuritySign inStart free trial

Legal

Data Processing Addendum

This Data Processing Addendum (DPA) describes how Temlavo processes personal data on behalf of a customer when providing invoice extraction and related service functionality.

Last updated: 29 September 2026Service operated from Cyprus

On this page

  1. Scope and roles
  2. Customer instructions
  3. Confidentiality
  4. Security measures
  5. Subprocessors
  6. Data-subject requests
  7. Security incidents
  8. Compliance assistance
  9. Return and deletion
  10. Compliance information
  11. International transfers
  12. Processing details
  13. Contact

1. Scope and roles

This DPA applies when a customer uses Temlavo to process personal data contained in invoices, supporting documents, submitted metadata, callback configuration, or structured results and Temlavo acts as a processor on the customer's behalf.

The customer is the controller, or a processor authorized by the relevant controller, for that customer personal data. Temlavo is the processor or subprocessor, as applicable. Each party remains responsible for the personal data it processes for its own independent purposes, such as account administration, security, billing, fraud prevention, and legal compliance.

2. Customer instructions

Temlavo will process customer personal data only on documented instructions from the customer, including the instructions inherent in using the API, SDK, CLI, account controls, configured callbacks, and documented service features.

If Temlavo is required by applicable law to process customer personal data beyond those instructions, Temlavo will inform the customer before doing so unless the law prohibits that notice.

The customer is responsible for ensuring its instructions comply with applicable law and that it has the rights, notices, permissions, and lawful bases needed to provide the data to Temlavo.

3. Confidentiality

Temlavo will limit access to customer personal data to people and service providers who need that access to provide, secure, maintain, or support the service and who are subject to appropriate confidentiality obligations.

4. Security measures

Temlavo maintains technical and organizational measures designed to protect customer personal data against unauthorized access, disclosure, alteration, loss, or destruction, appropriate to the nature of the service and the risks of processing.

  • account-scoped authorization and server-side API credentials;
  • private source and processing-object storage;
  • short-lived signed upload capabilities;
  • encrypted protected application state and secret management;
  • bounded source, intermediate, result, and operational retention;
  • privacy-minimized application logging and operational telemetry;
  • rate, abuse, and provider-spend safeguards;
  • dependency, migration, contract, and release verification;
  • document deletion and retention-cleanup paths; and
  • operational monitoring, recovery, and incident-response procedures.

The public Security & retention page describes additional product boundaries.

5. Subprocessors

The customer gives general authorization for Temlavo to use the subprocessors needed to provide the service. Temlavo will impose data-protection obligations appropriate to the services each subprocessor performs.

Before a material addition or replacement that affects customer personal data, Temlavo will provide notice through the customer's account email or another service notice, giving the customer an opportunity to raise a reasonable data-protection objection. Questions or objections may be sent to privacy@temlavo.com.

Temlavo's direct subprocessors

Direct subprocessorPurposeCustomer data involved
VercelApplication hosting and runtimeApplication requests and service data needed to operate the API and web service, including request and callback destination metadata in platform logs
SupabaseDatabase and private object storageCustomer service records, source files, and short-lived processing artifacts
MistralDocument OCR processingSubmitted invoice and document content
OpenRouterStructured AI processing and privacy-controlled model routingDocument-derived content needed for extraction, with routing controls requiring zero data retention, no data collection for training, disabled response caching, and no content-mutating tools or plugins
SentryService diagnostics and error monitoringAllowlisted account, document, run, and request identifiers, statuses, error codes, timings, and page counts; no invoice content or provider response bodies

OpenRouter model routing

OpenRouter dynamically routes document-derived content to downstream model providers under the privacy controls listed above. Provider availability can change, and the provider used may vary by request. OpenRouter's directory includes providers outside Temlavo's eligible routing pool; Temlavo's requests require ZDR-compatible endpoints. See OpenRouter's provider directory and zero-data-retention routing documentation.

6. Data-subject requests

Taking into account the nature of the processing, Temlavo will provide reasonable assistance to help a customer respond to requests by individuals exercising applicable data-protection rights where the relevant personal data is processed through the service and the customer cannot address the request using available service functionality.

If Temlavo receives a request relating to customer personal data for which the customer is the controller, Temlavo may direct the requester to the customer unless prohibited by law.

7. Personal-data incidents

Temlavo will notify affected customers without undue delay after becoming aware of a confirmed personal-data breach involving customer personal data processed by Temlavo, to the extent required by applicable data-protection law.

Temlavo will provide information reasonably available to it that customers need to meet applicable breach-assessment and notification obligations, subject to security and confidentiality constraints.

8. Compliance assistance

Taking into account the nature of the processing and information available to Temlavo, Temlavo will provide reasonable assistance with applicable security, breach-notification, data-protection impact assessment, and supervisory-authority consultation obligations that relate to Temlavo's processing of customer personal data.

9. Return and deletion

Temlavo is designed as a short-retention processing service rather than a long-term invoice archive. Confirmed source files and processing intermediates have a 24-hour default expiry from each stored object's creation. Unconfirmed uploads expire 24 hours after document creation. Structured document results expire seven days from completion by default, ending API access to the result.

These are expiry deadlines. Temlavo removes expired content through retention cleanup, which may follow expiry while processing recovery or storage-deletion retries complete. Explicit document deletion ends document API access and clears stored results and document fields; storage deletion is attempted immediately and retried if needed.

Individual document deletion does not remove the account's separate discovery index of raw accounting-entity IDs and first/last-seen timestamps. That index is retained for the active account lifetime, has no automatic expiry, and is subject to the end-of-service return and deletion obligations below. Account closure is separate from subscription cancellation and document deletion. Requests may be sent to privacy@temlavo.com.

Customers can retrieve retained structured results through the API during the documented retention window and can explicitly delete a document through the API. At the end of the relevant service relationship, and at the customer's choice where applicable processor law requires it, Temlavo will delete customer personal data or make retained customer data available for return through supported service functionality before deletion. This is subject to applicable law requiring retention and to content-free security, billing, or legal records that must be preserved.

Document deletion does not delete Vercel's platform logs, including request metadata and callback destinations, which follow a separate retention policy. See the Privacy Notice.

10. Compliance information

Temlavo makes available information reasonably necessary to demonstrate compliance with applicable processor obligations through current security documentation, subprocessor and retention disclosures, relevant contractual information, and reasonable written responses.

Compliance requests should use available documentation and written responses first. Any further audit request must be reasonably necessary to satisfy applicable processor law, use reasonable advance notice, minimize disruption and cost, protect other customers, security controls, confidential information, and service availability, and avoid unnecessary access to production systems or customer content. Temlavo may use independent audit reports or equivalent evidence where they reasonably address the requested subject.

11. International transfers

Temlavo is operated from Cyprus and uses service providers that may process customer personal data in other countries. For information about provider locations and applicable transfer arrangements, contact privacy@temlavo.com.

12. Processing details

Subject matter
Processing invoices and related documents to provide structured extraction, consistency checks, duplicate signals, result delivery, and related support and security functions.
Duration
For the customer's use of the service and the documented retention periods, subject to earlier deletion and legally required retention.
Nature and purpose
Receiving, storing, reading, transmitting, extracting, structuring, checking, returning, securing, troubleshooting, and deleting customer-submitted data as needed to provide the service.
Categories of data subjects
Customer personnel and users; vendors, customers, sole traders, employees, contractors, contacts, or other individuals whose information appears in submitted invoices or related documents.
Types of personal data
Contact and account information; invoice identifiers; names, business/contact details and addresses; line-item and financial information; tax or registration identifiers; document metadata; customer-supplied metadata; and any other personal data included by the customer in submitted documents.
Special-category data
The service is not designed for intentional processing of special categories of personal data. Customers should avoid submitting such data unless it is genuinely necessary, lawful, and appropriate for the supported invoice-processing purpose.

13. Contact

Privacy and DPA questions: privacy@temlavo.com

Security reports: security@temlavo.com

Country of establishment: Cyprus

TemlavoInvoice Extraction API
DocsSDK on npm (opens in a new tab)SecurityPrivacyTermsContact supportSign in

© Temlavo