An accounting firm is trusted with everything its clients buy. When the firm uploads those invoices to an AI service, that trust travels with the file. This post is about where it goes.
What actually happens to an uploaded invoice
Most cloud capture tools follow the same path. The document is uploaded to the vendor's storage, passed to an OCR or AI extraction service, which may be the vendor's own or a third party's, the result is stored alongside the image, and both are kept for as long as the vendor's retention policy says, sometimes to improve the vendor's models. Each hop can be in a different country. Whether the extraction service is in Frankfurt, Virginia or Singapore is rarely on the pricing page; it is in the sub-processor list, if there is one.
None of that is sinister. It is how cloud software works. It is also, for an EU accounting firm, a set of GDPR obligations that the firm, not the vendor, is answerable to the client for.
Why an invoice is personal data
A supplier invoice names the person who raised it and the person it is addressed to. If the supplier is a sole trader it carries a home address and a personal IBAN. Expense items carry employee names. Under the GDPR that is personal data, the firm is a processor for its client (or a controller, depending on the engagement), and the AI vendor is a sub-processor. Uploading is processing.
What Article 28 asks of the firm
Article 28 requires a written contract with any processor. It has to set out the subject matter, duration, nature and purpose of the processing, oblige the processor to act only on documented instructions, ensure confidentiality, take appropriate security measures, engage sub-processors only with authorisation and under the same obligations, assist with data subject rights and breach notification, and delete or return the data at the end. If the processing leaves the EU, Chapter V applies as well: an adequacy decision or standard contractual clauses plus a transfer assessment.
In plain terms: before your team forwards a client's invoices to a tool, you should be able to say where they go, who touches them, and under what contract. If the vendor's answer to "where" is "the cloud", that is not an answer.
What Invoreg does
We took the simple route. Every document uploaded to Invoreg is processed and stored on Invoreg infrastructure inside the European Union. The AI that reads it runs there. Documents are not used to train or fine-tune models, ours or anyone else's. Retention is the period you set; deleted documents are recoverable for that period and then removed, and you can export everything at any time. We sign a data processing agreement on request and list our sub-processors and their locations in it. Your accounting software is connected through OAuth with the minimum scopes needed to read vendors, items and accounts and to post bills, and the tokens are stored encrypted and revocable from your accounting software.
Access is role-based down to individual features, every action on a document is logged with who, what and the before and after value, and each client company is a separate organisation that users see only when assigned. The security page has the current wording; ask for the detailed version during a demo.
We do not claim that EU processing makes the GDPR question disappear. It removes the transfer question and makes the sub-processor list short enough to read.
Five questions for any vendor
Where exactly are documents processed and stored, by country? Who are the sub-processors, including the AI or OCR provider, and where are they? Are our documents used to train or improve models, and can we opt out? How long are documents and extracted data retained, and what happens when we delete? Will you sign a DPA that states all of the above?
A vendor that answers the five in writing is a vendor you can put in your engagement letter. Ours are on the security page and in the DPA; contact us for the pack.