PROradius Invoicing PROradius Invoicing
Privacy Terms Data deletion

Privacy Policy

What personal data PROradius Invoicing collects, why, who we share it with, and the rights you have over it.

Effective 21 August 2026  ·  Last updated 21 August 2026

This policy explains what personal data PROradius Invoicing collects, why we collect it, who we share it with, and what rights you have. It covers the PROradius Invoicing web application, mobile apps, and client portal (together, the "Service"), operated by PROradius Invoicing ("we", "us"), registered in Lebanon, with its registered office in Beirut, Lebanon.

The most important thing to understand

PROradius Invoicing is business software. Our customers are businesses, and they use it to manage their own customers. So there are two very different relationships:

  • For our business customers and their staff, we are the controller — we decide how their data is used, and this policy governs it.
  • For their customers (people who receive an invoice from a business using PROradius Invoicing), we are only the processor. The business decides what to record and for how long. If your details are in the Service because a company invoices you, contact that company first — see section 9.

1. What we collect

1.1 Information you give us when you sign up

To create and run an account we collect, about each user:

  • name and email address;
  • a password, which we store only as a cryptographic hash — we never see it;
  • optionally, a profile photo;
  • if you enable two-factor authentication, the secret and recovery codes needed for it;
  • your organization's name, branding, and settings.

We do not ask for a staff member's phone number, date of birth, or any government identification document at sign-up.

1.2 Information you enter about your own customers

This is data you control. Depending on what you choose to record, the Service can store the following about each of your clients:

CategoryFields
IdentitySalutation, name, username, a reference or code you assign
ContactEmail address, phone number
AddressCountry, city, zone, street, building, box number, postal address
Precise location GPS coordinates of the client's premises, where you record them
Portal accessA hashed password, if you enable portal login for them
PreferencesPreferred language, agreed payment method, billing due day
FinancialInvoices, payments, balances, deposits, wallet activity, discounts
Service recordsSubscribed services, meter and odometer readings, support tickets
VisitsWhere your staff recorded a visit: GPS coordinates, timestamp, notes

We do not require, and the Service has no dedicated field for, national identity numbers, passport numbers, or dates of birth.

You decide what goes in. Because free-text fields exist, you could enter sensitive information into them. Please don't — the Service is not designed to hold special categories of data such as health or biometric information, and you would be responsible for the consequences of putting it there.

1.3 Information collected automatically

  • Technical data — IP address, browser and device type, operating system version, app version, and the pages or endpoints you use.
  • Activity logs — a record of who changed what and when, which the Service keeps so your organization has an audit trail.
  • Device data for notifications — if you install our mobile app, a push token plus the device model, platform, and app version.
  • Product analytics — which screens you open and when, and events such as completing a step of the setup wizard. We use this to find where the Service confuses people. Session recordings mask all page text — not only what you type, but names, amounts and contact details as they appear on screen. We see the shape of a page and where you clicked, not the data on it. We also do not record every session: new accounts are recorded during their first week so we can find what confuses people at the start, after which only a small sample of sessions is kept. Collector and Cashier accounts are never session-recorded at all, because those roles work from shared vans and POS terminals.
  • Cookies — see our cookie notice. We use cookies to keep you signed in, to keep the Service secure, and for product analytics. We do not use advertising or cross-site tracking cookies.

2. Why we use it

PurposeWhat this involves
Providing the ServiceCreating accounts, generating invoices, recording payments, keeping your books
Sending messages you ask us to sendInvoice and payment reminders to your clients over WhatsApp, SMS, or email
Billing youCalculating subscription fees, issuing our invoices, collecting payment
SupportAnswering your questions and investigating faults you report
Security & fraud preventionDetecting unauthorised access, abuse, and suspicious activity
Improving the ServiceUnderstanding which features are used, diagnosing errors, capacity planning
Legal complianceKeeping accounting records and responding to lawful requests

We do not sell personal data, and we do not use your data or your clients' data to serve advertising.

3. Legal basis for processing

We process personal data under Lebanese Law No. 81/2018 on Electronic Transactions and Personal Data. Where the EU or UK GDPR applies to you, our legal bases are:

  • Performance of a contract — to provide the Service you signed up for.
  • Legitimate interests — to secure the Service, prevent fraud, and improve our product, balanced against your rights.
  • Legal obligation — to keep accounting records and comply with lawful requests.
  • Consent — where we ask for it specifically, such as for optional integrations. You can withdraw consent at any time.

For data about your own clients, you are responsible for establishing the legal basis, and we process it on your documented instructions.

4. Who we share it with

We share personal data only with the service providers listed below, only to the extent needed to run the Service, and under contracts requiring them to protect it. This list is accurate as of the effective date of this policy.

4.1 Always used

ProviderPurposeDataLocation
Amazon Web Services Application and database hosting, file storage, and backups All Service data, including uploaded files and attachments European Union (Frankfurt)
ResendSending transactional email Recipient address, subject, message body, attachmentsUnited States
ExpoMobile push notifications Push token, notification title and bodyUnited States

4.2 Used only if you enable them

These are optional integrations. Nothing is sent unless you connect them and supply credentials.

ProviderPurposeData sent
Meta (WhatsApp Business Platform)Official WhatsApp messaging Recipient phone number, template name and language, message variable values, and invoice documents where attached
Whaply · WassengerWhatsApp messaging (unofficial providers) Recipient phone number, full message body, and a link the provider fetches to retrieve an attached invoice
Globe SMS · BestSmsBulkSMS delivery Recipient phone number, full message body
Whish MoneyOnline payment collection Amount, currency, invoice number, your organization name. We do not send your client's name, email, or address. Whish returns the payer's phone number to us to reconcile the payment.
AnthropicAI assistant — see section 5 Your questions, and records the assistant retrieves to answer them, which can include client contact details and financial data
TuyaSmart meter and breaker control Device identifiers, energy readings, connect/disconnect commands
PostHog (EU region)Product analytics — understanding how the Service is used Your user id, name, email, role, and organization, together with the screens you visit and in-app events. Session recordings mask all page text, so client names and financial figures are not transmitted, and Collector and Cashier accounts are not recorded at all. Hosted in the European Union. Analytics requests are routed through Cloudflare, which already serves this Service, so they reach PostHog from our own domain rather than a third-party one.

4.3 Two small technical disclosures

In the interest of being complete rather than merely compliant: the Service generates placeholder avatar images through ui-avatars.com, which means a client's or user's name appears in the image address your browser requests. Printed receipts render a QR code through api.qrserver.com, which receives the invoice number. Neither receives contact details or financial data, and we are working to bring both in-house.

4.4 Other disclosures

  • Legal requirements — where we are required by law, court order, or a competent authority.
  • Business transfer — if we are involved in a merger, acquisition, or sale of assets, data may transfer to the successor, who remains bound by this policy. We will notify you.
  • With your instruction — anyone else you explicitly ask us to share with.
Not on this list, deliberately: we do not use advertising networks and we do not sell your data. Our one analytics provider, PostHog, is named in the table above and hosted in the EU. Payment methods such as OMT and BOB Finance are recorded in the Service purely as bookkeeping entries — we send them no data at all.

5. AI features

Please read this before enabling the AI assistant.

The assistant answers questions about your business by retrieving your records and sending them to an external AI provider. When you ask something like "what does this client owe?", the assistant looks the client up and transmits the retrieved details — which can include name, email address, phone number, and postal address, alongside invoice and payment data — to Anthropic so it can compose an answer.

Specifics:

  • The assistant is off unless you enable it and supply an API key.
  • Only data your own account is already permitted to see can be retrieved.
  • Conversation history is stored in your account so you can revisit past threads.
  • Actions that change data — such as creating an invoice — always require your explicit confirmation.
  • Your use of the provider is governed by that provider's terms and privacy policy in addition to this one.

If you would rather no client data ever left the Service for this purpose, simply leave the AI assistant disabled. Every other feature works without it.

6. Messaging, WhatsApp, and delivery records

When you send a reminder, the recipient's phone number and the message content go to whichever messaging provider you have connected. We also keep a local record of each message — the recipient, the rendered text, the delivery status, and the provider's response — so you have a history of what was sent and can investigate failures.

Where you attach an invoice, some providers retrieve the document from a link rather than receiving the file directly, which means the document is briefly reachable by that provider.

If you connect an official WhatsApp Business Account, Meta processes those messages under its own terms, sends us delivery and read receipts, and bills you directly for conversations. Inbound replies from your clients are also received and stored so we know whether a reply window is open.

7. Staff location tracking

If you are a collector or field agent, this section is about you.

The Service includes optional location tracking for staff who collect payments in the field. Where an organization enables it, the app records the device's GPS coordinates, accuracy, speed, and battery level, together with the time.

Employers use this to dispatch the nearest collector and to reconcile cash collections. Location history is deleted automatically after a retention period the organization sets.

If you are an employee: your employer, not us, decides whether to enable this and for how long to keep the data. Employers are responsible for telling their staff that tracking is on, and for having a lawful basis for it. If you have questions about tracking on your device, ask your employer; you may also contact us and we will point you to the right person.

8. How long we keep it

DataRetention
Account and business recordsFor as long as your account is active
After you close your accountDeleted within 30 days; backups within 90 days
Our invoices to you and payment records10 years, as required by Lebanese law
Staff location historyA retention period each organization sets, after which it is purged automatically
Message and delivery logsFor the life of the account, unless you delete them sooner
Security and audit logs12 months
Encrypted backupsRotated out within 90 days

You can delete most records yourself at any time. Note that paid invoices are voided rather than erased so your ledger stays balanced — an accounting requirement, not a refusal to act on your request. Full instructions are on our Data Deletion page.

9. If you received an invoice from a business using PROradius Invoicing

Your details are in the Service because that business put them there. They decide what to record, what to send you, and how long to keep it. We only store and process it on their behalf, and we cannot delete or amend their business records on our own initiative.

So:

  1. Contact the business that invoices you — they can correct or delete your record directly.
  2. To stop receiving messages, reply to the message asking to opt out, or tell them directly.
  3. If they do not respond, contact us at [email protected]. We will pass your request on, require them to deal with it, and tell you what happened.

10. Your rights

Subject to applicable law, you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have data deleted, where we are not required to keep it.
  • Restriction — ask us to limit processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on our legitimate interests.
  • Withdraw consent — where processing relies on consent, without affecting what was done beforehand.

To exercise any of these, email [email protected]. We respond within 30 days and will verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

11. How we protect it

  • Traffic is encrypted in transit using TLS.
  • Passwords are stored only as salted hashes; we cannot recover them.
  • Integration credentials and access tokens are encrypted at rest.
  • Access is controlled by role and permission, and each organization's data is isolated from every other organization's.
  • Backups are encrypted.
  • Two-factor authentication is available, and we recommend enabling it.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights, we will notify you and the competent authority without undue delay, and in any event within 72 hours of becoming aware of it where the law requires.

To report a vulnerability, email [email protected]. We welcome responsible disclosure and will not pursue researchers who act in good faith.

12. International transfers

We are based in Lebanon, and some of the providers in section 4 operate outside it — notably in the European Union and the United States. Where data is transferred out of a jurisdiction whose law restricts it, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

13. Children

The Service is business software and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has been provided to us, contact us and we will delete it.

14. Changes to this policy

We may update this policy. For material changes — such as adding a new category of recipient — we will give notice by email or in the Service at least 30 days before they take effect. The effective date at the top of this page always shows the current version.

15. Contact us

PROradius Invoicing

Beirut
Lebanon

Privacy enquiries and data requests: [email protected]
Security reports: [email protected]
General: [email protected]

If you are unhappy with our response, you may complain to the Ministry of Economy and Trade in Lebanon, which supervises Law No. 81/2018. If you are in the European Economic Area or the United Kingdom, you may complain to your local data protection authority.

See also our Terms of Service and Data Deletion instructions.

© 2026 PROradius Invoicing. All rights reserved.

Home Privacy Terms Data deletion