SSolarc Labs

InvoiceBatch FR · data processing terms

Customer-controlled processing for a bounded corpus.

Updated 24 August 2026. These terms supplement the InvoiceBatch FR business-service terms when SOLARC GOODS LIMITED processes personal data in a customer-provided invoice corpus on the customer's behalf.

Parties and roles

The customer is the controller to the extent it determines why the supplied corpus is processed. SOLARC GOODS LIMITED is the processor for that instructed corpus processing. Each party remains independently responsible for personal data it processes as a controller for its own administration, payment, legal or security purposes.

1. Processing details

Subject matter: technical validation and corpus-level analysis of the representative UBL, CII and/or Factur-X material supplied for the purchased InvoiceBatch FR scope, including any agreed mapping file, review and bounded re-test.

Nature and purpose: receive the controlled intake, execute the release-pinned preflight, identify deterministic/review findings, support human review, compare an included re-test where purchased, and create the bounded evidence deliverable. The corpus is not used to train a model, advertise to data subjects, build unrelated profiles or make decisions about individuals.

Duration: from accepted intake until the purchased review, included re-test window and reasonably necessary delivery/support handling end, followed by return/deletion as described below unless law requires retention.

Personal-data types that may incidentally occur: names, business contact details, addresses, identifiers appearing on invoices, sole-trader information, invoice/payment references and free-text invoice fields. Customers should not intentionally supply special-category or criminal-offence data unless separately agreed in writing as necessary.

Potential data subjects: customer/supplier staff, business contacts, sole traders and other individuals whose details legitimately appear in the representative business invoice corpus.

2. Documented instructions

Solarc processes customer corpus personal data only for the purchased scope and the customer's saved written instructions, including the accepted intake, source-system scope, engagement reference, review decisions and written support instructions, unless applicable law requires otherwise. If applicable law requires processing outside those instructions, Solarc will inform the customer beforehand unless the law prohibits that notice.

If an instruction would, in Solarc's reasonable view, infringe applicable data-protection law, Solarc may pause the affected processing and inform the customer rather than silently execute it.

3. Confidentiality and access

Access to the controlled corpus is limited to persons who need it to deliver or support the purchased engagement and who are bound by confidentiality obligations. Public website visitors cannot access the operator runtime or customer corpus.

4. Technical and organisational measures

Runtime boundary

The invoice-analysis application binds to loopback by default. Standards validation uses pinned local factur-x, loopback Saxon and a local CodeDB; a public multi-user invoice portal is outside the current service.

Data minimisation

Customers are asked for a representative, minimised corpus. Evidence output records bounded hashes/findings/coverage/review provenance instead of embedding the supplied invoice bodies.

Additional measures include restrictive HTTP/browser security headers on the operator UI, explicit body/file/archive limits and fail-closed input handling, review controls that cannot waive deterministic blockers into a clear result, and release verification before commercial use.

5. Sub-processors

Solarc will not appoint a third party to process the customer invoice corpus on its behalf without the customer's prior specific or general written authorisation. If a corpus-processing sub-processor is proposed under a general authorisation, Solarc will identify the proposed provider/change and give the customer a reasonable opportunity to object before that provider processes the corpus.

Any authorised sub-processor will be bound by data-protection obligations offering materially equivalent protection for the relevant processing. Stripe-hosted payment processing and ordinary website hosting do not receive the customer invoice corpus under the published InvoiceBatch FR flow.

6. Data-subject requests and controller assistance

Taking account of the nature of the processing and information available, Solarc will provide reasonable assistance for the customer to respond to applicable data-subject rights requests concerning corpus personal data processed by Solarc. If such a request is received directly and the customer can be identified, Solarc will ordinarily direct it to the customer unless law requires another response.

7. Security, incidents and DPIA assistance

Solarc will maintain measures appropriate to the current processing risk and, taking account of the nature of processing and information available, provide reasonable assistance relevant to the customer's security, personal-data-breach notification, DPIA and regulator-consultation obligations. Solarc will notify the customer without undue delay after becoming aware of a personal-data breach affecting corpus personal data processed on the customer's behalf.

8. Return or deletion at end of processing

At the end of the processor relationship, and subject to the customer's written choice, Solarc will return or securely delete customer corpus personal data and delete remaining processor copies unless applicable law requires retention. Any copy that cannot immediately be removed from a protected backup/technical recovery layer will be put beyond ordinary use and removed through the applicable deletion cycle.

Accounting, payment, contract, security or dispute records that Solarc must or reasonably needs to retain as an independent controller are outside this processor deletion instruction and remain subject to the applicable retention/privacy rules.

9. Information, audit and compliance evidence

Solarc will make available information reasonably necessary to demonstrate the processor obligations applicable to this engagement and will permit and contribute to reasonable audits or inspections required by applicable data-protection law, subject to appropriate confidentiality, security, scope and non-disruption safeguards. Existing release evidence and documentation should be used first where they can satisfy the request.

10. France / EEA to United Kingdom transfers

The European Commission currently recognises the United Kingdom as providing adequate protection under the GDPR, including the December 2025 renewal. Where an EU/EEA customer transfers corpus personal data to Solarc in the United Kingdom within the scope of that adequacy decision, the parties may rely on that adequacy decision for the international-transfer mechanism while it remains applicable.

If that legal basis ceases to cover a future transfer, the parties must agree an appropriate transfer mechanism before the affected transfer continues.

11. Customer obligations and contact

The customer remains responsible for the lawfulness of its collection and instructions, authority to provide the corpus, selecting representative data, minimising unnecessary personal data and giving any notices required to affected individuals. Data-processing questions can be sent to enoch@solarclabs.com without attaching invoice files to the first email.

Regulatory references

These product terms are designed around the controller/processor contract requirements described by the UK Information Commissioner and the current EU adequacy status for the United Kingdom. They do not replace a customer's own legal assessment of its role or processing.