Data Processing Policy

Review how Oxiom processes invoice, financial, and account data when delivering the Oxiom Invoice Processing platform to enterprise customers.

Data Controller vs Processor

Customers generally act as the data controller for personal data and business records they submit to Oxiom Invoice Processing. Oxiom acts as a processor or service provider when handling that data on the customer’s behalf, except where Oxiom determines purposes and means independently for security, legal, or business administration needs.

Processing Activities

Processing activities may include secure receipt, storage, extraction, validation, indexing, workflow routing, approval history capture, analytics, support diagnostics, and export of invoice-related records as required to operate the platform.

Legal Basis

Where applicable, Oxiom relies on legal bases such as contract performance, legitimate interests, compliance with legal obligations, and customer instructions documented in applicable agreements or platform configurations.

Retention

Data is retained according to customer instructions, contractual commitments, operational needs, audit requirements, and applicable law, including active storage, archive periods, and controlled deletion processes.

Sub-processors

Oxiom may engage sub-processors for cloud hosting, observability, support tooling, and other operational services required to deliver the platform, subject to appropriate contractual and security obligations.

Data Transfers

Where personal data is transferred across borders, Oxiom applies appropriate transfer safeguards such as contractual commitments, organizational controls, and technical protections.

Security Measures

Oxiom maintains role-based access controls, encryption in transit and at rest, logging, monitoring, vulnerability management, and incident-response procedures designed to protect invoice and financial data.