<TRANSFORM/STUDIO>
Validate an invoice
Menu
Data handling and security

What happens to your invoice data.

Operational summary for validation users, clients and procurement review. Last reviewed: July 2026. Questions or deletion requests: portal@transformstudio.io.

60 minutesConfigured temporary-upload window for the free validator.
2555 days (about 7 years)Default engagement retention setting, subject to contract and legal hold.
No training useClient files are not used to train machine-learning models.
Important: payload validation requires temporary server-side processing. The free validator is not a document vault. For highly sensitive invoices, use the in-browser anonymizer before upload.

1. Free validation

The service receives the uploaded XML, writes a temporary copy, executes the selected validation pipeline and returns the report. Temporary files become eligible for cleanup after the configured 60-minute window. Creating a work package moves the selected source and validation evidence into the engagement record.

2. Paid engagement records

A governed engagement can include uploaded source files, validation evidence, messages, quotes, contract approvals, corrected files, reports, release manifests and acceptance records. These records are retained to perform the purchased work and preserve its audit trail.

The default configured retention period is 2555 days (about 7 years). The engagement may specify a different period, and legal hold can suspend deletion. Destructive deletion remains an operator-reviewed action.

3. Storage and access

  • Production deployment is designed for Australian-region infrastructure and encrypted HTTPS transport.
  • Application access is limited to authorised operators and the authenticated client portal.
  • Invoice files are not attached to routine notification emails; the email provider receives message and recipient data only.
  • Exact subprocessors and hosting arrangements should be confirmed in the engagement agreement or procurement response.

4. Anonymization

The browser-based anonymizer replaces party identifiers and contact details on the device before upload while preserving monetary values, codes and XML structure. A Python CLI is also available for batch use and internal security review.

5. Use and disclosure

Files are used to provide the validation, remediation, transformation, rendering or assurance service requested by the client. They are not sold, used for advertising or used to train a model. De-identified aggregate operational patterns may inform service guidance only where no client or transaction can be recognised.

6. Deletion and incidents

Deletion requests are reviewed against the engagement contract, outstanding delivery obligations and legal hold. Where an incident affects client data, notifications and regulatory steps are handled according to the applicable law, contract and incident-response process.

7. Assurance boundary

This page describes the current application and supported operating model. It is not legal advice, a data-processing agreement or a substitute for the terms agreed for a specific engagement.