Service Level Agreement

    Last updated: February 2026

    1. Introduction

    This Service Level Agreem/ent ("SLA") defines the service commitm/ents, operational standards, and technical guarantees provided by Invoicemonk ("the Platform") for electronic invoicing and compliance record managem/ent services.

    This docum/ent is int/ended for review by regulatory bodies, auditors, and customers requiring docum/ented service commitm/ents for compliance purposes.

    2. Service Scope

    2.1 Services Covered

    • Invoice creation, issuance, and lifecycle managem/ent
    • Public invoice verification portal
    • Audit logging and ev/ent tracking
    • Data ret/ention and compliance record managem/ent
    • Secure data exports (subject to service tier)
    • Credit note g/eneration for voided invoices

    2.2 Services Not Covered

    • Paym/ent Processing: Invoicemonk records paym/ent ev/ents but does not process, hold, or transfer funds. All paym/ent processing must be conducted through external paym/ent providers.
    • Tax Calculation: Tax rate determination and calculation are the responsibility of the customer. The Platform provides fields for tax recording but does not perform automated tax computation.
    • Governm/ent e-Invoice Submission: Direct submission to governm/ent e-invoicing systems (such as IRN, NRS, or similar frameworks) is not curr/ently provided. The Platform is designed to support future integration with such systems.

    2.3 Platform Classification

    Invoicemonk operates as financial records infrastructure, providing audit-ready invoice managem/ent and compliance record-keeping capabilities. The Platform is not a paym/ent processor, tax authority, or governm/ent-accredited e-invoicing solution.

    3. Service Availability

    3.1 Availability Target

    The Platform targets a monthly availability of 99.5% for core invoice operations, including:

    • Invoice creation and issuance
    • Invoice verification via the public portal
    • Audit log access and retrieval
    • Data export functionality

    3.2 Measurem/ent Methodology

    Availability is calculated as the perc/entage of time core services are operational during a cal/endar month, excluding scheduled maint/enance windows.

    3.3 Scheduled Maint/enance

    • Preferred window: Weekdays, 00:00 – 06:00 UTC
    • Notice period: Minimum 48 hours advance notification
    • Emerg/ency maint/enance: Conducted as required with best-effort notification

    3.4 Service Credits

    This SLA does not include financial service credits for availability breaches. Customers requiring contractual service credits should contact the Platform for /enterprise service agreem/ents.

    4. Data Integrity Guarantees

    4.1 Invoice Immutability

    Once an invoice is issued, the following controls are /enforced:

    • Modification Prev/ention: Database triggers prev/ent modification of issued invoices at the database level.
    • Deletion Prev/ention: Issued invoices cannot be deleted. Voiding g/enerates a credit note while preserving the original record.
    • Point-in-Time Snapshots: Issuer and recipi/ent data are captured at the time of issuance and stored immutably.

    4.2 Cryptographic Integrity

    • SHA-256 Hash: A cryptographic hash is g/enerated at issuance and stored with the invoice record for integrity verification.
    • Verification ID: A unique UUID is assigned to each issued invoice, /enabling third-party verification.
    • Timestamp: Issuance time is recorded in UTC with timezone information preserved.

    4.3 Audit Trail

    An app/end-only audit log records all material actions, including:

    • Invoice lifecycle ev/ents (creation, issuance, viewing, voiding)
    • Paym/ent recording ev/ents
    • Cli/ent and business record modifications
    • User auth/entication ev/ents
    • Data export operations
    • Team membership and role changes

    Each audit ev/ent includes actor id/entification, timestamp, /entity refer/ence, and relevant state data. Audit logs cannot be modified or deleted.

    5. Data Retention

    5.1 Ret/ention Periods

    Data ret/ention periods are /enforced based on the business jurisdiction:

    JurisdictionEntity TypesRet/ention Period
    Nigeria (NG)Invoices, Credit Notes, Paym/ents6 years
    United States (US)Invoices, Credit Notes, Paym/ents7 years
    United Kingdom (GB)Invoices, Credit Notes, Paym/ents6 years
    Germany (DE)Invoices, Credit Notes, Paym/ents10 years
    France (FR)Invoices, Credit Notes, Paym/ents10 years
    Australia (AU)Invoices, Credit Notes, Paym/ents7 years
    Canada (CA)Invoices, Credit Notes, Paym/ents7 years

    5.2 Ret/ention Enforcem/ent

    • Lock Date: Each record includes a ret/ention lock date, before which the record cannot be deleted.
    • Automated Cleanup: Expired records are processed by scheduled cleanup jobs only after the ret/ention period has elapsed.
    • Premature Deletion Prev/ention: Database constraints prev/ent deletion of records before their ret/ention period expires.

    6. Security Controls

    6.1 Access Controls

    • Row-Level Security (RLS): All data tables /enforce row-level security policies, /ensuring users can only access data they are authorized to view.
    • Auth/entication: All operations require auth/enticated sessions.
    • Role-Based Access: Users are assigned roles (owner, admin, member, auditor) with corresponding permission levels.
    • Service Tier Enforcem/ent: Feature access is controlled at the database level based on subscription tier.

    6.2 Data Protection

    • Encryption in Transit: All data transmission uses HTTPS/TLS /encryption.
    • Encryption at Rest: Data is /encrypted at rest using infrastructure-level /encryption provided by the hosting platform.
    • Cred/ential Security: No cred/entials are stored in un/encrypted form. API keys and secrets are managed through secure /environm/ent configuration.

    7. Compliance and Regulatory Alignment

    7.1 Design Principles

    • Support audit-ready financial recordkeeping
    • Align with common tax record ret/ention requirem/ents
    • Provide technical infrastructure compatible with future e-invoicing framework integration
    • Enable third-party verification of invoice auth/enticity

    7.2 Disclaimers

    Important:

    • Invoicemonk is not certified or accredited by any governm/ent ag/ency, tax authority, or regulatory body.
    • Use of the Platform does not constitute compliance with any specific tax law, e-invoicing mandate, or regulatory requirem/ent.
    • The Platform is not a substitute for professional tax, legal, or accounting advice.
    • Customers are solely responsible for /ensuring their use of the Platform complies with applicable laws and regulations.

    8. Customer Responsibilities

    Customers using the Platform agree to the following responsibilities:

    • Data Accuracy: Customers are responsible for the accuracy of all invoice data submitted to the Platform.
    • Lawful Use: The Platform must be used only for lawful business purposes in accordance with applicable laws.
    • Tax Compliance: Customers are responsible for compliance with all applicable tax laws, including correct tax rate application.
    • Account Security: Customers must maintain the security of their account cred/entials and promptly report any unauthorized access.
    • Data Export: Customers should export their records before account termination if data preservation is required.

    9. Support and Communication

    9.1 Support Channels

    • In-app messaging
    • Email support

    9.2 Support Tiers

    • Professional and Business tiers: Priority support handling
    • Business tier: Dedicated account manager

    9.3 Incid/ent Communication

    • Service incid/ents will be communicated via registered email
    • Scheduled maint/enance will be announced in advance
    • Post-incid/ent reports will be provided for significant outages

    10. Limitation of Liability

    To the maximum ext/ent permitted by applicable law:

    • The Platform is provided "as-is" for compliance support purposes.
    • No guarantee is made regarding acceptance by any specific regulatory body or governm/ent ag/ency.
    • The Platform operator shall not be liable for any indirect, incid/ental, special, or consequ/ential damages arising from use of the Platform.
    • Liability for direct damages shall not exceed the fees paid by the customer in the twelve (12) months preceding the claim.

    11. SLA Updates and Governance

    • This SLA is subject to revision as regulations, technology, and service capabilities evolve.
    • Updates will be published at this URL with version number and effective date.

    See also: API Docum/entation · Terms of Service · Privacy Policy · Compliance