This English text is a convenience translation. In case of discrepancies, the German version of this agreement prevails.
Parties
- Controller
- The company operating an Invoisary account and using the application (the “controller”). The company details stored in the account are authoritative.
- Processor
- Klaus Pfeiffer (Invoisary)Josef Karner Platz 1, 3423 Wördern, AustriaVAT ID: ATU69615348
- Contact for data protection matters
- office@invoisary.com
1. Preamble and scope
This data processing agreement (DPA) specifies the data protection rights and obligations of the parties in connection with the agreement on the use of the Invoisary software (the “main agreement”). It applies to all processing of personal data carried out by the processor on behalf of and on the instructions of the controller in the course of providing Invoisary.
The controller alone determines the purposes and means of processing the data it enters into Invoisary and is responsible for the lawfulness of the processing and for safeguarding the rights of data subjects.
Where the processor processes data for its own purposes — such as the controller's contract and billing data or data from the invoisary.com website — it acts as a controller in its own right; that processing is not covered by this DPA.
2. Subject matter, nature and purpose of processing
The subject matter is the provision of Invoisary as software as a service for managing incoming and outgoing invoices, receipts, offers, payments, bank transactions, budgets, cost centres and reports, together with the associated web and mobile applications.
Processing is automated and includes in particular the collection, recording, organisation, storage, adaptation, retrieval, consultation, use, transmission, restriction and erasure of personal data. Specifically, the scope of the service covers:
- Capturing and managing invoices, receipts and receipt documents, including upload, batch processing and the document archive
- AI-assisted extraction of receipt data from uploaded documents (OCR and document extraction) as well as processing of structured e-invoices
- Receiving receipts via a dedicated email address and sending invoices, notifications and system messages by email
- Connecting bank accounts under PSD2, importing account transactions and reconciling them with invoices and payments
- Approval, query and workflow functions, notes and activity logs
- Budget planning, cost centre and cost object accounting, reports and forecasts
- Exports to accounting and provision of an integration API
- User, role and permission management including sign-in and optional multi-factor authentication
- Operation, maintenance, error analysis and support of the application
The sole purpose of the processing is performance of the main agreement. The processor does not process the controller's data for its own purposes and does not use it to train its own or any third party's AI models.
3. Duration of processing
Processing takes place for the term of the main agreement. This DPA ends automatically with the main agreement; separate termination of this DPA is excluded. The obligations regarding erasure and return under section 14 and the confidentiality obligations survive the end of the agreement.
4. Categories of data subjects
The processing may concern the following groups of persons:
- Employees and other users of the controller (e.g. for data capture, approval, accounting, administration)
- Contact persons at the controller's customers, suppliers and other business partners
- Employees submitting personal expenses or using company cards, and their managers in the approval process
- Payees and payers appearing in imported bank transactions
- Senders of emails to the controller's receipt address
- Other persons whose data is contained in uploaded receipts or captured documents
5. Types of personal data processed
- Master data: name, company name, address, tax and VAT identification numbers, names of cost centres and projects
- Contact data: email addresses, phone numbers, contact persons
- User account data: user name, email address, passwords stored exclusively as cryptographic hashes, roles and permissions, multi-factor authentication settings, language settings
- Invoice and receipt data: invoice numbers, dates, amounts, tax rates, line items, payment terms, uploaded receipt documents (PDF and image files) and the information they contain
- Payment and banking data: IBAN, BIC, account names, account transactions, payment references, payment status and matches to invoices
- Employee-related data: expenses and reimbursements, assignment of receipts to employees, approvals and refusals including reasons
- Communication data: incoming and outgoing emails including attachments, notes, queries about receipts and their answers
- Usage and log data: timestamps, activity and change logs, sign-in events, technical log and error data including IP address and device information
Special categories of personal data under Art. 9 GDPR are not part of the service. The controller ensures that such data is not entered into the application, unless it exceptionally and unavoidably follows from the content of a receipt.
6. The controller's right to issue instructions
The processor processes personal data solely on documented instructions from the controller, unless required to process by Union or Member State law; in that case the processor informs the controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
The main agreement and this DPA, together with the use of the functions offered in the application, constitute the complete initial instruction. Additional instructions must be sent in text form to office@invoisary.com. The persons registered as administrators in the Invoisary account are authorised to issue instructions.
The processor informs the controller without undue delay if, in its opinion, an instruction infringes data protection law (Art. 28(3) final sentence GDPR). It is entitled to suspend execution of such an instruction until it is confirmed or amended.
7. Obligations of the processor
- Processing exclusively within the scope of the main agreement and the controller's instructions
- Committing all persons authorised to process the data to confidentiality; the confidentiality obligation continues after their activity ends
- Implementing and maintaining the technical and organisational measures set out in section 9
- Engaging further processors only in accordance with section 10
- Assisting the controller in responding to requests from data subjects in accordance with section 11
- Assisting the controller in complying with the obligations under Art. 32 to 36 GDPR, in particular with data protection impact assessments and prior consultations, taking into account the nature of processing and the information available to the processor
- Notifying personal data breaches in accordance with section 12
- Erasing or returning the data after the end of the agreement in accordance with section 14
- Making available all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allowing for audits in accordance with section 13
- Maintaining a record of all categories of processing activities carried out on behalf of the controller pursuant to Art. 30(2) GDPR
8. Place of processing
The controller's data is stored exclusively in member states of the European Union or in states party to the Agreement on the European Economic Area. The application, database and document storage are operated in the Frankfurt am Main region (eu-central-1); receipts received by email additionally pass through the Ireland region (eu-west-1).
Personal data is transferred to, or accessed from, a third country only in the case of the sub-processors named in section 10, and only under the conditions of Chapter V GDPR. This concerns in particular the processing of subscription payments via Stripe and the operational monitoring by Datadog.
9. Technical and organisational measures (Art. 32 GDPR)
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, the processor implements the following measures to ensure a level of security appropriate to the risk:
| Area | Implementation |
|---|---|
| Physical access control | The service runs exclusively in certified Amazon Web Services data centres within the EU. The processor operates no server infrastructure of its own. Physical security of the data centres is provided by the operator and certified against common standards (including ISO/IEC 27001, SOC 1/2/3, C5). |
| System access control | Individual user accounts with personal sign-in, passwords stored exclusively as cryptographic hashes, optional multi-factor authentication, locking and reset mechanisms, administrative access limited to a narrowly defined group of people, access to the production environment only over secured connections. |
| Data access control | Role and permission based authorisation model down to record level, separate visibilities for notes and receipts, strict tenant separation. Staff of the processor access customer data only to the extent required for support, troubleshooting or operations. |
| Transfer control | Transport encryption (TLS) for all access to the application, the API and the mobile apps, encrypted storage of documents in object storage and of the database, encrypted transmission to sub-processors, TLS-secured email delivery with SPF, DKIM and DMARC support. |
| Input control | Activity and change logs per invoice and receipt, traceable approvals, refusals and queries, a trash bin with logged deletion, logging of sign-in events. |
| Separation control | Logical separation of data per tenant at application and database level, strict separation of production, staging and development environments; credentials are reset in test environments. |
| Availability and recoverability control | Regular automated and encrypted backups of the database and document storage, redundant infrastructure provided by the data centre operator, continuous monitoring of availability and errors through monitoring and central logging. |
| Control of processing on behalf | Careful selection of sub-processors against data protection and security criteria, conclusion of agreements under Art. 28 GDPR, documented instructions, maintenance of a record of processing activities. |
| Pseudonymisation and encryption | Encryption of data at rest in the database and object storage, hashing of passwords, use of access tokens with limited validity, reduction of personal data in log and error records. |
| Resilience and regular review | Continuous updating of the components in use and of security patches, automated tests in the development process, review and adjustment of the measures whenever material changes occur and at least annually. |
The measures are subject to technical progress. The processor may adapt them provided the agreed level of protection is not reduced.
10. Sub-processors
The controller grants the processor general authorisation to engage the following additional processors:
| Company | Registered office | Service | Place of processing |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Luxembourg | Operation of the application, database and document storage, sending and receiving of email (Amazon SES) | EU (Frankfurt, eu-central-1; inbound email Ireland, eu-west-1) |
| Mistral AI SAS | Paris, France | AI-assisted extraction of receipt data from uploaded documents | EU |
| finAPI GmbH | Munich, Germany | PSD2 bank connectivity, retrieval of account information and transactions | Germany |
| Stripe Payments Europe Ltd. | Dublin, Ireland | Processing of subscription payments for Invoisary | USA and other third countries (transfer to Stripe, LLC) |
| Datadog, Inc. | New York, USA | Operational monitoring, error and log data of the web and mobile applications | EU (Frankfurt data centre, EU1 site), access from the USA possible |
The processor selects sub-processors carefully, reviews their data protection and security levels and concludes contracts with them that meet the requirements of Art. 28(4) GDPR and impose essentially the same obligations as this DPA.
The processor informs the controller at least 30 days in advance, by email to the administrators registered in the account, of the addition of a new sub-processor or a change of an existing one. The controller may object to the change within that period on important data protection grounds. If the objection cannot be resolved, the controller is entitled to terminate the main agreement for cause with effect from the date of the change.
Ancillary services obtained from third parties without any intended access to the controller's personal data — such as telecommunications services or maintenance without data access — do not constitute sub-processing.
Where personal data is transferred to, or accessed from, a third country — in particular by Stripe, LLC and Datadog, Inc., both established in the United States — this takes place on the basis of an adequacy decision of the European Commission or the standard contractual clauses pursuant to Art. 46(2)(c) GDPR together with supplementary safeguards. For Stripe the transfer mechanism follows the Data Transfers Addendum to Stripe's data processing agreement (EU-US Data Privacy Framework or standard contractual clauses); for Datadog the standard contractual clauses incorporated into its data processing agreement apply.
Stripe processes part of the payment data not as a sub-processor but as an independent controller — in particular to detect and prevent fraud, to comply with anti-money-laundering and regulatory obligations including customer identification, and to develop its own services. For that processing Stripe determines the purposes and means itself; it is not governed by this DPA but by Stripe's own privacy policy.
11. Rights of data subjects
The processor assists the controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests for exercising the data subject rights laid down in Chapter III GDPR. The application provides functions for access, rectification, restriction, erasure and export of data in common formats.
If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay and does not answer it itself unless expressly instructed to do so. The processor rectifies, erases or restricts data only on the controller's instructions or where legally obliged to do so.
12. Personal data breaches
The processor notifies the controller of any personal data breach without undue delay, as a rule within 24 hours of becoming aware of it, by email to the administrators registered in the account.
The notification contains, where available, a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed to address and mitigate it. The processor assists the controller with its notification obligations under Art. 33 and 34 GDPR and documents all incidents.
13. Evidence and audit rights
On request, the processor demonstrates compliance with the obligations set out in this DPA, in particular through this documentation of the technical and organisational measures, through information in text form and by providing available certificates, attestations or audit reports of the sub-processors engaged.
The controller is further entitled to carry out audits or have them carried out by an appointed auditor. On-site audits require reasonable prior notice of at least four weeks, take place during normal business hours, must not disrupt operations and are as a rule limited to once per year. Where there is specific cause, in particular following a personal data breach, the annual limit does not apply. Appointed auditors must not be in competition with the processor and must be bound to confidentiality. The controller bears its own costs and those of any appointed auditor.
14. Erasure and return of data
After the end of the main agreement, the processor erases all personal data processed on behalf of the controller or returns it, at the controller's choice. The controller can download its data at any time during the term and within 30 days after the end of the agreement using the export and reporting functions of the application in common formats.
Production data is erased within 30 days after the end of the agreement. Data contained in backups is erased in the course of the regular backup cycle, at the latest within 90 days after the end of the agreement; until then it is reserved exclusively for restore purposes.
This does not affect the storage of data that the processor is required to retain under Union or Member State law. Such data is restricted until the respective retention period expires and is processed solely for the purpose of fulfilling the legal obligation.
15. Liability
Art. 82 GDPR applies to the liability of the parties. Between the parties, the liability provisions of the main agreement apply in addition, to the extent they do not conflict with mandatory data protection law.
16. Final provisions
- Amendments and additions to this DPA must be made in text form; this also applies to any waiver of this form requirement.
- In the event of conflicts between this DPA and the main agreement, the provisions of this DPA prevail in data protection matters.
- Should any provision of this DPA be or become invalid, the validity of the remaining provisions remains unaffected. The parties shall replace the invalid provision with a valid one that comes closest to its economic purpose.
- Austrian law applies, excluding its conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods. Mandatory data protection provisions remain unaffected.
- To the extent legally permissible, the exclusive place of jurisdiction is the competent court at the processor's registered office.
Concluding the DPA
This agreement becomes part of the contractual relationship when the service agreement is concluded; no separate signature is required. If you need a signed copy for your data protection documentation, we are happy to send you one.
Request a signed copy