Bizalma
Product Pricing Trust FAQ Accounting
EN LV RU
Sign in Create account

Data Processing Agreement

Version: 1.0 · Effective date: __[set on publication]__

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between AIS TECH LIMITED (“Processor”, “we”) and the customer accepting those Terms (“Controller”, “you”). It is concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 (“GDPR”).

Where this DPA conflicts with the Terms of Service, this DPA prevails in respect of the processing of personal data contained in Documents.

1. Subject matter and roles

You upload Documents to the Service. Those Documents contain personal data of individuals who are not our users — representatives of suppliers and buyers, sole traders, and individuals named on an invoice.

In respect of that personal data you are the controller and we are the processor. You determine the purposes and means of processing; we process only as set out in this DPA and on your instructions.

Personal data relating to your own users and to the administration and billing of your account is processed by us as controller, and is governed by our Privacy Policy, not by this DPA.

2. Your instructions

We process personal data in Documents only on your documented instructions. Your instructions consist of:

  • the Terms of Service and this DPA;
  • the configuration you apply in the Platform, including the service profile, the party mode of the Organisation, the Output Format, and the Served Companies you register;
  • the act of uploading a Document for processing;
  • requests you submit through support.

We will inform you if, in our opinion, an instruction infringes the GDPR or another provision of Union or member state data protection law, and may suspend performance of that instruction until it is confirmed or amended.

We will not process the personal data for our own purposes. We do not use Documents, Extracted Data, or Output Files to train machine learning models, and we do not sell or otherwise make personal data available to third parties except as provided in clause 5.

3. Your obligations

You warrant that you have a lawful basis for the processing you instruct, that you are entitled to submit each Document, including Documents of Served Companies, and that you have provided any information required to the individuals concerned.

You must not upload special categories of personal data within the meaning of Article 9 GDPR, or personal data unrelated to the commercial content of an invoice. The Service is not designed for such data, and the measures in Annex II are not calibrated to it.

4. Confidentiality and personnel

We ensure that persons authorised to process the personal data are bound by obligations of confidentiality and are subject to appropriate training. Access is granted only to personnel who require it in order to deliver the Service or to support it.

Access by our personnel to your Documents, including corrections made during moderation, is recorded in an audit log available to you.

5. Subprocessors

You grant a general written authorisation for the engagement of subprocessors. Those engaged at the date of this DPA are listed in Annex III.

We impose on each subprocessor, by written contract, data protection obligations no less protective than those in this DPA, and we remain liable to you for the performance of each subprocessor’s obligations.

We will notify you at least 30 days before adding or replacing a subprocessor. If you object on reasonable grounds related to data protection within that period, we will work with you in good faith to find an accommodation; if none is found, either party may terminate the affected part of the Service, and you will not be charged for the Service after the date of termination.

6. International transfers

Personal data is stored at rest exclusively within the European Union.

Personal data contained in Documents is transmitted to our artificial intelligence subprocessor for the purpose of extraction, and that subprocessor may process it outside the European Economic Area. Such transfers are carried out on the basis of the transfer mechanism identified in Annex III, being the Standard Contractual Clauses adopted by the European Commission or an adequacy decision, together with supplementary measures where required.

7. Security

We implement the technical and organisational measures set out in Annex II, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to individuals.

We may update those measures over time provided the level of protection is not reduced.

8. Assistance with your obligations

Data subject rights. Where we receive a request from an individual relating to personal data in your Documents, we will not respond to it on the merits and will refer the individual to you, informing you without undue delay. We will assist you in fulfilling such requests by making available the functions of the Platform and, where those are insufficient, by reasonable assistance on request.

Impact assessments and consultation. We will provide, on request, the information in our possession that you reasonably require in order to carry out a data protection impact assessment or to consult a supervisory authority under Articles 35 and 36 GDPR.

9. Personal data breach

We will notify you of a personal data breach affecting personal data processed under this DPA without undue delay and in any event within 48 hours of becoming aware of it, at the contact address registered for your account.

The notification will describe the nature of the breach, the categories and approximate number of records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full information is not available at the time of notification, we will provide it in phases without undue delay.

We will not notify a supervisory authority or any individual on your behalf unless you instruct us to do so or we are independently required to.

10. Audit and demonstration of compliance

We will make available to you the information necessary to demonstrate compliance with this DPA.

You may audit our compliance once in any twelve-month period, on at least 30 days’ written notice, during business hours, without unreasonable disruption to our operations, and subject to confidentiality obligations. Additional audits may be conducted where required by a supervisory authority or following a personal data breach affecting your data. We may satisfy an audit request by providing documentation, written responses, or a third-party report where that reasonably addresses the scope of the request. You bear your own costs of an audit and, where the audit exceeds one working day of our personnel’s time, our reasonable costs.

11. Deletion and return

At any time during the term you may export the personal data through the Platform, in the formats and subject to the limits described in the Terms of Service.

On termination, and on deletion of a Document or an Organisation, the record is placed in a deleted state and is then irreversibly deleted from our databases and object storage on expiry of the retention period for deleted data, being one year. On your written request we will carry out that deletion earlier.

Entries in the audit log recording actions taken on a Document are retained after that deletion, as a record of processing and for the establishment, exercise, and defence of legal claims. Those entries identify the acting user, the object, the action, and the time; they do not retain the content of the Document.

We will not retain personal data beyond those periods except where required by Union or member state law, in which case we will inform you of that requirement.

12. Liability and term

The limitations of liability in the Terms of Service apply to claims under this DPA to the extent permitted by law.

This DPA takes effect when you accept the Terms of Service and continues for as long as we process personal data on your behalf, including during the retention period in clause 11.


Annex I — Details of the processing

Categories of data subjects. Representatives, contact persons, and signatories of suppliers and buyers named in the Documents; sole traders and other natural persons who are themselves a party to the invoiced transaction; employees and representatives of you and of your Served Companies whose details appear on a Document.

Categories of personal data. Names; business contact details including postal address, email address, and telephone number; registration and tax identification numbers; bank account details; the commercial content of the invoice, including references, descriptions of goods and services, quantities, and amounts; and any personal data incidentally present in free-text fields or in the image of the uploaded file.

Special categories of personal data. None. Their submission is prohibited under clause 3.

Nature and purpose of the processing. Receipt and storage of uploaded files; automated extraction of data from them, including by machine learning models; construction of a canonical invoice model aligned to EN 16931; validation against that standard and, where selected, against Peppol BIS rules; human review and correction of extracted values where the outcome requires judgement; generation and provision of Output Files; metering of usage for invoicing.

Duration. For the term of the Terms of Service, and thereafter until deletion in accordance with clause 11.

Frequency. Continuous, on each upload.


Annex II — Technical and organisational measures

Access control — persons. Authentication through a dedicated identity provider using OpenID Connect with authorisation code flow and PKCE. Role-based authorisation. Passwords stored only as cryptographic hashes; email verification required on registration. Access by our personnel restricted to those who require it; support access to customer data is read-only.

Access control — data segregation. The Organisation is the boundary of isolation, enforced in the application layer on every request for documents, results, and exports. A user of one Organisation cannot address the data of another.

Transmission control. All external traffic is served over TLS. Internal services — the validation service, the company registry service, the AI pipeline, the object storage, and the database — are not published to the public internet and are reachable only on the internal container network.

Input and accountability control. An append-only audit log records the acting user, the object, the action, and the time for actions in the Service, including uploads, corrections, exports, deletions, and access in support mode. The provenance of each extracted value records whether it was produced automatically or confirmed by a human.

Subprocessor control at the AI provider. Logging of API calls at our artificial intelligence provider is disabled at organisation level, so that prompts and model outputs are not retained in that provider’s environment for review, analysis, or evaluation. Data submitted through the interface is not used to train that provider’s models. Administrative actions in that provider’s environment are logged.

Availability control. Capacity limits are applied per Organisation and globally to protect the availability of processing; requests exceeding capacity are declined with a retry indication rather than dropped. Upload size and batch limits are enforced at the proxy, framework, and application layers.

Separation of environments and secrets. Development and production are separate environments. Production secrets are held only on the production host and are not stored in source control. Deployment is automated from source control over an authenticated channel.

Organisational measures. Confidentiality obligations for all personnel with access; least-privilege administrative accounts on infrastructure; documented runbooks for infrastructure operations.


Annex III — Subprocessors

SubprocessorPurposeData processedLocationTransfer basis
netcup GmbH, GermanyHosting and infrastructure for all services, the database, and object storageAll personal data processed under this DPA, at restGermanyNot applicable — within the EU
__[OpenAI contracting entity — confirm from invoice]__Extraction of data from Documents by machine learning modelsContent of uploaded Documents, including any personal data it containsEuropean Union and United StatesStandard Contractual Clauses under the subprocessor’s data processing addendum
Sendinblue SAS, trading as Brevo, FranceTransactional email deliveryEmail addresses and names of your users. No Document contentFranceNot applicable — within the EU

The object storage, database, identity provider, and observability tooling are operated by us on the infrastructure listed above and are not separate subprocessors.

Our payment provider is not a subprocessor under this DPA. It receives payment and billing data relating to your account, never the content of a Document, and that processing is described in the Privacy Policy instead.

Bizalma

AIS TECH LIMITED · HE 494533
Ifigeneias 14, Limassol 3036, Cyprus

Product Pricing Trust FAQ Accounting Contact
Terms of Service Privacy Policy Data Processing Agreement support@bizalma.com