Compliance
Data Processing Agreement (DPA)
Last updated: October 2026
This Data Processing Agreement (“DPA”) governs the processing of personal data in connection with the electronic invoicing REST API services provided by EInvoiceFile (“Processor”, “we”, “us”) to the subscribing enterprise or organization (“Controller”, “you”). This DPA is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”) and is incorporated into and forms an integral part of the Terms of Service.
1. Purpose, Scope & Instructions
- Roles: Customer is the Data Controller; EInvoiceFile is the Data Processor.
- Scope: This DPA applies solely to personal data contained within electronic invoice documents (XML, JSON, PDF) submitted by Controller to Processor's API for creation, validation, conversion, rendering, or extraction (“Customer Invoice Data”).
- Documented Instructions: Processor shall process Customer Invoice Data exclusively on documented instructions from Controller, including with respect to transfers of personal data to a third country, unless required to do so by applicable Union or Member State law. Controller's API calls and parameter selections constitute complete and final documented instructions.
2. Details of Processing (Annex I)
- Subject Matter: Technical transformation, validation, rendering, and schema compliance checking of electronic invoices (Factur-X, ZUGFeRD, XRechnung, Peppol BIS, UBL, CII, KSeF, and FatturaPA).
- Duration: Ephemeral. Customer Invoice Data exists in volatile process memory (RAM) strictly for the duration of the HTTP transaction and is discarded immediately upon transmission of the API response. Processor maintains no persistent storage or archive of customer invoice payloads.
- Categories of Data Subjects: Controller's customers, clients, suppliers, vendors, contractors, and designated contact persons appearing on invoice records.
- Categories of Personal Data: Contact names, business/residential addresses, telephone numbers, email addresses, tax identification numbers (VAT ID, tax numbers), bank coordinates (IBAN, BIC), and commercial transaction line items.
3. Technical & Organizational Measures (TOMs - Art. 32 GDPR)
Processor implements and maintains appropriate technical and organizational security measures designed to protect Customer Invoice Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:
- Encryption in Transit: Mandatory enforcement of TLS 1.3 across all production API endpoints. Plaintext HTTP connections are refused.
- Volatile In-Memory Execution: Invoice XML and PDF payloads are parsed and processed in memory buffers only. Payloads are never written to persistent disk storage or stored in databases.
- Access Controls & Authentication: Production systems require hardware-backed multi-factor authentication (MFA) and least-privilege role-based access controls (RBAC).
- Continuous Quality & Security: Automated static application security testing (SAST), automated dependency auditing, and secure coding practices.
4. Subprocessors (Art. 28(2) & Art. 28(4))
Controller grants general written authorization to Processor to engage the following vetted subprocessors to support delivery of the service:
| Subprocessor | Activity | Location | Transfer Safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Cloud compute and networking infrastructure | Frankfurt, Germany | Intra-EEA (EU Data Residency) |
| MongoDB Ltd. | Workspace and account database storage | Frankfurt, Germany | Intra-EEA (EU Data Residency) |
| Polar Signals Inc. | Merchant of Record, subscriptions and payments | USA / EU | EU-US Data Privacy Framework / SCCs |
| EInvoiceFile Operating Team | Technical maintenance, deployment and support | India | EU Standard Contractual Clauses (Module 2) |
Processor shall provide at least thirty (30) days' prior written notice of any intended changes concerning the addition or replacement of subprocessors, giving Controller the opportunity to object on reasonable data protection grounds.
5. Cross-Border Transfers & Standard Contractual Clauses
Where operational maintenance or support involves remote access from India or any jurisdiction outside the EEA lacking an adequacy decision under Article 45 GDPR, the parties agree that the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module 2: Controller-to-Processor) are incorporated into this DPA by reference:
- Controller is the “data exporter” and Processor is the “data importer”.
- Clause 9 (Sub-processors): Option 2 (General written authorization) applies with 30 days' notice.
- Clause 11 (Redress): The optional independent redress mechanism is not selected.
- Clause 17 (Governing Law): The Clauses shall be governed by the laws of Germany.
- Clause 18 (Choice of Forum): Any dispute arising from the Clauses shall be resolved by the competent courts of Frankfurt am Main, Germany.
6. Security Incident Notification
Processor shall notify Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a confirmed personal data breach affecting Customer Invoice Data. Processor shall take reasonable steps to mitigate the effects and provide Controller with information reasonably necessary to meet its breach reporting obligations under Articles 33 and 34 of the GDPR.
7. Audits & Compliance Verification
Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including administrative reviews, conducted by Controller or an independent auditor mandated by Controller, upon reasonable advance written notice and subject to appropriate confidentiality obligations.
8. Deletion & Return of Data
Due to Processor's ephemeral, RAM-only execution architecture, Customer Invoice Data is automatically erased from memory immediately upon completion of the API request. No retained invoice copies exist to return or delete.
9. Inquiries & Execution
For inquiries regarding this DPA or if your organization requires a countersigned PDF agreement for enterprise records, please contact our compliance team at support@einvoicefile.com.